Repository navigation
v2.12.10
2.12.10 (2026-10-03)
Bug Fixes
- go: let the govulncheck install fetch the Go toolchain it needs (#506) (ab4ab90), closes #501
- rust: install native deps with the workflow's hyperi-ci, not the release (#508) (c39ee0a), closes #501
- rust: install the dev packages rdkafka.pc requires (#507) (0c9af68), closes #501
Heads up for consumers
These fix the hosted-runner path ahead of ubuntu-latest moving to 26.04 from 2026-10-19 (#501). ARC runners are unaffected.
- Go, hosted runners (#506): the govulncheck install now fetches the Go toolchain it needs (1.26+), so a repo whose go.mod declares an older
gono longer fails at tool install. govulncheck then checks the stdlib of the Go your go.mod selects. A repo on an out-of-supportgodirective (1.22, say) will see stdlib advisories, and the fix is to raise the directive. - Rust with rdkafka (#507): native deps now also install zlib1g-dev, libzstd-dev and libcurl4-openssl-dev, which Confluent's rdkafka.pc requires. Without them rdkafka-sys could not find librdkafka on the 26.04 image.
- Rust native deps (#508): they now install with the same hyperi-ci the rest of the workflow uses, so they honour
HYPERCI_INSTALL_OVERRIDEand the workflow's Python pin. Before this they always came from the latest PyPI release.
What's Changed
- fix(rust): install native deps with the workflow's hyperi-ci, not the release by @catinspace-au in #508
- fix(rust): install the dev packages rdkafka.pc requires by @catinspace-au in #507
- fix(go): let the govulncheck install fetch the Go toolchain it needs by @catinspace-au in #506
Full Changelog: v2.12.9...v2.12.10