Update the Go dependencies - #94
Merged
Merged
Conversation
- Move kong, the AWS SDK, aws-lambda-go, and testify forward. - Move caarlos0/env to v11. - Read slices from the standard library.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What changes
golang.org/x/exp/slicesis replaced by the standard libraryslices, which has carriedContainssince Go 1.21.x/expdrops from a direct requirement to an indirect one, where ANTLR still needs it.None of these carried an open advisory at the pinned version. This is hygiene.
The go directive moves to 1.26
aws/aws-lambda-go@v1.55.0declaresgo 1.26, sogo mod tidyraised the module's directive from1.25.0to match.toolchainalready namedgo1.27.0and the builder image ships Go 1.27, so nothing in this repository is affected. It does raise the floor for anyone importing go-dims as a library.caarlos0/env v11
This is a major version, and it parses every setting the service has, so it was checked beyond the test suite. Two binaries, one built with v10 and one with v11, were started with the same environment and their effective configuration compared:
The two configurations are byte identical across all 1061 bytes, so the list splitting, the integer and boolean parsing, and every
envDefaultagree.Verify
go build ./...andgo build -tags "lambda.norpc lambda" ./...both succeed.go test -race -count=1 ./...passes on the builder image, golden images included.govulncheckreports no vulnerabilities.