Skip to content

Fix security audit by aligning the Go toolchain - #4

Merged
Distortions81 merged 1 commit into
mainfrom
fix/go-toolchain-audit
Oct 1, 2026
Merged

Distortions81 merged 1 commit into
mainfrom
fix/go-toolchain-audit

Conversation

@Distortions81

@Distortions81 Distortions81 commented Oct 1, 2026 •

Copy link
Copy Markdown
Member

CI installs Go 1.26.5 even when the Docker builder is updated, so its vulnerability audit fails on reachable standard-library vulnerabilities.

Align the module and Docker builder on Go 1.27.1, retain the immutable Alpine image digest, and make CI read its Go version from go.mod. This supersedes the container-only update in #3 once approved and merged.

Validation passed locally: go test ./..., go test -race ./..., go vet ./..., formatting and whitespace checks, the Linux build used by the Dockerfile, govulncheck v1.6.0, and gitleaks v8.29.1 on history and working files.

GitHub CI passed, including the full Docker build, race tests, vet, vulnerability audit, and secret scans. This draft is prepared for approval before merging.

@Distortions81
Distortions81 marked this pull request as ready for review October 1, 2026 02:05
@Distortions81
Distortions81 merged commit 440cb55 into main Oct 1, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant