From 644e0365786401ad841ad0c39d594d835517bb1d Mon Sep 17 00:00:00 2001 From: PJ Date: Sun, 16 Aug 2026 17:20:59 +0530 Subject: [PATCH] ci: pin the protoc plugins instead of installing @latest these generate the committed stubs, so @latest makes codegen depend on whatever released most recently. pinned to the versions proto/ records: protoc-gen-go v1.36.11, protoc-gen-go-grpc v1.6.0. --- .github/workflows/ci.yml | 8 ++++++-- 1 file changed, 6 insertions(+), 2 deletions(-) diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 9d91b30..dac1d1f 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -86,10 +86,14 @@ jobs: setup_only: true github_token: ${{ secrets.GITHUB_TOKEN }} + # Pinned, not @latest: these two write the committed stubs, so a floating + # version is an unreviewed input to generated code. The versions are the + # ones the stubs under proto/ record generating them, so what CI builds + # with and what is checked in stay the same thing. - name: Install protoc plugins run: | - go install google.golang.org/protobuf/cmd/protoc-gen-go@latest - go install google.golang.org/grpc/cmd/protoc-gen-go-grpc@latest + go install google.golang.org/protobuf/cmd/protoc-gen-go@v1.36.11 + go install google.golang.org/grpc/cmd/protoc-gen-go-grpc@v1.6.0 echo "$(go env GOPATH)/bin" >> "$GITHUB_PATH" - name: Cache Gradle