Files
dependabot[bot]andJo 16b34348e8 chore(deps): bump the go-all group across 1 directory with 4 updates (#2982)
* chore(deps): bump the go-all group across 1 directory with 4 updates

Bumps the go-all group with 4 updates in the / directory: [github.com/stretchr/testify](https://github.com/stretchr/testify), [golang.org/x/net](https://github.com/golang/net), [golang.org/x/sys](https://github.com/golang/sys) and [golang.org/x/term](https://github.com/golang/term).


Updates `github.com/stretchr/testify` from 1.11.1 to 1.12.1
- [Release notes](https://github.com/stretchr/testify/releases)
- [Commits](https://github.com/stretchr/testify/compare/v1.11.1...v1.12.1)

Updates `golang.org/x/net` from 0.57.0 to 0.59.0
- [Commits](https://github.com/golang/net/compare/v0.57.0...v0.59.0)

Updates `golang.org/x/sys` from 0.47.0 to 0.48.0
- [Commits](https://github.com/golang/sys/compare/v0.47.0...v0.48.0)

Updates `golang.org/x/term` from 0.45.0 to 0.46.0
- [Commits](https://github.com/golang/term/compare/v0.45.0...v0.46.0)

---
updated-dependencies:
- dependency-name: github.com/stretchr/testify
  dependency-version: 1.12.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-all
- dependency-name: golang.org/x/net
  dependency-version: 0.59.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-all
- dependency-name: golang.org/x/sys
  dependency-version: 0.48.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-all
- dependency-name: golang.org/x/term
  dependency-version: 0.46.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-all
...

Signed-off-by: dependabot[bot] <support@github.com>

* fix(deps): keep go directive unpinned so CI uses latest patch

Dependabot's go mod tidy on a newer toolchain rewrote the directive to
go 1.26.0, which makes actions/setup-go (go-version-file: go.mod) install
exactly 1.26.0 instead of the latest 1.26.x patch. govulncheck then fails
on 18 standard-library CVEs already fixed in 1.26.6.

Restore the go 1.26 + toolchain form used on next.

* fix(ci): install latest Go 1.26 patch instead of pinning 1.26.0

The x/net, x/sys and x/term bumps declare go 1.26.0, so go mod tidy now
requires the module's go directive to be go 1.26.0 rather than go 1.26.
setup-go's go-version-file reads that directive verbatim and installs
exactly 1.26.0, which govulncheck flags for 18 standard-library CVEs
already fixed in later 1.26 patches.

Resolve the Go version from the 1.26 minor line so the latest patch is
installed.

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Jo <me@jguer.space>
2026-09-27 00:15:30 +02:00

56 lines
1.7 KiB
YAML

name: Test against pacman
on:
pull_request:
permissions:
contents: read
jobs:
build:
name: Lint and test yay
runs-on: ubuntu-latest
container:
image: ghcr.io/jguer/yay-builder:latest
steps:
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
- uses: actions/setup-go@40f1582b2485089dde7abd97c1529aa768e1baff # v5.6.0
with:
# Use the latest 1.26.x patch (go.mod pins go 1.26.0, which
# setup-go would otherwise resolve to that exact patch release).
go-version: "1.26"
- uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5.0.5
with:
path: ~/go/pkg/mod
key: ${{ runner.os }}-go-${{ hashFiles('**/go.sum') }}
restore-keys: |
${{ runner.os }}-go-
- name: Lint
env:
GOFLAGS: -buildvcs=false -tags=next
run: /app/bin/golangci-lint run -v ./...
- name: Vulnerability scan
env:
GOFLAGS: -buildvcs=false
run: go run golang.org/x/vuln/cmd/govulncheck@latest ./...
- name: Run Build and Tests
run: make test
- name: Run Integration Tests
continue-on-error: true
run: |
useradd -m yay &&
chown -R yay:yay . &&
cp -r ~/go/ /home/yay/go/ &&
chown -R yay:yay /home/yay/go/ &&
su yay -c "make test-integration"
- name: Build yay Artifact
env:
GOFLAGS: -buildvcs=false -tags=next
run: make
- name: Upload yay Artifact
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: yay
path: ./yay
if-no-files-found: error
overwrite: true