Found by the build machine failing on its own build, minutes after the bus work merged:
go: go.mod requires go >= 1.26.0 (running go 1.25.14; GOTOOLCHAIN=local)
nats.go v1.54.0 declares go >= 1.26, so the directive is 1.26.0 and go mod tidy will not leave it at 1.25 — I checked, because a stray toolchain rewrite was the likelier explanation and it isn't this one. The base image is pinned by digest at 1.25.14-alpine, so nothing in this repository compiles against it.
Moved to 1.26.8-alpine, by digest, same flavour. Still a digest: the reason for pinning is that the compiler cannot change underneath a build, and that holds one version along.
builder and route-proxy carry the same pin for the same reason — they compile this repository's code from its context — and move with it in mesh-catalog.
This blocks every Go build in the mesh, so it wants to go in before anything else is built.
Found by the build machine failing on its own build, minutes after the bus work merged:
```
go: go.mod requires go >= 1.26.0 (running go 1.25.14; GOTOOLCHAIN=local)
```
`nats.go v1.54.0` declares `go >= 1.26`, so the directive is 1.26.0 and `go mod tidy` will not leave it at 1.25 — I checked, because a stray toolchain rewrite was the likelier explanation and it isn't this one. The base image is pinned by digest at `1.25.14-alpine`, so nothing in this repository compiles against it.
Moved to `1.26.8-alpine`, by digest, same flavour. Still a digest: the reason for pinning is that the compiler cannot change underneath a build, and that holds one version along.
`builder` and `route-proxy` carry the same pin for the same reason — they compile this repository's code from its context — and move with it in mesh-catalog.
This blocks every Go build in the mesh, so it wants to go in before anything else is built.
`nats.go v1.54.0` declares `go >= 1.26`, so `go mod tidy` puts the directive at
1.26.0 and will not leave it at 1.25. The base image is pinned by digest at
1.25.14-alpine, so nothing in this repository compiles against it — caught when the
build machine's own build failed with "go.mod requires go >= 1.26.0 (running go
1.25.14)".
Moved to 1.26.8-alpine by digest, same flavour as before. The pin stays a digest:
the point of pinning is that the compiler does not change underneath a build, and
that is still true one version along.
Two other manifests carry the same pin for the same reason — they compile this
repository's code — and move with it in the catalogue.
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Found by the build machine failing on its own build, minutes after the bus work merged:
nats.go v1.54.0declaresgo >= 1.26, so the directive is 1.26.0 andgo mod tidywill not leave it at 1.25 — I checked, because a stray toolchain rewrite was the likelier explanation and it isn't this one. The base image is pinned by digest at1.25.14-alpine, so nothing in this repository compiles against it.Moved to
1.26.8-alpine, by digest, same flavour. Still a digest: the reason for pinning is that the compiler cannot change underneath a build, and that holds one version along.builderandroute-proxycarry the same pin for the same reason — they compile this repository's code from its context — and move with it in mesh-catalog.This blocks every Go build in the mesh, so it wants to go in before anything else is built.