diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index ff1d20c..7dbb37d 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -38,11 +38,13 @@ jobs: go-version: ${{ matrix.go-version }} cache: true - # go.mod's toolchain line and this workflow's Go version must agree: - # fail loudly if they drift rather than test on one Go and pin another. + # go.mod's Go (its toolchain line, or the go line when there is none — + # go mod tidy drops a toolchain line equal to the go line) and this + # workflow's Go must agree: fail loudly if they drift rather than test on + # one Go and pin another. - name: Toolchain matches go.mod run: | - want=$(awk '/^toolchain /{print $2}' go.mod) + want=$(awk '/^toolchain /{t=$2} /^go /{g="go"$2} END{print (t != "" ? t : g)}' go.mod) got=$(go env GOVERSION) echo "go.mod toolchain: $want · CI: $got" test -n "$want" && test "$got" = "$want" @@ -94,8 +96,11 @@ jobs: with: go-version: "1.27.1" cache: true + # Pinned, so a scanner release never changes the result unannounced. It + # is built with the job's Go (1.27.1): a govulncheck built with an older + # Go refuses a module targeting a newer one. - name: Install govulncheck - run: go install golang.org/x/vuln/cmd/govulncheck@latest + run: go install golang.org/x/vuln/cmd/govulncheck@v1.8.0 - name: Run govulncheck run: govulncheck ./... diff --git a/CHANGELOG.md b/CHANGELOG.md index ec2306b..f8c0c99 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -6,6 +6,14 @@ All notable changes to backendkit are documented here. Format: ## [Unreleased] +### Changed +- **The module now requires Go 1.27.1** (`go 1.27.1`; was `go 1.25.0` with `toolchain go1.27.1`). + Importers need Go 1.27.1 or later; with `GOTOOLCHAIN=auto`, the default, an older `go` command + downloads it. backendkit's language level and `GODEBUG` defaults now match the Go it is built + and tested with. No exported identifier changes. `bff.NewSingleHostProxy` keeps its + `httputil.ReverseProxy.Director` (deprecated since Go 1.26, still supported): callers wrap it, + so moving to `Rewrite` needs a new, additive constructor. CI pins govulncheck to v1.8.0. + ## [1.19.0] - 2026-10-03 Minor release on the **v1** line: additive only. The service-side helpers Lakebridge asked for: diff --git a/CLAUDE.md b/CLAUDE.md index 5bf31b2..e7b4aaa 100644 --- a/CLAUDE.md +++ b/CLAUDE.md @@ -54,7 +54,8 @@ golangci-lint run ./... # v2.14.0, built with Go 1.27.1 govulncheck ./... ``` -CI also fails if the Go version it runs differs from the `toolchain` line in `go.mod`. +CI also fails if the Go version it runs differs from `go.mod`'s (its `go` line, or a `toolchain` +line when there is one). ## Git workflow diff --git a/CONTRIBUTING.md b/CONTRIBUTING.md index 88a96a1..2981f2b 100644 --- a/CONTRIBUTING.md +++ b/CONTRIBUTING.md @@ -8,7 +8,7 @@ policy decisions. Contributions are accepted under the project's licence, ## Development setup -Requirements: Go (the `toolchain` line in `go.mod` downloads the exact version, 1.27.1). The +Requirements: Go (the `go` line in `go.mod` downloads the exact version, 1.27.1). The tests need no database and no network service. ```bash diff --git a/README.md b/README.md index 8420c19..d4822eb 100644 --- a/README.md +++ b/README.md @@ -119,9 +119,9 @@ to Socrate (`bff`, `pep`) and `ailang` for `aigateway`. ## Requirements -- **Go 1.25 or later** to import the module (the `go` line in `go.mod`). Build your service with - a Go release that still receives security fixes. backendkit itself is built and tested with - Go 1.27.1, pinned by the `toolchain` line. +- **Go 1.27.1 or later** to import the module (the `go` line in `go.mod`, which is also the Go + backendkit is built and tested with). With `GOTOOLCHAIN=auto`, the default, an older `go` + command downloads it. - **A Socrate server** for the packages that talk to it: `jwtauth`, `socrate`, `bff` and `pep`. They are written for Socrate's API and claims, not as a generic OAuth toolkit. The other packages, `ctxutil` included, are plain Go helpers and work without Socrate. @@ -140,7 +140,7 @@ go get github.com/ovander/backendkit@v1.19.0 // go.mod module github.com/your-org/my-service -go 1.25 +go 1.27.1 require github.com/ovander/backendkit v1.19.0 ``` diff --git a/bff/gateway.go b/bff/gateway.go index fcc2056..aeb4a04 100644 --- a/bff/gateway.go +++ b/bff/gateway.go @@ -305,8 +305,8 @@ var clientIPHeaders = []string{"X-Real-IP", "True-Client-IP", "Forwarded"} func NewSingleHostProxy(upstream *url.URL) *httputil.ReverseProxy { p := httputil.NewSingleHostReverseProxy(upstream) p.FlushInterval = -1 - director := p.Director - p.Director = func(r *http.Request) { + director := p.Director //nolint:staticcheck // SA1019: v1 API, callers wrap Director; a Rewrite-based proxy is a separate, additive change + p.Director = func(r *http.Request) { //nolint:staticcheck // SA1019: v1 API, callers wrap Director; a Rewrite-based proxy is a separate, additive change director(r) for _, h := range clientIPHeaders { r.Header.Del(h) diff --git a/docs/CLIENT-INTEGRATION.md b/docs/CLIENT-INTEGRATION.md index 10a96e9..a2e9bfc 100644 --- a/docs/CLIENT-INTEGRATION.md +++ b/docs/CLIENT-INTEGRATION.md @@ -127,7 +127,7 @@ enforce your own authorization first. go get github.com/ovander/backendkit@latest ``` -Requires **Go 1.25+**. +Requires **Go 1.27.1+** (the `go` line of backendkit's `go.mod`). `backendkit` reads **no environment variables itself** — you pass everything to constructors explicitly. These are the conventional names used throughout this diff --git a/go.mod b/go.mod index 85a3060..0dc4eb1 100644 --- a/go.mod +++ b/go.mod @@ -1,13 +1,9 @@ module github.com/ovander/backendkit -go 1.25.0 - -// Build/release with a patched toolchain to pick up Go standard-library security -// fixes (govulncheck GO-2026-4599…GO-2026-5039, and the 2026-08-28 releases). -// The go directive above stays at 1.25.0 so the module remains importable by -// consumers on Go 1.25; this toolchain directive only governs builds where -// backendkit is the main module. Keep it equal to the Go version in CI. -toolchain go1.27.1 +// The go line is both the minimum Go for every module that imports backendkit +// and the exact Go it is built and tested with (with no toolchain line, it is +// the toolchain too). CI checks it against the Go CI runs. +go 1.27.1 require ( github.com/golang-jwt/jwt/v5 v5.3.1