Repository navigation
chore(agent): build with Go 1.26.8 toolchain - #1
Merged
Merged
Conversation
added 2 commits
September 15, 2026 09:54
govulncheck reports 5 reachable stdlib vulnerabilities in binaries built with the 1.25 line: net/url, crypto/tls (x2), encoding/asn1 and net/http. All are fixed in go1.26.6. CI and the release workflow both resolve their Go version from agent/go.mod, so pinning the toolchain there is what actually changes the shipped binaries. Pin `toolchain` rather than raising the `go` directive so the minimum language version to build from source stays 1.25.0. After: 7 reachable vulnerabilities drop to 2, both daemon-side Moby issues (CVE-2026-34040, CVE-2026-33997) reached only through the docker client import, with no fixed module version published.
The S3 e2e pulled `minio/minio` by bare name. That repository no longer exists on Docker Hub, so the job fails at the pull with "access denied" before any agent code runs. Nothing in the repo changed; the image moved out from under us while the tree sat idle. quay.io is MinIO's own registry and carries the same releases. Pinned to a specific RELEASE tag rather than floating, since an unpinned reference is what let this break without a single failing run to point at.
dabelle
pushed a commit
that referenced
this pull request
Sep 19, 2026
chore(agent): build with Go 1.26.8 toolchain
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
govulncheck currently reports 7 vulnerabilities reachable from the agent. Five
are stdlib issues fixed in go1.26.6: net/url, crypto/tls (x2), encoding/asn1
and net/http. Binaries built off the 1.25 line carry all five, which includes
the v0.1.0 tarballs on the release page.
Both CI and the release workflow resolve their Go version from agent/go.mod,
so the toolchain directive is the thing that actually changes what gets
shipped. Pinned it rather than raising the
godirective so the minimumversion needed to build from source stays 1.25.0.
Takes the reachable count from 7 to 2. The remaining two are daemon-side Moby
issues (CVE-2026-34040, CVE-2026-33997) reached through the docker client
import, with no fixed module version published upstream.
Verified locally under 1.26.8: build, full test suite, golangci-lint clean.
CI had no signal on the branch because it only triggers on main or a PR, so
this run is the first real check.
Note that merging this does not fix the published v0.1.0 binaries. That needs
a v0.1.1 tag to rebuild them.