From 864bc8ca7256f042e88d97431e5761c0263b0cda Mon Sep 17 00:00:00 2001 From: Phil Leggetter Date: Fri, 7 Aug 2026 16:30:19 +0100 Subject: [PATCH 1/2] chore(deps): bump golang.org/x/crypto to v0.52.0 Clears all 13 open Dependabot alerts on the default branch: 7 critical, 2 high and 4 moderate, every one of them golang.org/x/crypto and every one fixed in 0.52.0. golang.org/x/text comes along as a transitive requirement of the new version. Nothing else in go.mod moves. x/crypto is an indirect dependency and `go mod why` reports that the main module does not import it, so exposure was limited, but the alerts are real and the bump is free. Co-Authored-By: Claude Opus 5 (1M context) Claude-Session: https://claude.ai/code/session_01HHJQ1QSdKmJMivqw7SER6t --- go.mod | 4 ++-- go.sum | 16 ++++++++-------- 2 files changed, 10 insertions(+), 10 deletions(-) diff --git a/go.mod b/go.mod index 8f57eff..e342a50 100644 --- a/go.mod +++ b/go.mod @@ -69,10 +69,10 @@ require ( github.com/xo/terminfo v0.0.0-20220910002029-abceb7e1c41e // indirect github.com/yosida95/uritemplate/v3 v3.0.2 // indirect go.yaml.in/yaml/v3 v3.0.4 // indirect - golang.org/x/crypto v0.45.0 // indirect + golang.org/x/crypto v0.52.0 // indirect golang.org/x/oauth2 v0.35.0 // indirect golang.org/x/sync v0.20.0 // indirect - golang.org/x/text v0.31.0 // indirect + golang.org/x/text v0.37.0 // indirect golang.org/x/time v0.15.0 // indirect gopkg.in/check.v1 v1.0.0-20201130134442-10cb98267c6c // indirect gopkg.in/yaml.v2 v2.4.0 // indirect diff --git a/go.sum b/go.sum index c86a716..0e2c9c9 100644 --- a/go.sum +++ b/go.sum @@ -173,8 +173,8 @@ go.yaml.in/yaml/v3 v3.0.4 h1:tfq32ie2Jv2UxXFdLJdh3jXuOzWiL1fo0bu/FbuKpbc= go.yaml.in/yaml/v3 v3.0.4/go.mod h1:DhzuOOF2ATzADvBadXxruRBLzYTpT36CKvDb3+aBEFg= golang.org/x/crypto v0.0.0-20190308221718-c2843e01d9a2/go.mod h1:djNgcEr1/C05ACkg1iLfiJU5Ep61QUkGW8qpdssI0+w= golang.org/x/crypto v0.0.0-20210921155107-089bfa567519/go.mod h1:GvvjBRRGRdwPK5ydBHafDWAxML/pGHZbMvKqRZ5+Abc= -golang.org/x/crypto v0.45.0 h1:jMBrvKuj23MTlT0bQEOBcAE0mjg8mK9RXFhRH6nyF3Q= -golang.org/x/crypto v0.45.0/go.mod h1:XTGrrkGJve7CYK7J8PEww4aY7gM3qMCElcJQ8n8JdX4= +golang.org/x/crypto v0.52.0 h1:RMs7fP2rXdep0CftQlK8Uf+kibLm7qkCcradZWYz988= +golang.org/x/crypto v0.52.0/go.mod h1:1QgfPxDqh0T2M/elOJtp9RvuR95kVjir0e6/BvEmGbc= golang.org/x/exp v0.0.0-20231006140011-7918f672742d h1:jtJma62tbqLibJ5sFQz8bKtEM8rJBtfilJ2qTU199MI= golang.org/x/exp v0.0.0-20231006140011-7918f672742d/go.mod h1:ldy0pHrwJyGW56pPQzzkH36rKxoZW1tw7ZJpeKx+hdo= golang.org/x/mod v0.6.0-dev.0.20220419223038-86c51ed26bb4/go.mod h1:jJ57K6gSWd91VN4djpZkiMVwK6gcyfeH4XE8wZrZaV4= @@ -184,8 +184,8 @@ golang.org/x/net v0.0.0-20190620200207-3b0461eec859/go.mod h1:z5CRVTTTmAJ677TzLL golang.org/x/net v0.0.0-20200520004742-59133d7f0dd7/go.mod h1:qpuaurCH72eLCgpAm/N6yyVIVM9cpaDIP3A8BGJEC5A= golang.org/x/net v0.0.0-20210226172049-e18ecbb05110/go.mod h1:m0MpNAwzfU5UDzcl9v0D8zg8gWTRqZa9RBIspLL5mdg= golang.org/x/net v0.0.0-20220722155237-a158d28d115b/go.mod h1:XRhObCWvk6IyKnWLug+ECip1KBveYUHfp+8e9klMJ9c= -golang.org/x/net v0.47.0 h1:Mx+4dIFzqraBXUugkia1OOvlD6LemFo1ALMHjrXDOhY= -golang.org/x/net v0.47.0/go.mod h1:/jNxtkgq5yWUGYkaZGqo27cfGZ1c5Nen03aYrrKpVRU= +golang.org/x/net v0.54.0 h1:2zJIZAxAHV/OHCDTCOHAYehQzLfSXuf/5SoL/Dv6w/w= +golang.org/x/net v0.54.0/go.mod h1:Sj4oj8jK6XmHpBZU/zWHw3BV3abl4Kvi+Ut7cQcY+cQ= golang.org/x/oauth2 v0.0.0-20180821212333-d2e6202438be/go.mod h1:N/0e6XlmueqKjAGxoOufVs8QHGRruUQn6yWY3a++T0U= golang.org/x/oauth2 v0.35.0 h1:Mv2mzuHuZuY2+bkyWXIHMfhNdJAdwW3FuWeCPYN5GVQ= golang.org/x/oauth2 v0.35.0/go.mod h1:lzm5WQJQwKZ3nwavOZ3IS5Aulzxi68dUSgRHujetwEA= @@ -220,15 +220,15 @@ golang.org/x/text v0.3.2/go.mod h1:bEr9sfX3Q8Zfm5fL9x+3itogRgK3+ptLWKqgva+5dAk= golang.org/x/text v0.3.3/go.mod h1:5Zoc/QRtKVWzQhOtBMvqHzDpF6irO9z98xDceosuGiQ= golang.org/x/text v0.3.7/go.mod h1:u+2+/6zg+i71rQMx5EYifcz6MCKuco9NR6JIITiCfzQ= golang.org/x/text v0.4.0/go.mod h1:mrYo+phRRbMaCq/xk9113O4dZlRixOauAjOtrjsXDZ8= -golang.org/x/text v0.31.0 h1:aC8ghyu4JhP8VojJ2lEHBnochRno1sgL6nEi9WGFGMM= -golang.org/x/text v0.31.0/go.mod h1:tKRAlv61yKIjGGHX/4tP1LTbc13YSec1pxVEWXzfoeM= +golang.org/x/text v0.37.0 h1:Cqjiwd9eSg8e0QAkyCaQTNHFIIzWtidPahFWR83rTrc= +golang.org/x/text v0.37.0/go.mod h1:a5sjxXGs9hsn/AJVwuElvCAo9v8QYLzvavO5z2PiM38= golang.org/x/time v0.15.0 h1:bbrp8t3bGUeFOx08pvsMYRTCVSMk89u4tKbNOZbp88U= golang.org/x/time v0.15.0/go.mod h1:Y4YMaQmXwGQZoFaVFk4YpCt4FLQMYKZe9oeV/f4MSno= golang.org/x/tools v0.0.0-20180917221912-90fa682c2a6e/go.mod h1:n7NCudcB/nEzxVGmLbDWY5pfWTLqBcC2KZ6jyYvM4mQ= golang.org/x/tools v0.0.0-20191119224855-298f0cb1881e/go.mod h1:b+2E5dAYhXwXZwtnZ6UAqBI28+e2cm9otk0dWdXHAEo= golang.org/x/tools v0.1.12/go.mod h1:hNGJHUnrk76NpqgfD5Aqm5Crs+Hm0VOH/i9J2+nxYbc= -golang.org/x/tools v0.42.0 h1:uNgphsn75Tdz5Ji2q36v/nsFSfR/9BRFvqhGBaJGd5k= -golang.org/x/tools v0.42.0/go.mod h1:Ma6lCIwGZvHK6XtgbswSoWroEkhugApmsXyrUmBhfr0= +golang.org/x/tools v0.44.0 h1:UP4ajHPIcuMjT1GqzDWRlalUEoY+uzoZKnhOjbIPD2c= +golang.org/x/tools v0.44.0/go.mod h1:KA0AfVErSdxRZIsOVipbv3rQhVXTnlU6UhKxHd1seDI= golang.org/x/xerrors v0.0.0-20190717185122-a985d3407aa7/go.mod h1:I/5z698sn9Ka8TeJc9MKroUUfqBBauWjQqLJ2OPfmY0= golang.org/x/xerrors v0.0.0-20191204190536-9bdfabe68543 h1:E7g+9GITq07hpfrRu66IVDexMakfv52eLZ2CXBWiKr4= golang.org/x/xerrors v0.0.0-20191204190536-9bdfabe68543/go.mod h1:I/5z698sn9Ka8TeJc9MKroUUfqBBauWjQqLJ2OPfmY0= From 417e205597dedceb6e0fb63f69edbad52d07e826 Mon Sep 17 00:00:00 2001 From: Phil Leggetter Date: Fri, 7 Aug 2026 16:41:54 +0100 Subject: [PATCH 2/2] ci: build with Go 1.26.5 The pinned 1.24.9 toolchain carries standard-library vulnerabilities that govulncheck flags as reachable from this code, including crypto/x509, crypto/tls, net/http and net/textproto. release.yml builds the published binaries, so the pin decides what ships to users. Verified against both toolchains on the same tree: go1.26.1 10 vulnerabilities (1 module + standard library) go1.26.5 1 vulnerability (1 module, no standard library) The remaining one is GO-2026-5932, the unmaintained x/crypto/openpgp package reached transitively through go-github. It is marked "Fixed in: N/A" and no version bump resolves it. Note the pin was already misleading: go.mod declares `go 1.25.0`, above the pinned 1.24.9, so Go was auto-downloading a newer toolchain anyway. test-homebrew-build.yml already derives its version from go.mod and is left alone. Co-Authored-By: Claude Opus 5 (1M context) Claude-Session: https://claude.ai/code/session_01HHJQ1QSdKmJMivqw7SER6t --- .github/workflows/acceptance.yml | 4 ++-- .github/workflows/release.yml | 8 ++++---- .github/workflows/test-npm-build.yml | 2 +- .github/workflows/test.yml | 8 ++++---- 4 files changed, 11 insertions(+), 11 deletions(-) diff --git a/.github/workflows/acceptance.yml b/.github/workflows/acceptance.yml index d496e26..3945285 100644 --- a/.github/workflows/acceptance.yml +++ b/.github/workflows/acceptance.yml @@ -33,7 +33,7 @@ jobs: - name: Set up Go uses: actions/setup-go@v3 with: - go-version: "1.24.9" + go-version: "1.26.5" - name: Run Go Acceptance Tests (slice ${{ matrix.slice }}) run: go test -tags="${{ matrix.tags }}" ./test/acceptance/... -v -timeout 12m @@ -55,7 +55,7 @@ jobs: - name: Set up Go uses: actions/setup-go@v3 with: - go-version: "1.24.9" + go-version: "1.26.5" - name: Run telemetry acceptance tests run: go test -tags=telemetry ./test/acceptance/... -v -timeout 12m diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 3d7c5d2..2eba61f 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -24,7 +24,7 @@ jobs: - name: Set up Go uses: actions/setup-go@v5 with: - go-version: 1.24.9 + go-version: 1.26.5 - name: Run GoReleaser uses: goreleaser/goreleaser-action@v5 with: @@ -56,7 +56,7 @@ jobs: - name: Set up Go uses: actions/setup-go@v5 with: - go-version: 1.24.9 + go-version: 1.26.5 - name: Run GoReleaser uses: goreleaser/goreleaser-action@v5 with: @@ -76,7 +76,7 @@ jobs: - name: Set up Go uses: actions/setup-go@v5 with: - go-version: 1.24.9 + go-version: 1.26.5 - name: Run GoReleaser uses: goreleaser/goreleaser-action@v5 with: @@ -151,7 +151,7 @@ jobs: - name: Set up Go uses: actions/setup-go@v5 with: - go-version: 1.24.9 + go-version: 1.26.5 - name: Build npm binaries with GoReleaser uses: goreleaser/goreleaser-action@v5 diff --git a/.github/workflows/test-npm-build.yml b/.github/workflows/test-npm-build.yml index 4c649f0..6fcb966 100644 --- a/.github/workflows/test-npm-build.yml +++ b/.github/workflows/test-npm-build.yml @@ -16,7 +16,7 @@ jobs: - name: Set up Go uses: actions/setup-go@v5 with: - go-version: 1.24.9 + go-version: 1.26.5 - name: Set up Node.js uses: actions/setup-node@v4 diff --git a/.github/workflows/test.yml b/.github/workflows/test.yml index 425f363..fa84877 100644 --- a/.github/workflows/test.yml +++ b/.github/workflows/test.yml @@ -27,7 +27,7 @@ jobs: - name: Set up Go uses: actions/setup-go@v5 with: - go-version: 1.24.9 + go-version: 1.26.5 - name: Run unit tests run: go test -short ./pkg/... @@ -41,7 +41,7 @@ jobs: - name: Set up Go uses: actions/setup-go@v5 with: - go-version: 1.24.9 + go-version: 1.26.5 - name: Run GoReleaser uses: goreleaser/goreleaser-action@v5 with: @@ -73,7 +73,7 @@ jobs: - name: Set up Go uses: actions/setup-go@v5 with: - go-version: 1.24.9 + go-version: 1.26.5 - name: Run GoReleaser uses: goreleaser/goreleaser-action@v5 with: @@ -92,7 +92,7 @@ jobs: - name: Set up Go uses: actions/setup-go@v5 with: - go-version: 1.24.9 + go-version: 1.26.5 - name: Run GoReleaser uses: goreleaser/goreleaser-action@v5 with: