Skip to content

chore(agent): build with Go 1.26.8 toolchain - #1

Merged
dabelle merged 2 commits into
mainfrom
chore/go-toolchain-1.26.8
Sep 15, 2026
Merged

dabelle merged 2 commits into
mainfrom
chore/go-toolchain-1.26.8

Conversation

@dabelle

@dabelle dabelle commented Sep 15, 2026

Copy link
Copy Markdown
Collaborator

govulncheck currently reports 7 vulnerabilities reachable from the agent. Five
are stdlib issues fixed in go1.26.6: net/url, crypto/tls (x2), encoding/asn1
and net/http. Binaries built off the 1.25 line carry all five, which includes
the v0.1.0 tarballs on the release page.

Both CI and the release workflow resolve their Go version from agent/go.mod,
so the toolchain directive is the thing that actually changes what gets
shipped. Pinned it rather than raising the go directive so the minimum
version needed to build from source stays 1.25.0.

Takes the reachable count from 7 to 2. The remaining two are daemon-side Moby
issues (CVE-2026-34040, CVE-2026-33997) reached through the docker client
import, with no fixed module version published upstream.

Verified locally under 1.26.8: build, full test suite, golangci-lint clean.
CI had no signal on the branch because it only triggers on main or a PR, so
this run is the first real check.

Note that merging this does not fix the published v0.1.0 binaries. That needs
a v0.1.1 tag to rebuild them.

thetechnologist1911 added 2 commits September 15, 2026 09:54
govulncheck reports 5 reachable stdlib vulnerabilities in binaries built
with the 1.25 line: net/url, crypto/tls (x2), encoding/asn1 and net/http.
All are fixed in go1.26.6. CI and the release workflow both resolve their
Go version from agent/go.mod, so pinning the toolchain there is what
actually changes the shipped binaries.

Pin `toolchain` rather than raising the `go` directive so the minimum
language version to build from source stays 1.25.0.

After: 7 reachable vulnerabilities drop to 2, both daemon-side Moby issues
(CVE-2026-34040, CVE-2026-33997) reached only through the docker client
import, with no fixed module version published.
The S3 e2e pulled `minio/minio` by bare name. That repository no longer
exists on Docker Hub, so the job fails at the pull with "access denied"
before any agent code runs. Nothing in the repo changed; the image moved
out from under us while the tree sat idle.

quay.io is MinIO's own registry and carries the same releases. Pinned to a
specific RELEASE tag rather than floating, since an unpinned reference is
what let this break without a single failing run to point at.
@dabelle
dabelle merged commit d91d235 into main Sep 15, 2026
4 checks passed
@dabelle
dabelle deleted the chore/go-toolchain-1.26.8 branch September 15, 2026 23:45
dabelle pushed a commit that referenced this pull request Sep 19, 2026
chore(agent): build with Go 1.26.8 toolchain
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant