Repository navigation
ci: bump actions/setup-go from 5 to 6 - #3
Closed
dependabot[bot] wants to merge 1 commit into
Closed
dependabot[bot] wants to merge 1 commit into
dependabot[bot] wants to merge 1 commit into
Conversation
Bumps [actions/setup-go](https://github.com/actions/setup-go) from 5 to 6. - [Release notes](https://github.com/actions/setup-go/releases) - [Commits](actions/setup-go@v5...v6) --- updated-dependencies: - dependency-name: actions/setup-go dependency-version: '6' dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
Contributor
Author
|
Looks like actions/setup-go is up-to-date now, so this is no longer needed. |
EricAndrechek
added a commit
that referenced
this pull request
Apr 23, 2026
Medium-severity findings from Claude's re-review, plus three unresolved Copilot threads tied to the same work. 1. board-state-sync.yml guard used \`exit 0\` on missing PROJECT_BOARD_TOKEN — which only exits the step shell, not the job. Subsequent steps would run with an empty GH_TOKEN and fail. Switched to the SKIP_BOARD=true env-var pattern used in project-orchestrator.yml (Claude Medium #1). 2. project-orchestrator.yml: when SKIP_BOARD is set, the pr-status step is skipped and its \`promote\` output is unset, which caused the Assign + request review step's \`promote == 'true'\` condition to silently fail — skipping reviewer assignment even though that operation uses GITHUB_TOKEN and doesn't need the board token. Extended the condition to also allow \`env.SKIP_BOARD == 'true'\` (Claude Medium #2). 3. dependabot-automerge.yml major-bump flow: reordered so the token guard + board-add + assign steps run before the comment, and the comment wording is now conditional on SKIP_BOARD — previously the comment claimed "Added to the Task Board" before the board-add even ran, and if the token was missing the claim was false (Claude Low #3 / Copilot R4 restated). 4. AGENTS.md §Review tooling reference table — three stale facts corrected to match the new implementation: - review-request channel IS used now (not "intentionally not") - re-eval trigger is workflow_run + bot COMMENTED reviews, not check_suite (documented the GITHUB_TOKEN suppression reason) - reviewer selection is single-pick parity-based, not "both admins" (Claude Low #4) 5. Copilot R4 remaining: board-state-sync comment referenced \`closingPullRequestsReferences\` on a line I hadn't fixed in an earlier round. Verified all references now align on \`closedByPullRequestsReferences\` (the actual field name). Also added a SKIP_BOARD guard to every subsequent step in board-state-sync.yml so the "not-configured" path produces a clean no-op instead of a cascade of failing gh calls.
EricAndrechek
added a commit
that referenced
this pull request
Apr 28, 2026
Medium-severity findings from Claude's re-review, plus three unresolved Copilot threads tied to the same work. 1. board-state-sync.yml guard used \`exit 0\` on missing PROJECT_BOARD_TOKEN — which only exits the step shell, not the job. Subsequent steps would run with an empty GH_TOKEN and fail. Switched to the SKIP_BOARD=true env-var pattern used in project-orchestrator.yml (Claude Medium #1). 2. project-orchestrator.yml: when SKIP_BOARD is set, the pr-status step is skipped and its \`promote\` output is unset, which caused the Assign + request review step's \`promote == 'true'\` condition to silently fail — skipping reviewer assignment even though that operation uses GITHUB_TOKEN and doesn't need the board token. Extended the condition to also allow \`env.SKIP_BOARD == 'true'\` (Claude Medium #2). 3. dependabot-automerge.yml major-bump flow: reordered so the token guard + board-add + assign steps run before the comment, and the comment wording is now conditional on SKIP_BOARD — previously the comment claimed "Added to the Task Board" before the board-add even ran, and if the token was missing the claim was false (Claude Low #3 / Copilot R4 restated). 4. AGENTS.md §Review tooling reference table — three stale facts corrected to match the new implementation: - review-request channel IS used now (not "intentionally not") - re-eval trigger is workflow_run + bot COMMENTED reviews, not check_suite (documented the GITHUB_TOKEN suppression reason) - reviewer selection is single-pick parity-based, not "both admins" (Claude Low #4) 5. Copilot R4 remaining: board-state-sync comment referenced \`closingPullRequestsReferences\` on a line I hadn't fixed in an earlier round. Verified all references now align on \`closedByPullRequestsReferences\` (the actual field name). Also added a SKIP_BOARD guard to every subsequent step in board-state-sync.yml so the "not-configured" path produces a clean no-op instead of a cascade of failing gh calls.
EricAndrechek
added a commit
that referenced
this pull request
May 13, 2026
6 tasks
EricAndrechek
added a commit
that referenced
this pull request
Jun 4, 2026
Extract the ~210-line format-detection / record-reader machinery (the recordReader interface, the object/array/line readers, the sentinels, and the content-sniffing newRecordReader factory) out of ingest.go into a new record_reader.go. ingest.go drops from 665 to 428 lines and is now focused on the handler pipeline (Handle / handleSingle / handleBatch / processRecord). No behavior change. Also DRY the whole-request abort response (status + optional Retry-After) into a shared writeAbort helper used by both the single-object and batch paths. Revert the README ingest array example (those docs land on a separate branch) and drop README.md from the CHANGELOG file list; add record_reader.go there and point AGENTS.md design decision #3 at it. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
3 tasks done
EricAndrechek
added a commit
that referenced
this pull request
Sep 4, 2026
Two findings from taitelee's review. AGENTS.md invariant #3 still described ingest as "takes flat JSON, validated against the discovered schema. No envelope." — nothing about the declared Content-Type choosing the format, or the 415 landing before the body is read. That file is the index an agent reads before touching internal/api, and §Doc Sync pairs it with architecture.md for exactly this kind of change. A fail-closed precondition belongs there. One clause added. The second is the better catch, and it is an operational one I had missed entirely: the comma-join case is explained only in api.md, but the people who hit it are operators with a proxy, not callers. reverse-proxy.mdx enumerates every other header whose forwarding matters — Authorization, X-Operator-Key, the X-Forwarded-* family, CORS — and never mentioned Content-Type. The failure mode is specific and quiet. A proxy appending a second header LINE is fine: both are resolved and accepted when they agree. A proxy that MERGES duplicates into one comma-joined value — Envoy's `append: true`, some WAF rewrite rules — produces `application/json, application/json`, which is a 415 on every ingest even though both halves are identical. Someone flipping that setting would see ingest fail fleet-wide with nothing on the proxy page to point at. Verified rather than repeated: two agreeing LINES resolve to json with no error; the MERGED value returns errUnsupportedContentType. The bullet says forward it verbatim, explains the line-vs-merge distinction, and links back to the api.md section. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01FZqHaWmHxxNLRUEQy5ZYRw
EricAndrechek
added a commit
that referenced
this pull request
Sep 4, 2026
The reordering this branch exists to establish had no test defending it. Every 415 case passes a small, readable body, so moving resolveContentType back below body.ReadFrom left the entire suite green while making an unsupported request pay for a full 16 MiB buffer — and AGENTS.md Key Design Decision #3 ("a 415 decided *before* the body is read") would have become false with nothing to say so. Verified by mutation: hoisting the buffer read above resolution fails both new subtests (415 -> 400, 415 -> 413) and no pre-existing test at all. The body-cap consequence reached table.ts's insertNDJSON docstring, api.md and reverse-proxy.mdx but not the SDK doc page for that same method, whose example uploads a whole .ndjson file. That page is where a reader forms the "NDJSON is the big-upload path" belief this branch retires. The adjacent array-insert paragraph had the same gap. architecture.md's ingest flow skipped from the Content-Type step straight to schema validation, so the step both neighbours point at ("before the body is parsed", "before the body is read") was invisible. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01FZqHaWmHxxNLRUEQy5ZYRw
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps actions/setup-go from 5 to 6.
Release notes
Sourced from actions/setup-go's releases.
... (truncated)
Commits
4b73464Fix golang download url to go.dev (#469)a5f9b05Update default Go module caching to use go.mod (#705)7a3fe6cBump qs from 6.14.0 to 6.14.1 (#703)b9adafdBump actions/checkout from 5 to 6 (#686)d73f6bcREADME.md: correct to actions/checkout@v6 (#683)ae252eeBump@actions/cacheto v5 (#695)bf7446aBump js-yaml from 3.14.1 to 3.14.2 (#682)02aadfeFix Node.js version in action.yml (#691)4aaadf4Example for restore-only cache in documentation (#696)4dc6199Bump semver and@types/semver(#652)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)