Skip to content

Add PR CI workflow and update terraform-plugin-framework and other dependencies - #22

Draft
vasuman wants to merge 3 commits into
mainfrom
varav/pr-ci-and-dep-bumps-aee6
Draft

vasuman wants to merge 3 commits into
mainfrom
varav/pr-ci-and-dep-bumps-aee6

Conversation

@vasuman

@vasuman vasuman commented Oct 9, 2026 •

Copy link
Copy Markdown
Member

Three commits; the CI commit comes first so the new workflow validates the dependency bump in this same PR.

1. PR CI (.github/workflows/ci.yml)

Runs on pull_request and on pushes to main. release.yml is untouched; the new workflow reuses its exact actions/checkout and actions/setup-go pins and reads the Go version from go.mod via go-version-file with the module cache enabled.

Job What fails it
Build, vet, format, tidy go build ./..., go vet ./..., any gofmt -l output, any go.mod/go.sum diff after go mod tidy
Unit tests go test ./... -race
Generated docs up to date make docs (tfplugindocs generate + validate), then any git status --porcelain docs/ output
Registry manifest is valid JSON terraform-registry-manifest.json fails to parse
govulncheck (advisory) continue-on-error: true for now; does not block merge

2. Dependency bumps

Module Old New
github.com/hashicorp/terraform-plugin-framework v1.17.0 v1.19.0
github.com/hashicorp/terraform-plugin-go v0.29.0 v0.31.0
github.com/hashicorp/terraform-plugin-log v0.10.0 v0.11.0
connectrpc.com/connect v1.19.1 v1.21.0
google.golang.org/protobuf v1.36.11 v1.36.12
google.golang.org/grpc (indirect) v1.79.3 v1.84.0
golang.org/x/net (indirect) v0.55.0 v0.60.0
golang.org/x/text (indirect) v0.37.0 v0.42.0
golang.org/x/sys (indirect) v0.45.0 v0.48.0
google.golang.org/genproto/googleapis/rpc (indirect) 20251202 20261005
go directive 1.25.0 1.26.0
toolchain directive (none) go1.26.9

terraform-plugin-framework-validators and terraform-plugin-testing are not dependencies of this module, so there was nothing to bump there.

Go 1.26 requirement. golang.org/x/net v0.60.0 (the release that fixes GO-2026-6603/6611/6612/6617) declares go >= 1.26.0, so go get moved the module's go directive to 1.26.0. Both workflows read the version from go.mod, so CI and release builds pick it up automatically; local builds on an older toolchain auto-download under the default GOTOOLCHAIN=auto.

Toolchain pin (3rd commit). setup-go installs exactly what go.mod names. With only go 1.26.0, the first CI run's govulncheck job flagged net/http standard-library CVEs fixed in go1.26.9, and release.yml would have shipped binaries built with that same unpatched stdlib. A toolchain go1.26.9 directive is honored by setup-go in both workflows, so no change to release.yml is needed.

govulncheck: main reports 8 reachable findings (4× x/net, 3× grpc, 1× x/text). After the bump and toolchain pin: No vulnerabilities found., both locally and in the CI job.

make docs produces no diff after the bump; go build, go vet, gofmt, go mod tidy, and go test ./... -race all pass locally and in CI.

Changelog items relevant to this provider

terraform-plugin-framework 1.18.0 / 1.19.0

  • Deprecation handling (1.18.0, #1276 + plugin-go #600): DeprecationMessage on attributes and nested attributes is now also sent to Terraform in the provider schema (SchemaAttribute.DeprecationMessage), in addition to the framework's existing Attribute Deprecated / Block Deprecated warning diagnostic emitted at validate time when a deprecated attribute is set. The validate-time warning code is unchanged between 1.17.0 and 1.19.0, so the 13 DeprecationMessage uses in this provider (namespace_id, respond_in_thread, channel, ...) keep behaving the same; newer Terraform CLIs can additionally surface the message from the schema.
  • Import config generation (1.19.0, #1281): the terraform plan -generate-config-out logic moved from Terraform Core into the framework for Terraform ≥ 1.14, implemented via the new, now-required GenerateResourceConfig RPC in plugin-go 0.31.0. HashiCorp states no functional change. All importable resources here go through the framework's providerserver, so nothing to implement.
  • Plan modifiers and nested attributes: no semantic changes in 1.18.0 or 1.19.0 to planmodifier.*, UseStateForUnknown, RequiresReplace*, ModifyPlan, or SingleNested/ListNested attribute and block handling. Only additions: Length() on List/Map/Set/Tuple values and the experimental statestore packages.
  • Both framework and plugin-go now require Go 1.25 as a floor (this PR goes to 1.26 for the x/net reason above).

terraform-plugin-go 0.31.0 (breaking at the protocol layer only): GenerateResourceConfig is now required on ResourceServer; satisfied by framework 1.19.0, which this PR upgrades to in the same step.

connect-go 1.20.0 / 1.21.0: minimum Go 1.25; client-side bugfixes (user-agent no longer injected into request headers, client streaming no longer blocks after context cancellation, data race / connection leak fix in duplexHTTPCall). New server-side WithRequestGate option is not used here. No API changes for the unary AutomationsService client this provider uses.

protobuf-go 1.36.12: protojson now rejects non-numeric ints/floats and fixes google.protobuf.Empty serialization; prototext gains a recursion limit. This provider does not use protojson/prototext directly, so no impact beyond the vendored automations.pb.go continuing to compile.

Open in Web Open in Cursor 

cursoragent and others added 3 commits October 9, 2026 00:42
Build, vet, gofmt, go mod tidy, race-enabled unit tests, generated docs drift,
and registry manifest checks run on pull requests and pushes to main.
govulncheck runs as an advisory job until the baseline is clean.

Co-authored-by: Vasuman Ravichandran <varav@varav.in>
terraform-plugin-framework 1.17.0 -> 1.19.0, terraform-plugin-go 0.29.0 -> 0.31.0,
terraform-plugin-log 0.10.0 -> 0.11.0, connectrpc.com/connect 1.19.1 -> 1.21.0,
google.golang.org/protobuf 1.36.11 -> 1.36.12, and indirect grpc / x/net / x/text
updates that clear the current govulncheck findings. x/net 0.60.0 requires Go 1.26,
so the module's go directive moves from 1.25.0 to 1.26.0. Generated docs are unchanged.

Co-authored-by: Vasuman Ravichandran <varav@varav.in>
… standard library

setup-go honors the toolchain directive in go.mod, so without it both workflows
install exactly go1.26.0 and govulncheck reports the net/http fixes that landed
in later 1.26.x patch releases.

Co-authored-by: Vasuman Ravichandran <varav@varav.in>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants