Skip to content

chore(deps): update go indirect dependencies - #253

Closed
red-hat-konflux[bot] wants to merge 1 commit into
mainfrom
konflux/mintmaker/main/go-indirect-dependencies
Closed

red-hat-konflux[bot] wants to merge 1 commit into
mainfrom
konflux/mintmaker/main/go-indirect-dependencies

Conversation

@red-hat-konflux

@red-hat-konflux red-hat-konflux Bot commented Sep 7, 2026 •

Copy link
Copy Markdown
Contributor

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Change Age Confidence Type Update Pending
al.essio.dev/pkg/shellescape v1.6.0 → v1.6.1 age confidence indirect patch
charm.land/lipgloss/v2 v2.0.5 → v2.0.6 age confidence indirect patch
github.com/Masterminds/squirrel v1.1.0 → v1.5.4 age confidence indirect minor
github.com/bxcodec/faker/v3 v3.2.0 → v3.8.1 age confidence indirect minor
github.com/cenkalti/backoff/v4 v4.2.1 → v4.3.0 age confidence indirect minor
github.com/charmbracelet/x/ansi v0.11.7 → v0.11.8 age confidence indirect patch
github.com/containerd/log v0.1.0 → v0.2.0 age confidence indirect minor
github.com/docker/distribution v2.8.1+incompatible → v2.8.3+incompatible age confidence indirect patch
github.com/docker/go-connections v0.6.0 → v0.8.1 age confidence indirect minor
github.com/evilmartians/lefthook/v2 v2.1.10 → v2.1.12 age confidence indirect patch v2.1.14 (+1)
github.com/fatih/color v1.18.0 → v1.19.0 age confidence indirect minor
github.com/felixge/httpsnoop v1.0.4 → v1.1.0 age confidence indirect minor
github.com/fxamacker/cbor/v2 v2.9.2 → v2.9.3 age confidence indirect patch v2.9.4
github.com/getkin/kin-openapi v0.135.0 → v0.149.0 age confidence indirect minor
github.com/go-json-experiment/json 01eb442 → c27c302 age confidence indirect digest
github.com/go-logr/logr v1.4.3 → v1.4.4 age confidence indirect patch
github.com/go-ole/go-ole v1.2.6 → v1.3.0 age confidence indirect minor
github.com/go-openapi/jsonpointer v0.21.0 → v0.24.0 age confidence indirect minor
github.com/go-openapi/jsonpointer v0.23.1 → v0.24.0 age confidence indirect minor
github.com/go-openapi/jsonreference v0.21.5 → v0.21.6 age confidence indirect patch
github.com/go-openapi/swag v0.23.0 → v0.29.2 age confidence indirect minor
github.com/go-openapi/swag v0.26.0 → v0.29.2 age confidence indirect minor
github.com/go-openapi/swag/cmdutils v0.26.0 → v0.29.2 age confidence indirect minor
github.com/go-openapi/swag/conv v0.26.0 → v0.29.2 age confidence indirect minor
github.com/go-openapi/swag/fileutils v0.26.0 → v0.29.2 age confidence indirect minor
github.com/go-openapi/swag/jsonname v0.26.0 → v0.29.2 age confidence indirect minor
github.com/go-openapi/swag/jsonutils v0.26.0 → v0.29.2 age confidence indirect minor
github.com/go-openapi/swag/loading v0.26.0 → v0.29.2 age confidence indirect minor
github.com/go-openapi/swag/mangling v0.26.0 → v0.29.2 age confidence indirect minor
github.com/go-openapi/swag/netutils v0.26.0 → v0.29.2 age confidence indirect minor
github.com/go-openapi/swag/stringutils v0.26.0 → v0.29.2 age confidence indirect minor
github.com/go-openapi/swag/typeutils v0.26.0 → v0.29.2 age confidence indirect minor
github.com/go-openapi/swag/yamlutils v0.26.0 → v0.29.2 age confidence indirect minor
github.com/go-viper/mapstructure/v2 v2.4.0 → v2.5.0 age confidence indirect minor
github.com/gorilla/handlers v1.4.2 → v1.5.2 age confidence indirect minor
github.com/grpc-ecosystem/grpc-gateway/v2 v2.29.0 → v2.30.0 age confidence indirect minor v2.31.0
github.com/inconshreveable/mousetrap v1.0.0 → v1.1.0 age confidence indirect minor
github.com/kaptinlin/jsonpointer v0.4.27 → v0.4.28 age confidence indirect patch
github.com/kaptinlin/jsonschema v0.9.3 → v0.9.10 age confidence indirect patch
github.com/klauspost/compress v1.18.0 → v1.20.0 age confidence indirect minor v1.20.1
github.com/knadh/koanf/maps v0.1.2 → v0.1.3 age confidence indirect patch
github.com/knadh/koanf/parsers/json v1.0.0 → v1.0.1 age confidence indirect patch
github.com/knadh/koanf/parsers/toml/v2 v2.2.1 → v2.2.2 age confidence indirect patch
github.com/knadh/koanf/parsers/yaml v1.1.0 → v1.1.1 age confidence indirect patch
github.com/knadh/koanf/providers/fs v1.0.0 → v1.0.1 age confidence indirect patch
github.com/knadh/koanf/providers/rawbytes v1.0.0 → v1.0.1 age confidence indirect patch
github.com/knadh/koanf/v2 v2.3.5 → v2.3.6 age confidence indirect patch v2.3.7
github.com/lucasb-eyer/go-colorful v1.4.0 → v1.4.1 age confidence indirect patch
github.com/lufia/plan9stats 39d0f17 → 341c2f0 age confidence indirect digest
github.com/magiconair/properties v1.8.10 → v1.18.11 age confidence indirect minor v1.18.12
github.com/mailru/easyjson v0.7.7 → v0.9.2 age confidence indirect minor
github.com/mattn/go-colorable v0.1.13 → v0.1.15 age confidence indirect patch
github.com/mattn/go-colorable v0.1.14 → v0.1.15 age confidence indirect patch
github.com/mattn/go-isatty v0.0.22 → v0.0.24 age confidence indirect patch
github.com/mattn/go-isatty v0.0.20 → v0.0.24 age confidence indirect patch
github.com/mattn/go-runewidth v0.0.24 → v0.0.30 age confidence indirect patch
github.com/moby/go-archive v0.1.0 → v0.3.3 age confidence indirect minor
github.com/moby/patternmatcher v0.6.0 → v0.6.1 age confidence indirect patch
github.com/moby/sys/sequential v0.6.0 → v0.7.0 age confidence indirect minor
github.com/moby/sys/user v0.4.0 → v0.4.1 age confidence indirect patch
github.com/moby/sys/userns v0.1.0 → v0.2.1 age confidence indirect minor
github.com/moby/term v0.5.0 → v0.5.2 age confidence indirect patch
github.com/morikuni/aec v1.0.0 → v1.1.0 age confidence indirect minor
github.com/oasdiff/yaml v0.0.9 → v0.1.1 age confidence indirect minor
github.com/oasdiff/yaml3 v0.0.9 → v0.0.14 age confidence indirect patch
github.com/prometheus/common v0.42.0 → v0.71.0 age confidence indirect minor
github.com/prometheus/procfs v0.10.1 → v0.22.0 age confidence indirect minor
github.com/shirou/gopsutil/v3 v3.23.12 → v3.24.5 age confidence indirect minor
github.com/sirupsen/logrus v1.9.3 → v1.10.2 age confidence indirect minor
github.com/testcontainers/testcontainers-go v0.33.0 → v0.44.0 age confidence indirect minor
github.com/testcontainers/testcontainers-go/modules/postgres v0.33.0 → v0.44.0 age confidence indirect minor
github.com/tklauser/go-sysconf v0.3.12 → v0.4.0 age confidence indirect minor
github.com/tklauser/numcpus v0.6.1 → v0.12.0 age confidence indirect minor
github.com/urfave/cli/v3 v3.10.1 → v3.11.0 age confidence indirect minor v3.13.0 (+1)
github.com/woodsbury/decimal128 v1.3.0 → v1.5.0 age confidence indirect minor
go.opentelemetry.io/otel/exporters/otlp/otlptrace v1.44.0 → v1.46.0 age confidence indirect minor
go.yaml.in/yaml/v3 v3.0.4 → v3.0.5 age confidence indirect patch
golang.org/x/crypto v0.54.0 → v0.57.0 age confidence indirect minor
golang.org/x/mod v0.37.0 → v0.41.0 age confidence indirect minor
golang.org/x/net v0.57.0 → v0.59.0 age confidence indirect minor
golang.org/x/oauth2 v0.36.0 → v0.37.0 age confidence indirect minor
golang.org/x/sync v0.21.0 → v0.23.0 age confidence indirect minor
golang.org/x/sync v0.22.0 → v0.23.0 age confidence indirect minor
golang.org/x/sys v0.46.0 → v0.48.0 age confidence indirect minor
golang.org/x/sys v0.47.0 → v0.48.0 age confidence indirect minor
golang.org/x/sys v0.29.0 → v0.48.0 age confidence indirect minor
golang.org/x/term v0.44.0 → v0.46.0 age confidence indirect minor
golang.org/x/term v0.45.0 → v0.46.0 age confidence indirect minor
golang.org/x/text v0.38.0 → v0.42.0 age confidence indirect minor
golang.org/x/text v0.40.0 → v0.42.0 age confidence indirect minor
golang.org/x/time v0.15.0 → v0.16.0 age confidence indirect minor
gorm.io/driver/postgres v1.6.0 → v1.6.2 age confidence indirect patch v1.6.3
k8s.io/utils 28399d8 → cf1189d age confidence indirect digest
sigs.k8s.io/json 2d32026 → 11ed52e age confidence indirect digest
sigs.k8s.io/structured-merge-diff/v6 v6.4.0 → v6.4.2 age confidence indirect patch

Warning

Some dependencies could not be looked up. Check the warning logs for more information.


Release Notes

alessio/shellescape (al.essio.dev/pkg/shellescape)

v1.6.1

Compare Source

Changelog

charmbracelet/lipgloss (charm.land/lipgloss/v2)

v2.0.6

Compare Source

Devanagari, auto-grapheme mode, and more

Hi! The big news in this release is that Lip Gloss now properly renders Devanagari (Hindi)! Beyond that—or perhaps as a result—Lip Gloss will now switch to mode 2027 for grapheme support when possible.

There's other good stuff too. Let's go!

क्या हाल है?

Hindi speakers, it's about time! Lip Gloss and Ultraviolet now properly renders Devanagari. That means Bubble Tea will as well.

Screenshot 2026-08-12 at 10 12 14

This brings us to…

Cyberpunk 2027

Lip Gloss (and Ultraviolet) now asks the terminal at startup whether it supports Unicode core mode (DEC mode 2027), and when it does, measures widths the same way the terminal does. We did this for Devanagari but it also means Emojis and things render better now too. Let's go!

Shrinky tables: not anymore

Columns no longer shrink to zero width. Thanks, @​taciturnaxolotl!


Changelog

Fixed

The Charm logo

Thoughts? Questions? We love hearing from you. Feel free to reach out on X, Discord, Slack, The Fediverse, Bluesky.

Masterminds/squirrel (github.com/Masterminds/squirrel)

v1.5.4

Compare Source

What's Changed

New Contributors

Full Changelog: Masterminds/squirrel@v1.5.3...v1.5.4

v1.5.3

Compare Source

v1.5.2: Fix placeholder generation for And/Or

Compare Source

What's Changed

v1.5.1

Compare Source

What's Changed

New Contributors

Full Changelog: Masterminds/squirrel@v1.5.0...v1.5.1

v1.5.0

Compare Source

  • Add InnerJoin and CrossJoin methods
  • Fix nested select statements in Update.Set values

v1.4.0

Compare Source

Test fix and StatementBuilder.Where

v1.3.0

Compare Source

v1.2.0

Compare Source

bxcodec/faker (github.com/bxcodec/faker/v3)

v3.8.1: Deprecating v3 module

Compare Source

Full Changelog: bxcodec/faker@v3.8.0...v3.8.1

v3.8.0

Compare Source

What's Changed

New Contributors

Full Changelog: bxcodec/faker@v3.7.0...v3.8.0

v3.7.0

Compare Source

What's Changed

New Contributors

Full Changelog: bxcodec/faker@v3.6.0...v3.7.0

v3.6.0

Compare Source

Features
Chores

v3.5.0

Compare Source

Features
Fixes

v3.4.0

Compare Source

Features
Fixes

✂ Note

PR body was truncated to here.


Configuration

📅 Schedule: (in timezone America/New_York)

  • Branch creation
    • Between 12:00 AM and 07:59 AM, only on Monday (* 0-7 * * 1)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

To execute skipped test pipelines write comment /ok-to-test.


Documentation

Find out how to configure dependency updates in MintMaker documentation or see all available configuration options in Renovate documentation.

@red-hat-konflux

red-hat-konflux Bot commented Sep 7, 2026 •

Copy link
Copy Markdown
Contributor Author

ℹ️ Artifact update notice

File name: components/api-server/go.mod

In order to perform the update(s) described in the table above, Renovate ran the go get command, which resulted in the following additional change(s):

  • 16 additional dependencies were updated

Due to Go's usage of Minimal Version Selection (MVS), these packages have been updated to the minimum version available, so will still abide by minimumReleaseAge=14 days

Details:

Package Change
github.com/jackc/pgx/v5 v5.6.0 -> v5.10.0
github.com/prometheus/client_golang v1.16.0 -> v1.23.2
github.com/prometheus/client_model v0.3.0 -> v0.6.2
go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.49.0 -> v0.70.0
go.opentelemetry.io/otel v1.44.0 -> v1.46.0
go.opentelemetry.io/otel/metric v1.44.0 -> v1.46.0
go.opentelemetry.io/otel/sdk v1.44.0 -> v1.46.0
go.opentelemetry.io/otel/sdk/metric v1.44.0 -> v1.46.0
go.opentelemetry.io/otel/trace v1.44.0 -> v1.46.0
google.golang.org/grpc v1.82.1 -> v1.83.0
google.golang.org/protobuf v1.36.11 -> v1.36.12
gorm.io/gorm v1.31.1 -> v1.31.2
github.com/Azure/go-ansiterm v0.0.0-20210617225240-d185dfc1b5a1 -> v0.0.0-20250102033503-faa5f7b0171c
github.com/power-devops/perfstat v0.0.0-20210106213030-5aafc221ea8c -> v0.0.0-20240221224432-82ca36839d55
google.golang.org/genproto/googleapis/api v0.0.0-20260720211330-0afa2a65878a -> v0.0.0-20260803160001-6ac0973c030d
google.golang.org/genproto/googleapis/rpc v0.0.0-20260720211330-0afa2a65878a -> v0.0.0-20260803160001-6ac0973c030d
File name: components/control-plane/go.mod

In order to perform the update(s) described in the table above, Renovate ran the go get command, which resulted in the following additional change(s):

  • 7 additional dependencies were updated

Due to Go's usage of Minimal Version Selection (MVS), these packages have been updated to the minimum version available, so will still abide by minimumReleaseAge=14 days

Details:

Package Change
go.opentelemetry.io/otel v1.45.0 -> v1.46.0
go.opentelemetry.io/otel/metric v1.45.0 -> v1.46.0
go.opentelemetry.io/otel/sdk v1.45.0 -> v1.46.0
go.opentelemetry.io/otel/sdk/metric v1.45.0 -> v1.46.0
go.opentelemetry.io/otel/trace v1.45.0 -> v1.46.0
google.golang.org/protobuf v1.36.12-0.20260120151049-f2248ac996af -> v1.36.12
google.golang.org/genproto/googleapis/api v0.0.0-20260720211330-0afa2a65878a -> v0.0.0-20260803160001-6ac0973c030d
File name: go.mod

In order to perform the update(s) described in the table above, Renovate ran the go get command, which resulted in the following additional change(s):

  • 1 additional dependency was updated
  • The go directive was updated for compatibility reasons

Due to Go's usage of Minimal Version Selection (MVS), these packages have been updated to the minimum version available, so will still abide by minimumReleaseAge=14 days

Details:

Package Change
go 1.26.4 -> 1.27.0
github.com/charmbracelet/ultraviolet v0.0.0-20251205161215-1948445e3318 -> v0.0.0-20260811164956-006e29f97886
File name: scripts/cli-generator/go.mod

In order to perform the update(s) described in the table above, Renovate ran the go get command, which resulted in the following additional change(s):

  • The go directive was updated for compatibility reasons

Due to Go's usage of Minimal Version Selection (MVS), these packages have been updated to the minimum version available, so will still abide by minimumReleaseAge=14 days

Details:

Package Change
go 1.24.0 -> 1.27.0
File name: scripts/openapi-ir/go.mod

In order to perform the update(s) described in the table above, Renovate ran the go get command, which resulted in the following additional change(s):

  • The go directive was updated for compatibility reasons

Due to Go's usage of Minimal Version Selection (MVS), these packages have been updated to the minimum version available, so will still abide by minimumReleaseAge=14 days

Details:

Package Change
go 1.24.0 -> 1.27.0
File name: scripts/sdk-generator/go.mod

In order to perform the update(s) described in the table above, Renovate ran the go get command, which resulted in the following additional change(s):

  • The go directive was updated for compatibility reasons

Due to Go's usage of Minimal Version Selection (MVS), these packages have been updated to the minimum version available, so will still abide by minimumReleaseAge=14 days

Details:

Package Change
go 1.24.0 -> 1.27.0

@coderabbitai

coderabbitai Bot commented Sep 7, 2026 •

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository YAML (base), Central YAML (inherited)

Review profile: CHILL

Plan: Enterprise

Run ID: 7e2e72c8-90f4-434b-9141-eb4e18c94727

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Comment @coderabbitai help to get the list of available commands.

@jsell-rh

jsell-rh commented Sep 7, 2026 •

Copy link
Copy Markdown
Collaborator

Amber review: comment

Amber review

Status: Complete

View the submitted review.

@jsell-rh jsell-rh left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Verdict

This is an automated Renovate/Mintmaker Go dependency bump touching only go.mod/go.sum across every module; no production, test, or manifest code changes. The go.sum regeneration is internally consistent (e.g. gopsutil/v3 cleanly replaced by v4, docker/docker swapped for moby/moby, hashes present for updated modules), so this is safe to land once CI confirms it builds and tests pass.

Summary

I reviewed the full diff against the HyperShell conventions. Because this PR contains no Go source, none of the panic/error-wrapping/SecurityContext/reconcile/secret-handling rules apply. The google/uuid promotion to a direct require in components/control-plane/go.mod is correct - it is imported directly by internal/reconciler/reconciler_test.go, so go mod tidy legitimately hoists it. My findings are limited to scope/accuracy notes and a request that CI validate the behavior-relevant transitive bumps, since no Go toolchain is available in this review environment to run go build, go mod verify, or the test suites myself.

Notable behavior-adjacent bumps to confirm via CI (all indirect/test-facing): testcontainers-go v0.33 -> v0.44 (replaces docker/docker with moby/moby/api + moby/moby/client), shirou/gopsutil v3 -> v4 (module-path major bump), jackc/pgx/v5 v5.6 -> v5.10, prometheus/client_golang v1.16 -> v1.23, and the OTel stack to v1.45. None of these should require code changes, but they are the ones most likely to surface a compile or integration-test break.

Findings

[Minor] The commit/PR title "update go indirect dependencies" understates the scope. Several direct dependencies changed in components/api-server/go.mod (prometheus/client_golang v1.16.0 -> v1.23.2, the go.opentelemetry.io/otel* set to v1.45.0, google.golang.org/grpc v1.82.1 -> v1.83.0, gorm.io/gorm v1.31.1 -> v1.31.2). Not a blocker, but the changelog/title should reflect that direct deps moved too. Confidence: High

[Minor] The Go language directive was raised beyond a dependency bump: go.mod 1.26.4 -> 1.26.6 and the three scripts/* modules 1.24.0 -> 1.26.0. This raises the minimum Go toolchain required to build those modules. It is consistent with the repo toolchain go1.26.7, but confirm CI runners and any downstream consumers of the scripts/* generators use Go >= 1.26. Confidence: Medium

Cross-PR coordination

No material cross-PR coordination issue requires maintainer action.

Convention Checklist

Convention Result
Conventional commit message Pass
go.mod/go.sum internally consistent Pass
Image references consistent across manifests N/A (no manifest changes)

github.com/onsi/gomega v1.27.1
github.com/openshift-online/rh-trex-ai v0.0.32-0.20260819203335-5798cb607fcb
github.com/prometheus/client_golang v1.16.0
github.com/prometheus/client_golang v1.23.2

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The PR title says "indirect dependencies," but this is a direct dependency and it moved from v1.16.0 to v1.23.2 (as did the otel set to v1.45.0, grpc v1.82.1->v1.83.0, and gorm v1.31.1->v1.31.2 in this same require block). Please reflect the direct-dependency changes in the title/changelog. Minor, non-blocking.

Comment thread scripts/openapi-ir/go.mod Outdated
module github.com/openshift-online/hypershell/scripts/openapi-ir

go 1.24.0
go 1.26.0

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This raises the module's minimum Go language version from 1.24.0 to 1.26.0 (same change in scripts/cli-generator and scripts/sdk-generator) - that's more than an indirect-dependency bump. It aligns with the repo toolchain go1.26.7, but please confirm CI runners and anyone building these generator modules are on Go >= 1.26. Minor.

amber-review-bot

This comment was marked as outdated.

@amber-review-bot

Copy link
Copy Markdown
Collaborator

Amber review: comment

Amber review

Status: Complete

View the submitted review.

@red-hat-konflux
red-hat-konflux Bot force-pushed the konflux/mintmaker/main/go-indirect-dependencies branch from fba63a2 to e4bbbd9 Compare September 14, 2026 04:41
@red-hat-konflux red-hat-konflux Bot changed the title chore(deps): update go indirect dependencies Update Go indirect dependencies Sep 14, 2026
@amber-review-bot

amber-review-bot commented Sep 14, 2026 •

Copy link
Copy Markdown
Collaborator

Amber review: comment

Amber review

Status: Complete

View the submitted review.

amber-review-bot

This comment was marked as outdated.

@red-hat-konflux
red-hat-konflux Bot force-pushed the konflux/mintmaker/main/go-indirect-dependencies branch from e4bbbd9 to 7710cd2 Compare September 21, 2026 04:46
@red-hat-konflux
red-hat-konflux Bot enabled auto-merge September 21, 2026 04:46
@red-hat-konflux red-hat-konflux Bot changed the title Update Go indirect dependencies chore(deps): update go indirect dependencies Sep 21, 2026
amber-review-bot

This comment was marked as outdated.

amber-review-bot

This comment was marked as outdated.

@red-hat-konflux
red-hat-konflux Bot force-pushed the konflux/mintmaker/main/go-indirect-dependencies branch from c5f5ea6 to 7b27e35 Compare September 24, 2026 01:05

@amber-review-bot amber-review-bot left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Verdict

This remains a Renovate/Mintmaker dependency-bump PR that rewrites go.mod/go.sum across all seven modules; the regeneration is mechanically consistent (e.g. gopsutil/v3 fully removed and replaced by v4, docker/docker swapped for moby/moby/api+moby/moby/client, new hashes present for prometheus/client_golang v1.23.2). It is broader than its "indirect" title implies and still leaves the root and scripts/* modules on go 1.27 while the three component modules stay on 1.26; it needs one maintainer decision on the Go version and a green build+test run.

No Go toolchain is available in this review environment, so I could not run go build, go mod verify, or the test suites - those gates must be enforced by CI.

Findings

All findings on this head are continuations of open Amber inline threads. Per review policy I am not re-posting duplicate inline comments; the existing threads are linked below.

[Major] Go language-version directive is inconsistent across modules (Consistency / CI toolchain).
The root go.mod now declares go 1.27 and drops the toolchain go1.26.7 line (L3), and all three scripts/* modules were raised to go 1.27.0. But components/api-server, components/control-plane, and components/cli still declare go 1.26.4 / toolchain go1.26.7. Any environment that builds the root module (the lefthook tool directive / git hooks) or the generator modules now needs a 1.27 toolchain, which the pinned 1.26.7 CI/Konflux images may not satisfy. Please confirm this bump is intentional and either align all modules and the CI/Konflux toolchain to 1.27, or keep the root and scripts/* on 1.26. Confidence: Medium-High. Continues #253 (comment).

[Major] Title says "indirect" but several direct, production-path dependencies moved (Scope / Verification).
components/api-server/go.mod upgrades prometheus/client_golang v1.16.0 -> v1.23.2, the OpenTelemetry otel/metric/sdk/trace stack v1.44 -> v1.46 (otelhttp v0.49 -> v0.70), google.golang.org/grpc v1.82.1 -> v1.83.0, protobuf v1.36.11 -> v1.36.12, and gorm v1.31.1 -> v1.31.2; components/control-plane/go.mod bumps lib/pq v1.10.9 -> v1.12.3. These sit in the metrics, tracing, gRPC, and DB code paths, so this is not a no-op indirect bump. Require a full go build ./... + make test (and make check) across every module before merge. Confidence: High. See #253 (comment) and #253 (comment).

[Minor] Transitive major-version jumps carry breaking-change risk (Verification).
shirou/gopsutil v3 -> v4 (module-path change), go-openapi/jsonpointer v0.21 -> v1.0.1 (in scripts/*), testcontainers-go v0.33 -> v0.44, and the moby/docker restructure (docker/docker replaced by moby/moby/api + moby/moby/client) can change APIs even as indirect deps. go.sum is internally consistent for these (verified gopsutil/v3 removed, v4 and moby/moby hashes present), but rely on green CI as the merge gate; I could not run go build / go mod verify here. Confidence: Medium. See #253 (comment).

Cross-PR coordination

No material cross-PR coordination issue requires maintainer action.

Previous concerns

  • Root go.mod bumps to 1.27 while other modules stay on 1.26 - still present. Verified on this head: go.mod L3 is go 1.27 (toolchain line removed) and scripts/cli-generator, scripts/sdk-generator, scripts/openapi-ir are go 1.27.0, while components/api-server, components/control-plane, and components/cli remain go 1.26.4 / toolchain go1.26.7.
  • Title "indirect" but direct prod dependencies upgraded; needs build+test and lib/pq direct bump in control plane - still present. Verified in the diffs of components/api-server/go.mod (prometheus/client_golang, otel, grpc, protobuf, gorm) and components/control-plane/go.mod (lib/pq v1.10.9 -> v1.12.3) at this head.
  • Transitive major-version jumps - still present. Verified: gopsutil v3 -> v4, go-openapi/jsonpointer v1.0.1, testcontainers-go v0.33 -> v0.44, and the moby/docker restructure remain in the go.mod/go.sum diffs.
  • Title is not a Conventional Commit - addressed. The PR title/head is chore(deps): update go indirect dependencies, a valid type(scope): prefix.

Findings Summary (ordered by severity, highest first)

  1. [Major] Go version directive inconsistent - root and scripts/* on go 1.27, component modules on 1.26 - Consistency / CI toolchain (go.mod L3; scripts/*/go.mod L3)
  2. [Major] "indirect" title but direct prod deps upgraded; needs build+test - Scope / Verification (components/api-server/go.mod L14, L21-L30; components/control-plane/go.mod L10)
  3. [Minor] Transitive major-version jumps (gopsutil v4, go-openapi v1, testcontainers, moby) - Verification (components/api-server/go.mod)

Convention Checklist

Convention Result
Conventional commit message Pass
go.mod/go.sum internally consistent Pass
Go version directive consistent across modules Fail
go.mod/go.sum verified (go build / go mod verify) Not verifiable in this environment - defer to CI
Image references consistent across manifests N/A (no manifests changed)

@markturansky

markturansky commented Sep 25, 2026 •

Copy link
Copy Markdown
Collaborator

Amber review: comment

Amber review

Status: Complete

View the submitted review.

markturansky

This comment was marked as outdated.

Signed-off-by: red-hat-konflux <126015336+red-hat-konflux[bot]@users.noreply.github.com>
@red-hat-konflux
red-hat-konflux Bot force-pushed the konflux/mintmaker/main/go-indirect-dependencies branch from 7b27e35 to 2bb93ee Compare September 28, 2026 04:57

@markturansky markturansky left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Verdict

This remains a Renovate/Mintmaker dependency-bump PR that rewrites go.mod/go.sum across all seven modules; on this rebased head the regeneration is mechanically consistent (verified: gopsutil/v3 fully removed and replaced by v4, docker/docker swapped for moby/moby/api+moby/moby/client, and prometheus/client_golang v1.23.2 hashes present). It is broader than its "indirect" title implies and still leaves the root and scripts/* modules on go 1.27.0 while the three component modules stay on 1.26; it needs one maintainer decision on the Go version and a green build+test run.

No Go toolchain is available in this review environment, so I could not run go build, go mod verify, or the test suites - those gates must be enforced by CI.

Findings

All findings on this head are continuations of open Amber inline threads. Per review policy I am not re-posting duplicate inline comments; the existing threads are linked below.

[Major] Go language-version directive is inconsistent across modules (Consistency / CI toolchain).
The root go.mod declares go 1.27.0 and drops the toolchain go1.26.7 line (L3), and all three scripts/* modules were raised to go 1.27.0. But components/api-server, components/control-plane, and components/cli still declare go 1.26.4 / toolchain go1.26.7. Any environment that builds the root module (the lefthook tool directive / git hooks) or the generator modules now needs a 1.27 toolchain, which the pinned 1.26.7 CI/Konflux images may not satisfy. Please confirm this bump is intentional and either align all modules and the CI/Konflux toolchain to 1.27, or keep the root and scripts/* on 1.26. Confidence: Medium-High. Continues #253 (comment).

