Skip to content

Upgrade Go to 1.27.1 and refresh compatible dependencies - #71

Merged
merefield merged 4 commits into
mainfrom
chore/go-1.27.1
Oct 5, 2026
Merged

merefield merged 4 commits into
mainfrom
chore/go-1.27.1

Conversation

@merefield

@merefield merefield commented Oct 5, 2026 •

Copy link
Copy Markdown
Owner

Why

Update Codexometer’s Go toolchain and compatible dependencies, incorporating terminal reliability fixes while preserving the existing application behaviour.

Highlights

  • Terminal reliability fixes. Bubble Tea patches fix redraw/clearing artefacts and Kitty keyboard-state cleanup on exit.
  • Reliable toolchain selection for releases. CI and release jobs use the checked-out go.mod, so rebuilding an older tag uses its declared Go version rather than the current default branch’s version.

Upstream references: Go 1.27 release notes, Go 1.27.1 maintenance release, Bubble Tea releases.

Changes and compatibility

  • Require Go 1.27.1 in go.mod.
  • CI and release jobs read the toolchain from the checked-out go.mod, matching security scanning. Manually publishing an older tag therefore selects its historical toolchain, not the version on main.
  • New Go 1.27-based macOS builds require macOS 13 Ventura or later. The v0.19.0 tag specifies Go 1.26.6.
  • Update README and intro post requirements.
  • Bubble Tea 2.0.8 → 2.0.10; Starlark July 8 → September 30 revision.
  • x/sys 0.47.0 → 0.48.0; x/text 0.41.0 → 0.42.0; transitive x/sync 0.22.0 → 0.23.0.
  • Svelte 5.57.0 → 5.57.1; Vite 8.3.0 → 8.3.2; Svelte Vite plugin 7.3.0 → 7.3.1; Prettier 3.9.6 → 3.9.9.
  • Refresh lockfiles and embedded frontend/license assets. No application version bump or major dependency migration.

Validation

  • Full Go test suite and race-enabled suite pass; vet and Go 1.27.1 formatting checks pass.
  • All six Linux/macOS/Windows amd64/arm64 cross-builds pass with the refreshed dependencies.
  • All 45 browser regressions pass against the updated build.
  • Svelte checks, formatting and production build pass.
  • npm audit and govulncheck v1.8.0 report no vulnerabilities.
  • Confirmed v0.19.0 go.mod specifies 1.26.6, current branch specifies 1.27.1, and both release test/build jobs check out the validated tag before setup-go reads go.mod.
  • CI runs native Linux/macOS/Windows tests plus browser and vulnerability checks.

@merefield merefield changed the title Upgrade Go toolchain to 1.27.1 Upgrade Go to 1.27.1 and refresh compatible dependencies Oct 5, 2026
@merefield
merefield requested a lite review from Copilot October 5, 2026 15:38

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Release reruns for historical tags may rebuild them with the wrong Go toolchain.

Review effort: Lite
Findings: 1 Medium severity

Open (1)
What changed in this PR

Upgrades Go to 1.27.1, refreshes compatible dependencies, updates CI/release workflows, documentation, and embedded web assets.

Changes:

  • Refreshes Go and frontend dependencies.
  • Updates CI, release tooling, and build guidance.
  • Regenerates frontend bundles and license metadata.
File Summary
web/​package.json Updates frontend tooling versions.
web/​package-lock.json Refreshes locked frontend dependencies.
README.md Documents toolchain and macOS requirements.
intro-post.md Updates source-build guidance.
internal/​web/​dist/​index.html References the regenerated bundle.
internal/​web/​dist/​assets/​THIRD-PARTY-LICENSES.md Updates Svelte licensing metadata.
internal/​web/​dist/​assets/​index-BB7ka8z9.js Removes the superseded bundle.
go.sum Refreshes dependency checksums.
go.mod Updates the Go toolchain and dependencies.
.github/​workflows/​release.yml Uses Go 1.27.1; historical tag reruns should preserve their original toolchain.
.github/​workflows/​ci.yml Uses Go 1.27.1 in CI.
Files not reviewed (1)
  • web/package-lock.json: Generated file

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread .github/workflows/release.yml Outdated
@merefield
merefield merged commit 3e6d7c4 into main Oct 5, 2026
6 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants