Repository navigation
chore(deps): update module github.com/goccy/go-json to v0.11.2 #28
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: main
Are you sure you want to change the base?
Changes from all commits
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -134,7 +134,7 @@ require ( | |
| github.com/go-openapi/swag v0.19.15 // indirect | ||
| github.com/go-playground/locales v0.14.1 // indirect | ||
| github.com/go-playground/universal-translator v0.18.1 // indirect | ||
| github.com/goccy/go-json v0.10.5 // indirect | ||
| github.com/goccy/go-json v0.11.2 // indirect | ||
|
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. [low] runtime behavioral change go-json v0.11.x introduces stricter JSON validation compared to v0.10.x. However, go-json is an indirect (transitive) dependency marked with // indirect in go.mod. No Go source files in the project directly import it. Gin v1.9.1 defaults to encoding/json and only uses go-json when the go_json build tag is explicitly set. The actual runtime impact is low without the build tag. Suggested fix: No specific action required beyond ensuring existing tests pass. If the project uses a custom build tag to enable go-json in gin, verify API endpoints with integration tests. |
||
| github.com/godbus/dbus v0.0.0-20190726142602-4481cbc300e2 // indirect | ||
| github.com/gogo/protobuf v1.3.2 // indirect | ||
| github.com/golang/groupcache v0.0.0-20210331224755-41bb18bfe9da // indirect | ||
|
|
||
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
[high] build integrity
The PR updates go-json from v0.10.5 to v0.11.2 in go.mod but does not include a corresponding update to backend/go.sum. The existing go.sum contains checksums only for v0.10.5. Without v0.11.2 checksums in go.sum, go build, go mod verify, and go test will fail with a checksum verification error, preventing the project from building.
Suggested fix: Run
go mod tidy(orgo mod download) in the backend/ directory and include the resulting go.sum changes in the PR.