Move the Go toolchain pins to 1.26, in CI and in every image

Two Dependabot PRs are stuck behind the same number.

#35 raises the go directive to 1.26.0 in six modules, because
golang.org/x/crypto v0.56.0 requires it -- x/crypto tracks the two most
recent Go releases and 0.56 dropped 1.25. A module that says 1.26 cannot
be built by the 1.25 this repository pins in two places, so that PR
fails every Go job.

#29 raises actions/setup-go to v7, which sets GOTOOLCHAIN=local. With
that set, `go install golang.org/x/vuln/cmd/govulncheck@latest` cannot
quietly fetch a newer toolchain, and stops with

  golang.org/x/[email protected] requires go >= 1.26.0 (running go 1.25.14)

Under setup-go v5 the same install succeeded by downloading 1.26 behind
our backs, which is its own reason to be on 1.26 deliberately instead.

So: security-scan's go-version and all eight Dockerfiles move together,
1.25 -> 1.26. Nothing else needs to. A newer toolchain builds an older
directive happily, so this stands on its own before #35 lands, and the
go.mod files stay where they are here.

Checked by building rather than by reading: the api and ingest images
both build on golang:1.26-alpine, and api, ingest and enterprise still
`go build ./...` clean against their existing 1.25 directives.
This commit is contained in:
2026-09-10 09:54:45 -07:00
parent 907bf52541
commit c60028aad1
9 changed files with 20 additions and 19 deletions
+12 -11
View File
@@ -58,17 +58,18 @@ jobs:
- uses: actions/setup-go@v5
with:
# Deliberately NOT go-version-file. Each go.mod pins an exact
# patch (`go 1.25.0`), so go-version-file made CI scan against
# the *unpatched* 1.25.0 standard library and fail on 28
# stdlib CVEs -- crypto/x509 quadratic name-constraint parsing
# (GO-2025-4007) and friends, all fixed in 1.25.3. None of it
# was real: every Dockerfile builds `FROM golang:1.25-alpine`,
# a floating tag that resolves to the newest 1.25.x, so the
# shipped binaries already had the fixes. The go directive
# states the minimum language version, not the toolchain to
# audit with. Track the floating 1.25 line so this scans what
# production actually builds.
go-version: '1.25'
# patch, so go-version-file made CI scan against the *unpatched*
# standard library of that patch and fail on 28 stdlib CVEs --
# crypto/x509 quadratic name-constraint parsing (GO-2025-4007)
# and friends, all long since fixed. None of it was real: every
# Dockerfile builds `FROM golang:1.26-alpine`, a floating tag
# that resolves to the newest 1.26.x, so the shipped binaries
# already had the fixes. The go directive states the minimum
# language version, not the toolchain to audit with. Track the
# floating 1.26 line so this scans what production actually
# builds, and keep it in step with the Dockerfiles above all --
# a mismatch here fails every module at once.
go-version: '1.26'
- run: go install golang.org/x/vuln/cmd/govulncheck@latest
- name: Check for known vulnerabilities
working-directory: ${{ matrix.module_dir }}