Repository navigation
fix(ci): upgrade Go and network security baseline - #290
Merged
Merged
Conversation
5 tasks done
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
The nightly Go audit began failing on unchanged main after the 2026-10-08 vulnerability database update: the retired Go 1.25 toolchain was reported to reach ten standard-library advisories. Pin Go 1.26.9 in go.mod and use go-version-file in every central CI and release builder, so a lagging setup-go catalog cannot resolve a wildcard to an older vulnerable patch. Update x/net to v0.60.0 with its required module versions. Keep the blocking audit and existing nightly / affected-check policy.
Local desktop builders require that exact compiler too: a module minimum alone would accept affected Go 1.27.0/1.27.1. The Windows fixed-Go fixture still requires the exact setup-go version and verified official archive/executable bytes. Align macOS compile/link flags, bundle metadata and archive validation to macOS 12: both Go 1.25 and 1.26 require it, so the previous macOS 11 declaration was stale. Current contributor/package guidance and CI evidence limits are updated; historical verification records remain intact.
Closes #289.
Validation
go mod verifyandgo mod tidy -diff.govulncheck@v1.6.0 ./...on Windows with the same 2026-10-08 22:31:09 UTC database as the failed job: 0 reachable vulnerabilities, 0 in imported packages. One advisory remains in an uncalled required module.go test -p 2 -count=1andgo vetforhostproxy,llm,mcp,fileedit,plugins,workspacecheckpoint, andreleasegate.git diff --check.go run ./cmd/cyberagent version.560c6b66e63e8b37965aae3d7045dd5e9b4f65ec: Windows dual-product packaging and macOS amd64/arm64 archives. PR-only attestation/publication jobs were skipped as intended; no release was published. No local macOS build or manual OS matrix is claimed.560c6b66e63e8b37965aae3d7045dd5e9b4f65ec: all 22 jobs successful, none skipped. This includes full Go tests/vet, the vulnerability audit, all Store shards, authority race checks, real browser/LSP coverage, both native shells, and reproducible Desktop builds.Windows reliability note: the first shell attempt interrupted the paginated command-output regression. The exact ordered test passed locally, and one failed-job retry on the unchanged head passed the entire Windows job;
multiple-output-pagespassed in 47.51 seconds anddesktop_reproduciblewas true. The original interruption's underlying cause is unconfirmed. This is recorded as remaining reliability uncertainty, not claimed as a runtime bug fix; no authority guard or timeout was weakened.Surface governance
Audit