Skip to content

fix(ci): make Dependabot gomod PRs tested and lint-clean - #9197

Open
DoDiODev wants to merge 2 commits into
apache:mainfrom
DoDiODev:ci/gomod-dependabot-testable
Open

DoDiODev wants to merge 2 commits into
apache:mainfrom
DoDiODev:ci/gomod-dependabot-testable

Conversation

@DoDiODev

@DoDiODev DoDiODev commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

Summary

Two small fixes so that Dependabot's gomod PRs (first one: #9192) are
actually tested and can turn green:

  1. fix(ci): run unit/e2e tests when backend/go.mod, go.sum or
    Makefile change.
    The pull_request.paths filters of test.yml and
    test-e2e.yml list go.mod, go.sum and Makefile without a directory
    prefix. GitHub matches those against the repository root only, so a diff
    that touches only backend/go.mod/backend/go.sum — i.e. every Dependabot
    gomod PR — never triggers unit-test, e2e-mysql or e2e-postgres. On
    build(deps): bump the go-minor-patch group in /backend with 26 updates #9192 only lint and a few metadata checks ran; the 26 updates were never
    compiled or tested, and the go mod tidy guard from fix(build): make go mod tidy work on a fresh clone #9179 was skipped.
    The patterns are now prefixed with **/ (which also matches the root).
  2. build(lint): tolerate the aws-sdk-go v1 deprecation in the kiro
    plugin.
    aws-sdk-go v1 is end-of-support since 2025-07-31; its last
    release v1.55.8 (pulled in by build(deps): bump the go-minor-patch group in /backend with 26 updates #9192) marks every package deprecated, so
    staticcheck reports 11× SA1019 in plugins/kiro. The exclusion is
    limited to that check, that import path and that plugin, and carries a
    comment to remove it after the migration to aws-sdk-go-v2, which is tracked
    in [Refactor][Kiro] Migrate the kiro plugin from aws-sdk-go v1 to aws-sdk-go-v2 #9195 and [Refactor][Build] Remove the end-of-support aws-sdk-go v1 from backend/go.mod #9196.

No production code changes.

Does this close any open issues?

No. Unblocks #9192. Related: #9195, #9196.

Verification

Other Information

I can't exercise the kiro plugin against real AWS resources, so I kept the
code untouched and only made the existing deprecation explicit; the actual
migration is left to the plugin author (see the issues).

…le change

The pull_request paths filters of test.yml and test-e2e.yml list
'go.mod', 'go.sum' and 'Makefile' without a directory prefix. GitHub
matches these patterns against the repository root only, so changes to
backend/go.mod, backend/go.sum or backend/Makefile never trigger the
unit-test and e2e jobs. Dependabot gomod PRs (e.g. apache#9192) therefore
become mergeable without a single compile or test run, and the go.mod
tidiness guard added in apache#9179 is skipped exactly where it matters.

Prefix the patterns with '**/' so they match at any depth, including
the repository root.
aws-sdk-go v1 reached end-of-support on 2025-07-31. Its final release,
v1.55.8, marks every package as deprecated, so staticcheck reports
SA1019 for each import in plugins/kiro. This turns the lint job red for
the Dependabot go-minor-patch group (apache#9192) and for every future gomod
update, although nothing in the code changed.

Exclude exactly this finding (SA1019 for aws-sdk-go, only under
plugins/kiro/) instead of pinning the dependency or adding nolint
comments, so the remaining technical debt stays visible in one place.
The exclusion is meant to be removed once the plugin is migrated to
aws-sdk-go-v2 (tracked in a separate issue).
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant