build(go)!: require Go 1.26.8 and test Go 1.27 - #62
Merged
Merged
Conversation
- Require Go 1.26.8 and validate Go 1.26 and 1.27 in CI - Align lint and CodeQL toolchains and enforce Trivy security checks - Build example modules with both supported Go versions - Upgrade vulnerable dependencies and synchronize module checksums - Validate release configuration with GoReleaser v2 BREAKING CHANGE: Go 1.26.8 or newer is required. Upgrade the Go toolchain before building this module.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Raise the minimum Go version to 1.26.8 and test both Go 1.26 and 1.27.
GOTOOLCHAIN=localensures each CI job actually uses the selected compiler. Checkout now precedes setup-go, and cache keys distinguish Go versions.Compatibility and scope
Breaking toolchain requirement: consumers using Go 1.25 or an older 1.26 patch must upgrade to Go 1.26.8 or newer. This PR implements the requested Go upgrade, CI compatibility checks and vulnerability remediation. No issue or Jira reference was supplied.
CI flow
AI authorship and classification
.github/workflows/codeql.yaml.github/workflows/go.yml.goreleaser.yaml_example/producer-consumer/go.mod_example/producer-consumer/go.sum_example/worker/go.mod_example/worker/go.sumgo.modgo.sumVerification
Setup
Check out
chore/go-1.26-upgradeingolang-queue/natsand run commands from the repository root unless stated otherwise:Prerequisites: Go 1.26.8 and 1.27.1, golangci-lint 2.14.0, Trivy 0.70.0, actionlint 1.7.12, GoReleaser 2.18.2. Docker must be running; tests create disposable containers.
Start the two NATS services used by the existing CI tests:
Wait for
Server is readyin both logs before testing.Automated checks and observed results
Results below were obtained locally before this PR was opened on 2026-09-28. Expected results are separate from observations.
GOTOOLCHAIN=go1.26.8 go test -mod=readonly -count=1 -timeout=8m -covermode=atomic ./...andGOTOOLCHAIN=go1.27.1 go test -mod=readonly -count=1 -timeout=8m -covermode=atomic ./...GOTOOLCHAIN=go1.26.8 golangci-lint run --timeout=3mtrivy fs --ignore-unfixed --severity CRITICAL,HIGH,MEDIUM --exit-code 1 .actionlintandgit diff --checkGOTOOLCHAIN=go1.26.8 go build -mod=readonly ./...and repeat withgo1.27.1in each directory containing_example/**/go.modgoreleaser checkAcceptance scenarios
go.mod: the directive must bego 1.26.8. Inspect the workflow matrix: it must contain quoted1.26and1.27, withGOTOOLCHAIN: local. Passed: all module directives and matrix entries checked.Cleanup
No persistent application data is created. Testcontainers removes its test containers. Remove only these verification services with
docker stop pr-go-nats01 pr-go-nats02. Example builds may produce binaries; remove only the generatedexampleorexample_01executables inside the example module directories.Security, risk and rollback
go.mod, workflow version selection, Trivy policy and dependency upgrades carefully; spot-check generated checksums and example directives.