diff --git a/.github/dependabot.yml b/.github/dependabot.yml index 21170067..314d7ced 100644 --- a/.github/dependabot.yml +++ b/.github/dependabot.yml @@ -33,9 +33,13 @@ version: 2 # every one of them, and GPL-3.0 makes that a real question rather than # a formality. # -# None of these are merged on a green tick alone. Every one is checked locally -# first, with the full suite, before it is accepted - the owner's rule, and the -# reason the two points above are written here rather than left to be +# None of these are merged on a green tick alone. Every one is read before it +# is accepted: which files of the module changed between the two versions +# (diff the two copies in the module cache, not the release notes), whether +# anything the command line binary links is among them, and what the byte +# stability guards said. The full suite runs in CI on the pull request, on +# three systems - the owner's decision of 2026-09-22, replacing the earlier +# rule that it ran locally first. Written here rather than left to be # rediscovered on a Monday morning by whoever opens the pull request. # # Grouped for actions and ungrouped for Go on purpose. An action bump is one diff --git a/CHANGELOG.md b/CHANGELOG.md index 4245d57a..1fb45d87 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -16,6 +16,17 @@ because it turns other people's test suites red. ### Changed +- **Two names are compared with a corrected Unicode normaliser.** The + library that decides whether two file names are one name spelled two ways, + `golang.org/x/text`, moves from 0.41.0 to 0.42.0, and that release fixes how + a few rare sequences compose - a combining mark after a Hangul syllable, + and a mark that an earlier letter should have kept apart. A recipe naming + such a pair is now refused as a collision, where an older build wrote two + files that macOS would have stored as one. No generated byte moves: the + normaliser only compares names and never rewrites the one written to disk. + The window's `golang.org/x/image` (0.46.0, no code change) and + `golang.org/x/sys` (0.48.0) move with it, and the third-party notices name + the new numbers. - **The window says where things begin and end.** Every field's name now stands above its box rather than beside it, in a lighter ink than the value under it, so a form reads as a column of named boxes. A section diff --git a/THIRD-PARTY-NOTICES.md b/THIRD-PARTY-NOTICES.md index 208782d2..c4833c50 100644 --- a/THIRD-PARTY-NOTICES.md +++ b/THIRD-PARTY-NOTICES.md @@ -76,7 +76,7 @@ Source: ## golang.org/x/text -Version 0.41.0. Supplies Unicode normalisation, used to decide whether two file +Version 0.42.0. Supplies Unicode normalisation, used to decide whether two file names are one name spelled two ways. ``` @@ -273,9 +273,9 @@ is the module's own MIT, carried unchanged. | `github.com/srwiley/oksvg` | v0.0.0-20221011165216-be6e8873101c | BSD-3-Clause | (c) 2018, Steven R Wiley | | `github.com/srwiley/rasterx` | v0.0.0-20220730225603-2ab79fcdd4ef | BSD-3-Clause | (c) 2018, Steven R Wiley | | `github.com/yuin/goldmark` | v1.8.2 | MIT | (c) 2019 Yusuke Inuzuka | -| `golang.org/x/image` | v0.45.0 | BSD-3-Clause | 2009 The Go Authors. | +| `golang.org/x/image` | v0.46.0 | BSD-3-Clause | 2009 The Go Authors. | | `golang.org/x/net` | v0.57.0 | BSD-3-Clause | 2009 The Go Authors. | -| `golang.org/x/sys` | v0.47.0 | BSD-3-Clause | 2009 The Go Authors. | +| `golang.org/x/sys` | v0.48.0 | BSD-3-Clause | 2009 The Go Authors. | The five licence texts follow, one copy each. They differ only in the copyright line, which is in the table above for every module. diff --git a/go.mod b/go.mod index b26c01ce..df597672 100644 --- a/go.mod +++ b/go.mod @@ -74,8 +74,7 @@ require ( github.com/gen2brain/jxl v0.2.0 github.com/goccy/go-yaml v1.19.2 github.com/nicksnyder/go-i18n/v2 v2.6.1 - golang.org/x/image v0.45.0 - golang.org/x/text v0.41.0 + golang.org/x/text v0.42.0 ) require ( @@ -107,8 +106,9 @@ require ( github.com/srwiley/rasterx v0.0.0-20220730225603-2ab79fcdd4ef // indirect github.com/stretchr/testify v1.11.1 // indirect github.com/yuin/goldmark v1.8.2 // indirect + golang.org/x/image v0.46.0 // indirect golang.org/x/net v0.57.0 // indirect - golang.org/x/sys v0.47.0 // indirect + golang.org/x/sys v0.48.0 // indirect gopkg.in/yaml.v3 v3.0.1 // indirect ) diff --git a/go.sum b/go.sum index 191cc20e..a3831697 100644 --- a/go.sum +++ b/go.sum @@ -70,14 +70,14 @@ github.com/yuin/goldmark v1.8.2 h1:kEGpgqJXdgbkhcOgBxkC0X0PmoPG1ZyoZ117rDVp4zE= github.com/yuin/goldmark v1.8.2/go.mod h1:ip/1k0VRfGynBgxOz0yCqHrbZXhcjxyuS66Brc7iBKg= go.yaml.in/yaml/v3 v3.0.4 h1:tfq32ie2Jv2UxXFdLJdh3jXuOzWiL1fo0bu/FbuKpbc= go.yaml.in/yaml/v3 v3.0.4/go.mod h1:DhzuOOF2ATzADvBadXxruRBLzYTpT36CKvDb3+aBEFg= -golang.org/x/image v0.45.0 h1:FMb1nTbH5H9vF55SriQHgFw5GnNL9Jg6L25BwXKzhB0= -golang.org/x/image v0.45.0/go.mod h1:n62x/7RqlwXDvGsSU4u6IUTUf6KghUZ9Bt7cG/T9Fx4= +golang.org/x/image v0.46.0 h1:b1+oYj0Jbp6K5MDT4i4/eZpYlk3V8SJhhDKh6LBHAyQ= +golang.org/x/image v0.46.0/go.mod h1:3B3W05VGVQyuXucLINLjXKrqISASfi4Xj+iCVkLMwew= golang.org/x/net v0.57.0 h1:K5+3DljvIuDG9/Jv9rvyMywYNFCQ9RSUY6OOTTkT+tE= golang.org/x/net v0.57.0/go.mod h1:KpXc8iv+r3XplLAG/f7Jsf9RPszJzdR0f58q9vGOuEU= -golang.org/x/sys v0.47.0 h1:o7XGOvZQCADBQQ4Y7VNq2dRWQR7JmOUW8Kxx4ZsNgWs= -golang.org/x/sys v0.47.0/go.mod h1:4GL1E5IUh+htKOUEOaiffhrAeqysfVGipDYzABqnCmw= -golang.org/x/text v0.41.0 h1:vz/seA0lnX87Othu2f/0L24RcgrXD9/YFTSuGjj3rH8= -golang.org/x/text v0.41.0/go.mod h1:jvf1O8ajNzZqhSrQBPbutR/EB83Cc0CFrezNQIwbb5M= +golang.org/x/sys v0.48.0 h1:bbX/i/6MgT9BVLM9RT1thmxL04yeTAhbEz4SyadbXoo= +golang.org/x/sys v0.48.0/go.mod h1:hNLxWAXmnKAxqDtdwIYC4bM9oQPEecfsnNMuSxOs3og= +golang.org/x/text v0.42.0 h1:JbOZXgfeCPU9gacVtYliJqOhD+zhrEqK4LfdpmlUZqI= +golang.org/x/text v0.42.0/go.mod h1:ojzP1Z+2QtioaF8DTtO8K5q7JWVVYwZKenzujK0Zd0E= gopkg.in/check.v1 v0.0.0-20161208181325-20d25e280405/go.mod h1:Co6ibVJAznAaIkqp8huTwlJQCZ016jof/cbN4VW5Yz0= gopkg.in/check.v1 v1.0.0-20200227125254-8fa46927fb4f h1:BLraFXnmrev5lT+xlilqcH8XK9/i0At2xKjWk4p6zsU= gopkg.in/check.v1 v1.0.0-20200227125254-8fa46927fb4f/go.mod h1:Co6ibVJAznAaIkqp8huTwlJQCZ016jof/cbN4VW5Yz0= diff --git a/internal/format/webp/webp.go b/internal/format/webp/webp.go index 95d4fc5c..e6ef60c0 100644 --- a/internal/format/webp/webp.go +++ b/internal/format/webp/webp.go @@ -8,10 +8,11 @@ // // Written by hand rather than taken from a library, and the reason is // measured rather than assumed: x/image/webp holds decode.go and doc.go and -// nothing else, so the ecosystem offers no encoder to take. Checked at v0.43.0 -// and again at v0.45.0 on 2026-09-02, when the module was raised - a claim -// about what somebody else ships has to be re-read when their version moves, -// not carried across with the number changed. Pure Go +// nothing else, so the ecosystem offers no encoder to take. Checked at v0.43.0, +// again at v0.45.0 on 2026-09-02 and again at v0.46.0 on 2026-09-22, each time +// the module was raised - a claim about what somebody else ships has to be +// re-read when their version moves, not carried across with the number +// changed. Pure Go // encoders exist outside it, and taking one would have put somebody else's // release inside the byte stability contract D11 - their next version would // move the hashes in our users' test suites. See docs/STACK.md section 4.2.