Skip to content

Security: bump Go toolchain to 1.26.6 - #4

Merged
hrodrig merged 1 commit into
developfrom
security/go-1.26.6
Sep 2, 2026
Merged

hrodrig merged 1 commit into
developfrom
security/go-1.26.6

Conversation

@hrodrig

@hrodrig hrodrig commented Sep 2, 2026

Copy link
Copy Markdown
Owner

Summary

  • Bump minimum Go from 1.26.5 to 1.26.6 in go.mod and Dockerfile.
  • Sync README Go badge / build requirements.
  • Record stdlib Grype findings under [Unreleased] in CHANGELOG.

Why

make docker-scan on 1.26.5 failed with High stdlib GO-2026-5026, 5972, 6088, 6090, 5942, and Medium 6218 (fixed in 1.26.6).

Test plan

  • make release-check (lint, test, cover ≥80%, govulncheck, docker-scan — no vulnerabilities)

Made with Cursor

Grype docker-scan on 1.26.5 reported High stdlib GO-2026-* (fixed in 1.26.6).
Sync go.mod, Dockerfile, README Go badge, and CHANGELOG [Unreleased].

Co-authored-by: Cursor <cursoragent@cursor.com>
@hrodrig
hrodrig merged commit a402295 into develop Sep 2, 2026
9 checks passed
@hrodrig
hrodrig deleted the security/go-1.26.6 branch September 2, 2026 00:32
@hrodrig hrodrig mentioned this pull request Sep 2, 2026
3 tasks
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant