From 318732a3e070ee5b5c5364e1fb1fc681a513a86f Mon Sep 17 00:00:00 2001 From: Claude Date: Sun, 27 Sep 2026 11:06:22 +0000 Subject: [PATCH] build: move the Go toolchain to 1.27.1 Step 3 of the toolchain review. The pin moves from 1.26.8 to 1.27.1: the toolchain line in go.mod, the golang image in the Dockerfile where there is one, explicit CI versions, and the docs that state the pin. CI's drift check keeps them equal. The go line is unchanged at 1.25.x. That line, not the toolchain, sets GODEBUG defaults, so the defaults Go 1.26 and 1.27 changed (cryptocustomrand, tlssecpmlkem, urlstrictcolons, tracebacklabels, x509sslcertoverrideplatform) keep their previous behaviour until the go line is raised on purpose. Verified on go1.27.1: build, vet, golangci-lint v2.14.0 built with go1.27.1 (0 issues, caps off), and go test -race green. Co-Authored-By: Claude Opus 5.5 Claude-Session: https://claude.ai/code/session_01GKRxaeYxyDhmt42cehLsGA --- .github/workflows/ci.yml | 8 ++++---- CHANGELOG.md | 3 +++ README.md | 2 +- go.mod | 2 +- 4 files changed, 9 insertions(+), 6 deletions(-) diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index aeca3bb..db41ce6 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -11,7 +11,7 @@ jobs: runs-on: ubuntu-latest strategy: matrix: - go-version: ["1.26.8"] + go-version: ["1.27.1"] steps: - uses: actions/checkout@v4 @@ -52,12 +52,12 @@ jobs: - uses: actions/checkout@v4 - uses: actions/setup-go@v5 with: - go-version: "1.26.8" + go-version: "1.27.1" cache: true - uses: golangci/golangci-lint-action@v7 with: version: v2.14.0 - # Build golangci-lint with the job's Go toolchain (1.26.8). The prebuilt + # Build golangci-lint with the job's Go toolchain (1.27.1). The prebuilt # release binaries are compiled with an older Go and refuse to lint a # module whose toolchain directive targets a newer Go ("the Go language # version used to build golangci-lint is lower than the targeted Go @@ -76,7 +76,7 @@ jobs: - uses: actions/checkout@v4 - uses: actions/setup-go@v5 with: - go-version: "1.26.8" + go-version: "1.27.1" cache: true - name: Install govulncheck run: go install golang.org/x/vuln/cmd/govulncheck@latest diff --git a/CHANGELOG.md b/CHANGELOG.md index ac0cbdf..628f75d 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -33,6 +33,9 @@ build toolchain. Both purely additive for consumers. ### Changed +- **Build toolchain: Go 1.26.8 → Go 1.27.1** (`toolchain` directive and CI). + The `go 1.25.0` minimum is unchanged: consumers are unaffected, and the + GODEBUG defaults this module's own tests run with stay those of Go 1.25. - **Build toolchain: Go 1.26.6 → Go 1.26.8** (`toolchain` directive and CI), picking up the 2026-08-28 security release. The `go 1.25.0` language minimum is unchanged, so consumers are unaffected. CI now fails if its Go and the diff --git a/README.md b/README.md index d21cea4..258c6b4 100644 --- a/README.md +++ b/README.md @@ -45,7 +45,7 @@ backendkit packages that foundation into a single, versioned dependency so every ## Requirements - **Go 1.25** or later to import the module. For building/releasing backendkit - itself, use **Go 1.26.8** (pinned via the `toolchain` directive in `go.mod`, + itself, use **Go 1.27.1** (pinned via the `toolchain` directive in `go.mod`, and checked against CI's Go on every run) so the binary picks up the latest Go standard-library security fixes; run `govulncheck ./...` to verify. Go 1.25 itself is out of support since Go 1.27's release — consumers should build with diff --git a/go.mod b/go.mod index 93b85a6..bd85574 100644 --- a/go.mod +++ b/go.mod @@ -7,7 +7,7 @@ go 1.25.0 // The go directive above stays at 1.25.0 so the module remains importable by // consumers on Go 1.25; this toolchain directive only governs builds where // backendkit is the main module. Keep it equal to the Go version in CI. -toolchain go1.26.8 +toolchain go1.27.1 require ( github.com/golang-jwt/jwt/v5 v5.3.1