build: move to Go 1.27.1, refresh website dependencies, fix CI gates - #506
Merged
Conversation
Bumps the go-minor group with 1 update: [github.com/klauspost/compress](https://github.com/klauspost/compress). Updates `github.com/klauspost/compress` from 1.19.0 to 1.19.1 - [Release notes](https://github.com/klauspost/compress/releases) - [Commits](klauspost/compress@v1.19.0...v1.19.1) --- updated-dependencies: - dependency-name: github.com/klauspost/compress dependency-version: 1.19.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: go-minor ... Signed-off-by: dependabot[bot] <support@github.com> (cherry picked from commit 0a7157d)
Bumps golang from 1.26.5-alpine3.24 to 1.27.1-alpine3.24. --- updated-dependencies: - dependency-name: golang dependency-version: 1.27.1-alpine3.24 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com> (cherry picked from commit c1ae0ee)
…pdates Bumps the actions-minor group with 9 updates in the / directory: | Package | From | To | | --- | --- | --- | | [actions/checkout](https://github.com/actions/checkout) | `7.0.0` | `7.0.1` | | [docker/setup-buildx-action](https://github.com/docker/setup-buildx-action) | `4.2.0` | `4.3.0` | | [docker/login-action](https://github.com/docker/login-action) | `4.4.0` | `4.6.0` | | [softprops/action-gh-release](https://github.com/softprops/action-gh-release) | `3.0.2` | `3.0.3` | | [actions/setup-python](https://github.com/actions/setup-python) | `6.3.0` | `7.0.0` | | [github/codeql-action/init](https://github.com/github/codeql-action) | `4.37.1` | `4.37.9` | | [github/codeql-action/analyze](https://github.com/github/codeql-action) | `4.37.1` | `4.37.9` | | [github/codeql-action/upload-sarif](https://github.com/github/codeql-action) | `4.37.1` | `4.37.9` | | [anchore/sbom-action](https://github.com/anchore/sbom-action) | `0.24.0` | `0.24.2` | Updates `actions/checkout` from 7.0.0 to 7.0.1 - [Release notes](https://github.com/actions/checkout/releases) - [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md) - [Commits](actions/checkout@v7...3d3c42e) Updates `docker/setup-buildx-action` from 4.2.0 to 4.3.0 - [Release notes](https://github.com/docker/setup-buildx-action/releases) - [Commits](docker/setup-buildx-action@bb05f3f...37fe631) Updates `docker/login-action` from 4.4.0 to 4.6.0 - [Release notes](https://github.com/docker/login-action/releases) - [Commits](docker/login-action@af1e73f...dbcb813) Updates `softprops/action-gh-release` from 3.0.2 to 3.0.3 - [Release notes](https://github.com/softprops/action-gh-release/releases) - [Changelog](https://github.com/softprops/action-gh-release/blob/master/CHANGELOG.md) - [Commits](softprops/action-gh-release@3d0d988...efb3536) Updates `actions/setup-python` from 6.3.0 to 7.0.0 - [Release notes](https://github.com/actions/setup-python/releases) - [Commits](actions/setup-python@ece7cb0...5fda3b9) Updates `github/codeql-action/init` from 4.37.1 to 4.37.9 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@7188fc3...cdf488f) Updates `github/codeql-action/analyze` from 4.37.1 to 4.37.9 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@7188fc3...cdf488f) Updates `github/codeql-action/upload-sarif` from 4.37.1 to 4.37.9 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@7188fc3...cdf488f) Updates `anchore/sbom-action` from 0.24.0 to 0.24.2 - [Release notes](https://github.com/anchore/sbom-action/releases) - [Changelog](https://github.com/anchore/sbom-action/blob/main/RELEASE.md) - [Commits](anchore/sbom-action@e22c389...3ad7283) --- updated-dependencies: - dependency-name: actions/checkout dependency-version: 7.0.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: actions-minor - dependency-name: docker/setup-buildx-action dependency-version: 4.3.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: actions-minor - dependency-name: docker/login-action dependency-version: 4.6.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: actions-minor - dependency-name: softprops/action-gh-release dependency-version: 3.0.3 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: actions-minor - dependency-name: actions/setup-python dependency-version: 7.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: actions-minor - dependency-name: github/codeql-action/init dependency-version: 4.37.9 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: actions-minor - dependency-name: github/codeql-action/analyze dependency-version: 4.37.9 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: actions-minor - dependency-name: github/codeql-action/upload-sarif dependency-version: 4.37.9 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: actions-minor - dependency-name: anchore/sbom-action dependency-version: 0.24.2 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: actions-minor ... Signed-off-by: dependabot[bot] <support@github.com> (cherry picked from commit 743ccb7)
Go 1.26.5 carries five reachable stdlib advisories (GO-2026-6218, GO-2026-6090, GO-2026-6089, GO-2026-5972, GO-2026-5026) that govulncheck flags on every PR. Move go.mod, bench/go.mod, all workflow setup-go pins and the getting-started doc to 1.27.1 (the Docker builder image is bumped in the preceding commit). golangci-lint built against Go 1.26 refuses a Go 1.27 go.mod, so the lint action moves to v2.13.2; it reports zero issues on the current tree.
Docusaurus 3.10.0 -> 3.10.2 and a targeted refresh of the transitive tree: postcss, fast-uri, brace-expansion, js-yaml, nanoid, browserslist, svgo, mermaid, dompurify, qs, @swc/html, baseline-browser-mapping, colord, joi and postcss-selector-parser. mermaid is pinned to 11.x via overrides because 12.0.0 pulls a vulnerable chevrotain/lodash-es chain; qs is overridden to >=6.16.0. gray-matter becomes a declared devDependency because Docusaurus 3.10.2 replaced it internally with @11ty/gray-matter and the site config imports it directly. npm audit now reports only the image-size chain, which has no upstream fix. Site typechecks and builds.
…bot updates The changelog gate treated website/ as release-impacting, so every Dependabot bump of the website lockfile failed for lacking a CHANGELOG entry. website/ is now a non-release path (docs site is published independently of the proxy binary and chart). Two unit tests cover the dependency-only and website-only cases. Dependabot gains an npm entry for /website with grouped version and security updates so future website bumps arrive as one PR instead of one per package.
…t-rule exclusions gosec v2.22.7 cannot type-check Go 1.27 (internal error: package log/slog without types). Every Go-1.27-capable release also ships the newer taint rules G118/G704/G705, whose nine hits here are not applicable: the healthcheck fetches loopback only, the flagged writes are cached JSON bodies with an application/json content type, and the field-batcher goroutine intentionally outlives a single request. Excluded with the rationale inline; zero findings with the new version and exclusion list.
Contributor
PR Quality ReportCompared against base branch Coverage and tests
Compatibility
Performance smokeLower CPU cost (
State
|
This was referenced Sep 12, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Main has been red since Go 1.26.5 picked up five stdlib advisories: every PR fails the
testjob ongovulncheck,Security / staticfails on Trivy's scan of the website lockfile, the nightly image scan fails on the same stdlib CVEs, and the changelog gate rejects every Dependabot website bump. This PR fixes all four causes in one change so the open Dependabot backlog can land and CI is green again.What changed
Toolchain
1.26.5 → 1.27.1ingo.mod,bench/go.mod, the Docker builder image (golang:1.27.1-alpine3.24, from build(deps): bump golang from 1.26.5-alpine3.24 to 1.27.1-alpine3.24 #498) and every workflowsetup-gopin.v2.11.4 → v2.13.2— a lint binary built with Go 1.26 refuses a Go 1.27go.mod.github.com/klauspost/compress1.19.0 → 1.19.1(from build(deps): bump github.com/klauspost/compress from 1.19.0 to 1.19.1 in the go-minor group #485).Website dependencies (
website/, not shipped in the binary or chart)3.10.0 → 3.10.2, plus a targeted refresh ofpostcss,fast-uri,brace-expansion,js-yaml,nanoid,browserslist,svgo,mermaid,dompurify,qs,@swc/html,baseline-browser-mapping,colord,joi,postcss-selector-parser.mermaidpinned to 11.x viaoverrides— 12.0.0 pulls a vulnerablechevrotain/lodash-eschain.qsoverridden to>=6.16.0.gray-matterdeclared as a devDependency: Docusaurus 3.10.2 replaced it internally with@11ty/gray-matter, and the site config imports it directly.npm auditnow reports only theimage-sizechain, which has no upstream fix.CI gates
website/is now a non-release path, so Dependabot website bumps and docs-site-only PRs no longer fail for a missing CHANGELOG entry. Two new unit tests.npmentry for/website(weekly, 7-day cooldown; version updates and security updates each grouped into one PR).CHANGELOG: Security and Changed entries under
[Unreleased], including the CVE mapping for the Go advisories and the rationale for the two dispositions that are not upgrades (image-size, CodeQL request-log finding).Security advisories closed
Plus the 16 Trivy image findings on
stdlib(the CVEs above and CVE-2026-46600, CVE-2026-56858, CVE-2026-56859) and 33 of the 35 open Dependabot npm advisories.Verification (local, Go 1.27.1)
go build ./...,go vet ./...,gofmt -s -lgo test ./...golangci-lint run(v2.13.2)govulncheck ./...fswith the CI argumentsgo.mod,bench/go.mod,website/package-lock.json)docker build+ Trivyimageloki-vl-proxyandhealthcheckbinaries and the base layernpm run typecheck,npm run buildscripts/ci/tests/test_check_changelog_pr.pyscripts/ci/check_changelog_pr.py --base main --head HEADSupersedes
Folded in as cherry-picks: #485, #498, #499.
Superseded by the website refresh (Dependabot will close these once this merges): #484, #488, #489, #490, #491, #492, #496, #497, #500, #501, #502, #503, #504, #505.