Repository navigation
Commit 75448a0
authored
fix(ci): drop lib/pq by moving golang-migrate onto the pgx/v5 driver (#1850)
govulncheck fails repo-wide on five lib/pq advisories with no fix
Every module's source-mode govulncheck reported GO-2026-6166, 6168, 6170,
6171 and 6172 in github.com/lib/pq, reached through Driver.Open and
conn.Exec. All five are Fixed in: N/A, so no version bump clears them and
every branch went red on a dependency nothing here imports directly. The
issue was filed naming three; the database grew two more while it sat.
lib/pq arrived through exactly one edge: internal/database/postgres/
migrations imported golang-migrate's database/postgres driver, which is
lib/pq-backed. Moving that blank import to database/pgx/v5 removes the
module from the build closure, and pgx is already this repo's driver
everywhere else.
The driver swap is not import-only. database/pgx/v5 registers just the
pgx5 scheme, where database/postgres registered postgres and postgresql,
and golang-migrate selects its driver by URL scheme. Every migration URL
had to move to pgx5:// - scripts/entrypoint.sh, which runs migrate up on
every container start, the three per-cloud jobs in database-migration.yml,
and the copy-pasteable commands in the docs.
The standalone migrate CLI moved to -tags=pgx5 for the same reason. That
binary runs against production on every container start, so leaving lib/pq
in it would have cleaned the source-mode signal while the real exposure
stayed. The naive form of that change regressed the image gate: go install
pkg@v4.19.1 resolves dependencies from golang-migrate's own go.mod, which
pins pgx v5.5.4 and x/crypto v0.45.0, so the shipped CLI came back with 17
fixable advisories. Building it from this module instead makes its
dependency graph ours, and the binary is now clean of every advisory,
fixable or not, where main's carries the five unfixable lib/pq ones.
Verified: govulncheck clean across all six modules where it previously
exited 3; go list -deps drops from 3 lib/pq packages to 0 for both ./...
and -test ./...; migrations run up and down against a real PostgreSQL on
the new URL scheme; the rebuilt image scans clean under
scripts/scan-shipped-image.sh, with migrate reporting v4.19.1 and drivers
"stub, pgx5" from inside the container.
TestLibPqDriverNotRegistered guards both axes rather than one. Driver
registration alone would stay green if a change linked lib/pq without
registering a driver, so the build closure is asserted directly for the
root module and for the CLI as configured. A failed or empty go list is a
hard failure, not an absence, so the guard cannot pass for the wrong
reason. All three subtests execute in the default unit-test run.
go mod why still reports a path to lib/pq. It runs through the test binary
of testcontainers-go, a module-graph artifact rather than a linked
dependency, which is why go list -deps is the measurement that matters.
Deferred: #1851, migrate down -all cannot roll back past migration 55 and
leaves the database dirty, reproduced here and pre-existing on main, with
database-migration.yml exposing direction: down against all three clouds.
#1838, Dockerfile.dev still downloads a prebuilt v4.17.0 migrate that
links lib/pq; dev-only and not the shipped runtime image.
Not verified: the deployed migration path against RDS, Cloud SQL or Azure
Database, which needs real cloud credentials.1 parent 3ea91fb commit 75448a0
4 files changed
Lines changed: 15 additions & 6 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
236 | 236 | | |
237 | 237 | | |
238 | 238 | | |
239 | | - | |
| 239 | + | |
| 240 | + | |
| 241 | + | |
| 242 | + | |
| 243 | + | |
| 244 | + | |
240 | 245 | | |
241 | 246 | | |
242 | 247 | | |
| |||
248 | 253 | | |
249 | 254 | | |
250 | 255 | | |
251 | | - | |
| 256 | + | |
252 | 257 | | |
253 | 258 | | |
254 | 259 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
15 | 15 | | |
16 | 16 | | |
17 | 17 | | |
18 | | - | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
19 | 21 | | |
20 | 22 | | |
21 | 23 | | |
| |||
246 | 248 | | |
247 | 249 | | |
248 | 250 | | |
249 | | - | |
250 | | - | |
| 251 | + | |
| 252 | + | |
251 | 253 | | |
252 | 254 | | |
253 | 255 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
149 | 149 | | |
150 | 150 | | |
151 | 151 | | |
| 152 | + | |
152 | 153 | | |
153 | 154 | | |
154 | 155 | | |
155 | 156 | | |
156 | | - | |
157 | 157 | | |
158 | 158 | | |
159 | 159 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
236 | 236 | | |
237 | 237 | | |
238 | 238 | | |
| 239 | + | |
| 240 | + | |
239 | 241 | | |
240 | 242 | | |
241 | 243 | | |
| |||
0 commit comments