Skip to content

build(deps): refresh Go modules and worker tooling - #1192

Merged
steipete merged 1 commit into
mainfrom
codex/gogcli-round8-deps
Oct 7, 2026
Merged

steipete merged 1 commit into
mainfrom
codex/gogcli-round8-deps

Conversation

@steipete

@steipete steipete commented Oct 7, 2026

Copy link
Copy Markdown
Collaborator

Refresh Google API, Google auth support, OpenTelemetry, generated protocol dependencies, and x/tools. Update the tracking worker's lint/test/build dependencies and patch-level pnpm 11 pin, keeping CI and package metadata aligned.

The Go 1.26 minimum and existing 24-hour worker release cooldown remain unchanged. Versions newer than the cooldown allows remain deferred, as do pnpm and transitive Nano ID major upgrades. Existing action pins, Go toolchain, gofumpt, golangci-lint, and Corepack are current. There were no open dependency-bot PRs to consolidate.

Validation passed on AWS: go mod verify, complete make ci, frozen worker install, worker lint/typecheck, and all 15 worker tests. Independent Codex review found no actionable P0–P2 issues. GitHub CI also validates the existing worker build and cross-platform/minimum-Go jobs.

The remote image initially selected pnpm 11.1.0; activating the pinned 11.28.5 through Corepack resolved that setup mismatch. Vitest 5.0.3 deliberately pins why-is-node-running to 3.2.1, explaining its transitive downgrade. No application code or production configuration changed.

@steipete
steipete requested a review from a team as a code owner October 7, 2026 06:28
@clawsweeper

clawsweeper Bot commented Oct 7, 2026 •

Copy link
Copy Markdown
Contributor

🦞👀
ClawSweeper picked this up.

Pull request received. I will update this pull request when review starts.

ClawSweeper review complete

ClawSweeper finished reviewing this revision. The review result is being finalized.

View the workflow run.

@clawsweeper clawsweeper Bot added P3 Low-risk cleanup, docs, polish, ergonomics, or speculative feature. rating: 🐚 platinum hermit Good normal PR readiness with ordinary maintainer review expected. status: 👀 ready for maintainer look ClawSweeper has no concrete contributor-facing blocker left for this PR. labels Oct 7, 2026
@clawsweeper

clawsweeper Bot commented Oct 7, 2026

Copy link
Copy Markdown
Contributor

Codex review: needs maintainer review before merge. Reviewed October 7, 2026, 2:30 AM ET / 06:30 UTC.

ClawSweeper review

What this changes

Updates Go client and telemetry dependencies, worker development tools and lockfiles, and the matching pnpm and Go-tool pins.

Merge readiness

✅ Ready for maintainer review

Keep open: this remains a useful dependency refresh absent from pinned main and v0.43.0. No actionable correctness or security defect was found.

Likely related people: steipete, a high-confidence routing candidate based on repeated prior dependency work.

Priority: P3
Reviewed head: 912a13ef0c80ec1702d81fe058c222ce873c6c1e

Review scores

Measure Result What it means
Overall readiness 🐚 platinum hermit (4/6) A focused, internally consistent dependency refresh with reported validation and no actionable review findings.
Proof confidence 🌊 off-meta tidepool Not applicable: The collaborator-authored refresh is exempt from ordinary contributor runtime proof; reported AWS checks and worker CI are supplemental validation. No authority-bearing application logic or stored-data contract changes are introduced.
Patch quality 🐚 platinum hermit (4/6) No actionable review findings were identified.

Verification

Check Result Evidence
Real behavior Not applicable Not applicable: The collaborator-authored refresh is exempt from ordinary contributor runtime proof; reported AWS checks and worker CI are supplemental validation. No authority-bearing application logic or stored-data contract changes are introduced.
Evidence reviewed 8 items Pinned introduced change: Inspected all eight introduced files, including the complete lockfile diff in bounded ranges. Changes are dependency versions, checksums, aligned tool pins, and an Unreleased changelog entry; application source, worker schema, and production configuration are unchanged.
Install safeguards preserved: The worker retains minimumReleaseAge: 1440 and the existing allowBuilds restrictions. Updated overrides agree with the lockfile; pnpm 11.28.5 agrees between package metadata and CI. Go 1.26.0 and the existing toolchain directive remain unchanged.
Still necessary on main: The original main package metadata uses pnpm 11.28.2, Vitest 5.0.2, and Wrangler 4.144.0; its Go module uses Google API v0.299.0. The refresh is distinct from those existing versions.
Findings None None.
Security None None.

How this fits together

Go dependencies support gog's authenticated Google Workspace commands. Worker tooling builds and tests the Cloudflare service that records email opens and serves tracking queries.

flowchart TD
  A[Dependency versions and checksums] --> B[Go build tools]
  A --> C[Worker package installation]
  C --> D[Lint tests and worker build]
  B --> E[Google Workspace CLI]
  D --> F[Email tracking worker]
Loading

Before merge

None.

Agent review details

Security

None.

Review metrics

None.

Technical review

Best possible solution:

Keep dependency pins and lockfiles synchronized while preserving the existing runtime floors and worker installation safeguards.

Do we have a high-confidence way to reproduce the issue?

Not applicable: this PR refreshes dependencies rather than reporting a reproducible application defect.

Is this the best way to solve the issue?

Yes: updating the existing manifests, checksums, and corresponding tool pins is a focused maintenance path without parallel implementation or changed product settings.

AGENTS.md: found and applied where relevant.

Codex review notes: model internal, reasoning medium; reviewed against 282ea0a629f6.

Labels

Label changes:

  • add P3: This is routine dependency maintenance with no demonstrated urgent user-facing failure.
  • add rating: 🐚 platinum hermit: Overall readiness is 🐚 platinum hermit; proof is 🌊 off-meta tidepool and patch quality is 🐚 platinum hermit.
  • add status: 👀 ready for maintainer look: ClawSweeper has no concrete contributor-facing blocker left for this PR. Not applicable: The collaborator-authored refresh is exempt from ordinary contributor runtime proof; reported AWS checks and worker CI are supplemental validation. No authority-bearing application logic or stored-data contract changes are introduced.

Label justifications:

  • P3: This is routine dependency maintenance with no demonstrated urgent user-facing failure.
  • rating: 🐚 platinum hermit: Overall readiness is 🐚 platinum hermit; proof is 🌊 off-meta tidepool and patch quality is 🐚 platinum hermit.
  • status: 👀 ready for maintainer look: ClawSweeper has no concrete contributor-facing blocker left for this PR. Not applicable: The collaborator-authored refresh is exempt from ordinary contributor runtime proof; reported AWS checks and worker CI are supplemental validation. No authority-bearing application logic or stored-data contract changes are introduced.

Evidence

What I checked:

  • Pinned introduced change: Inspected all eight introduced files, including the complete lockfile diff in bounded ranges. Changes are dependency versions, checksums, aligned tool pins, and an Unreleased changelog entry; application source, worker schema, and production configuration are unchanged. (912a13ef0c80)
  • Install safeguards preserved: The worker retains minimumReleaseAge: 1440 and the existing allowBuilds restrictions. Updated overrides agree with the lockfile; pnpm 11.28.5 agrees between package metadata and CI. Go 1.26.0 and the existing toolchain directive remain unchanged. (internal/tracking/worker/pnpm-workspace.yaml:1, 912a13ef0c80)
  • Still necessary on main: The original main package metadata uses pnpm 11.28.2, Vitest 5.0.2, and Wrangler 4.144.0; its Go module uses Google API v0.299.0. The refresh is distinct from those existing versions. (internal/tracking/worker/package.json:15, 282ea0a629f6)
  • Latest release comparison: v0.43.0 also contains the older worker versions. Its Go module retains Google API v0.299.0, so the requested refresh is not already shipped in the supplied latest release. (internal/tracking/worker/package.json:15, 3b5122f4c81c)
  • Reported validation and proof exemption: The captured PR body reports AWS go mod verify, complete make ci, frozen worker installation, lint/typecheck, and 15 passing worker tests. These were not rerun during this read-only review. GitHub REST confirms the pinned head is open, unmerged, and authored by a COLLABORATOR; the ordinary external-contributor runtime-proof gate therefore does not apply. (912a13ef0c80)
  • Prior area work: Local history shows repeated earlier dependency updates by Peter Steinberger. GitHub commit metadata verifies steipete as the author account for the prior worker refresh at build(deps): refresh policy-eligible worker dependencies #1178. This supports routing, not a source-line introduction claim. (internal/tracking/worker/package.json, 132b3cadc77e)

Likely related people:

  • steipete: Suggested for follow-up; no historical authorship or introduction is verified. (role: unverified routing candidate; confidence: low)

Rating scale

Score Internal tier Crab rank Meaning
6/6 S 🦀 challenger crab Exceptional readiness
5/6 A 🦞 diamond lobster Very strong readiness
4/6 B 🐚 platinum hermit Good normal PR; ordinary maintainer review
3/6 C 🦐 gold shrimp Useful, but confidence is limited
2/6 D 🦪 silver shellfish Proof or implementation needs work
1/6 F 🧂 unranked krab Not merge-ready
N/A NA 🌊 off-meta tidepool Rating does not apply

Overall follows the weaker of proof and patch quality.
Shiny media proof means a screenshot, video, or linked artifact directly shows the changed behavior. Runtime, network, CSP, and security claims still need visible diagnostics.

Workflow

  • ClawSweeper keeps one durable marker-backed review comment per issue or PR.
  • Re-runs edit this comment so the latest verdict, findings, and automation markers stay together instead of adding duplicate bot comments.
  • A fresh review can be triggered by eligible @clawsweeper re-review comments, exact-item GitHub events, scheduled/background review runs, or manual workflow dispatch.
  • PR/issue authors and users with repository write access can comment @clawsweeper re-review or @clawsweeper re-run on an open PR or issue to request a fresh review only.
  • Maintainers can also comment @clawsweeper review to request a fresh review only.
  • Fresh-review commands do not start repair, autofix, rebase, CI repair, or automerge.
  • Maintainer-only repair and merge flows require explicit commands such as @clawsweeper autofix, @clawsweeper automerge, @clawsweeper fix ci, or @clawsweeper address review.
  • Maintainers can comment @clawsweeper explain to ask for more context, or @clawsweeper stop to stop active automation.

@steipete
steipete merged commit 4d7478e into main Oct 7, 2026
11 checks passed
@steipete
steipete deleted the codex/gogcli-round8-deps branch October 7, 2026 06:39
@steipete

steipete commented Oct 7, 2026

Copy link
Copy Markdown
Collaborator Author

Landed as 4d7478e after exact-head CI passed Linux, minimum Go, Windows, macOS build, and the tracking worker. Docker and CodeQL also passed.

Before publication, AWS validation passed go mod verify, the complete make ci gate, frozen worker install, lint, typecheck, and all 15 worker tests. Independent P0–P2 review was clean. The initial runner pnpm mismatch was resolved by activating the exact project pin through Corepack; no source workaround was required.

Go 1.26 and the 24-hour worker release cooldown are unchanged. No manual deployment, release, tag, or application version bump was performed.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

P3 Low-risk cleanup, docs, polish, ergonomics, or speculative feature. rating: 🐚 platinum hermit Good normal PR readiness with ordinary maintainer review expected. status: 👀 ready for maintainer look ClawSweeper has no concrete contributor-facing blocker left for this PR.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant