Golang
Description
The golang crawler looks recursively for every go.mod file from a root directory, and updates two independent things:
the Go version declared by the
godirective. Restrict to this withonlygoversion: true.the module versions declared in
requireandreplacedirectives. Restrict to these withonlygomodule: true.
This crawler is enabled by default, so it can be used either automatically by running updatecli diff from a directory containing the files to update, or by providing a manifest.
The automatic discovery behavior can be tuned by providing a YAML manifest with a golang crawler in top-level directive autodiscovery as explained in the "Autodiscovery" page.
Note | The aliases go and golang/gomod can also be used instead of golang. |
Generated manifests
| Update | Manifest shape |
|---|---|
Go version | A |
Module | A |
Modules already pinned to a pseudo-version are handled as such, so a pseudo-version is not replaced by a tagged release.
go mod tidy
When a change is applied, Updatecli can run go mod tidy to keep go.sum consistent. That extra shell target is only added when both conditions hold:
a
go.sumfile sits next to thego.mod, andthe
gobinary is available onPATH.
If a go.sum is present but Go is not installed, the target is omitted and a warning is logged, since go.sum would otherwise drift out of sync.
Release age
The age parameter filters out releases that are too new or too old, which is useful to avoid adopting a version the day it ships. minimum and maximum accept a duration such as 24h, 7d, 3w, 6mo, or 1y; a bare number is read as hours.
Limitations
Modules marked
// indirectare not updated. They are expected to follow from their parent module, or fromgo mod tidy.
Manifest
Parameters
| Name | Type | Description | Required |
|---|---|---|---|
| age | object | “age” defines the minimum or maximum age of a release to be considered valid. default: empty, no age filtering. remark:
| |
| maximum | string | “maximum” defines the maximum age a release may have to be considered. remark:
example:
| |
| minimum | string | “minimum” defines the minimum age a release must have to be considered. remark:
example:
| |
| ignore | array | “ignore” defines rules to exclude matching Go modules or Go versions from the autodiscovery. remark:
| |
| goversion | string | “goversion” defines a Go version constraint to match. remark:
example:
| |
| modules | object | “modules” defines the Go modules to match, keyed by module name. remark:
example:
| |
| path | string | “path” defines a go.mod path pattern. remark:
example:
| |
| replace | boolean | “replace” defines whether the module must come from a replace directive. default: unset, any module matches. remark:
| |
| only | array | “only” defines rules to restrict the autodiscovery to matching Go modules or Go versions. remark:
| |
| goversion | string | “goversion” defines a Go version constraint to match. remark:
example:
| |
| modules | object | “modules” defines the Go modules to match, keyed by module name. remark:
example:
| |
| path | string | “path” defines a go.mod path pattern. remark:
example:
| |
| replace | boolean | “replace” defines whether the module must come from a replace directive. default: unset, any module matches. remark:
| |
| onlygomodule | boolean | “onlygomodule” restricts the autodiscovery to the Go modules defined in go.mod. default: false | |
| onlygoversion | boolean | “onlygoversion” restricts the autodiscovery to the Go version defined in go.mod. default: false remark:
| |
| rootdir | string | “rootdir” defines the directory where the crawler starts searching for go.mod files. default: the scm directory when “scmid” is set, otherwise the directory relative paths resolve from, by default the working directory. remark:
| |
| versionfilter | object | “versionfilter” defines the version filter used by the generated manifests. default: kind “semver” with pattern “*”, any version greater than or equal to the current one. remark:
example: | |
| kind | string | “kind” defines the versioning scheme used to select a version. default: latest remark:
example:
| |
| pattern | string | “pattern” defines the version pattern, according to “kind”. default:
remark:
example:
| |
| regex | string | “regex” defines the regular expression extracting the version from each entry. remark:
example:
| |
| replaceall | object | “replaceall” applies a regular expression replacement to each version before filtering. remark:
example: turns “curl-8_15_0” into “curl-8.15.0”. | |
| pattern | string | “pattern” defines the regular expression matching the text to replace. example:
| |
| replacement | string | “replacement” defines the text replacing each match of “pattern”. remark:
example:
| |
| strict | boolean | “strict” enforces strict semantic versioning rules when parsing versions. default: false remark:
| |
| vulnerability | object | “vulnerability” switches the autodiscovery to security updates, based on the OSV database (https://osv.dev). Each Go module is updated to the lowest version without known vulnerabilities, and left untouched when it has none. remark:
example: | |
| ignore | array | “ignore” defines the vulnerability IDs or aliases to disregard. example: | |
| minseverity | string | “minseverity” defines the minimum severity of the vulnerabilities to account for. remark:
example:
| |
| strategy | string | “strategy” defines the version a vulnerable dependency is updated to. default: lowest remark:
| |
| url | string | “url” defines the OSV API URL. default: https://api.osv.dev |
Example
Golang update only
In the following example, we want to automate minor version update of Golang, such as from "1.19" to "1.20" If Updatecli detects a change, then it opens a new pull request with the propose version update.
# updatecli.d/default.yaml
name: "Bump Golang Version"
scms:
default:
kind: github
spec:
owner: olblak
repository: updatecli
token: {{ requiredEnv "GITHUB_TOKEN" }}
username: {{ requiredEnv "GITHUB_ACTOR" }}
branch: main
actions:
default:
kind: github/pullrequest
scmid: default
spec:
labels:
- "dependencies"
autodiscovery:
scmid: default
actionid: default
crawlers:
golang:
versionfilter:
kind: semver
pattern: minor
only:
- goversion: "*"
Semantic version patch update only
In this example, Updatecli is looking for all version that can have a patch version update. If at least one version needs to be updated, then it opens a single pull request with all the version bump.
# updatecli.d/default.yaml
name: "Bump Patch version for Golang module"
scms:
default:
kind: github
spec:
owner: olblak
repository: updatecli
token: {{ requiredEnv "GITHUB_TOKEN" }}
username: {{ requiredEnv "GITHUB_ACTOR" }}
branch: main
actions:
default:
# The action title is used to define the pullrequest title
# Since we use the groupby set to all we need to be sure that the pullrequest title
# is the same for all the pipeline generated by autodiscovery.
title: Bump Patch version for Golang module
kind: github/pullrequest
scmid: default
spec:
labels:
- "dependencies"
autodiscovery:
scmid: default
actionid: default
groupby: all
crawlers:
golang:
versionfilter:
kind: semver
pattern: patch
ignore:
- modules:
# Ignoring the following modules as they do not publish release
github.com/ProtonMail/go-crypto:
# Ignoring the following modules as they do not publish release
github.com/shurcooL/githubv4:
# Ignore module using version matching constraint 1.x
helm.sh/helm/v3: "1.x"
# The remote version uses the version v0.0.0-20190318233801-ac98e3ecb4b0 which do not exists anymore
# the patch version will try to fetch the version matching 0.0.x and finds nothing
github.com/iancoleman/orderedmap:
# Same for https://pkg.go.dev/golang.org/x/time?tab=versions
golang.org/x/time: