Repository navigation
Update dependencies and adopt four new major versions - #832
Merged
Merged
Conversation
Every module moves to its newest release within its current major version. The AWS SDK, gRPC, ginkgo, gomega and the Google API packages carry the bulk of the change. Supersedes the go-minor-patch Dependabot group in #831, which cannot merge: its required concourse-ci/status check comes from the retired Concourse pipeline and will never report.
Every symbol the plugin uses is unchanged in v2: KV, KVPair, Client, DefaultConfig, HttpBasicAuth, NewClient and HTTPSSLVerifyEnvName all keep their signatures, so this is the import path and nothing else.
v2 takes a context on every call that reaches the network, so Connect, Authenticate, ObjectPutBytes, ObjectGetBytes and ObjectDelete all gain one. The plugin interface hands us no context, so Store, Retrieve and Purge each start from context.Background(), which leaves the current behaviour of waiting indefinitely unchanged.
The fields we set, Issuer and ClaimsToValidate, and the Jwt.Claims map we read back are all unchanged. The one difference is that New() now returns an error alongside the verifier, so verifyToken reports a verifier it could not build rather than carrying on with a nil one. This also takes the lestrrat-go/jwx dependency from v1, which upstream no longer maintains, to v2.
v92 replaced the NewClient(nil).WithAuthToken(token) pair with a single variadic constructor that returns an error, so the token becomes a WithAuthToken option and a configured enterprise API address becomes a WithURLs option. WithURLs does the url.Parse the old code did by hand, which is why net/url is no longer imported. It also appends the trailing slash that go-github has always needed on a base URL, so an enterprise address configured without one now reaches the right endpoint instead of silently losing its last path segment.
Six direct dependencies have not been pushed in over two years. Each one is already on the newest version published, so there is nothing to upgrade to, and the file says why we are leaving each one alone so the next pass does not re-open the question.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Brings the module graph fully current. Go itself is already on 1.27.1, the newest release, so nothing changes there.
What is here
The first commit moves every module to its newest release within its current major version. The next four each cross a major version boundary, and the last one records the stale dependencies we looked at and decided to keep.
hashicorp/consul/apincw/swiftokta/okta-jwt-verifier-golangNew()now returns an error.google/go-githubNewClientbecame a variadic constructor returning an error.The Okta bump also moves
lestrrat-go/jwxoff v1, which upstream no longer maintains.The go-github change fixes a latent bug along the way.
WithURLsappends the trailing slash that go-github has always required on a base URL, so a GitHub Enterprise address configured without one now reaches the right endpoint instead of silently losing its last path segment.Stale dependencies
Six direct dependencies have not been pushed in over two years, and every one of them is already on the newest version published, so there is nothing to upgrade to.
.modrotignorerecords why we are leaving each one alone, with a date, so the next pass does not re-open the question.pborman/uuidis the one worth a second look later.google/uuidis its maintained successor and is already in the tree indirectly, but itsParsereturns(UUID, error)where pborman's returns a nilUUID, so swapping it across the 14 files that import it changes error handling rather than just an import path. That is its own change, not this one.Verification
Run locally against the final commit:
gofmt,go vet -mod=vendor ./...,go mod verify, andgo build -mod=vendor ./...all cleanmake go-testspasses with the race detector and reports no data racesgovulncheck ./...finds no reachable vulnerabilitiestrivy fsreports no HIGH or CRITICAL findingsstaticcheck ./...reports the same 141 findings asdevelop, with none added. The set is identical line for line, so the update introduced no deprecated API use.make plugin-testsfails the same 8 of 134 specs it fails ondevelop, which are the help-text assertions the CI job already documents and runs withcontinue-on-error.Supersedes #831
Dependabot's go-minor-patch group in #831 cannot merge: its required
concourse-ci/statuscheck comes from the retired Concourse pipeline and will never report. The first commit here covers that group and more.