Skip to content

Update dependencies and adopt four new major versions - #832

Merged
wayneeseguin merged 6 commits into
developfrom
update-deps-majors
Oct 1, 2026
Merged

wayneeseguin merged 6 commits into
developfrom
update-deps-majors

Conversation

@wayneeseguin

Copy link
Copy Markdown
Contributor

Brings the module graph fully current. Go itself is already on 1.27.1, the newest release, so nothing changes there.

What is here

The first commit moves every module to its newest release within its current major version. The next four each cross a major version boundary, and the last one records the stale dependencies we looked at and decided to keep.

Module From To What the migration needed
hashicorp/consul/api v1.34.4 v2.0.0 The import path. Every symbol the plugin uses kept its signature.
ncw/swift v1.0.53 v2.0.5 A context on each call that reaches the network.
okta/okta-jwt-verifier-golang v1.3.1 v2.1.1 New() now returns an error.
google/go-github v76.0.0 v92.0.0 NewClient became a variadic constructor returning an error.

The Okta bump also moves lestrrat-go/jwx off v1, which upstream no longer maintains.

The go-github change fixes a latent bug along the way. WithURLs appends the trailing slash that go-github has always required on a base URL, so a GitHub Enterprise address configured without one now reaches the right endpoint instead of silently losing its last path segment.

Stale dependencies

Six direct dependencies have not been pushed in over two years, and every one of them is already on the newest version published, so there is nothing to upgrade to. .modrotignore records why we are leaving each one alone, with a date, so the next pass does not re-open the question.

pborman/uuid is the one worth a second look later. google/uuid is its maintained successor and is already in the tree indirectly, but its Parse returns (UUID, error) where pborman's returns a nil UUID, so swapping it across the 14 files that import it changes error handling rather than just an import path. That is its own change, not this one.

Verification

Run locally against the final commit:

  • gofmt, go vet -mod=vendor ./..., go mod verify, and go build -mod=vendor ./... all clean

  • make go-tests passes with the race detector and reports no data races

  • govulncheck ./... finds no reachable vulnerabilities

  • trivy fs reports no HIGH or CRITICAL findings

  • staticcheck ./... reports the same 141 findings as develop, with none added. The set is identical line for line, so the update introduced no deprecated API use.

  • make plugin-tests fails the same 8 of 134 specs it fails on develop, which are the help-text assertions the CI job already documents and runs with continue-on-error.

Supersedes #831

Dependabot's go-minor-patch group in #831 cannot merge: its required concourse-ci/status check comes from the retired Concourse pipeline and will never report. The first commit here covers that group and more.

Every module moves to its newest release within its current major
version. The AWS SDK, gRPC, ginkgo, gomega and the Google API
packages carry the bulk of the change.

Supersedes the go-minor-patch Dependabot group in #831, which
cannot merge: its required concourse-ci/status check comes from
the retired Concourse pipeline and will never report.
Every symbol the plugin uses is unchanged in v2: KV, KVPair,
Client, DefaultConfig, HttpBasicAuth, NewClient and
HTTPSSLVerifyEnvName all keep their signatures, so this is the
import path and nothing else.
v2 takes a context on every call that reaches the network, so
Connect, Authenticate, ObjectPutBytes, ObjectGetBytes and
ObjectDelete all gain one. The plugin interface hands us no
context, so Store, Retrieve and Purge each start from
context.Background(), which leaves the current behaviour of
waiting indefinitely unchanged.
The fields we set, Issuer and ClaimsToValidate, and the Jwt.Claims
map we read back are all unchanged. The one difference is that
New() now returns an error alongside the verifier, so verifyToken
reports a verifier it could not build rather than carrying on with
a nil one.

This also takes the lestrrat-go/jwx dependency from v1, which
upstream no longer maintains, to v2.
v92 replaced the NewClient(nil).WithAuthToken(token) pair with a
single variadic constructor that returns an error, so the token
becomes a WithAuthToken option and a configured enterprise API
address becomes a WithURLs option.

WithURLs does the url.Parse the old code did by hand, which is why
net/url is no longer imported. It also appends the trailing slash
that go-github has always needed on a base URL, so an enterprise
address configured without one now reaches the right endpoint
instead of silently losing its last path segment.
Six direct dependencies have not been pushed in over two years.
Each one is already on the newest version published, so there is
nothing to upgrade to, and the file says why we are leaving each
one alone so the next pass does not re-open the question.
@wayneeseguin
wayneeseguin merged commit 0ae5497 into develop Oct 1, 2026
5 of 6 checks passed
@wayneeseguin
wayneeseguin deleted the update-deps-majors branch October 1, 2026 00:55
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

1 participant