Skip to content

fix: require go 1.26.8 to clear standard library advisories - #15

Merged
major0 merged 1 commit into
mainfrom
fix/go-toolchain-stdlib-cves
Sep 23, 2026
Merged

major0 merged 1 commit into
mainfrom
fix/go-toolchain-stdlib-cves

Conversation

@major0

@major0 major0 commented Sep 23, 2026

Copy link
Copy Markdown
Owner

Summary

The Snyk PR check has been failing on unrelated pull requests. It is not a scan
error — Snyk completes successfully and fails the check because it found
issues: 11 issues across 927 vulnerable paths, 9 high and 2 medium.

Every one of them is in the Go standard library, not in a dependency:

Package Package
std/crypto/tls (×2) std/net
std/crypto/x509 std/net/http
std/encoding/asn1 std/net/textproto
std/encoding/xml std/net/url
std/mime std/os

No third-party module is implicated and no replace directive is involved. The
standard library that matters is the one belonging to the toolchain that
compiles the module, so the remedy is a toolchain requirement rather than a
dependency change.

Changes

Raise the go directive from 1.26.1 to 1.26.8.

The highest fixed-in version across the advisories is 1.26.6; 1.26.8 is the
latest release on that line, which leaves some headroom without moving to a new
language version.

Raising the go directive rather than adding a toolchain directive is
deliberate. A toolchain line is a preference that GOTOOLCHAIN=local
overrides, whereas the go directive is a floor — a consumer building this
module cannot quietly link a standard library that still carries these
advisories.

Testing

Verified locally against the 1.26.8 toolchain, which go fetched automatically
from the updated directive:

Check Before After
snyk test 11 issues, 927 vulnerable paths no vulnerable paths found
go build ./... pass pass
go vet ./... pass pass
go test ./... pass pass

Dependency count is unchanged at 318, confirming this alters the toolchain floor
and nothing about the dependency graph.

CI

No workflow changes needed. build-module.yml, lint.yml, and precommit.yml
all request go-version: '1.26', which already resolves to the newest patch on
that line.

Notes for review

The Snyk GitHub App has no build environment, so it reads the Go version from
go.mod rather than from an installed toolchain. That is why the go directive
is what moves this check — bumping only setup-go would have fixed the builds
while leaving Snyk red.

This is independent of #14, which fixed the golangci-lint installer. Both checks
were red for unrelated reasons.

Snyk reported 11 issues across 927 vulnerable paths, 9 high and 2 medium.
Every one of them is in the Go standard library rather than a dependency:

  std/crypto/tls (x2)   std/net
  std/crypto/x509       std/net/http
  std/encoding/asn1     std/net/textproto
  std/encoding/xml      std/net/url
  std/mime              std/os

The standard library that matters is the one belonging to the toolchain
that compiles the module, so the remedy is a toolchain requirement rather
than a dependency change. No third-party module is implicated, and no
replace directive is involved.

The highest fixed-in version across the advisories is 1.26.6. This raises
the go directive to 1.26.8, the latest release on that line, which keeps
some headroom without moving to a new language version.

Raising the go directive rather than adding a toolchain directive is
deliberate. A toolchain line expresses a preference that GOTOOLCHAIN=local
overrides, whereas the go directive is a floor: a consumer building this
module cannot quietly link a standard library that still carries these
advisories.

CI needs no change. The workflows request go-version '1.26', which already
resolves to the newest patch on that line.

Verified with the 1.26.8 toolchain: snyk test reports no vulnerable paths
across the same 318 dependencies, and go build, go vet, and go test all
pass.

Assisted-by: Kiro <noreply@kiro.dev> (1.0.116)
@major0
major0 merged commit d1dbea3 into main Sep 23, 2026
12 checks passed
@major0
major0 deleted the fix/go-toolchain-stdlib-cves branch September 23, 2026 12:23
@major0
major0 restored the fix/go-toolchain-stdlib-cves branch September 23, 2026 13:28
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant