From ecb5c78a6e42071dacdbb75d5bda7ca4a67448b3 Mon Sep 17 00:00:00 2001 From: David Gageot Date: Fri, 9 Oct 2026 12:03:13 +0200 Subject: [PATCH 1/2] chore: bump Go to 1.27.2 --- Dockerfile | 2 +- go.mod | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/Dockerfile b/Dockerfile index 445000ff2..c652e9127 100644 --- a/Dockerfile +++ b/Dockerfile @@ -1,6 +1,6 @@ # syntax=docker/dockerfile:1 -ARG GO_VERSION="1.27.0" +ARG GO_VERSION="1.27.2" ARG ALPINE_VERSION="3.23" ARG XX_VERSION="1.9.0" diff --git a/go.mod b/go.mod index 8eeb637d8..2a912d09e 100644 --- a/go.mod +++ b/go.mod @@ -2,7 +2,7 @@ module github.com/docker/docker-agent go 1.27 -toolchain go1.27.0 +toolchain go1.27.2 require ( charm.land/bubbles/v2 v2.2.1 From 1958faaad252210c288ce26d45671b0ec4356204 Mon Sep 17 00:00:00 2001 From: David Gageot Date: Fri, 9 Oct 2026 12:09:23 +0200 Subject: [PATCH 2/2] fix(ci): update lint tooling for Go 1.27.2 golangci-lint 2.13.2 can't read export data from Go 1.27.2, so bump CI to 2.14.0 and document the minimum version. Also quiets the gosec G407 false positive on NewGCMWithRandomNonce and tweaks the doctor command-quoting output/tests to match. Assisted-By: cagent Signed-off-by: David Gageot --- .github/workflows/ci.yml | 2 +- cmd/root/doctor.go | 4 ++-- cmd/root/doctor_test.go | 4 ++-- docs/community/contributing/index.md | 2 +- pkg/protect/encrypt.go | 2 +- 5 files changed, 7 insertions(+), 7 deletions(-) diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index b39fd7db5..a0b6f77b8 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -109,7 +109,7 @@ jobs: - name: golangci-lint uses: golangci/golangci-lint-action@ba0d7d2ec06a0ea1cb5fa41b2e4a3ab91d21278a # v9.3.0 with: - version: v2.13.2 + version: v2.14.0 # The rest of `task lint`: project cops and go.mod tidiness. - name: Project cops diff --git a/cmd/root/doctor.go b/cmd/root/doctor.go index 59a0f8601..4644ce1f4 100644 --- a/cmd/root/doctor.go +++ b/cmd/root/doctor.go @@ -473,13 +473,13 @@ func allAgentsHarnessBacked(cfg *latest.Config) bool { func claudeHarnessIssue(ref string, status codingharness.ClaudeCLIStatus) string { switch status.State { case codingharness.ClaudeStateNotInstalled: - return fmt.Sprintf("%s uses a claude-code harness but the `claude` CLI was not found in PATH; install Claude Code (%s) and log in with `%s`", + return fmt.Sprintf("%s uses a claude-code harness but the `claude` CLI was not found in PATH; install Claude Code (%s) and log in with %#q", ref, codingharness.ClaudeInstallDocsURL, codingharness.ClaudeLoginCommand) case codingharness.ClaudeStateAuthCheckFailed: return fmt.Sprintf("%s uses a claude-code harness but the Claude Code login could not be verified (%s); run `claude auth status` as the same OS user and environment that run docker-agent", ref, status.Detail) case codingharness.ClaudeStateUnauthenticated: - return fmt.Sprintf("%s uses a claude-code harness but the `claude` CLI is not logged in; run `%s` as the same OS user and environment that run docker-agent", + return fmt.Sprintf("%s uses a claude-code harness but the `claude` CLI is not logged in; run %#q as the same OS user and environment that run docker-agent", ref, codingharness.ClaudeLoginCommand) default: return "" diff --git a/cmd/root/doctor_test.go b/cmd/root/doctor_test.go index 759116dbd..94f4a4318 100644 --- a/cmd/root/doctor_test.go +++ b/cmd/root/doctor_test.go @@ -458,7 +458,7 @@ func TestDoctorCommand_ClaudeHarnessNotInstalled(t *testing.T) { assert.Contains(t, output, "Claude Code harness") assert.Contains(t, output, "not found in PATH") assert.Contains(t, output, codingharness.ClaudeInstallDocsURL) - assert.Contains(t, output, "claude auth login --claudeai") + assert.Contains(t, output, "log in with `claude auth login --claudeai`") } func TestDoctorCommand_ClaudeHarnessUnauthenticated(t *testing.T) { @@ -475,7 +475,7 @@ func TestDoctorCommand_ClaudeHarnessUnauthenticated(t *testing.T) { require.Error(t, err) assert.Contains(t, output, "Status: installed (2.1.210 (Claude Code)), not logged in") - assert.Contains(t, output, "claude auth login --claudeai") + assert.Contains(t, output, "run `claude auth login --claudeai`") assert.Contains(t, output, "same OS user and environment") } diff --git a/docs/community/contributing/index.md b/docs/community/contributing/index.md index ede4ba339..ec8f935ec 100644 --- a/docs/community/contributing/index.md +++ b/docs/community/contributing/index.md @@ -15,7 +15,7 @@ _Docker Agent is open source. Here's how to set up your development environment - [Go 1.27](https://go.dev/dl/) or higher - API key(s) for your chosen AI provider - [Task](https://taskfile.dev/installation/) -- [golangci-lint](https://golangci-lint.run/docs/welcome/install/local/) +- [golangci-lint 2.14.0](https://golangci-lint.run/docs/welcome/install/local/) or higher > [!NOTE] > **Platform Support** diff --git a/pkg/protect/encrypt.go b/pkg/protect/encrypt.go index f47e4f7a4..6ae7e8dcc 100644 --- a/pkg/protect/encrypt.go +++ b/pkg/protect/encrypt.go @@ -142,7 +142,7 @@ func aeadSeal(key, data, aad []byte) ([]byte, error) { if err != nil { return nil, err } - return gcm.Seal(nil, nil, data, aad), nil + return gcm.Seal(nil, nil, data, aad), nil //nolint:gosec // G407: NewGCMWithRandomNonce generates the nonce internally. } func aeadOpen(key, blob, aad []byte) ([]byte, error) {