chore: Update Go and third-party dependencies#2656
Conversation
Updated Go to version 1.25.7 and refreshed several Go modules, including `github.com/google/cel-go`, `github.com/tektoncd/pipeline`, `go.opentelemetry.io/otel`, and `knative.dev/eventing` to incorporate recent improvements and security patches. This clear security issue on go jose for example Signed-off-by: Chmouel Boudjnah <chmouel@redhat.com>
|
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #2656 +/- ##
=======================================
Coverage 58.80% 58.80%
=======================================
Files 206 206
Lines 20304 20304
=======================================
Hits 11940 11940
Misses 7591 7591
Partials 773 773 ☔ View full report in Codecov by Sentry. 🚀 New features to boost your workflow:
|
There was a problem hiding this comment.
Code Review
This pull request updates the Go version to 1.25.7 and increments several dependency versions, including Tekton pipelines, OpenTelemetry, and various Kubernetes-related libraries. Feedback points out a discrepancy between the pull request description and the actual changes, specifically noting that intended security updates for the go-jose dependency are missing from the go.mod file.
📝 Description of the Change
Updated Go to version 1.25.7 and refreshed several Go modules, including
github.com/google/cel-go,github.com/tektoncd/pipeline,go.opentelemetry.io/otel, andknative.dev/eventingto incorporate recent improvements and security patches.🔗 Linked GitHub Issue
Fixes #
🧪 Testing Strategy
🤖 AI Assistance
AI assistance can be used for various tasks, such as code generation,
documentation, or testing.
Please indicate whether you have used AI assistance
for this PR and provide details if applicable.
Important
Slop will be simply rejected, if you are using AI assistance you need to make sure you
understand the code generated and that it meets the project's standards. you
need at least know how to run the code and deploy it (if needed). See
startpaac to make it easy
to deploy and test your code changes.
If the majority of the code in this PR was generated by an AI, please add a
Co-authored-bytrailer to your commit message.For example:
Co-authored-by: Claude noreply@anthropic.com
✅ Submitter Checklist
fix:,feat:) matches the "Type of Change" I selected above.make testandmake lintlocally to check for and fix anyissues. For an efficient workflow, I have considered installing
pre-commit and running
pre-commit installtoautomate these checks.