Skip to content

Migrate process configuration to maintained Go YAML libraries - #305

Open
ai-collaboration-app[bot] wants to merge 2 commits into
masterfrom
yaml-maintained
Open

ai-collaboration-app[bot] wants to merge 2 commits into
masterfrom
yaml-maintained

Conversation

@ai-collaboration-app

@ai-collaboration-app ai-collaboration-app Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

Migrate process config/tests to maintained YAML v2 and adopt Datadog PR #853 at b06402db3fad. Reconcile affected modules and explicitly select owned Viper, retaining baseline HCL/filesystem/mapstructure APIs.

Native amd64/arm64 CI passed generation/drift checks, module verification, lint/vet, tests/build, OpenPGP exclusion, BCI smoke/scans and signing. Both binaries have no legacy parser modules/symbols; candidate image signatures independently verify. Focused HCL/config contracts pass; Viper’s full suite retains one flag-slice failure reproduced on unmodified v1.14.0. CVE gates remain in inform mode.

Tracking: https://github.com/StackVista/stackstate/issues/717

Keep the existing v2 API and configuration semantics while moving owned
production and test imports to go.yaml.in/yaml/v2 v2.4.4. Cover file loading,
aliases, YAML 1.1 scalar interpretation, multiline strings, unknown fields,
null/default pointer booleans, missing files and parse errors. The same
fixtures pass against the isolated original v2 source at 0294bfe.

Upgrade testify to v1.12.1 and DataDog/viper to v1.15.3 so their consumed
parsers use maintained v3 and v2. The process-agent configuration suite and
the consumed fork's config/model, config/nodetreemodel and config/setup
suites (with the test tag) pass. Preserve all existing module replacements.

Tagged Linux amd64 and arm64 package graphs still reach gopkg.in/yaml.v2
v2.4.0 and gopkg.in/yaml.v3 v3.0.1 through the Datadog fork at b8455a4d7b2b.
All 57 consumed Datadog modules resolve through 116 root replacements;
upstream replacement directives cannot migrate these consumer graphs.
ghodss/yaml is metadata-only in the qualified package targets. No duplicate
effective module/version identities were found.

Config vet/revive/imports, tidy consistency, module verification and the
existing OpenPGP exclusion check pass. Full tagged builds/tests need native
prebuild artifacts: both baseline and candidate fail on missing generated
runtime.Tracer and runtime.RuntimeSecurity symbols. Native amd64/arm64 CI,
image scans and binary provenance remain required before adoption.

Tracking: StackVista/stackstate#717
Reconcile 51 affected existing Datadog replacements with the published
b06402db3fad candidate, including the consumed config, secrets, security,
scrubber and test utility modules. Explicitly replace logical DataDog/viper
with the fork's checksum-verified third_party/viper module. Restore its
v1.14.0 logical requirement to match the reviewed source and retain baseline
HCL, filesystem and mapstructure APIs instead of the earlier v1.15.3 change.
Keep the separate metadata-only spf13/viper replacement distinct.

Dependency coherence selects swag conv/jsonutils/typeutils/yamlutils and
pools v0.27.1; the existing facade stays v0.25.5 selected by this consumer.
Preserve owned config migration and compatibility fixtures. This signed
checkpoint precedes native amd64/arm64 candidate CI qualification.

Tracking: StackVista/stackstate#717
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant