Skip to content

Bump release Go toolchain to fix stale stdlib CVEs - #326

Merged
braydonk merged 1 commit into
google:mainfrom
gw0:gw0/bump-dependencies-fix-cve
Sep 24, 2026
Merged

braydonk merged 1 commit into
google:mainfrom
gw0:gw0/bump-dependencies-fix-cve

Conversation

@gw0

@gw0 gw0 commented Sep 23, 2026

Copy link
Copy Markdown
Contributor

Summary

  • .github/workflows/release.yaml pinned Go builds to go-version: 1.24, which is now past Go's
    security-backport window (only the two newest majors get stdlib patches) — release binaries stopped picking up
    stdlib fixes for crypto/tls, net/url, archive/tar, html/template, etc.
  • Switch it to go-version-file: go.mod (keeps check-latest: true) so the release build always tracks the same
    Go version as the rest of the project, instead of drifting on its own again.
  • Bump go.mod's toolchain directive from go1.24.8 to go1.27.1.

Downstream consumers maintain a Trivy suppression list for CVEs baked into prebuilt dockerfmt binaries (e.g. https://github.com/gw0/docker-claude-code/blob/main/.trivyignore.yaml). This fixes the root cause upstream instead of relying on per-consumer suppressions.

Test plan

  • go mod tidy — clean, no go.sum changes
  • go vet (matching make vet) — clean
  • go test ./... — all packages pass
  • make integrationtest — passes
  • Built the binary with each toolchain and scanned with Trivy (trivy rootfs, gobinary analyzer):
    • go1.24.8 (before): 36 vulnerabilities (1 CRITICAL, 21 HIGH, 13 MEDIUM, 1 LOW)
    • go1.27.1 (after): 0 vulnerabilities

@google-cla

google-cla Bot commented Sep 23, 2026

Copy link
Copy Markdown

Thanks for your pull request! It looks like this may be your first contribution to a Google open source project. Before we can look at your pull request, you'll need to sign a Contributor License Agreement (CLA).

View this failed invocation of the CLA check for more information.

For the most up to date status, view the checks section at the bottom of the pull request.

@gw0

gw0 commented Sep 23, 2026 •

Copy link
Copy Markdown
Contributor Author

Unable to sign CLA... Creating a new Google Account requires a email verification (no problem) and a phone number, for this it says "This phone number can't receive calls or SMS from Google" (it is a normal working phone number) and requires a QR code verification with your phone, after completing phone says "You're now verified. Thanks for taking this step to help keep Google services safe", but on the web page it refuses to continue with "Please try again with a phone that is connected to a phone number or SIM".

Update: Managed to sign CLA.

@braydonk braydonk left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for the PR, I have one suggestion.

Comment thread .github/workflows/release.yaml Outdated
uses: actions/setup-go@v5
with:
go-version: 1.24
go-version-file: go.mod

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I would rather not rely on the toolchain directive in go.mod... Would you be willing to add a .go-version file and refer to it here? The action docs seem to indicate this is an option. If it's swapped to this, I might be able to set up renovate on this repo to automatically bump the version of Go I use anytime a new Go version comes out.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Done, makes sense. I opened a PR to add Renovate #327.

go-version: 1.24 in release.yaml fell out of Go's security-backport
window, so release binaries stopped getting stdlib patches. Track a
.go-version instead and bump toolchain to go1.27.1.
@braydonk

Copy link
Copy Markdown
Collaborator

Ignoring the zizmor warnings for this PR I'll follow up on those later

@braydonk
braydonk merged commit 1cb82be into google:main Sep 24, 2026
10 of 11 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants