From 80bc93a002ae3755f1f8eeee6672c95edf57b800 Mon Sep 17 00:00:00 2001 From: Kevin Tang <73975146+vt128@users.noreply.github.com> Date: Sun, 20 Sep 2026 02:54:43 +0800 Subject: [PATCH] [ci] resolve current Go patches before using runner caches --- .github/workflows/go-ci.yml | 2 ++ CLAUDE.md | 4 +++- 2 files changed, 5 insertions(+), 1 deletion(-) diff --git a/.github/workflows/go-ci.yml b/.github/workflows/go-ci.yml index b4b3052..6339bc9 100644 --- a/.github/workflows/go-ci.yml +++ b/.github/workflows/go-ci.yml @@ -108,6 +108,8 @@ jobs: uses: actions/setup-go@v6 with: go-version: ${{ matrix.go-version }} + # Runner caches may lag behind a newly required security patch. + check-latest: true cache: true cache-dependency-path: ${{ inputs.working-directory }}/go.sum - name: Build diff --git a/CLAUDE.md b/CLAUDE.md index c5c1313..8042e28 100644 --- a/CLAUDE.md +++ b/CLAUDE.md @@ -63,7 +63,9 @@ surface, revive = GoDoc. ## go-ci.yml design (the part that matters when editing) -- Matrix: `[.x, 1.25.x] × {ubuntu-22.04, macos-14, windows-2022}`. +- Matrix: `[.x, 1.27.x] × {ubuntu-22.04, macos-14, windows-2022}`. + Resolve the latest patch with `check-latest: true`; a runner's cached patch + can be older than the consumer's minimum secure Go version. - Two env-flag legs: **`IS_CHECKS`** (latest Go + Linux) runs the once-only static checks (vet/gofmt/tidy/govulncheck/doccov); **`IS_REPORT`** (floor + Linux) runs `make ci` coverage upload + the covcheck/footprint gates (floor for comparable