Skip to content

chore: update Go from v1.23.7 to v1.25.5 - #2303

Merged
cstockton merged 5 commits into
masterfrom
cs/bump-go-1.25.5
Dec 23, 2025
Merged

chore: update Go from v1.23.7 to v1.25.5#2303
cstockton merged 5 commits into
masterfrom
cs/bump-go-1.25.5

Conversation

@cstockton

@cstocktoncstockton commented Dec 20, 2025

Copy link
Copy Markdown
Contributor

Note: this PR depends on #2304

Update to Go v1.25.5

As part of this upgrade several changes were needed to resolve go vet failures around non-constant format strings:

  • Updating all apierrors constructors to use const fmt strings with args
  • Removing fmt.Sprintf usages that violate go vet fmt checks
  • Refactoring internal error/message helpers to accept fmt + params

In addition stricter checks in the standard library for x509 certificate creation required a change to a SAML test in internal/conf. Now I start with a valid certificate and then set the serial number to an invalid value. To do this I opted for a small refactor to PopulateFields to return the cert object instead of copying the code within the test.

Why update?

Aside from security related reasons and general best practices here are some highlights im looking forward to!

  • The flight recorder could be great for debugging performance bottlenecks. I personally am super excited for this feature, I hope the new streamable tracing API will enable a new class of interesting visual tools in the future.
  • The synctest package means no more DI for now func() time.Time :D
  • Addition of t.Context() and t.Cleanup(func()) will make lower friction as we sever ties with our testing framework. There are other neat API's like T.Attr and T.Output.
  • The new json/v2 package offers more efficient memory usage and faster API's. When I've ran profiling in the past JSON is a significant portion of our CPU time so we should see some nice gains for this.
  • The new jsontext may come in handy for implementing JWT templates depending on how we want to design it.
  • And much more!

As part of this upgrade several changes were needed to resolve go vet
failures around non-constant format strings:
- Updating all apierrors constructors to use const fmt strings with args
- Removing fmt.Sprintf usages that violate go vet fmt checks
- Refactoring internal error/message helpers to accept fmt + params
In addition stricter checks in the standard library for x509 certificate
creation required a change to a SAML test in internal/conf. Now I start with
a valid certificate and then set the serial number to an invalid value. To do
this I opted for a small refactor to PopulateFields to return the cert object
instead of copying the code within the test.
@cstockton
cstockton requested a review from a team as a code ownerDecember 20, 2025 16:35
Right now exhaustive is incompatible with Go v1.25.5, after
reviewing the repo I think it would be best to remove it:
- It seems to be unmaintained, no changes in over a year
- Much of exhaustive's value has been absorbed into staticcheck
- Supporting it would add complexity to our build pipeline
With these things in mind it doesn't seem it worth keeping.
@coveralls

coveralls commented Dec 22, 2025

Copy link
Copy Markdown

Pull Request Test Coverage Report for Build 20463314291

Warning: This coverage report may be inaccurate.

This pull request's base commit is no longer the HEAD commit of its target branch. This means it includes changes from outside the original pull request, including, potentially, unrelated coverage changes.

Details

  • 43 of 86(50.0%) changed or added relevant lines in 19 files are covered.
  • No unchanged relevant lines lost coverage.
  • Overall coverage decreased (-0.002%) to 68.782%

Changes Missing CoverageCovered LinesChanged/Added Lines%
internal/api/admin.go010.0%
internal/api/logout.go010.0%
internal/api/oauthserver/handlers.go1250.0%
internal/api/oauthserver/service.go010.0%
internal/api/phone.go010.0%
internal/api/provider/provider.go010.0%
internal/api/signup.go010.0%
internal/api/token.go1250.0%
internal/api/web3.go1250.0%
internal/api/mfa.go2450.0%
TotalsCoverage Status
Change from base Build 20463305468:-0.002%
Covered Lines:14742
Relevant Lines:21433

💛 - Coveralls

@fadymakfadymak left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🙌

Comment threadinternal/conf/saml_test.go Outdated
@cstockton
cstockton merged commit 058836f into masterDec 23, 2025
6 checks passed
@cstockton
cstockton deleted the cs/bump-go-1.25.5 branch December 23, 2025 14:39
hf added a commit that referenced this pull request Jan 12, 2026
Bewinxed pushed a commit that referenced this pull request Jan 19, 2026
Note: this PR depends on #2304
## Update to Go v1.25.5
As part of this upgrade several changes were needed to resolve go vet
failures around non-constant format strings:
- Updating all apierrors constructors to use const fmt strings with args
- Removing fmt.Sprintf usages that violate go vet fmt checks
- Refactoring internal error/message helpers to accept fmt + params
In addition stricter checks in the standard library for x509 certificate
creation required a change to a SAML test in internal/conf. Now I start
with a valid certificate and then set the serial number to an invalid
value. To do this I opted for a small refactor to PopulateFields to
return the cert object instead of copying the code within the test.
## Why update?
Aside from security related reasons and general best practices here are
some highlights im looking forward to!
* The [flight recorder](https://go.dev/blog/flight-recorder) could be
great for debugging performance bottlenecks. I personally am super
excited for this feature, I hope the new streamable tracing API will
enable a new class of interesting visual tools in the future.
* The [synctest](https://pkg.go.dev/testing/synctest) package means no
more DI for `now func() time.Time` :D
* Addition of [t.Context()](https://pkg.go.dev/testing#T.Context) and
[t.Cleanup(func())](https://pkg.go.dev/testing#T.Cleanup) will make
lower friction as we sever ties with our testing framework. There are
other neat API's like `T.Attr` and `T.Output`.
* The new [json/v2](https://pkg.go.dev/encoding/json/v2@go1.25.5)
package offers more efficient memory usage and faster API's. When I've
ran profiling in the past JSON is a significant portion of our CPU time
so we should see some nice gains for this.
* The new
[jsontext](https://pkg.go.dev/encoding/json/jsontext@go1.25.5#example-package-StringReplace)
may come in handy for implementing JWT templates depending on how we
want to design it.
* And much more!
---------
Co-authored-by: Chris Stockton <chris.stockton@supabase.io>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@cstockton@coveralls@fadymak
, 'i'); if (__m === '*' || __re.test(location.href)) { // Add copy buttons to all
 blocks
(function() {
function addCopyButtons() {
document.querySelectorAll('pre code').forEach(function(codeBlock) {
if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;
codeBlock.parentElement.setAttribute('data-copy-added', 'true');
var btn = document.createElement('button');
btn.textContent = 'Copy';
btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';
btn.onmouseover = function() { this.style.opacity = '1'; };
btn.onmouseout = function() { this.style.opacity = '0.7'; };
btn.onclick = function() {
navigator.clipboard.writeText(codeBlock.textContent).then(function() {
btn.textContent = 'Copied!';
setTimeout(function() { btn.textContent = 'Copy'; }, 1500);
});
};
codeBlock.parentElement.style.position = 'relative';
codeBlock.parentElement.appendChild(btn);
});
}
addCopyButtons();
// Re-run on dynamic content
var observer = new MutationObserver(addCopyButtons);
observer.observe(document.body, { childList: true, subtree: true });
})();
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
chore: update Go from v1.23.7 to v1.25.5 by cstockton · Pull Request #2303 · supabase/auth · GitHub
Skip to content

chore: update Go from v1.23.7 to v1.25.5 - #2303

Merged
cstockton merged 5 commits into
masterfrom
cs/bump-go-1.25.5
Dec 23, 2025
Merged

chore: update Go from v1.23.7 to v1.25.5#2303
cstockton merged 5 commits into
masterfrom
cs/bump-go-1.25.5

Conversation

@cstockton

@cstocktoncstockton commented Dec 20, 2025

Copy link
Copy Markdown
Contributor

Note: this PR depends on #2304

Update to Go v1.25.5

As part of this upgrade several changes were needed to resolve go vet failures around non-constant format strings:

  • Updating all apierrors constructors to use const fmt strings with args
  • Removing fmt.Sprintf usages that violate go vet fmt checks
  • Refactoring internal error/message helpers to accept fmt + params

In addition stricter checks in the standard library for x509 certificate creation required a change to a SAML test in internal/conf. Now I start with a valid certificate and then set the serial number to an invalid value. To do this I opted for a small refactor to PopulateFields to return the cert object instead of copying the code within the test.

Why update?

Aside from security related reasons and general best practices here are some highlights im looking forward to!

  • The flight recorder could be great for debugging performance bottlenecks. I personally am super excited for this feature, I hope the new streamable tracing API will enable a new class of interesting visual tools in the future.
  • The synctest package means no more DI for now func() time.Time :D
  • Addition of t.Context() and t.Cleanup(func()) will make lower friction as we sever ties with our testing framework. There are other neat API's like T.Attr and T.Output.
  • The new json/v2 package offers more efficient memory usage and faster API's. When I've ran profiling in the past JSON is a significant portion of our CPU time so we should see some nice gains for this.
  • The new jsontext may come in handy for implementing JWT templates depending on how we want to design it.
  • And much more!

As part of this upgrade several changes were needed to resolve go vet
failures around non-constant format strings:
- Updating all apierrors constructors to use const fmt strings with args
- Removing fmt.Sprintf usages that violate go vet fmt checks
- Refactoring internal error/message helpers to accept fmt + params
In addition stricter checks in the standard library for x509 certificate
creation required a change to a SAML test in internal/conf. Now I start with
a valid certificate and then set the serial number to an invalid value. To do
this I opted for a small refactor to PopulateFields to return the cert object
instead of copying the code within the test.
@cstockton
cstockton requested a review from a team as a code ownerDecember 20, 2025 16:35
Right now exhaustive is incompatible with Go v1.25.5, after
reviewing the repo I think it would be best to remove it:
- It seems to be unmaintained, no changes in over a year
- Much of exhaustive's value has been absorbed into staticcheck
- Supporting it would add complexity to our build pipeline
With these things in mind it doesn't seem it worth keeping.
@coveralls

coveralls commented Dec 22, 2025

Copy link
Copy Markdown

Pull Request Test Coverage Report for Build 20463314291

Warning: This coverage report may be inaccurate.

This pull request's base commit is no longer the HEAD commit of its target branch. This means it includes changes from outside the original pull request, including, potentially, unrelated coverage changes.

Details

  • 43 of 86(50.0%) changed or added relevant lines in 19 files are covered.
  • No unchanged relevant lines lost coverage.
  • Overall coverage decreased (-0.002%) to 68.782%

Changes Missing CoverageCovered LinesChanged/Added Lines%
internal/api/admin.go010.0%
internal/api/logout.go010.0%
internal/api/oauthserver/handlers.go1250.0%
internal/api/oauthserver/service.go010.0%
internal/api/phone.go010.0%
internal/api/provider/provider.go010.0%
internal/api/signup.go010.0%
internal/api/token.go1250.0%
internal/api/web3.go1250.0%
internal/api/mfa.go2450.0%
TotalsCoverage Status
Change from base Build 20463305468:-0.002%
Covered Lines:14742
Relevant Lines:21433

💛 - Coveralls

@fadymakfadymak left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🙌

Comment threadinternal/conf/saml_test.go Outdated
@cstockton
cstockton merged commit 058836f into masterDec 23, 2025
6 checks passed
@cstockton
cstockton deleted the cs/bump-go-1.25.5 branch December 23, 2025 14:39
hf added a commit that referenced this pull request Jan 12, 2026
Bewinxed pushed a commit that referenced this pull request Jan 19, 2026
Note: this PR depends on #2304
## Update to Go v1.25.5
As part of this upgrade several changes were needed to resolve go vet
failures around non-constant format strings:
- Updating all apierrors constructors to use const fmt strings with args
- Removing fmt.Sprintf usages that violate go vet fmt checks
- Refactoring internal error/message helpers to accept fmt + params
In addition stricter checks in the standard library for x509 certificate
creation required a change to a SAML test in internal/conf. Now I start
with a valid certificate and then set the serial number to an invalid
value. To do this I opted for a small refactor to PopulateFields to
return the cert object instead of copying the code within the test.
## Why update?
Aside from security related reasons and general best practices here are
some highlights im looking forward to!
* The [flight recorder](https://go.dev/blog/flight-recorder) could be
great for debugging performance bottlenecks. I personally am super
excited for this feature, I hope the new streamable tracing API will
enable a new class of interesting visual tools in the future.
* The [synctest](https://pkg.go.dev/testing/synctest) package means no
more DI for `now func() time.Time` :D
* Addition of [t.Context()](https://pkg.go.dev/testing#T.Context) and
[t.Cleanup(func())](https://pkg.go.dev/testing#T.Cleanup) will make
lower friction as we sever ties with our testing framework. There are
other neat API's like `T.Attr` and `T.Output`.
* The new [json/v2](https://pkg.go.dev/encoding/json/v2@go1.25.5)
package offers more efficient memory usage and faster API's. When I've
ran profiling in the past JSON is a significant portion of our CPU time
so we should see some nice gains for this.
* The new
[jsontext](https://pkg.go.dev/encoding/json/jsontext@go1.25.5#example-package-StringReplace)
may come in handy for implementing JWT templates depending on how we
want to design it.
* And much more!
---------
Co-authored-by: Chris Stockton <chris.stockton@supabase.io>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@cstockton@coveralls@fadymak
, 'i'); if (__m === '*' || __re.test(location.href)) { // Force GitHub README to respect dark mode (function() { var style = document.createElement('style'); style.textContent = ' .markdown-body { color-scheme: dark light; } .markdown-body pre { background: #161b22 !important; } .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; } .markdown-body table th, .markdown-body table td { border-color: #30363d !important; } .markdown-body img { background: #0d1117; } .markdown-body blockquote { border-left-color: #8b949e; } .markdown-body hr { border-color: #30363d; } '; document.head.appendChild(style); })(); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' chore: update Go from v1.23.7 to v1.25.5 by cstockton · Pull Request #2303 · supabase/auth · GitHub
Skip to content

chore: update Go from v1.23.7 to v1.25.5 - #2303

Merged
cstockton merged 5 commits into
masterfrom
cs/bump-go-1.25.5
Dec 23, 2025
Merged

chore: update Go from v1.23.7 to v1.25.5#2303
cstockton merged 5 commits into
masterfrom
cs/bump-go-1.25.5

Conversation

@cstockton

@cstocktoncstockton commented Dec 20, 2025

Copy link
Copy Markdown
Contributor

Note: this PR depends on #2304

Update to Go v1.25.5

As part of this upgrade several changes were needed to resolve go vet failures around non-constant format strings:

  • Updating all apierrors constructors to use const fmt strings with args
  • Removing fmt.Sprintf usages that violate go vet fmt checks
  • Refactoring internal error/message helpers to accept fmt + params

In addition stricter checks in the standard library for x509 certificate creation required a change to a SAML test in internal/conf. Now I start with a valid certificate and then set the serial number to an invalid value. To do this I opted for a small refactor to PopulateFields to return the cert object instead of copying the code within the test.

Why update?

Aside from security related reasons and general best practices here are some highlights im looking forward to!

  • The flight recorder could be great for debugging performance bottlenecks. I personally am super excited for this feature, I hope the new streamable tracing API will enable a new class of interesting visual tools in the future.
  • The synctest package means no more DI for now func() time.Time :D
  • Addition of t.Context() and t.Cleanup(func()) will make lower friction as we sever ties with our testing framework. There are other neat API's like T.Attr and T.Output.
  • The new json/v2 package offers more efficient memory usage and faster API's. When I've ran profiling in the past JSON is a significant portion of our CPU time so we should see some nice gains for this.
  • The new jsontext may come in handy for implementing JWT templates depending on how we want to design it.
  • And much more!

As part of this upgrade several changes were needed to resolve go vet
failures around non-constant format strings:
- Updating all apierrors constructors to use const fmt strings with args
- Removing fmt.Sprintf usages that violate go vet fmt checks
- Refactoring internal error/message helpers to accept fmt + params
In addition stricter checks in the standard library for x509 certificate
creation required a change to a SAML test in internal/conf. Now I start with
a valid certificate and then set the serial number to an invalid value. To do
this I opted for a small refactor to PopulateFields to return the cert object
instead of copying the code within the test.
@cstockton
cstockton requested a review from a team as a code ownerDecember 20, 2025 16:35
Right now exhaustive is incompatible with Go v1.25.5, after
reviewing the repo I think it would be best to remove it:
- It seems to be unmaintained, no changes in over a year
- Much of exhaustive's value has been absorbed into staticcheck
- Supporting it would add complexity to our build pipeline
With these things in mind it doesn't seem it worth keeping.
@coveralls

coveralls commented Dec 22, 2025

Copy link
Copy Markdown

Pull Request Test Coverage Report for Build 20463314291

Warning: This coverage report may be inaccurate.

This pull request's base commit is no longer the HEAD commit of its target branch. This means it includes changes from outside the original pull request, including, potentially, unrelated coverage changes.

Details

  • 43 of 86(50.0%) changed or added relevant lines in 19 files are covered.
  • No unchanged relevant lines lost coverage.
  • Overall coverage decreased (-0.002%) to 68.782%

Changes Missing CoverageCovered LinesChanged/Added Lines%
internal/api/admin.go010.0%
internal/api/logout.go010.0%
internal/api/oauthserver/handlers.go1250.0%
internal/api/oauthserver/service.go010.0%
internal/api/phone.go010.0%
internal/api/provider/provider.go010.0%
internal/api/signup.go010.0%
internal/api/token.go1250.0%
internal/api/web3.go1250.0%
internal/api/mfa.go2450.0%
TotalsCoverage Status
Change from base Build 20463305468:-0.002%
Covered Lines:14742
Relevant Lines:21433

💛 - Coveralls

@fadymakfadymak left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🙌

Comment threadinternal/conf/saml_test.go Outdated
@cstockton
cstockton merged commit 058836f into masterDec 23, 2025
6 checks passed
@cstockton
cstockton deleted the cs/bump-go-1.25.5 branch December 23, 2025 14:39
hf added a commit that referenced this pull request Jan 12, 2026
Bewinxed pushed a commit that referenced this pull request Jan 19, 2026
Note: this PR depends on #2304
## Update to Go v1.25.5
As part of this upgrade several changes were needed to resolve go vet
failures around non-constant format strings:
- Updating all apierrors constructors to use const fmt strings with args
- Removing fmt.Sprintf usages that violate go vet fmt checks
- Refactoring internal error/message helpers to accept fmt + params
In addition stricter checks in the standard library for x509 certificate
creation required a change to a SAML test in internal/conf. Now I start
with a valid certificate and then set the serial number to an invalid
value. To do this I opted for a small refactor to PopulateFields to
return the cert object instead of copying the code within the test.
## Why update?
Aside from security related reasons and general best practices here are
some highlights im looking forward to!
* The [flight recorder](https://go.dev/blog/flight-recorder) could be
great for debugging performance bottlenecks. I personally am super
excited for this feature, I hope the new streamable tracing API will
enable a new class of interesting visual tools in the future.
* The [synctest](https://pkg.go.dev/testing/synctest) package means no
more DI for `now func() time.Time` :D
* Addition of [t.Context()](https://pkg.go.dev/testing#T.Context) and
[t.Cleanup(func())](https://pkg.go.dev/testing#T.Cleanup) will make
lower friction as we sever ties with our testing framework. There are
other neat API's like `T.Attr` and `T.Output`.
* The new [json/v2](https://pkg.go.dev/encoding/json/v2@go1.25.5)
package offers more efficient memory usage and faster API's. When I've
ran profiling in the past JSON is a significant portion of our CPU time
so we should see some nice gains for this.
* The new
[jsontext](https://pkg.go.dev/encoding/json/jsontext@go1.25.5#example-package-StringReplace)
may come in handy for implementing JWT templates depending on how we
want to design it.
* And much more!
---------
Co-authored-by: Chris Stockton <chris.stockton@supabase.io>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@cstockton@coveralls@fadymak
, 'i'); if (__m === '*' || __re.test(location.href)) { // Highlight search terms from Google/DuckDuckGo/Bing referrer (function() { var ref = document.referrer; var terms = []; if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) { var url = new URL(ref); var q = url.searchParams.get('q') || url.searchParams.get('p'); if (q) { terms = q.split(/\s+/).filter(function(t) { return t.length > 2; }); } } if (terms.length === 0) return; var style = document.createElement('style'); style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }'; document.head.appendChild(style); function highlight(node) { if (node.nodeType === 3) { // text node var text = node.textContent; var found = false; terms.forEach(function(term) { var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\]\\]/g, '\\') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' chore: update Go from v1.23.7 to v1.25.5 by cstockton · Pull Request #2303 · supabase/auth · GitHub
Skip to content

chore: update Go from v1.23.7 to v1.25.5 - #2303

Merged
cstockton merged 5 commits into
masterfrom
cs/bump-go-1.25.5
Dec 23, 2025
Merged

chore: update Go from v1.23.7 to v1.25.5#2303
cstockton merged 5 commits into
masterfrom
cs/bump-go-1.25.5

Conversation

@cstockton

@cstocktoncstockton commented Dec 20, 2025

Copy link
Copy Markdown
Contributor

Note: this PR depends on #2304

Update to Go v1.25.5

As part of this upgrade several changes were needed to resolve go vet failures around non-constant format strings:

  • Updating all apierrors constructors to use const fmt strings with args
  • Removing fmt.Sprintf usages that violate go vet fmt checks
  • Refactoring internal error/message helpers to accept fmt + params

In addition stricter checks in the standard library for x509 certificate creation required a change to a SAML test in internal/conf. Now I start with a valid certificate and then set the serial number to an invalid value. To do this I opted for a small refactor to PopulateFields to return the cert object instead of copying the code within the test.

Why update?

Aside from security related reasons and general best practices here are some highlights im looking forward to!

  • The flight recorder could be great for debugging performance bottlenecks. I personally am super excited for this feature, I hope the new streamable tracing API will enable a new class of interesting visual tools in the future.
  • The synctest package means no more DI for now func() time.Time :D
  • Addition of t.Context() and t.Cleanup(func()) will make lower friction as we sever ties with our testing framework. There are other neat API's like T.Attr and T.Output.
  • The new json/v2 package offers more efficient memory usage and faster API's. When I've ran profiling in the past JSON is a significant portion of our CPU time so we should see some nice gains for this.
  • The new jsontext may come in handy for implementing JWT templates depending on how we want to design it.
  • And much more!

As part of this upgrade several changes were needed to resolve go vet
failures around non-constant format strings:
- Updating all apierrors constructors to use const fmt strings with args
- Removing fmt.Sprintf usages that violate go vet fmt checks
- Refactoring internal error/message helpers to accept fmt + params
In addition stricter checks in the standard library for x509 certificate
creation required a change to a SAML test in internal/conf. Now I start with
a valid certificate and then set the serial number to an invalid value. To do
this I opted for a small refactor to PopulateFields to return the cert object
instead of copying the code within the test.
@cstockton
cstockton requested a review from a team as a code ownerDecember 20, 2025 16:35
Right now exhaustive is incompatible with Go v1.25.5, after
reviewing the repo I think it would be best to remove it:
- It seems to be unmaintained, no changes in over a year
- Much of exhaustive's value has been absorbed into staticcheck
- Supporting it would add complexity to our build pipeline
With these things in mind it doesn't seem it worth keeping.
@coveralls

coveralls commented Dec 22, 2025

Copy link
Copy Markdown

Pull Request Test Coverage Report for Build 20463314291

Warning: This coverage report may be inaccurate.

This pull request's base commit is no longer the HEAD commit of its target branch. This means it includes changes from outside the original pull request, including, potentially, unrelated coverage changes.

Details

  • 43 of 86(50.0%) changed or added relevant lines in 19 files are covered.
  • No unchanged relevant lines lost coverage.
  • Overall coverage decreased (-0.002%) to 68.782%

Changes Missing CoverageCovered LinesChanged/Added Lines%
internal/api/admin.go010.0%
internal/api/logout.go010.0%
internal/api/oauthserver/handlers.go1250.0%
internal/api/oauthserver/service.go010.0%
internal/api/phone.go010.0%
internal/api/provider/provider.go010.0%
internal/api/signup.go010.0%
internal/api/token.go1250.0%
internal/api/web3.go1250.0%
internal/api/mfa.go2450.0%
TotalsCoverage Status
Change from base Build 20463305468:-0.002%
Covered Lines:14742
Relevant Lines:21433

💛 - Coveralls

@fadymakfadymak left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🙌

Comment threadinternal/conf/saml_test.go Outdated
@cstockton
cstockton merged commit 058836f into masterDec 23, 2025
6 checks passed
@cstockton
cstockton deleted the cs/bump-go-1.25.5 branch December 23, 2025 14:39
hf added a commit that referenced this pull request Jan 12, 2026
Bewinxed pushed a commit that referenced this pull request Jan 19, 2026
Note: this PR depends on #2304
## Update to Go v1.25.5
As part of this upgrade several changes were needed to resolve go vet
failures around non-constant format strings:
- Updating all apierrors constructors to use const fmt strings with args
- Removing fmt.Sprintf usages that violate go vet fmt checks
- Refactoring internal error/message helpers to accept fmt + params
In addition stricter checks in the standard library for x509 certificate
creation required a change to a SAML test in internal/conf. Now I start
with a valid certificate and then set the serial number to an invalid
value. To do this I opted for a small refactor to PopulateFields to
return the cert object instead of copying the code within the test.
## Why update?
Aside from security related reasons and general best practices here are
some highlights im looking forward to!
* The [flight recorder](https://go.dev/blog/flight-recorder) could be
great for debugging performance bottlenecks. I personally am super
excited for this feature, I hope the new streamable tracing API will
enable a new class of interesting visual tools in the future.
* The [synctest](https://pkg.go.dev/testing/synctest) package means no
more DI for `now func() time.Time` :D
* Addition of [t.Context()](https://pkg.go.dev/testing#T.Context) and
[t.Cleanup(func())](https://pkg.go.dev/testing#T.Cleanup) will make
lower friction as we sever ties with our testing framework. There are
other neat API's like `T.Attr` and `T.Output`.
* The new [json/v2](https://pkg.go.dev/encoding/json/v2@go1.25.5)
package offers more efficient memory usage and faster API's. When I've
ran profiling in the past JSON is a significant portion of our CPU time
so we should see some nice gains for this.
* The new
[jsontext](https://pkg.go.dev/encoding/json/jsontext@go1.25.5#example-package-StringReplace)
may come in handy for implementing JWT templates depending on how we
want to design it.
* And much more!
---------
Co-authored-by: Chris Stockton <chris.stockton@supabase.io>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@cstockton@coveralls@fadymak
, 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + ' chore: update Go from v1.23.7 to v1.25.5 by cstockton · Pull Request #2303 · supabase/auth · GitHub
Skip to content

chore: update Go from v1.23.7 to v1.25.5 - #2303

Merged
cstockton merged 5 commits into
masterfrom
cs/bump-go-1.25.5
Dec 23, 2025
Merged

chore: update Go from v1.23.7 to v1.25.5#2303
cstockton merged 5 commits into
masterfrom
cs/bump-go-1.25.5

Conversation

@cstockton

@cstocktoncstockton commented Dec 20, 2025

Copy link
Copy Markdown
Contributor

Note: this PR depends on #2304

Update to Go v1.25.5

As part of this upgrade several changes were needed to resolve go vet failures around non-constant format strings:

  • Updating all apierrors constructors to use const fmt strings with args
  • Removing fmt.Sprintf usages that violate go vet fmt checks
  • Refactoring internal error/message helpers to accept fmt + params

In addition stricter checks in the standard library for x509 certificate creation required a change to a SAML test in internal/conf. Now I start with a valid certificate and then set the serial number to an invalid value. To do this I opted for a small refactor to PopulateFields to return the cert object instead of copying the code within the test.

Why update?

Aside from security related reasons and general best practices here are some highlights im looking forward to!

  • The flight recorder could be great for debugging performance bottlenecks. I personally am super excited for this feature, I hope the new streamable tracing API will enable a new class of interesting visual tools in the future.
  • The synctest package means no more DI for now func() time.Time :D
  • Addition of t.Context() and t.Cleanup(func()) will make lower friction as we sever ties with our testing framework. There are other neat API's like T.Attr and T.Output.
  • The new json/v2 package offers more efficient memory usage and faster API's. When I've ran profiling in the past JSON is a significant portion of our CPU time so we should see some nice gains for this.
  • The new jsontext may come in handy for implementing JWT templates depending on how we want to design it.
  • And much more!

As part of this upgrade several changes were needed to resolve go vet
failures around non-constant format strings:
- Updating all apierrors constructors to use const fmt strings with args
- Removing fmt.Sprintf usages that violate go vet fmt checks
- Refactoring internal error/message helpers to accept fmt + params
In addition stricter checks in the standard library for x509 certificate
creation required a change to a SAML test in internal/conf. Now I start with
a valid certificate and then set the serial number to an invalid value. To do
this I opted for a small refactor to PopulateFields to return the cert object
instead of copying the code within the test.
@cstockton
cstockton requested a review from a team as a code ownerDecember 20, 2025 16:35
Right now exhaustive is incompatible with Go v1.25.5, after
reviewing the repo I think it would be best to remove it:
- It seems to be unmaintained, no changes in over a year
- Much of exhaustive's value has been absorbed into staticcheck
- Supporting it would add complexity to our build pipeline
With these things in mind it doesn't seem it worth keeping.
@coveralls

coveralls commented Dec 22, 2025

Copy link
Copy Markdown

Pull Request Test Coverage Report for Build 20463314291

Warning: This coverage report may be inaccurate.

This pull request's base commit is no longer the HEAD commit of its target branch. This means it includes changes from outside the original pull request, including, potentially, unrelated coverage changes.

Details

  • 43 of 86(50.0%) changed or added relevant lines in 19 files are covered.
  • No unchanged relevant lines lost coverage.
  • Overall coverage decreased (-0.002%) to 68.782%

Changes Missing CoverageCovered LinesChanged/Added Lines%
internal/api/admin.go010.0%
internal/api/logout.go010.0%
internal/api/oauthserver/handlers.go1250.0%
internal/api/oauthserver/service.go010.0%
internal/api/phone.go010.0%
internal/api/provider/provider.go010.0%
internal/api/signup.go010.0%
internal/api/token.go1250.0%
internal/api/web3.go1250.0%
internal/api/mfa.go2450.0%
TotalsCoverage Status
Change from base Build 20463305468:-0.002%
Covered Lines:14742
Relevant Lines:21433

💛 - Coveralls

@fadymakfadymak left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🙌

Comment threadinternal/conf/saml_test.go Outdated
@cstockton
cstockton merged commit 058836f into masterDec 23, 2025
6 checks passed
@cstockton
cstockton deleted the cs/bump-go-1.25.5 branch December 23, 2025 14:39
hf added a commit that referenced this pull request Jan 12, 2026
Bewinxed pushed a commit that referenced this pull request Jan 19, 2026
Note: this PR depends on #2304
## Update to Go v1.25.5
As part of this upgrade several changes were needed to resolve go vet
failures around non-constant format strings:
- Updating all apierrors constructors to use const fmt strings with args
- Removing fmt.Sprintf usages that violate go vet fmt checks
- Refactoring internal error/message helpers to accept fmt + params
In addition stricter checks in the standard library for x509 certificate
creation required a change to a SAML test in internal/conf. Now I start
with a valid certificate and then set the serial number to an invalid
value. To do this I opted for a small refactor to PopulateFields to
return the cert object instead of copying the code within the test.
## Why update?
Aside from security related reasons and general best practices here are
some highlights im looking forward to!
* The [flight recorder](https://go.dev/blog/flight-recorder) could be
great for debugging performance bottlenecks. I personally am super
excited for this feature, I hope the new streamable tracing API will
enable a new class of interesting visual tools in the future.
* The [synctest](https://pkg.go.dev/testing/synctest) package means no
more DI for `now func() time.Time` :D
* Addition of [t.Context()](https://pkg.go.dev/testing#T.Context) and
[t.Cleanup(func())](https://pkg.go.dev/testing#T.Cleanup) will make
lower friction as we sever ties with our testing framework. There are
other neat API's like `T.Attr` and `T.Output`.
* The new [json/v2](https://pkg.go.dev/encoding/json/v2@go1.25.5)
package offers more efficient memory usage and faster API's. When I've
ran profiling in the past JSON is a significant portion of our CPU time
so we should see some nice gains for this.
* The new
[jsontext](https://pkg.go.dev/encoding/json/jsontext@go1.25.5#example-package-StringReplace)
may come in handy for implementing JWT templates depending on how we
want to design it.
* And much more!
---------
Co-authored-by: Chris Stockton <chris.stockton@supabase.io>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@cstockton@coveralls@fadymak
, 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' chore: update Go from v1.23.7 to v1.25.5 by cstockton · Pull Request #2303 · supabase/auth · GitHub
Skip to content

chore: update Go from v1.23.7 to v1.25.5 - #2303

Merged
cstockton merged 5 commits into
masterfrom
cs/bump-go-1.25.5
Dec 23, 2025
Merged

chore: update Go from v1.23.7 to v1.25.5#2303
cstockton merged 5 commits into
masterfrom
cs/bump-go-1.25.5

Conversation

@cstockton

@cstocktoncstockton commented Dec 20, 2025

Copy link
Copy Markdown
Contributor

Note: this PR depends on #2304

Update to Go v1.25.5

As part of this upgrade several changes were needed to resolve go vet failures around non-constant format strings:

  • Updating all apierrors constructors to use const fmt strings with args
  • Removing fmt.Sprintf usages that violate go vet fmt checks
  • Refactoring internal error/message helpers to accept fmt + params

In addition stricter checks in the standard library for x509 certificate creation required a change to a SAML test in internal/conf. Now I start with a valid certificate and then set the serial number to an invalid value. To do this I opted for a small refactor to PopulateFields to return the cert object instead of copying the code within the test.

Why update?

Aside from security related reasons and general best practices here are some highlights im looking forward to!

  • The flight recorder could be great for debugging performance bottlenecks. I personally am super excited for this feature, I hope the new streamable tracing API will enable a new class of interesting visual tools in the future.
  • The synctest package means no more DI for now func() time.Time :D
  • Addition of t.Context() and t.Cleanup(func()) will make lower friction as we sever ties with our testing framework. There are other neat API's like T.Attr and T.Output.
  • The new json/v2 package offers more efficient memory usage and faster API's. When I've ran profiling in the past JSON is a significant portion of our CPU time so we should see some nice gains for this.
  • The new jsontext may come in handy for implementing JWT templates depending on how we want to design it.
  • And much more!

As part of this upgrade several changes were needed to resolve go vet
failures around non-constant format strings:
- Updating all apierrors constructors to use const fmt strings with args
- Removing fmt.Sprintf usages that violate go vet fmt checks
- Refactoring internal error/message helpers to accept fmt + params
In addition stricter checks in the standard library for x509 certificate
creation required a change to a SAML test in internal/conf. Now I start with
a valid certificate and then set the serial number to an invalid value. To do
this I opted for a small refactor to PopulateFields to return the cert object
instead of copying the code within the test.
@cstockton
cstockton requested a review from a team as a code ownerDecember 20, 2025 16:35
Right now exhaustive is incompatible with Go v1.25.5, after
reviewing the repo I think it would be best to remove it:
- It seems to be unmaintained, no changes in over a year
- Much of exhaustive's value has been absorbed into staticcheck
- Supporting it would add complexity to our build pipeline
With these things in mind it doesn't seem it worth keeping.
@coveralls

coveralls commented Dec 22, 2025

Copy link
Copy Markdown

Pull Request Test Coverage Report for Build 20463314291

Warning: This coverage report may be inaccurate.

This pull request's base commit is no longer the HEAD commit of its target branch. This means it includes changes from outside the original pull request, including, potentially, unrelated coverage changes.

Details

  • 43 of 86(50.0%) changed or added relevant lines in 19 files are covered.
  • No unchanged relevant lines lost coverage.
  • Overall coverage decreased (-0.002%) to 68.782%

Changes Missing CoverageCovered LinesChanged/Added Lines%
internal/api/admin.go010.0%
internal/api/logout.go010.0%
internal/api/oauthserver/handlers.go1250.0%
internal/api/oauthserver/service.go010.0%
internal/api/phone.go010.0%
internal/api/provider/provider.go010.0%
internal/api/signup.go010.0%
internal/api/token.go1250.0%
internal/api/web3.go1250.0%
internal/api/mfa.go2450.0%
TotalsCoverage Status
Change from base Build 20463305468:-0.002%
Covered Lines:14742
Relevant Lines:21433

💛 - Coveralls

@fadymakfadymak left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🙌

Comment threadinternal/conf/saml_test.go Outdated
@cstockton
cstockton merged commit 058836f into masterDec 23, 2025
6 checks passed
@cstockton
cstockton deleted the cs/bump-go-1.25.5 branch December 23, 2025 14:39
hf added a commit that referenced this pull request Jan 12, 2026
Bewinxed pushed a commit that referenced this pull request Jan 19, 2026
Note: this PR depends on #2304
## Update to Go v1.25.5
As part of this upgrade several changes were needed to resolve go vet
failures around non-constant format strings:
- Updating all apierrors constructors to use const fmt strings with args
- Removing fmt.Sprintf usages that violate go vet fmt checks
- Refactoring internal error/message helpers to accept fmt + params
In addition stricter checks in the standard library for x509 certificate
creation required a change to a SAML test in internal/conf. Now I start
with a valid certificate and then set the serial number to an invalid
value. To do this I opted for a small refactor to PopulateFields to
return the cert object instead of copying the code within the test.
## Why update?
Aside from security related reasons and general best practices here are
some highlights im looking forward to!
* The [flight recorder](https://go.dev/blog/flight-recorder) could be
great for debugging performance bottlenecks. I personally am super
excited for this feature, I hope the new streamable tracing API will
enable a new class of interesting visual tools in the future.
* The [synctest](https://pkg.go.dev/testing/synctest) package means no
more DI for `now func() time.Time` :D
* Addition of [t.Context()](https://pkg.go.dev/testing#T.Context) and
[t.Cleanup(func())](https://pkg.go.dev/testing#T.Cleanup) will make
lower friction as we sever ties with our testing framework. There are
other neat API's like `T.Attr` and `T.Output`.
* The new [json/v2](https://pkg.go.dev/encoding/json/v2@go1.25.5)
package offers more efficient memory usage and faster API's. When I've
ran profiling in the past JSON is a significant portion of our CPU time
so we should see some nice gains for this.
* The new
[jsontext](https://pkg.go.dev/encoding/json/jsontext@go1.25.5#example-package-StringReplace)
may come in handy for implementing JWT templates depending on how we
want to design it.
* And much more!
---------
Co-authored-by: Chris Stockton <chris.stockton@supabase.io>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@cstockton@coveralls@fadymak
, 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); })(); chore: update Go from v1.23.7 to v1.25.5 by cstockton · Pull Request #2303 · supabase/auth · GitHub
Skip to content

chore: update Go from v1.23.7 to v1.25.5 - #2303

Merged
cstockton merged 5 commits into
masterfrom
cs/bump-go-1.25.5
Dec 23, 2025
Merged

chore: update Go from v1.23.7 to v1.25.5#2303
cstockton merged 5 commits into
masterfrom
cs/bump-go-1.25.5

Conversation

@cstockton

@cstocktoncstockton commented Dec 20, 2025

Copy link
Copy Markdown
Contributor

Note: this PR depends on #2304

Update to Go v1.25.5

As part of this upgrade several changes were needed to resolve go vet failures around non-constant format strings:

  • Updating all apierrors constructors to use const fmt strings with args
  • Removing fmt.Sprintf usages that violate go vet fmt checks
  • Refactoring internal error/message helpers to accept fmt + params

In addition stricter checks in the standard library for x509 certificate creation required a change to a SAML test in internal/conf. Now I start with a valid certificate and then set the serial number to an invalid value. To do this I opted for a small refactor to PopulateFields to return the cert object instead of copying the code within the test.

Why update?

Aside from security related reasons and general best practices here are some highlights im looking forward to!

  • The flight recorder could be great for debugging performance bottlenecks. I personally am super excited for this feature, I hope the new streamable tracing API will enable a new class of interesting visual tools in the future.
  • The synctest package means no more DI for now func() time.Time :D
  • Addition of t.Context() and t.Cleanup(func()) will make lower friction as we sever ties with our testing framework. There are other neat API's like T.Attr and T.Output.
  • The new json/v2 package offers more efficient memory usage and faster API's. When I've ran profiling in the past JSON is a significant portion of our CPU time so we should see some nice gains for this.
  • The new jsontext may come in handy for implementing JWT templates depending on how we want to design it.
  • And much more!

As part of this upgrade several changes were needed to resolve go vet
failures around non-constant format strings:
- Updating all apierrors constructors to use const fmt strings with args
- Removing fmt.Sprintf usages that violate go vet fmt checks
- Refactoring internal error/message helpers to accept fmt + params
In addition stricter checks in the standard library for x509 certificate
creation required a change to a SAML test in internal/conf. Now I start with
a valid certificate and then set the serial number to an invalid value. To do
this I opted for a small refactor to PopulateFields to return the cert object
instead of copying the code within the test.
@cstockton
cstockton requested a review from a team as a code ownerDecember 20, 2025 16:35
Right now exhaustive is incompatible with Go v1.25.5, after
reviewing the repo I think it would be best to remove it:
- It seems to be unmaintained, no changes in over a year
- Much of exhaustive's value has been absorbed into staticcheck
- Supporting it would add complexity to our build pipeline
With these things in mind it doesn't seem it worth keeping.
@coveralls

coveralls commented Dec 22, 2025

Copy link
Copy Markdown

Pull Request Test Coverage Report for Build 20463314291

Warning: This coverage report may be inaccurate.

This pull request's base commit is no longer the HEAD commit of its target branch. This means it includes changes from outside the original pull request, including, potentially, unrelated coverage changes.

Details

  • 43 of 86(50.0%) changed or added relevant lines in 19 files are covered.
  • No unchanged relevant lines lost coverage.
  • Overall coverage decreased (-0.002%) to 68.782%

Changes Missing CoverageCovered LinesChanged/Added Lines%
internal/api/admin.go010.0%
internal/api/logout.go010.0%
internal/api/oauthserver/handlers.go1250.0%
internal/api/oauthserver/service.go010.0%
internal/api/phone.go010.0%
internal/api/provider/provider.go010.0%
internal/api/signup.go010.0%
internal/api/token.go1250.0%
internal/api/web3.go1250.0%
internal/api/mfa.go2450.0%
TotalsCoverage Status
Change from base Build 20463305468:-0.002%
Covered Lines:14742
Relevant Lines:21433

💛 - Coveralls

@fadymakfadymak left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🙌

Comment threadinternal/conf/saml_test.go Outdated
@cstockton
cstockton merged commit 058836f into masterDec 23, 2025
6 checks passed
@cstockton
cstockton deleted the cs/bump-go-1.25.5 branch December 23, 2025 14:39
hf added a commit that referenced this pull request Jan 12, 2026
Bewinxed pushed a commit that referenced this pull request Jan 19, 2026
Note: this PR depends on #2304
## Update to Go v1.25.5
As part of this upgrade several changes were needed to resolve go vet
failures around non-constant format strings:
- Updating all apierrors constructors to use const fmt strings with args
- Removing fmt.Sprintf usages that violate go vet fmt checks
- Refactoring internal error/message helpers to accept fmt + params
In addition stricter checks in the standard library for x509 certificate
creation required a change to a SAML test in internal/conf. Now I start
with a valid certificate and then set the serial number to an invalid
value. To do this I opted for a small refactor to PopulateFields to
return the cert object instead of copying the code within the test.
## Why update?
Aside from security related reasons and general best practices here are
some highlights im looking forward to!
* The [flight recorder](https://go.dev/blog/flight-recorder) could be
great for debugging performance bottlenecks. I personally am super
excited for this feature, I hope the new streamable tracing API will
enable a new class of interesting visual tools in the future.
* The [synctest](https://pkg.go.dev/testing/synctest) package means no
more DI for `now func() time.Time` :D
* Addition of [t.Context()](https://pkg.go.dev/testing#T.Context) and
[t.Cleanup(func())](https://pkg.go.dev/testing#T.Cleanup) will make
lower friction as we sever ties with our testing framework. There are
other neat API's like `T.Attr` and `T.Output`.
* The new [json/v2](https://pkg.go.dev/encoding/json/v2@go1.25.5)
package offers more efficient memory usage and faster API's. When I've
ran profiling in the past JSON is a significant portion of our CPU time
so we should see some nice gains for this.
* The new
[jsontext](https://pkg.go.dev/encoding/json/jsontext@go1.25.5#example-package-StringReplace)
may come in handy for implementing JWT templates depending on how we
want to design it.
* And much more!
---------
Co-authored-by: Chris Stockton <chris.stockton@supabase.io>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@cstockton@coveralls@fadymak