chore(deps): update module gitlab.com/gitlab-org/api/client-go to v3

Takes over !3863 (closed), which Renovate could only take partway: it bumped go.mod alone, but the v3 module declares its import path as gitlab.com/gitlab-org/api/client-go/v3, so the branch could not compile. Closing that one in favour of this.

Follows the 3.0 migration guide.

What changed

The /v2 import path is rewritten to /v3 across the tree, covering the gitlabtesting and gitlaboauth2 subpackages, plus the gitlabtesting import example in .gitlab/duo/mr-review-instructions.yaml so the conventions doc stops teaching the old path.

Every changed line in the diff is an import path. Nothing else moved, which you can confirm with:

git diff -U0 main -- . ':!go.mod' ':!go.sum' \
  | grep -E '^[+-]' | grep -vE '^(\+\+\+|---)' | grep -v 'api/client-go/v'

That prints nothing.

Breaking changes: none apply

Each v3 breaking change was checked against this codebase:

Breaking change Exposure here
Go 1.26 minimum None, go.mod already requires 1.27.0
config package extracted to its own module No importers
ListMergeRequestsOptions.Approved removed Not used
FeatureFlagStrategyOptions split into create/update Not used
ProjectFeatureFlagScope split into create/update Not used
Webhook reviewers EventUser to EventReviewer Not used
GroupIssueBoards.UpdateIssueBoardList return type Not called
gitlab.Ptr deprecated for v4 removal 0 call sites, nothing to migrate ahead of v4

So this is a pure import-path bump with no behaviour change.

Why not alias the import in one place

Worth recording, since it is the obvious first instinct. Go encodes the major version in the import path by design so that v2 and v3 can coexist in a build, and there is no module-wide alias. The two workarounds are both worse:

  • A facade package re-exporting types saves nothing now (all call sites still need editing once, to point at the facade) and adds a permanent re-export surface to maintain on every upstream addition.
  • replace .../client-go/v2 => .../client-go/v3 v3.0.0 compiles, but misreports the dependency: go list, Renovate, and anyone reading an import all still see v2 while v3 is on disk, and Renovate would stop offering future bumps.

The mechanical rewrite was a single sed, so the honest path was also the cheap one.

Verification

make build      # clean
make lint       # 0 issues
make test       # 4971 tests, 9 skipped, 0 failures
make gen-docs   # no drift
make generate   # no drift

lefthook run pre-push passes end to end (check-args, check-embed, build, check-generated, go-lint, go-test).

Merge request reports

Loading
Loading