Update dependency golangci-lint to v2.13.2 - #1018
Conversation
AI Dependency Impact AnalysisPrevious analysisRisk Level: HIGHSummary of Dependency ChangesThis dependency update bumps Affected CodeAs Breaking Change AssessmentWhile minor version bumps in Go generally adhere to semver, Security AssessmentNo specific security advisories or Supply-Chain AssessmentThis PR has failed supply-chain validation with the following finding:
Recommended ActionNeeds careful review Do NOT merge this PR automatically. A maintainer must manually inspect the changes made to the Risk Level: HIGHSummary of Dependency ChangesThe dependency Affected CodeAs a linting tool, Breaking Change AssessmentAlthough this is a minor bump, Security AssessmentNo security advisories or Supply-Chain AssessmentThis PR has failed supply-chain validation.
Recommended ActionNeeds careful review: This PR should not be merged automatically. A reviewer must manually inspect the changes to the |
There was a problem hiding this comment.
Risk Level: HIGH
Summary of Dependency Changes
This dependency update bumps golangci-lint from v2.8.0 to v2.13.1. Key changes include Go 1.26 and Go 1.27 support, the addition of the new clickhouselint linter, numerous updates and new rules for existing linters (such as gosec, govet, revive, and wsl), and multiple bug fixes across various linters.
Affected Code
As golangci-lint is a development tool, there are typically no direct Go code imports of this package in the codebase. However, this PR modifies the Makefile, which is used to orchestrate build, test, and linting pipelines.
Breaking Change Assessment
While minor version bumps in Go generally adhere to semver, golangci-lint updates frequently introduce new linter rules or modify existing ones (such as revive breaking changes moving package-related checks to package-naming), which can break CI pipelines due to new lint failures. However, the primary concern for this PR is the supply-chain validation failure rather than linter behavior.
Security Assessment
No specific security advisories or govulncheck vulnerabilities were reported. However, unauthorized modifications to build infrastructure files (like Makefile) pose a critical security risk.
Supply-Chain Assessment
This PR has failed supply-chain validation with the following finding:
- SUPPLY_CHAIN_UNEXPECTED_SCOPE: This dependency PR modifies files outside the expected scope for a dependency update. Specifically, it modifies the
Makefile. Dependency updates should only modify package manifests (e.g.,go.mod,go.sum) or lockfiles. Modifying build scripts is a known attack vector for injecting malicious behavior into CI/CD pipelines or local development environments.
Recommended Action
Needs careful review
Do NOT merge this PR automatically. A maintainer must manually inspect the changes made to the Makefile to ensure they are legitimate and do not introduce malicious commands or unexpected build behaviors.
|
🤖 Finished Review · ✅ Success · Started 1:57 AM UTC · Completed 2:05 AM UTC Commit: Runtime: claude · Model: opus → claude-opus-4-6 · Effort: high · Cost: $2.11 |
|
Looks good to me Previous runLooks good to me |
Codecov Report✅ All modified and coverable lines are covered by tests.
Additional details and impacted files@@ Coverage Diff @@
## main #1018 +/- ##
===========================================
- Coverage 76.74% 30.56% -46.19%
===========================================
Files 26 26
Lines 2817 2817
===========================================
- Hits 2162 861 -1301
- Misses 456 1794 +1338
+ Partials 199 162 -37
Flags with carried forward coverage won't be shown. Click here to find out more. Continue to review full report in Codecov by Harness.
🚀 New features to boost your workflow:
|
Signed-off-by: red-hat-konflux <126015336+red-hat-konflux[bot]@users.noreply.github.com>
0f8ecda to
aaa7f32
Compare
There was a problem hiding this comment.
Risk Level: HIGH
Summary of Dependency Changes
The dependency golangci-lint is updated from v2.8.0 to v2.13.2. This minor update introduces support for Go 1.26 and Go 1.27, adds new linters (such as clickhouselint), updates several underlying linters with new options and rules, and introduces a breaking configuration change in the revive linter where package-related checks moved to a new rule package-naming.
Affected Code
As a linting tool, golangci-lint is used for static analysis during builds or CI/CD pipelines and is not imported directly into the application's Go source code. The update impacts the configuration files (such as .golangci.yml) and build scripts (such as Makefile) that manage linting execution and rule enforcement.
