Repository navigation
chore(deps): bump tailscale.com from 1.102.5 to 1.104.0 in the go-modules group - #431
Conversation
--- updated-dependencies: - dependency-name: tailscale.com dependency-version: 1.104.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: go-modules ... Signed-off-by: dependabot[bot] <support@github.com>
|
Important Review skippedBot user detected. To trigger a single review, invoke the ⚙️ Run configuration
You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
PR Reviewer Guide 🔍Here are some key observations to aid the review process:
|
Review triage
Reviewer output dispositioned: github-actions, 2026-10-09T16:52:36Z; coderabbitai[bot], 2026-10-07T12:54:21Z. |
## Summary <!-- Brief description of what this PR does and why --> Upgrade the Go floor to 1.27.1 alongside Tailscale 1.104.0. Dependabot #431 cannot be tested with the existing Go 1.26 CI/linter pins, so this PR supersedes that non-editable bot branch. ## Changes - Take the exact `go.mod` / `go.sum` upgrade from #431, without weakening checksum verification. - Derive CI, release, mutation and hygiene toolchains from `go.mod`; pin golangci-lint v2.14.0, built with Go 1.27. - Add a fixture-backed workflow guard, update operator instructions, and document the checksum incident in lesson 037. - Track the migration and verification under `specs/DEPS-312-go-127-tailscale/`. ## Testing - [ ] `go test -race ./...` passes - [x] `go vet ./...` clean - [x] Tested manually (if applicable) - `go test -race ./...` — not run locally: Windows has no GCC (`CGO_ENABLED=0`); Linux CI will run this check. - `go test -count=1 ./...` — passed on Windows; `go build ./...` and `go vet ./...` — passed. - `golangci-lint run` (pinned v2.14.0) — passed, 0 issues. `go mod tidy` and `git diff --exit-code -- go.mod go.sum` — passed; `go mod verify` — passed. - `bash scripts/tests/test-go-toolchain.sh` — passed on four Go workflows, after its stale-pin and conflicting-pin fixtures failed as intended. - `shellcheck scripts/tests/test-go-toolchain.sh` and `actionlint -shellcheck=shellcheck` on the four edited workflows — passed. - `bash scripts/check-actions-pinned.sh`, `bash scripts/check-workflow-permissions.sh`, `bash scripts/check-lessons.sh` — passed. - `go build -o <output> ./cmd/ts-bridge/` — passed for all 6 GOOS/GOARCH combinations (Linux, Windows and macOS; amd64 and arm64). - `go run ./cmd/ts-bridge version` — passed; returned `ts-bridge dev (commit unknown)`. ## Type - [ ] `feat` — New feature - [ ] `fix` — Bug fix - [ ] `refactor` — Code restructuring (no behavior change) - [ ] `docs` — Documentation only - [ ] `test` — Test additions/changes - [x] `chore` — Maintenance ## Knowledge - Lesson: `docs/lessons/lesson-037-2026-10-09.md` (checksum mismatch; never alter `go.sum` to hide it). - ADR: none; the Go floor follows an upstream dependency requirement rather than a new architecture. - Runbook: none; operator minimum/version instructions are updated in `AGENTS.md`. Closes #435 <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Updates** * Updated the Go toolchain and Tailscale version, along with related supporting packages. * Updated the linting tool to a newer version. * **Reliability** * Continuous integration and release workflows now use the Go version declared by the project, with an added consistency check. * **Documentation** * Updated Go and linting guidance and added a lesson on verifying module checksum mismatches. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions