Skip to content

chore: bump Go toolchain to 1.26.8 - #166

Open
fullstackjam wants to merge 1 commit into
mainfrom
chore/go-1.26
Open

fullstackjam wants to merge 1 commit into
mainfrom
chore/go-1.26

Conversation

@fullstackjam

Copy link
Copy Markdown
Member

What does this PR do?

Bumps the go directive in go.mod from 1.25.12 to 1.26.8. That directive also sets the CI and release toolchain, because every workflow uses setup-go with go-version-file: go.mod.

Why?

  • Release binaries are currently built with go1.25.12. On that toolchain, govulncheck finds 5 stdlib vulnerabilities in our code's call paths:
    • GO-2026-6090 (crypto/tls), GO-2026-5026 (net/http), GO-2026-6218 (net/url): reached through updater.DownloadAndReplace, httputil.Do, and config.versionTransport
    • GO-2026-6088 (encoding/xml): reached through snapshot/dock.go plist parsing
    • GO-2026-5972 (encoding/asn1): reached through the TLS path in the self-updater
  • Go 1.25 is out of support now that 1.27 has shipped (only 1.27.x and 1.26.x get fixes), so staying on the 1.25 line means no patches for the next CVE.

Testing

  • go vet ./... passes (go1.26.8)
  • make test-unit (L1): 24/24 packages ok
  • golangci-lint v2.11.4 run ./...: 0 issues. The pinned lint binary is itself built with Go 1.26, so it can lint a 1.26 module.
  • govulncheck on go1.26.8: 0 reachable vulnerabilities. One remaining module finding is Windows-only (golang.org/x/sys GO-2026-5024), is unreachable here, and will be handled in a follow-up deps PR.
  • make build + ./openboot version smoke run; the binary reports go1.26.8
  • Relevant tests added or updated: n/a, toolchain-only change

Cross-repo checklist

  • Does this need a docs/content update in openboot.dev? No
  • Does this change the CLI ↔ server API contract? No

Notes for reviewer

The only other change is updating "Go 1.25" to "Go 1.26" in AGENTS.md. This is the first of a planned series; the follow-ups are separate PRs:

  1. GitHub Actions off Node 20. CI already warns that checkout@v4, setup-go@v5, and golangci-lint-action@v7 are being forced onto Node 24.
  2. Minor dependency bumps: bubbletea, lipgloss, cobra, testify, x/term, x/sys.
  3. bubbles and huh to v1, with a manual TUI check.

Release binaries are built from the go.mod version (setup-go uses
go-version-file), so they were compiled with go1.25.12. govulncheck
reports five stdlib vulnerabilities reachable from our code on that
toolchain (crypto/tls, net/http, net/url via the self-updater and
httputil.Do; encoding/xml via snapshot dock plist parsing;
encoding/asn1). Go 1.25 is also out of support since the 1.27 release.

On go1.26.8 govulncheck reports 0 reachable vulnerabilities; vet,
L1 (make test-unit) and golangci-lint v2.11.4 are clean.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant