Skip to content

fix(vuln): bump go 1.26.4 to patch stdlib CVEs#20

Merged
nanjingfm merged 1 commit into
alauda-v1.6.5from
fix/stdlib-1264
Jun 10, 2026
Merged

fix(vuln): bump go 1.26.4 to patch stdlib CVEs#20
nanjingfm merged 1 commit into
alauda-v1.6.5from
fix/stdlib-1264

Conversation

@nanjingfm

Copy link
Copy Markdown
Collaborator

Summary

  • Bump go directive 1.26.3 → 1.26.4

CVEs (stdlib)

Needed by gitlab-chart alauda-18.5.4 vuln scan (cfssl binary embeds stdlib).

🤖 Generated with Claude Code

- stdlib CVE-2026-42504 / CVE-2026-27145 / CVE-2026-42507

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
@nanjingfm nanjingfm merged commit 26fddad into alauda-v1.6.5 Jun 10, 2026
1 check passed
@nanjingfm nanjingfm deleted the fix/stdlib-1264 branch June 10, 2026 14:51
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant