Repository navigation
Conversation
Build, vet, gofmt, go mod tidy, race-enabled unit tests, generated docs drift, and registry manifest checks run on pull requests and pushes to main. govulncheck runs as an advisory job until the baseline is clean. Co-authored-by: Vasuman Ravichandran <varav@varav.in>
terraform-plugin-framework 1.17.0 -> 1.19.0, terraform-plugin-go 0.29.0 -> 0.31.0, terraform-plugin-log 0.10.0 -> 0.11.0, connectrpc.com/connect 1.19.1 -> 1.21.0, google.golang.org/protobuf 1.36.11 -> 1.36.12, and indirect grpc / x/net / x/text updates that clear the current govulncheck findings. x/net 0.60.0 requires Go 1.26, so the module's go directive moves from 1.25.0 to 1.26.0. Generated docs are unchanged. Co-authored-by: Vasuman Ravichandran <varav@varav.in>
… standard library setup-go honors the toolchain directive in go.mod, so without it both workflows install exactly go1.26.0 and govulncheck reports the net/http fixes that landed in later 1.26.x patch releases. Co-authored-by: Vasuman Ravichandran <varav@varav.in>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Three commits; the CI commit comes first so the new workflow validates the dependency bump in this same PR.
1. PR CI (
.github/workflows/ci.yml)Runs on
pull_requestand on pushes tomain.release.ymlis untouched; the new workflow reuses its exactactions/checkoutandactions/setup-gopins and reads the Go version fromgo.modviago-version-filewith the module cache enabled.go build ./...,go vet ./..., anygofmt -loutput, anygo.mod/go.sumdiff aftergo mod tidygo test ./... -racemake docs(tfplugindocs generate + validate), then anygit status --porcelain docs/outputterraform-registry-manifest.jsonfails to parsecontinue-on-error: truefor now; does not block merge2. Dependency bumps
github.com/hashicorp/terraform-plugin-frameworkgithub.com/hashicorp/terraform-plugin-gogithub.com/hashicorp/terraform-plugin-logconnectrpc.com/connectgoogle.golang.org/protobufgoogle.golang.org/grpc(indirect)golang.org/x/net(indirect)golang.org/x/text(indirect)golang.org/x/sys(indirect)google.golang.org/genproto/googleapis/rpc(indirect)godirectivetoolchaindirectiveterraform-plugin-framework-validatorsandterraform-plugin-testingare not dependencies of this module, so there was nothing to bump there.Go 1.26 requirement.
golang.org/x/net v0.60.0(the release that fixes GO-2026-6603/6611/6612/6617) declaresgo >= 1.26.0, sogo getmoved the module'sgodirective to 1.26.0. Both workflows read the version fromgo.mod, so CI and release builds pick it up automatically; local builds on an older toolchain auto-download under the defaultGOTOOLCHAIN=auto.Toolchain pin (3rd commit).
setup-goinstalls exactly whatgo.modnames. With onlygo 1.26.0, the first CI run's govulncheck job flaggednet/httpstandard-library CVEs fixed in go1.26.9, andrelease.ymlwould have shipped binaries built with that same unpatched stdlib. Atoolchain go1.26.9directive is honored bysetup-goin both workflows, so no change torelease.ymlis needed.govulncheck:
mainreports 8 reachable findings (4× x/net, 3× grpc, 1× x/text). After the bump and toolchain pin:No vulnerabilities found., both locally and in the CI job.make docsproduces no diff after the bump;go build,go vet,gofmt,go mod tidy, andgo test ./... -raceall pass locally and in CI.Changelog items relevant to this provider
terraform-plugin-framework 1.18.0 / 1.19.0
DeprecationMessageon attributes and nested attributes is now also sent to Terraform in the provider schema (SchemaAttribute.DeprecationMessage), in addition to the framework's existingAttribute Deprecated/Block Deprecatedwarning diagnostic emitted at validate time when a deprecated attribute is set. The validate-time warning code is unchanged between 1.17.0 and 1.19.0, so the 13DeprecationMessageuses in this provider (namespace_id,respond_in_thread,channel, ...) keep behaving the same; newer Terraform CLIs can additionally surface the message from the schema.terraform plan -generate-config-outlogic moved from Terraform Core into the framework for Terraform ≥ 1.14, implemented via the new, now-requiredGenerateResourceConfigRPC in plugin-go 0.31.0. HashiCorp states no functional change. All importable resources here go through the framework'sproviderserver, so nothing to implement.planmodifier.*,UseStateForUnknown,RequiresReplace*,ModifyPlan, orSingleNested/ListNestedattribute and block handling. Only additions:Length()on List/Map/Set/Tuple values and the experimentalstatestorepackages.terraform-plugin-go 0.31.0 (breaking at the protocol layer only):
GenerateResourceConfigis now required onResourceServer; satisfied by framework 1.19.0, which this PR upgrades to in the same step.connect-go 1.20.0 / 1.21.0: minimum Go 1.25; client-side bugfixes (user-agent no longer injected into request headers, client streaming no longer blocks after context cancellation, data race / connection leak fix in
duplexHTTPCall). New server-sideWithRequestGateoption is not used here. No API changes for the unaryAutomationsServiceclient this provider uses.protobuf-go 1.36.12:
protojsonnow rejects non-numeric ints/floats and fixesgoogle.protobuf.Emptyserialization;prototextgains a recursion limit. This provider does not useprotojson/prototextdirectly, so no impact beyond the vendoredautomations.pb.gocontinuing to compile.