Skip to content

Update the Go dependencies - #94

Merged
beetlebugorg merged 1 commit into
mainfrom
deps/go-modules
Aug 28, 2026
Merged

beetlebugorg merged 1 commit into
mainfrom
deps/go-modules

Conversation

@beetlebugorg

Copy link
Copy Markdown
Owner

What changes

alecthomas/kong        v1.10.0  -> v1.16.1
aws/aws-lambda-go      v1.48.0  -> v1.55.0
aws/aws-sdk-go-v2      v1.44.0  -> v1.45.0
aws/aws-sdk-go-v2/...            the config and s3 sets move with it
caarlos0/env           v10.0.0  -> v11.4.1   (major)
stretchr/testify       v1.7.2   -> v1.12.1

golang.org/x/exp/slices is replaced by the standard library slices, which has carried Contains since Go 1.21. x/exp drops from a direct requirement to an indirect one, where ANTLR still needs it.

None of these carried an open advisory at the pinned version. This is hygiene.

The go directive moves to 1.26

aws/aws-lambda-go@v1.55.0 declares go 1.26, so go mod tidy raised the module's directive from 1.25.0 to match. toolchain already named go1.27.0 and the builder image ships Go 1.27, so nothing in this repository is affected. It does raise the floor for anyone importing go-dims as a library.

caarlos0/env v11

This is a major version, and it parses every setting the service has, so it was checked beyond the test suite. Two binaries, one built with v10 and one with v11, were started with the same environment and their effective configuration compared:

DIMS_ALLOWED_HOSTS=images.example.com,.cdn.example.net
DIMS_EXCLUDED_OUTPUT_FORMATS=gif,svg
DIMS_ALLOWED_SOURCE_BACKENDS=http,s3,file
DIMS_MAX_SOURCE_BYTES=12345  DIMS_MAX_CONCURRENT=7  DIMS_VIPS_CONCURRENCY=3
DIMS_JPEG_INTERLACE=true  DIMS_WEBP_COMPRESSION=lossless
DIMS_CACHE_CONTROL_MAX=99  DIMS_MAX_REDIRECTS=5  DIMS_ALLOW_PRIVATE_NETWORKS=true

The two configurations are byte identical across all 1061 bytes, so the list splitting, the integer and boolean parsing, and every envDefault agree.

Verify

go build ./... and go build -tags "lambda.norpc lambda" ./... both succeed. go test -race -count=1 ./... passes on the builder image, golden images included. govulncheck reports no vulnerabilities.

- Move kong, the AWS SDK, aws-lambda-go, and testify forward.
- Move caarlos0/env to v11.
- Read slices from the standard library.
@beetlebugorg
beetlebugorg merged commit b81a45d into main Aug 28, 2026
3 checks passed
@beetlebugorg
beetlebugorg deleted the deps/go-modules branch August 28, 2026 00:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant