chore: update Go toolchain to 1.27.1 and refresh dependencies - #14
Merged
gitrgoliveira merged 2 commits intoSep 22, 2026
Merged
Conversation
Bumps go.mod to Go 1.27.1 (latest stable) and CI's go-version pin from 1.26 to 1.27, fixing three stdlib CVEs present in 1.26.4 (govulncheck: GO-2026-6090, GO-2026-5972, GO-2026-5856). Also refreshes go.sum via `go get -u` across direct and applicable indirect deps (testify, pgx, otel, grpc, protobuf, go-kms-wrapping, etc.), keeping armon/go-metrics and hashicorp/go-metrics on the versions vault/sdk's compat shim still supports. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
v1.84.0 (picked up by the earlier go get -u) reintroduces the xDS server panic fixed in v1.83.2 (GHSA-2v4p-qf9q-27wj); the fix isn't in any stable release yet, only a v1.85.0-dev pre-release. Pinning back to v1.83.2 keeps govulncheck clean, matching the CI security job that caught this. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
gitrgoliveira
deleted the
worktree-bridge-cse_01CxbpfsrBN3GeMsF8gaMHkW
branch
September 22, 2026 11:18
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
go.modto Go 1.27.1 (latest stable) and the CIgo-versionpin from1.26to1.27.go.sum/go.modviago get -uacross direct deps (testify) and applicable indirect deps (pgx, otel, grpc, protobuf, go-kms-wrapping, moby, etc.), keepingarmon/go-metricsandhashicorp/go-metricson the versionsvault/sdk's compat shim still supports (bumping either further breaks thegithub.com/hashicorp/go-metrics/compatimport path).Why
govulncheckflagged 3 stdlib vulnerabilities reachable from this plugin's code on Go 1.26.4 (GO-2026-6090,GO-2026-5972,GO-2026-5856— TLS/ASN.1 issues incrypto/tlsandencoding/asn1). All are fixed as of Go 1.27.1, andgovulnchecknow reports 0 vulnerabilities reachable from this module's code.One remaining flagged issue (
GO-2026-6443ingoogle.golang.org/grpc) has no stable fix yet — only av1.85.0-devpre-release fixes it — so it's left on the latest stablev1.84.0.Test plan
go build ./...go vet ./...go test ./...go mod verifygofmt -l .(clean)make lint— golangci-lint (0 issues), staticcheck (clean), gosec (0 issues) all pass; the finalgovulncheckstep inmake lintstill exits non-zero solely due to the unfixedGO-2026-6443grpc issue noted above (no stable release fixes it yet)🤖 Generated with Claude Code