chore(deps): bump github.com/go-git/go-git/v5 from 5.17.2 to 5.18.0 - #63
Closed
dependabot[bot] wants to merge 1 commit into
Closed
dependabot[bot] wants to merge 1 commit into
dependabot[bot] wants to merge 1 commit into
Conversation
Bumps [github.com/go-git/go-git/v5](https://github.com/go-git/go-git) from 5.17.2 to 5.18.0. - [Release notes](https://github.com/go-git/go-git/releases) - [Changelog](https://github.com/go-git/go-git/blob/main/HISTORY.md) - [Commits](go-git/go-git@v5.17.2...v5.18.0) --- updated-dependencies: - dependency-name: github.com/go-git/go-git/v5 dependency-version: 5.18.0 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
Contributor
Author
|
Superseded by #68. |
dependabot
Bot
deleted the
dependabot/go_modules/github.com/go-git/go-git/v5-5.18.0
branch
May 11, 2026 08:22
phpboyscout
added a commit
that referenced
this pull request
Sep 15, 2026
"telemetry.enabled" was spelled as a literal eleven times across five files in four packages; the update.* trust keys three times each; the ai.* keys had constants in pkg/chat that six call sites in the generator and the adapter did not use. A key is part of a tool's config contract, and a copy is a place for the spelling to drift. pkg/setup/config_keys.go now holds the update and telemetry keys (the packages that read them already import setup), pkg/chat/constants.go gains the missing ai keys, and every consumer reads the constant. A test in internal/repopolicy scans pkg/ and cli/pkg/ for a literal of those three families outside its constants file; it was red at 41 sites. The server.* family moves with the http/grpc adapter merge. Closes #63
phpboyscout
added a commit
that referenced
this pull request
Sep 15, 2026
"telemetry.enabled" was spelled as a literal eleven times across five files in four packages; the update.* trust keys three times each; the ai.* keys had constants in pkg/chat that call sites in the generator and the adapter did not use. A key is part of a tool's config contract, and a copy is a place for the spelling to drift. pkg/setup/config_keys.go now holds the update and telemetry keys (the packages that read them already import setup), pkg/chat/constants.go gains the missing ai keys, and every framework consumer reads the constant. A test in internal/repopolicy scans pkg/ for a literal of those three families outside its constants file; it was red at 35 sites. Two CLI sites keep "ai.model" and "ai.claude.local" as literals for now: cli/go.mod builds against the released framework, so the CLI can adopt a constant only one release after pkg/ declares it (the cli-release-build job is what caught it). The guard widens to cli/pkg and those two sites move once the framework that carries the constants is released. The server.* family moves with the http/grpc adapter merge. Refs #63
phpboyscout
added a commit
that referenced
this pull request
Sep 15, 2026
"telemetry.enabled" was spelled as a literal eleven times across five files in four packages; the update.* trust keys three times each; the ai.* keys had constants in pkg/chat that call sites in the generator and the adapter did not use. A key is part of a tool's config contract, and a copy is a place for the spelling to drift. pkg/setup/config_keys.go now holds the update and telemetry keys (the packages that read them already import setup), pkg/chat/constants.go gains the missing ai keys, and every framework consumer reads the constant. A test in internal/repopolicy scans pkg/ for a literal of those three families outside its constants file; it was red at 35 sites. Two CLI sites keep "ai.model" and "ai.claude.local" as literals for now: cli/go.mod builds against the released framework, so the CLI can adopt a constant only one release after pkg/ declares it (the cli-release-build job is what caught it). The guard widens to cli/pkg and those two sites move once the framework that carries the constants is released. The server.* family moves with the http/grpc adapter merge. Refs #63
phpboyscout
added a commit
that referenced
this pull request
Sep 17, 2026
… keys once The first half (5cbbc1a) moved the update, telemetry and ai families to constants and guarded pkg/ for them. This closes the rest: the forge and chat credential subtrees, log.*, vcs.provider, and the CLI, which the workspace now lets adopt a framework constant in the same change. credentialposture gains SingleToken(prefix) and DualCredential(prefix), the one statement of the <prefix>.auth.* and Bitbucket key layouts. The forge profiles read their keys and keychain account from them (the KeychainAccount field goes, it was the prefix plus ".auth" five times), and so does the posture declaration in check.go. chat gains ProviderCredentialKeys, the enumeration of its credential roots. config migrate's credential table is one table again: each row carries the keys, keychain account, fallback env var and blob field, with the chat rows derived from chat and the forge rows from the layout helpers; jsonBlobFieldFor and defaultEnvVarName look the row up instead of repeating the keys in a switch. The root's protected project keys read the same sources. log.level and log.format join setup's keys file, vcs.provider is vcs.ConfigKeyProvider, and the generator reads the chat constants for the provider key, ai.model and ai.claude.local. The repopolicy guard now covers every family above in pkg/ and cli/pkg/, skipping constant declarations and struct tags. It was red at 71 sites. Closes #63
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps github.com/go-git/go-git/v5 from 5.17.2 to 5.18.0.
Release notes
Sourced from github.com/go-git/go-git/v5's releases.
Commits
ea3e7ecMerge pull request #2004 from go-git/v5-http-hardeningbcd20a9plumbing: transport/http, Add support for followRedirects policyDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)