From 89da6e73b2774876246b6942a143ce12cd8c982c Mon Sep 17 00:00:00 2001 From: packetloss404 Date: Sat, 5 Sep 2026 13:33:40 -0500 Subject: [PATCH 1/3] deps: take x/crypto v0.56.0 and raise the language floor to Go 1.26 govulncheck reported seven reachable advisories, all in x/crypto v0.43.0 and all reached through internal/computers/ssh_backend.go. Five are fixed in v0.52.0; GO-2026-6354 and GO-2026-6355, both SSH channel deadlock DoS, need v0.56.0. v0.56.0 declares go 1.26.0, so taking the fix raises the module's floor from 1.24.2. The intermediate option was considered and rejected. v0.52.0 needs only go 1.25.0, but Go supports the two most recent majors and the current release is 1.27, so 1.25 is already end of life: it would move the floor to an unsupported language version, clear five of seven, and leave vulncheck failing with two live DoS paths. Raising the floor is the cost either way, so it should buy the whole fix. The floor moves less than it appears. CI and the release pipeline already build with a 1.26 toolchain, and go.mod carries no toolchain line, so with the default GOTOOLCHAIN=auto a contributor on an older Go fetches a compliant toolchain rather than failing. Only builds pinned to GOTOOLCHAIN=local, chiefly distro packaging, have to move. x/sys and x/text come along as transitive upgrades. The three places that state the build requirement move with it. After this, govulncheck reports no reachable module advisories at all. Co-Authored-By: Claude Opus 5 --- README.md | 2 +- docs/getting-started.md | 2 +- docs/manual.md | 2 +- go.mod | 8 ++++---- go.sum | 21 ++++++++------------- 5 files changed, 15 insertions(+), 20 deletions(-) diff --git a/README.md b/README.md index d5d261f..2240136 100644 --- a/README.md +++ b/README.md @@ -65,7 +65,7 @@ Windows) to make an unverifiable download an error rather than a note. See [docs/releases.md](docs/releases.md) for what is published, how to verify a download by hand, and how release signing is configured. -Build from source with Go 1.24.2 or newer: +Build from source with Go 1.26.0 or newer: ```bash make build diff --git a/docs/getting-started.md b/docs/getting-started.md index f70bd2d..f3ec336 100644 --- a/docs/getting-started.md +++ b/docs/getting-started.md @@ -2,7 +2,7 @@ ## Build and Run -packetcode requires Go 1.24.2 or newer. +packetcode requires Go 1.26.0 or newer. ```bash make build diff --git a/docs/manual.md b/docs/manual.md index 1b6b3b6..b91f319 100644 --- a/docs/manual.md +++ b/docs/manual.md @@ -6,7 +6,7 @@ This manual starts with the shortest path to a useful session, then introduces t ## 1. Install and Start -packetcode requires Go 1.24.2 or newer when building from source. +packetcode requires Go 1.26.0 or newer when building from source. ### macOS or Linux release install diff --git a/go.mod b/go.mod index 0ba0139..5653402 100644 --- a/go.mod +++ b/go.mod @@ -1,6 +1,6 @@ module github.com/packetcode/packetcode -go 1.24.2 +go 1.26.0 require ( github.com/BurntSushi/toml v1.6.0 @@ -14,8 +14,8 @@ require ( github.com/pkg/sftp v1.13.10 github.com/pmezard/go-difflib v1.0.0 github.com/stretchr/testify v1.11.1 - golang.org/x/crypto v0.43.0 - golang.org/x/sys v0.38.0 + golang.org/x/crypto v0.56.0 + golang.org/x/sys v0.47.0 ) require ( @@ -37,6 +37,6 @@ require ( github.com/muesli/termenv v0.16.0 // indirect