Skip to content

fix(ci): govulncheck fails repo-wide on 7 stdlib CVEs fixed in go1.26.6, blocking every merge #1829

Description

@cristim

Blocks every merge in the repo. Not caused by any PR.

What

Security Scanning → Run govulncheck CVE scanner (all modules) now fails on every branch, reporting 7 Go standard library vulnerabilities, all present in go1.26.5 and all fixed in go1.26.6:

ID Package
GO-2026-6218 net/url
GO-2026-6091 html/template
GO-2026-6090 crypto/tls
GO-2026-6089 net/http
GO-2026-6088 encoding/xml
GO-2026-5972 encoding/asn1
GO-2026-5026 net/http

Each reports Found in: <pkg>@go1.26.5 / Fixed in: <pkg>@go1.26.6.

Why it appeared without any code change

CI pins GO_VERSION: '1.26.5' (.github/workflows/ci.yml:26). govulncheck fetches the vulnerability database at run time, so the same commit that passed earlier now fails once these advisories were published against 1.26.5.

Evidence that it is time-based and not change-based:

CI Success then fails downstream, so the whole workflow is red and no PR can satisfy the merge gate.

Fix

Bump the pinned toolchain:

-  GO_VERSION: '1.26.5'
+  GO_VERSION: '1.26.6'

.github/workflows/ci.yml:26, and the matching comment at :9. That is the only place the version is pinned; rg "GO_VERSION: |go-version: '" .github/workflows/*.yml returns those two lines and nothing else.

Do not bump the go directives in the six go.mod files. The directive is a minimum, and setup-go installing 1.26.6 supplies the 1.26.6 standard library regardless. Bumping the directive is also the change that historically broke the gosec Docker action. (That specific trap no longer applies here, since gosec now runs in a per-module loop rather than the Docker action after #1717, but the directive bump is still unnecessary scope.)

Do not suppress the finding. No -scan=module-style narrowing, no ignore list, no continue-on-error. These are real advisories against the running standard library and the fix is a one-line version bump.

Verification

  • Confirm go1.26.6 is the current patch release before pinning it.
  • After the bump, Run govulncheck CVE scanner (all modules) must pass on all six modules (., pkg, providers/{aws,azure,gcp}, tests/e2e).
  • Note tests/e2e/go.mod declares go 1.25; confirm the loop still resolves a 1.26.6 toolchain for it, or that its stdlib is likewise reported clean.
  • Confirm no other job regressed on the newer toolchain, particularly Lint Code (golangci-lint is pinned at v2.10.1 and is sensitive to the toolchain) and gosec.

No activity

Activity on this issue will appear here.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions