Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion .github/workflows/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -52,7 +52,7 @@ Runs comprehensive quality checks on every pull request and push to main branch.

### Required Variables

- `GO_VERSION` (default: 1.25)
- `GO_VERSION` (default: 1.26.6)

### Example

Expand Down
5 changes: 4 additions & 1 deletion .github/workflows/pre-commit.yml
Original file line number Diff line number Diff line change
Expand Up @@ -32,7 +32,10 @@ jobs:
- name: Set up Go
uses: actions/setup-go@4a3601121dd01d1626a1e23e37211e3254c1c06c # v6.4.0
with:
go-version: "1.26.6"
# Read from go.mod rather than a hardcoded string, matching
# aws_sanity / azure_sanity / database-migration. One fewer place the
# Go version has to be bumped by hand (issue #1833).
go-version-file: go.mod

- name: Set up Node.js
uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6.4.0
Expand Down
6 changes: 4 additions & 2 deletions CONTRIBUTING.md
Original file line number Diff line number Diff line change
Expand Up @@ -48,7 +48,7 @@ By participating in this project, you agree to maintain a respectful and inclusi

### Prerequisites

- Go 1.23 or later
- Go 1.26.6 or later (the floor set by the `go` directive in `go.mod`)
- AWS/Azure/GCP credentials for integration testing
- Git

