Skip to content

chore(deps): update module github.com/goccy/go-json to v0.11.1 - #28

Open
red-hat-konflux[bot] wants to merge 1 commit into
mainfrom
konflux/mintmaker/main/github.com-goccy-go-json-0.x
Open

red-hat-konflux[bot] wants to merge 1 commit into
mainfrom
konflux/mintmaker/main/github.com-goccy-go-json-0.x

Conversation

@red-hat-konflux

@red-hat-konflux red-hat-konflux Bot commented Nov 6, 2025 •

Copy link
Copy Markdown

This PR contains the following updates:

Package Change Age Confidence
github.com/goccy/go-json v0.10.5 → v0.11.1 age confidence

Warning

Some dependencies could not be looked up. Check the warning logs for more information.


Release Notes

goccy/go-json (github.com/goccy/go-json)

v0.11.1

Compare Source

What's Changed

  • Handle the reported pull requests: omitzero, nil TextMarshaler pointers, the generated-code marker and a godoc fix by @​goccy in #​671
  • Encoder: jump to one code of a large struct which is a value in many places by @​goccy in #​672

Full Changelog: goccy/go-json@v0.11.0...v0.11.1

v0.11.0

Compare Source

Highlights

  • Compatible with encoding/json of the Go version in use: values are decoded and encoded, and errors are reported (their types, messages and offsets), as encoding/json does, including Go 1.27, whose encoding/json is built on encoding/json/v2. Many reported compatibility issues are fixed.
  • Much faster: with the same behavior as encoding/json ( a live heap of 64 MB, geometric mean over the payloads of the report ), go-json decodes about 4.2–4.4x and encodes about 2.7–2.8x as fast as encoding/json, on amd64 and arm64 ( the results of this release are at https://goccy.github.io/go-json/ ).
  • A benchmark report of the JSON libraries of Go, measured on GitHub Actions for every change and published at https://goccy.github.io/go-json/: the libraries are compared by category of behavior ( the behavior of encoding/json, of encoding/json/v2, without HTML escaping, key sorting and string copying, and every library at its fastest ), which every run checks, and the result files are attested with GitHub Artifact Attestations.
  • No more go:linkname: go-json no longer links to the internals of the runtime or of reflect, so it builds with the restrictions of newer Go versions on go:linkname.

New APIs

  • MarshalOf[T]: encodes a value of type T without copying it to the heap ( #​632 ).
  • UnmarshalOf[T]: decodes into a *T which may stay on the stack of the caller, without an allocation for the argument ( #​658 ).
  • OptimizeFieldOrder(): lets the encoder order the fields of a struct as it encodes them fastest, when the order of the keys doesn't matter ( #​646 ).
  • DecodeNoCopyString(): lets the decoded strings refer to the input instead of copying them ( #​658 ).

Changes of behavior

These follow encoding/json, and may change what a program which relied on the previous behavior gets:

  • The values of the keys which match no field are validated: invalid JSON anywhere in the input is a syntax error, as with encoding/json ( #​664 ).
  • Syntax errors and type errors are reported as encoding/json of the Go version reports them: their types, messages and offsets ( #​661, #​664 ).
  • A decoded string is a copy of its bytes, and doesn't keep the input alive; short strings share buffers of up to 16 KB ( #​658 ). Use DecodeNoCopyString() to refer to the input instead.
  • The elements of an array are decoded into the existing elements of a slice, including the ones after its length within its capacity, as encoding/json does ( #​666 ).
  • MarshalNoEscape and UnmarshalNoEscape are deprecated: use Marshal and UnmarshalOf ( #​631, #​658 ).
  • DecodeFieldPriorityFirstWin() no longer allocates for each object, and is as fast as the default decode or faster ( #​668 ).

What's Changed

Decoder
  • Decoder: decode a stream by the byte slice decoders, compare the decoder with sonic by @​goccy in #​656
  • Decoder: allocate and assign through reflect instead of go:linkname by @​goccy in #​657
  • Decoder: UnmarshalOf, copies of the decoded strings, recent decoders of a context by @​goccy in #​658
  • Decoder and encoder: struct keys by a table, numbers in one pass, strings by AVX2, benchmarks of real APIs by @​goccy in #​659
  • Decoder: allocate the value of a pointer by new of its kind by @​goccy in #​660
  • Decoder: report the type errors as encoding/json of the Go version does by @​goccy in #​661
  • Decoder: decode a value of interface{} without reflect by @​goccy in #​662
  • Decoder: decode the values held by interface values by their type, as encoding/json does by @​goccy in #​663
  • Decoder: fix the reported decoder issues, as encoding/json of the Go version decodes by @​goccy in #​664
  • Decoder: narrow the gaps to sonic on escaped strings, and compare with sonic as a real program runs by @​goccy in #​665
  • Decoder: narrow the gaps to sonic at its fastest: slices, maps, long escaped strings and interface values by @​goccy in #​666
  • Decoder: remember the decoded fields of DecodeFieldPriorityFirstWin in a bit set by @​goccy in #​668
  • Decoder: narrow the gap to sonic on interface{} values and string fields by @​goccy in #​670
Encoder
  • Remove go:linkname to reflect.(*rtype) methods by @​goccy in #​624
  • Remove runtime.Type and go:linkname to reflect.ifaceIndir by @​goccy in #​625
  • Always give the address of the value to the encoder VM by @​goccy in #​626
  • Fix the encoding of recursive structs and omitempty with a pointer receiver marshaler by @​goccy in #​628
  • Fix the indent of deep recursive structs, marshalers of empty values and embedded structs by @​goccy in #​630
  • Carry the values of the encoder VM as unsafe.Pointer and remove KeepRefs by @​goccy in #​631
  • Add MarshalOf, which encodes a value without copying it to the heap by @​goccy in #​632
  • Speed up the encoder: a hash table for the cache of a type, a lighter VM and a faster AppendString by @​goccy in #​634
  • Encode a scalar held by an interface value without a frame by @​goccy in #​635
  • Scan a string for a byte to escape by SIMD by @​goccy in #​637
  • Call the method of a marshaler directly by its code by @​goccy in #​638
  • Copy the output of a marshaler as it is if it is compact and valid by @​goccy in #​639
  • Encoder: inline the helpers of the VM, and shorter paths for strings and maps by @​goccy in #​640
  • Write the key of a map of strings by the opcode of the map entry by @​goccy in #​641
  • Encoder: encode fields of the same kind in a row without a dispatch between them by @​goccy in #​643
  • Encode a list of values of a recursive type in one frame by @​goccy in #​645
  • Add the option to let the encoder order the fields of a struct by @​goccy in #​646
  • Read the entries of a map without a linkname of the runtime by @​goccy in #​647
  • Encoder: compare the keys of a map by their first bytes as a number first by @​goccy in #​649
  • Encoder: cheaper frames of interface values by @​goccy in #​650
  • Encoder: write the scalar entries of an unordered map of interface values as the map is read by @​goccy in #​651
  • Write null for an interface value which holds nothing without a call by @​goccy in #​652
  • Encoder: encode a field of interface{} by an opcode of its own by @​goccy in #​653
  • Test the cases of the reported issues of the encoder by @​goccy in #​655
Other fixes
Benchmarks, documents and CI
  • Fix CI failures on master caused by outdated Go versions by @​goccy in #​594
  • Add bench-check task to fail CI on performance degradation by @​goccy in #​623
  • Judge the benchmarks by the mean and by the fastest results by @​goccy in #​629
  • Benchmarks: add the benchmarks of sonic's encoder, with go-json beside it by @​goccy in #​648
  • Modernize the code: any, unsafe.Add, slices.Contains, min, max, bytes.Cut by @​goccy in #​654
  • Publish a benchmark report of the JSON libraries by category of behavior, describe the decoder as it is now in the README, and run no CI for documents alone by @​goccy in #​667
  • Benchmarks: color the bars of the summary by library by @​goccy in #​669

New Contributors

Full Changelog: goccy/go-json@v0.10.6...v0.11.0

v0.10.6: 0.10.6

Compare Source

What's Changed

New Contributors

Full Changelog: goccy/go-json@v0.10.5...v0.10.6


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

To execute skipped test pipelines write comment /ok-to-test.


Documentation

Find out how to configure dependency updates in MintMaker documentation or see all available configuration options in Renovate documentation.

@red-hat-konflux red-hat-konflux Bot changed the title chore(deps): update module github.com/goccy/go-json to v0.10.5 chore(deps): update module github.com/goccy/go-json to v0.10.5 - autoclosed Nov 8, 2025
@red-hat-konflux red-hat-konflux Bot closed this Nov 8, 2025
@red-hat-konflux
red-hat-konflux Bot deleted the konflux/mintmaker/main/github.com-goccy-go-json-0.x branch November 8, 2025 00:55
@red-hat-konflux red-hat-konflux Bot changed the title chore(deps): update module github.com/goccy/go-json to v0.10.5 - autoclosed chore(deps): update module github.com/goccy/go-json to v0.10.5 Nov 8, 2025
@red-hat-konflux red-hat-konflux Bot reopened this Nov 8, 2025
@red-hat-konflux
red-hat-konflux Bot force-pushed the konflux/mintmaker/main/github.com-goccy-go-json-0.x branch from 65accc9 to b5ab3af Compare November 8, 2025 04:33
@red-hat-konflux

red-hat-konflux Bot commented Nov 8, 2025 •

Copy link
Copy Markdown
Author

⚠️ Artifact update problem

Renovate failed to update an artifact related to this branch. You probably do not want to merge this PR as-is.

♻ Renovate will retry this branch, including artifacts, only when one of the following happens:

  • any of the package files in this branch needs updating, or
  • the branch becomes conflicted, or
  • you click the rebase/retry checkbox if found above, or
  • you rename this PR's title to start with "rebase!" to trigger it manually

The artifact failure details are included below:

File name: backend/go.sum
Command failed: go get -t ./...
go: downloading github.com/goccy/go-json v0.11.1
go: github.com/apache/incubator-devlake/helpers/unithelper imports
	github.com/apache/incubator-devlake/mocks/core/context: cannot find module providing package github.com/apache/incubator-devlake/mocks/core/context
go: github.com/apache/incubator-devlake/helpers/unithelper imports
	github.com/apache/incubator-devlake/mocks/core/dal: cannot find module providing package github.com/apache/incubator-devlake/mocks/core/dal
go: github.com/apache/incubator-devlake/helpers/unithelper imports
	github.com/apache/incubator-devlake/mocks/core/log: cannot find module providing package github.com/apache/incubator-devlake/mocks/core/log
go: github.com/apache/incubator-devlake/helpers/unithelper imports
	github.com/apache/incubator-devlake/mocks/core/plugin: cannot find module providing package github.com/apache/incubator-devlake/mocks/core/plugin
go: github.com/apache/incubator-devlake/helpers/pluginhelper/api tested by
	github.com/apache/incubator-devlake/helpers/pluginhelper/api.test imports
	github.com/apache/incubator-devlake/mocks/helpers/pluginhelper/api: cannot find module providing package github.com/apache/incubator-devlake/mocks/helpers/pluginhelper/api
go: module github.com/aws/aws-sdk-go is deprecated: aws-sdk-go is deprecated. Use aws-sdk-go-v2.

@red-hat-konflux red-hat-konflux Bot changed the title chore(deps): update module github.com/goccy/go-json to v0.10.5 chore(deps): update module github.com/goccy/go-json to v0.10.5 - autoclosed Dec 8, 2025
@red-hat-konflux red-hat-konflux Bot closed this Dec 8, 2025
@red-hat-konflux red-hat-konflux Bot changed the title chore(deps): update module github.com/goccy/go-json to v0.10.5 - autoclosed chore(deps): update module github.com/goccy/go-json to v0.10.5 Dec 9, 2025
@red-hat-konflux red-hat-konflux Bot reopened this Dec 9, 2025
@red-hat-konflux
red-hat-konflux Bot force-pushed the konflux/mintmaker/main/github.com-goccy-go-json-0.x branch from 600d889 to b5ab3af Compare December 9, 2025 01:10
@snyk-io

snyk-io Bot commented Dec 9, 2025 •

Copy link
Copy Markdown

✅ Snyk checks have passed. No issues have been found so far.

Status Scan Engine Critical High Medium Low Total (0)
✅ Open Source Security 0 0 0 0 0 issues
✅ Licenses 0 0 0 0 0 issues
✅ Code Security 0 0 0 0 0 issues

💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse.

@red-hat-konflux red-hat-konflux Bot changed the title chore(deps): update module github.com/goccy/go-json to v0.10.5 chore(deps): update module github.com/goccy/go-json to v0.10.5 - autoclosed Dec 12, 2025
@red-hat-konflux red-hat-konflux Bot closed this Dec 12, 2025
@red-hat-konflux red-hat-konflux Bot changed the title chore(deps): update module github.com/goccy/go-json to v0.10.5 - autoclosed chore(deps): update module github.com/goccy/go-json to v0.10.5 Dec 12, 2025
@red-hat-konflux red-hat-konflux Bot reopened this Dec 12, 2025
@red-hat-konflux
red-hat-konflux Bot force-pushed the konflux/mintmaker/main/github.com-goccy-go-json-0.x branch from cc3cef0 to b5ab3af Compare December 12, 2025 13:10
@red-hat-konflux red-hat-konflux Bot changed the title chore(deps): update module github.com/goccy/go-json to v0.10.5 chore(deps): update module github.com/goccy/go-json to v0.10.5 - autoclosed Dec 13, 2025
@red-hat-konflux red-hat-konflux Bot closed this Dec 13, 2025
@red-hat-konflux red-hat-konflux Bot changed the title chore(deps): update module github.com/goccy/go-json to v0.10.5 - autoclosed chore(deps): update module github.com/goccy/go-json to v0.10.5 Dec 13, 2025
@red-hat-konflux red-hat-konflux Bot reopened this Dec 13, 2025
@red-hat-konflux
red-hat-konflux Bot force-pushed the konflux/mintmaker/main/github.com-goccy-go-json-0.x branch from 87cc841 to b5ab3af Compare December 13, 2025 10:19
@red-hat-konflux red-hat-konflux Bot changed the title chore(deps): update module github.com/goccy/go-json to v0.10.5 chore(deps): update module github.com/goccy/go-json to v0.10.5 - autoclosed Dec 13, 2025
@red-hat-konflux red-hat-konflux Bot closed this Dec 13, 2025
@red-hat-konflux red-hat-konflux Bot changed the title chore(deps): update module github.com/goccy/go-json to v0.10.5 - autoclosed chore(deps): update module github.com/goccy/go-json to v0.10.5 Dec 13, 2025
@red-hat-konflux red-hat-konflux Bot reopened this Dec 13, 2025
@red-hat-konflux
red-hat-konflux Bot force-pushed the konflux/mintmaker/main/github.com-goccy-go-json-0.x branch from 30c978e to b5ab3af Compare December 13, 2025 21:17
@red-hat-konflux red-hat-konflux Bot changed the title chore(deps): update module github.com/goccy/go-json to v0.10.5 chore(deps): update module github.com/goccy/go-json to v0.10.5 - autoclosed Dec 25, 2025
@red-hat-konflux red-hat-konflux Bot closed this Dec 25, 2025
@red-hat-konflux
red-hat-konflux Bot force-pushed the konflux/mintmaker/main/github.com-goccy-go-json-0.x branch from 437ff8b to b5ab3af Compare January 9, 2026 17:08
@red-hat-konflux red-hat-konflux Bot changed the title chore(deps): update module github.com/goccy/go-json to v0.10.5 chore(deps): update module github.com/goccy/go-json to v0.10.5 - autoclosed Jan 10, 2026
@red-hat-konflux red-hat-konflux Bot closed this Jan 10, 2026
@red-hat-konflux red-hat-konflux Bot changed the title chore(deps): update module github.com/goccy/go-json to v0.10.5 - autoclosed chore(deps): update module github.com/goccy/go-json to v0.10.5 Jan 10, 2026
@red-hat-konflux red-hat-konflux Bot reopened this Jan 10, 2026
@red-hat-konflux
red-hat-konflux Bot force-pushed the konflux/mintmaker/main/github.com-goccy-go-json-0.x branch from 90f64ea to b5ab3af Compare January 10, 2026 21:11
@red-hat-konflux red-hat-konflux Bot changed the title chore(deps): update module github.com/goccy/go-json to v0.10.5 chore(deps): update module github.com/goccy/go-json to v0.10.5 - autoclosed Jan 11, 2026
@red-hat-konflux red-hat-konflux Bot closed this Jan 11, 2026
@red-hat-konflux red-hat-konflux Bot changed the title chore(deps): update module github.com/goccy/go-json to v0.10.5 - autoclosed chore(deps): update module github.com/goccy/go-json to v0.10.5 Jan 11, 2026
@red-hat-konflux red-hat-konflux Bot reopened this Jan 11, 2026
@red-hat-konflux
red-hat-konflux Bot force-pushed the konflux/mintmaker/main/github.com-goccy-go-json-0.x branch from 0956b3a to b5ab3af Compare January 11, 2026 09:08
@red-hat-konflux
red-hat-konflux Bot force-pushed the konflux/mintmaker/main/github.com-goccy-go-json-0.x branch from b5ab3af to 967a329 Compare February 12, 2026 21:16
@red-hat-konflux
red-hat-konflux Bot force-pushed the konflux/mintmaker/main/github.com-goccy-go-json-0.x branch from 967a329 to 1adaea9 Compare March 12, 2026 14:33
@red-hat-konflux red-hat-konflux Bot changed the title chore(deps): update module github.com/goccy/go-json to v0.10.5 chore(deps): update module github.com/goccy/go-json to v0.10.6 Mar 12, 2026
@red-hat-konflux red-hat-konflux Bot changed the title chore(deps): update module github.com/goccy/go-json to v0.10.6 chore(deps): update module github.com/goccy/go-json to v0.10.6 - autoclosed Mar 15, 2026
@fullsend-ai-review

fullsend-ai-review Bot commented Jun 25, 2026 •

Copy link
Copy Markdown

🤖 Finished Review · ✅ Success · Started 10:15 PM UTC · Completed 10:21 PM UTC
Commit: ec21706 · View workflow run →

@fullsend-ai-review

fullsend-ai-review Bot commented Jun 25, 2026 •

Copy link
Copy Markdown

Looks good to me

Previous run

Looks good to me

Previous run (2)

Review — PR #28

Verdict: ✅ Approve

Summary

Automated patch version bump of an indirect dependency: github.com/goccy/go-json v0.10.5 → v0.10.6 in backend/go.mod.

The upstream v0.10.6 release contains a single bug fix — resolving a panic on embedded structs with recursive definitions (goccy/go-json#483). This is a safe, minimal patch bump.

Dimensions

Dimension Result Notes
Correctness ✅ Pass Patch version bump of indirect dep; no logic changes in this repo
Security ✅ Pass No security implications — JSON parsing library bug fix
Intent & coherence ✅ Pass Automated MintMaker dependency update, properly scoped
Style/conventions ✅ Pass Standard go.mod format
Documentation ✅ Pass No documentation changes needed
Cross-repo contracts ✅ Pass No API or schema changes

Notes

  • The PR only updates go.mod; go.sum will be updated when go mod tidy runs (standard behavior for MintMaker/Renovate bots).
  • The upstream change is a targeted panic fix with no breaking changes, consistent with a patch version bump.
Previous run (3)

Looks good to me

Previous run (4)

Review

Findings

High

  • [error handling gaps] backend/go.sum — The PR updates github.com/goccy/go-json from v0.10.2 to v0.10.6 in go.mod, but go.sum is not included in the changed files. The go.sum file contains only v0.10.2 checksum entries. Without the corresponding v0.10.6 checksum entries in go.sum, go build will fail with a missing checksum error, making this change non-buildable as submitted.
    Remediation: Run go mod tidy inside the backend/ directory and commit the resulting go.sum changes alongside go.mod.

fullsend-ai-review[bot]

This comment was marked as outdated.

@fullsend-ai-retro

fullsend-ai-retro Bot commented Jul 5, 2026 •

Copy link
Copy Markdown

🤖 Finished Retro · ✅ Success · Started 1:54 AM UTC · Completed 2:00 AM UTC
Commit: ec21706 · View workflow run →

@fullsend-ai-retro

Copy link
Copy Markdown

Retro: PR #28 — Autoclosed Renovate dependency bump

What happened: PR #28 was an automated Renovate bot PR updating github.com/goccy/go-json from v0.10.2 to v0.10.6. It only modified go.mod without updating go.sum, which Renovate itself flagged as an artifact failure on 2025-11-08. The PR sat untouched for ~8 months with zero human engagement. On 2026-06-25, the fullsend review agent ran (review run 28203771680) and correctly identified the missing go.sum checksums as a HIGH finding — but this was redundant with Renovate's own warning from 7 months earlier. The PR was autoclosed on 2026-07-05, triggering this retro.

Assessment: The review agent's finding was technically correct, but the entire review cycle was wasted effort — the PR was abandoned, the issue was already known, and no human was ever going to act on it. The retro dispatch on the autoclosed bot PR is similarly low-value.

All improvement areas are already tracked upstream:

  • #1371 — Skip review dispatch for bot-authored PRs
  • #1406 — Review agent should weigh bot warning comments on dependency PRs
  • #2461 — Skip retro dispatch for autoclosed bot-authored PRs
  • #2586 — Review agent should recommend closing unfixable dependency-bot PRs
  • #2863 — Add stale bot PR detection to auto-close PRs with prolonged CI failure
  • #664 — Incorporate existing human and bot reviews into assessment

No new proposals needed — existing issues comprehensively cover the improvements this workflow surfaces. Prioritizing apache#1371 and apache#2461 would eliminate the most waste for this class of PR.

@fullsend-ai-review

fullsend-ai-review Bot commented Jul 5, 2026 •

Copy link
Copy Markdown

🤖 Finished Review · ✅ Success · Started 9:41 AM UTC · Completed 9:45 AM UTC
Commit: ec21706 · View workflow run →

fullsend-ai-review[bot]

This comment was marked as outdated.

@fullsend-ai-review

fullsend-ai-review Bot commented Jul 16, 2026 •

Copy link
Copy Markdown

🤖 Finished Review · ✅ Success · Started 8:35 PM UTC · Completed 8:38 PM UTC
Commit: 14477fe · View workflow run →

fullsend-ai-review[bot]

This comment was marked as outdated.

@fullsend-ai-review

fullsend-ai-review Bot commented Aug 3, 2026 •

Copy link
Copy Markdown

🤖 Finished Review · ✅ Success · Started 5:04 PM UTC · Completed 5:10 PM UTC
Commit: 701e62a · View workflow run →

fullsend-ai-review[bot]

This comment was marked as outdated.

Signed-off-by: red-hat-konflux <126015336+red-hat-konflux[bot]@users.noreply.github.com>
@fullsend-ai-review

fullsend-ai-review Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

🤖 Finished Review · ✅ Success · Started 2:00 AM UTC · Completed 2:11 AM UTC

Commit: 83a79c0 · View workflow run →

Runtime: claude · Model: opus → claude-opus-4-6 · Effort: high · Cost: $1.90

@fullsend-ai-review

Copy link
Copy Markdown

Risk Assessment: low (1/5)

Details

Bot-authored single-file (go.mod) indirect dependency bump of 2 lines with no linked issue; Tier 1 composite 1.25 and Tier 2 composite 1.71 yield a weighted score of 0.62×1.25 + 0.38×1.71 = 1.43 → 1 (low), consistent with a routine automated dependency update.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

ready-for-merge All reviewers approved — ready to merge risk/low PR risk: low

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants