chore: stop vendoring dependencies (MAPCO-11521) - #38
Open
NivGreenstein wants to merge 3 commits into
Open
NivGreenstein wants to merge 3 commits into
NivGreenstein wants to merge 3 commits into
Conversation
The flag is redundant while vendor/ is committed: with vendor/modules.txt present and a go directive of 1.14 or later, the go command selects vendor mode on its own. Dropping it first keeps every build path working through the removal of vendor/ that follows, rather than breaking them in the same commit (MAPCO-11521). Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
vendor/ was 88% of the tracked files and 72% of the bytes, inherited from Tegola and kept only while the fork tracked it. It bought availability, not integrity -- go.sum already pins every module -- and it cost a formatting gate that had to carve it out and a `gofmt -s -w .` that rewrote 257 vendored files. Dependencies now resolve from the module cache against go.sum, and /vendor/ is ignored so a local `go mod vendor` cannot creep back in. The Dockerfile downloads modules in a layer of its own before copying source, so a source-only change reuses them. That download is now the container build's one network dependency; CONTRIBUTING.md records the decision and how to build offline from a seeded module cache or an internal proxy instead of reinstating vendor/ (MAPCO-11521). Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
A local `go mod vendor` is ignored by git but was still sent to the daemon, and with vendor/modules.txt present go build switches to vendor mode on its own -- the image would have built from that local copy rather than the go.sum-verified download. Exclude it, and say so in CONTRIBUTING.md for local builds. Also fixes prose the removal left stale: the .dockerignore header, the "vendored SDK" comment in cache/s3, the LICENSE/NOTICE wording, and the pipefail rationale the gofmt gate comment had dropped (MAPCO-11521). Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Coverage Report for CI Build 0Coverage remained the same at 56.828%Details
Uncovered ChangesNo uncovered changes found. Coverage RegressionsNo coverage regressions found. Coverage Stats
💛 - Coveralls |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Jira: MAPCO-11521 · Docs PR: MapColonies/shigola-docs#19
What and why
vendor/was 88% of the tracked files and 72% of the bytes. The fork inherited it from Tegola and kept it only while it tracked Tegola. It bought availability, not integrity, becausego.sumalready pins every module. Meanwhile it cost a formatting gate that had to carve it out, and agofmt -s -w .at the root that rewrote 257 vendored files.Dependencies now resolve from the module cache and are checked against
go.sum.7caa4403removes-mod vendorfrom the workflows and docs first. The flag was redundant: withvendor/modules.txtpresent, Go selects vendor mode on its own. So every build still works through the next commit.0cbfd0e8removesvendor/and adds/vendor/to.gitignore. The Dockerfile now downloads modules (go mod download) in a layer of its own, before copying the source. The gofmt gate becomesgit ls-files -z '*.go' | xargs -0 gofmt -s -l. A new "Dependencies" section inCONTRIBUTING.mdrecords the decision and gives the offline-build recipe (seededGOMODCACHE+GOPROXY=off, or an internal proxy) so nobody reinstatesvendor/by reflex.df6d61d7addsvendorto.dockerignore, a gap review found.go buildswitches to vendor mode whenevervendor/modules.txtexists, so without this entry a localgo mod vendorwould silently become what the image builds from. It also fixes prose the removal left stale.Base is
development, notmaster: the current work lives there and feature branches are cut from it.Two things the ticket had wrong
apk add build-base". That stopped being true when the build wentCGO_ENABLED=0, so before this PR the build stage was offline-capable. After it,go mod downloadis the build stage's one network dependency. CI and the release builds are networked, so nothing breaks, but it is a real change for anyone building air-gapped.Verification
All in
golang:1.26.6containers:go mod download,go mod verifyandgo mod tidy(no diff).go build ./..., plusCGO_ENABLED=0build and test-link.go vetwith both tag sets. The gofmt gate is clean.-tags lambda.norpc), darwin/arm64 and windows.docker buildproduces an image, andshigola versionruns from it. This also passes with a bogus localvendor/modules.txtpresent.GOPROXY=off go buildfrom a seeded cache (the documented offline recipe).go install github.com/mattn/goveralls, which the coverage upload uses.go test -race ./...on linux/amd64 withRUN_POSTGIS_TESTSandRUN_REDIS_TESTSon: green.CI has not run yet, so this PR's first run is the check for the release and CITE workflows.
Left out
-mod vendor/-mod=vendorstrings ininternal/build/*_test.go. They are arbitrary test inputs, not build assumptions.LICENSE.mdandNOTICE.mdis untouched. Only the paragraph that pointed atvendor/was reworded.🤖 Generated with Claude Code