diff --git a/go/CHANGELOG.md b/go/CHANGELOG.md index f3436272..d7d545c3 100644 --- a/go/CHANGELOG.md +++ b/go/CHANGELOG.md @@ -6,6 +6,13 @@ The four bindings in this repository are released together and give one answer, ## [Unreleased] +## [1.0.1] — 2026-10-04 + +### Fixed + +- `go mod tidy` failed in every module that depends on this one (#454). Five retained 0.x files were excluded from the build by a custom build tag, but `go mod tidy` considers every build tag except `ignore`, so it resolved their imports, including a package 1.0.0 no longer ships, and left the consumer's `go.sum` incomplete. They now carry `//go:build ignore`, so a consumer's `go mod tidy` (and `go mod tidy -diff`) succeeds with no `-e`. Nothing in the built package changes. +- The release verification now runs a consumer's `go mod tidy` with no `-e`, in every dry run and after every publish, so this cannot ship again. + ## [1.0.0] — 2026-10-04 The Go binding's first v1 release, and a deliberate break from 0.x. The default branch switches to v1 shortly after release. The sections below are the entries written as each part landed; this is what they add up to. diff --git a/go/chtypes/fetch.go b/go/chtypes/fetch.go index ef941b1c..ec9ea3f7 100644 --- a/go/chtypes/fetch.go +++ b/go/chtypes/fetch.go @@ -1,4 +1,4 @@ -//go:build chtypes_v0_retired +//go:build ignore package chtypes diff --git a/go/chtypes/fetch_sign.go b/go/chtypes/fetch_sign.go index f58e53fc..3ba97563 100644 --- a/go/chtypes/fetch_sign.go +++ b/go/chtypes/fetch_sign.go @@ -1,4 +1,4 @@ -//go:build chtypes_v0_retired +//go:build ignore package chtypes diff --git a/go/chtypes/multiversion.go b/go/chtypes/multiversion.go index cd1fa3ef..d6095356 100644 --- a/go/chtypes/multiversion.go +++ b/go/chtypes/multiversion.go @@ -1,4 +1,4 @@ -//go:build chtypes_v0_retired +//go:build ignore package chtypes diff --git a/go/chtypes/registry_path.go b/go/chtypes/registry_path.go index fa1f50b2..93b11408 100644 --- a/go/chtypes/registry_path.go +++ b/go/chtypes/registry_path.go @@ -1,4 +1,4 @@ -//go:build chtypes_v0_retired +//go:build ignore package chtypes diff --git a/go/chtypes/resolve.go b/go/chtypes/resolve.go index fdb9b0a2..3c88a102 100644 --- a/go/chtypes/resolve.go +++ b/go/chtypes/resolve.go @@ -1,4 +1,4 @@ -//go:build chtypes_v0_retired +//go:build ignore package chtypes diff --git a/go/internal/ocifetch/useragent.go b/go/internal/ocifetch/useragent.go index de34c578..72d067fd 100644 --- a/go/internal/ocifetch/useragent.go +++ b/go/internal/ocifetch/useragent.go @@ -6,7 +6,7 @@ import "regexp" // from (the release tag is the version), so a release bumps this constant // with the other three bindings' manifests (RELEASING.md, step 1). It is // never empty: an unknown version would be spelled userAgentDevVersion. -const bindingVersion = "1.0.0" +const bindingVersion = "1.0.1" // userAgentDevVersion stands in when no version is available. The header is // never omitted (docs/guides/fetch-v1.md §2). diff --git a/scripts/release-verify.sh b/scripts/release-verify.sh index 266a699d..3a8fd216 100755 --- a/scripts/release-verify.sh +++ b/scripts/release-verify.sh @@ -241,8 +241,10 @@ func main() { fmt.Println(lib.BuildInfo().ABIFingerprint) } GO - # -e: tidy considers every build tag, including the retired v0 files (tagged out of the real build) whose imports no longer exist. - go mod tidy -e >/dev/null 2>&1 || true + # A consumer's own `go mod tidy`, with no -e and no masking: it fails loudly + # if the module ships any file, under any build tag except `ignore`, that + # imports a package the module does not contain (go/v1.0.0 did: #454). + go mod tidy loaded_ok "$(go run . "$line")" ;; esac