-
Notifications
You must be signed in to change notification settings - Fork 46
Bump golangci/golangci-lint-action from 7 to 8 #271
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Bump golangci/golangci-lint-action from 7 to 8 #271
Conversation
Bumps [golangci/golangci-lint-action](https://github.com/golangci/golangci-lint-action) from 7 to 8. - [Release notes](https://github.com/golangci/golangci-lint-action/releases) - [Commits](golangci/golangci-lint-action@v7...v8) --- updated-dependencies: - dependency-name: golangci/golangci-lint-action dependency-version: '8' dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <[email protected]>
@dependabot rebase |
Looks like this PR has been edited by someone other than Dependabot. That means Dependabot can't rebase it - sorry! If you're happy for Dependabot to recreate it from scratch, overwriting any edits, you can request |
f01e09d
to
2596398
Compare
.github/workflows/golangci-lint.yml
Outdated
with: | ||
version: v2.0.2 |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
@elezar What is the reason you'd prefer to go without version-locking the linter ?
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
It was either this or bump the version since the newer action requires a newer version.
What benefit does locking the linter add?
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Predictability, mostly I think. Newer versions of golangci-lint has consistently started flagging things earlier version did not use to complain about.
Without a version lock (IOW without control over which version of golangci-lint is used in CI), I think it can easily happen that a PR starts failing the linter without any related changes being introduced in the PR itself, just the linter action bumping the default version of the linter being used. Whether this is a problem or a desired thing is admittedly a bit of a matter of taste.
The v8 action requires at least v2.1.0. Signed-off-by: Evan Lezar <[email protected]>
2596398
to
983da8e
Compare
Bumps golangci/golangci-lint-action from 7 to 8.
Release notes
Sourced from golangci/golangci-lint-action's releases.
Commits
4afd733
8.0.07774f98
feat: use absolute paths by default when using working-directory option (#1231)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase
.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebase
will rebase this PR@dependabot recreate
will recreate this PR, overwriting any edits that have been made to it@dependabot merge
will merge this PR after your CI passes on it@dependabot squash and merge
will squash and merge this PR after your CI passes on it@dependabot cancel merge
will cancel a previously requested merge and block automerging@dependabot reopen
will reopen this PR if it is closed@dependabot close
will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot show <dependency name> ignore conditions
will show all of the ignore conditions of the specified dependency@dependabot ignore this major version
will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor version
will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependency
will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)