[Major] Title says "indirect" but several direct, production-path dependencies moved (Scope / Verification).
components/api-server/go.mod upgrades jackc/pgx/v5 v5.6.0 -> v5.10.0 (DB driver), prometheus/client_golang v1.16.0 -> v1.23.2 (and client_model v0.3.0 -> v0.6.2), the OpenTelemetry otel/metric/sdk/trace stack v1.44 -> v1.46 (otelhttp v0.49 -> v0.70), google.golang.org/grpc v1.82.1 -> v1.83.0, protobuf v1.36.11 -> v1.36.12, and gorm v1.31.1 -> v1.31.2. These sit in the DB, metrics, tracing, and gRPC code paths, so this is not a no-op indirect bump. Require a full go build ./... + make test (and make check) across every module before merge. Confidence: High. See #253 (comment).

[Minor] Transitive major-version jumps carry breaking-change risk (Verification).
shirou/gopsutil v3 -> v4 (module-path change), go-openapi/jsonpointer v0.21 -> v1.0.1 (in scripts/* and control-plane) and jsonreference v0.21 -> v1.0.0, testcontainers-go v0.33 -> v0.44, and the moby/docker restructure (docker/docker replaced by moby/moby/api + moby/moby/client) can change APIs even as indirect deps. go.sum is internally consistent for these (verified gopsutil/v3 removed, v4 and moby/moby hashes present), but rely on green CI as the merge gate; I could not run go build / go mod verify here. Confidence: Medium. See #253 (comment).

Cross-PR coordination

There is a competing direct-dependency version target that needs a maintainer merge-order decision. This PR pins google.golang.org/grpc to v1.83.0 in components/api-server/go.mod, while PR #370 targets v1.83.2 for the same module in both components/api-server and components/control-plane. If #370 lands first and this PR is then merged, api-server's gRPC dependency would be downgraded from v1.83.2 back to v1.83.0. Maintainers should either merge this PR before #370, drop the grpc bump from this PR, or reconcile both on v1.83.2 so the later merge does not regress the patch level.

Previous concerns

  • Root go.mod bumps to 1.27 while component modules stay on 1.26 - still present. Verified on this head: go.mod L3 is go 1.27.0 (toolchain line removed) and scripts/cli-generator, scripts/sdk-generator, scripts/openapi-ir are go 1.27.0, while components/api-server, components/control-plane, and components/cli remain go 1.26.4 / toolchain go1.26.7.
  • Title "indirect" but direct prod dependencies upgraded; needs build+test - still present. Verified in the diff of components/api-server/go.mod: pgx/v5, prometheus/client_golang, otel, grpc, protobuf, and gorm all moved.
  • lib/pq direct bump in control plane - addressed / no longer present. After the rebase onto current main, components/control-plane/go.mod and components/api-server/go.mod both keep github.com/lib/pq v1.10.9; this head no longer bumps lib/pq. (The DB-path concern now shifts to the pgx/v5 bump noted above.)
  • Transitive major-version jumps - still present. Verified: gopsutil v3 -> v4, go-openapi/jsonpointer v1.0.1, testcontainers-go v0.33 -> v0.44, and the moby/docker restructure remain in the go.mod/go.sum diffs.
  • Title is not a Conventional Commit - addressed. The PR title/head is chore(deps): update go indirect dependencies, a valid type(scope): prefix.

Findings Summary (ordered by severity, highest first)

  1. [Major] Go version directive inconsistent - root and scripts/* on go 1.27.0, component modules on 1.26 - Consistency / CI toolchain (go.mod L3; scripts/*/go.mod L3)
  2. [Major] "indirect" title but direct prod deps upgraded (pgx, prometheus, otel, grpc, protobuf, gorm); needs build+test - Scope / Verification (components/api-server/go.mod)
  3. [Minor] Transitive major-version jumps (gopsutil v4, go-openapi v1, testcontainers, moby) - Verification (components/api-server/go.mod)

Convention Checklist

Convention Result
Conventional commit message Pass
go.mod/go.sum internally consistent Pass
Go version directive consistent across modules Fail
go.mod/go.sum verified (go build / go mod verify) Not verifiable in this environment - defer to CI
Image references consistent across manifests N/A (no manifests changed)

@hypershell-delivery

hypershell-delivery Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

Amber review: comment

Amber review

Status: Complete

View the submitted review.

@hypershell-delivery hypershell-delivery Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Verdict

This is a Konflux/mintmaker automated module refresh touching only go.mod/go.sum across all Go modules, with no production or test code changes. The updates look mechanically consistent, but the PR silently raises the Go language/toolchain floor to 1.27.0 in the root and generator modules only, which needs a maintainer decision before merge.

Findings

[Major] Go toolchain floor raised to 1.27.0 inconsistently. The root go.mod goes from go 1.26.4 + toolchain go1.26.7 to go 1.27.0 (toolchain directive dropped), and scripts/{cli-generator,openapi-ir,sdk-generator}/go.mod go from go 1.24.0 to go 1.27.0. Meanwhile components/{api-server,control-plane,cli}/go.mod stay at go 1.26.4/toolchain go1.26.7, and every component Dockerfile still pins registry.access.redhat.com/hi/go:1.26.7. For a PR scoped as "update go indirect dependencies," this quietly requires Go 1.27.0 for the root module and the code generators. checks.yml sets up Go via go-version-file: go.mod and go-version-file: scripts/sdk-generator/go.mod, so those jobs now need Go 1.27.0 available; and any hermetic build that runs the generator modules on the pinned 1.26.7 image with GOTOOLCHAIN=local will fail because the go directive (1.27.0) exceeds the toolchain. Please confirm this bump is intentional and that all runners/build images provide Go 1.27.0. Otherwise, either pin the root/generator modules back to 1.26.x, or bump the component modules and Dockerfiles together so the whole stack moves as one. Confidence: Medium.

[Minor] Direct dependencies are bumped despite the "indirect" title. Beyond indirect deps, the diff advances several direct requires - github.com/jackc/pgx/v5 v5.6.0 -> v5.10.0 (the Postgres driver), github.com/prometheus/client_golang v1.16.0 -> v1.23.2, go.opentelemetry.io/otel v1.44.0 -> v1.46.0, and google.golang.org/grpc v1.82.1 -> v1.83.0. These are the DB driver, metrics, tracing, and RPC libraries. The jumps look non-breaking within their major lines, but the title/scope mismatch is worth calling out so reviewers confirm CI build + go test pass (I could not build here - no Go toolchain in this environment). Confidence: High.

Note: No test files changed, so Test Diff Scrutiny is not applicable. go.sum/go.mod consistency and buildability should be validated by CI (go mod verify, build, unit tests) since I cannot compile in this environment.

Cross-PR coordination

A separate open dependency PR (#370) modifies the exact same google.golang.org/grpc require line in components/api-server/go.mod, targeting v1.83.2, whereas this PR sets it to v1.83.0. These are competing edits to the same line, so merge order decides the final version: if this PR lands after #370, api-server grpc is downgraded from v1.83.2 back to v1.83.0, and it diverges from components/control-plane (which #370 raises to v1.83.2 and this PR leaves at v1.83.0). Maintainers should decide the target grpc version and the merge order - e.g., merge #370 and drop this PR's grpc bump, or merge this PR first and let #370 supersede it - so grpc does not regress or skew between the two components.

Previous concerns

No prior Amber findings exist for this pull request (empty review history), so there is nothing to reconcile.

Findings Summary (ordered by severity, highest first)

  1. [Major] Go toolchain floor raised to 1.27.0 in root + generator modules only, while component modules and Dockerfiles stay on 1.26.7 - Build/Consistency (go.mod L3; scripts/*/go.mod L3)
  2. [Minor] Direct deps (pgx, prometheus, otel, grpc) bumped despite "indirect" title; verify CI build/tests - Dependency Hygiene (components/api-server/go.mod)

Convention Checklist

Convention Result
Conventional commit message Pass
Image references consistent across manifests Pass (Dockerfiles unchanged)
Go module go/toolchain directives consistent across stack Fail
No production/test code behavior change Pass

Comment thread go.mod
go 1.26.4

toolchain go1.26.7
go 1.27.0

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This bumps the root module's Go directive to go 1.27.0 and drops the toolchain go1.26.7 line, but the component modules (components/api-server, components/control-plane, components/cli) stay at go 1.26.4 and their Dockerfiles still pin hi/go:1.26.7. checks.yml uses go-version-file: go.mod here, so this job now needs Go 1.27.0. Please confirm the toolchain floor bump is intentional and that all runners provide Go 1.27.0 - otherwise pin back to 1.26.x or move the whole stack (component modules + Dockerfiles) together. Same concern applies to the scripts/*/go.mod bumps to go 1.27.0.

go.opentelemetry.io/otel/sdk v1.46.0
go.opentelemetry.io/otel/sdk/metric v1.46.0
go.opentelemetry.io/otel/trace v1.46.0
google.golang.org/grpc v1.83.0

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Despite the "indirect" title, this line and several nearby direct requires are advanced: google.golang.org/grpc v1.82.1 -> v1.83.0, jackc/pgx/v5 v5.6.0 -> v5.10.0, prometheus/client_golang v1.16.0 -> v1.23.2, otel v1.44.0 -> v1.46.0. These are the RPC, DB-driver, metrics, and tracing libraries - please make sure CI build + go test pass since I can't compile here. Note: another open deps PR edits this same grpc line to v1.83.2; see the Cross-PR coordination section in the review summary.

@rh-amarin

Copy link
Copy Markdown
Collaborator

obsolete

@rh-amarin rh-amarin closed this Sep 29, 2026
auto-merge was automatically disabled September 29, 2026 09:36

Pull request was closed

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants