diff --git a/.github/workflows/codeql-analysis.yml b/.github/workflows/codeql-analysis.yml index 7fac235..45169af 100644 --- a/.github/workflows/codeql-analysis.yml +++ b/.github/workflows/codeql-analysis.yml @@ -30,7 +30,7 @@ jobs: steps: - name: Checkout repository - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 + uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0 # Initializes the CodeQL tools for scanning. - name: Initialize CodeQL diff --git a/.github/workflows/linters.yml b/.github/workflows/linters.yml index d87d9d7..a699b16 100644 --- a/.github/workflows/linters.yml +++ b/.github/workflows/linters.yml @@ -15,7 +15,7 @@ jobs: pull-requests: read # for golangci/golangci-lint-action to fetch pull requests steps: - name: Checkout code - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 + uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0 with: persist-credentials: false - name: Setup Go diff --git a/.github/workflows/scorecard.yml b/.github/workflows/scorecard.yml index 0ad7158..733d266 100644 --- a/.github/workflows/scorecard.yml +++ b/.github/workflows/scorecard.yml @@ -35,7 +35,7 @@ jobs: steps: - name: "Checkout code" - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 + uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0 with: persist-credentials: false diff --git a/.github/workflows/tests.yml b/.github/workflows/tests.yml index fde213f..397f2b9 100644 --- a/.github/workflows/tests.yml +++ b/.github/workflows/tests.yml @@ -15,7 +15,7 @@ jobs: contents: read # for actions/checkout to fetch code steps: - name: Checkout code - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 + uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0 with: persist-credentials: false - name: Setup Go -- 2.51.2 From f3d4a0c20837b1d2dc1507201d784e331f0756c2 Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Thu, 4 Sep 2025 21:16:06 +0000 Subject: [PATCH 2/6] chore(deps): bump actions/setup-go from 5.5.0 to 6.0.0 Bumps [actions/setup-go](https://github.com/actions/setup-go) from 5.5.0 to 6.0.0. - [Release notes](https://github.com/actions/setup-go/releases) - [Commits](https://github.com/actions/setup-go/compare/d35c59abb061a4a6fb18e82ac0862c26744d6ab5...44694675825211faa026b3c33043df3e48a5fa00) --- updated-dependencies: - dependency-name: actions/setup-go dependency-version: 6.0.0 dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] --- .github/workflows/linters.yml | 2 +- .github/workflows/tests.yml | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/.github/workflows/linters.yml b/.github/workflows/linters.yml index d87d9d7..0e19638 100644 --- a/.github/workflows/linters.yml +++ b/.github/workflows/linters.yml @@ -19,7 +19,7 @@ jobs: with: persist-credentials: false - name: Setup Go - uses: actions/setup-go@d35c59abb061a4a6fb18e82ac0862c26744d6ab5 # v5.5.0 + uses: actions/setup-go@44694675825211faa026b3c33043df3e48a5fa00 # v6.0.0 with: go-version: 'stable' - name: golangci-lint diff --git a/.github/workflows/tests.yml b/.github/workflows/tests.yml index fde213f..c73e656 100644 --- a/.github/workflows/tests.yml +++ b/.github/workflows/tests.yml @@ -19,7 +19,7 @@ jobs: with: persist-credentials: false - name: Setup Go - uses: actions/setup-go@d35c59abb061a4a6fb18e82ac0862c26744d6ab5 # v5.5.0 + uses: actions/setup-go@44694675825211faa026b3c33043df3e48a5fa00 # v6.0.0 with: go-version: 1.23.9 - name: Build -- 2.51.2 From 78bd6628d12e9408063f103da0d4844b7a49cff1 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Dario=20Casta=C3=B1=C3=A9?= Date: Sun, 22 Mar 2026 15:31:02 +0100 Subject: [PATCH 3/6] fix: add "Build with Ona" button --- README.md | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/README.md b/README.md index 6a257c9..e26caf3 100644 --- a/README.md +++ b/README.md @@ -13,7 +13,9 @@ [![Become my sponsor][15]][16] [![Tidelift][17]][18] [![Liberapay patrons][23]][24] + [![Support mergo on drips.network][25]][26] +[![Build with Ona][27]][28] [1]: https://github.com/darccio/mergo/workflows/tests/badge.svg?branch=master [2]: https://github.com/darccio/mergo/actions/workflows/tests.yml @@ -41,6 +43,8 @@ [24]: https://liberapay.com/dario/donate [25]: https://www.drips.network/api/embed/project/https%3A%2F%2Fgithub.com%2Fdarccio%2Fmergo/support.png?background=light&style=github&text=project&stat=none [26]: https://www.drips.network/app/projects/github/darccio/mergo +[27]: https://ona.com/build-with-ona.svg +[28]: https://app.ona.com/#https://github.com/darccio/mergo A helper to merge structs and maps in Golang. Useful for configuration default values, avoiding messy if-statements. -- 2.51.2 From 11c20956dda5852673925ecf7fbdee39fda38fa9 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Dario=20Casta=C3=B1=C3=A9?= Date: Sun, 22 Mar 2026 14:52:13 +0000 Subject: [PATCH 4/6] docs: fix typos and stale links - doc.go: fix 'suppot' typo and double period in 0.3.10 release note - CONTRIBUTING.md: replace empty email placeholders with GitHub issue link (CoC) and reference to SECURITY.md (security reports); correct documentation URLs from github.com/darccio/mergo to dario.cat/mergo - README.md: update Sourcegraph and FOSSA badge URLs from imdario/mergo to darccio/mergo Co-authored-by: Ona --- CONTRIBUTING.md | 8 ++++---- README.md | 8 ++++---- doc.go | 2 +- 3 files changed, 9 insertions(+), 9 deletions(-) diff --git a/CONTRIBUTING.md b/CONTRIBUTING.md index 6f3fa87..f379ad9 100644 --- a/CONTRIBUTING.md +++ b/CONTRIBUTING.md @@ -25,12 +25,12 @@ All types of contributions are encouraged and valued. See the [Table of Contents This project and everyone participating in it is governed by the [mergo Code of Conduct](https://github.com/darccio/mergo/blob/master/CODE_OF_CONDUCT.md). By participating, you are expected to uphold this code. Please report unacceptable behavior -to <>. +by opening a [GitHub issue](https://github.com/darccio/mergo/issues/new). ## I Have a Question -> If you want to ask a question, we assume that you have read the available [Documentation](https://pkg.go.dev/github.com/darccio/mergo). +> If you want to ask a question, we assume that you have read the available [Documentation](https://pkg.go.dev/dario.cat/mergo). Before you ask a question, it is best to search for existing [Issues](https://github.com/darccio/mergo/issues) that might help you. In case you have found a suitable issue and still need clarification, you can write your question in this issue. It is also advisable to search the internet for answers first. @@ -55,7 +55,7 @@ We will then take care of the issue as soon as possible. A good bug report shouldn't leave others needing to chase you up for more information. Therefore, we ask you to investigate carefully, collect information and describe the issue in detail in your report. Please complete the following steps in advance to help us fix any potential bug as fast as possible. - Make sure that you are using the latest version. -- Determine if your bug is really a bug and not an error on your side e.g. using incompatible environment components/versions (Make sure that you have read the [documentation](). If you are looking for support, you might want to check [this section](#i-have-a-question)). +- Determine if your bug is really a bug and not an error on your side e.g. using incompatible environment components/versions (Make sure that you have read the [documentation](https://pkg.go.dev/dario.cat/mergo). If you are looking for support, you might want to check [this section](#i-have-a-question)). - To see if other users have experienced (and potentially already solved) the same issue you are having, check if there is not already a bug report existing for your bug or error in the [bug tracker](https://github.com/darccio/mergo/issues?q=label%3Abug). - Also make sure to search the internet (including Stack Overflow) to see if users outside of the GitHub community have discussed the issue. - Collect information about the bug: @@ -68,7 +68,7 @@ A good bug report shouldn't leave others needing to chase you up for more inform #### How Do I Submit a Good Bug Report? -> You must never report security related issues, vulnerabilities or bugs including sensitive information to the issue tracker, or elsewhere in public. Instead sensitive bugs must be sent by email to . +> You must never report security related issues, vulnerabilities or bugs including sensitive information to the issue tracker, or elsewhere in public. Instead, follow the instructions in [SECURITY.md](https://github.com/darccio/mergo/blob/master/SECURITY.md). We use GitHub issues to track bugs and errors. If you run into an issue with the project: diff --git a/README.md b/README.md index 6a257c9..1c1089e 100644 --- a/README.md +++ b/README.md @@ -25,10 +25,10 @@ [8]: https://goreportcard.com/report/dario.cat/mergo [9]: https://coveralls.io/repos/github/darccio/mergo/badge.svg?branch=master [10]: https://coveralls.io/github/darccio/mergo?branch=master -[11]: https://sourcegraph.com/github.com/imdario/mergo/-/badge.svg -[12]: https://sourcegraph.com/github.com/imdario/mergo?badge -[13]: https://app.fossa.io/api/projects/git%2Bgithub.com%2Fimdario%2Fmergo.svg?type=shield -[14]: https://app.fossa.io/projects/git%2Bgithub.com%2Fimdario%2Fmergo?ref=badge_shield +[11]: https://sourcegraph.com/github.com/darccio/mergo/-/badge.svg +[12]: https://sourcegraph.com/github.com/darccio/mergo?badge +[13]: https://app.fossa.io/api/projects/git%2Bgithub.com%2Fdarccio%2Fmergo.svg?type=shield +[14]: https://app.fossa.io/projects/git%2Bgithub.com%2Fdarccio%2Fmergo?ref=badge_shield [15]: https://img.shields.io/github/sponsors/darccio [16]: https://github.com/sponsors/darccio [17]: https://tidelift.com/badges/package/go/dario.cat%2Fmergo diff --git a/doc.go b/doc.go index 7d96ec0..f76b77f 100644 --- a/doc.go +++ b/doc.go @@ -20,7 +20,7 @@ In 1.0.0 Mergo moves to a vanity URL `dario.cat/mergo`. 0.3.9 -Please keep in mind that a problematic PR broke 0.3.9. We reverted it in 0.3.10. We consider 0.3.10 as stable but not bug-free. . Also, this version adds suppot for go modules. +Please keep in mind that a problematic PR broke 0.3.9. We reverted it in 0.3.10. We consider 0.3.10 as stable but not bug-free. Also, this version adds support for go modules. Keep in mind that in 0.3.2, Mergo changed Merge() and Map() signatures to support transformers. We added an optional/variadic argument so that it won't break the existing code. -- 2.51.2 From 2ef752d88a860eae46256fe67bc31f8b34786e32 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Dario=20Casta=C3=B1=C3=A9?= Date: Sun, 22 Mar 2026 15:55:44 +0100 Subject: [PATCH 5/6] chore: keep original imdario/darccio sourcegraph badge --- README.md | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/README.md b/README.md index 1c1089e..5462d92 100644 --- a/README.md +++ b/README.md @@ -25,8 +25,8 @@ [8]: https://goreportcard.com/report/dario.cat/mergo [9]: https://coveralls.io/repos/github/darccio/mergo/badge.svg?branch=master [10]: https://coveralls.io/github/darccio/mergo?branch=master -[11]: https://sourcegraph.com/github.com/darccio/mergo/-/badge.svg -[12]: https://sourcegraph.com/github.com/darccio/mergo?badge +[11]: https://sourcegraph.com/github.com/imdario/-mergo/-/badge.svg +[12]: https://sourcegraph.com/github.com/imdario/mergo?badge [13]: https://app.fossa.io/api/projects/git%2Bgithub.com%2Fdarccio%2Fmergo.svg?type=shield [14]: https://app.fossa.io/projects/git%2Bgithub.com%2Fdarccio%2Fmergo?ref=badge_shield [15]: https://img.shields.io/github/sponsors/darccio -- 2.51.2 From 305fcca2c8eb97d3c84e925206346c8de32390e1 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Dario=20Casta=C3=B1=C3=A9?= Date: Sun, 22 Mar 2026 15:56:23 +0100 Subject: [PATCH 6/6] fix: ensure right project name in sourcegraph badge --- README.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/README.md b/README.md index 5462d92..6208ae5 100644 --- a/README.md +++ b/README.md @@ -25,7 +25,7 @@ [8]: https://goreportcard.com/report/dario.cat/mergo [9]: https://coveralls.io/repos/github/darccio/mergo/badge.svg?branch=master [10]: https://coveralls.io/github/darccio/mergo?branch=master -[11]: https://sourcegraph.com/github.com/imdario/-mergo/-/badge.svg +[11]: https://sourcegraph.com/github.com/imdario/mergo/-/badge.svg [12]: https://sourcegraph.com/github.com/imdario/mergo?badge [13]: https://app.fossa.io/api/projects/git%2Bgithub.com%2Fdarccio%2Fmergo.svg?type=shield [14]: https://app.fossa.io/projects/git%2Bgithub.com%2Fdarccio%2Fmergo?ref=badge_shield