From 54db60d191e302c0336e69b5a1a5f26609745910 Mon Sep 17 00:00:00 2001 From: Frederic BIDON Date: Thu, 3 Sep 2026 18:41:08 +0200 Subject: [PATCH 1/2] chore: upgrade to go1.26 Signed-off-by: Frederic BIDON --- go.mod | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/go.mod b/go.mod index d6992d0..97f1252 100644 --- a/go.mod +++ b/go.mod @@ -18,4 +18,4 @@ require ( go.yaml.in/yaml/v3 v3.0.5 // indirect ) -go 1.25.0 +go 1.26.0 From 744abba3a708a64f9c10c02f4e44f6e140ea1526 Mon Sep 17 00:00:00 2001 From: Frederic BIDON Date: Thu, 3 Sep 2026 20:51:55 +0200 Subject: [PATCH 2/2] test: fixed expectation on URL following go1.26 (change of GODEBUG flag) Signed-off-by: Frederic BIDON --- normalizer_canonical_test.go | 17 +++++++++++------ 1 file changed, 11 insertions(+), 6 deletions(-) diff --git a/normalizer_canonical_test.go b/normalizer_canonical_test.go index e8ac098..15d7849 100644 --- a/normalizer_canonical_test.go +++ b/normalizer_canonical_test.go @@ -60,17 +60,22 @@ func TestNormalizer_Canonicalization(t *testing.T) { refPath: "https://user:pw@EXAMPLE.com:443/other.json", expected: "https://user:pw@example.com/other.json", }, - { - name: "degenerate authority, port kept", - rule: "url.Parse reads the host as \":a\" on port 443, and dropping the port would leave a URI that no longer parses", + // Since go1.26, url.Parse rejects a colon outside a bracketed IPv6 host on an http or https URL + // (GODEBUG urlstrictcolons=1, the default from a go.mod declaring go 1.26 or later). Both $refs below + // used to parse - the first as the host ":a" on port 443, the second as "0:443" on port 443 - and both + // now fail. normalizeURI logs a warning, repairs the $ref to the empty URI and resolves it against the + // base, so the base itself comes back. + { + name: "degenerate authority, stray colon", + rule: "a colon in the host is rejected, and an unresolvable $ref falls back to the base", refPath: "https://:a:443/other.json", - expected: "https://:a:443/other.json", + expected: base, }, { name: "degenerate authority, port twice", - rule: "the host \"0:443\" spells a default port of its own, so removal repeats", + rule: "same for a host spelling a port of its own", refPath: "https://0:443:443/other.json", - expected: "https://0/other.json", + expected: base, }, { name: "duplicate slashes, relative",