Skip to content

fix(ci): upgrade Go and network security baseline - #290

Merged
Qiyuanqiii merged 2 commits into
mainfrom
codex/go-security-toolchain
Oct 9, 2026
Merged

Qiyuanqiii merged 2 commits into
mainfrom
codex/go-security-toolchain

Conversation

@Qiyuanqiii

@Qiyuanqiii Qiyuanqiii commented Oct 9, 2026 •

Copy link
Copy Markdown
Member

Summary

The nightly Go audit began failing on unchanged main after the 2026-10-08 vulnerability database update: the retired Go 1.25 toolchain was reported to reach ten standard-library advisories. Pin Go 1.26.9 in go.mod and use go-version-file in every central CI and release builder, so a lagging setup-go catalog cannot resolve a wildcard to an older vulnerable patch. Update x/net to v0.60.0 with its required module versions. Keep the blocking audit and existing nightly / affected-check policy.

Local desktop builders require that exact compiler too: a module minimum alone would accept affected Go 1.27.0/1.27.1. The Windows fixed-Go fixture still requires the exact setup-go version and verified official archive/executable bytes. Align macOS compile/link flags, bundle metadata and archive validation to macOS 12: both Go 1.25 and 1.26 require it, so the previous macOS 11 declaration was stale. Current contributor/package guidance and CI evidence limits are updated; historical verification records remain intact.

Closes #289.

Validation

  • Go 1.26.9: go mod verify and go mod tidy -diff.
  • govulncheck@v1.6.0 ./... on Windows with the same 2026-10-08 22:31:09 UTC database as the failed job: 0 reachable vulnerabilities, 0 in imported packages. One advisory remains in an uncalled required module.
  • go test -p 2 -count=1 and go vet for hostproxy, llm, mcp, fileedit, plugins, workspacecheckpoint, and releasegate.
  • Actual Windows parent-junction and Plugin snapshot-junction regression tests executed and passed; old local Go 1.26.5 is rejected by the module minimum. The actual Windows builder also rejects installed Go 1.27.0 before building; both platform preflight regressions cover newer vulnerable compilers.
  • CI helper tests: 55 total, 54 passed and one existing Windows filename skip; macOS archive/preflight tests: 16 passed, including rehashed archives with an incorrect minimum OS.
  • Windows fixed-Go guard tests, both modified shell scripts' syntax, and git diff --check.
  • CLI smoke: go run ./cmd/cyberagent version.
  • Native release validation 37865654016 passed on 560c6b66e63e8b37965aae3d7045dd5e9b4f65ec: Windows dual-product packaging and macOS amd64/arm64 archives. PR-only attestation/publication jobs were skipped as intended; no release was published. No local macOS build or manual OS matrix is claimed.
  • Full CI 37865654058, attempt 2 passed on 560c6b66e63e8b37965aae3d7045dd5e9b4f65ec: all 22 jobs successful, none skipped. This includes full Go tests/vet, the vulnerability audit, all Store shards, authority race checks, real browser/LSP coverage, both native shells, and reproducible Desktop builds.

Windows reliability note: the first shell attempt interrupted the paginated command-output regression. The exact ordered test passed locally, and one failed-job retry on the unchanged head passed the entire Windows job; multiple-output-pages passed in 47.51 seconds and desktop_reproducible was true. The original interruption's underlying cause is unconfirmed. This is recorded as remaining reliability uncertainty, not claimed as a runtime bug fix; no authority guard or timeout was weakened.

Surface governance

  • No Surface is added, promoted, downgraded, deprecated, or removed.
  • Registry item(s): N/A — no Surface change.
  • Target tier / transition: N/A.
  • Entry criteria / decision: N/A.
  • Owner: Existing Go control-plane and build owners.
  • Shared Go Application contract: Unchanged.
  • Authority impact: No new runtime authority; compiler and module security fixes apply to existing paths.
  • Supported platforms: Existing Windows/Linux/macOS architectures; macOS minimum metadata corrected to the compiler-supported 12+.
  • Release / test evidence: Above; full CI (22 successful jobs) and native release validation passed on the repair head. Windows first-attempt interruption and the single successful retry are recorded explicitly.
  • Compatibility strategy: Keep exact version/hash checks, package identity, current authority gates and historical readers.
  • Deprecation window: N/A.
  • Removal / rollback plan: Reverting reintroduces the affected toolchain and audit failure; do not disable the audit to roll back.

Audit

  • No credentials or local runtime data are included.
  • Existing policy, workspace, sandbox and persistence boundaries remain enforced.
  • Current project memory, developer/build guidance and CI evidence limits are updated.

@Qiyuanqiii
Qiyuanqiii merged commit b52410d into main Oct 9, 2026
48 of 50 checks passed
@Qiyuanqiii
Qiyuanqiii deleted the codex/go-security-toolchain branch October 9, 2026 01:37
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

fix(ci): 升级 Go 安全基线,修复定时漏洞审计失败

1 participant