Skip to content

chore(deps): bump golang.org/x/sys from 0.44.0 to 0.48.0 in /languages/golang - #1016

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/languages/golang/golang.org/x/sys-0.48.0
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/languages/golang/golang.org/x/sys-0.48.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

Bumps golang.org/x/sys from 0.44.0 to 0.48.0.

Commits
  • 613e257 cpu: add riscv64 hwprobe drift test
  • 6f7b10f unix: add MLOCK_ONFAULT constant
  • 663e7c8 cpu: add basic support for GOARCH=sparc64
  • de5f12f cpu: add ppc64le POWER10 detection
  • 80e8acf unix: run go fix
  • 1e3c182 unix: add IPMI interface
  • d429e20 unix: stop generating sparc termbits from the generic header
  • bd3bddf unix: add missing HWTSTAMP_* constants
  • e812f53 windows: add SO_SNDTIMEO constant for socket options
  • f6989c5 unix: align Ifreq so its union accessors cannot fault
  • Additional commits viewable in compare view

@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Oct 2, 2026
@dependabot @github

dependabot Bot commented on behalf of github Oct 2, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: supply-chain. Please create it before Dependabot can add it to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@dependabot
dependabot Bot requested a review from a team as a code owner October 2, 2026 18:26
@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Oct 2, 2026
@changeset-bot

changeset-bot Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

⚠️ No Changeset found

Latest commit: 18be08a

Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.

This PR includes no changesets

When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types

Click here to learn what changesets are, and how to add one.

Click here if you're a maintainer who wants to add a changeset to this PR

tobyhede commented Oct 3, 2026

Copy link
Copy Markdown
Contributor

@dependabot rebase

Bumps [golang.org/x/sys](https://github.com/golang/sys) from 0.44.0 to 0.48.0.
- [Commits](golang/sys@v0.44.0...v0.48.0)

---
updated-dependencies:
- dependency-name: golang.org/x/sys
  dependency-version: 0.48.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/go_modules/languages/golang/golang.org/x/sys-0.48.0 branch from 98f963c to 18be08a Compare October 3, 2026 07:28

@tobyhede tobyhede left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed together with #1015. No blocking finding. Audited x/sys v0.44.0→v0.48.0 against the directly used Unix Flock, Mmap/Mprotect/Mlock/Munmap/Getrlimit/Madvise and Windows LockFileEx/UnlockFileEx/VirtualAlloc/VirtualFree/VirtualLock paths. The upstream diff does not change those used primitives; broader changes concern other syscall wrappers, constants, CPU detection and fixes. Security-sensitive locking and guest memory behavior still require runtime validation, which now passes. Go 1.26 matches the existing root mise pin, though it raises the Go module's consumer minimum.

Requested Dependabot rebase onto current main to include tests-golang.yml. Validated head 18be08a. Tests (Go) passed: Go lint, WASI core/no-http checks, guest lint/tests/release builds and import checks, Go format/vet/tests on Linux (including 386), macOS and Windows, and live ZeroKMS tests/examples. Refresh-lock replay tests passed on Linux and macOS; the Windows Go binding job also passed. Linux CI requires successful memory locking instead of allowing a lock-refusal skip. Test JS, Test EQL, CodeQL and OSV also passed on this head.

Go validation: https://github.com/cipherstash/stack/actions/runs/37106455673

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant