Skip to content

chore: Sync upstream - #213

Closed
spiffcs wants to merge 13 commits into
hashicorp:mainfrom
anchore:sync-upstream
Closed

spiffcs wants to merge 13 commits into
hashicorp:mainfrom
anchore:sync-upstream

Conversation

@spiffcs

@spiffcs spiffcs commented Sep 15, 2026 •

Copy link
Copy Markdown

Description

Sync this fork with hashicorp/go-version picking up 93 upstream commits since the fork point (59da58c) while preserving Anchore commits.

We are unarchiving this repository and maintaining it as part of Anchore, so this merge establishes the baseline that future syncs build on. No contributed Anchore behavior changes in this PR.

Anchore changes preserved (none of them modified by this merge):

  • Constraints as [][]*Constraint, supporting || (or) constraints
  • the ^ (caret) and ~ (tilde) constraint operators
  • MarshalJSON / UnmarshalJSON on Version and Constraints
  • comparison operators do not apply prereleaseCheck, per semver spec item 11
  • comparePart ordering for empty prerelease parts
  • module path github.com/anchore/go-version, and README badges/links pointing at this fork

Upstream changes that needed adapting to our 2D Constraints type:

Upstream refactored constraint.go in ways that assume the flat Constraints []*Constraint, so three things were reconciled rather than taken verbatim:

  1. Upstream replaced the constraintOperators map (and its init()-built regexp) with a lazily-compiled getConstraintRegexp() and a switch in parseSingle. Our ^ and ~ operators were added to both, plus caret/tilde entries in the operator constants. Regexp alternation keeps ~> ahead of ~ so pessimistic constraints still parse correctly.
  2. Upstream added Constraints.Equals and sort.Interface on Constraints, both written against the flat type. These are now: constraintGroup (sorts the constraints inside one comma-separated conjunction), Constraints.sorted() (sorts the groups and their contents), and Constraints Len/Less/Swap (order the || groups). TestConstraint_sort calls sorted() and passes upstream's expectations unchanged.
  3. prereleaseCheck now uses upstream's new Version.equalSegments helper instead of reflect.DeepEqual on Segments64(), which drops the reflect import.

Notable upstream additions this brings in:

  • WithPrefix parsing option, for stripping a known release prefix before parsing
  • Version.Core(), returning just the MAJOR.MINOR.PATCH segments
  • MarshalText / UnmarshalText, implementing the encoding text interfaces
  • sql.Scanner / driver.Valuer, for reading and writing versions as SQL values
  • MustConstraints, the Constraints counterpart to the existing Must
  • correct comparison of numeric prerelease identifiers exceeding math.MaxInt64
  • a fix for String() on a zero-value Version, which previously printed empty rather than 0.0.0

Upstream repo tooling (Makefile, .copywrite.hcl, CODEOWNERS, go-tests.yml, copywrite.yml, CHANGELOG.md, CONTRIBUTING.md, this PR template) is taken exactly as upstream ships it, so the diff stays reviewable as a pure resync. Replacing it with Anchore's standard tooling like go-make, binny, bouncer, chronicle, the anchore/workflows reusable workflows, golangci.yaml will be a follow-up PR stacked on this branch.

To verify locally:

git fetch origin sync-upstream && git checkout sync-upstream
go build ./... && go test ./...

To confirm nothing of ours was reverted, diff the Anchore-owned surface against the pre-merge tip:

git diff main...sync-upstream -- constraint.go version.go

wagoodman-anchore and others added 13 commits July 1, 2020 08:48
…y enforce this) (#1)

Signed-off-by: Alex Goodman <alex.goodman@anchore.com>
This function was incorrectly comparing the segments of the two values and returning false if the segments were different

Signed-off-by: Zane Burstein <zane.burstein@anchore.com>
…than-equal

Remove prerelease check from less than equal
* upstream/main: (76 commits)
  correctly compare numeric prerelease values larger than int64 (hashicorp#212)
  docs: Add contributing guide and LLM PR template link. (hashicorp#209)
  Bump actions/checkout from 7.0.0 to 7.0.1 in the github-actions-backward-compatible group across 1 directory (hashicorp#203)
  fix: empty Version.String() prints 0.0.0 (hashicorp#201)
  Bump actions/setup-go from 6.5.0 to 7.0.0 in the github-actions-breaking group (hashicorp#200)
  Bump golangci/golangci-lint-action from 9.2.1 to 9.3.0 in the github-actions-backward-compatible group (hashicorp#199)
  Bump the github-actions-breaking group with 2 updates (hashicorp#197)
  Bump actions/setup-go from 6.4.0 to 6.5.0 in the github-actions-backward-compatible group (hashicorp#198)
  ci: Add copywrite workflow and makefile for easier local dev. (hashicorp#196)
  [COMPLIANCE] Add/Update Copyright Headers (hashicorp#191)
  Bump the github-actions-backward-compatible group across 1 directory with 4 updates (hashicorp#194)
  Remove ip-compliance team from CODEOWNERS, transfer ownership to nomad-eng
  Add explicit go version to go.mod
  Update workflow to trigger on push events to main branch (hashicorp#188)
  Update CHANGELOG for version 1.9.0 (hashicorp#187)
  Bump the github-actions-backward-compatible group across 1 directory with 2 updates (hashicorp#186)
  Bump actions/upload-artifact from 6.0.0 to 7.0.0 in the github-actions-breaking group across 1 directory (hashicorp#183)
  Update GitHub Actions to trigger on pull requests and update go version (hashicorp#185)
  Support parsing versions with custom prefixes via opt-in option (hashicorp#79)
  Bump the github-actions-backward-compatible group with 3 updates
  ...

Signed-off-by: Christopher Phillips <32073428+spiffcs@users.noreply.github.com>
@spiffcs
spiffcs requested a review from a team as a code owner September 15, 2026 06:30
@hashicorp-cla-app

hashicorp-cla-app Bot commented Sep 15, 2026 •

Copy link
Copy Markdown

CLA assistant check

Thank you for your submission! We require that all contributors sign our Contributor License Agreement ("CLA") before we can accept the contribution. Read and sign the agreement

Learn more about why HashiCorp requires a CLA and what the CLA includes


0 out of 3 committers have signed the CLA.

  • spiffcs
  • wagoodman
  • zburstein

Have you signed the CLA already but the status is still pending? Recheck it.

@hashicorp-cla-app

Copy link
Copy Markdown

CLA assistant check

Thank you for your submission! We require that all contributors sign our Contributor License Agreement ("CLA") before we can accept the contribution. Read and sign the agreement

Learn more about why HashiCorp requires a CLA and what the CLA includes


0 out of 3 committers have signed the CLA.

  • wagoodman
  • spiffcs
  • zburstein

Have you signed the CLA already but the status is still pending? Recheck it.

@spiffcs spiffcs closed this Sep 15, 2026
@spiffcs

spiffcs commented Sep 15, 2026

Copy link
Copy Markdown
Author

Apologies, this was meant to target our fork of go-version. Closing.

@wagoodman
wagoodman deleted the sync-upstream branch September 16, 2026 18:48
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants