Skip to content

chore(deps): update go module directive to v1.26.5 - #48

Open
scality-renovate[bot] wants to merge 1 commit into
mainfrom
renovate/golang
Open

chore(deps): update go module directive to v1.26.5#48
scality-renovate[bot] wants to merge 1 commit into
mainfrom
renovate/golang

Conversation

@scality-renovate

@scality-renovate scality-renovate Bot commented Jun 29, 2026

Copy link
Copy Markdown

This PR contains the following updates:

Package Type Update Change Pending
go (source) golang patch 1.26.41.26.5 1.26.6

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • "before 9am on monday"
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate CLI.

@scality-renovate
scality-renovate Bot requested a review from a team as a code owner June 29, 2026 04:06
@scality-renovate scality-renovate Bot added dependencies Pull requests that update a dependency file digest docker go Pull requests that update go code labels Jun 29, 2026
@github-actions

github-actions Bot commented Jun 29, 2026

Copy link
Copy Markdown

Dependency Bump Evaluation

Packages:

  • golang (build stage): digest 792443b -> f96cc55 (same golang:1.26 tag)
  • mcr.microsoft.com/devcontainers/go (devcontainer): digest 232b16d -> 638cb8e (same 1.26-trixie tag)

Bump type: Docker digest rotation (no semver change)

Changes:

  • Picks up the latest rebuild of both Go Docker images, which typically includes OS-level security patches and minor updates to the base layer
  • Go toolchain version remains 1.26 -- no compiler or stdlib changes

Breaking changes: None -- same Go version, same tags, only the underlying OS packages are refreshed

Security concerns: None -- digest rotations are the standard mechanism for receiving OS-level security patches in pinned Docker images. This is a positive security update.

Impact on codebase: No impact. The Dockerfile uses a multi-stage build: the golang:1.26 builder compiles a statically linked binary (CGO_ENABLED=0), which is then copied to a distroless/static:nonroot runtime image. OS-layer changes in the builder do not affect the final artifact. The devcontainer change only affects the development environment.

CI status: lint passed, test passed, build in progress

Recommendation: SAFE TO MERGE (once CI passes)

-- Claude Code

@scality-renovate scality-renovate Bot changed the title chore(deps): update golang:1.26 docker digest to 32c0e6e chore(deps): update golang:1.26 docker digest to f96cc55 Jun 30, 2026
@scality-renovate scality-renovate Bot changed the title chore(deps): update golang:1.26 docker digest to f96cc55 chore(deps): update golang Jul 2, 2026
@scality-renovate
scality-renovate Bot force-pushed the renovate/golang branch 3 times, most recently from d182e9e to bc40f30 Compare July 14, 2026 04:08
@scality-renovate
scality-renovate Bot force-pushed the renovate/golang branch 3 times, most recently from fbdf362 to 94be558 Compare July 20, 2026 04:43
@github-actions

github-actions Bot commented Jul 31, 2026

Copy link
Copy Markdown

Dependency Bump Evaluation

Version change: Go 1.26.41.26.5 (patch) + Docker image digest updates
Semver bump type: patch

Changes:

  • Go toolchain patch bump from 1.26.4 to 1.26.5
  • Docker base image digest updates for golang and devcontainers/go (track the new Go version)
  • No source code changes — only go.mod, Dockerfile, and .devcontainer/Dockerfile

Go 1.26.5 includes (11 issues):

  • Security: CVE-2026-39822os.Root escape via symlink + trailing slash; crypto/tls ECH/PSK fix
  • Runtime: 5 bug fixes (GC AVX-512 crash, map concurrency on ppc64le, fork+race SIGSEGV on darwin/arm64, version parsing, moveSliceNoCap)
  • cmd/go: GOFIPS140 interaction fix, test caching with T.Chdir
  • os/signal: NotifyContext error cause mismatch with context.Canceled
  • net: Windows DNS test fix

Breaking changes: None

Security concerns: None — the security fixes are beneficial. CVE-2026-39822 (os.Root escape) does not affect this codebase: the adapter only uses os.Exit() and os.Getenv(), never os.Root or symlink-traversal APIs. crypto/tls is not directly imported. The os/signal.NotifyContext fix (#79499) is relevant to cmd/main.go:44 but harmless: the codebase never checks errors.Is(err, context.Canceled) on the signal context.

Impact on codebase: No affected patterns found. All fixes are either in packages not used by this project or in code paths not exercised.

Recommendation: SAFE TO MERGE (once CI is green)

Notes: CI checks (build, test) are still in progress and renovate/stability-days is pending. Merge after all checks pass. This is a standard Go patch release with security hardening — recommended to merge promptly.

— Claude Code

@scality-renovate
scality-renovate Bot force-pushed the renovate/golang branch 2 times, most recently from 76603f8 to 8649ed5 Compare August 6, 2026 04:07
@scality-renovate scality-renovate Bot changed the title chore(deps): update golang chore(deps): update go module directive to v1.26.5 Aug 13, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file go Pull requests that update go code patch

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants