Skip to content

Mirror golangci-lint v2.13.1 when hyperi-ci releases it #63

Description

@catinspace-au

Four tools in hyperi_versions are behind upstream. We cannot just bump them here: tools/check_version_pins.py fails the test run on ANY disagreement with hyperi-ci, which is the whole point of that check. So this is a two-repo change, hyperi-ci first, then mirror it here.

Current vs upstream latest, checked 2026-08-26:

  • osv-scanner v2.4.0 -> v2.5.1
  • golangci-lint v2.12.2 -> v2.13.1
  • govulncheck v1.1.4 -> v1.7.0 -- five minors behind, and it is the vulnerability scanner itself, so this one matters most
  • cargo-chef v0.1.77 -> v0.1.78

None of them has a published CVE, so nothing is on fire. govulncheck being five minors stale just means a pinned box scans with an older database than it should.

Worth knowing while you are in there: until the pin-plumbing fix lands, several of these pins were not being consumed at all, so a --pinned box installed latest regardless of what the map said. Bumping the numbers only helps once the pin is actually read.

DONE WHEN hyperi-ci carries the four new versions and hyperi_versions mirrors them with the pin check green.

Activity

  1. catinspace-au commented on Aug 30, 2026

    @catinspace-au
    ContributorAuthor

    Checked all four against hyperi-ci, and the title is wrong -- three of them are not stale in the sense that matters.

    check_version_pins.py enforces agreement with hyperi-ci, not with upstream. On that test:

    • osv-scanner v2.4.0 -- hyperi-ci pins v2.4.0. MATCHES.
    • govulncheck v1.1.4 -- hyperi-ci pins v1.1.4. MATCHES.
    • cargo-chef v0.1.77 -- hyperi-ci pins v0.1.77. MATCHES.
    • golangci-lint v2.12.2 -- hyperi-ci main carries v2.13.1. The only real divergence.

    So there is nothing to bump for three of the four, and doing it would turn the build red rather than green.

    The golangci-lint one is a timer, not a task. hyperi-ci main has v2.13.1 (06b9fdb, 2026-08-27) but has NOT released it -- latest tag is v2.9.24. And check_version_pins.py imports from the INSTALLED hyperi-ci, not from a clone, which is why it still reports ok (12 pin(s) match) today.

    The moment hyperi-ci cuts 2.9.25 and anyone reinstalls, this repo goes red until all.yml:44 becomes v2.13.1. That is the whole remaining job here, and it has to happen in that window -- landing it early breaks the check just as surely as landing it late.

    Retitled to match. Leaving open as the watch item; no code change in #70.

    Not checked: whether osv-scanner/govulncheck/cargo-chef have newer upstream releases. That is a hyperi-ci question, since it moves first.

  2. changed the title [-]Four hyperi_versions pins are stale, and hyperi-ci has to move first[/-] [+]Mirror golangci-lint v2.13.1 when hyperi-ci releases it[/+] on Aug 30, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions