Skip to content

Foundation hardening before plugin registry - #55

Merged
devops-rob merged 10 commits into
mainfrom
foundation-hardening-pre-registry
Aug 1, 2026
Merged

devops-rob merged 10 commits into
mainfrom
foundation-hardening-pre-registry

Conversation

@devops-rob

@devops-rob devops-rob commented Aug 1, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • Align Go toolchain to 1.25 (.go-version, go.mod, CI workflows)
  • Fix builtin protobuf registration conflicts by renaming 19 plugin.proto files to unique names and regenerating plugins
  • Remove all GOLANG_PROTOBUF_REGISTRATION_CONFLICT workarounds from CI, Docker, and E2E tests
  • Bump tier-3b dependencies (grpc v1.56.3, x/text, go-git, runc; migrate to distribution/reference)
  • Add informational govulncheck CI job and document deferred findings in docs/security/vuln-triage.md
  • Fix Go 1.25 vet errors and singleprocess test timeouts (background goroutine cleanup, Horizon skip guard)

Change Classification

  • Open-core MPL files only (derrick)

Test plan

  • GOWORK=off go test ./pkg/server/singleprocess/... (~29s)
  • GOWORK=off make bin/cli-only && ./derrick version (clean, no protobuf stderr)
  • GOWORK=off go vet on previously failing packages
  • Full CI matrix (unit, integration, E2E)

Dependencies

  • Merge and tag derrick-plugin-sdk#1 as v0.1.1, then bump go.mod SDK dependency in a follow-up commit

devops-rob and others added 2 commits August 1, 2026 02:17
Align Go toolchain to 1.25, fix builtin protobuf registration conflicts,
remove GOLANG_PROTOBUF_REGISTRATION_CONFLICT workarounds, bump tier-3b
dependencies, add govulncheck CI, document deferred vulns, and fix
singleprocess test lifecycle hangs.

Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
devops-rob and others added 8 commits August 1, 2026 02:45
Use *Service type assertion in test helpers so non-test packages compile,
and upgrade golangci-lint to v2.1.6 for Go 1.25 export data support.

Co-authored-by: Cursor <cursoragent@cursor.com>
Use --default=none and run gofmt separately since v2 removed --disable-all.

Co-authored-by: Cursor <cursoragent@cursor.com>
Use xargs for gofmt file list to avoid SC2046 word-splitting warning.

Co-authored-by: Cursor <cursoragent@cursor.com>
Prebuilt golangci-lint binaries are built with Go 1.24 and cannot target
Go 1.25; gofmt + go vet preserves the same checks without that mismatch.

Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
Remove unreachable code, cancel stream contexts on all error paths, and
avoid copying protobuf refs that embed sync.Mutex in tests.

Co-authored-by: Cursor <cursoragent@cursor.com>
Use golangci-lint built with Go 1.25 with lostcancel disabled for the
runner accept loop, and compare on-demand runner targets with proto.Equal.

Co-authored-by: Cursor <cursoragent@cursor.com>
Wait for the runner to reconnect after a simulated server restart before
unblocking job completion, and tolerate transient stream errors when
sending the job complete message.

Co-authored-by: Cursor <cursoragent@cursor.com>
@devops-rob
devops-rob merged commit f569063 into main Aug 1, 2026
32 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant