Closed mohammed90 closed 1 month ago
Wait but I thought we weren't supposed to upgrade things unless we really needed to :face_with_diagonal_mouth:
This is good at least for the last point:
The go command is more careful about keeping checksums of go.mod files in the go.sum file.
Notice how it cleaned up the go.sum file. Go 1.21 isn't a stretch because it's not EOL by the Go team.
So we're good to upgrade the Go version? That doesn't affect Caddy builds?
Yes, Caddy requires go 1.21 minimum anyways
@mohammed90 Since merging this, my inbox is flooded with bogus vuln notifications:
(Yeah, we're definitely not vulnerable to SQL injection.)
These tools need to go somewhere to die.
Dependabot is 🗑️ 🔥
You can dismiss them as "Vulnerable code is not actually used". Just shows how stupid those scanners are. The dep list didn't change, but somehow it was parsing the dep list differently.
Hello,
Should I rebuild my Caddy Webdav with this commit? Any new bug fix in terms of Webdav features?
Should I rebuild my Caddy Webdav with this commit? Any new bug fix in terms of Webdav features?
Just build with this commit. I don't know if Matt is planning on adding any features in the near future.
Yeah, no immediate plans. As Mohammed said you can build with the latest commit and get the benefits. (I recommend always using the latest Go version.)
With Go 1.21, the Go module behavior brings in:
Source