Blocks every merge in the repo. Not caused by any PR.
What
Security Scanning → Run govulncheck CVE scanner (all modules) now fails on every branch, reporting 7 Go standard library vulnerabilities, all present in go1.26.5 and all fixed in go1.26.6:
| ID |
Package |
| GO-2026-6218 |
net/url |
| GO-2026-6091 |
html/template |
| GO-2026-6090 |
crypto/tls |
| GO-2026-6089 |
net/http |
| GO-2026-6088 |
encoding/xml |
| GO-2026-5972 |
encoding/asn1 |
| GO-2026-5026 |
net/http |
Each reports Found in: <pkg>@go1.26.5 / Fixed in: <pkg>@go1.26.6.
Why it appeared without any code change
CI pins GO_VERSION: '1.26.5' (.github/workflows/ci.yml:26). govulncheck fetches the vulnerability database at run time, so the same commit that passed earlier now fails once these advisories were published against 1.26.5.
Evidence that it is time-based and not change-based:
CI Success then fails downstream, so the whole workflow is red and no PR can satisfy the merge gate.
Fix
Bump the pinned toolchain:
- GO_VERSION: '1.26.5'
+ GO_VERSION: '1.26.6'
.github/workflows/ci.yml:26, and the matching comment at :9. That is the only place the version is pinned; rg "GO_VERSION: |go-version: '" .github/workflows/*.yml returns those two lines and nothing else.
Do not bump the go directives in the six go.mod files. The directive is a minimum, and setup-go installing 1.26.6 supplies the 1.26.6 standard library regardless. Bumping the directive is also the change that historically broke the gosec Docker action. (That specific trap no longer applies here, since gosec now runs in a per-module loop rather than the Docker action after #1717, but the directive bump is still unnecessary scope.)
Do not suppress the finding. No -scan=module-style narrowing, no ignore list, no continue-on-error. These are real advisories against the running standard library and the fix is a one-line version bump.
Verification
- Confirm
go1.26.6 is the current patch release before pinning it.
- After the bump,
Run govulncheck CVE scanner (all modules) must pass on all six modules (., pkg, providers/{aws,azure,gcp}, tests/e2e).
- Note
tests/e2e/go.mod declares go 1.25; confirm the loop still resolves a 1.26.6 toolchain for it, or that its stdlib is likewise reported clean.
- Confirm no other job regressed on the newer toolchain, particularly
Lint Code (golangci-lint is pinned at v2.10.1 and is sensitive to the toolchain) and gosec.
Blocks every merge in the repo. Not caused by any PR.
What
Security Scanning→Run govulncheck CVE scanner (all modules)now fails on every branch, reporting 7 Go standard library vulnerabilities, all present ingo1.26.5and all fixed ingo1.26.6:net/urlhtml/templatecrypto/tlsnet/httpencoding/xmlencoding/asn1net/httpEach reports
Found in: <pkg>@go1.26.5/Fixed in: <pkg>@go1.26.6.Why it appeared without any code change
CI pins
GO_VERSION: '1.26.5'(.github/workflows/ci.yml:26).govulncheckfetches the vulnerability database at run time, so the same commit that passed earlier now fails once these advisories were published against 1.26.5.Evidence that it is time-based and not change-based:
main@f4585084cpassedCI - Build & Testat 2026-08-13T21:54ZCI Successthen fails downstream, so the whole workflow is red and no PR can satisfy the merge gate.Fix
Bump the pinned toolchain:
.github/workflows/ci.yml:26, and the matching comment at:9. That is the only place the version is pinned;rg "GO_VERSION: |go-version: '" .github/workflows/*.ymlreturns those two lines and nothing else.Do not bump the
godirectives in the sixgo.modfiles. The directive is a minimum, andsetup-goinstalling 1.26.6 supplies the 1.26.6 standard library regardless. Bumping the directive is also the change that historically broke the gosec Docker action. (That specific trap no longer applies here, since gosec now runs in a per-module loop rather than the Docker action after #1717, but the directive bump is still unnecessary scope.)Do not suppress the finding. No
-scan=module-style narrowing, no ignore list, nocontinue-on-error. These are real advisories against the running standard library and the fix is a one-line version bump.Verification
go1.26.6is the current patch release before pinning it.Run govulncheck CVE scanner (all modules)must pass on all six modules (.,pkg,providers/{aws,azure,gcp},tests/e2e).tests/e2e/go.moddeclaresgo 1.25; confirm the loop still resolves a 1.26.6 toolchain for it, or that its stdlib is likewise reported clean.Lint Code(golangci-lint is pinned at v2.10.1 and is sensitive to the toolchain) andgosec.