Skip to content

build(go)!: require Go 1.26.8 and test Go 1.27 - #62

Merged
appleboy merged 2 commits into
mainfrom
chore/go-1.26-upgrade
Sep 29, 2026
Merged

appleboy merged 2 commits into
mainfrom
chore/go-1.26-upgrade

Conversation

@appleboy

@appleboy appleboy commented Sep 28, 2026 •

Copy link
Copy Markdown
Member

Summary

Raise the minimum Go version to 1.26.8 and test both Go 1.26 and 1.27. GOTOOLCHAIN=local ensures each CI job actually uses the selected compiler. Checkout now precedes setup-go, and cache keys distinguish Go versions.

  • Align lint and CodeQL toolchains and enforce Trivy security checks.
  • Build example modules with both supported Go versions.
  • Upgrade vulnerable dependencies and synchronize module checksums.
  • Validate release configuration with GoReleaser v2.

Compatibility and scope

Breaking toolchain requirement: consumers using Go 1.25 or an older 1.26 patch must upgrade to Go 1.26.8 or newer. This PR implements the requested Go upgrade, CI compatibility checks and vulnerability remediation. No issue or Jira reference was supplied.

CI flow

flowchart TD
  M["go.mod: Go 1.26.8"] --> C["codeql.yaml: explicit Go setup"]
  M --> L["go.yml: golangci-lint 2.14.0"]
  M --> T["go.yml: tests on 1.26 and 1.27"]
  M --> S["go.yml: Trivy security gate"]
  style M fill:#dbeafe,stroke:#2563eb
  style C fill:#dbeafe,stroke:#2563eb
  style L fill:#dbeafe,stroke:#2563eb
  style T fill:#dbeafe,stroke:#2563eb
  style S fill:#dbeafe,stroke:#2563eb
Loading

AI authorship and classification

  • AI was used: Codex (GPT-6).
  • AI-authored/modified files:
    • .github/workflows/codeql.yaml
    • .github/workflows/go.yml
    • .goreleaser.yaml
    • _example/producer-consumer/go.mod
    • _example/producer-consumer/go.sum
    • _example/worker/go.mod
    • _example/worker/go.sum
    • go.mod
    • go.sum
  • Human line-by-line reviewed: None — not yet reviewed by a human.
  • Core change: changes the supported toolchain and CI gates for this shared module. Request two reviewers, including the module owner.

Verification

Setup

Check out chore/go-1.26-upgrade in golang-queue/nats and run commands from the repository root unless stated otherwise:

git fetch origin chore/go-1.26-upgrade
git switch chore/go-1.26-upgrade

Prerequisites: Go 1.26.8 and 1.27.1, golangci-lint 2.14.0, Trivy 0.70.0, actionlint 1.7.12, GoReleaser 2.18.2. Docker must be running; tests create disposable containers.

Start the two NATS services used by the existing CI tests:

docker run -d --rm --name pr-go-nats01 -p 4222:4222 nats
docker run -d --rm --name pr-go-nats02 -p 4223:4222 nats
docker logs pr-go-nats01
docker logs pr-go-nats02

Wait for Server is ready in both logs before testing.

Automated checks and observed results

Results below were obtained locally before this PR was opened on 2026-09-28. Expected results are separate from observations.

Command Expected result / behavior Status Observed result
GOTOOLCHAIN=go1.26.8 go test -mod=readonly -count=1 -timeout=8m -covermode=atomic ./... and GOTOOLCHAIN=go1.27.1 go test -mod=readonly -count=1 -timeout=8m -covermode=atomic ./... Both compiler versions run the suite successfully Passed Both versions exited 0; macOS
GOTOOLCHAIN=go1.26.8 golangci-lint run --timeout=3m Configured lint rules pass Passed 0 issues with v2.14.0
trivy fs --ignore-unfixed --severity CRITICAL,HIGH,MEDIUM --exit-code 1 . Fail on fixable vulnerabilities at the CI threshold Passed Exit 0; 0 vulnerability and secret findings with v0.70.0
actionlint and git diff --check Valid workflow syntax and clean patch Passed No findings
Run GOTOOLCHAIN=go1.26.8 go build -mod=readonly ./... and repeat with go1.27.1 in each directory containing _example/**/go.mod Nested examples build without modifying dependencies Passed All example modules built on both versions
goreleaser check Release configuration is accepted Passed Validated with v2.18.2
GitHub-hosted CodeQL, Codecov uploads and tag release Remote integration succeeds Not run Requires the pushed PR / release event; local validation does not establish hosted success

Acceptance scenarios

  1. Inspect every go.mod: the directive must be go 1.26.8. Inspect the workflow matrix: it must contain quoted 1.26 and 1.27, with GOTOOLCHAIN: local. Passed: all module directives and matrix entries checked.
  2. Run the two-version tests and example builds above. Both must exit 0; an unsupported toolchain must not be silently substituted by CI. Passed: both versions tested; no production behavior was intentionally changed.
  3. Run the Trivy command above. It must retain exit code 1 on qualifying findings, without new ignore files or disabled checks. Passed: policy inspected and scan exited 0 after dependency remediation. Findings depend on the current DB; unfixed and lower-severity vulnerabilities follow the existing exclusion policy.

Cleanup

No persistent application data is created. Testcontainers removes its test containers. Remove only these verification services with docker stop pr-go-nats01 pr-go-nats02. Example builds may produce binaries; remove only the generated example or example_01 executables inside the example module directories.

Security, risk and rollback

  • No secrets or credentials are included; Trivy secret findings were 0.
  • No authentication, authorization or external input interface was changed.
  • Main risks: the raised Go minimum and dependency behavior changes. Revert this PR's commit to restore previous module and CI settings.
  • Review go.mod, workflow version selection, Trivy policy and dependency upgrades carefully; spot-check generated checksums and example directives.

- Require Go 1.26.8 and validate Go 1.26 and 1.27 in CI
- Align lint and CodeQL toolchains and enforce Trivy security checks
- Build example modules with both supported Go versions
- Upgrade vulnerable dependencies and synchronize module checksums
- Validate release configuration with GoReleaser v2

BREAKING CHANGE: Go 1.26.8 or newer is required. Upgrade the Go toolchain before building this module.
Copilot AI lite review requested due to automatic review settings September 28, 2026 13:51

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@appleboy
appleboy merged commit 8384bdd into main Sep 29, 2026
10 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants