Skip to content

GHO-11493: bump go toolchain and bundled osv-scanner to clear CVEs#9

Merged
bgeesaman merged 1 commit intomainfrom
GHO-11493-go-deps
Apr 23, 2026
Merged

GHO-11493: bump go toolchain and bundled osv-scanner to clear CVEs#9
bgeesaman merged 1 commit intomainfrom
GHO-11493-go-deps

Conversation

@bgeesaman
Copy link
Copy Markdown
Member

@bgeesaman bgeesaman commented Apr 23, 2026

Summary

  • Bump embedded Go stdlib from 1.25.6 to 1.25.9
  • Bump bundled osv-scanner from v2.3.2 to v2.3.5
  • Align the CI test workflow to the same versions

Test plan

  • go build ./... passes on go 1.25.9
  • make test (unit) passes
  • Integration tests

Go stdlib 1.25.6 -> 1.25.9 to patch embedded stdlib CVEs in the wraith
binary. osv-scanner v2.3.2 -> v2.3.5 picks up grpc 1.79.3, mcp-go-sdk
1.4.1, docker/cli 29.2.0, and a go 1.26.1 build, clearing the bundled
binary's high/critical findings except two buildkit indirect deps that
require an upstream release.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@bgeesaman bgeesaman self-assigned this Apr 23, 2026
@bgeesaman bgeesaman enabled auto-merge (squash) April 23, 2026 12:32
@bgeesaman bgeesaman merged commit 4dea1f3 into main Apr 23, 2026
2 checks passed
@bgeesaman bgeesaman deleted the GHO-11493-go-deps branch April 23, 2026 12:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants