Skip to content

Update Go toolchain, dependencies and action pins - #2

Merged
dvdksn merged 1 commit into
mainfrom
update-dependencies
Aug 24, 2026
Merged

dvdksn merged 1 commit into
mainfrom
update-dependencies

Conversation

@dvdksn

@dvdksn dvdksn commented Aug 24, 2026

Copy link
Copy Markdown
Collaborator

Pre-release dependency review.

govulncheck flagged five standard-library vulnerabilities that this code
actually reaches on go1.26.4 — GO-2026-6218 (net/url), GO-2026-6090 and
GO-2026-5856 (crypto/tls), GO-2026-5972 (encoding/asn1) and GO-2026-5026
(net/http). All are fixed by go1.26.6. This matters more than usual here
because the release binary is statically linked, so the standard library ships
inside the artifact rather than being picked up from the host at run time.

  • Go directive 1.26.4 → 1.26.7, the current patch release of the same minor
  • stretchr/testify 1.11.1 → 1.12.1, which internalises go-spew and
    difflib and moves to go.yaml.in/yaml/v3 — three indirect deps become one
  • golang.org/x/sys 0.46.0 → 0.47.0
  • Action pins: checkout v7.0.0 → v7.0.1, setup-go v6.5.0 → v7.0.0,
    attest-build-provenance v4.1.1 → v4.2.2, action-gh-release v3.0.1 →
    v3.0.2, all re-pinned by commit SHA

setup-go v7 is a major bump but the changelog is an ESM migration and a cache
dependency update; go-version-file and cache are unchanged.

Staying on the 1.26 line rather than moving to 1.27.0 keeps this a security-only
change ahead of a release. Worth doing 1.27 deliberately as its own PR.

Test plan

  • make test (-count=2), make vet, gofmt -l ., make build-all on
    go1.26.7
  • govulncheck ./... — was 5 reachable, now reports none

🤖 Generated with Claude Code

govulncheck reported five standard-library vulnerabilities reachable
from this code on go1.26.4 — GO-2026-6218, -6090, -5972, -5856 and
-5026 — all fixed by go1.26.6. The released binary is statically
linked, so the standard library ships inside the artifact rather than
being resolved at run time.

- go directive 1.26.4 -> 1.26.7
- testify 1.11.1 -> 1.12.1, which internalises go-spew and difflib and
  moves to go.yaml.in/yaml/v3, taking three indirect deps down to one
- golang.org/x/sys 0.46.0 -> 0.47.0
- checkout v7.0.0 -> v7.0.1, setup-go v6.5.0 -> v7.0.0,
  attest-build-provenance v4.1.1 -> v4.2.2, action-gh-release v3.0.1
  -> v3.0.2

govulncheck reports no vulnerabilities afterwards.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@dvdksn
dvdksn merged commit d7cab6e into main Aug 24, 2026
1 check passed
@dvdksn
dvdksn deleted the update-dependencies branch August 24, 2026 15:05
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant