Repository navigation
Conversation
Releases are built with the toolchain from go.mod (go-version-file). go1.26.6 binaries are affected by the net/http and crypto/tls DoS issues CVE-2026-78667, CVE-2026-78669, CVE-2026-97031 (fixed in 1.26.9/1.27.2).
powerman
previously approved these changes
Oct 10, 2026
…1.27.2 The CI lint toolchain (mise.lock golangci-lint built with go1.26) rejects a go.mod targeting 1.27.2. GOTOOLCHAIN=auto picks up the toolchain directive for builds and tests, and setup-go (go-version-file) honors the toolchain directive for releases, so release binaries still embed the fixed stdlib: CVE-2026-78667, CVE-2026-78669, CVE-2026-97031.
Owner
|
Thanks for the heads-up. It looks like you didn't checked "allow edits by maintainers", so I had to replace this PR with #407 to update linter to fix CI issue. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Releases are built with the toolchain from
go.mod(your sharedpowerman/workflowsbuild.yml usesactions/setup-gowithgo-version-file: 'go.mod'), sov0.25.2shipped with Go 1.26.6, whose stdlib is affected by three HIGH DoS issues fixed in 1.26.9/1.27.2:net/http: DoS via crafted HTTP Range headersnet/http/internal/http2: DoS via excessive HTTP/2 SETTINGScrypto/tls: DoS via multiple ECH outer extension referencesThis PR bumps the
godirective to1.27.2so the next release embeds the fixed stdlib. One-line change.Context: Closes #406 - we scan the foreman-proxy container images (which embed dockerize) with Trivy at
--exit-code 1on HIGH, so release binaries built from the vulnerable stdlib keep failing our scans.