Skip to content

Conversation

mostafa
Copy link
Member

@mostafa mostafa commented Mar 4, 2025

Ticket(s)

N/A

Description

  • Update Go to v1.24
  • Update deps

Related PRs

N/A

Development Checklist

  • I have added a descriptive title to this PR.
  • I have squashed related commits together.
  • I have rebased my branch on top of the latest main branch.
  • I have performed a self-review of my own code.
  • I have commented on my code, particularly in hard-to-understand areas.
  • I have added docstring(s) to my code.
  • I have made corresponding changes to the documentation (docs).
  • I have updated docs using make gen-docs command.
  • I have added tests for my changes.
  • I have signed all the commits.

Legal Checklist

Copy link

github-actions bot commented Mar 4, 2025

Overview

Image reference ghcr.io/gatewayd-io/gatewayd:3548171 gatewaydio/gatewayd:latest
- digest e99346b40ff2 383013efa302
- tag 3548171 latest
- provenance b6df86a
- vulnerabilities critical: 0 high: 0 medium: 0 low: 0 critical: 1 high: 5 medium: 6 low: 0
- platform linux/amd64 linux/amd64
- size 21 MB 18 MB (-3.5 MB)
- packages 145 140 (-5)
Base Image alpine:3
also known as:
3.21
3.21.3
latest
alpine:3.20
also known as:
3
latest
- vulnerabilities critical: 0 high: 0 medium: 0 low: 0 critical: 0 high: 1 medium: 3 low: 0
Packages and Vulnerabilities (63 package changes and 6 vulnerability changes)
  • ➕ 2 packages added
  • ➖ 6 packages removed
  • ♾️ 55 packages changed
  • 79 packages unchanged
  • ❗ 6 vulnerabilities added
Changes for packages of type apk (19 changes)
Package Version
ghcr.io/gatewayd-io/gatewayd:3548171
Version
gatewaydio/gatewayd:latest
alpine-base 3.21.3-r0
♾️ alpine-baselayout 3.6.8-r1 3.6.5-r0
♾️ alpine-baselayout-data 3.6.8-r1 3.6.5-r0
♾️ alpine-keys 2.5-r0 2.4-r1
alpine-release 3.21.3-r0
♾️ apk-tools 2.14.6-r3 2.14.4-r0
♾️ busybox 1.37.0-r12 1.36.1-r29
♾️ busybox-binsh 1.37.0-r12 1.36.1-r29
ca-certificates 20241121-r1
♾️ ca-certificates-bundle 20241121-r1 20240705-r0
♾️ libcrypto3 3.3.3-r0 3.3.2-r0
♾️ libssl3 3.3.3-r0 3.3.2-r0
♾️ musl 1.2.5-r9 1.2.5-r0
♾️ musl-utils 1.2.5-r9 1.2.5-r0
critical: 0 high: 1 medium: 0 low: 0
Added vulnerabilities (1):
  • high : CVE--2025--26519
openssl 3.3.3-r0
pax-utils 1.3.8-r1
♾️ scanelf 1.3.8-r1 1.3.7-r2
♾️ ssl_client 1.37.0-r12 1.36.1-r29
♾️ zlib 1.3.1-r2 1.3.1-r1
Changes for packages of type golang (44 changes)
Package Version
ghcr.io/gatewayd-io/gatewayd:3548171
Version
gatewaydio/gatewayd:latest
♾️ github.com/cpuguy83/go-md2man/v2 2.0.6 2.0.4
♾️ github.com/envoyproxy/protoc-gen-validate 1.2.1 1.1.0
♾️ github.com/gatewayd-io/gatewayd 0.0.0-20250305212227-354817166e09 0.0.0-20241214123014-b6df86a6fe94
♾️ github.com/gatewayd-io/gatewayd-plugin-sdk 0.4.1 0.3.5
♾️ github.com/getsentry/sentry-go 0.31.1 0.30.0
♾️ github.com/go-git/go-billy/v5 5.6.0 5.5.0
♾️ github.com/go-git/go-git/v5 5.13.0 5.12.0
critical: 1 high: 1 medium: 0 low: 0
Added vulnerabilities (2):
  • critical : CVE--2025--21613
  • high : CVE--2025--21614
♾️ github.com/google/go-github/v53 68.0.0 53.2.0
♾️ github.com/grpc-ecosystem/grpc-gateway/v2 2.26.3 2.24.0
github.com/hashicorp/go-metrics 0.5.4
♾️ github.com/hashicorp/go-plugin 1.6.3 1.6.2
♾️ github.com/hashicorp/raft 1.7.2 1.7.1
♾️ github.com/hashicorp/raft-boltdb 0.0.0-20250225060035-8f7048cdfa53 0.0.0-20241202213821-f9dd2ba30efd
♾️ github.com/invopop/jsonschema 0.13.0 0.12.0
♾️ github.com/jackc/pgx/v5 5.7.2 5.7.1
♾️ github.com/mattn/go-colorable 0.1.14 0.1.13
♾️ github.com/pganalyze/pg_query_go/v5 6.0.0 5.1.0
♾️ github.com/prometheus/client_golang 1.21.1 1.20.5
♾️ github.com/prometheus/common 0.62.0 0.61.0
♾️ github.com/protonmail/go-crypto 1.1.3 1.0.0
♾️ github.com/redis/go-redis/v9 9.7.1 9.7.0
♾️ github.com/spf13/cast 1.7.1 1.7.0
♾️ github.com/spf13/cobra 1.9.1 1.8.1
♾️ github.com/spf13/pflag 1.0.6 1.0.5
♾️ github.com/tetratelabs/wazero 1.9.0 1.8.2
♾️ github.com/wasilibs/go-pgquery 0.0.0-20250219053243-148840c597e6 0.0.0-20241011013927-817756c5aae4
♾️ github.com/wasilibs/wazero-helpers 0.0.0-20250123031827-cd30c44769bb 0.0.0-20240620070341-3dff1577cd52
♾️ go.opentelemetry.io/otel 1.34.0 1.33.0
♾️ go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc 1.34.0 1.33.0
♾️ go.opentelemetry.io/otel/metric 1.34.0 1.33.0
♾️ go.opentelemetry.io/otel/sdk 1.34.0 1.33.0
♾️ go.opentelemetry.io/otel/trace 1.34.0 1.33.0
♾️ go.opentelemetry.io/proto/otlp 1.5.0 1.4.0
♾️ golang.org/x/crypto 0.35.0 0.31.0
critical: 0 high: 1 medium: 0 low: 0
Added vulnerabilities (1):
  • high : CVE--2025--22869
golang.org/x/exp 0.0.0-20241210194714-1829a127f884
♾️ golang.org/x/net 0.35.0 0.32.0
critical: 0 high: 1 medium: 0 low: 0
Added vulnerabilities (1):
  • high : CVE--2024--45338
golang.org/x/oauth2 0.24.0
critical: 0 high: 1 medium: 0 low: 0
Added vulnerabilities (1):
  • high : CVE--2025--22868
♾️ golang.org/x/sync 0.11.0 0.10.0
♾️ golang.org/x/sys 0.30.0 0.28.0
♾️ golang.org/x/text 0.22.0 0.21.0
♾️ google.golang.org/genproto/googleapis/rpc 0.0.0-20250303144028-a0af3efb3deb 0.0.0-20241209162323-e6fa225c2576
♾️ google.golang.org/grpc 1.71.0 1.69.0
♾️ google.golang.org/protobuf 1.36.5 1.35.2
♾️ stdlib go1.24.1 1.23.4

@mostafa mostafa requested a review from Copilot March 4, 2025 22:28
Copy link

@Copilot Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

PR Overview

This PR updates the Go version and related dependencies to v1.24 while replacing usage of context.Background() with the test-provided context (t.Context()) in tests. In addition, it adds explicit calls to discard the HTTP request body in several API endpoints.

Reviewed Changes

File Description
api/v1/api.pb.gw.go Added io.Copy calls to discard request bodies in API endpoints.
api/http_server_test.go Replaced context.Background() with t.Context() in HTTP server tests.
.github/workflows/release.yaml Updated Go version from 1.23 to 1.24.
.github/workflows/test.yaml Updated Go version from 1.23 to 1.24.
metrics/merger_test.go & others Updated tests to use t.Context() consistently.
config/, act/, logging/, api/ Various tests updated to use t.Context() for context propagation.

Copilot reviewed 38 out of 38 changed files in this pull request and generated 1 comment.

@mostafa mostafa requested a review from sinadarbouy March 5, 2025 12:45
@mostafa
Copy link
Member Author

mostafa commented Mar 5, 2025

@sinadarbouy Do you have any idea why the tests are failing. I see a cryptic message possibly from Raft, but I cannot find the source of it. It's about the transaction rollbacks.

@sinadarbouy
Copy link
Collaborator

@sinadarbouy Do you have any idea why the tests are failing. I see a cryptic message possibly from Raft, but I cannot find the source of it. It's about the transaction rollbacks.

@mostafa Hmm, not sure about transaction rollbacks—probably okay because the related test cases passed. However, these two test cases failed:

FAIL: Test_Run_Async_Redis and TestGetVersion.

@mostafa mostafa merged commit 9211a74 into main Mar 5, 2025
4 checks passed
@mostafa mostafa deleted the update-deps branch March 5, 2025 21:32
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants