Skip to content

fix(go): clear the govulncheck findings and track supported Go releases - #126

Merged
JeanExtreme002 merged 1 commit into
mainfrom
fix/go-vuln-scan
Oct 9, 2026
Merged

JeanExtreme002 merged 1 commit into
mainfrom
fix/go-vuln-scan

Conversation

@JeanExtreme002

Copy link
Copy Markdown
Owner

Why

The Go Package workflow failed on the 1.6.2 bump (runs 37953153947 and 37953225503) at the make security step on the 1.26.x leg. govulncheck reported nine standard library findings (GO-2026-6603 through GO-2026-6617, in net/http, net/textproto and crypto/tls) plus the matching golang.org/x/net advisories.

Two things lined up:

  • The runner resolved 1.26.x to Go 1.26.8 from its toolcache. The fixes landed in 1.26.9, released today, but setup-go only looks past the cache when check-latest is set.
  • go.mod required golang.org/x/net v0.58.0; the fix is in v0.60.0.

What

  • setup-go now runs with check-latest: true, so a new patch release is picked up as soon as it ships instead of whenever the runner image refreshes.
  • golang.org/x/net bumped to v0.61.0 (x/text follows to v0.43.0). Every patched x/net release requires go 1.26.0, so the module directive moves from 1.25.0 to 1.26.0 and the matrix becomes 1.26.x / 1.27.x. Go 1.25 left the two-release support window when 1.27 shipped, so no supported toolchain is dropped. The go-1.25+ badges in the READMEs and docs now say 1.26+.
  • Static analysis stays pinned to the 1.26.x leg: staticcheck v0.8.1 (the latest) cannot read Go 1.27 export data yet. The vulnerability scan runs on the 1.27.x leg.
  • Makefile comment updated to match.

Verification

Both legs reproduced locally with the real toolchains via GOTOOLCHAIN:

Toolchain lint staticcheck test-coverage test-race govulncheck
go1.26.9 ok ok 93.1% ok no vulnerabilities
go1.27.2 ok skipped (see above) 93.1% ok no vulnerabilities

go mod tidy leaves go.mod and go.sum unchanged.

Note on consumers

Raising the module directive to 1.26.0 means go get of the next tagged Go module version needs Go 1.26 or newer. This does not affect go/v1.6.2, which is already tagged.

The 1.26.x leg resolved to Go 1.26.8 from the runner toolcache while the
nine standard library findings are fixed in 1.26.9, released today.
setup-go now runs with check-latest so a patch release is picked up as
soon as it ships.

golang.org/x/net moves from v0.58.0 to v0.61.0 (fixed from v0.60.0).
Every patched x/net requires go 1.26.0, so the module directive follows
and the matrix becomes 1.26.x / 1.27.x. Go 1.25 stopped receiving
security fixes when 1.27 shipped, so nothing supported is dropped.

Static analysis stays on the 1.26.x leg: staticcheck v0.8.1 cannot read
Go 1.27 export data yet.
@JeanExtreme002
JeanExtreme002 merged commit 8070df0 into main Oct 9, 2026
7 checks passed
@github-actions
github-actions Bot deleted the fix/go-vuln-scan branch October 9, 2026 19:05
JeanExtreme002 added a commit that referenced this pull request Oct 9, 2026
Patch release so the next Go module tag requires golang.org/x/net
v0.61.0 (#126) instead of a version with open advisories. Python and
Node move with it because verify-versions refuses a release whose three
declared versions disagree.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant