Skip to content

chore: require Go 1.27.1 (go directive) - #81

Merged
ovander merged 1 commit into
mainfrom
chore/go-1.27
Oct 4, 2026
Merged

ovander merged 1 commit into
mainfrom
chore/go-1.27

Conversation

@ovander

@ovander ovander commented Oct 4, 2026

Copy link
Copy Markdown
Owner

What and why

This aligns backendkit with the rest of the suite, which builds and ships with Go 1.27.1 (go-oauth2 #306 does the same for Socrate):

  • go.mod: go 1.27.1, was go 1.25.0 plus toolchain go1.27.1. go mod tidy drops a toolchain line equal to the go line. The language level and GODEBUG defaults now match the Go that CI tests.
  • CI:
    • The "Toolchain matches go.mod" check reads the toolchain line, or the go line when there is none.
    • govulncheck is pinned to v1.8.0, was @latest. It's built with the job's Go 1.27.1; a govulncheck built with an older Go refuses a go 1.27 module.
  • Docs: README (requirements and the install example), docs/CLIENT-INTEGRATION.md, CONTRIBUTING.md and CLAUDE.md state the new requirement.

Compatibility, please confirm:

  • Importers need Go 1.27.1 or later. With GOTOOLCHAIN=auto (the default), an older go command downloads it. With GOTOOLCHAIN=local and an older Go, the build fails with "requires go >= 1.27.1".
  • The old comment kept go 1.25.0 precisely so Go 1.25 consumers could import backendkit. Go 1.25 is out of support, and both consoles build with 1.27.1.
  • Ascenda, Lakebridge and GPWA should be on Go 1.27.1 before taking the release that includes this.
  • No exported identifier changes.

httputil.ReverseProxy.Director, deprecated since Go 1.26 and flagged by staticcheck SA1019 at go 1.27:

  • bff.NewSingleHostProxy builds its proxy with Director, and its doc tells callers to wrap Director, which both consoles do. Switching it to Rewrite would break those callers (v1 rule), and Rewrite also changes how X-Forwarded-For is built, which Socrate's rate limiting and audit attribution rely on.
  • So the two lines carry //nolint:staticcheck with that reason. Director remains supported under the Go 1 compatibility promise.
  • The proper fix is a new, additive Rewrite-based constructor, in its own PR, which the consoles adopt when they move off backendkit v1.15.

How it was tested

  • go mod tidy && git diff --exit-code go.sum leaves go.sum unchanged
  • go build ./... passes
  • go vet ./... passes
  • go test -race -count=1 -timeout=120s ./... passes
  • golangci-lint run ./... (v2.14.0, built with Go 1.27.1) reports no issue
  • govulncheck ./...: CI (the sandbox can't reach vuln.go.dev)
  • A line is added under ## [Unreleased] in CHANGELOG.md

CI's toolchain check run locally passes: go1.27.1 from go.mod against go1.27.1 from the go command.

Compatibility

  • Exported-API change: no.
  • Behaviour change for existing callers: none at run time. The minimum Go for importers rises from 1.25.0 to 1.27.1.
  • Breaking change: only for an importer that pins an older Go with GOTOOLCHAIN=local. Raising the go directive is normally done in a minor release, but by this repo's own rule it's for you to accept.

🤖 Generated with Claude Code

https://claude.ai/code/session_01GKRxaeYxyDhmt42cehLsGA


Generated by Claude Code

go.mod: go 1.27.1 (was go 1.25.0 + toolchain go1.27.1); go mod tidy
drops the now-redundant toolchain line. Importers need Go 1.27.1 or
later (GOTOOLCHAIN=auto downloads it). No exported identifier changes.

- bff.NewSingleHostProxy keeps httputil.ReverseProxy.Director
  (deprecated since Go 1.26, SA1019 at go 1.27): callers wrap it, so a
  Rewrite-based proxy must be a new, additive constructor; the two lines
  carry a reasoned nolint until then.
- CI: the toolchain check reads the go line when there is no toolchain
  line; govulncheck pinned to v1.8.0.
- README, CLIENT-INTEGRATION, CONTRIBUTING and CLAUDE.md state the new
  requirement.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GKRxaeYxyDhmt42cehLsGA
@ovander
ovander merged commit f5b1cfe into main Oct 4, 2026
3 checks passed
@ovander ovander mentioned this pull request Oct 4, 2026
7 tasks done
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants