Skip to content

chore: upgrade to Go 1.26 and refresh dependencies - #26

Merged
appleboy merged 2 commits into
mainfrom
chore/go-1.26-dependency-updates
Sep 12, 2026
Merged

appleboy merged 2 commits into
mainfrom
chore/go-1.26-dependency-updates

Conversation

@appleboy

@appleboy appleboy commented Sep 12, 2026 •

Copy link
Copy Markdown
Owner

Summary

Raise the minimum Go version and Docker builder to Go 1.26, and test Go 1.26 and 1.27 in CI with separate cache keys. Update declared Go dependencies and golangci-lint to current stable releases, including golangci-lint 2.13.2. Keep GitHub Actions on floating major-version tags where upstream provides them.

  • Upgrade appleboy/com to 1.2.1 and go-openai to 1.42.1; godump 0.11.1 is already current.
  • Preserve legacy max_tokens behavior for non-reasoning models and compatible services using narrowly scoped staticcheck exceptions for the SDK's new deprecation annotation.
  • Trivy Action 0.36.0 and Hadolint Action 3.5.0 are already current; retain these full versions because upstream does not publish v0 and v3 tags respectively. All other Action references use a single major version, and their tags were verified through the GitHub API.

Verification

From the repository root on chore/go-1.26-dependency-updates, with Go toolchain downloads enabled, a C compiler for race detection, golangci-lint 2.13.2, hadolint 2.14.0, and actionlint 1.7.12:

Command Result
GOTOOLCHAIN=go1.26.7 go test -race -cover ./... Passed; 68.1% coverage
GOTOOLCHAIN=go1.27.1 go test -race -cover ./... Passed; 67.5% coverage
golangci-lint run Passed; 0 issues
hadolint Dockerfile Passed
actionlint -shellcheck= Passed; shellcheck integration disabled locally
CGO_ENABLED=0 GOOS=linux go build -o /tmp/llm-action . Passed on Go 1.26.7
go mod tidy and go mod verify Passed; all modules verified
git diff --check Passed

Existing TestBuildChatRequest cases exercise explicit completion-token limits, reasoning-model fallback, and legacy max_tokens behavior. All passed in both Go test runs. No API credentials or live services are needed for these tests. Local build outputs and coverage were written outside the checkout. Hosted CI and a full Docker image build remain for CI verification.

Classification and review

Core change: toolchain and dependency changes affect the entire application. Please use two reviewers including the maintainer, with particular attention to SDK compatibility, minimum Go version, workflow versions, and cache separation.

AI authorship

  • AI used: Codex (GPT-6).
  • AI-authored changes: go.mod, go.sum, Dockerfile, CLAUDE.md, main.go, main_test.go, and the five workflows under .github/workflows (testing, docker, goreleaser, codeql, trivy).
  • Human line-by-line reviewed: None — not yet reviewed by a human.

Scope, risk, and rollback

Plan: upgrade the requested toolchain and dependencies, preserve request behavior, verify both Go versions, and open this PR. No issue reference supplied. No secrets or permission changes are included.

The minimum compiler version rises from Go 1.25 to 1.26. Dependency and Action updates may affect runtime or CI behavior. Revert this commit to restore the previous toolchain, dependency versions, and workflows together; no data migration is involved.

- Require Go 1.26 and test Go 1.26 and 1.27 with separate caches.
- Update Go modules and GitHub Actions to current stable versions.
- Preserve legacy token-limit compatibility with scoped lint exceptions.
Copilot AI lite review requested due to automatic review settings September 12, 2026 13:59
Comment thread Dockerfile
@@ -1,4 +1,4 @@
FROM golang:1.25-alpine AS builder
FROM golang:1.26-alpine AS builder
Comment thread Dockerfile
@@ -1,4 +1,4 @@
FROM golang:1.25-alpine AS builder
FROM golang:1.26-alpine AS builder

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔵 Needs a closer look

Broad toolchain, dependency, and CI workflow updates warrant final human review.

Pull request overview

Upgrades the project to Go 1.26, refreshes dependencies and CI actions, and preserves legacy token behavior.

Changes:

  • Updates Go, Docker, dependencies, and workflow actions.
  • Tests Go 1.26 and 1.27 with separate caches.
  • Maintains compatibility for legacy max_tokens behavior.
File summaries
File Description
main.go Preserves legacy token support with a targeted deprecation exception.
main_test.go Maintains compatibility test coverage.
go.sum Refreshes dependency checksums.
go.mod Updates Go and dependency versions.
Dockerfile Uses the Go 1.26 builder.
CLAUDE.md Updates documented tool versions.
.github/workflows/trivy.yml Pins updated scanning actions.
.github/workflows/testing.yml Tests Go 1.26 and 1.27 with separate caches.
.github/workflows/goreleaser.yml Pins updated release actions.
.github/workflows/docker.yml Pins updated Docker and scanning actions.
.github/workflows/codeql.yml Pins updated CodeQL actions.
Review details
  • Files reviewed: 10/11 changed files
  • Comments generated: 0
  • Review effort level: Lite

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

- Use floating major tags where upstream provides them.
- Retain exact Trivy and Hadolint versions because major tags are unavailable.
@appleboy
appleboy merged commit 13d0c02 into main Sep 12, 2026
9 of 11 checks passed
@appleboy
appleboy deleted the chore/go-1.26-dependency-updates branch September 12, 2026 14:05
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants