Skip to content

fix(deps): bump Go to 1.26.9 and x/net to v0.60.0 - #2154

Merged
cristim merged 1 commit into
mainfrom
fix/go-advisories-go1.26.9-xnet-0.60
Oct 9, 2026
Merged

cristim merged 1 commit into
mainfrom
fix/go-advisories-go1.26.9-xnet-0.60

Conversation

@cristim

@cristim cristim commented Oct 9, 2026 •

Copy link
Copy Markdown
Member

Why

The Go vulnerability DB entries GO-2026-6599..6617 were published on 2026-10-08. They make govulncheck (v1.1.4, the pin CI uses across the cloud-commitments repos) fail on main.

I reproduced this locally at origin/main bef177f5 with GOTOOLCHAIN=go1.26.6, which is what go-version-file: go.mod resolves to in CI:

  • "Your code is affected by 9 vulnerabilities from the Go standard library", and govulncheck exits 3.
  • The IDs are GO-2026-6603, -6605, -6607, -6608, -6610, -6611, -6612, -6613, -6617 (net/http, crypto/tls, net/textproto, mime/multipart, net/http/httputil). All are fixed in go1.26.9.
  • golang.org/x/net@v0.58.0 findings are also reported, and they are fixed in v0.60.0.

What

  • The go directive is now 1.26.9 in go.mod and go.work. CI reads its Go version from these, so this is the toolchain pin. The docs and CI defaults that quote the version are updated too. No Dockerfile here pins Go.
  • golang.org/x/net is now v0.60.0. go get moved x/crypto, x/sync, x/sys, x/term and x/text to the minimums that x/net v0.60.0 requires, and go mod tidy was run.
  • The pins of the cloud-commitments-go modules are unchanged. Their go.mod go lines don't affect this repo's toolchain, and the matching go PR is fix(deps): bump Go to 1.26.9 and x/net to v0.60.0 cloud-commitments-go#287.

Verification (local, macOS, GOTOOLCHAIN=go1.26.9)

  • go build -o /dev/null ./cmd: ok
  • go vet ./...: ok
  • go test -count=1 ./... (no -race): ok
  • govulncheck ./...: exit 0, "Your code is affected by 0 vulnerabilities". One uncalled finding is left in a required module: GO-2026-5932 in x/crypto, which has no fixed version yet.

🤖 Generated with Claude Code

Summary by CodeRabbit

  • Documentation
    • Updated the documented minimum Go version to 1.26.9.
  • Chores
    • Updated the Go version requirement and several dependencies.

govulncheck v1.1.4 reports called standard library vulnerabilities on
Go 1.26.6 (GO-2026-6599..6617, fixed in go1.26.9) and golang.org/x/net
v0.58.0 findings fixed in v0.60.0. CI resolves its Go version from
go.mod, so the go directive is the toolchain pin.

- go 1.26.9 in go.mod and go.work, and in the docs and CI defaults
  that quote the version.
- golang.org/x/net v0.60.0; go get also moved x/crypto, x/sync, x/sys,
  x/term and x/text to the minimum versions it requires.

With GOTOOLCHAIN=go1.26.9, build, vet, go test ./... and govulncheck
./... pass; govulncheck exits 0 (one uncalled x/crypto finding,
GO-2026-5932, has no fix).
@coderabbitai

coderabbitai Bot commented Oct 9, 2026 •

Copy link
Copy Markdown
Contributor

Review in Change Stack →

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Repository: LeanerCloud/cloud-commitments-cli/.coderabbit.yaml
  • Review profile: CHILL
  • Plan: Essentials
  • Run ID: b4e8a5a4-63c1-4b3d-8cce-988bc3f560e5

📥 Commits

Reviewing files that changed from the base of the PR and between bef177f and 281aec7.


⛔ Files ignored due to path filters (2)
  • go.sum is excluded by !**/*.sum
  • go.work is excluded by !**/*.work

📒 Files selected for processing (2)
  • CONTRIBUTING.md
  • go.mod

Included review availability: This review used your included allowance. 0 included reviews remain after this review. Your included PR review attempts over the past 7 days set your current allowance at 1 review per hour.



📝 Walkthrough

Walkthrough

The module and contributor documentation now specify Go 1.26.9. Several indirect dependency versions also changed.

Changes

Go toolchain updates

Layer / File(s) Summary
Go version and dependency updates
go.mod, CONTRIBUTING.md
The module requirement, prerequisites, and workspace example now specify Go 1.26.9. Versions of golang.org/x/crypto, x/net, x/sync, x/sys, x/text, and x/term were updated. x/oauth2 remains unchanged.

Priority: ➖ Normal

Estimated code review effort: 1 (Trivial) | ~5 minutes

Change: Other


Merge Risk: ⚪ Minimal · up to 281ae

The toolchain update is consistently applied across the documented and inspected automated paths; no identified issue warrants holding the change.

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check Passed The title clearly and concisely identifies the main changes: updating Go to 1.26.9 and golang.org/x/net to v0.60.0.
Docstring Coverage Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check Passed Check skipped because no linked issues were found for this pull request.


✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR


  • Autofix · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Comment @coderabbitai help to get the list of available commands.

@cristim

cristim commented Oct 9, 2026

Copy link
Copy Markdown
Member Author

Independent review at head 281aec7 by archera-quotes-kimi: no blocking findings. Summary: only version moves (go directive 1.26.9, golang.org/x bumps with matching go.sum, CI GO_VERSION and docs); no stale 1.26.6 and no Dockerfile or .tool-versions pins; go mod tidy -diff clean; govulncheck ./... exits 3 at base with go1.26.6 and 0 at head with go1.26.9; build, vet and tests pass. Note: the ./cmd tests need about 450s (445s at base, 448s at head); they time out at a 150s limit at both and pass with 590s, so this is not a regression. CI not watched by me (rollup CLEAN, only the CodeRabbit context non-green). Full evidence: ~/.claude/agent-comms/messages/review-20261009T101500Z-archera-quotes-kimi-go-advisory-prs-287-2154-46.md

@cristim
cristim merged commit 8c35e8d into main Oct 9, 2026
12 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant