Skip to content

chore(deps): update module github.com/go-git/gcfg to v2 - #160

Open
red-hat-konflux[bot] wants to merge 1 commit into
mainfrom
konflux/mintmaker/main/github.com-go-git-gcfg-2.x
Open

chore(deps): update module github.com/go-git/gcfg to v2#160
red-hat-konflux[bot] wants to merge 1 commit into
mainfrom
konflux/mintmaker/main/github.com-go-git-gcfg-2.x

Conversation

@red-hat-konflux

@red-hat-konflux red-hat-konflux Bot commented Jan 27, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
github.com/go-git/gcfg v1.5.1-0.20230307220236-3a3c6141e376v2.0.2 age confidence

Release Notes

go-git/gcfg (github.com/go-git/gcfg)

v2.0.2

Compare Source

What's Changed

New Contributors

Full Changelog: go-git/gcfg@v2.0.1...v2.0.2

v2.0.1

Compare Source

What's Changed

New Contributors

Full Changelog: go-git/gcfg@v2.0.0...v2.0.1


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

To execute skipped test pipelines write comment /ok-to-test.


Documentation

Find out how to configure dependency updates in MintMaker documentation or see all available configuration options in Renovate documentation.

@red-hat-konflux red-hat-konflux Bot changed the title chore(deps): update module github.com/go-git/gcfg to v2 chore(deps): update module github.com/go-git/gcfg to v2 - autoclosed Jan 29, 2026
@red-hat-konflux red-hat-konflux Bot closed this Jan 29, 2026
@red-hat-konflux
red-hat-konflux Bot deleted the konflux/mintmaker/main/github.com-go-git-gcfg-2.x branch January 29, 2026 21:01
@red-hat-konflux red-hat-konflux Bot changed the title chore(deps): update module github.com/go-git/gcfg to v2 - autoclosed chore(deps): update module github.com/go-git/gcfg to v2 Jan 30, 2026
@red-hat-konflux red-hat-konflux Bot reopened this Jan 30, 2026
@red-hat-konflux
red-hat-konflux Bot force-pushed the konflux/mintmaker/main/github.com-go-git-gcfg-2.x branch 2 times, most recently from ef8d717 to 71a61d8 Compare January 30, 2026 01:02
@red-hat-konflux red-hat-konflux Bot changed the title chore(deps): update module github.com/go-git/gcfg to v2 chore(deps): update module github.com/go-git/gcfg to v2 - autoclosed Jan 30, 2026
@red-hat-konflux red-hat-konflux Bot closed this Jan 30, 2026
@red-hat-konflux red-hat-konflux Bot changed the title chore(deps): update module github.com/go-git/gcfg to v2 - autoclosed chore(deps): update module github.com/go-git/gcfg to v2 Jan 31, 2026
@red-hat-konflux red-hat-konflux Bot reopened this Jan 31, 2026
@red-hat-konflux
red-hat-konflux Bot force-pushed the konflux/mintmaker/main/github.com-go-git-gcfg-2.x branch 2 times, most recently from 71a61d8 to 49ba3e1 Compare January 31, 2026 01:06
@red-hat-konflux red-hat-konflux Bot changed the title chore(deps): update module github.com/go-git/gcfg to v2 chore(deps): update module github.com/go-git/gcfg to v2 - autoclosed Feb 18, 2026
@red-hat-konflux red-hat-konflux Bot closed this Feb 18, 2026
@red-hat-konflux red-hat-konflux Bot changed the title chore(deps): update module github.com/go-git/gcfg to v2 - autoclosed chore(deps): update module github.com/go-git/gcfg to v2 Feb 18, 2026
@red-hat-konflux red-hat-konflux Bot reopened this Feb 18, 2026
@red-hat-konflux
red-hat-konflux Bot force-pushed the konflux/mintmaker/main/github.com-go-git-gcfg-2.x branch 2 times, most recently from 49ba3e1 to 373cc5d Compare February 18, 2026 05:34
@red-hat-konflux red-hat-konflux Bot changed the title chore(deps): update module github.com/go-git/gcfg to v2 chore(deps): update module github.com/go-git/gcfg to v2 - autoclosed Feb 19, 2026
