Build and scan with Go 1.26.9
govulncheck in the security job reports ten standard-library vulnerabilities (net/http, mime/multipart, crypto/tls), all fixed in 1.26.9. The workflows pinned golang:1.26.6-bookworm. Claude-Session: https://claude.ai/code/session_016mBLURvJoMuUEr9cB2RpUN
This commit is contained in:
@@ -35,7 +35,7 @@ jobs:
|
||||
# Runs inside the toolchain image rather than installing Go per job. Note this puts
|
||||
# the job on the dind bridge, which cannot reach github.com or get.helm.sh --
|
||||
# proxy.golang.org and git.ryuvia.com are reachable, which is all this job needs.
|
||||
image: golang:1.26.6-bookworm
|
||||
image: golang:1.26.9-bookworm
|
||||
# act_runner destroys a job's own volumes when it finishes, so without these every
|
||||
# run re-downloads the whole module graph. The names must appear in the runner's
|
||||
# container.valid_volumes allowlist (charts/act-runner in the k8s repo); unlisted
|
||||
@@ -101,7 +101,7 @@ jobs:
|
||||
security:
|
||||
runs-on: ubuntu-latest
|
||||
container:
|
||||
image: golang:1.26.6-bookworm
|
||||
image: golang:1.26.9-bookworm
|
||||
volumes:
|
||||
- go-mod-cache:/go/pkg/mod
|
||||
- go-build-cache:/root/.cache/go-build
|
||||
|
||||
@@ -30,7 +30,7 @@ jobs:
|
||||
test:
|
||||
runs-on: ubuntu-latest
|
||||
container:
|
||||
image: golang:1.26.6-bookworm
|
||||
image: golang:1.26.9-bookworm
|
||||
volumes:
|
||||
- go-mod-cache:/go/pkg/mod
|
||||
- go-build-cache:/root/.cache/go-build
|
||||
@@ -71,7 +71,7 @@ jobs:
|
||||
needs: test
|
||||
runs-on: ubuntu-latest
|
||||
container:
|
||||
image: golang:1.26.6-bookworm
|
||||
image: golang:1.26.9-bookworm
|
||||
volumes:
|
||||
- go-mod-cache:/go/pkg/mod
|
||||
- go-build-cache:/root/.cache/go-build
|
||||
|
||||
Reference in New Issue
Block a user