diff --git a/.github/workflows/client.yml b/.github/workflows/client.yml index cf6f3f71fc..fdbc0dabbc 100644 --- a/.github/workflows/client.yml +++ b/.github/workflows/client.yml @@ -92,9 +92,9 @@ jobs: - uses: actions/checkout@v4 - name: Set up Go - uses: actions/setup-go@v5 + uses: actions/setup-go@v6 with: - go-version: '1.24.1' + go-version-file: "go.mod" - name: Verify vendored btcec byte identity vs upstream v0.22.3 run: | @@ -627,6 +627,17 @@ jobs: cache-from: type=local,src=/tmp/.buildx-cache context: . + - name: Verify Linux release compatibility + run: | + release_dir=$(mktemp -d) + trap 'rm -rf "$release_dir"' EXIT + tar -xzf out/bin/*-linux-amd64.tar.gz -C "$release_dir" + for image in debian:bullseye-slim ubuntu:20.04; do + docker run --rm --platform linux/amd64 \ + --mount "type=bind,src=$release_dir,dst=/release,readonly" \ + "$image" sh -ec 'getconf GNU_LIBC_VERSION; /release/keep-client --version' + done + - name: Archive Client Binaries uses: actions/upload-artifact@v4 with: @@ -688,7 +699,7 @@ jobs: runs-on: ubuntu-latest steps: - uses: actions/checkout@v4 - - uses: actions/setup-go@v5 + - uses: actions/setup-go@v6 with: go-version-file: "go.mod" - name: gofmt @@ -706,7 +717,7 @@ jobs: runs-on: ubuntu-latest steps: - uses: actions/checkout@v4 - - uses: actions/setup-go@v5 + - uses: actions/setup-go@v6 with: go-version-file: "go.mod" - run: go vet @@ -719,13 +730,13 @@ jobs: runs-on: ubuntu-latest steps: - uses: actions/checkout@v4 - - uses: actions/setup-go@v5 + - uses: actions/setup-go@v6 with: go-version-file: "go.mod" - name: Staticcheck uses: dominikh/staticcheck-action@v1.4.0 with: - version: "2025.1.1" + version: "2026.1" install-go: false checks: "-SA1019" @@ -739,6 +750,7 @@ jobs: runs-on: ubuntu-latest permissions: actions: read + contents: read pull-requests: write env: # PRs and the nightly schedule compare against the target/current @@ -747,13 +759,15 @@ jobs: BENCHMARK_BASELINE_BRANCH: ${{ github.event_name == 'pull_request' && github.base_ref || github.ref_name }} BENCHMARK_BASELINE_EVENT: ${{ github.event_name == 'workflow_dispatch' && 'workflow_dispatch' || 'push' }} steps: + - uses: actions/checkout@v4 + - name: Set up Docker Buildx uses: docker/setup-buildx-action@v3 - name: Set up Go - uses: actions/setup-go@v5 + uses: actions/setup-go@v6 with: - go-version: "1.24" + go-version-file: "go.mod" cache: false - name: Download Docker Build Image diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 7df458d649..43c26f7d62 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -67,6 +67,17 @@ jobs: push: false context: . + - name: Verify Linux release compatibility + run: | + release_dir=$(mktemp -d) + trap 'rm -rf "$release_dir"' EXIT + tar -xzf out/bin/*-linux-amd64.tar.gz -C "$release_dir" + for image in debian:bullseye-slim ubuntu:20.04; do + docker run --rm --platform linux/amd64 \ + --mount "type=bind,src=$release_dir,dst=/release,readonly" \ + "$image" sh -ec 'getconf GNU_LIBC_VERSION; /release/keep-client --version' + done + - name: Generate release notes id: release_notes run: | @@ -172,4 +183,4 @@ jobs: - name: Move Docker cache run: | rm -rf /tmp/.buildx-cache - mv /tmp/.buildx-cache-docker-new /tmp/.buildx-cache \ No newline at end of file + mv /tmp/.buildx-cache-docker-new /tmp/.buildx-cache diff --git a/Dockerfile b/Dockerfile index 75388c19f4..fc3de655aa 100644 --- a/Dockerfile +++ b/Dockerfile @@ -1,4 +1,5 @@ -FROM golang:1.24-alpine3.21 AS build-sources +# Keep both builders aligned with the toolchain directive in go.mod. +FROM golang:1.26.8-alpine3.23 AS build-sources ENV GOPATH=/go \ GOBIN=/go/bin \ @@ -96,7 +97,7 @@ RUN GOOS=linux make build \ version=$VERSION \ revision=$REVISION -FROM alpine:3.21 as runtime-docker +FROM alpine:3.23 as runtime-docker ENV APP_NAME=keep-client \ APP_DIR=/go/src/github.com/keep-network/keep-core \ @@ -116,9 +117,15 @@ CMD [] # # Build Binaries # -FROM golang:1.24-bullseye AS build-bins +# Keep cgo release binaries compatible with glibc 2.31 (Debian 11/Ubuntu 20.04). +# Copy only Go so the C compiler and libc still come from Bullseye. +FROM buildpack-deps:bullseye AS build-bins -ENV APP_DIR=/go/src/github.com/keep-network/keep-core +COPY --from=golang:1.26.8-bookworm /usr/local/go /usr/local/go + +ENV PATH=/usr/local/go/bin:$PATH \ + GOTOOLCHAIN=local \ + APP_DIR=/go/src/github.com/keep-network/keep-core WORKDIR $APP_DIR diff --git a/go.mod b/go.mod index e47cf6925e..c3efb0f839 100644 --- a/go.mod +++ b/go.mod @@ -1,8 +1,8 @@ module github.com/keep-network/keep-core -go 1.24.0 +go 1.25.7 -toolchain go1.24.1 +toolchain go1.26.8 replace ( github.com/bnb-chain/tss-lib => github.com/threshold-network/tss-lib v0.0.0-20230901144531-2e712689cfbe