Skip to content

chore(deps): update go module directive to v1.27.1 - #47

Open
scality-renovate[bot] wants to merge 1 commit into
mainfrom
renovate/golang
Open

scality-renovate[bot] wants to merge 1 commit into
mainfrom
renovate/golang

Conversation

@scality-renovate

@scality-renovate scality-renovate Bot commented Jun 8, 2026 •

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Type Update Change
go (source) golang minor 1.25.0 → 1.27.1

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • "before 9am on monday"
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate CLI.

@scality-renovate
scality-renovate Bot requested a review from a team as a code owner June 8, 2026 14:01
@scality-renovate scality-renovate Bot added dependencies Pull requests that update a dependency file docker go Pull requests that update go code minor labels Jun 8, 2026
@scality-renovate scality-renovate Bot changed the title chore(deps): update golang to v1.26 chore(deps): update golang Jun 8, 2026
@scality-renovate

Copy link
Copy Markdown
Contributor Author

Edited/Blocked Notification

Renovate will not automatically rebase this PR, because it does not recognize the last commit author and assumes somebody else may have edited the PR.

You can manually request rebase by checking the rebase/retry box above.

⚠️ Warning: custom changes will be lost.

@scality-renovate
scality-renovate Bot force-pushed the renovate/golang branch 5 times, most recently from af2689f to 30990fd Compare June 16, 2026 04:16
@scality-renovate scality-renovate Bot removed the docker label Jun 25, 2026
@scality-renovate scality-renovate Bot changed the title chore(deps): update golang chore(deps): update go module directive to v1.26.4 Jun 26, 2026
@scality-renovate scality-renovate Bot changed the title chore(deps): update go module directive to v1.26.4 chore(deps): update golang Jul 7, 2026
@scality-renovate scality-renovate Bot removed the docker label Jul 8, 2026
@scality-renovate scality-renovate Bot changed the title chore(deps): update golang chore(deps): update go module directive to v1.26.4 Jul 8, 2026
@scality-renovate scality-renovate Bot changed the title chore(deps): update go module directive to v1.26.4 chore(deps): update go module directive to v1.26.5 Jul 14, 2026
@scality-renovate scality-renovate Bot changed the title chore(deps): update go module directive to v1.26.5 chore(deps): update golang Jul 28, 2026
@scality-renovate scality-renovate Bot removed the docker label Aug 5, 2026
@scality-renovate scality-renovate Bot changed the title chore(deps): update golang chore(deps): update go module directive to v1.26.5 Aug 5, 2026
@scality-renovate scality-renovate Bot changed the title chore(deps): update go module directive to v1.26.5 chore(deps): update go module directive to v1.26.6 Aug 20, 2026
@github-actions

github-actions Bot commented Aug 20, 2026 •

Copy link
Copy Markdown

Dependency Bump Evaluation

Version change: Go 1.25.0 → 1.27.1 (multi-minor jump, skips 1.26 entirely)
Semver bump type: minor (x2)

Changes:

  • Go module directive bumped from 1.25.0 to 1.27.1
  • require blocks reorganized (no dependency version changes)
  • Only go.mod modified; Dockerfile and CI tooling not updated

Breaking changes:

  • encoding/json v2 backend (Go 1.27): Now rejects invalid UTF-8 and duplicate JSON keys. Error message text changed. Opt-out: GOEXPERIMENT=nojsonv2. This codebase uses json.Unmarshal in e2e tests and relies on controller-runtime which heavily uses JSON serialization for CRDs.
  • crypto/tls hardening (Go 1.26+1.27): Post-quantum key exchanges enabled by default; tlsrsakex, tls3des, tls10server GODEBUG settings permanently removed. This codebase configures TLS in cmd/main.go and webhook tests.
  • Timer channels permanently unbuffered (Go 1.27): asynctimerchan GODEBUG removed. No direct usage found in this codebase, but controller-runtime may use timers internally.
  • go mod tidy enforces exactly two require blocks for go 1.27+ modules.
  • go test runs stdversion vet check by default, failing on stdlib symbols newer than the module's go directive.
  • Green Tea GC enabled by default (Go 1.26), changing GC timing.

Security concerns: None — this is a Go toolchain upgrade with no new dependencies. Crypto changes strengthen TLS defaults.

Impact on codebase:

  • encoding/json used in test/e2e/e2e_test.go (token unmarshaling) — low direct risk but controller-runtime CRD serialization may be affected
  • crypto/tls configured in cmd/main.go (lines 72, 107, 136, 185) and webhook_suite_test.go — modern TLS usage, unlikely to break
  • No time.NewTimer/time.NewTicker, url.Parse, or ReverseProxy usage found

Recommendation: REVIEW REQUIRED

Notes:

  1. CI is broken — PR is incomplete. The Dockerfile (golang:1.25 on line 2) and golangci-lint (v2.5.0, built with Go 1.25) both need updating to support Go 1.27.1:
    • Dockerfile:2 — update base image from golang:1.25 to golang:1.27
    • .github/workflows/pre-merge.yaml:47 — update golangci-lint to a version built with Go 1.27+
  2. Multi-minor jump risk. Jumping from 1.25 → 1.27 skips Go 1.26 entirely. Both releases contain breaking stdlib changes (JSON v2, TLS hardening, timer semantics). Run the full test suite after fixing CI to verify compatibility.
  3. Suggested approach: Fix the Dockerfile and lint config in this PR (or a companion PR), then verify all CI checks pass before merging.

— Claude Code

@scality-renovate scality-renovate Bot changed the title chore(deps): update go module directive to v1.26.6 chore(deps): update go module directive to v1.27.0 Aug 26, 2026
@scality-renovate scality-renovate Bot changed the title chore(deps): update go module directive to v1.27.0 chore(deps): update go module directive to v1.27.1 Sep 8, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file go Pull requests that update go code minor

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant