Skip to content

chore: update Go toolchain to 1.27.1 and refresh dependencies - #14

Merged
gitrgoliveira merged 2 commits into
mainfrom
worktree-bridge-cse_01CxbpfsrBN3GeMsF8gaMHkW
Sep 22, 2026
Merged

gitrgoliveira merged 2 commits into
mainfrom
worktree-bridge-cse_01CxbpfsrBN3GeMsF8gaMHkW

Conversation

@gitrgoliveira

Copy link
Copy Markdown
Owner

Summary

  • Bump go.mod to Go 1.27.1 (latest stable) and the CI go-version pin from 1.26 to 1.27.
  • Refresh go.sum/go.mod via go get -u across direct deps (testify) and applicable indirect deps (pgx, otel, grpc, protobuf, go-kms-wrapping, moby, etc.), keeping armon/go-metrics and hashicorp/go-metrics on the versions vault/sdk's compat shim still supports (bumping either further breaks the github.com/hashicorp/go-metrics/compat import path).

Why

govulncheck flagged 3 stdlib vulnerabilities reachable from this plugin's code on Go 1.26.4 (GO-2026-6090, GO-2026-5972, GO-2026-5856 — TLS/ASN.1 issues in crypto/tls and encoding/asn1). All are fixed as of Go 1.27.1, and govulncheck now reports 0 vulnerabilities reachable from this module's code.

One remaining flagged issue (GO-2026-6443 in google.golang.org/grpc) has no stable fix yet — only a v1.85.0-dev pre-release fixes it — so it's left on the latest stable v1.84.0.

Test plan

  • go build ./...
  • go vet ./...
  • go test ./...
  • go mod verify
  • gofmt -l . (clean)
  • make lint — golangci-lint (0 issues), staticcheck (clean), gosec (0 issues) all pass; the final govulncheck step in make lint still exits non-zero solely due to the unfixed GO-2026-6443 grpc issue noted above (no stable release fixes it yet)

🤖 Generated with Claude Code

gitrgoliveira and others added 2 commits September 22, 2026 11:37
Bumps go.mod to Go 1.27.1 (latest stable) and CI's go-version pin from
1.26 to 1.27, fixing three stdlib CVEs present in 1.26.4 (govulncheck:
GO-2026-6090, GO-2026-5972, GO-2026-5856). Also refreshes go.sum via
`go get -u` across direct and applicable indirect deps (testify, pgx,
otel, grpc, protobuf, go-kms-wrapping, etc.), keeping
armon/go-metrics and hashicorp/go-metrics on the versions vault/sdk's
compat shim still supports.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
v1.84.0 (picked up by the earlier go get -u) reintroduces the xDS
server panic fixed in v1.83.2 (GHSA-2v4p-qf9q-27wj); the fix isn't
in any stable release yet, only a v1.85.0-dev pre-release. Pinning
back to v1.83.2 keeps govulncheck clean, matching the CI security
job that caught this.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@gitrgoliveira
gitrgoliveira merged commit 389a7aa into main Sep 22, 2026
8 checks passed
@gitrgoliveira
gitrgoliveira deleted the worktree-bridge-cse_01CxbpfsrBN3GeMsF8gaMHkW branch September 22, 2026 11:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant