Skip to content

fix(release): bump examples/go and track go.work.sum on release - #43

Merged
samzong merged 1 commit into
mainfrom
fix/release-example-go-version
Sep 12, 2026
Merged

samzong merged 1 commit into
mainfrom
fix/release-example-go-version

Conversation

@samzong

@samzong samzong commented Sep 12, 2026

Copy link
Copy Markdown
Collaborator

Summary

go.work.sum was permanently dirty: every go command rewrote it, so any local build left an unrelated modification in the worktree.

Root cause is a version skew introduced by the v0.1.4 release. go-cobra/go.mod moved to v0.1.4 but examples/go/go.mod stayed on v0.1.3, and both modules are in the workspace:

module required github.com/lathe-cli/kitup/go
go-cobra/go.mod v0.1.4
examples/go/go.mod v0.1.3 (before this PR)

Minimal version selection picks the higher of the two, so go kept rewriting the tracked v0.1.3 line to v0.1.4.

scripts/prepare-release.mjs only knew about go-cobra/go.mod, so the skew would reappear on the next release. Both modules now go through the same replaceOne.

go.work.sum is also added to changedFiles. The script runs make check before git add, and that run rewrites the file, so leaving it out of the commit list would have reopened the same gap one release later.

Verification beyond make check:

  • Deleting go.work.sum and letting the toolchain regenerate it reproduces the committed line byte for byte, so the committed content is the tool's steady state rather than a hand-written guess.
  • A full check.mjs run no longer leaves the file dirty.
  • prepare-release.mjs patch --dry-run exits 0, which also proves the version regex matches exactly once in both go.mod files — replaceOne fails when the match count is not 1.
  • Bumping both modules to a version that does not exist on the module proxy still builds, since the workspace satisfies the dependency from ./go locally. A release run therefore does not need its own version published first.

Scope Check

  • Stays within the v0.1 bundled-skill installer boundary.
  • Does not add marketplace, registry, private remote install, script execution, GUI, MCP server, or agent runtime behavior.
  • Updates golden cases for observable installer behavior changes. (Build metadata only; no installer behavior change.)
  • Regenerates host constants after spec/hosts.json changes. (spec/hosts.json untouched.)

Verification

  • make check

The v0.1.4 release left examples/go/go.mod on v0.1.3 while go-cobra/go.mod
moved to v0.1.4. The workspace then had to resolve two versions of the same
dependency, so every go command rewrote go.work.sum to the higher one and the
file was permanently dirty.

prepare-release.mjs only knew about go-cobra/go.mod, so the drift would
reappear on the next release. It now bumps both modules through the same
replaceOne, and carries go.work.sum in changedFiles: make check runs before
git add and rewrites that file, so leaving it out reopened the same gap.

Deleting go.work.sum and letting the toolchain regenerate it reproduces the
committed line exactly, and a full check.mjs run no longer leaves it dirty.

Signed-off-by: samzong <samzong.lu@gmail.com>
@samzong
samzong merged commit 6dc6e48 into main Sep 12, 2026
22 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant