fix(deps): update golang.org/x/net to v0.60.0 and golang.org/x/tools to v0.51.0 #203

Merged
argoyle merged 2 commits from fix/x-net-x-tools into main 2026-10-11 06:56:55 +00:00
2 Commits
Author SHA1 Message Date
argoyleandClaude Opus 5.5 9b7fe11d3b fix(otel): use otel.SetLoggerProvider instead of deprecated log/global
otelsetup / test (pull_request) Successful in 9m13s
otelsetup / vulnerabilities (pull_request) Successful in 9m58s
pre-commit / pre-commit (pull_request) Successful in 18m57s
OpenTelemetry v1.47 deprecates go.opentelemetry.io/otel/log/global, so
golangci-lint's staticcheck (SA1019) fails pre-commit on every PR.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012GZcP1B9UALgvE785GL8Jb
2026-10-10 23:29:28 +02:00
argoyleandClaude Opus 5.5 b606291e9f fix(deps): update golang.org/x/net to v0.60.0 and golang.org/x/tools to v0.51.0
otelsetup / vulnerabilities (pull_request) Successful in 14m50s
otelsetup / test (pull_request) Successful in 19m2s
pre-commit / pre-commit (pull_request) Failing after 20m43s
golang.org/x/net v0.58.0 has five advisories fixed in v0.60.0 (GO-2026-6603, GO-2026-6610, GO-2026-6611, GO-2026-6612, GO-2026-6617), so the vulnerabilities job fails on every PR. x/net is indirect, so Renovate never proposed it.

golang.org/x/tools v0.49.0 under Go 1.27.2 makes gqlgen miss methods on bound model types: go generate replaces them with panicking resolver stubs, which fails the check job's codegen gate. x/tools v0.51.0 generates the committed code again.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012GZcP1B9UALgvE785GL8Jb
2026-10-10 17:20:36 +02:00