Skip to content

Update dependency golangci-lint to v2.13.2 - #1018

Open
red-hat-konflux[bot] wants to merge 1 commit into
mainfrom
konflux/mintmaker/main/golangci-lint-2.x
Open

Update dependency golangci-lint to v2.13.2#1018
red-hat-konflux[bot] wants to merge 1 commit into
mainfrom
konflux/mintmaker/main/golangci-lint-2.x

Conversation

@red-hat-konflux

@red-hat-konflux red-hat-konflux Bot commented Aug 25, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Update Change
golangci-lint minor v2.8.0v2.13.2

Warning

Some dependencies could not be looked up. Check the warning logs for more information.


Release Notes

golangci/golangci-lint (golangci-lint)

v2.13.2

Compare Source

Released on 2026-08-28

  1. Bug fixes
    • Decrease cache entropy
  2. Linters bug fixes
    • iface: from 1.5.0 to 1.5.1
    • staticcheck: from 0.8.0 to 0.8.1
    • unparam: from 3f964bc to 2fa3d84
    • canonicalheader: from v1.1.2 to a temporary fork

v2.13.1

Compare Source

Released on 2026-08-20

  1. Linters bug fixes
    • ginkgolinter: from 0.23.1 to 0.24.0
    • gofmt: from d62b90e to e84e050
    • staticcheck: from 0.8.0-rc.1 to 0.8.0
    • wsl_v5: from 5.8.0 to 5.9.0

v2.13.0

Compare Source

Released on 2026-08-19

  1. Enhancements
    • 🎉 go1.27 support
  2. Bug fixes
    • fix: cache package facts
  3. Linters new features or changes
    • dupword: from 0.1.7 to 0.1.8 (new option skip-raw-strings)
    • errcheck: from 1.10.0 to 1.20.0
    • exhaustruct_v5: from 4.0.0 to 5.0.2 (new configuration)
    • exhaustruct: deprecated and replaced by exhaustruct_v5
    • fatcontext: from 0.9.0 to 0.10.0 (new options: check-loops, check-function-literals)
    • goconst: from 1.10.0 to 1.11.0 (new options: ignore-map-keys, exclude-types)
    • gofumpt: from 0.9.2 to 0.11.0 (new options: extra.group-params, extra.clothe-returns, extra.balance-calls)
    • gomoddirectives: from 0.8.0 to 0.9.0 (new option: replace-allow-all)
    • gosec: from 2.26.1 to 2.27.1
    • govet-modernize: from 0.44.0 to 0.49.0 (fmtappendf is removed. New analyzers atomictypes, embedlit, errorsastype, importcomment, reflecttypeassert, slicesclip, and slicesbackward. waitgroup is renamed waitgroupgo)
    • iface: from 1.4.3 to 1.5.0 (new analyzer: unusedmethod)
    • noinlineerr: from 1.0.5 to 1.0.6
    • nonamedreturns: from 1.0.6 to 1.0.8 (new option: allow-unused-named-returns)
    • recvcheck: from 0.2.0 to 0.3.0 (new default exclusions)
    • unparam: from 5beb8c8 to 3f964bc
  4. Linters bug fixes
    • clickhouse-go-linter: from 1.2.0 to 1.2.1
    • errname: from 1.1.1 to 1.1.2
    • exhaustruct: from 5.0.2 to 5.0.3
    • funcorder: add missing Function field
    • ginkgolinter: from 0.23.0 to 0.23.1
    • gocheckcompilerdirectives: from 1.3.0 to 1.4.0
    • gocritic: from 0.14.3 to 0.14.4
    • gomoddirectives: add missing IgnoreForbidden field
    • iface: from 1.4.2 to 1.4.3
    • mirror: from 1.3.0 to 1.3.3
    • nilnil: from 1.1.1 to 1.1.2
    • protogetter: from 0.3.20 to 0.3.21

v2.12.2

Compare Source

Released on 2026-05-06

  1. Linters bug fixes
    • gomodguard_v2: fix blocked configuration
    • gomodguard_v2: from 2.1.0 to 2.1.3
    • iface: from 1.4.1 to 1.4.2

v2.12.1

Compare Source

Released on 2026-05-01

  1. Linters bug fixes
    • gomodguard_v2: fix panic with migration suggestion
  2. Misc.
    • fix install.sh script (if you are still using an URL based on the branch master, please update to use https://golangci-lint.run/install.sh)

v2.12.0

Compare Source

Released on 2026-05-01

  1. New linters
  2. Linters new features or changes
    • dupl: from f665c8d to c99c5cf (extended detection)
    • funcorder: from 0.5.0 to 0.6.0 (new option: function)
    • goconst: add an option to ignore strings from tests
    • goconst: from 1.8.2 to 1.10.0 (extended detection)
    • gomodguard_v2: from 1.4.1 to 2.1.0 (major version with new configuration)
    • gosec: from 619ce21 to 2.28.0 (new checks: G124, G708, G709, G710)
    • govet: add inline analyzer
    • makezero: from 2.1.0 to 2.2.1 (support slice type aliases)
    • paralleltest: expose checkcleanup option
    • sloglint: from 0.11.1 to 0.12.0 (new options: allowed-keys, custom-funcs)
    • wsl_v5: from 5.6.0 to 5.8.0 (new option: cuddle-max-statements; new checks: after-decl, after-defer, after-expr, after-go, cuddle-group)
  3. Linters bug fixes
    • forbidigo: from 2.3.0 to 2.3.1
    • godot: from 1.5.4 to 1.5.6
    • govet-modernize: from 0.43.0 to 0.44.0
    • ireturn: from 0.4.0 to 0.4.1
    • rowserrcheck: from 1.1.1 to c5f79b8
  4. Misc.
    • Decrease cache entropy
    • Embed the JSON schema in the binary
    • Filter env vars when cloning the repository with the custom command

v2.11.4

Compare Source

Released on 2026-03-22

  1. Linters bug fixes
    • govet-modernize: from 0.42.0 to 0.43.0
    • noctx: from 0.5.0 to 0.5.1
    • sqlclosecheck: from 0.5.1 to 0.6.0

v2.11.3

Compare Source

Released on 2026-03-10

  1. Linters bug fixes

v2.11.2

Compare Source

Released on 2026-03-07

  1. Fixes
    • fmt: fix error when using the fmt command with explicit paths.

v2.11.1

Compare Source

Released on 2026-03-06

Due to an error related to AUR, some artifacts of the v2.11.0 release have not been published.

This release contains the same things as v2.11.0.

v2.11.0

Compare Source

Released on 2026-03-06

  1. Linters new features or changes
    • errcheck: from 1.9.0 to 1.10.0 (exclude crypto/rand.Read by default)
    • gosec: from 2.23.0 to 2.24.6 (new rules: G113, G118, G119, G120, G121, G122, G123, G408, G707)
    • noctx: from 0.4.0 to 0.5.0 (new detection: httptest.NewRequestWithContext)
    • prealloc: from 1.0.2 to 1.1.0
    • revive: from 1.14.0 to 1.15.0 (⚠️ Breaking change: package-related checks moved from var-naming to a new rule package-naming)
  2. Linters bug fixes
    • gocognit: from 1.2.0 to 1.2.1
    • gosec: from 2.24.6 to 2.24.7
    • unqueryvet: from 1.5.3 to 1.5.4

v2.10.1

Compare Source

Released on 2026-02-17

  1. Fixes
    • buildssa panic

v2.10.0

Compare Source

Released on 2026-02-17

  1. Linters new features or changes
    • ginkgolinter: from 0.22.0 to 0.23.0
    • gosec: from 2.22.11 to 2.23.0 (new rules: G117, G602, G701, G702, G703, G704, G705, G706)
    • staticcheck: from 0.6.1 to 0.7.0
  2. Linters bug fixes
    • godoclint: from 0.11.1 to 0.11.2

v2.9.0

Compare Source

Released on 2026-02-10

  1. Enhancements
    • 🎉 go1.26 support
  2. Linters new features or changes
    • arangolint: from 0.3.1 to 0.4.0 (new rule: detect potential query injections)
    • ginkgolinter: from 0.21.2 to 0.22.0 (support for wrappers)
    • golines: from 0.14.0 to 0.15.0
    • misspell: from 0.7.0 to 0.8.0
    • revive: from v1.13.0 to v1.14.0 (new rules: epoch-naming, use-slices-sort)
    • unqueryvet: from 1.4.0 to 1.5.3 (new options: check-n1, check-sql-injection, check-tx-leaks, allow, custom-rules)
    • wsl_v5: from 5.3.0 to 5.6.0 (new rule: after-block)
  3. Linters bug fixes
    • modernize: from 0.41.0 to 0.42.0
    • prealloc: from 1.0.1 to 1.0.2
    • protogetter: from 0.3.18 to 0.3.20
  4. Misc.
    • Log information about files when configuration verification
    • Emit an error when no linters enabled
    • Do not collect VCS information when loading code

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

To execute skipped test pipelines write comment /ok-to-test.


Documentation

Find out how to configure dependency updates in MintMaker documentation or see all available configuration options in Renovate documentation.

@github-actions github-actions Bot added supply-chain/unexpected-scope PR changes files outside expected dependency update scope semver/minor Semver minor version bump labels Aug 25, 2026
@github-actions

github-actions Bot commented Aug 25, 2026

Copy link
Copy Markdown

AI Dependency Impact Analysis

Previous analysis

Risk Level: HIGH

Summary of Dependency Changes

This dependency update bumps golangci-lint from v2.8.0 to v2.13.1. Key changes include Go 1.26 and Go 1.27 support, the addition of the new clickhouselint linter, numerous updates and new rules for existing linters (such as gosec, govet, revive, and wsl), and multiple bug fixes across various linters.

Affected Code

As golangci-lint is a development tool, there are typically no direct Go code imports of this package in the codebase. However, this PR modifies the Makefile, which is used to orchestrate build, test, and linting pipelines.

Breaking Change Assessment

While minor version bumps in Go generally adhere to semver, golangci-lint updates frequently introduce new linter rules or modify existing ones (such as revive breaking changes moving package-related checks to package-naming), which can break CI pipelines due to new lint failures. However, the primary concern for this PR is the supply-chain validation failure rather than linter behavior.

Security Assessment

No specific security advisories or govulncheck vulnerabilities were reported. However, unauthorized modifications to build infrastructure files (like Makefile) pose a critical security risk.

Supply-Chain Assessment

This PR has failed supply-chain validation with the following finding:

  • SUPPLY_CHAIN_UNEXPECTED_SCOPE: This dependency PR modifies files outside the expected scope for a dependency update. Specifically, it modifies the Makefile. Dependency updates should only modify package manifests (e.g., go.mod, go.sum) or lockfiles. Modifying build scripts is a known attack vector for injecting malicious behavior into CI/CD pipelines or local development environments.

Recommended Action

Needs careful review

Do NOT merge this PR automatically. A maintainer must manually inspect the changes made to the Makefile to ensure they are legitimate and do not introduce malicious commands or unexpected build behaviors.

Risk Level: HIGH

Summary of Dependency Changes

The dependency golangci-lint is updated from v2.8.0 to v2.13.2. This minor update introduces support for Go 1.26 and Go 1.27, adds new linters (such as clickhouselint), updates several underlying linters with new options and rules, and introduces a breaking configuration change in the revive linter where package-related checks moved to a new rule package-naming.

Affected Code

As a linting tool, golangci-lint is used for static analysis during builds or CI/CD pipelines and is not imported directly into the application's Go source code. The update impacts the configuration files (such as .golangci.yml) and build scripts (such as Makefile) that manage linting execution and rule enforcement.

Breaking Change Assessment

Although this is a minor bump, golangci-lint updates often cause CI failures due to new rules or stricter analysis. Specific changes of note include the deprecation of exhaustruct in favor of exhaustruct_v5 and a breaking change in the revive linter where package-related checks migrated from var-naming to package-naming.

Security Assessment

No security advisories or govulncheck data were provided. However, updating tools like gosec within golangci-lint introduces new security rules (e.g., G113, G118-G123, G408, G701-G710) which can help identify previously undetected vulnerabilities in the codebase.

Supply-Chain Assessment

This PR has failed supply-chain validation.

  • SUPPLY_CHAIN_UNEXPECTED_SCOPE: The PR modifies files outside the expected scope for a dependency update. Specifically, it modifies Makefile. Dependency updates should typically only change manifests, lock files, and vendored code. This unexpected modification poses a high risk of tampering or injecting unauthorized commands into the build process.

Recommended Action

Needs careful review: This PR should not be merged automatically. A reviewer must manually inspect the changes to the Makefile to verify that they are legitimate and do not introduce untrusted actions or security risks.

@github-actions github-actions Bot added the risk/high AI-assessed high risk dependency update label Aug 25, 2026

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Risk Level: HIGH

Summary of Dependency Changes

This dependency update bumps golangci-lint from v2.8.0 to v2.13.1. Key changes include Go 1.26 and Go 1.27 support, the addition of the new clickhouselint linter, numerous updates and new rules for existing linters (such as gosec, govet, revive, and wsl), and multiple bug fixes across various linters.

Affected Code

As golangci-lint is a development tool, there are typically no direct Go code imports of this package in the codebase. However, this PR modifies the Makefile, which is used to orchestrate build, test, and linting pipelines.

Breaking Change Assessment

While minor version bumps in Go generally adhere to semver, golangci-lint updates frequently introduce new linter rules or modify existing ones (such as revive breaking changes moving package-related checks to package-naming), which can break CI pipelines due to new lint failures. However, the primary concern for this PR is the supply-chain validation failure rather than linter behavior.

Security Assessment

No specific security advisories or govulncheck vulnerabilities were reported. However, unauthorized modifications to build infrastructure files (like Makefile) pose a critical security risk.

Supply-Chain Assessment

This PR has failed supply-chain validation with the following finding:

  • SUPPLY_CHAIN_UNEXPECTED_SCOPE: This dependency PR modifies files outside the expected scope for a dependency update. Specifically, it modifies the Makefile. Dependency updates should only modify package manifests (e.g., go.mod, go.sum) or lockfiles. Modifying build scripts is a known attack vector for injecting malicious behavior into CI/CD pipelines or local development environments.

Recommended Action

Needs careful review

Do NOT merge this PR automatically. A maintainer must manually inspect the changes made to the Makefile to ensure they are legitimate and do not introduce malicious commands or unexpected build behaviors.

@fullsend-ai-review

fullsend-ai-review Bot commented Aug 25, 2026

Copy link
Copy Markdown

🤖 Finished Review · ✅ Success · Started 1:57 AM UTC · Completed 2:05 AM UTC

Commit: 9ee3c25 · View workflow run →

Runtime: claude · Model: opus → claude-opus-4-6 · Effort: high · Cost: $2.11

@fullsend-ai-review

fullsend-ai-review Bot commented Aug 25, 2026

Copy link
Copy Markdown

Looks good to me

Previous run

Looks good to me

fullsend-ai-review[bot]

This comment was marked as outdated.

@fullsend-ai-review fullsend-ai-review Bot added the ready-for-merge All reviewers approved — ready to merge label Aug 25, 2026
@codecov-commenter

codecov-commenter commented Aug 25, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 30.56%. Comparing base (7e565ab) to head (aaa7f32).

❗ There is a different number of reports uploaded between BASE (7e565ab) and HEAD (aaa7f32). Click for more details.

HEAD has 3 uploads less than BASE
Flag BASE (7e565ab) HEAD (aaa7f32)
e2e-tests 2 1
unit-tests 2 0
Additional details and impacted files

Impacted file tree graph

@@             Coverage Diff             @@
##             main    #1018       +/-   ##
===========================================
- Coverage   76.74%   30.56%   -46.19%     
===========================================
  Files          26       26               
  Lines        2817     2817               
===========================================
- Hits         2162      861     -1301     
- Misses        456     1794     +1338     
+ Partials      199      162       -37     
Flag Coverage Δ
e2e-tests 30.56% <ø> (+0.53%) ⬆️
unit-tests ?

Flags with carried forward coverage won't be shown. Click here to find out more.
see 22 files with indirect coverage changes


Continue to review full report in Codecov by Harness.

Legend - Click here to learn more
Δ = absolute <relative> (impact), ø = not affected, ? = missing data
Powered by Codecov. Last update 7e565ab...aaa7f32. Read the comment docs.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

Signed-off-by: red-hat-konflux <126015336+red-hat-konflux[bot]@users.noreply.github.com>
@red-hat-konflux
red-hat-konflux Bot force-pushed the konflux/mintmaker/main/golangci-lint-2.x branch from 0f8ecda to aaa7f32 Compare August 31, 2026 01:53
@red-hat-konflux red-hat-konflux Bot changed the title Update dependency golangci-lint to v2.13.1 Update dependency golangci-lint to v2.13.2 Aug 31, 2026
@github-actions github-actions Bot added risk/high AI-assessed high risk dependency update and removed risk/high AI-assessed high risk dependency update labels Aug 31, 2026

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Risk Level: HIGH

Summary of Dependency Changes

The dependency golangci-lint is updated from v2.8.0 to v2.13.2. This minor update introduces support for Go 1.26 and Go 1.27, adds new linters (such as clickhouselint), updates several underlying linters with new options and rules, and introduces a breaking configuration change in the revive linter where package-related checks moved to a new rule package-naming.

Affected Code

As a linting tool, golangci-lint is used for static analysis during builds or CI/CD pipelines and is not imported directly into the application's Go source code. The update impacts the configuration files (such as .golangci.yml) and build scripts (such as Makefile) that manage linting execution and rule enforcement.

Breaking Change Assessment

Although this is a minor bump, golangci-lint updates often cause CI failures due to new rules or stricter analysis. Specific changes of note include the deprecation of exhaustruct in favor of exhaustruct_v5 and a breaking change in the revive linter where package-related checks migrated from var-naming to package-naming.

Security Assessment

No security advisories or govulncheck data were provided. However, updating tools like gosec within golangci-lint introduces new security rules (e.g., G113, G118-G123, G408, G701-G710) which can help identify previously undetected vulnerabilities in the codebase.

Supply-Chain Assessment

This PR has failed supply-chain validation.

  • SUPPLY_CHAIN_UNEXPECTED_SCOPE: The PR modifies files outside the expected scope for a dependency update. Specifically, it modifies Makefile. Dependency updates should typically only change manifests, lock files, and vendored code. This unexpected modification poses a high risk of tampering or injecting unauthorized commands into the build process.

Recommended Action

Needs careful review: This PR should not be merged automatically. A reviewer must manually inspect the changes to the Makefile to verify that they are legitimate and do not introduce untrusted actions or security risks.

@fullsend-ai-review

fullsend-ai-review Bot commented Aug 31, 2026

Copy link
Copy Markdown

🤖 Finished Review · ✅ Success · Started 1:54 AM UTC · Completed 1:59 AM UTC

Commit: 9ee3c25 · View workflow run →

Runtime: claude · Model: opus → claude-opus-4-6 · Effort: high · Cost: $1.57

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

ready-for-merge All reviewers approved — ready to merge risk/high AI-assessed high risk dependency update semver/minor Semver minor version bump supply-chain/unexpected-scope PR changes files outside expected dependency update scope

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant