Skip to content

chore(deps): bump grpc 1.83.1 and x/crypto 0.56.0 to clear govulncheck - #158

Merged
blue4209211 merged 2 commits into
mainfrom
fix/bump-grpc-xcrypto-vulns
Sep 25, 2026
Merged

blue4209211 merged 2 commits into
mainfrom
fix/bump-grpc-xcrypto-vulns

Conversation

@mayankpande88

Copy link
Copy Markdown
Contributor

Description

The vuln CI job fails on every open PR (#153–#157) because of:

  • GO-2026-6348, in grpc 1.83.0 (fixed in 1.83.1);
  • GO-2026-6354 and GO-2026-6355, in x/crypto 0.55.0 (fixed in 0.56.0).

x/crypto 0.56.0 requires Go 1.26, so the go directive moves from 1.25.13 to 1.26.6. That matches the Dockerfile build image (golang:1.26.6). Pinning 1.26.0 would make CI (go-version-file: go.mod) install a toolchain with stdlib vulnerabilities that were fixed in later 1.26 patches.

Type of change

  • Bug fix (non-breaking change which fixes an issue)
  • New feature (non-breaking change which adds functionality)
  • Enhancement (non-breaking change which improves existing functionality)
  • Refactor (non-breaking change which improves code structure)
  • Breaking change (fix or feature that would cause existing functionality to not work as expected)
  • Documentation
  • CI/CD

How Has This Been Tested?

  • Unit tests
  • Manual testing

Under go1.26.6, go test ./... passes, govulncheck ./... exits 0, and golangci-lint reports 0 issues.

Checklist

  • CLA signed (the CLA bot will prompt on your first PR)
  • make validate passes (fmt + lint + test)
  • Docs updated if the wire shape, config surface, or proxy module behavior changed

GO-2026-6348 (grpc) and GO-2026-6354/6355 (x/crypto) fail the vuln job on
every PR. x/crypto 0.56.0 requires go 1.26, so the go directive moves to
1.26.6, matching the Dockerfile build image; 1.26.0 would pull in stdlib
vulns fixed in later patches.

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request updates the Go runtime version to 1.26.6 and upgrades the dependencies golang.org/x/crypto to v0.56.0 and google.golang.org/grpc to v1.83.1. I have no feedback to provide on these changes.

v2.7.2 is built with go1.25 and refuses to load a go 1.26 module.
The newer staticcheck flags the deprecated DetectOptions.CredentialsFile
(now loaded via NewCredentialsFromJSON with the file's declared type) and
an SA6001 false positive in a test helper.
@blue4209211
blue4209211 merged commit d217c85 into main Sep 25, 2026
6 checks passed
@blue4209211
blue4209211 deleted the fix/bump-grpc-xcrypto-vulns branch September 25, 2026 08:27
blue4209211 pushed a commit that referenced this pull request Sep 25, 2026
The go directive moved to 1.26 in #158/#157, but release.yml still pinned
golangci-lint v2.7.2, which is built with go1.25 and refuses to load the
module, so the Release workflow fails on main.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants