From 155be3bfd308c27902ba0a7f433cc6ace503bbf1 Mon Sep 17 00:00:00 2001 From: Chris Miles Date: Fri, 4 Sep 2026 22:16:47 +0000 Subject: [PATCH 1/8] chore: harden security automation --- .github/dependabot.yml | 10 ++++ .github/workflows/codeql.yml | 42 ++++++++++++++++ .github/workflows/security.yml | 88 ++++++++++++++++++++++++++++++++++ .github/workflows/tests.yml | 13 +++-- 4 files changed, 148 insertions(+), 5 deletions(-) create mode 100644 .github/dependabot.yml create mode 100644 .github/workflows/codeql.yml create mode 100644 .github/workflows/security.yml diff --git a/.github/dependabot.yml b/.github/dependabot.yml new file mode 100644 index 0000000..eff95b7 --- /dev/null +++ b/.github/dependabot.yml @@ -0,0 +1,10 @@ +version: 2 +updates: + - package-ecosystem: "github-actions" + directory: "/" + schedule: + interval: weekly + - package-ecosystem: "gomod" + directory: "/" + schedule: + interval: weekly diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml new file mode 100644 index 0000000..322a413 --- /dev/null +++ b/.github/workflows/codeql.yml @@ -0,0 +1,42 @@ +name: CodeQL + +on: + push: + branches: [main] + pull_request: + branches: [main] + schedule: + - cron: "29 3 * * 4" + workflow_dispatch: + +permissions: + contents: read + security-events: write + +jobs: + analyze: + runs-on: ubuntu-latest + steps: + - name: Checkout + uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 + - name: Set up Go + uses: actions/setup-go@0a12ed9d6a96ab950c8f026ed9f722fe0da7ef32 # v5.0.2 + with: + go-version: stable + - name: Initialize CodeQL + uses: github/codeql-action/init@6f5948dfacef28e207b48d0905cf90c03365536d # v3.37.9 + with: + languages: go + build-mode: none + - name: Load every Go module + shell: bash + run: | + while IFS= read -r -d '' module; do + module_dir=${module%/go.mod} + ( + cd -- "$module_dir" + GOWORK=off go list ./... + ) + done < <(find . -name go.mod -type f -not -path './.git/*' -not -path './node_modules/*' -not -path './vendor/*' -print0) + - name: Analyze + uses: github/codeql-action/analyze@6f5948dfacef28e207b48d0905cf90c03365536d # v3.37.9 diff --git a/.github/workflows/security.yml b/.github/workflows/security.yml new file mode 100644 index 0000000..b99c7b1 --- /dev/null +++ b/.github/workflows/security.yml @@ -0,0 +1,88 @@ +name: Security + +on: + schedule: + - cron: "17 3 * * 1" + workflow_dispatch: + pull_request: + +permissions: + contents: read + +jobs: + dependency-review: + if: github.event_name == 'pull_request' + runs-on: ubuntu-latest + steps: + - name: Review dependencies + uses: actions/dependency-review-action@2031cfc080254a8a887f58cffee85186f0e49e48 # v4.9.0 + + vulnerabilities-and-sbom: + runs-on: ubuntu-latest + steps: + - name: Checkout + uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 + - name: Set up Go + uses: actions/setup-go@0a12ed9d6a96ab950c8f026ed9f722fe0da7ef32 # v5.0.2 + with: + go-version: stable + - name: Check every Go module for vulnerabilities + shell: bash + run: | + while IFS= read -r -d '' module; do + module_dir=${module%/go.mod} + package_list=$( + ( + cd -- "$module_dir" + GOWORK=off go list ./... + ) + ) + if [ -n "$package_list" ]; then + ( + cd -- "$module_dir" + GOWORK=off go run golang.org/x/vuln/cmd/govulncheck@v1.7.0 -test ./... + ) + fi + done < <(find . -name go.mod -type f -not -path './.git/*' -not -path './node_modules/*' -not -path './vendor/*' -print0) + - name: Generate an SBOM for every Go module + shell: bash + run: | + mkdir -p sbom + module_count=0 + while IFS= read -r -d '' module; do + module_dir=${module%/go.mod} + package_list=$( + ( + cd -- "$module_dir" + GOWORK=off go list ./... + ) + ) + if [ -n "$package_list" ]; then + module_count=$((module_count + 1)) + ( + cd -- "$module_dir" + GOWORK=off go run github.com/CycloneDX/cyclonedx-gomod/cmd/cyclonedx-gomod@v1.9.0 mod -output "$GITHUB_WORKSPACE/sbom/go-${module_count}.cdx.json" + ) + fi + done < <(find . -name go.mod -type f -not -path './.git/*' -not -path './node_modules/*' -not -path './vendor/*' -print0) + test "$module_count" -gt 0 + artifact_count=$(find sbom -type f -name '*.cdx.json' | wc -l | tr -d ' ') + test "$module_count" -eq "$artifact_count" + - name: Upload SBOMs + uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2 + with: + name: cyclonedx-sboms + path: sbom + if-no-files-found: error + + secret-scan: + runs-on: ubuntu-latest + steps: + - name: Checkout complete history + uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 + with: + fetch-depth: 0 + - name: Install Gitleaks + run: go install github.com/zricethezav/gitleaks/v8@v8.30.1 + - name: Scan Git history for secrets + run: gitleaks git . --redact --no-banner diff --git a/.github/workflows/tests.yml b/.github/workflows/tests.yml index 2c47637..c1a8f0a 100644 --- a/.github/workflows/tests.yml +++ b/.github/workflows/tests.yml @@ -14,6 +14,9 @@ name: Wire Tests on: [push, pull_request] + +permissions: + contents: read jobs: build: strategy: @@ -26,11 +29,11 @@ jobs: WIRE_CACHE_MODE: ${{ matrix.cache-mode }} steps: - name: Install Go - uses: actions/setup-go@v2 + uses: actions/setup-go@0a12ed9d6a96ab950c8f026ed9f722fe0da7ef32 # v5.0.2 with: go-version: ${{ matrix.go-version }} - name: Checkout code - uses: actions/checkout@v2 + uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 with: fetch-depth: 2 # required for codecov - name: Run Tests @@ -42,10 +45,10 @@ jobs: steps: - name: Checkout - uses: actions/checkout@v4 + uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 - name: Set up Go - uses: actions/setup-go@v5 + uses: actions/setup-go@0a12ed9d6a96ab950c8f026ed9f722fe0da7ef32 # v5.0.2 with: go-version: "stable" @@ -56,6 +59,6 @@ jobs: run: go test ./internal/... -coverprofile=coverage.txt - name: Upload results to Codecov - uses: codecov/codecov-action@v5 + uses: codecov/codecov-action@5a1091511ad55cbe89839c7260b706298ca349f7 # v5.5.1 env: CODECOV_TOKEN: ${{ secrets.CODECOV_TOKEN }} From 22ad88d6051d4bcd06aebb365e70fc0cbe89c36e Mon Sep 17 00:00:00 2001 From: Chris Miles Date: Fri, 4 Sep 2026 22:40:16 +0000 Subject: [PATCH 2/8] fix: restore Go 1.19 test compatibility --- .github/workflows/codeql.yml | 11 ++++++----- .github/workflows/security.yml | 17 ++++++++++++----- .github/workflows/tests.yml | 14 ++++++++++++++ internal/loader/loader_test.go | 13 +++++++++++-- internal/wire/wire_test.go | 22 +++++++++++++++++++++- 5 files changed, 64 insertions(+), 13 deletions(-) diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml index 322a413..666d4ba 100644 --- a/.github/workflows/codeql.yml +++ b/.github/workflows/codeql.yml @@ -24,19 +24,20 @@ jobs: with: go-version: stable - name: Initialize CodeQL - uses: github/codeql-action/init@6f5948dfacef28e207b48d0905cf90c03365536d # v3.37.9 + uses: github/codeql-action/init@cdf488f595d80d6e07e03d4674febd5ab45fa938 # v4.37.9 with: languages: go - build-mode: none - - name: Load every Go module + build-mode: manual + - name: Build every Go module for CodeQL shell: bash run: | + GOWORK=off go clean -cache while IFS= read -r -d '' module; do module_dir=${module%/go.mod} ( cd -- "$module_dir" - GOWORK=off go list ./... + GOWORK=off go build ./... ) done < <(find . -name go.mod -type f -not -path './.git/*' -not -path './node_modules/*' -not -path './vendor/*' -print0) - name: Analyze - uses: github/codeql-action/analyze@6f5948dfacef28e207b48d0905cf90c03365536d # v3.37.9 + uses: github/codeql-action/analyze@cdf488f595d80d6e07e03d4674febd5ab45fa938 # v4.37.9 diff --git a/.github/workflows/security.yml b/.github/workflows/security.yml index b99c7b1..8c71c23 100644 --- a/.github/workflows/security.yml +++ b/.github/workflows/security.yml @@ -1,6 +1,8 @@ name: Security on: + push: + branches: [main] schedule: - cron: "17 3 * * 1" workflow_dispatch: @@ -11,7 +13,7 @@ permissions: jobs: dependency-review: - if: github.event_name == 'pull_request' + if: github.event_name == 'pull_request' && vars.ENABLE_GITHUB_ADVANCED_SECURITY == 'true' runs-on: ubuntu-latest steps: - name: Review dependencies @@ -61,12 +63,15 @@ jobs: module_count=$((module_count + 1)) ( cd -- "$module_dir" - GOWORK=off go run github.com/CycloneDX/cyclonedx-gomod/cmd/cyclonedx-gomod@v1.9.0 mod -output "$GITHUB_WORKSPACE/sbom/go-${module_count}.cdx.json" + GOWORK=off go run github.com/CycloneDX/cyclonedx-gomod/cmd/cyclonedx-gomod@v1.9.0 mod -json -type library -test -output "$GITHUB_WORKSPACE/sbom/go-${module_count}.cdx.json" ) fi done < <(find . -name go.mod -type f -not -path './.git/*' -not -path './node_modules/*' -not -path './vendor/*' -print0) test "$module_count" -gt 0 - artifact_count=$(find sbom -type f -name '*.cdx.json' | wc -l | tr -d ' ') + for artifact in sbom/*.cdx.json; do + jq -e '.bomFormat == "CycloneDX" and .metadata.component.type == "library" and all(.components[]?; .name != "..")' "$artifact" >/dev/null + done + artifact_count=$(find sbom -type f -name '*.cdx.json' -size +0c | wc -l | tr -d ' ') test "$module_count" -eq "$artifact_count" - name: Upload SBOMs uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2 @@ -83,6 +88,8 @@ jobs: with: fetch-depth: 0 - name: Install Gitleaks - run: go install github.com/zricethezav/gitleaks/v8@v8.30.1 + run: | + GOBIN="$RUNNER_TEMP/gitleaks" go install github.com/zricethezav/gitleaks/v8@v8.30.1 - name: Scan Git history for secrets - run: gitleaks git . --redact --no-banner + run: | + "$RUNNER_TEMP/gitleaks/gitleaks" git . --redact --no-banner diff --git a/.github/workflows/tests.yml b/.github/workflows/tests.yml index c1a8f0a..b200eed 100644 --- a/.github/workflows/tests.yml +++ b/.github/workflows/tests.yml @@ -40,6 +40,20 @@ jobs: shell: bash run: 'internal/runtests.sh' + minimum-go: + name: Go 1.19 on Linux + runs-on: ubuntu-latest + steps: + - name: Install Go + uses: actions/setup-go@0a12ed9d6a96ab950c8f026ed9f722fe0da7ef32 # v5.0.2 + with: + go-version: "1.19.x" + - name: Checkout code + uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 + - name: Run Tests + shell: bash + run: 'internal/runtests.sh' + codecov: runs-on: ubuntu-latest diff --git a/internal/loader/loader_test.go b/internal/loader/loader_test.go index 328fe6a..12c949d 100644 --- a/internal/loader/loader_test.go +++ b/internal/loader/loader_test.go @@ -3281,12 +3281,21 @@ func comparableErrors(errs []packages.Error) []string { continue } pos := normalizeErrorPos(err.Pos) - add(pos + "|" + err.Msg) + add(pos + "|" + normalizeCompilerDiagnostic(err.Msg)) } sort.Strings(out) return out } +// normalizeCompilerDiagnostic makes package-loader comparisons independent of Go's equivalent diagnostic wording. +func normalizeCompilerDiagnostic(msg string) string { + const legacy = "undefined: " + if strings.HasPrefix(msg, legacy) { + return "undeclared name: " + strings.TrimPrefix(msg, legacy) + } + return msg +} + func hasPrefixLabel(labels []string, prefix string) bool { for _, label := range labels { if strings.HasPrefix(label, prefix) { @@ -3336,7 +3345,7 @@ func expandSummaryDiagnostics(msg string) []string { } if parts := strings.SplitN(line, ": ", 2); len(parts) == 2 { pos := normalizeErrorPos(parts[0]) - out = append(out, pos+"|"+parts[1]) + out = append(out, pos+"|"+normalizeCompilerDiagnostic(parts[1])) continue } out = append(out, line) diff --git a/internal/wire/wire_test.go b/internal/wire/wire_test.go index 23db303..3ea856f 100644 --- a/internal/wire/wire_test.go +++ b/internal/wire/wire_test.go @@ -542,7 +542,7 @@ func isIdent(s string) bool { // "C:\GOPATH" and running on Windows, the string // "C:\GOPATH\src\foo\bar.go:15:4" would be rewritten to "foo/bar.go:x:y". func scrubError(gopath string, s string) string { - s = normalizeHeaderRelativeError(s) + s = normalizeLegacyUnexportedName(normalizeHeaderRelativeError(s)) sb := new(strings.Builder) query := gopath + string(os.PathSeparator) + "src" + string(os.PathSeparator) for { @@ -582,6 +582,26 @@ func scrubError(gopath string, s string) string { return strings.TrimRight(sb.String(), "\n") } +// normalizeLegacyUnexportedName aligns the Go 1.19 compiler diagnostic with newer Go releases. +func normalizeLegacyUnexportedName(s string) string { + const marker = ": " + const suffix = " not exported by package " + idx := strings.Index(s, marker) + if idx == -1 { + return s + } + rest := s[idx+len(marker):] + end := strings.Index(rest, suffix) + if end == -1 { + return s + } + name := rest[:end] + if !isLowerIdent(name) { + return s + } + return s[:idx] + ": name " + rest +} + func normalizeHeaderRelativeError(s string) string { const headerPrefix = "-: # " if !strings.HasPrefix(s, headerPrefix) { From 3f69402a01aeae6f58963e5d0ebec67c17cdd987 Mon Sep 17 00:00:00 2001 From: Chris Miles Date: Fri, 4 Sep 2026 22:54:16 +0000 Subject: [PATCH 3/8] fix: update workflow action prerequisites --- .github/workflows/codeql.yml | 4 ++-- .github/workflows/security.yml | 10 +++++----- .github/workflows/tests.yml | 12 ++++++------ 3 files changed, 13 insertions(+), 13 deletions(-) diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml index 666d4ba..c6a06f7 100644 --- a/.github/workflows/codeql.yml +++ b/.github/workflows/codeql.yml @@ -18,9 +18,9 @@ jobs: runs-on: ubuntu-latest steps: - name: Checkout - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 + uses: actions/checkout@fbc6f3992d24b796d5a048ff273f7fcc4a7b6c09 # v5.0.0 - name: Set up Go - uses: actions/setup-go@0a12ed9d6a96ab950c8f026ed9f722fe0da7ef32 # v5.0.2 + uses: actions/setup-go@924ae3a1cded613372ab5595356fb5720e22ba16 # v6.0.0 with: go-version: stable - name: Initialize CodeQL diff --git a/.github/workflows/security.yml b/.github/workflows/security.yml index 8c71c23..dedc21c 100644 --- a/.github/workflows/security.yml +++ b/.github/workflows/security.yml @@ -13,7 +13,7 @@ permissions: jobs: dependency-review: - if: github.event_name == 'pull_request' && vars.ENABLE_GITHUB_ADVANCED_SECURITY == 'true' + if: github.event_name == 'pull_request' && vars.ENABLE_DEPENDENCY_REVIEW == 'true' runs-on: ubuntu-latest steps: - name: Review dependencies @@ -23,9 +23,9 @@ jobs: runs-on: ubuntu-latest steps: - name: Checkout - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 + uses: actions/checkout@fbc6f3992d24b796d5a048ff273f7fcc4a7b6c09 # v5.0.0 - name: Set up Go - uses: actions/setup-go@0a12ed9d6a96ab950c8f026ed9f722fe0da7ef32 # v5.0.2 + uses: actions/setup-go@924ae3a1cded613372ab5595356fb5720e22ba16 # v6.0.0 with: go-version: stable - name: Check every Go module for vulnerabilities @@ -74,7 +74,7 @@ jobs: artifact_count=$(find sbom -type f -name '*.cdx.json' -size +0c | wc -l | tr -d ' ') test "$module_count" -eq "$artifact_count" - name: Upload SBOMs - uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2 + uses: actions/upload-artifact@330a01c490aca151604b8cf639adc76d48f6c5d4 # v5.0.0 with: name: cyclonedx-sboms path: sbom @@ -84,7 +84,7 @@ jobs: runs-on: ubuntu-latest steps: - name: Checkout complete history - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 + uses: actions/checkout@fbc6f3992d24b796d5a048ff273f7fcc4a7b6c09 # v5.0.0 with: fetch-depth: 0 - name: Install Gitleaks diff --git a/.github/workflows/tests.yml b/.github/workflows/tests.yml index b200eed..c3ee4b6 100644 --- a/.github/workflows/tests.yml +++ b/.github/workflows/tests.yml @@ -29,11 +29,11 @@ jobs: WIRE_CACHE_MODE: ${{ matrix.cache-mode }} steps: - name: Install Go - uses: actions/setup-go@0a12ed9d6a96ab950c8f026ed9f722fe0da7ef32 # v5.0.2 + uses: actions/setup-go@924ae3a1cded613372ab5595356fb5720e22ba16 # v6.0.0 with: go-version: ${{ matrix.go-version }} - name: Checkout code - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 + uses: actions/checkout@fbc6f3992d24b796d5a048ff273f7fcc4a7b6c09 # v5.0.0 with: fetch-depth: 2 # required for codecov - name: Run Tests @@ -45,11 +45,11 @@ jobs: runs-on: ubuntu-latest steps: - name: Install Go - uses: actions/setup-go@0a12ed9d6a96ab950c8f026ed9f722fe0da7ef32 # v5.0.2 + uses: actions/setup-go@924ae3a1cded613372ab5595356fb5720e22ba16 # v6.0.0 with: go-version: "1.19.x" - name: Checkout code - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 + uses: actions/checkout@fbc6f3992d24b796d5a048ff273f7fcc4a7b6c09 # v5.0.0 - name: Run Tests shell: bash run: 'internal/runtests.sh' @@ -59,10 +59,10 @@ jobs: steps: - name: Checkout - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 + uses: actions/checkout@fbc6f3992d24b796d5a048ff273f7fcc4a7b6c09 # v5.0.0 - name: Set up Go - uses: actions/setup-go@0a12ed9d6a96ab950c8f026ed9f722fe0da7ef32 # v5.0.2 + uses: actions/setup-go@924ae3a1cded613372ab5595356fb5720e22ba16 # v6.0.0 with: go-version: "stable" From 75d5d19954ff177f12ed30af49645f97de095b67 