From c82002c4866b03c2101b6a6e31a81703c2d2c900 Mon Sep 17 00:00:00 2001 From: Carlos Herrero Date: Fri, 8 May 2026 11:14:50 +0200 Subject: [PATCH] security: bump Go to 1.26.3 to fix stdlib vulnerabilities Addresses 5 vulnerabilities reported by govulncheck in go1.26.2, including GO-2026-4918 (infinite loop in HTTP/2 transport, net/http/internal/http2). All fixed in go1.26.3. Bumps all modules and the workspace: go.mod, sdk/go.mod, plugins/contrib/go.mod, plugins/contrib/microsoft/keyvault/go.mod, admin/go.mod, go.work. Co-Authored-By: Claude Sonnet 4.6 --- admin/go.mod | 2 +- go.mod | 2 +- go.work | 2 +- plugins/contrib/go.mod | 2 +- plugins/contrib/microsoft/keyvault/go.mod | 2 +- sdk/go.mod | 2 +- 6 files changed, 6 insertions(+), 6 deletions(-) diff --git a/admin/go.mod b/admin/go.mod index 6de0c0d..d19a301 100644 --- a/admin/go.mod +++ b/admin/go.mod @@ -1,6 +1,6 @@ module github.com/cloudblue/chaperone/admin -go 1.26.2 +go 1.26.3 require ( github.com/prometheus/client_model v0.6.2 diff --git a/go.mod b/go.mod index 0edc193..98cd7ae 100644 --- a/go.mod +++ b/go.mod @@ -1,6 +1,6 @@ module github.com/cloudblue/chaperone -go 1.26.2 +go 1.26.3 require github.com/cloudblue/chaperone/sdk v0.1.0 diff --git a/go.work b/go.work index 77648f7..265362d 100644 --- a/go.work +++ b/go.work @@ -1,4 +1,4 @@ -go 1.26.2 +go 1.26.3 use ( . diff --git a/plugins/contrib/go.mod b/plugins/contrib/go.mod index 13a3255..f56f38b 100644 --- a/plugins/contrib/go.mod +++ b/plugins/contrib/go.mod @@ -1,6 +1,6 @@ module github.com/cloudblue/chaperone/plugins/contrib -go 1.26.2 +go 1.26.3 require github.com/cloudblue/chaperone/sdk v0.1.0 diff --git a/plugins/contrib/microsoft/keyvault/go.mod b/plugins/contrib/microsoft/keyvault/go.mod index 64a2a0c..07097de 100644 --- a/plugins/contrib/microsoft/keyvault/go.mod +++ b/plugins/contrib/microsoft/keyvault/go.mod @@ -1,6 +1,6 @@ module github.com/cloudblue/chaperone/plugins/contrib/microsoft/keyvault -go 1.26.2 +go 1.26.3 require ( github.com/Azure/azure-sdk-for-go/sdk/azcore v1.21.1 diff --git a/sdk/go.mod b/sdk/go.mod index f09a817..bc47884 100644 --- a/sdk/go.mod +++ b/sdk/go.mod @@ -1,3 +1,3 @@ module github.com/cloudblue/chaperone/sdk -go 1.26.2 +go 1.26.3