Skip to content

chore(deps): bump tailscale.com from 1.102.5 to 1.104.0 in the go-modules group - #431

Merged
mlorentedev merged 3 commits into
masterfrom
dependabot/go_modules/go-modules-2df9ca97c8
Oct 9, 2026
Merged

mlorentedev merged 3 commits into
masterfrom
dependabot/go_modules/go-modules-2df9ca97c8

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 7, 2026

Copy link
Copy Markdown
Contributor

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

---
updated-dependencies:
- dependency-name: tailscale.com
  dependency-version: 1.104.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-modules
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file go Pull requests that update go code labels Oct 7, 2026
@coderabbitai

coderabbitai Bot commented Oct 7, 2026 •

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration
  • Configuration used: defaults
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: c091ebe5-ca2a-47bb-8562-74de89c8e36b

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autofix · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions

github-actions Bot commented Oct 9, 2026

Copy link
Copy Markdown
Contributor

PR Reviewer Guide 🔍

Here are some key observations to aid the review process:

⏱️ Estimated effort to review: 1 🔵⚪⚪⚪⚪
🧪 No relevant tests
🔒 No security concerns identified
⚡ Recommended focus areas for review

Toolchain Bump (REAL)

REAL: This bump silently raises the module's minimum Go version from go 1.26.6 to go 1.27.1. Any environment with a pinned Go 1.26.x toolchain and GOTOOLCHAIN=local (common in offline/hermetic CI images and release builders) will now fail with "go.mod requires go >= 1.27.1". This also contradicts the repo's own documentation: AGENTS.md states "Language: Go 1.26+", which is no longer true after this PR. Either revert the go directive to a 1.26 patch version (if tailscale.com v1.104.0 permits it), or consciously update AGENTS.md and verify every CI job's setup-go version matches 1.27.1 before merge. Note: I can only see the diff, so I could not confirm whether CI pins Go 1.26 — that check remains for the author.

go 1.27.1

@mlorentedev

Copy link
Copy Markdown
Owner

Review triage

Item Disposition Reason
PR-Agent, go.mod:3 (Go 1.27.1 toolchain bump) defer to #435 / #436 Valid: Tailscale v1.104.0 requires Go 1.27.1, and every Go 1.26 CI job fails before tests run. The bot-owned branch does not allow maintainer edits. #436 carries the exact dependency graph plus coordinated workflow, linter, documentation and regression-guard updates. Do not merge this red Dependabot PR.
CodeRabbit status notice skip Review skipped because the author is a bot; this is not a review or a no-findings verdict.
Failing CI jobs defer to #436 Linux/Windows tests, smoke, lint and security cannot start on Go 1.26; the replacement PR validates with the required Go version.

Reviewer output dispositioned: github-actions, 2026-10-09T16:52:36Z; coderabbitai[bot], 2026-10-07T12:54:21Z.

mlorentedev added a commit that referenced this pull request Oct 9, 2026
## Summary

<!-- Brief description of what this PR does and why -->
Upgrade the Go floor to 1.27.1 alongside Tailscale 1.104.0. Dependabot
#431 cannot be tested with the existing Go 1.26 CI/linter pins, so this
PR supersedes that non-editable bot branch.

## Changes

- Take the exact `go.mod` / `go.sum` upgrade from #431, without
weakening checksum verification.
- Derive CI, release, mutation and hygiene toolchains from `go.mod`; pin
golangci-lint v2.14.0, built with Go 1.27.
- Add a fixture-backed workflow guard, update operator instructions, and
document the checksum incident in lesson 037.
- Track the migration and verification under
`specs/DEPS-312-go-127-tailscale/`.

## Testing

- [ ] `go test -race ./...` passes
- [x] `go vet ./...` clean
- [x] Tested manually (if applicable)

- `go test -race ./...` — not run locally: Windows has no GCC
(`CGO_ENABLED=0`); Linux CI will run this check.
- `go test -count=1 ./...` — passed on Windows; `go build ./...` and `go
vet ./...` — passed.
- `golangci-lint run` (pinned v2.14.0) — passed, 0 issues. `go mod tidy`
and `git diff --exit-code -- go.mod go.sum` — passed; `go mod verify` —
passed.
- `bash scripts/tests/test-go-toolchain.sh` — passed on four Go
workflows, after its stale-pin and conflicting-pin fixtures failed as
intended.
- `shellcheck scripts/tests/test-go-toolchain.sh` and `actionlint
-shellcheck=shellcheck` on the four edited workflows — passed.
- `bash scripts/check-actions-pinned.sh`, `bash
scripts/check-workflow-permissions.sh`, `bash scripts/check-lessons.sh`
— passed.
- `go build -o <output> ./cmd/ts-bridge/` — passed for all 6 GOOS/GOARCH
combinations (Linux, Windows and macOS; amd64 and arm64).
- `go run ./cmd/ts-bridge version` — passed; returned `ts-bridge dev
(commit unknown)`.

## Type

- [ ] `feat` — New feature
- [ ] `fix` — Bug fix
- [ ] `refactor` — Code restructuring (no behavior change)
- [ ] `docs` — Documentation only
- [ ] `test` — Test additions/changes
- [x] `chore` — Maintenance

## Knowledge

- Lesson: `docs/lessons/lesson-037-2026-10-09.md` (checksum mismatch;
never alter `go.sum` to hide it).
- ADR: none; the Go floor follows an upstream dependency requirement
rather than a new architecture.
- Runbook: none; operator minimum/version instructions are updated in
`AGENTS.md`.

Closes #435

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Updates**
* Updated the Go toolchain and Tailscale version, along with related
supporting packages.
  * Updated the linting tool to a newer version.
* **Reliability**
* Continuous integration and release workflows now use the Go version
declared by the project, with an added consistency check.
* **Documentation**
* Updated Go and linting guidance and added a lesson on verifying module
checksum mismatches.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@mlorentedev
mlorentedev merged commit e682f4b into master Oct 9, 2026
14 of 15 checks passed
@mlorentedev
mlorentedev deleted the dependabot/go_modules/go-modules-2df9ca97c8 branch October 9, 2026 19:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file go Pull requests that update go code Review effort 1/5

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant