Update Go to 1.26.5 to fix stdlib CVEs
Bump the Go toolchain from 1.26.4 to 1.26.5 to address CVE-2026-42505 (ECH handshake de-anonymization) and CVE-2026-39822 (os.Root symlink following on Unix). Signed-off-by: Sacha Al Himdani <sacha@probo.com>
This commit is contained in:
2
.github/actions/setup/action.yaml
vendored
2
.github/actions/setup/action.yaml
vendored
@@ -15,7 +15,7 @@ runs:
|
||||
- if: inputs.go == 'true'
|
||||
uses: "actions/setup-go@v6"
|
||||
with:
|
||||
go-version: "1.26.4"
|
||||
go-version: "1.26.5"
|
||||
cache: true
|
||||
- if: inputs.go == 'true'
|
||||
shell: bash
|
||||
|
||||
@@ -11,7 +11,7 @@ export LIMA_CIDATA_USER
|
||||
|
||||
export DEBIAN_FRONTEND=noninteractive
|
||||
|
||||
GO_VERSION="1.26.4"
|
||||
GO_VERSION="1.26.5"
|
||||
NODE_MAJOR=24
|
||||
NPM_VERSION="11.8.0"
|
||||
|
||||
|
||||
Reference in New Issue
Block a user