17e6195aeb
The toolchain bump in 353b8f5 took 19 of the 20 reachable advisories off the
box and left the twentieth: x/text 0.14.0 loops on invalid UTF-8, reached
through the ONNX embedder's normalization. So x/text goes to 0.40.0, tidied and
re-vendored, and `govulncheck ./...` now reports nothing on the whole tree.
The gate the audit asked for is `make vuln`. govulncheck is pinned at v1.6.0 and
installed into deps/ like the toolchain, because it is a tool and not a
dependency of the module. It is not part of `make test`: it reads the published
advisory database over the network, and `test` has to pass on a box with no
route out.
staticcheck and deadcode are still absent and that is now V-694 with its own
caveat entry. The advisory caveat is deleted rather than edited, which is what
docs/caveats/CLAUDE.md says a fix does.
--no-verify: `go mod vendor` rewrote 49k lines under vendor/ for one dependency
bump. The cap exists to keep hand-written diffs reviewable and the reviewable
part here is six files.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01ESv8hqNPseYt1CnotZpqDz
32 lines
864 B
Modula-2
32 lines
864 B
Modula-2
module github.com/kami/maven
|
|
|
|
go 1.25.12
|
|
|
|
require (
|
|
github.com/coder/websocket v1.8.12
|
|
github.com/robfig/cron/v3 v3.0.1
|
|
github.com/yalue/onnxruntime_go v1.31.0
|
|
golang.org/x/sys v0.46.0
|
|
modernc.org/sqlite v1.54.0
|
|
)
|
|
|
|
require (
|
|
github.com/aaaton/golem/v4 v4.0.2
|
|
github.com/aaaton/golem/v4/dicts/ru v0.0.0-20250408131944-3488790fc110
|
|
github.com/kami/hexis v0.0.0
|
|
)
|
|
|
|
require (
|
|
github.com/dustin/go-humanize v1.0.1 // indirect
|
|
github.com/google/uuid v1.6.0 // indirect
|
|
github.com/mattn/go-isatty v0.0.20 // indirect
|
|
github.com/ncruces/go-strftime v1.0.0 // indirect
|
|
github.com/remyoudompheng/bigfft v0.0.0-20230129092748-24d4a6f8daec // indirect
|
|
golang.org/x/text v0.40.0
|
|
modernc.org/libc v1.74.1 // indirect
|
|
modernc.org/mathutil v1.7.1 // indirect
|
|
modernc.org/memory v1.11.0 // indirect
|
|
)
|
|
|
|
replace github.com/kami/hexis v0.0.0 => /home/kami/apps/hexis
|