feat: updatecheck foundation package (PR-01 of 5) - #651
Merged
Merged
Conversation
Adds sast-engine/updatecheck/ — a purely additive, zero-callers package that implements the full version-check pipeline described in the version-update-check tech spec. - manifest.go: wire types (Manifest, ManifestLatest, ManifestAnnouncement, etc.), public Result/UpgradeNotice/Announcement/Options types, and Fetch() with context-scoped 800ms/5s HTTP timeout. - semver.go: strict MAJOR.MINOR.PATCH parser, Compare(), Match() with <, <=, >, >=, = and space-separated AND (up to 2 constraints). - select.go: selectUpgrade() (info/warn escalation via min_supported) and selectAnnouncement() with the 6-tier priority rule, audience filter, time-window filter, dismissed-IDs filter, and version_range semver filter. - check.go (!noupdatecheck): Check() orchestrator with opt-out via DisableCheck flag and PATHFINDER_NO_UPDATE_CHECK env var. - check_noop.go (noupdatecheck): stub returning nil for distros that compile the feature out via -tags noupdatecheck. - 100% statement coverage across all files. - Zero callers anywhere in the binary tree (purely additive). Part of: version-update-check stack (PR-01 of 5). Next: PR-02 wires Check() into cmd/root.go PersistentPreRun. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
SafeDep Report SummaryNo dependency changes detected. Nothing to scan. This report is generated by SafeDep Github App |
Code Pathfinder Security ScanNo security issues detected.
Powered by Code Pathfinder |
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #651 +/- ##
==========================================
+ Coverage 84.75% 84.87% +0.11%
==========================================
Files 165 169 +4
Lines 24403 24594 +191
==========================================
+ Hits 20682 20873 +191
Misses 2937 2937
Partials 784 784 ☔ View full report in Codecov by Sentry. 🚀 New features to boost your workflow:
|
Owner
Author
This was referenced Apr 12, 2026
Owner
Author
Merge activity
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.




Summary
sast-engine/updatecheck/as a purely additive, zero-callers foundation package implementing the full version-check pipeline from the version-update-check tech spec.What's in this PR
manifest.goManifest,ManifestLatest,ManifestAnnouncement), publicResult/UpgradeNotice/Announcement/Options,Fetch()with context-scoped timeoutsemver.goCompare(),Match()with<<=>>==and space-separated ANDselect.goselectUpgrade()(info/warn escalation viamin_supported) andselectAnnouncement()with 6-tier priority, audience filter, time-window, dismissed-IDs, andversion_rangesemver filtercheck.goCheck()orchestrator; opt-out viaDisableCheckflag andPATHFINDER_NO_UPDATE_CHECKenv var (build tag!noupdatecheck)check_noop.go-tags noupdatecheckStack
Verification
Test plan
go build ./...— zero issuesgo test ./updatecheck/...— all tests passgo tool cover— 100.0% statement coveragegolangci-lint run ./updatecheck/...— 0 issuesgo build -tags noupdatecheck ./...— noop stub compilesupdatecheck/(grep -r "updatecheck" . --include="*.go" --exclude-dir=updatecheckreturns empty)🤖 Generated with Claude Code