testify icon indicating copy to clipboard operation
testify copied to clipboard

change yaml library to go.yaml.in/yaml/v3

Open boekkooi-impossiblecloud opened this issue 6 months ago • 6 comments

Summary

The go-yaml project was archived on Apr 1, 2025 and is no longer maintained. Luckily the official YAML organization forked the project and is maintaining it under https://github.com/yaml/go-yaml/tree/v3.

Changes

Replaced all occurrences of gopkg.in/yaml.v3 with go.yaml.in/yaml/v3

Motivation

go-yaml was archived on Apr 1.

Related issues

  • https://github.com/stretchr/testify/issues/1724

There is work in progress about the license of that project: https://github.com/yaml/go-yaml/pull/6

So we should block until that is stabilized.

dolmen avatar Aug 01 '25 09:08 dolmen

There is work in progress about the license of that project: yaml/go-yaml#6

So we should block until that is stabilized.

License of go-yaml has changed to Apache now. This PR can move forward

harryzcy avatar Aug 30 '25 05:08 harryzcy

The change are only on main branch for now.

go-yaml has only released -rc for now for the v4.

It might be a bit early

ccoVeille avatar Aug 30 '25 09:08 ccoVeille

I'd like to see this PR merged, with the v3 tag it now has, while the YAML organization works on v4. That move would make it easier to get buy-in for using Testify at organizations that balk at running abandonware. The main branch's README received a July 30 update that makes it clear that v3 will receive security updates.

mrideout avatar Sep 17 '25 00:09 mrideout

I think this is good to be merged, so instantly all indirect dependencies to the archive repo would disappear. Notice that the build tags trick that is used in assert/yaml has no influence on how go.mod propagates dependencies.

fredbi avatar Sep 20 '25 18:09 fredbi

The majority of testify users would need to wait until we make a release to benefit from this. Recently we've been on a (very) approximate 6-monthly release cadence, that's not to say we couldn't release earlier than expected to mitigate this and another EOL dependency.

My point is that there isn't a pressing need to rush this. We really do want to merge this, but v4 is in release candidate so I don't think it will be all that long now.

brackendawson avatar Sep 22 '25 10:09 brackendawson