Breaking Change Assessment
Although this is a minor bump, golangci-lint updates often cause CI failures due to new rules or stricter analysis. Specific changes of note include the deprecation of exhaustruct in favor of exhaustruct_v5 and a breaking change in the revive linter where package-related checks migrated from var-naming to package-naming.
Security Assessment
No security advisories or govulncheck data were provided. However, updating tools like gosec within golangci-lint introduces new security rules (e.g., G113, G118-G123, G408, G701-G710) which can help identify previously undetected vulnerabilities in the codebase.
Supply-Chain Assessment
This PR has failed supply-chain validation.
- SUPPLY_CHAIN_UNEXPECTED_SCOPE: The PR modifies files outside the expected scope for a dependency update. Specifically, it modifies
Makefile. Dependency updates should typically only change manifests, lock files, and vendored code. This unexpected modification poses a high risk of tampering or injecting unauthorized commands into the build process.
Recommended Action
Needs careful review: This PR should not be merged automatically. A reviewer must manually inspect the changes to the Makefile to verify that they are legitimate and do not introduce untrusted actions or security risks.
|
🤖 Finished Review · ✅ Success · Started 1:54 AM UTC · Completed 1:59 AM UTC Commit: Runtime: claude · Model: opus → claude-opus-4-6 · Effort: high · Cost: $1.57 |
This PR contains the following updates:
v2.8.0→v2.13.2Warning
Some dependencies could not be looked up. Check the warning logs for more information.
Release Notes
golangci/golangci-lint (golangci-lint)
v2.13.2Compare Source
Released on 2026-08-28
iface: from 1.5.0 to 1.5.1staticcheck: from 0.8.0 to 0.8.1unparam: from3f964bcto2fa3d84canonicalheader: from v1.1.2 to a temporary forkv2.13.1Compare Source
Released on 2026-08-20
ginkgolinter: from 0.23.1 to 0.24.0gofmt: fromd62b90etoe84e050staticcheck: from 0.8.0-rc.1 to 0.8.0wsl_v5: from 5.8.0 to 5.9.0v2.13.0Compare Source
Released on 2026-08-19
dupword: from 0.1.7 to 0.1.8 (new optionskip-raw-strings)errcheck: from 1.10.0 to 1.20.0exhaustruct_v5: from 4.0.0 to 5.0.2 (new configuration)exhaustruct: deprecated and replaced byexhaustruct_v5fatcontext: from 0.9.0 to 0.10.0 (new options:check-loops,check-function-literals)goconst: from 1.10.0 to 1.11.0 (new options:ignore-map-keys,exclude-types)gofumpt: from 0.9.2 to 0.11.0 (new options:extra.group-params,extra.clothe-returns,extra.balance-calls)gomoddirectives: from 0.8.0 to 0.9.0 (new option:replace-allow-all)gosec: from 2.26.1 to 2.27.1govet-modernize: from 0.44.0 to 0.49.0 (fmtappendfis removed. New analyzersatomictypes,embedlit,errorsastype,importcomment,reflecttypeassert,slicesclip, andslicesbackward.waitgroupis renamedwaitgroupgo)iface: from 1.4.3 to 1.5.0 (new analyzer:unusedmethod)noinlineerr: from 1.0.5 to 1.0.6nonamedreturns: from 1.0.6 to 1.0.8 (new option:allow-unused-named-returns)recvcheck: from 0.2.0 to 0.3.0 (new default exclusions)unparam: from5beb8c8to3f964bcclickhouse-go-linter: from 1.2.0 to 1.2.1errname: from 1.1.1 to 1.1.2exhaustruct: from 5.0.2 to 5.0.3funcorder: add missingFunctionfieldginkgolinter: from 0.23.0 to 0.23.1gocheckcompilerdirectives: from 1.3.0 to 1.4.0gocritic: from 0.14.3 to 0.14.4gomoddirectives: add missingIgnoreForbiddenfieldiface: from 1.4.2 to 1.4.3mirror: from 1.3.0 to 1.3.3nilnil: from 1.1.1 to 1.1.2protogetter: from 0.3.20 to 0.3.21v2.12.2Compare Source
Released on 2026-05-06
gomodguard_v2: fix blocked configurationgomodguard_v2: from 2.1.0 to 2.1.3iface: from 1.4.1 to 1.4.2v2.12.1Compare Source
Released on 2026-05-01
gomodguard_v2: fix panic with migration suggestioninstall.shscript (if you are still using an URL based on the branchmaster, please update to usehttps://golangci-lint.run/install.sh)v2.12.0Compare Source
Released on 2026-05-01
clickhouselintlinter https://github.com/ClickHouse/clickhouse-go-linterdupl: fromf665c8dtoc99c5cf(extended detection)funcorder: from 0.5.0 to 0.6.0 (new option:function)goconst: add an option to ignore strings from testsgoconst: from 1.8.2 to 1.10.0 (extended detection)gomodguard_v2: from 1.4.1 to 2.1.0 (major version with new configuration)gosec: from619ce21to 2.28.0 (new checks:G124,G708,G709,G710)govet: addinlineanalyzermakezero: from 2.1.0 to 2.2.1 (support slice type aliases)paralleltest: exposecheckcleanupoptionsloglint: from 0.11.1 to 0.12.0 (new options:allowed-keys,custom-funcs)wsl_v5: from 5.6.0 to 5.8.0 (new option:cuddle-max-statements; new checks:after-decl,after-defer,after-expr,after-go,cuddle-group)forbidigo: from 2.3.0 to 2.3.1godot: from 1.5.4 to 1.5.6govet-modernize: from 0.43.0 to 0.44.0ireturn: from 0.4.0 to 0.4.1rowserrcheck: from 1.1.1 toc5f79b8customcommandv2.11.4Compare Source
Released on 2026-03-22
govet-modernize: from 0.42.0 to 0.43.0noctx: from 0.5.0 to 0.5.1sqlclosecheck: from 0.5.1 to 0.6.0v2.11.3Compare Source
Released on 2026-03-10
gosec: from v2.24.7 to619ce21v2.11.2Compare Source
Released on 2026-03-07
fmt: fix error when using thefmtcommand with explicit paths.v2.11.1Compare Source
Released on 2026-03-06
Due to an error related to AUR, some artifacts of the v2.11.0 release have not been published.
This release contains the same things as v2.11.0.
v2.11.0Compare Source
Released on 2026-03-06
errcheck: from 1.9.0 to 1.10.0 (excludecrypto/rand.Readby default)gosec: from 2.23.0 to 2.24.6 (new rules:G113,G118,G119,G120,G121,G122,G123,G408,G707)noctx: from 0.4.0 to 0.5.0 (new detection:httptest.NewRequestWithContext)prealloc: from 1.0.2 to 1.1.0revive: from 1.14.0 to 1.15.0 (var-namingto a new rulepackage-naming)gocognit: from 1.2.0 to 1.2.1gosec: from 2.24.6 to 2.24.7unqueryvet: from 1.5.3 to 1.5.4v2.10.1Compare Source
Released on 2026-02-17
v2.10.0Compare Source
Released on 2026-02-17
ginkgolinter: from 0.22.0 to 0.23.0gosec: from 2.22.11 to 2.23.0 (new rules:G117,G602,G701,G702,G703,G704,G705,G706)staticcheck: from 0.6.1 to 0.7.0godoclint: from 0.11.1 to 0.11.2v2.9.0Compare Source
Released on 2026-02-10
arangolint: from 0.3.1 to 0.4.0 (new rule: detect potential query injections)ginkgolinter: from 0.21.2 to 0.22.0 (support for wrappers)golines: from 0.14.0 to 0.15.0misspell: from 0.7.0 to 0.8.0revive: from v1.13.0 to v1.14.0 (new rules:epoch-naming,use-slices-sort)unqueryvet: from 1.4.0 to 1.5.3 (new options:check-n1,check-sql-injection,check-tx-leaks,allow,custom-rules)wsl_v5: from 5.3.0 to 5.6.0 (new rule:after-block)modernize: from 0.41.0 to 0.42.0prealloc: from 1.0.1 to 1.0.2protogetter: from 0.3.18 to 0.3.20Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
To execute skipped test pipelines write comment
/ok-to-test.Documentation
Find out how to configure dependency updates in MintMaker documentation or see all available configuration options in Renovate documentation.