Repository navigation
fix: require go 1.26.8 to clear standard library advisories - #15
Merged
Merged
Conversation
Snyk reported 11 issues across 927 vulnerable paths, 9 high and 2 medium. Every one of them is in the Go standard library rather than a dependency: std/crypto/tls (x2) std/net std/crypto/x509 std/net/http std/encoding/asn1 std/net/textproto std/encoding/xml std/net/url std/mime std/os The standard library that matters is the one belonging to the toolchain that compiles the module, so the remedy is a toolchain requirement rather than a dependency change. No third-party module is implicated, and no replace directive is involved. The highest fixed-in version across the advisories is 1.26.6. This raises the go directive to 1.26.8, the latest release on that line, which keeps some headroom without moving to a new language version. Raising the go directive rather than adding a toolchain directive is deliberate. A toolchain line expresses a preference that GOTOOLCHAIN=local overrides, whereas the go directive is a floor: a consumer building this module cannot quietly link a standard library that still carries these advisories. CI needs no change. The workflows request go-version '1.26', which already resolves to the newest patch on that line. Verified with the 1.26.8 toolchain: snyk test reports no vulnerable paths across the same 318 dependencies, and go build, go vet, and go test all pass. Assisted-by: Kiro <noreply@kiro.dev> (1.0.116)
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
The Snyk PR check has been failing on unrelated pull requests. It is not a scan
error — Snyk completes successfully and fails the check because it found
issues: 11 issues across 927 vulnerable paths, 9 high and 2 medium.
Every one of them is in the Go standard library, not in a dependency:
std/crypto/tls(×2)std/netstd/crypto/x509std/net/httpstd/encoding/asn1std/net/textprotostd/encoding/xmlstd/net/urlstd/mimestd/osNo third-party module is implicated and no
replacedirective is involved. Thestandard library that matters is the one belonging to the toolchain that
compiles the module, so the remedy is a toolchain requirement rather than a
dependency change.
Changes
Raise the
godirective from1.26.1to1.26.8.The highest fixed-in version across the advisories is
1.26.6;1.26.8is thelatest release on that line, which leaves some headroom without moving to a new
language version.
Raising the
godirective rather than adding atoolchaindirective isdeliberate. A
toolchainline is a preference thatGOTOOLCHAIN=localoverrides, whereas the
godirective is a floor — a consumer building thismodule cannot quietly link a standard library that still carries these
advisories.
Testing
Verified locally against the 1.26.8 toolchain, which
gofetched automaticallyfrom the updated directive:
snyk testgo build ./...go vet ./...go test ./...Dependency count is unchanged at 318, confirming this alters the toolchain floor
and nothing about the dependency graph.
CI
No workflow changes needed.
build-module.yml,lint.yml, andprecommit.ymlall request
go-version: '1.26', which already resolves to the newest patch onthat line.
Notes for review
The Snyk GitHub App has no build environment, so it reads the Go version from
go.modrather than from an installed toolchain. That is why thegodirectiveis what moves this check — bumping only
setup-gowould have fixed the buildswhile leaving Snyk red.
This is independent of #14, which fixed the golangci-lint installer. Both checks
were red for unrelated reasons.