• Home
  • Features
  • Pricing
  • Docs
  • Announcements
  • Sign In

opendefensecloud / solution-arsenal / 35360159916
79%

Build:
DEFAULT BRANCH: main
Ran 18 Sep 2026 03:17PM UTC
Jobs 1
Files 94
Run time 1min
Badge
Embed ▾
README BADGES
x

If you need to use a raster PNG badge, change the '.svg' to '.png' in the link

Markdown

Textile

RDoc

HTML

Rst

18 Sep 2026 03:04PM UTC coverage: 78.534% (-0.03%) from 78.565%
35360159916

push

github

web-flow
ci: fail on an untidy go.mod, and hold structured-merge-diff (#813)

## What

Run `go mod tidy` in the codegen `check` job so an untidy `go.mod` fails
CI, and stop Renovate proposing the `sigs.k8s.io/structured-merge-diff`
**major** bump until Kubernetes 0.38.

## Why

Renovate keeps proposing the `structured-merge-diff` v6 to v7 major
bump, but it cannot complete it. The import lives in generated code
(`client-go/applyconfigurations/internal/internal.go` imports
`sigs.k8s.io/structured-merge-diff/v6/typed`), and rewriting a Go major
import path needs `gomodUpdateImportPaths`, which our shared config does
not enable. Renovate therefore adds the v7 require without touching the
import, nothing imports it, and the next `go mod tidy` deletes it again.
That already happened once: it merged as #808 and was silently reverted
by the tidy in #786. #812 is the same change reopened.

The major is not ours to pick. `applyconfiguration-gen` from
`k8s.io/code-generator` emits the import, and
`apimachinery/managedfields` has to agree on the same major — a mismatch
is a hard compile error, which is what #786 hit. Both move together when
Kubernetes 0.38 ships, so the hold shares a gate with the existing
`kube-openapi` rule.

The `go mod tidy` step is the general safety net rather than a fix for
this one dependency: it turns any untidy `go.mod` into a failing check
instead of something that merges and gets quietly undone by a later PR.

## Testing

- `make codegen` is clean on this branch — no generated output changes.
- Verified the new check discriminates: `go mod tidy` on `origin/main`
leaves the tree clean (passes), and on #812's branch leaves `go.mod` and
`go.sum` modified (fails).
- Confirmed the reproduction from tidy-stable `main`: adding the v7
require and running `go mod tidy` removes it again, so the require
Renovate commits is genuinely unused.

## Notes for reviewers

- The hold is scoped with `matchUpdateTypes: ["major"]` on purpose. A
bare `enabled: fals... (continued)

5078 of 6466 relevant lines covered (78.53%)

27.11 hits per line

Coverage Regressions

Lines Coverage ∆ File
2
71.88
-3.13% pkg/controller/registrybinding_controller.go
2
76.69
-0.2% pkg/controller/target_controller.go
1
88.66
-1.03% pkg/discovery/runner.go
Jobs
ID Job ID Ran Files Coverage
1 35360159916.1 18 Sep 2026 03:17PM UTC 94
78.53
GitHub Action Run
Source Files on build 35360159916
  • Tree
  • List 94
  • Changed 5
  • Source Changed 0
  • Coverage Changed 5
Coverage ∆ File Lines Relevant Covered Missed Hits/Line
  • Back to Repo
  • Github Actions Build #35360159916
  • 72fe7d8d on github
  • Prev Build on main (#35347912429)
  • Next Build on main (#35553136166)
STATUS · Troubleshooting · Open an Issue · Sales · Support · CAREERS · ENTERPRISE · START FREE TRIAL · SCHEDULE DEMO
ANNOUNCEMENTS · TWITTER · TOS & SLA · Supported CI Services · What's a CI service? · Automated Testing

© 2026 Coveralls, Inc