Skip to content

Upgrade go-pipeline to v0.18.0, jwx to v3.2.0 - #4139

Merged
DrJosh9000 merged 1 commit into
mainfrom
go-pipeline-v0.18.0-jwx-v3.2.0
Jul 30, 2026
Merged

Upgrade go-pipeline to v0.18.0, jwx to v3.2.0#4139
DrJosh9000 merged 1 commit into
mainfrom
go-pipeline-v0.18.0-jwx-v3.2.0

Conversation

@DrJosh9000

Copy link
Copy Markdown
Contributor

Description

v2 of lestrrat-go/jwx is deprecated. I upgraded go-pipeline to v3 - now upgrade the agent.

Context

Needs to happen.

Changes

  • Upgrade the dependencies
  • Change the call sites to the jwx/v3 way

Testing

  • Tests have run locally (with go test ./...). Buildkite employees may check this if the pipeline has run automatically.
  • Code is formatted (with go tool gofumpt -extra -w .)

Disclosures / Credits

Me 👉 🧑‍💻

@DrJosh9000
DrJosh9000 requested review from a team as code owners July 30, 2026 04:58
@DrJosh9000 DrJosh9000 added the internal Non-user facing, internal change. label Jul 30, 2026
@socket-security

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Addedgolang/​github.com/​lestrrat-go/​jwx/​v3@​v3.2.091100100100100
Updatedgolang/​github.com/​buildkite/​go-pipeline@​v0.17.1 ⏵ v0.18.0100 +1100100100100

View full report

@CerealBoy CerealBoy left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM 🚀 🚀

@buildsworth-bk-app buildsworth-bk-app Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No inline findings. This changes the agent's job-signing and verification path, so I'm leaving a comment rather than approving.

Want to dig deeper?

Paste this into your agent to explore the findings from this review's Buildkite build:

Download the buildsworth logs from build 9910, then answer my questions about the findings.

Install the reading-buildsworth-logs skill to run this.

About buildsworth

Model: gpt-5.6-sol with xhigh thinking.

How to request a review: Comment @buildsworth-bk review on the PR, or request buildsworth-bk as a reviewer.

Risk labels (how buildsworth classifies risk) — buildsworth classifies risk itself from the diff. To let it approve, grant L2 approval by mentioning @buildsworth-bk (see L2 approval grant):

  • L1 — Low risk (dep bumps, docs/copy, lockfiles, small presentational fixes). buildsworth may approve by default.
  • L2 — Standard risk (new UI, additive API fields, refactors). Approved only with an L2 grant; otherwise comment-only.
  • L3 — High risk (auth, migrations, payments, secrets, perf-critical paths). Human review always required.

@DrJosh9000
DrJosh9000 merged commit ac05a18 into main Jul 30, 2026
5 checks passed
@DrJosh9000
DrJosh9000 deleted the go-pipeline-v0.18.0-jwx-v3.2.0 branch July 30, 2026 05:10
@zhming0 zhming0 mentioned this pull request Aug 4, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

internal Non-user facing, internal change.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants