Skip to content

chore(deps): bump minor Go dependencies - #168

Open
fullstackjam wants to merge 1 commit into
chore/go-1.26from
chore/deps-minor
Open

fullstackjam wants to merge 1 commit into
chore/go-1.26from
chore/deps-minor

Conversation

@fullstackjam

Copy link
Copy Markdown
Member

What does this PR do?

Minor and patch bumps for the direct Go dependencies:

Module From To
charmbracelet/bubbletea v1.3.0 v1.3.10
charmbracelet/lipgloss v1.0.0 v1.1.0
spf13/cobra v1.8.1 v1.10.2 (pflag v1.0.5 → v1.0.9)
stretchr/testify v1.11.1 v1.12.1
golang.org/x/term v0.39.0 v0.46.0
golang.org/x/sys v0.40.0 v0.48.0

Stacked on #166. Current x/term and x/sys require go >= 1.26.0, so this PR's base is chore/go-1.26. Merge #166 first. GitHub then retargets this PR to main.

Why?

  • Routine currency. bubbletea has seven patch releases of fixes since v1.3.0.
  • x/sys v0.44+ fixes GO-2026-5024. That one is Windows-only and unreachable for us, but it was the last govulncheck finding.

Testing

  • go vet ./... passes (go1.26.8)
  • make test-unit (L1): 24/24 packages ok
  • golangci-lint v2.11.4: 0 issues
  • govulncheck: No vulnerabilities found
  • TTY rendering check. Unit tests don't cover terminal output, and lipgloss 1.1 changes color-profile detection while x/ansi jumps 0.8 → 0.10. So I built before and after binaries and drove both through openboot install -p minimal --dry-run in a 110×36 tmux pane (TERM=xterm-256color, COLORTERM=truecolor) with the same keystrokes. The six screens covered initial select, move+toggle, filter, catalog pane, review plan, and the dry-run apply. Captures including ANSI escape sequences are byte-identical between before and after.
  • Relevant tests added or updated: n/a, dependency bump only

Cross-repo checklist

  • Does this need a docs/content update in openboot.dev? No
  • Does this change the CLI ↔ server API contract? No

Notes for reviewer

  • Limitation of the TTY check: in the "filter" step the typed /git didn't visibly register, so that screen equals the previous one on both binaries. Filter-mode rendering wasn't separately exercised. Other terminals and color profiles (Apple Terminal 256-color, NO_COLOR) weren't compared.
  • testify v1.12 internalizes go-spew/go-difflib, which is why those indirect entries disappear and go.yaml.in/yaml/v3 appears.
  • bubbles and huh v1.0 are intentionally left for a separate PR.

  bubbletea v1.3.0 -> v1.3.10
  lipgloss  v1.0.0 -> v1.1.0
  cobra     v1.8.1 -> v1.10.2 (pflag v1.0.5 -> v1.0.9)
  testify   v1.11.1 -> v1.12.1
  x/term    v0.39.0 -> v0.46.0
  x/sys     v0.40.0 -> v0.48.0 (fixes GO-2026-5024, Windows-only)

x/term and x/sys now require go >= 1.26.0, so this sits on top of the
Go 1.26.8 toolchain bump.

vet, L1 (make test-unit), golangci-lint v2.11.4 clean; govulncheck
reports no vulnerabilities. Because lipgloss 1.1 changes color-profile
detection and x/ansi jumps 0.8 -> 0.10, the TTY wizard was also driven
through six screens in a fixed-size tmux pane with before/after
binaries: captures including ANSI escapes are byte-identical.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant