Repository navigation
Fix govulncheck findings and bump Go toolchain - #123
Closed
andrewkroh wants to merge 1 commit into
Closed
andrewkroh wants to merge 1 commit into
andrewkroh wants to merge 1 commit into
Conversation
govulncheck reports 7 reachable vulnerabilities in grpc, x/net, x/text, pgx and spdystream. Our code calls the affected functions, for example through http.Client.Do, sql.Open and remotecommand. Upgrade each module to a release that has the fix. x/text v0.39.0 requires x/net v0.56.0, so x/net goes to v0.56.0 and not to the v0.55.0 that the advisory lists. Also raise the toolchain directive to go1.26.8. The old toolchain go1.25.6 is no longer a supported Go release and it does not have the standard library security fixes. The minimum "go" directive is unchanged. govulncheck now reports no vulnerabilities that the code calls. [git-generate] go get \ google.golang.org/grpc@v1.83.1 \ golang.org/x/text@v0.39.0 \ golang.org/x/net@v0.56.0 \ github.com/jackc/pgx/v5@v5.9.2 \ github.com/moby/spdystream@v0.5.1 go mod edit -toolchain=go1.26.8 go mod tidy
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Forgot that we use release-1.28 branch. Closing
govulncheck reports 7 reachable vulnerabilities in grpc, x/net, x/text, pgx and spdystream. Our code calls the affected functions, for example through http.Client.Do, sql.Open and remotecommand.
Upgrade each module to a release that has the fix. x/text v0.39.0 requires x/net v0.56.0, so x/net goes to v0.56.0 and not to the v0.55.0 that the advisory lists.
Also raise the toolchain directive to go1.26.8. The old toolchain go1.25.6 is no longer a supported Go release and it does not have the standard library security fixes. The minimum "go" directive is unchanged.
govulncheck now reports no vulnerabilities that the code calls.
(For the uninitiated, git-generate is a tool for recreating mechanical commits.)