-
Notifications
You must be signed in to change notification settings - Fork 157
Closed
Description
Stop bumping go directive unless necessitated by other dependencies
There is nothing necessitating this bump.
❯ go mod graph | grep go@1.23.4 github.com/sigstore/fulcio go@1.23.4 go@1.23.4 toolchain@go1.23.4
❯ go mod graph | grep go@1.23.| grep -v fulcio chainguard.dev/go-grpc-kit@v0.17.7 go@1.23.1 chainguard.dev/sdk@v0.1.29 go@1.23.3 go@1.23.4 toolchain@go1.23.4
The minimum should be 1.23.3 without fulcio's own bump.
Stop the minimum virus :D
This repo by itself should not be enforcing minimum on other repositories importing it. Stop spreading "minimum virus"
toolchain version used will be defined outside of go.mod ideally, such as by installing a newer compatible go toolchain to ci/cd/development env.
Failing that, toolchain directive should be used instead of go directive for bumping versions to not cascade minimum versions to importing dependencies.
High profile repos that have removed/reduced minimum go patch version per user requests
Being proactive to prevent following from reoccuring
Metadata
Metadata
Assignees
Labels
No labels