Skip to content

chore(deps): bump Go to 1.26.4 and update vulnerable dependencies#250

Open
samcm wants to merge 2 commits into
masterfrom
chore/bump-go-and-deps
Open

chore(deps): bump Go to 1.26.4 and update vulnerable dependencies#250
samcm wants to merge 2 commits into
masterfrom
chore/bump-go-and-deps

Conversation

@samcm

@samcm samcm commented Jun 12, 2026

Copy link
Copy Markdown
Member

Bumps the Go directive to 1.26.4 and updates golang.org/x/net (v0.47.0 → v0.56.0), github.com/ethereum/go-ethereum (v1.16.4 → v1.17.3), and related golang.org/x/* modules.

The previous versions carried known CVEs reachable from this codebase, including an HTTP/2 DoS in x/net/net/http and several crypto/tls/crypto/x509 issues fixed in the go1.26.x patch releases.

Adds a govulncheck workflow (PR, push-to-master, and weekly) alongside the dependency fixes that make it pass, so known vulnerabilities in the toolchain or dependencies fail the build going forward. govulncheck ./... reports no reachable vulnerabilities after the bump.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant