Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Migrate goformation under pkg/ as a local package and remove location re-write #8218

Closed

Conversation

bryantbiggs
Copy link
Member

Description

  • Migrate goformation under pkg/ as a local package and remove location re-write
    • This removes the second set of dependencies and treats it as a local package, not a remote module

This is to resolve the reported security findings shown here https://github.com/eksctl-io/eksctl/security/dependabot

This is a repeat of #8153 which was reverted since it was caught up in the changes with the failed build image #8157

The steps used to create this PR are as follows (to better understand due to large number of path re-write changes):

  1. Move the goformation directory under pkg/
  2. Remove the goformation references from the main go.mod file
  3. Remove go.mod and go.sum from pkg/goformation/*
  4. Re-write paths for goformation (find ./ -type f -name '*.go' -exec sed -i 's|awslabs/goformation/v4|weaveworks/eksctl/pkg/goformation|g' {} \;)
  5. Run go mod tidy
  6. Run make build
  7. Run make unit-test-no-generate to test

Checklist

  • Added tests that cover your change (if possible)
  • Added/modified documentation as required (such as the README.md, or the userdocs directory)
  • Manually tested
  • Made sure the title of the PR is a good description that can go into the release notes
  • (Core team) Added labels for change area (e.g. area/nodegroup) and kind (e.g. kind/improvement)

BONUS POINTS checklist: complete for good vibes and maybe prizes?! 🤯

  • Backfilled missing tests for code in same general area 🎉
  • Refactored something and made the world a better place 🌟

@bryantbiggs bryantbiggs added skip-release-notes Causes PR not to show in release notes dependencies Pull requests that update a dependency file area/tech-debt Leftover improvements in code, testing and building labels Feb 14, 2025
@bryantbiggs bryantbiggs force-pushed the chore/goformation-internal-pkg branch from a965dbe to f831d81 Compare February 14, 2025 15:05
@bryantbiggs bryantbiggs requested a review from dims February 14, 2025 17:54
@cheeseandcereal
Copy link
Member

cheeseandcereal commented Feb 14, 2025

These changes largely look good to me. I have 2 asks:

  1. Can you move this to a feature branch within this eksctl repository? Then I'll be able to run the integration tests against them to help confirm nothing is broken by this.
  2. Can you confirm that go mod verify works too? That's what broke some packaging last time (Vendoring 0.199.0 fails with "goformation/v4 v4.0.0: missing ziphash: open hash: no such file or directory" #8090). I don't see why it wouldn't work, but good to double check.

@bryantbiggs
Copy link
Member Author

yes, the go mod verify still works. let me close and re-open with a branch of this repo and not a fork

image

@bryantbiggs
Copy link
Member Author

moved to #8219

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
area/tech-debt Leftover improvements in code, testing and building dependencies Pull requests that update a dependency file skip-release-notes Causes PR not to show in release notes
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants