Skip to content

fix(marketplace): bump Go 1.26.4→1.26.5 to clear Go CVEs - #4

Merged
SongHyeopPark merged 1 commit into
release/2025-10-15-go1.25.9from
fix/marketplace-go-1.26.5
Jul 13, 2026
Merged

SongHyeopPark merged 1 commit into
release/2025-10-15-go1.25.9from
fix/marketplace-go-1.26.5

Conversation

@SongHyeopPark

Copy link
Copy Markdown
Contributor

What

Bump the Go toolchain from 1.26.4 → 1.26.5 in the two places the marketplace image is built from:

  • go.mod — toolchain go1.26.4 → go1.26.5
  • Dockerfile.marketplace — golang:1.26.4-alpine → golang:1.26.5-alpine

Why

Go 1.26.5 clears the stdlib CVEs flagged by the Grype scan (GO-2026-4970 / CVE-2026-39822). This mirrors the same bump already landed in envector-msa (fix(security): bump Go 1.26.4→1.26.5 …, #2167).

The SBOM & Vulnerability Scan workflow builds Dockerfile.marketplace, so this is the image the scan actually sees.

Scope

Marketplace image only. The other release* / hotfix Dockerfiles pin golang:1.24-alpine and are left untouched.

🤖 Generated with Claude Code

…0 / CVE-2026-39822)

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@SongHyeopPark
SongHyeopPark merged commit b89d784 into release/2025-10-15-go1.25.9 Jul 13, 2026
1 check passed
@SongHyeopPark
SongHyeopPark deleted the fix/marketplace-go-1.26.5 branch July 13, 2026 02:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants