* chore(deps): bump the go-all group across 1 directory with 4 updates
Bumps the go-all group with 4 updates in the / directory: [github.com/stretchr/testify](https://github.com/stretchr/testify), [golang.org/x/net](https://github.com/golang/net), [golang.org/x/sys](https://github.com/golang/sys) and [golang.org/x/term](https://github.com/golang/term).
Updates `github.com/stretchr/testify` from 1.11.1 to 1.12.1
- [Release notes](https://github.com/stretchr/testify/releases)
- [Commits](https://github.com/stretchr/testify/compare/v1.11.1...v1.12.1)
Updates `golang.org/x/net` from 0.57.0 to 0.59.0
- [Commits](https://github.com/golang/net/compare/v0.57.0...v0.59.0)
Updates `golang.org/x/sys` from 0.47.0 to 0.48.0
- [Commits](https://github.com/golang/sys/compare/v0.47.0...v0.48.0)
Updates `golang.org/x/term` from 0.45.0 to 0.46.0
- [Commits](https://github.com/golang/term/compare/v0.45.0...v0.46.0)
---
updated-dependencies:
- dependency-name: github.com/stretchr/testify
dependency-version: 1.12.1
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: go-all
- dependency-name: golang.org/x/net
dependency-version: 0.59.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: go-all
- dependency-name: golang.org/x/sys
dependency-version: 0.48.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: go-all
- dependency-name: golang.org/x/term
dependency-version: 0.46.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: go-all
...
Signed-off-by: dependabot[bot] <support@github.com>
* fix(deps): keep go directive unpinned so CI uses latest patch
Dependabot's go mod tidy on a newer toolchain rewrote the directive to
go 1.26.0, which makes actions/setup-go (go-version-file: go.mod) install
exactly 1.26.0 instead of the latest 1.26.x patch. govulncheck then fails
on 18 standard-library CVEs already fixed in 1.26.6.
Restore the go 1.26 + toolchain form used on next.
* fix(ci): install latest Go 1.26 patch instead of pinning 1.26.0
The x/net, x/sys and x/term bumps declare go 1.26.0, so go mod tidy now
requires the module's go directive to be go 1.26.0 rather than go 1.26.
setup-go's go-version-file reads that directive verbatim and installs
exactly 1.26.0, which govulncheck flags for 18 standard-library CVEs
already fixed in later 1.26 patches.
Resolve the Go version from the 1.26 minor line so the latest patch is
installed.
---------
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Jo <me@jguer.space>
* Initial plan
* ci: add explicit setup-go step to use Go 1.26 matching go.mod
Both testing.yml and testing-git.yml were relying on whatever Go version
shipped in ghcr.io/jguer/yay-builder:latest (Go 1.24.13), which is
incompatible with the go 1.26 / toolchain go1.26.0 declarations in
go.mod and scripts/go.mod, causing build/lint failures in PR #2917.
Add an actions/setup-go step (pinned to the same hash already used in
pages.yml) immediately after checkout so CI always picks up Go 1.26 as
read from go.mod, regardless of what the builder image contains.
Co-authored-by: Jguer <8071073+Jguer@users.noreply.github.com>
---------
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
Co-authored-by: Jguer <8071073+Jguer@users.noreply.github.com>
* cleanup arch build
* don't doubleptade
* fix pacman-git build
* fix final issues with some sandbox kernels
* use quay because docker is out of steam
* remove docker hub
* -si on testing
* fix(ci): do not attempt to install extra packages for building pacman-git
* install needed in ci image
* fix missing pacman key
* wip
* add missing deps