Skip to content

fix(deps): bump golang.org/x/text to v0.39.0 (GO-2026-5970) - #1484

Merged
cristim merged 1 commit into
mainfrom
fix/gxtext-cve-2026-5970
Jul 22, 2026
Merged

cristim merged 1 commit into
mainfrom
fix/gxtext-cve-2026-5970

Conversation

@cristim

@cristim cristim commented Jul 21, 2026 •

Copy link
Copy Markdown
Member

Summary

  • golang.org/x/text@v0.38.0 is affected by GO-2026-5970 (infinite loop on invalid input in the norm package), fixed in v0.39.0.
  • govulncheck flags it as reachable (exit code 3) via:
    • internal/server/scheduledauth/validator.go:269 (Validator.Warmup -> http.Client.Do -> norm.Form.*)
    • internal/database/connection.go:319 (Connection.TryAdvisoryLock -> pgxpool.Acquire -> norm.Form.*)
  • This reddens the Security Scanning job (CI - Build & Test) on main and every PR.
  • Bumped the indirect x/text dependency to v0.39.0 in the three modules that pin it: root go.mod, providers/azure/go.mod, providers/gcp/go.mod. pkg, providers/aws, and tests/e2e do not depend on x/text and needed no change.
  • The go directive is left untouched in all three modules (bumping it breaks the gosec Docker action's bundled Go toolchain per prior repo incident).

No existing tracking issue found for this specific CVE (searched x/text, GO-2026-5970, govulncheck); closest related issues are #1285 (pgx CVE, different advisory, closed via prior fix) and LeanerCloud/cloud-commitments-platform#74 (govulncheck retry hardening, unrelated). Not closing either.

Test plan

  • go get golang.org/x/text@v0.39.0 && go mod tidy in root, providers/azure, providers/gcp — clean diffs, single-line x/text bump each, no unexpected transitive changes
  • govulncheck@v1.1.4 ./... (pinned to match CI) run in all 6 CI-scanned modules (root, pkg, providers/aws, providers/azure, providers/gcp, tests/e2e) — exit 0 in all, GO-2026-5970 no longer reported anywhere
  • go build ./... — exit 0 in root, providers/azure, providers/gcp
  • go vet ./... — exit 0 in root
  • pre-commit hooks — all passed (no --no-verify)

Summary by CodeRabbit

  • Chores
    • Updated underlying build components to newer versions across the core, Azure, and Google Cloud integrations.
    • No user-facing features or public interfaces changed.

golang.org/x/text v0.38.0 is affected by GO-2026-5970, an infinite loop
on invalid input in the norm package. govulncheck flags it as reachable
via:
  - internal/server/scheduledauth/validator.go:269
    (Validator.Warmup -> http.Client.Do -> norm.Form.*)
  - internal/database/connection.go:319
    (Connection.TryAdvisoryLock -> pgxpool.Acquire -> norm.Form.*)

This reddens the Security Scanning job on main and every PR.

Bump the indirect x/text dependency to v0.39.0 (fixed version) in the
three modules that pin it: root, providers/azure, providers/gcp. The
go directive is left untouched in all three, per repo policy (bumping
it breaks the gosec Docker action's bundled Go toolchain).

Clears GO-2026-5970 from govulncheck across all 6 CI-scanned modules
(root, pkg, providers/aws, providers/azure, providers/gcp, tests/e2e).
@cristim cristim added triaged Item has been triaged priority/p1 Next up; this sprint severity/high Significant harm urgency/this-sprint Within the current sprint impact/internal Team-internal only effort/xs Trivial / one-liner type/security Security finding labels Jul 21, 2026
@cristim

cristim commented Jul 21, 2026

Copy link
Copy Markdown
Member Author

@coderabbitai review

@coderabbitai

coderabbitai Bot commented Jul 21, 2026 •

Copy link
Copy Markdown
Contributor

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: 9d3f65be-73b0-44d4-83d2-0e9fe5186d11

📥 Commits

Reviewing files that changed from the base of the PR and between d2e52d9 and e08b502.

⛔ Files ignored due to path filters (3)
  • go.sum is excluded by !**/*.sum
  • providers/azure/go.sum is excluded by !**/*.sum
  • providers/gcp/go.sum is excluded by !**/*.sum
📒 Files selected for processing (3)
  • go.mod
  • providers/azure/go.mod
  • providers/gcp/go.mod

📝 Walkthrough

Walkthrough

The pull request updates the indirect golang.org/x/text dependency from v0.38.0 to v0.39.0 in the root, Azure provider, and GCP provider Go modules.

Changes

Go module dependency alignment

Layer / File(s) Summary
Update indirect text dependency versions
go.mod, providers/azure/go.mod, providers/gcp/go.mod
The indirect golang.org/x/text requirement is updated from v0.38.0 to v0.39.0 across all three Go modules.

Estimated code review effort: 1 (Trivial) | ~2 minutes

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly summarizes the dependency bump and vulnerability fix reflected in the changes.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch fix/gxtext-cve-2026-5970

Comment @coderabbitai help to get the list of available commands.

@coderabbitai

coderabbitai Bot commented Jul 21, 2026 •

Copy link
Copy Markdown
Contributor
✅ Action performed

Review finished.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

@cristim

cristim commented Jul 21, 2026

Copy link
Copy Markdown
Member Author

@coderabbitai full review

@coderabbitai

coderabbitai Bot commented Jul 21, 2026 •

Copy link
Copy Markdown
Contributor
✅ Action performed

Full review finished.

@cristim

cristim commented Jul 21, 2026

Copy link
Copy Markdown
Member Author

Ready for human merge.

  • CI: 19/19 green. Security Scanning now passes: govulncheck clears GO-2026-5970 across all six scanned modules (root, pkg, providers/aws, providers/azure, providers/gcp, tests/e2e). This is the whole point of the PR.
  • CodeRabbit: full review finished, no actionable findings (status check SUCCESS).
  • Diff: single-line golang.org/x/text v0.38.0 -> v0.39.0 bump in root, providers/azure, providers/gcp go.mod + go.sum. No go directive change.
  • mergeState: CLEAN.

Recommend a human merge. Merging this first also clears the same pre-existing Security Scanning red on PR #394 once that branch rebases onto main.

Note: a separate non-reachable advisory GO-2026-5932 (x/crypto/openpgp unmaintained-package warning) remains on main and is out of scope here; worth a follow-up but does not fail the gate.

@cristim
cristim merged commit 9bfca74 into main Jul 22, 2026
19 checks passed
@cristim
cristim deleted the fix/gxtext-cve-2026-5970 branch July 27, 2026 11:10
cristim added a commit that referenced this pull request Sep 27, 2026
golang.org/x/text v0.38.0 is affected by GO-2026-5970, an infinite loop
on invalid input in the norm package. govulncheck flags it as reachable
via:
  - internal/server/scheduledauth/validator.go:269
    (Validator.Warmup -> http.Client.Do -> norm.Form.*)
  - internal/database/connection.go:319
    (Connection.TryAdvisoryLock -> pgxpool.Acquire -> norm.Form.*)

This reddens the Security Scanning job on main and every PR.

Bump the indirect x/text dependency to v0.39.0 (fixed version) in the
three modules that pin it: root, providers/azure, providers/gcp. The
go directive is left untouched in all three, per repo policy (bumping
it breaks the gosec Docker action's bundled Go toolchain).

Clears GO-2026-5970 from govulncheck across all 6 CI-scanned modules
(root, pkg, providers/aws, providers/azure, providers/gcp, tests/e2e).
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

effort/xs Trivial / one-liner impact/internal Team-internal only priority/p1 Next up; this sprint severity/high Significant harm triaged Item has been triaged type/security Security finding urgency/this-sprint Within the current sprint

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant