Problem
Dependabot PR #431 upgrades tailscale.com to v1.104.0, which requires Go 1.27.1. All Go CI jobs are pinned to 1.26, and golangci-lint v2.12.2 was built with Go 1.26. Tests, security, smoke, Windows build and lint fail before they can validate the dependency. Rewriting go.mod back to 1.26 would violate Tailscale's own minimum.
Approach
Upgrade the project Go floor, all CI/release/mutation/hygiene toolchains, the pinned linter, and operator-facing documentation alongside tailscale.com v1.104.0. Retain GOTOOLCHAIN=local so CI fails closed on drift. Verify Linux/Windows build, tests, lint, smoke and cross-compilation. Supersede #431 rather than editing Dependabot's non-editable branch.
Done when
- The module and documentation declare Go >= 1.27.1, with tailscale.com v1.104.0.
- Every workflow that runs Go and the pinned lint binary support the module's Go requirement.
- A regression guard detects an incompatible future module/workflow/linter combination.
- Tests, vet/lint and cross-platform builds pass; CI on the resulting PR is green.
Problem
Dependabot PR #431 upgrades tailscale.com to v1.104.0, which requires Go 1.27.1. All Go CI jobs are pinned to 1.26, and golangci-lint v2.12.2 was built with Go 1.26. Tests, security, smoke, Windows build and lint fail before they can validate the dependency. Rewriting go.mod back to 1.26 would violate Tailscale's own minimum.
Approach
Upgrade the project Go floor, all CI/release/mutation/hygiene toolchains, the pinned linter, and operator-facing documentation alongside tailscale.com v1.104.0. Retain GOTOOLCHAIN=local so CI fails closed on drift. Verify Linux/Windows build, tests, lint, smoke and cross-compilation. Supersede #431 rather than editing Dependabot's non-editable branch.
Done when