Skip to content

Commit ed7cb7f

Browse files
committed
ci: run govulncheck on Go 1.26.6 and bump golang.org/x/image
The scanner reported standard library vulnerabilities fixed in Go 1.26.6 and GO-2026-6222 in golang.org/x/image v0.44.0. Keep the module baseline at go 1.26.5 for consumers and move only the scanner toolchain, and take x/image v0.45.0.
1 parent 45406d7 commit ed7cb7f

3 files changed

Lines changed: 10 additions & 9 deletions

File tree

‎.github/workflows/build.yml‎

Lines changed: 4 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -12,11 +12,12 @@ jobs:
1212
GOTOOLCHAIN: local
1313
steps:
1414
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
15-
# Keep the module baseline in go.mod, but run the scanner with Go 1.26.5
16-
# so it uses a fixed standard library (GO-2026-5856).
15+
# Keep the module baseline in go.mod, but run the scanner with Go 1.26.6
16+
# so it uses a fixed standard library (GO-2026-5026, GO-2026-5972,
17+
# GO-2026-6088, GO-2026-6090, GO-2026-6218).
1718
- uses: actions/setup-go@4a3601121dd01d1626a1e23e37211e3254c1c06c # v6.4.0
1819
with:
19-
go-version: "1.26.5"
20+
go-version: "1.26.6"
2021
cache: true
2122
check-latest: true
2223
- run: |

‎go.mod‎

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -111,10 +111,10 @@ require (
111111
go.yaml.in/yaml/v2 v2.4.4 // indirect
112112
go.yaml.in/yaml/v4 v4.0.0-rc.3 // indirect
113113
golang.org/x/crypto v0.54.0 // indirect
114-
golang.org/x/image v0.44.0 // indirect
114+
golang.org/x/image v0.45.0 // indirect
115115
golang.org/x/sync v0.22.0 // indirect
116116
golang.org/x/sys v0.47.0 // indirect
117-
golang.org/x/text v0.40.0 // indirect
117+
golang.org/x/text v0.41.0 // indirect
118118
golang.org/x/time v0.15.0 // indirect
119119
google.golang.org/api v0.291.0 // indirect
120120
google.golang.org/genproto v0.0.0-20260729162451-8efbd57d26e0 // indirect

‎go.sum‎

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -245,8 +245,8 @@ go.yaml.in/yaml/v4 v4.0.0-rc.3 h1:3h1fjsh1CTAPjW7q/EMe+C8shx5d8ctzZTrLcs/j8Go=
245245
go.yaml.in/yaml/v4 v4.0.0-rc.3/go.mod h1:aZqd9kCMsGL7AuUv/m/PvWLdg5sjJsZ4oHDEnfPPfY0=
246246
golang.org/x/crypto v0.54.0 h1:YLIA59K4fiNzHzjnZt2tUJQjQtUWfWbeHBqKtk3eScw=
247247
golang.org/x/crypto v0.54.0/go.mod h1:KWL8ny2AZdGR2cWmzeHrp2azQPGogOv+HeQaVEXC2dk=
248-
golang.org/x/image v0.44.0 h1:+tDekMZED9+LrtB3G5xzRggpVh9CARjZqROla3R3R+I=
249-
golang.org/x/image v0.44.0/go.mod h1:V8K3KE9KKKE+pLpQDOeN18w9oacNSvy1tDOirTu4xtY=
248+
golang.org/x/image v0.45.0 h1:FMb1nTbH5H9vF55SriQHgFw5GnNL9Jg6L25BwXKzhB0=
249+
golang.org/x/image v0.45.0/go.mod h1:n62x/7RqlwXDvGsSU4u6IUTUf6KghUZ9Bt7cG/T9Fx4=
250250
golang.org/x/net v0.57.0 h1:K5+3DljvIuDG9/Jv9rvyMywYNFCQ9RSUY6OOTTkT+tE=
251251
golang.org/x/net v0.57.0/go.mod h1:KpXc8iv+r3XplLAG/f7Jsf9RPszJzdR0f58q9vGOuEU=
252252
golang.org/x/oauth2 v0.36.0 h1:peZ/1z27fi9hUOFCAZaHyrpWG5lwe0RJEEEeH0ThlIs=
@@ -255,8 +255,8 @@ golang.org/x/sync v0.22.0 h1:SZjpbeLmrCk4xhRSZFNZW5gFUeCeFgjekvI/+gfScek=
255255
golang.org/x/sync v0.22.0/go.mod h1:9xrNwdLfx4jkKbNva9FpL6vEN7evnE43NNNJQ2LF3+0=
256256
golang.org/x/sys v0.47.0 h1:o7XGOvZQCADBQQ4Y7VNq2dRWQR7JmOUW8Kxx4ZsNgWs=
257257
golang.org/x/sys v0.47.0/go.mod h1:4GL1E5IUh+htKOUEOaiffhrAeqysfVGipDYzABqnCmw=
258-
golang.org/x/text v0.40.0 h1:Ub2Z6/xjgF1WrYQz2nuITOEegKFtiIy+rieRJ5lHZKs=
259-
golang.org/x/text v0.40.0/go.mod h1:hpnzDAfGV753zIKo+wk3u1bVKCGPbrnF7+7LBF/UHVY=
258+
golang.org/x/text v0.41.0 h1:vz/seA0lnX87Othu2f/0L24RcgrXD9/YFTSuGjj3rH8=
259+
golang.org/x/text v0.41.0/go.mod h1:jvf1O8ajNzZqhSrQBPbutR/EB83Cc0CFrezNQIwbb5M=
260260
golang.org/x/time v0.15.0 h1:bbrp8t3bGUeFOx08pvsMYRTCVSMk89u4tKbNOZbp88U=
261261
golang.org/x/time v0.15.0/go.mod h1:Y4YMaQmXwGQZoFaVFk4YpCt4FLQMYKZe9oeV/f4MSno=
262262
gonum.org/v1/gonum v0.17.0 h1:VbpOemQlsSMrYmn7T2OUvQ4dqxQXU+ouZFQsZOx50z4=

0 commit comments

Comments
 (0)