Skip to content

chore: complete mergo migration — port remaining call sites in merge_yaml_functions.go and config_loader.go #2242

Description

@nitrocode

Summary

PR #2201 replaced the hot-path deep merge implementation with a native Go implementation (deepMergeNative) that is ~3.5× faster. However, the mergo library is still used in two lower-traffic call sites:

  • pkg/merge/merge_yaml_functions.go — YAML function merge helpers
  • pkg/devcontainer/config_loader.go — devcontainer config loading

Goal

  1. Port pkg/merge/merge_yaml_functions.go to use deepMergeNative / MergeWithOptions
  2. Port pkg/devcontainer/config_loader.go to use the native merge
  3. Remove dario.cat/mergo from go.mod / go.sum entirely (eliminates CVE surface)

Why

Until these sites are ported, a future CVE in mergo could still affect atmos. The dependency should be dropped once no call sites remain.

References

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions