Skip to content

Bump the go-dependencies group across 3 directories with 1 update - #1470

Closed
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/go_modules/go-dependencies-2a3df45bb2
Closed

dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/go_modules/go-dependencies-2a3df45bb2

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 7, 2026 •

Copy link
Copy Markdown
Contributor

⚠️ Dependabot is rebasing this PR ⚠️

Rebasing might not happen immediately, so don't worry if this takes some time.

Note: if you make any changes to this PR yourself, they will take precedence over the rebase.


Bumps the go-dependencies group with 1 update in the / directory: github.com/tidwall/gjson.
Bumps the go-dependencies group with 1 update in the /riverdriver/riverdrivertest directory: github.com/tidwall/gjson.
Bumps the go-dependencies group with 1 update in the /rivershared directory: github.com/tidwall/gjson.

Updates github.com/tidwall/gjson from 1.19.0 to 1.19.1

Commits

Updates github.com/tidwall/gjson from 1.19.0 to 1.19.1

Commits

Updates github.com/tidwall/gjson from 1.19.0 to 1.19.1

Commits

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the go-dependencies group with 1 update in the / directory: [github.com/tidwall/gjson](https://github.com/tidwall/gjson).
Bumps the go-dependencies group with 1 update in the /riverdriver/riverdrivertest directory: [github.com/tidwall/gjson](https://github.com/tidwall/gjson).
Bumps the go-dependencies group with 1 update in the /rivershared directory: [github.com/tidwall/gjson](https://github.com/tidwall/gjson).


Updates `github.com/tidwall/gjson` from 1.19.0 to 1.19.1
- [Commits](tidwall/gjson@v1.19.0...v1.19.1)

Updates `github.com/tidwall/gjson` from 1.19.0 to 1.19.1
- [Commits](tidwall/gjson@v1.19.0...v1.19.1)

Updates `github.com/tidwall/gjson` from 1.19.0 to 1.19.1
- [Commits](tidwall/gjson@v1.19.0...v1.19.1)

---
updated-dependencies:
- dependency-name: github.com/tidwall/gjson
  dependency-version: 1.19.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go-dependencies
- dependency-name: github.com/tidwall/gjson
  dependency-version: 1.19.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go-dependencies
- dependency-name: github.com/tidwall/gjson
  dependency-version: 1.19.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file go Pull requests that update go code labels Oct 7, 2026

@bgentry bgentry left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🤖 Codex review: Changes requested. Supply-chain review is clear, but this upgrade introduces a reproducible cross-language compatibility failure.

Blocking finding — reconcile snooze-counter coercion before merging

gjson.Result.Int() in v1.19.1 now accepts decimal/exponent numeric strings through strconv.ParseFloat. For metadata {"snoozes":"4.5"}, River Go's NextSnoozeCount changes from 1 to 5; Rust and JavaScript still produce 1. The Go-generated fractional_string_is_zero fixture now expects 5, and the Rust/JS tests fail. This is the cause of the red conformance, Rust and JavaScript checks, not a flaky-test assumption.

Choose the intended coercion policy and reconcile the Go, Rust and JavaScript implementations and fixture assertions before merging. Also check exponent strings and overflow boundaries covered by the upstream conversion changes.

Upgrade

  • github.com/tidwall/gjson: v1.19.0 → v1.19.1
  • Additional metadata: conformance adds indirect golang.org/x/tools v0.50.0; River v0.49.0 sums replace stale v0.48.0 records, while the base manifests already select v0.49.0.
  • Reviewed head: 06a1f1a026899860ca407f2d83396606c4f1a51c

Security review

  • Independently recomputed published module/content and go.mod hashes for old/new GJSON and x/tools plus seven River v0.49.0 modules; all match sum.golang.org and PR sums. Published files match canonical upstream commits byte-for-byte.
  • Reviewed the complete GJSON delta: numeric conversion/saturation, invalid-UTF8 replacement spelling and a malformed-path panic guard. No new network, credential/environment access, subprocesses, native code, lifecycle hooks or init side effects.
  • Reviewed x/tools graph churn and changed analysis/export/indexing source. Its Go 1.26 minimum is covered; x/sys v0.48.0 is already selected by base modules. No River runtime imports of the newly recorded developer tooling were found.
  • No same-version sum rewrite, source substitution, replace/toolchain/workspace/vendoring/generated-code change. Current official Go advisory ranges do not affect the reviewed GJSON versions; no x/tools advisory was listed. No confirmed advisory-driven security update identified.

Compatibility verification

  • make tidy and clean tracked diff — passed.
  • go mod verify — passed.
  • make test — passed across the Go workspace, including both driver families and legacy transaction coverage.
  • make lint encountered another local linter's global lock. Re-ran golangci-lint run --allow-parallel-runners in every workspace module — passed, with clean tracked diff.
  • make generate/fixtures — passed; fractional_string_is_zero has expected_snoozes: 5.
  • cargo test --manifest-path rust/Cargo.toml -p riverqueue --features chrono-tz --lib snooze_counter_matches_go_fixture --locked — FAILED locally on this exact head: Rust 1, fixture 5.
  • Existing hosted JavaScript checks fail at src/runtime/completion-command.test.ts:68 with the same 1 versus 5 mismatch. JavaScript was not run locally because the installed Node runtime is 24 and this workspace requires Node 26.

Residual risk

  • Compatibility remains blocked and this PR is intentionally unmerged. A clear static supply-chain review does not establish numeric-parser correctness or exclude unknown vulnerabilities. Existing unsafe byte/string optimizations are unchanged.

@bgentry

bgentry commented Oct 8, 2026

Copy link
Copy Markdown
Contributor

@dependabot rebase

@bgentry

bgentry commented Oct 8, 2026

Copy link
Copy Markdown
Contributor

Superseded by #1476, which Dependabot created on current master while processing the requested rebase. The new PR targets GJSON v1.20.0 and still has the same snooze-counter conformance failure. Its new artifact needs a fresh security delta review; the v1.19.1 review here does not approve v1.20.0. Closing this obsolete duplicate without merging it.

@dependabot @github

dependabot Bot commented on behalf of github Oct 8, 2026

Copy link
Copy Markdown
Contributor Author

This pull request was built based on a group rule. Closing it will not ignore any of these versions in future pull requests.

To ignore these dependencies, configure ignore rules in dependabot.yml

@dependabot
dependabot Bot deleted the dependabot/go_modules/go-dependencies-2a3df45bb2 branch October 8, 2026 01:16
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file go Pull requests that update go code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant