Brad Fitzpatrick 63f625397b misc/bumpdeps, .github/workflows: unify the bumpdeps tool and bumpdep workflow
The bumpdep workflow grew 170 lines of inline shell that duplicated
much of what misc/bumpdeps already did in Go (resolving versions,
special branches, running go get), and disagreed with it in small ways
(the workflow fetched wireguard-go with GOPROXY=direct; the tool asked
the proxy for the branch head). It was also untestable except by
extracting the run block and running it by hand.

Move all of that logic into misc/bumpdeps and make the workflow a thin
wrapper that runs it with -github. The tool now:

  - accepts the workflow's argument forms: "go" for the toolchain (via
    ./pull-toolchain.sh), the "wireguard-go" and "gvisor" aliases,
    exact module paths, "path@version", and modules not yet in go.mod,
    alongside its existing substring filters; comma-separated arguments
    are split, so the workflow input passes straight through;
  - finds branch heads with git ls-remote and then asks the proxy for
    the pseudo-version of that commit, so a just-pushed commit is seen
    without ever cloning (GOPROXY=direct on github.com/gokrazy/kernel.*
    hung the workflow for hours);
  - refuses downgrades by diffing go.mod before and after go get,
    rather than grepping go get's output;
  - runs "make tidy" and "make updatedeps" itself (-tidy=false to skip);
  - renders the PR title, body (GitHub compare links derived from the
    module path, including subdirectory-tagged modules), and commit
    message, printing a suggested commit message locally and, with
    -github, writing step outputs and the step summary. -issue accepts
    the issue URL or "#N" form and becomes the "Updates" line.

The branch name changes from a slug of every module path, which
produced names like actions/bumpdep/github.com-gokrazy-kernel.amd64-
main-github.com-gokrazy-kernel.arm64-main-github, to
actions/<workflow>/<actor>/<yyyymmdd-hhmmss> (no actor for scheduled
runs). Each run is a fresh PR; delete-branch cleans up after merge or
close.

The bumpdep workflow gains an optional exclude-newer-than-days input for
the cooldown. All of the formerly-inline logic now has unit tests,
including a fake module proxy.

Also add a gokrazy-bump workflow that runs the same tool every Sunday
night on the direct github.com/gokrazy/* modules (kernels, firmware,
gokrazy itself) and opens a PR labeled run-natlab-tests, so the natlab
VM tests boot the new kernels before merge. Substring filters now skip
indirect dependencies unless -indirect is set, so that "github.com/
gokrazy/" doesn't drag in gokapi; naming an indirect module exactly
still selects it.

Updates tailscale/corp#48312
Updates #8043
Updates #1866

Signed-off-by: Brad Fitzpatrick <bradfitz@tailscale.com>
Change-Id: I7c3e91a4d2f58b0e6a1c9d47f3b2e8a5c6d0f1e2
2026-09-23 06:42:52 -07:00
2026-09-16 10:08:11 -04:00
2026-09-03 15:37:10 -07:00
2026-07-10 17:39:16 -07:00
2026-01-27 16:15:17 -08:00
2026-06-02 10:59:29 -07:00
2026-08-28 12:47:04 -07:00
2026-09-17 16:55:23 -07:00

Tailscale

https://tailscale.com

Private WireGuard® networks made easy

Overview

This repository contains the majority of Tailscale's open source code. Notably, it includes the tailscaled daemon and the tailscale CLI tool. The tailscaled daemon runs on Linux, Windows, macOS, and to varying degrees on FreeBSD and OpenBSD. The Tailscale iOS and Android apps use this repo's code, but this repo doesn't contain the mobile GUI code.

Other Tailscale repos of note:

For background on which parts of Tailscale are open source and why, see https://tailscale.com/opensource/.

Using

We serve packages for a variety of distros and platforms at https://pkgs.tailscale.com.

Other clients

The macOS, iOS, and Windows clients use the code in this repository but additionally include small GUI wrappers. The GUI wrappers on non-open source platforms are themselves not open source.

Building

We always require the latest Go release, currently Go 1.27. (While we build releases with our Go fork, its use is not required.)

go install tailscale.com/cmd/tailscale{,d}

If you're packaging Tailscale for distribution, use build_dist.sh instead, to burn commit IDs and version info into the binaries:

./build_dist.sh tailscale.com/cmd/tailscale
./build_dist.sh tailscale.com/cmd/tailscaled

If your distro has conventions that preclude the use of build_dist.sh, please do the equivalent of what it does in your distro's way, so that bug reports contain useful version information.

Bugs

Please file any issues about this code or the hosted service on the issue tracker.

Contributing

PRs welcome! But please file bugs. Commit messages should reference bugs.

We require Developer Certificate of Origin Signed-off-by lines in commits.

See commit-messages.md (or skim git log) for our commit message style.

About Us

Tailscale is primarily developed by the people at https://github.com/orgs/tailscale/people. For other contributors, see:

WireGuard is a registered trademark of Jason A. Donenfeld.

S
Description
No description provided
Readme BSD-3-Clause
191 MiB
0 Stars 1 Watchers 0 Forks
Languages
Go 96.2%
C 1.3%
TypeScript 0.9%
Shell 0.5%
Swift 0.3%
Other 0.5%