Repository navigation
fix(deps): bump Go to 1.26.9 and x/net to v0.60.0 - #2154
Merged
Merged
Conversation
govulncheck v1.1.4 reports called standard library vulnerabilities on Go 1.26.6 (GO-2026-6599..6617, fixed in go1.26.9) and golang.org/x/net v0.58.0 findings fixed in v0.60.0. CI resolves its Go version from go.mod, so the go directive is the toolchain pin. - go 1.26.9 in go.mod and go.work, and in the docs and CI defaults that quote the version. - golang.org/x/net v0.60.0; go get also moved x/crypto, x/sync, x/sys, x/term and x/text to the minimum versions it requires. With GOTOOLCHAIN=go1.26.9, build, vet, go test ./... and govulncheck ./... pass; govulncheck exits 0 (one uncalled x/crypto finding, GO-2026-5932, has no fix).
Contributor
Member
Author
|
Independent review at head 281aec7 by archera-quotes-kimi: no blocking findings. Summary: only version moves (go directive 1.26.9, golang.org/x bumps with matching go.sum, CI GO_VERSION and docs); no stale 1.26.6 and no Dockerfile or .tool-versions pins; go mod tidy -diff clean; govulncheck ./... exits 3 at base with go1.26.6 and 0 at head with go1.26.9; build, vet and tests pass. Note: the ./cmd tests need about 450s (445s at base, 448s at head); they time out at a 150s limit at both and pass with 590s, so this is not a regression. CI not watched by me (rollup CLEAN, only the CodeRabbit context non-green). Full evidence: ~/.claude/agent-comms/messages/review-20261009T101500Z-archera-quotes-kimi-go-advisory-prs-287-2154-46.md |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Why
The Go vulnerability DB entries GO-2026-6599..6617 were published on 2026-10-08. They make
govulncheck(v1.1.4, the pin CI uses across the cloud-commitments repos) fail onmain.I reproduced this locally at
origin/mainbef177f5withGOTOOLCHAIN=go1.26.6, which is whatgo-version-file: go.modresolves to in CI:golang.org/x/net@v0.58.0findings are also reported, and they are fixed in v0.60.0.What
godirective is now1.26.9ingo.modandgo.work. CI reads its Go version from these, so this is the toolchain pin. The docs and CI defaults that quote the version are updated too. No Dockerfile here pins Go.golang.org/x/netis now v0.60.0.go getmoved x/crypto, x/sync, x/sys, x/term and x/text to the minimums that x/net v0.60.0 requires, andgo mod tidywas run.cloud-commitments-gomodules are unchanged. Their go.modgolines don't affect this repo's toolchain, and the matching go PR is fix(deps): bump Go to 1.26.9 and x/net to v0.60.0 cloud-commitments-go#287.Verification (local, macOS,
GOTOOLCHAIN=go1.26.9)go build -o /dev/null ./cmd: okgo vet ./...: okgo test -count=1 ./...(no -race): okgovulncheck ./...: exit 0, "Your code is affected by 0 vulnerabilities". One uncalled finding is left in a required module: GO-2026-5932 in x/crypto, which has no fixed version yet.🤖 Generated with Claude Code
Summary by CodeRabbit