Skip to content

fix: align all builds on Go 1.27.2 security toolchain #1273

Description

@crypt0rr

make security currently fails on Go 1.27.1 with ten reachable standard-library vulnerability reports, published on 8 October 2026: GO-2026-6617, GO-2026-6613, GO-2026-6612, GO-2026-6611, GO-2026-6610, GO-2026-6609, GO-2026-6608, GO-2026-6607, GO-2026-6605, and GO-2026-6603. All report Go 1.27.2 as the fix. See the official Go advisory and Go release history.

Update the minimum toolchain in go.mod as well as both immutable Docker Go builder pins, and align the development guide. CI and release builds derive their Go version from go.mod; updating only the Dockerfile leaves native release archives and security checks on the affected standard library. Preserve the existing immutable release candidate and scanner sandbox policies.

Implementation extends #1265 and is required before publishing the guided-monitor release (#1266). The persistent dependency dashboard #8 remains open.

Acceptance:

  • go version and release candidate build metadata show Go 1.27.2.
  • Pinned vulnerability and lint checks pass with no reachable findings.
  • Normal frontend, Go race/coverage, container and native ARM64 sandbox gates pass.
  • Development guide builds and its corresponding deployment is verified.
  • Release archives and digest-pinned multiarch image are verified through the existing release workflow.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions