Repository navigation
chore(ci): refresh build pins and strengthen portable checks - #52
Conversation
|
🦞👀 Pull request received. I will update this pull request when review starts. ClawSweeper review completeClawSweeper finished reviewing this revision. The review result is being finalized. |
|
Codex review: blocked before merge. Reviewed September 12, 2026, 10:57 PM ET / September 13, 2026, 02:57 UTC. ClawSweeper reviewWhat this changesUpdates build and release toolchain pins, pins GitHub Actions to commits, and adds non-mutating formatting, documentation metadata, and cross-platform race checks. Merge readiness⛔ Blocked before merge - 1 item remains This remains useful work: main and v0.4.9 still require Go 1.26.7, and no replacement PR owns this refresh. No actionable introduced defect was found. The collaborator-authored PR should remain open for normal merge handling. Priority: P3 Review scores
Verification
How this fits togethergoplaces provides a Go library and CLI for Google Places and Routes. Its build automation turns source into tested, vulnerability-scanned binaries, while separate release tooling verifies provenance before publication. flowchart TD
A[Source changes] --> B[Linux and Windows checks]
A --> C[macOS audit]
D[Pinned build tools] --> B
D --> C
C --> E[Six platform binaries]
E --> F[Vulnerability and reproducibility checks]
F --> G[Separate gated release process]
Before merge
Agent review detailsSecurityNone. Review metrics
Merge-risk optionsMaintainer options:
Technical reviewBest possible solution: Keep the coordinated producer/verifier refresh and its existing fail-closed release policy, with operators adopting the explicitly documented tool versions. Do we have a high-confidence way to reproduce the issue? Not applicable: this is a build-maintenance PR, and inspection identified no concrete introduced failure to reproduce. Is this the best way to solve the issue? Yes: updating producer and verifier pins together preserves the established release contract, and the new formatting check uses supported non-mutating behavior. AGENTS.md: not found in the target repository. Codex review notes: model internal, reasoning medium; reviewed against 7f230595529a. LabelsLabel changes:
Label justifications:
EvidenceWhat I checked:
Likely related people:
Rating scale
Overall follows the weaker of proof and patch quality. Workflow
|
Refresh the existing Go 1.26 release line to 1.26.8 for upstream compiler/runtime fixes, with matching producer, verifier, archive hashes, and rejection fixtures. Update GoReleaser to 2.18.1, Node to 26.8.2, deadcode to 0.50.0, and govulncheck to 1.8.0, including its reviewed module checksum. Kong 1.16.1 and golangci-lint 2.13.2 are already current. The application version stays unchanged.
Pin every external Action to its stable release commit. Keep full CI for PRs and main while avoiding duplicate branch-push audits. CI now uses the installed linter, checks formatting without rewriting files, runs Node metadata tests and checks generated docs, and exercises macOS race tests plus Windows race tests on Go 1.27.1. Staticcheck remains enabled through golangci-lint; the duplicate standalone invocation is removed. The coverage threshold, all release/security contract tests, source/binary vulnerability scans, and six-platform reproducibility gates are retained.
Release-age evidence: Go 1.26.8 (September 1), GoReleaser 2.18.1 (September 5), Node 26.8.2 (September 9), and x/tools 0.50.0 / x/vuln 1.8.0 (September 8, official Go module proxy metadata) all exceed 48 hours. Action tags were resolved through the official repositories; existing create-github-app-token was already current and pinned. Setup-node is added to run the existing metadata tests on the reviewed Node version.
Validation: isolated Codex autoreview is scoped-clean at P0–P2 after correcting stale negative fixtures. Go 1.26.8 race tests, 91.5% coverage, lint, actionlint, deadcode, source govulncheck, Node metadata tests, and all four release/security contract suites pass. A deliberately unformatted temporary source produces exit 1 from the new formatting check without changing the file.
Built-binary proof: the Go 1.26.8 CLI passes the same 21 synthetic HTTP cases as the baseline (all eight commands, human/JSON output, help/version and validation); captured requests/output/exit-code records remain byte-identical, SHA-256
043a9aa35c7e9a159a75b42afed4e4d56bf606646ee1352e3a22e8af3185eefe. GoReleaser builds all six platform binaries locally. Clean-checkout provenance, binary vulnerability scans and reproducibility are also required in exact-head CI before merge. No release, tag, signing or publication is performed.Clean-checkout proof at a2acf7f also passes locally:
SNAPSHOT_REQUIRE_CLEAN=1 ./scripts/verify-snapshot-security.shaccepts the exact six-binary inventory, Git revision and clean-source metadata; govulncheck reports no vulnerabilities for all six../scripts/test-reproducible-builds.sh distreports “exact six-target byte comparison passed” after independent rebuilds. A standalone checkout is used because this Go toolchain omits VCS metadata for linked worktrees.