Skip to content

fix(server): bump Go to 1.25.11 (clear govulncheck stdlib vulns)#65

Merged
dvcdsys merged 1 commit into
developfrom
fix/govulncheck-go-1.25.11
Jun 3, 2026
Merged

fix(server): bump Go to 1.25.11 (clear govulncheck stdlib vulns)#65
dvcdsys merged 1 commit into
developfrom
fix/govulncheck-go-1.25.11

Conversation

@dvcdsys
Copy link
Copy Markdown
Owner

@dvcdsys dvcdsys commented Jun 3, 2026

Unblocks the v0.8.0 release PR (#64): the Security workflow's govulncheck (server) failed on two Go standard-library vulns (not from any app code change), both fixed in go1.25.11:

  • GO-2026-5039net/textproto, reached via githubapi.DeleteWebhook → io.ReadAll
  • GO-2026-5037crypto/x509, reached via tunnels.Installer.Install → io.Copy

CI installs Go from server/go.mod (go-version-file), so bumping the go directive 1.25.10 → 1.25.11 is what moves the build onto the patched stdlib.

Verified locally with the 1.25.11 toolchain:

govulncheck ./...  → No vulnerabilities found. Your code is affected by 0 vulnerabilities.
go build ./...     → ok

Note: CLI (cli/go.mod, go 1.25.0) is not govulncheck-gated and is out of scope for this server release; bump it separately if desired.

🤖 Generated with Claude Code

govulncheck (Security workflow) flagged two Go standard-library
vulnerabilities, both fixed in go1.25.11:

- GO-2026-5039 (net/textproto) — reached via githubapi.DeleteWebhook → io.ReadAll
- GO-2026-5037 (crypto/x509) — reached via tunnels.Installer.Install → io.Copy

CI installs Go from `server/go.mod` (go-version-file), so bumping the
directive to 1.25.11 is what moves the build onto the patched stdlib.
Verified locally with the 1.25.11 toolchain: `govulncheck ./...` now
reports 0 affecting vulnerabilities; build passes.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
@dvcdsys dvcdsys merged commit 5295879 into develop Jun 3, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant