Skip to content

Use maintained Go YAML libraries - #45

Closed
ai-collaboration-app[bot] wants to merge 2 commits into
mainfrom
maintained-yaml
Closed

ai-collaboration-app[bot] wants to merge 2 commits into
mainfrom
maintained-yaml

Conversation

@ai-collaboration-app

@ai-collaboration-app ai-collaboration-app Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

Move ConfigMap/Secret parsing to maintained v3 and upgrade Testify plus Swag’s JSON/YAML leaves to patched v0.27.1. Preserve the existing façade, merge/validation behavior and ordered scalar/node contracts.

Validation: repository tests/lint, baseline compatibility fixtures, upstream depth/alias/OpenAPI tests, module checks, native build/provenance and source/binary govulncheck. Fresh PR artifact CI qualifies all five platforms.

Tracking: https://github.com/StackVista/stackstate/issues/717

Preserve the v3 configuration API, YAML tags, Secret merge and validation
behavior. Qualify aliases, scalar conversion, null/zero overrides and error
handling using mocked Kubernetes reads against both parsers.

Upgrade Testify to its maintained YAML release and Swag to the compatible
v0.25 line, removing legacy parser packages from all five release-target
graphs and the default repository test graph without module replacements.
Residual legacy module metadata belongs to upstream dependency tests.

Tracking: StackVista/stackstate#717
Upgrade jsonutils/yamlutils and their required conv/typeutils/pools modules
to v0.27.1 for GHSA-xh24-9qpg-8w28 and GHSA-hwp8-w8pv-xq8f. Keep the
existing root compatibility facade and unrelated Swag modules unchanged.
All selected modules require Go 1.25, satisfied by the existing builder.

Ordinary ordered JSON and YAML node/alias/scalar fixtures pass against the
previous and patched dependencies. Full upstream depth/alias and OpenAPI
regressions pass. Native provenance and retained ordered JSON symbols
confirm patched effective code without replacements or gate changes.

Tracking: StackVista/stackstate#717
@LouisLotter LouisLotter closed this Oct 2, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants