Repository navigation
chore: raise the go directive to 1.26.8 to clear stdlib findings in the scheduled govulncheck - #4616
Merged
Merged
Conversation
reinkrul
requested review from
Dirklectisch,
JorisHeadease,
gerardsn,
stevenvegt and
woutslakhorst
as code owners
October 8, 2026 08:46
reinkrul
force-pushed
the
chore/go-mod-1.26.8
branch
from
October 8, 2026 08:52
bd7ce2f to
701d421
Compare
…he scheduled govulncheck The go directive is the version the scheduled govulncheck tests against; the Docker image already builds with Go 1.27.1. At 1.26.5 the scan on master reported seven fixed standard library issues (GO-2026-6218, GO-2026-6091, GO-2026-6090, GO-2026-6089, GO-2026-6088, GO-2026-5972, GO-2026-5026, all fixed in Go 1.26.6), failing the job every day. 1.26.8 is the latest 1.26 release and what V6.2 and V5.4 already declare. Dependabot does not bump the go directive, so this is done by hand, as in #4430. Assisted by AI
reinkrul
force-pushed
the
chore/go-mod-1.26.8
branch
from
October 8, 2026 08:55
701d421 to
bd61fb2
Compare
stevenvegt
approved these changes
Oct 8, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The scheduled govulncheck on master has failed daily since 2026-10-02. It sets up Go from
go.mod, which still saysgo 1.26.5, so it analyses the 1.26.5 standard library and reports seven issues fixed in Go 1.26.6: GO-2026-6218 (net/url), GO-2026-6091 (html/template), GO-2026-6090 (crypto/tls), GO-2026-6089 (net/http), GO-2026-6088 (encoding/xml), GO-2026-5972 (encoding/asn1) and GO-2026-5026 (x/net/idna). The PR-triggered govulncheck usesstableand is green, which is why it went unnoticed.This raises the directive to 1.26.8, the latest 1.26 release and what V6.2 and V5.4 already declare. The Docker image keeps building with Go 1.27.1 (#4505); the directive is only the minimum. Dependabot does not bump the
godirective (dependabot-core#13520), so this is a manual bump, as in #4430.The same scheduled run also flagged grpc v1.84.0 for GO-2026-6443. That was a vulnerability database error, corrected upstream on 2026-10-06 (the fix commit is an ancestor of the v1.84.0 tag); govulncheck v1.8.0 against master no longer reports it, so no grpc change is needed.
Verified:
go mod tidymakes no further changes,go build ./...passes, andgovulncheck ./...(v1.8.0, Go 1.26.8) reports 0 vulnerabilities on this branch.Assisted by AI