chore: upgrade to Go 1.26 and refresh dependencies - #26
Merged
Merged
Conversation
- Require Go 1.26 and test Go 1.26 and 1.27 with separate caches. - Update Go modules and GitHub Actions to current stable versions. - Preserve legacy token-limit compatibility with scoped lint exceptions.
| @@ -1,4 +1,4 @@ | |||
| FROM golang:1.25-alpine AS builder | |||
| FROM golang:1.26-alpine AS builder | |||
| @@ -1,4 +1,4 @@ | |||
| FROM golang:1.25-alpine AS builder | |||
| FROM golang:1.26-alpine AS builder | |||
Contributor
There was a problem hiding this comment.
🔵 Needs a closer look
Broad toolchain, dependency, and CI workflow updates warrant final human review.
Pull request overview
Upgrades the project to Go 1.26, refreshes dependencies and CI actions, and preserves legacy token behavior.
Changes:
- Updates Go, Docker, dependencies, and workflow actions.
- Tests Go 1.26 and 1.27 with separate caches.
- Maintains compatibility for legacy
max_tokensbehavior.
File summaries
| File | Description |
|---|---|
main.go |
Preserves legacy token support with a targeted deprecation exception. |
main_test.go |
Maintains compatibility test coverage. |
go.sum |
Refreshes dependency checksums. |
go.mod |
Updates Go and dependency versions. |
Dockerfile |
Uses the Go 1.26 builder. |
CLAUDE.md |
Updates documented tool versions. |
.github/workflows/trivy.yml |
Pins updated scanning actions. |
.github/workflows/testing.yml |
Tests Go 1.26 and 1.27 with separate caches. |
.github/workflows/goreleaser.yml |
Pins updated release actions. |
.github/workflows/docker.yml |
Pins updated Docker and scanning actions. |
.github/workflows/codeql.yml |
Pins updated CodeQL actions. |
Review details
- Files reviewed: 10/11 changed files
- Comments generated: 0
- Review effort level: Lite
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
- Use floating major tags where upstream provides them. - Retain exact Trivy and Hadolint versions because major tags are unavailable.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Raise the minimum Go version and Docker builder to Go 1.26, and test Go 1.26 and 1.27 in CI with separate cache keys. Update declared Go dependencies and golangci-lint to current stable releases, including golangci-lint 2.13.2. Keep GitHub Actions on floating major-version tags where upstream provides them.
Verification
From the repository root on
chore/go-1.26-dependency-updates, with Go toolchain downloads enabled, a C compiler for race detection, golangci-lint 2.13.2, hadolint 2.14.0, and actionlint 1.7.12:GOTOOLCHAIN=go1.26.7 go test -race -cover ./...GOTOOLCHAIN=go1.27.1 go test -race -cover ./...golangci-lint runhadolint Dockerfileactionlint -shellcheck=CGO_ENABLED=0 GOOS=linux go build -o /tmp/llm-action .go mod tidyandgo mod verifygit diff --checkExisting TestBuildChatRequest cases exercise explicit completion-token limits, reasoning-model fallback, and legacy max_tokens behavior. All passed in both Go test runs. No API credentials or live services are needed for these tests. Local build outputs and coverage were written outside the checkout. Hosted CI and a full Docker image build remain for CI verification.
Classification and review
Core change: toolchain and dependency changes affect the entire application. Please use two reviewers including the maintainer, with particular attention to SDK compatibility, minimum Go version, workflow versions, and cache separation.
AI authorship
Scope, risk, and rollback
Plan: upgrade the requested toolchain and dependencies, preserve request behavior, verify both Go versions, and open this PR. No issue reference supplied. No secrets or permission changes are included.
The minimum compiler version rises from Go 1.25 to 1.26. Dependency and Action updates may affect runtime or CI behavior. Revert this commit to restore the previous toolchain, dependency versions, and workflows together; no data migration is involved.