Skip to content

v1.0.1

Latest

Choose a tag to compare

@github-actions github-actions released this 22 Sep 06:03
· 16 commits to main since this release
v1.0.1
e980c7b

A maintenance release: the go directive raised to 1.27, the dependency graph brought current, and the codebase modernized to what Go 1.27's go fix produces. No configuration key, endpoint or job semantics change, so no config file needs editing.

Two runtime defaults change

Go compiles a module declaring an older version with that version's compatibility settings, so the binary carried DefaultGODEBUG=tracebacklabels=0,x509sslcertoverrideplatform=0 until now. Raising the go directive drops both pins:

setting 0, until now 1, the Go 1.27 default
tracebacklabels goroutine labels absent from tracebacks labels appear
x509sslcertoverrideplatform the platform certificate store always wins on Windows and darwin, crypto/x509 loads roots from disk when SSL_CERT_FILE or SSL_CERT_DIR is set

The second one is the operationally relevant one. An operator who sets either variable on Windows or darwin and relies on the platform store winning should set GODEBUG=x509sslcertoverrideplatform=0. Linux builds and the ghcr.io image are unaffected — the setting exists only for those two platforms (#824 by @CybotTM).

Documentation

default-user and a job's own user are documented as the distinct states they have. An empty value means something different at the two levels, which the documentation did not say and is the easy mistake. For [global] default-user: absent yields nobody, empty and default both yield the container's own user, anything else is taken literally. For a job's own user: absent or empty inherits whatever the global resolved to, and only default bypasses it. Both are now tables in docs/CONFIGURATION.md, and the three per-job descriptions in docs/jobs.md say which of the two they are.

The reservation of default is written down for the first time: a container user of that name cannot be selected at either level (#825 by @CybotTM, closing #718 reported by @CybotTM).

AGENTS.md gained the release process, the backlog signals, the deprecation policy and what earns a major bump (#827, #828 by @CybotTM).

Internal

The codebase was modernized via go fix from Go 1.27.1, across 56 files (#850 by @CybotTM). In production code that is 23 counters becoming atomic.Int32/Int64/Uint64 instead of plain integers reached through atomic.LoadInt64(&x) — same memory semantics, and the atomic types carry their own 64-bit alignment — two Docker struct literals losing their embedded-type wrapper now that Go 1.27 accepts any field selector as a literal key, and one reflection loop becoming reflect.Value.Fields(). The rest is tests.

Two things were measured rather than assumed. BareJob.running became atomic.Int32, and BareJob.Hash walks the struct by reflection, recursing into any field of kind Struct before checking its hashme tag — that hash decides whether a config reload treats a job as changed. The same job hashes byte-identically before and after. The two flattened literals were compared with reflect.DeepEqual against the wrapped form and are equal.

The go fix run was repeated with -tags=integration,e2e, because a file behind a build tag is invisible to a plain go fix ./...: 25 of the 56 files appear only in the tagged run.

30 superseded go.sum checksums were removed. They had accumulated because a dependency bump adds the new checksum without removing the old one, which left go mod tidy -diff failing on main and this repository's own go-mod-tidy pre-commit hook rejecting every commit (#850).

Dependencies

creasty/defaults 1.11.0, docker/cli 29.8.1, go-playground/validator/v10 10.30.5, klauspost/compress 1.20.0, moby/moby/api 1.56.0, moby/moby/client 0.6.0, golang.org/x/crypto 0.57.0, x/term 0.46.0, x/text 0.42.0, x/time 0.16.0, the alpine base image to 3.24.2, and the toolchain to go1.27.1.

CI

Renovate processes this fork again; it had been skipping the repository because the Mend app runs in autodiscover mode and passes over forks that do not set forkProcessing (#830 by @CybotTM). The Dependabot configuration is removed, leaving Renovate as the only updater (#835 by @CybotTM). step-security/harden-runner moved to v2.21.1 (#832).

Full changelog: v1.0.0...v1.0.1