@red-hat-konflux red-hat-konflux Bot closed this Feb 19, 2026
@red-hat-konflux red-hat-konflux Bot changed the title chore(deps): update module github.com/go-git/gcfg to v2 - autoclosed chore(deps): update module github.com/go-git/gcfg to v2 Feb 20, 2026
@red-hat-konflux red-hat-konflux Bot reopened this Feb 20, 2026
@red-hat-konflux
red-hat-konflux Bot force-pushed the konflux/mintmaker/main/github.com-go-git-gcfg-2.x branch 2 times, most recently from 373cc5d to 98b34c1 Compare February 20, 2026 01:17
@red-hat-konflux red-hat-konflux Bot changed the title chore(deps): update module github.com/go-git/gcfg to v2 chore(deps): update module github.com/go-git/gcfg to v2 - autoclosed Mar 2, 2026
@red-hat-konflux red-hat-konflux Bot closed this Mar 2, 2026
@red-hat-konflux red-hat-konflux Bot changed the title chore(deps): update module github.com/go-git/gcfg to v2 - autoclosed chore(deps): update module github.com/go-git/gcfg to v2 Mar 3, 2026
@red-hat-konflux red-hat-konflux Bot reopened this Mar 3, 2026
@red-hat-konflux
red-hat-konflux Bot force-pushed the konflux/mintmaker/main/github.com-go-git-gcfg-2.x branch from 1f982e7 to 98b34c1 Compare March 3, 2026 01:52
@red-hat-konflux
red-hat-konflux Bot force-pushed the konflux/mintmaker/main/github.com-go-git-gcfg-2.x branch from a338931 to 2bcfce3 Compare April 2, 2026 22:34
@red-hat-konflux red-hat-konflux Bot changed the title chore(deps): update module github.com/go-git/gcfg to v2 chore(deps): update module github.com/go-git/gcfg to v2 - autoclosed Apr 5, 2026
@red-hat-konflux red-hat-konflux Bot closed this Apr 5, 2026
@red-hat-konflux red-hat-konflux Bot changed the title chore(deps): update module github.com/go-git/gcfg to v2 - autoclosed chore(deps): update module github.com/go-git/gcfg to v2 Apr 5, 2026
@red-hat-konflux red-hat-konflux Bot reopened this Apr 5, 2026
@red-hat-konflux
red-hat-konflux Bot force-pushed the konflux/mintmaker/main/github.com-go-git-gcfg-2.x branch 2 times, most recently from 2bcfce3 to 2edcaf6 Compare April 5, 2026 13:59
@red-hat-konflux
red-hat-konflux Bot force-pushed the konflux/mintmaker/main/github.com-go-git-gcfg-2.x branch from 2edcaf6 to 0b88791 Compare April 14, 2026 10:47
@red-hat-konflux red-hat-konflux Bot changed the title chore(deps): update module github.com/go-git/gcfg to v2 chore(deps): update module github.com/go-git/gcfg to v2 - autoclosed Apr 18, 2026
@red-hat-konflux red-hat-konflux Bot closed this Apr 18, 2026
@red-hat-konflux red-hat-konflux Bot changed the title chore(deps): update module github.com/go-git/gcfg to v2 - autoclosed chore(deps): update module github.com/go-git/gcfg to v2 Apr 18, 2026
@red-hat-konflux red-hat-konflux Bot reopened this Apr 18, 2026
@red-hat-konflux
red-hat-konflux Bot force-pushed the konflux/mintmaker/main/github.com-go-git-gcfg-2.x branch 2 times, most recently from 0b88791 to a6c992a Compare April 18, 2026 06:05
@red-hat-konflux red-hat-konflux Bot changed the title chore(deps): update module github.com/go-git/gcfg to v2 chore(deps): update module github.com/go-git/gcfg to v2 - autoclosed Apr 27, 2026
@red-hat-konflux red-hat-konflux Bot closed this Apr 27, 2026
@fullsend-ai-review

fullsend-ai-review Bot commented Jun 25, 2026

Copy link
Copy Markdown

🤖 Finished Review · ✅ Success · Started 10:46 PM UTC · Completed 10:53 PM UTC
Commit: 01f864b · View workflow run →

@fullsend-ai-review

fullsend-ai-review Bot commented Jun 25, 2026

Copy link
Copy Markdown

Review

Findings

High

  • [dependency compatibility] go.mod:57 — The PR replaces github.com/go-git/gcfg v1.5.1-... with github.com/go-git/gcfg/v2 v2.0.2. However, go-git/go-git/v5 v5.13.2 (the sole consumer of this indirect dependency) still requires gcfg v1, not v2 — confirmed by inspecting go-git's go.mod at the v5.13.2 tag. Even the latest go-git release (v5.19.1) depends on gcfg v1. In Go modules, gcfg and gcfg/v2 are entirely distinct modules with different import paths. Replacing v1 with v2 will break the module graph: go mod tidy will re-add the v1 entry and discard the unused v2 entry. The PR metadata itself notes "Some dependencies could not be looked up," corroborating that Renovate did not fully resolve the dependency graph.
    Remediation: Do not merge as-is. The v1 dependency must remain until go-git/go-git/v5 releases a version that imports gcfg/v2. Run go mod tidy to verify.

Medium

  • [missing artifact] go.mod — The PR modifies go.mod but does not include a corresponding go.sum update. The base branch go.sum has entries only for gcfg v1 — no checksums for gcfg/v2 exist. This confirms go mod tidy was not run, and the build will fail on checksum verification.
    Remediation: Run go mod tidy and include the resulting go.sum changes. This will also surface the compatibility issue above.
Previous run

Review — request-changes

PR: #160 — chore(deps): update module github.com/go-git/gcfg to v2
Author: red-hat-konflux[bot] (Renovate/MintMaker)
Changed files: go.mod (1 addition, 1 deletion)

Summary

This automated dependency-update PR attempts to bump github.com/go-git/gcfg from v1.5.1-0.20230307220236-3a3c6141e376 to github.com/go-git/gcfg/v2 v2.0.2. The change modifies only go.mod and does not update go.sum.

Findings

1. 🔴 Incompatible Go major-version module path change — high / correctness

File: go.mod (line 57)

The PR replaces github.com/go-git/gcfg (v1 module path) with github.com/go-git/gcfg/v2 (v2 module path). In Go modules, major version suffixes create distinct module pathsgcfg and gcfg/v2 are treated as entirely separate modules.

The parent dependency github.com/go-git/go-git/v5 v5.13.2 imports github.com/go-git/gcfg (the v1 path). Simply swapping the go.mod entry from v1 to v2 does not satisfy go-git's transitive dependency on the v1 module. The Go toolchain will either:

  • Fail to resolve the v1 import (build error), or
  • Re-add the v1 entry when go mod tidy is run, making the v2 line unnecessary

CI confirms this incompatibility: both "Run Tests" and "Lint Go Code" checks fail on this PR.

Remediation: This dependency cannot be updated to v2 independently. The migration to gcfg/v2 must be driven by go-git/go-git itself adopting the v2 import path in a future release. Once go-git/go-git updates its dependency, Renovate will pick up the transitive change automatically. Close this PR and, if desired, configure Renovate to ignore gcfg major-version updates (e.g., via matchPackageNames + matchUpdateTypes in renovate.json).

2. 🟡 Missing go.sum update — medium / correctness

File: go.sum

Any change to go.mod dependency versions must be accompanied by a corresponding go.sum update (removing old checksums, adding new ones). This PR modifies go.mod but leaves go.sum untouched, which means go mod verify would fail and the module graph is not properly locked.

Remediation: Run go mod tidy after resolving the module path incompatibility above. In practice, fixing finding #1 (closing the PR) makes this moot.

Verdict

request-changes — The Go major-version module path change is incompatible with the current go-git/go-git/v5 v5.13.2 dependency, breaking the build. This is confirmed by CI failures. The gcfg v1→v2 migration cannot be performed in isolation; it must come as part of a go-git/go-git update that itself adopts gcfg/v2.

Previous run (2)

Review — request-changes

Summary

This automated dependency update replaces github.com/go-git/gcfg v1.5.1-0.20230307220236-3a3c6141e376 with github.com/go-git/gcfg/v2 v2.0.2 in go.mod. However, in Go's module system, moving from v1 to v2 changes the module pathgithub.com/go-git/gcfg and github.com/go-git/gcfg/v2 are treated as entirely different modules. This is not a simple version bump.

Findings

1. Incompatible module path change breaks the build — high / correctness

File: go.mod (line 57)

gcfg is an indirect dependency, pulled in by go-git/go-git/v5 v5.13.2. The current go-git v5.13.2 imports github.com/go-git/gcfg (the v1 module path). Replacing the v1 entry in go.mod with the v2 module path (github.com/go-git/gcfg/v2) does not satisfy go-git's v1 import — Go treats these as separate modules.

Evidence:

  • go.sum on main only contains checksums for github.com/go-git/gcfg v1.5.1-... — no v2 entries exist
  • The PR does not update go.sum (only go.mod is changed)
  • Both "Run Tests" and "Lint Go Code" CI checks are failing on this PR

Impact: The module graph is broken. go build, go test, and go mod tidy will fail because go-git still requires the v1 module that was removed.

Remediation: This PR cannot be merged as-is. The migration to gcfg/v2 requires go-git itself to first release a version that imports gcfg/v2 instead of gcfg/v1. Until then, close this PR. If a newer go-git version that uses gcfg/v2 exists, the correct approach is to update go-git first, then run go mod tidy to let the dependency graph resolve naturally.

Previous run (3)

Review

Verdict: request-changes

Summary

This PR replaces the indirect dependency github.com/go-git/gcfg (v1) with github.com/go-git/gcfg/v2 (v2.0.2) in go.mod. However, this is a build-breaking change because the parent dependency go-git/go-git/v5 v5.13.2 still requires gcfg v1.

In Go modules, github.com/go-git/gcfg and github.com/go-git/gcfg/v2 are entirely separate module paths. Removing the v1 module from go.mod while go-git/go-git/v5 still depends on it will cause go mod tidy to re-add the v1 entry, or — if merged without running go mod tidy — the build will fail outright. Additionally, go.sum was not updated and contains no checksums for the v2 module.

Findings

# Severity Category File Description
1 🔴 critical Dependency graph break go.mod:57 go-git/go-git/v5 v5.13.2 requires gcfg v1, not gcfg/v2. These are distinct Go module paths — replacing one with the other removes a required transitive dependency and breaks the build.

Recommendation

Do not merge this PR. The gcfg v1 dependency must remain in go.mod as long as go-git/go-git/v5 v5.13.2 requires it. This can only be resolved when go-git/go-git/v5 itself releases a version that depends on gcfg/v2 — at which point both go-git and gcfg should be upgraded together. The Renovate/MintMaker configuration may need adjustment to avoid treating Go major-version module path changes as simple version bumps.

Previous run (4)

Review

Findings

High

  • [logic-error] go.mod:57 — This PR changes the indirect dependency from github.com/go-git/gcfg (v1 module path) to github.com/go-git/gcfg/v2 (v2 module path). In Go modules, these are distinct modules with different import paths. The direct consumer github.com/go-git/go-git/v5 v5.13.2 (line 59) was released importing github.com/go-git/gcfg (v1). Manually replacing the v1 module path with v2 will not satisfy go-git's imports — go-git will still require the v1 module, and the build will fail. Additionally, go.sum contains no checksums for gcfg/v2 (only for gcfg v1), so go mod verify will also fail.
    Remediation: Either (a) update go-git/go-git/v5 to a version that depends on gcfg/v2 (if one exists) and run go mod tidy, or (b) revert the gcfg change and let go mod tidy resolve transitive dependencies correctly. The go.sum must also be regenerated to match.
Previous run (5)

Review

Findings

High

  • [logic-error] go.mod:57 — This PR replaces the indirect dependency github.com/go-git/gcfg (v1 module path) with github.com/go-git/gcfg/v2 (v2 module path). In Go modules, these are distinct modules. The consumer is github.com/go-git/go-git/v5 v5.13.2. If go-git v5.13.2 does not actually require gcfg/v2, this change is incorrect — go-git would still transitively pull in v1, and the v2 entry would be unused or cause build failures. Additionally, go.sum has not been updated: it contains checksums only for gcfg v1 and has no entries for gcfg/v2, which means any build or go mod verify will fail regardless. Running go mod tidy would both validate whether gcfg/v2 is actually needed and regenerate go.sum with correct checksums.
    Remediation: Run go mod tidy and verify whether the resulting go.mod contains gcfg/v2 or gcfg v1. If gcfg/v2 is needed, include the updated go.sum. If it is not needed, this change is incorrect and should not be merged.

fullsend-ai-review[bot]

This comment was marked as outdated.

@fullsend-ai-review

fullsend-ai-review Bot commented Jun 28, 2026

Copy link
Copy Markdown

🤖 Finished Review · ✅ Success · Started 5:29 PM UTC · Completed 5:37 PM UTC
Commit: 01f864b · View workflow run →

fullsend-ai-review[bot]

This comment was marked as outdated.

@fullsend-ai-review

fullsend-ai-review Bot commented Jul 10, 2026

Copy link
Copy Markdown

🤖 Finished Review · ✅ Success · Started 5:44 PM UTC · Completed 5:51 PM UTC
Commit: 58b0710 · View workflow run →

fullsend-ai-review[bot]

This comment was marked as outdated.

@fullsend-ai-review

fullsend-ai-review Bot commented Jul 16, 2026

Copy link
Copy Markdown

🤖 Finished Review · ✅ Success · Started 2:18 PM UTC · Completed 2:22 PM UTC
Commit: 58b0710 · View workflow run →

fullsend-ai-review[bot]

This comment was marked as outdated.

@fullsend-ai-review

fullsend-ai-review Bot commented Jul 17, 2026

Copy link
Copy Markdown

🤖 Finished Review · ✅ Success · Started 5:26 AM UTC · Completed 5:30 AM UTC
Commit: 58b0710 · View workflow run →

fullsend-ai-review[bot]

This comment was marked as outdated.

@fullsend-ai-review

fullsend-ai-review Bot commented Jul 22, 2026

Copy link
Copy Markdown

🤖 Finished Review · ✅ Success · Started 4:39 PM UTC · Completed 4:50 PM UTC
Commit: 58b0710 · View workflow run →

@fullsend-ai-review fullsend-ai-review Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

See the review comment for full details.

Comment thread go.mod
github.com/fxamacker/cbor/v2 v2.7.0 // indirect
github.com/go-errors/errors v1.5.1 // indirect
github.com/go-git/gcfg v1.5.1-0.20230307220236-3a3c6141e376 // indirect
github.com/go-git/gcfg/v2 v2.0.2 // indirect

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[high] dependency compatibility

The PR replaces github.com/go-git/gcfg v1.5.1-... with github.com/go-git/gcfg/v2 v2.0.2. However, go-git/go-git/v5 v5.13.2 (the sole consumer of this indirect dependency) still requires gcfg v1, not v2. Even the latest go-git release (v5.19.1) depends on gcfg v1. In Go modules, gcfg and gcfg/v2 are entirely distinct modules with different import paths — replacing v1 with v2 will break the module graph.

Suggested fix: Do not merge as-is. The v1 dependency must remain until go-git/go-git/v5 releases a version that imports gcfg/v2. Run go mod tidy to verify.

Signed-off-by: red-hat-konflux <126015336+red-hat-konflux[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants