chore: update x/crypto and x/sys while keeping Go 1.25 support - #219
Merged
Merged
Conversation
- Bump go directive 1.24.0 -> 1.26.4 in all modules (root + 3 examples), clearing the stdlib advisories flagged by osv-scanner for 1.24.0. - Bump golang.org/x/crypto 0.46.0 -> 0.52.0 (x/sys 0.39.0 -> 0.45.0 via tidy), clearing GO-2026-5013/5017/5018/5019/5020. Test-only dependency, but bumped for downstream scanner hygiene. - Fix 4 printf vet errors (buf -> buf.String()) surfaced by the stricter printf analyzer at the new go directive, in shared_directory_test.go and socket_test.go. - Update CI matrix (build + test jobs) to ^1.26. Verified: go vet ./... clean, library + all 3 example modules build, and the codesigned VM integration suite passes (boots real Linux guests). Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
cfergeau
reviewed
Jun 8, 2026
Code-Hex
dismissed
AkihiroSuda’s stale review
September 28, 2026 08:02
指摘された Go 1.25 の最低要件を追加コミットで維持しました。Go 1.25.0 で vet、ビルド、対象 VM テストを確認済みです。
Owner
|
English clarification for the review dismissal: The follow-up commit keeps the minimum Go version at 1.25.0, as requested. With Go 1.25.0, |
Contributor
|
We objected to dropping go 1.25 support when this PR was filed as at the time, it was still a supported release upstream. However, go 1.27 has been released a few weeks ago, and 1.25 is now unsupported (see https://endoflife.date/go), so it would be less problematic to drop it in future PRs. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Update
golang.org/x/cryptoto v0.52.0 andgolang.org/x/systo v0.45.0 to resolve the root module's Dependabot alerts #7 through #19. @jlagedo contributed the original dependency update.Set the minimum Go version to 1.25.0, as required by the updated dependencies, so consumers can continue to use this library with Go 1.25. CI builds with both Go 1.25 and 1.26.
Fix four test diagnostics reported by
go vetby formatting thebytes.Buffercontents as strings.Verification
go vet ./..., test compilation, and builds of all three example modules passed.go mod tidy -diffproduced no changes.Note
The
godirective specifies the minimum compiler version. Consumers should use the latest patch release of a supported Go version for their builds.