Repository navigation
build(deps): refresh Go modules and worker tooling - #1192
Conversation
|
🦞👀 Pull request received. I will update this pull request when review starts. ClawSweeper review completeClawSweeper finished reviewing this revision. The review result is being finalized. |
|
Codex review: needs maintainer review before merge. Reviewed October 7, 2026, 2:30 AM ET / 06:30 UTC. ClawSweeper reviewWhat this changesUpdates Go client and telemetry dependencies, worker development tools and lockfiles, and the matching pnpm and Go-tool pins. Merge readiness✅ Ready for maintainer review Keep open: this remains a useful dependency refresh absent from pinned main and v0.43.0. No actionable correctness or security defect was found. Likely related people: steipete, a high-confidence routing candidate based on repeated prior dependency work. Priority: P3 Review scores
Verification
How this fits togetherGo dependencies support gog's authenticated Google Workspace commands. Worker tooling builds and tests the Cloudflare service that records email opens and serves tracking queries. flowchart TD
A[Dependency versions and checksums] --> B[Go build tools]
A --> C[Worker package installation]
C --> D[Lint tests and worker build]
B --> E[Google Workspace CLI]
D --> F[Email tracking worker]
Before mergeNone. Agent review detailsSecurityNone. Review metricsNone. Technical reviewBest possible solution: Keep dependency pins and lockfiles synchronized while preserving the existing runtime floors and worker installation safeguards. Do we have a high-confidence way to reproduce the issue? Not applicable: this PR refreshes dependencies rather than reporting a reproducible application defect. Is this the best way to solve the issue? Yes: updating the existing manifests, checksums, and corresponding tool pins is a focused maintenance path without parallel implementation or changed product settings. AGENTS.md: found and applied where relevant. Codex review notes: model internal, reasoning medium; reviewed against 282ea0a629f6. LabelsLabel changes:
Label justifications:
EvidenceWhat I checked:
Likely related people:
Rating scale
Overall follows the weaker of proof and patch quality. Workflow
|
|
Landed as 4d7478e after exact-head CI passed Linux, minimum Go, Windows, macOS build, and the tracking worker. Docker and CodeQL also passed. Before publication, AWS validation passed Go 1.26 and the 24-hour worker release cooldown are unchanged. No manual deployment, release, tag, or application version bump was performed. |
Refresh Google API, Google auth support, OpenTelemetry, generated protocol dependencies, and x/tools. Update the tracking worker's lint/test/build dependencies and patch-level pnpm 11 pin, keeping CI and package metadata aligned.
The Go 1.26 minimum and existing 24-hour worker release cooldown remain unchanged. Versions newer than the cooldown allows remain deferred, as do pnpm and transitive Nano ID major upgrades. Existing action pins, Go toolchain, gofumpt, golangci-lint, and Corepack are current. There were no open dependency-bot PRs to consolidate.
Validation passed on AWS:
go mod verify, completemake ci, frozen worker install, worker lint/typecheck, and all 15 worker tests. Independent Codex review found no actionable P0–P2 issues. GitHub CI also validates the existing worker build and cross-platform/minimum-Go jobs.The remote image initially selected pnpm 11.1.0; activating the pinned 11.28.5 through Corepack resolved that setup mismatch. Vitest 5.0.3 deliberately pins
why-is-node-runningto 3.2.1, explaining its transitive downgrade. No application code or production configuration changed.