Skip to content

chore: set Go toolchain to go1.26.6 - #530

Draft
stirby wants to merge 1 commit into
mainfrom
bump-go-toolchain
Draft

stirby wants to merge 1 commit into
mainfrom
bump-go-toolchain

Conversation

@stirby

@stirby stirby commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

Adds toolchain go1.26.6 to go.mod so builds use a Go release with the current standard-library fixes. govulncheck (run on go1.26.5): fixes 7 stdlib advisories, covering net/url, net/http, crypto/tls, html/template, encoding/xml, encoding/asn1 and net. GO-2026-5026 also needs the x/net bump PR.

Review notes:

  • Stdlib fixes only reach users if the release build uses this toolchain. .github/workflows/ci.yaml and release.yaml pin setup-go to ~1.22 and rely on GOTOOLCHAIN=auto to honour this line. It may be cleaner to set go-version-file: go.mod in the workflows instead. I left the workflows unchanged so the maintainer can choose.
  • No go directive change, so this does not raise the minimum Go version for library consumers.

Part of a set of independent dependency PRs.

Generated by Coder Agents on behalf of @stirby.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant