Skip to content

chore(deps): bump github.com/gobwas/glob from 0.2.3 to 1.0.0 (fix 2109) - #2112

Draft
frewilhelm wants to merge 5 commits into
open-component-model:mainfrom
frewilhelm:fix-2109
Draft

frewilhelm wants to merge 5 commits into
open-component-model:mainfrom
frewilhelm:fix-2109

Conversation

@frewilhelm

@frewilhelm frewilhelm commented Sep 14, 2026 •

Copy link
Copy Markdown
Contributor

Fixes #2109

The new release introduces a breaking change replacing the Glob type with Pattern.

We might postpone this upgrade as there is no security vulnerability or the like that requires us to upgrade.

dependabot Bot and others added 2 commits September 14, 2026 10:58
Bumps [github.com/gobwas/glob](https://github.com/gobwas/glob) from 0.2.3 to 1.0.0.
- [Release notes](https://github.com/gobwas/glob/releases)
- [Commits](gobwas/glob@v0.2.3...v1.0.0)

---
updated-dependencies:
- dependency-name: github.com/gobwas/glob
  dependency-version: 1.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: Frederic Wilhelm <frederic.wilhelm@sap.com>
@github-actions github-actions Bot added kind/chore chore, maintenance, etc. kind/dependency dependency update, etc. size/s Small and removed kind/chore chore, maintenance, etc. labels Sep 14, 2026
@frewilhelm

Copy link
Copy Markdown
Contributor Author

golangci-lint has not catched up yet. Until then, we cannot merge this PR

@frewilhelm

Copy link
Copy Markdown
Contributor Author

Why CI is red, and a way forward

The code change itself is correct and complete — glob.Glob → *glob.Pattern is the only API break in gobwas/glob v1.0.0, and api/ocm/selectors/refsel/interface.go is the sole consumer. go build ./..., go vet, and go mod tidy are all clean.

The failing check is Lint Golang, and it is not about this code:

github.com/OpenPeeDeeP/depguard/v2 .../settings.go:31: undefined: glob.Glob
github.com/ghostiam/protogetter   .../protogetter.go:76: undefined: glob.Glob
github.com/tomarrell/wrapcheck/v2 .../wrapcheck.go:114: undefined: glob.Glob

golangci-lint is pinned as a go tool directive in the main go.mod, which pulls its plugins (depguard, protogetter, wrapcheck, …) into our module graph. Those plugins still use the old glob.Glob API. Go modules allow only one version of github.com/gobwas/glob, and the project kept the import path across a breaking rename, so bumping to v1.0.0 fails to compile the linter toolchain.

Verified fix: move lint tooling into a separate module

Split golangci-lint into its own tools/ module so its dependency graph (incl. glob v0.2.3) is isolated from the main module (glob v1.0.0). This is the same structure open-component-model/open-component-model already uses.

Changes:

  • tools/go.mod (new): golangci-lint as a tool directive; keeps glob v0.2.3 isolated.
  • go.mod (main): drop golangci-lint from tool (...); go mod tidy removes all linter-only deps (-153 go.mod / -372 go.sum). Keeps glob v1.0.0.
  • Makefile: build the binary from the tools module (go -C tools install ...) instead of go tool golangci-lint; check/check-fix run the built binary.
  • .github/dependabot.yml: a gomod entry watching /tools so Dependabot keeps golangci-lint current (version now lives in tools/go.mod, not a Makefile var).

What was tested locally (on this branch)

Check Result
main go.mod glob version v1.0.0, 0 linter plugins remaining
go build ./... (main module) pass
go vet ./api/ocm/selectors/refsel/... pass
go test ./api/ocm/selectors/... pass
golangci-lint (built from tools module) on refsel pkg 0 issues (was 11x undefined: glob.Glob)
glob isolation in tools module v0.2.3, separate graph
make golangci-lint → make check wiring pass, v2.3.1
tools/go.mod go mod tidy stable
format tools (gci/goimports/gofumpt) still in main pass

Open question

There is no urgency: the PR author already noted no security driver. Two independent decisions:

  1. The glob bump itself — low value, fine to postpone.
  2. Decoupling lint tooling from the shipped module — a worthwhile hygiene change on its own merits, independent of the bump.

If the Check for diff after go mod tidy job should also cover /tools, that workflow needs to run tidy there too.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

kind/chore chore, maintenance, etc. kind/dependency dependency update, etc. size/s Small

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant