Fixes two CI gates that broke on 2026-10-09, when Go 1.27.2 was released (CI tracks go-version: stable).
vulnerabilities:golang.org/x/net v0.58.0 has five new advisories, all fixed in v0.60.0: GO-2026-6603, GO-2026-6610, GO-2026-6611, GO-2026-6612 and GO-2026-6617. x/net is an indirect dependency, so Renovate never opened a PR for it.
check (codegen gate): with golang.org/x/tools v0.49.0 under Go 1.27.2, gqlgen no longer sees methods on bound model types. go generate replaces them with panic("not implemented") resolver stubs. The same commit was green on 10-08 and red on 10-09, and generating with GOTOOLCHAIN=go1.27.1 gives no diff. x/tools v0.51.0 generates the committed code again.
Verified locally under Go 1.27.2: go generate ./... gives no diff, govulncheck ./... finds no vulnerabilities, go test -race ./... passes, and prek run --all-files passes. This is a dependency-only change, so there was no expert review.
Fixes two CI gates that broke on 2026-10-09, when Go 1.27.2 was released (CI tracks `go-version: stable`).
- **vulnerabilities:** `golang.org/x/net` v0.58.0 has five new advisories, all fixed in v0.60.0: GO-2026-6603, GO-2026-6610, GO-2026-6611, GO-2026-6612 and GO-2026-6617. x/net is an indirect dependency, so Renovate never opened a PR for it.
- **check (codegen gate):** with `golang.org/x/tools` v0.49.0 under Go 1.27.2, gqlgen no longer sees methods on bound model types. `go generate` replaces them with `panic("not implemented")` resolver stubs. The same commit was green on 10-08 and red on 10-09, and generating with `GOTOOLCHAIN=go1.27.1` gives no diff. x/tools v0.51.0 generates the committed code again.
Verified locally under Go 1.27.2: `go generate ./...` gives no diff, `govulncheck ./...` finds no vulnerabilities, `go test -race ./...` passes, and `prek run --all-files` passes. This is a dependency-only change, so there was no expert review.
🤖 Generated with [Claude Code](https://claude.com/claude-code)
https://claude.ai/code/session_012GZcP1B9UALgvE785GL8Jb
golang.org/x/net v0.58.0 has five advisories fixed in v0.60.0 (GO-2026-6603, GO-2026-6610, GO-2026-6611, GO-2026-6612, GO-2026-6617), so the vulnerabilities job fails on every PR. x/net is indirect, so Renovate never proposed it.
golang.org/x/tools v0.49.0 under Go 1.27.2 makes gqlgen miss methods on bound model types: go generate replaces them with panicking resolver stubs, which fails the check job's codegen gate. x/tools v0.51.0 generates the committed code again.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012GZcP1B9UALgvE785GL8Jb
argoyle
scheduled this pull request to auto merge when all checks succeed 2026-10-10 15:20:41 +00:00
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Fixes two CI gates that broke on 2026-10-09, when Go 1.27.2 was released (CI tracks
go-version: stable).golang.org/x/netv0.58.0 has five new advisories, all fixed in v0.60.0: GO-2026-6603, GO-2026-6610, GO-2026-6611, GO-2026-6612 and GO-2026-6617. x/net is an indirect dependency, so Renovate never opened a PR for it.golang.org/x/toolsv0.49.0 under Go 1.27.2, gqlgen no longer sees methods on bound model types.go generatereplaces them withpanic("not implemented")resolver stubs. The same commit was green on 10-08 and red on 10-09, and generating withGOTOOLCHAIN=go1.27.1gives no diff. x/tools v0.51.0 generates the committed code again.Verified locally under Go 1.27.2:
go generate ./...gives no diff,govulncheck ./...finds no vulnerabilities,go test -race ./...passes, andprek run --all-filespasses. This is a dependency-only change, so there was no expert review.🤖 Generated with Claude Code
https://claude.ai/code/session_012GZcP1B9UALgvE785GL8Jb
Coverage Report
Total coverage: 30%
Coverage Report
Total coverage: 30%