Repository navigation
Bump the go-dependencies group across 3 directories with 1 update - #1470
dependabot[bot] wants to merge 1 commit into
Conversation
Bumps the go-dependencies group with 1 update in the / directory: [github.com/tidwall/gjson](https://github.com/tidwall/gjson). Bumps the go-dependencies group with 1 update in the /riverdriver/riverdrivertest directory: [github.com/tidwall/gjson](https://github.com/tidwall/gjson). Bumps the go-dependencies group with 1 update in the /rivershared directory: [github.com/tidwall/gjson](https://github.com/tidwall/gjson). Updates `github.com/tidwall/gjson` from 1.19.0 to 1.19.1 - [Commits](tidwall/gjson@v1.19.0...v1.19.1) Updates `github.com/tidwall/gjson` from 1.19.0 to 1.19.1 - [Commits](tidwall/gjson@v1.19.0...v1.19.1) Updates `github.com/tidwall/gjson` from 1.19.0 to 1.19.1 - [Commits](tidwall/gjson@v1.19.0...v1.19.1) --- updated-dependencies: - dependency-name: github.com/tidwall/gjson dependency-version: 1.19.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: go-dependencies - dependency-name: github.com/tidwall/gjson dependency-version: 1.19.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: go-dependencies - dependency-name: github.com/tidwall/gjson dependency-version: 1.19.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: go-dependencies ... Signed-off-by: dependabot[bot] <support@github.com>
bgentry
left a comment
There was a problem hiding this comment.
🤖 Codex review: Changes requested. Supply-chain review is clear, but this upgrade introduces a reproducible cross-language compatibility failure.
Blocking finding — reconcile snooze-counter coercion before merging
gjson.Result.Int() in v1.19.1 now accepts decimal/exponent numeric strings through strconv.ParseFloat. For metadata {"snoozes":"4.5"}, River Go's NextSnoozeCount changes from 1 to 5; Rust and JavaScript still produce 1. The Go-generated fractional_string_is_zero fixture now expects 5, and the Rust/JS tests fail. This is the cause of the red conformance, Rust and JavaScript checks, not a flaky-test assumption.
Choose the intended coercion policy and reconcile the Go, Rust and JavaScript implementations and fixture assertions before merging. Also check exponent strings and overflow boundaries covered by the upstream conversion changes.
Upgrade
github.com/tidwall/gjson:v1.19.0→v1.19.1- Additional metadata: conformance adds indirect
golang.org/x/tools v0.50.0; River v0.49.0 sums replace stale v0.48.0 records, while the base manifests already select v0.49.0. - Reviewed head:
06a1f1a026899860ca407f2d83396606c4f1a51c
Security review
- Independently recomputed published module/content and go.mod hashes for old/new GJSON and x/tools plus seven River v0.49.0 modules; all match sum.golang.org and PR sums. Published files match canonical upstream commits byte-for-byte.
- Reviewed the complete GJSON delta: numeric conversion/saturation, invalid-UTF8 replacement spelling and a malformed-path panic guard. No new network, credential/environment access, subprocesses, native code, lifecycle hooks or init side effects.
- Reviewed x/tools graph churn and changed analysis/export/indexing source. Its Go 1.26 minimum is covered; x/sys v0.48.0 is already selected by base modules. No River runtime imports of the newly recorded developer tooling were found.
- No same-version sum rewrite, source substitution, replace/toolchain/workspace/vendoring/generated-code change. Current official Go advisory ranges do not affect the reviewed GJSON versions; no x/tools advisory was listed. No confirmed advisory-driven security update identified.
Compatibility verification
make tidyand clean tracked diff — passed.go mod verify— passed.make test— passed across the Go workspace, including both driver families and legacy transaction coverage.make lintencountered another local linter's global lock. Re-rangolangci-lint run --allow-parallel-runnersin every workspace module — passed, with clean tracked diff.make generate/fixtures— passed;fractional_string_is_zerohasexpected_snoozes: 5.cargo test --manifest-path rust/Cargo.toml -p riverqueue --features chrono-tz --lib snooze_counter_matches_go_fixture --locked— FAILED locally on this exact head: Rust1, fixture5.- Existing hosted JavaScript checks fail at
src/runtime/completion-command.test.ts:68with the same1versus5mismatch. JavaScript was not run locally because the installed Node runtime is 24 and this workspace requires Node 26.
Residual risk
- Compatibility remains blocked and this PR is intentionally unmerged. A clear static supply-chain review does not establish numeric-parser correctness or exclude unknown vulnerabilities. Existing unsafe byte/string optimizations are unchanged.
|
@dependabot rebase |
|
Superseded by #1476, which Dependabot created on current master while processing the requested rebase. The new PR targets GJSON v1.20.0 and still has the same snooze-counter conformance failure. Its new artifact needs a fresh security delta review; the v1.19.1 review here does not approve v1.20.0. Closing this obsolete duplicate without merging it. |
|
This pull request was built based on a group rule. Closing it will not ignore any of these versions in future pull requests. To ignore these dependencies, configure ignore rules in dependabot.yml |
Rebasing might not happen immediately, so don't worry if this takes some time.
Note: if you make any changes to this PR yourself, they will take precedence over the rebase.
Bumps the go-dependencies group with 1 update in the / directory: github.com/tidwall/gjson.
Bumps the go-dependencies group with 1 update in the /riverdriver/riverdrivertest directory: github.com/tidwall/gjson.
Bumps the go-dependencies group with 1 update in the /rivershared directory: github.com/tidwall/gjson.
Updates
github.com/tidwall/gjsonfrom 1.19.0 to 1.19.1Commits
9378d3bFix Result.Path panics8d89927Ensure floating points are correctly being clippedeaae8c6Fix large number overflows for Int() and Uint()6ac9851Change utf8 behavior for invalid codepoints5fc5c04Update README.md7d8b382Update README.md896d569Update gjson.go27a65e4Update README.md10c4bb5Update README.mde5cb9d0Update README.mdUpdates
github.com/tidwall/gjsonfrom 1.19.0 to 1.19.1Commits
9378d3bFix Result.Path panics8d89927Ensure floating points are correctly being clippedeaae8c6Fix large number overflows for Int() and Uint()6ac9851Change utf8 behavior for invalid codepoints5fc5c04Update README.md7d8b382Update README.md896d569Update gjson.go27a65e4Update README.md10c4bb5Update README.mde5cb9d0Update README.mdUpdates
github.com/tidwall/gjsonfrom 1.19.0 to 1.19.1Commits
9378d3bFix Result.Path panics8d89927Ensure floating points are correctly being clippedeaae8c6Fix large number overflows for Int() and Uint()6ac9851Change utf8 behavior for invalid codepoints5fc5c04Update README.md7d8b382Update README.md896d569Update gjson.go27a65e4Update README.md10c4bb5Update README.mde5cb9d0Update README.mdDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions