Skip to content

chore(deps): bump Go toolchain to 1.26.6 - #352

Merged
Thiht merged 1 commit into
mainfrom
fix/bump-go-1.26.6
Sep 23, 2026
Merged

Thiht merged 1 commit into
mainfrom
fix/bump-go-1.26.6

Conversation

@Thiht

@Thiht Thiht commented Sep 23, 2026

Copy link
Copy Markdown
Collaborator

Problem

The security CI job fails on all open PRs because govulncheck reports 24 vulnerabilities in the Go standard library (net/url, net/http, crypto/tls, crypto/x509, encoding/xml, html/template, encoding/asn1, net/textproto, ...).

Root cause

setup-go resolves the go directive in go.mod to its exact minor (go 1.26.0), so CI builds with go1.26.0. All the reported CVEs are fixed in go1.26.6.

Fix

Bump go 1.26.0 → go 1.26.6.

govulncheck reports 24 standard-library vulnerabilities
(net/url, net/http, crypto/tls, crypto/x509, encoding/xml, html/template,
encoding/asn1, net/textproto, ...) all fixed in go1.26.6. setup-go resolves
the go directive to its exact minor, so CI was building with go1.26.0.
@sonarqubecloud

Copy link
Copy Markdown

@Thiht
Thiht enabled auto-merge September 23, 2026 22:02
@Thiht
Thiht merged commit d95941a into main Sep 23, 2026
8 checks passed
@Thiht
Thiht deleted the fix/bump-go-1.26.6 branch September 23, 2026 22:04
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

1 participant