Skip to content

deps: bump Go to 1.26.4 to address Snyk findings - #342

Open
twmb wants to merge 1 commit into
masterfrom
tb/snyk-go-1.26.4
Open

deps: bump Go to 1.26.4 to address Snyk findings#342
twmb wants to merge 1 commit into
masterfrom
tb/snyk-go-1.26.4

Conversation

@twmb

@twmb twmb commented Jun 8, 2026

Copy link
Copy Markdown
Contributor

What

Bumps the go directive (go.mod) and the builder base image (Dockerfile: golang:1.26.3-alpinegolang:1.26.4-alpine) to 1.26.4.

Why

Clears two stdlib HIGH Snyk findings:

Both fixed in go1.26.4. (golang:1.26.4-alpine confirmed available on Docker Hub.)

References

🤖 Generated with Claude Code

Bumps the go directive (go.mod) and the builder base image
(Dockerfile: golang:1.26.3-alpine -> 1.26.4-alpine) to clear two
stdlib HIGH findings:

- CVE-2026-27145 / GO-2026-5037 - crypto/x509 resource exhaustion
- CVE-2026-42504 / GO-2026-5038 - net/mime resource exhaustion

Both fixed in go1.26.4.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant