From 392970e6d83eec611b97cd0e09feea1acf5730fb Mon Sep 17 00:00:00 2001 From: "copilot-swe-agent[bot]" <198982749+Copilot@users.noreply.github.com> Date: Mon, 16 Mar 2026 16:30:23 +0000 Subject: [PATCH 1/2] Initial plan From bd588eae70fd02f8a1c13b73063c78ba711d44fa Mon Sep 17 00:00:00 2001 From: "copilot-swe-agent[bot]" <198982749+Copilot@users.noreply.github.com> Date: Mon, 16 Mar 2026 16:33:19 +0000 Subject: [PATCH 2/2] fix: upgrade Go from 1.25.7 to 1.25.8 to fix stdlib vulns GO-2026-4899 and GO-2026-4601 Co-authored-by: dlevy-msft-sql <194277063+dlevy-msft-sql@users.noreply.github.com> --- .github/workflows/security.yml | 2 +- go.mod | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/.github/workflows/security.yml b/.github/workflows/security.yml index e7cfb83d..ff39cfa4 100644 --- a/.github/workflows/security.yml +++ b/.github/workflows/security.yml @@ -29,7 +29,7 @@ jobs: - name: Setup Go uses: actions/setup-go@v6 with: - go-version: '1.25.7' + go-version: '1.25.8' - name: Install govulncheck run: go install golang.org/x/vuln/cmd/govulncheck@latest diff --git a/go.mod b/go.mod index 1dcfbb2c..0b7f05f8 100644 --- a/go.mod +++ b/go.mod @@ -1,6 +1,6 @@ module github.com/microsoft/go-sqlcmd -go 1.25.7 +go 1.25.8 require ( github.com/alecthomas/chroma/v2 v2.23.1