Mon Sep 17 00:00:00 2001 From: Chris Miles Date: Fri, 4 Sep 2026 22:56:18 +0000 Subject: [PATCH 4/8] fix: pin current workflow actions --- .github/workflows/codeql.yml | 4 ++-- .github/workflows/security.yml | 10 +++++----- .github/workflows/tests.yml | 14 +++++++------- 3 files changed, 14 insertions(+), 14 deletions(-) diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml index c6a06f7..75b7743 100644 --- a/.github/workflows/codeql.yml +++ b/.github/workflows/codeql.yml @@ -18,9 +18,9 @@ jobs: runs-on: ubuntu-latest steps: - name: Checkout - uses: actions/checkout@fbc6f3992d24b796d5a048ff273f7fcc4a7b6c09 # v5.0.0 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - name: Set up Go - uses: actions/setup-go@924ae3a1cded613372ab5595356fb5720e22ba16 # v6.0.0 + uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 with: go-version: stable - name: Initialize CodeQL diff --git a/.github/workflows/security.yml b/.github/workflows/security.yml index dedc21c..58c38f9 100644 --- a/.github/workflows/security.yml +++ b/.github/workflows/security.yml @@ -17,15 +17,15 @@ jobs: runs-on: ubuntu-latest steps: - name: Review dependencies - uses: actions/dependency-review-action@2031cfc080254a8a887f58cffee85186f0e49e48 # v4.9.0 + uses: actions/dependency-review-action@a1d282b36b6f3519aa1f3fc636f609c47dddb294 # v5.0.0 vulnerabilities-and-sbom: runs-on: ubuntu-latest steps: - name: Checkout - uses: actions/checkout@fbc6f3992d24b796d5a048ff273f7fcc4a7b6c09 # v5.0.0 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - name: Set up Go - uses: actions/setup-go@924ae3a1cded613372ab5595356fb5720e22ba16 # v6.0.0 + uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 with: go-version: stable - name: Check every Go module for vulnerabilities @@ -74,7 +74,7 @@ jobs: artifact_count=$(find sbom -type f -name '*.cdx.json' -size +0c | wc -l | tr -d ' ') test "$module_count" -eq "$artifact_count" - name: Upload SBOMs - uses: actions/upload-artifact@330a01c490aca151604b8cf639adc76d48f6c5d4 # v5.0.0 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: cyclonedx-sboms path: sbom @@ -84,7 +84,7 @@ jobs: runs-on: ubuntu-latest steps: - name: Checkout complete history - uses: actions/checkout@fbc6f3992d24b796d5a048ff273f7fcc4a7b6c09 # v5.0.0 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: fetch-depth: 0 - name: Install Gitleaks diff --git a/.github/workflows/tests.yml b/.github/workflows/tests.yml index c3ee4b6..1db728b 100644 --- a/.github/workflows/tests.yml +++ b/.github/workflows/tests.yml @@ -29,11 +29,11 @@ jobs: WIRE_CACHE_MODE: ${{ matrix.cache-mode }} steps: - name: Install Go - uses: actions/setup-go@924ae3a1cded613372ab5595356fb5720e22ba16 # v6.0.0 + uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 with: go-version: ${{ matrix.go-version }} - name: Checkout code - uses: actions/checkout@fbc6f3992d24b796d5a048ff273f7fcc4a7b6c09 # v5.0.0 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: fetch-depth: 2 # required for codecov - name: Run Tests @@ -45,11 +45,11 @@ jobs: runs-on: ubuntu-latest steps: - name: Install Go - uses: actions/setup-go@924ae3a1cded613372ab5595356fb5720e22ba16 # v6.0.0 + uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 with: go-version: "1.19.x" - name: Checkout code - uses: actions/checkout@fbc6f3992d24b796d5a048ff273f7fcc4a7b6c09 # v5.0.0 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - name: Run Tests shell: bash run: 'internal/runtests.sh' @@ -59,10 +59,10 @@ jobs: steps: - name: Checkout - uses: actions/checkout@fbc6f3992d24b796d5a048ff273f7fcc4a7b6c09 # v5.0.0 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - name: Set up Go - uses: actions/setup-go@924ae3a1cded613372ab5595356fb5720e22ba16 # v6.0.0 + uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 with: go-version: "stable" @@ -73,6 +73,6 @@ jobs: run: go test ./internal/... -coverprofile=coverage.txt - name: Upload results to Codecov - uses: codecov/codecov-action@5a1091511ad55cbe89839c7260b706298ca349f7 # v5.5.1 + uses: codecov/codecov-action@e53489f4d376d79066609109e7a95a29eb3740b1 # v7.0.0 env: CODECOV_TOKEN: ${{ secrets.CODECOV_TOKEN }} From 1177b54c493cf5942a71823a8882b87174e1df7e Mon Sep 17 00:00:00 2001 From: Chris Miles Date: Sat, 5 Sep 2026 02:59:21 +0000 Subject: [PATCH 5/8] ci: enable dependency review --- .github/workflows/security.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/security.yml b/.github/workflows/security.yml index 58c38f9..e3e18d0 100644 --- a/.github/workflows/security.yml +++ b/.github/workflows/security.yml @@ -13,7 +13,7 @@ permissions: jobs: dependency-review: - if: github.event_name == 'pull_request' && vars.ENABLE_DEPENDENCY_REVIEW == 'true' + if: github.event_name == 'pull_request' runs-on: ubuntu-latest steps: - name: Review dependencies From f2184b7a4c03b6c4f4237dc8a65b0a87d1c6a135 Mon Sep 17 00:00:00 2001 From: Chris Miles Date: Sat, 5 Sep 2026 03:10:27 +0000 Subject: [PATCH 6/8] ci: use organization CodeQL scanning --- .github/workflows/codeql.yml | 43 ------------------------------------ 1 file changed, 43 deletions(-) delete mode 100644 .github/workflows/codeql.yml diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml deleted file mode 100644 index 75b7743..0000000 --- a/.github/workflows/codeql.yml +++ /dev/null @@ -1,43 +0,0 @@ -name: CodeQL - -on: - push: - branches: [main] - pull_request: - branches: [main] - schedule: - - cron: "29 3 * * 4" - workflow_dispatch: - -permissions: - contents: read - security-events: write - -jobs: - analyze: - runs-on: ubuntu-latest - steps: - - name: Checkout - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - - name: Set up Go - uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 - with: - go-version: stable - - name: Initialize CodeQL - uses: github/codeql-action/init@cdf488f595d80d6e07e03d4674febd5ab45fa938 # v4.37.9 - with: - languages: go - build-mode: manual - - name: Build every Go module for CodeQL - shell: bash - run: | - GOWORK=off go clean -cache - while IFS= read -r -d '' module; do - module_dir=${module%/go.mod} - ( - cd -- "$module_dir" - GOWORK=off go build ./... - ) - done < <(find . -name go.mod -type f -not -path './.git/*' -not -path './node_modules/*' -not -path './vendor/*' -print0) - - name: Analyze - uses: github/codeql-action/analyze@cdf488f595d80d6e07e03d4674febd5ab45fa938 # v4.37.9 From 519051b8380df8389396efc42c880480710ffc1f Mon Sep 17 00:00:00 2001 From: Chris Miles Date: Sat, 5 Sep 2026 07:57:42 +0000 Subject: [PATCH 7/8] fix: remediate transitive dependency advisories --- go.mod | 10 +++++----- go.sum | 16 ++++++++-------- 2 files changed, 13 insertions(+), 13 deletions(-) diff --git a/go.mod b/go.mod index 5db8855..61baf4d 100644 --- a/go.mod +++ b/go.mod @@ -1,17 +1,17 @@ module github.com/goforj/wire -go 1.19 +go 1.25.0 require ( github.com/fsnotify/fsnotify v1.7.0 github.com/google/go-cmp v0.6.0 github.com/google/subcommands v1.2.0 github.com/pmezard/go-difflib v1.0.0 - golang.org/x/tools v0.24.1 + golang.org/x/tools v0.49.0 ) require ( - golang.org/x/mod v0.20.0 // indirect - golang.org/x/sync v0.8.0 // indirect - golang.org/x/sys v0.23.0 // indirect + golang.org/x/mod v0.40.0 // indirect + golang.org/x/sync v0.22.0 // indirect + golang.org/x/sys v0.47.0 // indirect ) diff --git a/go.sum b/go.sum index 6fba262..2b0c19d 100644 --- a/go.sum +++ b/go.sum @@ -6,11 +6,11 @@ github.com/google/subcommands v1.2.0 h1:vWQspBTo2nEqTUFita5/KeEWlUL8kQObDFbub/EN github.com/google/subcommands v1.2.0/go.mod h1:ZjhPrFU+Olkh9WazFPsl27BQ4UPiG37m3yTrtFlrHVk= github.com/pmezard/go-difflib v1.0.0 h1:4DBwDE0NGyQoBHbLQYPwSUPoCMWR5BEzIk/f1lZbAQM= github.com/pmezard/go-difflib v1.0.0/go.mod h1:iKH77koFhYxTK1pcRnkKkqfTogsbg7gZNVY4sRDYZ/4= -golang.org/x/mod v0.20.0 h1:utOm6MM3R3dnawAiJgn0y+xvuYRsm1RKM/4giyfDgV0= -golang.org/x/mod v0.20.0/go.mod h1:hTbmBsO62+eylJbnUtE2MGJUyE7QWk4xUqPFrRgJ+7c= -golang.org/x/sync v0.8.0 h1:3NFvSEYkUoMifnESzZl15y791HH1qU2xm6eCJU5ZPXQ= -golang.org/x/sync v0.8.0/go.mod h1:Czt+wKu1gCyEFDUtn0jG5QVvpJ6rzVqr5aXyt9drQfk= -golang.org/x/sys v0.23.0 h1:YfKFowiIMvtgl1UERQoTPPToxltDeZfbj4H7dVUCwmM= -golang.org/x/sys v0.23.0/go.mod h1:/VUhepiaJMQUp4+oa/7Zr1D23ma6VTLIYjOOTFZPUcA= -golang.org/x/tools v0.24.1 h1:vxuHLTNS3Np5zrYoPRpcheASHX/7KiGo+8Y4ZM1J2O8= -golang.org/x/tools v0.24.1/go.mod h1:YhNqVBIfWHdzvTLs0d8LCuMhkKUgSUKldakyV7W/WDQ= +golang.org/x/mod v0.40.0 h1:hUv+3cXcdRHz08UmSiOob7sadHig73uo5bkXxQ/tvUs= +golang.org/x/mod v0.40.0/go.mod h1:0/weTWkPWGBikyTWAX3dkjVztMmBA5hM0DH6BElSupE= +golang.org/x/sync v0.22.0 h1:SZjpbeLmrCk4xhRSZFNZW5gFUeCeFgjekvI/+gfScek= +golang.org/x/sync v0.22.0/go.mod h1:9xrNwdLfx4jkKbNva9FpL6vEN7evnE43NNNJQ2LF3+0= +golang.org/x/sys v0.47.0 h1:o7XGOvZQCADBQQ4Y7VNq2dRWQR7JmOUW8Kxx4ZsNgWs= +golang.org/x/sys v0.47.0/go.mod h1:4GL1E5IUh+htKOUEOaiffhrAeqysfVGipDYzABqnCmw= +golang.org/x/tools v0.49.0 h1:3NI7VXzL9+1WZD52Dx2ttoPwD5DWrFGpl9mFZDlmisI= +golang.org/x/tools v0.49.0/go.mod h1:SJNXV9DBKT0UbdttsQjbfJlAE/q+y36++zo3uL3N0Oo= From 10cee8753e8c18e214fe3bdf64dcca627b6f5206 Mon Sep 17 00:00:00 2001 From: Chris Miles Date: Sat, 5 Sep 2026 08:01:23 +0000 Subject: [PATCH 8/8] docs: align the supported Go version --- .github/workflows/tests.yml | 4 ++-- README.md | 2 +- 2 files changed, 3 insertions(+), 3 deletions(-) diff --git a/.github/workflows/tests.yml b/.github/workflows/tests.yml index 1db728b..4a45dd1 100644 --- a/.github/workflows/tests.yml +++ b/.github/workflows/tests.yml @@ -41,13 +41,13 @@ jobs: run: 'internal/runtests.sh' minimum-go: - name: Go 1.19 on Linux + name: Go 1.25 on Linux runs-on: ubuntu-latest steps: - name: Install Go uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 with: - go-version: "1.19.x" + go-version: "1.25.x" - name: Checkout code uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - name: Run Tests diff --git a/README.md b/README.md index c094dbc..2a414d3 100644 --- a/README.md +++ b/README.md @@ -10,7 +10,7 @@ Go Reference License Go Test - Go version + Go version Latest tag