Skip to content

ci: move the pinned Go toolchain to 1.26.x - #11

Merged
MichalAFerber merged 1 commit into
mainfrom
devops/go-1.26-toolchain
Sep 11, 2026
Merged

MichalAFerber merged 1 commit into
mainfrom
devops/go-1.26-toolchain

Conversation

@tgwab-claude

Copy link
Copy Markdown
Collaborator

Unblocks Dependabot #10, and fixes a second breakage that #10 would have hidden.

Why #10 fails

#10 is titled as a golang.org/x/sys 0.47.0 → 0.48.0 bump, but the diff does more than that:

-go 1.25.0
+go 1.26.0
-	golang.org/x/sys v0.47.0
+	golang.org/x/sys v0.48.0

x/sys v0.48.0 requires Go 1.26, so go mod tidy raised the module's own go directive. Both workflows pin go-version: "1.25.x", and a 1.25 toolchain refuses to build a module declaring go 1.26.0. That is the whole failure — Logic tests died in 8s on macOS and 21s on Ubuntu, far too fast to be a test assertion.

Dependabot only edits go.mod and go.sum, so it cannot repair this itself. The toolchain pin has to move in a separate change.

Why release.yml is in this PR too

release.yml pins the same 1.25.x, but its triggers do not include pull_request — it runs on a tag push. So fixing only ci.yml would turn #10 green while leaving the release build broken, and nobody would find out until the next tag was cut.

That is a worse failure than the visible one: delayed, silent, and discovered at exactly the moment you want a release. v2.0.0 was built on 1.25.x this morning, so the next tag is the first one that would hit it.

Verified there are no residual 1.25 references anywhere under .github/workflows/.

Order

This can merge before #10 and is safe standing alone — a 1.26 toolchain still builds the current go 1.25.0 module. Once this lands, re-run #10 and it should pass.

Verified

  • Both pins changed, one occurrence each, confirmed by count before and after.
  • grep -rn "1\.25" .github/workflows/ returns nothing.

Not verified

🤖 Generated with Claude Code

https://claude.ai/code/session_01EQYeUULNUFx2m5nm6fCLwj

Dependabot #10 bumps golang.org/x/sys 0.47.0 -> 0.48.0, which requires
Go 1.26, so `go mod tidy` also raised go.mod's go directive from 1.25.0
to 1.26.0. Both workflows pin go-version "1.25.x", and a 1.25 toolchain
refuses to build a module declaring go 1.26.0 — #10's Logic tests fail
in 8s on macOS and 21s on Ubuntu.

Dependabot only edits go.mod and go.sum, so it cannot fix this itself.

release.yml is bumped alongside ci.yml deliberately. It pins the same
1.25.x but is not exercised by pull_request, so fixing only ci.yml would
make #10 go green while leaving the release build broken — discovered
later, by whoever next cuts a tag. That is a worse failure than this one
because it is delayed and silent.

A 1.26 toolchain still builds the current go 1.25.0 module, so this can
merge before #10 and is safe on its own.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EQYeUULNUFx2m5nm6fCLwj
@MichalAFerber
MichalAFerber enabled auto-merge (squash) September 11, 2026 00:54
@MichalAFerber
MichalAFerber merged commit 8a01097 into main Sep 11, 2026
6 checks passed
@MichalAFerber
MichalAFerber deleted the devops/go-1.26-toolchain branch September 11, 2026 01:04
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants