Skip to content

chore: bump Go 1.26.5 → 1.26.6 (stdlib CVE fixes) #4718

Description

Go Patch Upgrade: 1.26.5 → 1.26.6

Context

New Go stdlib CVEs have been published that affect Go 1.26.5. All PRs across the repo are currently failing govulncheck until we bump to Go 1.26.6. This is a Tier 2 patch bump.

CVEs fixed in Go 1.26.6:

  • GO-2026-6218 (net/url)
  • GO-2026-6091 (html/template)
  • GO-2026-6090 (crypto/tls)
  • GO-2026-6089 (net/http)
  • GO-2026-5972 (encoding/asn1)

Instructions

Use the acn-go-version-bump skill to perform this patch upgrade. This is a patch bump (not minor), so:

  1. Update go directive from 1.26.5 to 1.26.6 in ALL go.mod files:

    • Root go.mod (UPDATE FIRST)
    • tools-go/go.mod
    • All sub-module go.mod files (azure-ipam, azure-ip-masq-merger, azure-iptables-monitor, bpf-prog/ipv6-hp-bpf, cilium-log-collector, cni, crd, dropgz, npm, pkgerrlint, tools/azure-npm-to-cilium-validator, zapai)
  2. Update build/images.mk — update the GO_IMG digest (SHA256) to the new Go 1.26.6 image. Use skopeo inspect or read from .github/image-digests/go-image.txt if pre-cached.

  3. Update .pipelines/build/scripts/install-go.sh — update DEFAULT_IMAGE SHA to the new Go 1.26.6 digest.

  4. Update bpf-prog/ipv6-hp-bpf/linux.Dockerfile — update Go image SHA.

  5. Update npm/linux.Dockerfile and npm/windows.Dockerfile — update Go tag from 1.26.5 to 1.26.6.

  6. Run make dockerfiles to regenerate all template-based Dockerfiles.

  7. Run go build ./... to verify compilation.

  8. Do NOT run go mod tidy — it times out in the agent environment. Existing go.sum files remain valid for patch bumps.

  9. Do NOT change GOEXPERIMENT settings — patch bumps don't change crypto requirements.

Target Branch

master

PR Title

chore: bump Go 1.26.5 → 1.26.6 (stdlib CVE fixes)

Validation

After changes, verify:

# All go.mod files updated
grep -r "^go " */go.mod go.mod tools-go/go.mod | grep -v vendor

# build/images.mk has new digest
grep "GO_IMG" build/images.mk

# npm Dockerfiles updated
grep "golang:" npm/linux.Dockerfile npm/windows.Dockerfile

Priority

Critical — this unblocks all PRs failing govulncheck across the entire repo.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Labels

staleStale due to inactivity.

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions