diff --git a/.github/scripts/generate-versions b/.github/scripts/generate-versions index 5d75911..5a45b49 100755 --- a/.github/scripts/generate-versions +++ b/.github/scripts/generate-versions @@ -27,7 +27,9 @@ # # 3. Versions are considered once they've been out for at least COOLDOWN_DAYS, # so a release that turns out to be broken has some time to be pulled or -# fixed. +# fixed. Go is the exception: it moves as soon as it clears the checks in 2, +# since its releases often carry security fixes, and CI, which follows the +# stable release, takes them in that early anyway. # # With --no-refresh nothing upstream is consulted and .versions is rebuilt from # the .versions.json already on disk, which is how CI checks the two agree @@ -77,20 +79,6 @@ settled() { '(now - ($when | fromdateiso8601)) >= ($days * 86400)' >/dev/null } -# tagged reports when a git tag was laid down, ISO 8601. Go -# publishes no GitHub releases, so its dates come from the tags themselves. -tagged() { - tagged_ref="$(gh api "repos/$1/git/refs/tags/$2")" - tagged_type="$(printf '%s' "${tagged_ref}" | jq -r '.object.type')" - tagged_sha="$(printf '%s' "${tagged_ref}" | jq -r '.object.sha')" - - if [ "${tagged_type}" = tag ]; then - gh api "repos/$1/git/tags/${tagged_sha}" --jq '.tagger.date' - else - gh api "repos/$1/git/commits/${tagged_sha}" --jq '.committer.date' - fi -} - # at_most reports whether Go version a sits at or below b. Only the # major and the minor are compared: golangci-lint weighs language versions, so # a 1.27.0 build happily lints a module that asks for 1.27.9, and comparing @@ -280,12 +268,6 @@ update_releases() { continue fi - cut="$(tagged golang/go "go${candidate}")" - if ! settled "${cut}"; then - echo "go ${candidate} came out on ${cut%%T*}, inside the ${COOLDOWN_DAYS} day cooldown" >&2 - continue - fi - selected="${candidate}" break done <"${work}/go-candidates" diff --git a/AGENTS.md b/AGENTS.md index a209b1e..aba08be 100644 --- a/AGENTS.md +++ b/AGENTS.md @@ -91,7 +91,7 @@ jobs: - Shell steps use `set -euo pipefail` and pass inputs through `env:` rather than interpolating `${{ }}` into `run:` (zizmor's template-injection check). - Caller-supplied command strings (`build-command`, `test-command`, `codeql-build-cmd`) are `eval`ed on purpose. - Formatting: `.editorconfig` says tabs for Go, two-space indents for YAML and JSON, four spaces for `.github/scripts/*`, LF endings everywhere. -- Go toolchain moves are gated: `go` in `.versions` only advances when golangci-lint can lint it, `actions/setup-go` can install it, and Docker Hub has the image, and only after a 7-day cooldown. Do not bump `go` by hand. +- Go toolchain moves are gated: `go` in `.versions` only advances when golangci-lint can lint it, `actions/setup-go` can install it, and Docker Hub has the image. Unlike every other entry, it skips the 7-day cooldown. Do not bump `go` by hand. ## The shared `.golangci.yml`