12 Commits
Author SHA1 Message Date
dependabot[bot]andJo 16b34348e8 chore(deps): bump the go-all group across 1 directory with 4 updates (#2982)
* chore(deps): bump the go-all group across 1 directory with 4 updates

Bumps the go-all group with 4 updates in the / directory: [github.com/stretchr/testify](https://github.com/stretchr/testify), [golang.org/x/net](https://github.com/golang/net), [golang.org/x/sys](https://github.com/golang/sys) and [golang.org/x/term](https://github.com/golang/term).


Updates `github.com/stretchr/testify` from 1.11.1 to 1.12.1
- [Release notes](https://github.com/stretchr/testify/releases)
- [Commits](https://github.com/stretchr/testify/compare/v1.11.1...v1.12.1)

Updates `golang.org/x/net` from 0.57.0 to 0.59.0
- [Commits](https://github.com/golang/net/compare/v0.57.0...v0.59.0)

Updates `golang.org/x/sys` from 0.47.0 to 0.48.0
- [Commits](https://github.com/golang/sys/compare/v0.47.0...v0.48.0)

Updates `golang.org/x/term` from 0.45.0 to 0.46.0
- [Commits](https://github.com/golang/term/compare/v0.45.0...v0.46.0)

---
updated-dependencies:
- dependency-name: github.com/stretchr/testify
  dependency-version: 1.12.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-all
- dependency-name: golang.org/x/net
  dependency-version: 0.59.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-all
- dependency-name: golang.org/x/sys
  dependency-version: 0.48.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-all
- dependency-name: golang.org/x/term
  dependency-version: 0.46.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-all
...

Signed-off-by: dependabot[bot] <support@github.com>

* fix(deps): keep go directive unpinned so CI uses latest patch

Dependabot's go mod tidy on a newer toolchain rewrote the directive to
go 1.26.0, which makes actions/setup-go (go-version-file: go.mod) install
exactly 1.26.0 instead of the latest 1.26.x patch. govulncheck then fails
on 18 standard-library CVEs already fixed in 1.26.6.

Restore the go 1.26 + toolchain form used on next.

* fix(ci): install latest Go 1.26 patch instead of pinning 1.26.0

The x/net, x/sys and x/term bumps declare go 1.26.0, so go mod tidy now
requires the module's go directive to be go 1.26.0 rather than go 1.26.
setup-go's go-version-file reads that directive verbatim and installs
exactly 1.26.0, which govulncheck flags for 18 standard-library CVEs
already fixed in later 1.26 patches.

Resolve the Go version from the 1.26 minor line so the latest patch is
installed.

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Jo <me@jguer.space>
2026-09-27 00:15:30 +02:00
CopilotandJguer 6749bf7682 Restrict GitHub Actions token permissions in flagged workflows (#2940)
* Initial plan

* Restrict GitHub workflow token permissions

Co-authored-by: Jguer <8071073+Jguer@users.noreply.github.com>

---------

Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
Co-authored-by: Jguer <8071073+Jguer@users.noreply.github.com>
2026-08-07 03:10:30 +00:00
CopilotandJguer 144bd4d4f0 ci: pin Go 1.26 in test workflows via setup-go (#2920)
* Initial plan

* ci: add explicit setup-go step to use Go 1.26 matching go.mod

Both testing.yml and testing-git.yml were relying on whatever Go version
shipped in ghcr.io/jguer/yay-builder:latest (Go 1.24.13), which is
incompatible with the go 1.26 / toolchain go1.26.0 declarations in
go.mod and scripts/go.mod, causing build/lint failures in PR #2917.

Add an actions/setup-go step (pinned to the same hash already used in
pages.yml) immediately after checkout so CI always picks up Go 1.26 as
read from go.mod, regardless of what the builder image contains.

Co-authored-by: Jguer <8071073+Jguer@users.noreply.github.com>

---------

Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
Co-authored-by: Jguer <8071073+Jguer@users.noreply.github.com>
2026-07-19 20:33:59 +02:00
Jo e03be81baa Lock actions in CI (#2829)
* update dockerfile

* lock actions

* remove dockerhub

* fix golangci-lint install in ci image
2026-06-05 09:59:47 +02:00
Jo 4501213a02 ci(yay): fix missing user (#2730)
* cleanup arch build

* don't doubleptade

* fix pacman-git build

* fix final issues with some sandbox kernels

* use quay because docker is out of steam

* remove docker hub

* -si on testing
2025-12-13 17:40:16 +01:00
Jo a300330b94 fix(ci): prefer ghcr image (#2589)
prefer ghcr image
2025-03-09 22:50:58 +01:00
Jo e8080f87c2 chore(yay): fix breaking -git ci test (#2373)
* chore(yay): fix breaking test

* chore(yay): fix breaking test

* chore(yay): fix breaking test

* update gomod

* remove debug commands
2024-02-19 17:04:06 +01:00
Jo 4e3c664ab3 ci(yay) : attempt to use caches more effectively in CI (#1862)
* attempt to use caches more effectively

* fix cache key

* specify cache file
2022-12-18 20:42:22 +00:00
Jo 0b1ae938a3 fix(ci): do not install packages at pacman-git CI level (#1860)
* fix(ci): do not attempt to install extra packages for building pacman-git

* install needed in ci image

* fix missing pacman key

* wip

* add missing deps
2022-12-18 18:24:56 +00:00
Jguer 44a0a243ed remove gock from completion package (#1764)
* remove gock from completion package

* fix ci builder

* undo changes to default flow
2022-06-17 16:49:41 +00:00
J Guerreiro ae01f8e4a0 feat(config): Add version marker (#1720)
* only run on PRs

* prefer manual tags

* add defaults for tests

* cuddle assignment
2022-03-04 23:30:15 +00:00
J Guerreiro dc9bef0115 fix(ci): fix builds against pacman-git (#1718)
* fix(ci): fix builds against pacman-git

* fix(ci): fix builds against pacman-git

* update dockerfile

* update dockerfile

* update dockerfile

* fix(ci): fix builds against pacman-git

* fix(ci): fix builds against pacman-git

* update go-alpm

* update alpm

* return to lopsided images

* go mod tidy
2022-03-04 23:04:55 +00:00