Expand Down Expand Up @@ -88,7 +88,9 @@ from a copy of the committed `go.work` and append your active worktrees:

```go
// go.work.local -- gitignored, developer-local
go 1.25.0
// Keep this `go` line at or above the modules' own directive, otherwise the
// workspace is rejected. Copy it from the committed go.work.
go 1.26.6

use (
.
Expand Down
36 changes: 19 additions & 17 deletions Dockerfile
Original file line number Diff line number Diff line change
Expand Up @@ -12,10 +12,10 @@ ARG TARGETOS=linux
# Build stage
# Image pinned to a SHA256 digest for reproducible builds — a registry
# tag mutation (Docker Hub allows re-tagging) cannot poison this build.
# To refresh: `docker buildx imagetools inspect golang:1.26.5-alpine3.24`
# To refresh: `docker buildx imagetools inspect golang:1.26.6-alpine3.24`
# (or use the Docker Hub API tags endpoint) and update the digest below.
# A Renovate / Dependabot config can automate this if desired.
FROM --platform=$BUILDPLATFORM golang:1.26.5-alpine3.24@sha256:0178a641fbb4858c5f1b48e34bdaabe0350a330a1b1149aabd498d0699ff5fb2 AS builder
FROM --platform=$BUILDPLATFORM golang:1.26.6-alpine3.24@sha256:3889b425f035be855a72fb4755265311293b6d414521f0a519d819df32222d83 AS builder

# Re-declare args for use in this stage
ARG TARGETARCH
Expand All @@ -33,25 +33,27 @@ ARG BUILD_DATE
RUN apk add --no-cache \
git \
ca-certificates \
postgresql-client \
curl
postgresql-client

# Set shell with pipefail for safer pipe operations
SHELL ["/bin/ash", "-eo", "pipefail", "-c"]

# Install golang-migrate for database migrations (architecture-aware, checksum-verified)
RUN MIGRATE_ARCH=$([ "$TARGETARCH" = "arm64" ] && echo "arm64" || echo "amd64") && \
if [ "$MIGRATE_ARCH" = "arm64" ]; then \
MIGRATE_SHA256="2fea2455c0f3f07cc3f4b98471c951ad1a716059574b20b6416bd1e9058751c5"; \
else \
MIGRATE_SHA256="2ac648fbd1b127b69ab5a7b33cf96212178f71e22379fc50573630c6f4c7ce18"; \
fi && \
curl -Lo migrate.tar.gz "https://github.com/golang-migrate/migrate/releases/download/v4.19.1/migrate.linux-${MIGRATE_ARCH}.tar.gz" && \
echo "${MIGRATE_SHA256} migrate.tar.gz" | sha256sum -c - && \
tar xzf migrate.tar.gz && \
mv migrate /usr/local/bin/migrate && \
chmod +x /usr/local/bin/migrate && \
rm migrate.tar.gz
# Build golang-migrate from source on this stage's pinned Go toolchain, the same
# way `make install-tools` does. Upstream's prebuilt release tarballs carry
# whatever toolchain upstream built them with (v4.19.1 ships go1.25.4), which is
# how issue #1833's stdlib CVEs reached the runtime image, where entrypoint.sh
# runs `migrate up` against the database on every container start.
# `go install` refuses GOBIN when cross-compiling and writes to
# bin/${GOOS}_${GOARCH}/ instead, so resolve both layouts; the final `mv` fails
# the build if neither produced a binary.
# Keep this version in step with MIGRATE_VERSION in the Makefile.
RUN CGO_ENABLED=0 GOOS=${TARGETOS} GOARCH=${TARGETARCH} \
go install -tags=postgres -ldflags="-s -w -X main.Version=v4.19.1" \
github.com/golang-migrate/migrate/v4/cmd/migrate@v4.19.1 && \
GOPATH_BIN="$(go env GOPATH)/bin" && \
MIGRATE_BIN="${GOPATH_BIN}/${TARGETOS}_${TARGETARCH}/migrate" && \
{ [ -x "${MIGRATE_BIN}" ] || MIGRATE_BIN="${GOPATH_BIN}/migrate"; } && \
mv "${MIGRATE_BIN}" /usr/local/bin/migrate

WORKDIR /app

Expand Down
4 changes: 2 additions & 2 deletions Dockerfile.dev
Original file line number Diff line number Diff line change
@@ -1,11 +1,11 @@
# Development Dockerfile with hot reload using Air
# Image pinned to a SHA256 digest for reproducible builds; a registry
# tag mutation (Docker Hub allows re-tagging) cannot poison this build.
# To refresh: `docker buildx imagetools inspect golang:1.26.5-alpine3.24`
# To refresh: `docker buildx imagetools inspect golang:1.26.6-alpine3.24`
# (or use the Docker Hub API tags endpoint) and update the digest below.
# A Renovate / Dependabot config can automate this if desired.
# Keep this digest in sync with the builder stage in Dockerfile.
FROM golang:1.26.5-alpine3.24@sha256:0178a641fbb4858c5f1b48e34bdaabe0350a330a1b1149aabd498d0699ff5fb2 AS development
FROM golang:1.26.6-alpine3.24@sha256:3889b425f035be855a72fb4755265311293b6d414521f0a519d819df32222d83 AS development

# Install development tools and Air for hot reload
RUN apk add --no-cache \
Expand Down
2 changes: 1 addition & 1 deletion Dockerfile.test
Original file line number Diff line number Diff line change
Expand Up @@ -5,7 +5,7 @@
#
# Base image pinned by digest for the same supply-chain reasons as Dockerfile;
# keep the digest in sync with the builder stage there.
FROM golang:1.26.5-alpine3.24@sha256:0178a641fbb4858c5f1b48e34bdaabe0350a330a1b1149aabd498d0699ff5fb2
FROM golang:1.26.6-alpine3.24@sha256:3889b425f035be855a72fb4755265311293b6d414521f0a519d819df32222d83

# Run the suite as a non-root user (trivy DS-0002). tests/e2e is a stdlib-only
# module so no module downloads are needed; GOCACHE lives in the user's home,
Expand Down
4 changes: 2 additions & 2 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -598,7 +598,7 @@ runtimes.

- Terraform >= 1.6.0
- Docker with buildx
- Go 1.25+
- Go 1.26.6+
- Cloud CLI authenticated: `aws`, `gcloud`, or `az`

#### Quick deploy (using the helper script)
Expand Down Expand Up @@ -682,7 +682,7 @@ reload, and debugging workflows.

### Prerequisites

- Go 1.23 or later
- Go 1.26.6 or later
- AWS/Azure/GCP credentials for integration testing

### Building
Expand Down
2 changes: 1 addition & 1 deletion docs/DEPLOYMENT.md
Original file line number Diff line number Diff line change
Expand Up @@ -56,7 +56,7 @@ Terraform automatically handles: Docker image build/push (via build module), fro

- Docker with buildx support
- Terraform >= 1.6.0
- Go 1.25+
- Go 1.26.6+
- Cloud CLI configured: `aws`, `az`, or `gcloud`

---
Expand Down
2 changes: 1 addition & 1 deletion docs/DEVELOPMENT.md
Original file line number Diff line number Diff line change
Expand Up @@ -3,7 +3,7 @@
## Prerequisites

- Docker and Docker Compose
- Go 1.25+
- Go 1.26.6+
- Node.js and npm (for frontend development)
- Make (optional, for convenience commands)

Expand Down
2 changes: 1 addition & 1 deletion go.mod
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
module github.com/LeanerCloud/CUDly

go 1.26.5
go 1.26.6

require (
github.com/aws/aws-sdk-go-v2 v1.41.5
Expand Down
2 changes: 1 addition & 1 deletion go.work
Original file line number Diff line number Diff line change
@@ -1,4 +1,4 @@
go 1.26.5
go 1.26.6

use (
.
Expand Down
2 changes: 1 addition & 1 deletion pkg/go.mod
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
module github.com/LeanerCloud/CUDly/pkg

go 1.26.5
go 1.26.6

// This module contains shared types, provider interfaces, and the exchange package.
// The exchange package has AWS SDK dependencies for RI exchange operations.
Expand Down
2 changes: 1 addition & 1 deletion providers/aws/go.mod
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
module github.com/LeanerCloud/CUDly/providers/aws

go 1.26.5
go 1.26.6

require (
github.com/LeanerCloud/CUDly/pkg v0.0.0
Expand Down
2 changes: 1 addition & 1 deletion providers/azure/go.mod
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
module github.com/LeanerCloud/CUDly/providers/azure

go 1.26.5
go 1.26.6

require (
github.com/Azure/azure-sdk-for-go/sdk/azcore v1.21.1
Expand Down
2 changes: 1 addition & 1 deletion providers/gcp/go.mod
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
module github.com/LeanerCloud/CUDly/providers/gcp

go 1.26.5
go 1.26.6

require (
cloud.google.com/go/compute v1.54.0
Expand Down
Loading