github.com/rivo/uniseg v0.4.7 // indirect github.com/xo/terminfo v0.0.0-20220910002029-abceb7e1c41e // indirect - golang.org/x/text v0.30.0 // indirect + golang.org/x/text v0.41.0 // indirect gopkg.in/yaml.v3 v3.0.1 // indirect ) diff --git a/go.sum b/go.sum index 3f69f5a..a3608ce 100644 --- a/go.sum +++ b/go.sum @@ -60,23 +60,18 @@ github.com/stretchr/testify v1.11.1 h1:7s2iGBzp5EwR7/aIZr8ao5+dra3wiQyKjjFuvgVKu github.com/stretchr/testify v1.11.1/go.mod h1:wZwfW3scLgRK+23gO65QZefKpKQRnfz6sD981Nm4B6U= github.com/xo/terminfo v0.0.0-20220910002029-abceb7e1c41e h1:JVG44RsyaB9T2KIHavMF/ppJZNG9ZpyihvCd0w101no= github.com/xo/terminfo v0.0.0-20220910002029-abceb7e1c41e/go.mod h1:RbqR21r5mrJuqunuUZ/Dhy/avygyECGrLceyNeo4LiM= -golang.org/x/crypto v0.41.0 h1:WKYxWedPGCTVVl5+WHSSrOBT0O8lx32+zxmHxijgXp4= -golang.org/x/crypto v0.41.0/go.mod h1:pO5AFd7FA68rFak7rOAGVuygIISepHftHnr8dr6+sUc= -golang.org/x/crypto v0.43.0 h1:dduJYIi3A3KOfdGOHX8AVZ/jGiyPa3IbBozJ5kNuE04= -golang.org/x/crypto v0.43.0/go.mod h1:BFbav4mRNlXJL4wNeejLpWxB7wMbc79PdRGhWKncxR0= +golang.org/x/crypto v0.56.0 h1:GUh5Ii4J5jtcseSMiRqr1jXCNHoxjeV9Fmekc2oLy6Y= +golang.org/x/crypto v0.56.0/go.mod h1:OMW5y6CY9l38uPLmxU6l6pwcXp1obtLo3e6gT7gQR2I= golang.org/x/exp v0.0.0-20231006140011-7918f672742d h1:jtJma62tbqLibJ5sFQz8bKtEM8rJBtfilJ2qTU199MI= golang.org/x/exp v0.0.0-20231006140011-7918f672742d/go.mod h1:ldy0pHrwJyGW56pPQzzkH36rKxoZW1tw7ZJpeKx+hdo= golang.org/x/sys v0.0.0-20210809222454-d867a43fc93e/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg= golang.org/x/sys v0.6.0/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg= -golang.org/x/sys v0.38.0 h1:3yZWxaJjBmCWXqhN1qh02AkOnCQ1poK6oF+a7xWL6Gc= -golang.org/x/sys v0.38.0/go.mod h1:OgkHotnGiDImocRcuBABYBEXf8A9a87e/uXjp9XT3ks= -golang.org/x/term v0.34.0 h1:O/2T7POpk0ZZ7MAzMeWFSg6S5IpWd/RXDlM9hgM3DR4= -golang.org/x/term v0.34.0/go.mod h1:5jC53AEywhIVebHgPVeg0mj8OD3VO9OzclacVrqpaAw= -golang.org/x/term v0.36.0 h1:zMPR+aF8gfksFprF/Nc/rd1wRS1EI6nDBGyWAvDzx2Q= -golang.org/x/text v0.28.0 h1:rhazDwis8INMIwQ4tpjLDzUhx6RlXqZNPEM0huQojng= -golang.org/x/text v0.28.0/go.mod h1:U8nCwOR8jO/marOQ0QbDiOngZVEBB7MAiitBuMjXiNU= -golang.org/x/text v0.30.0 h1:yznKA/E9zq54KzlzBEAWn1NXSQ8DIp/NYMy88xJjl4k= -golang.org/x/text v0.30.0/go.mod h1:yDdHFIX9t+tORqspjENWgzaCVXgk0yYnYuSZ8UzzBVM= +golang.org/x/sys v0.47.0 h1:o7XGOvZQCADBQQ4Y7VNq2dRWQR7JmOUW8Kxx4ZsNgWs= +golang.org/x/sys v0.47.0/go.mod h1:4GL1E5IUh+htKOUEOaiffhrAeqysfVGipDYzABqnCmw= +golang.org/x/term v0.45.0 h1:NwWyBmoJCbfTHpxrWoZ9C6/VxOf7ic219I8xZZFdrf0= +golang.org/x/term v0.45.0/go.mod h1:9aqxs0blBcrm/n0L9QW0aRVD+ktan8ssZromtqJC43w= +golang.org/x/text v0.41.0 h1:vz/seA0lnX87Othu2f/0L24RcgrXD9/YFTSuGjj3rH8= +golang.org/x/text v0.41.0/go.mod h1:jvf1O8ajNzZqhSrQBPbutR/EB83Cc0CFrezNQIwbb5M= gopkg.in/check.v1 v0.0.0-20161208181325-20d25e280405 h1:yhCVgyC4o1eVCa2tZl7eS0r+SDo693bJlVdllGtEeKM= gopkg.in/check.v1 v0.0.0-20161208181325-20d25e280405/go.mod h1:Co6ibVJAznAaIkqp8huTwlJQCZ016jof/cbN4VW5Yz0= gopkg.in/yaml.v3 v3.0.1 h1:fxVm/GzAzEWqLHuvctI91KS9hhNmmWOoWu0XTYJS7CA= From 872e276f8905e087a4d9d8f96002dda8b5adf65b Mon Sep 17 00:00:00 2001 From: packetloss404 Date: Sat, 5 Sep 2026 13:33:40 -0500 Subject: [PATCH 2/3] ci: pin Go 1.27.1 The remaining govulncheck findings are all standard library, and the highest of them is fixed in go1.26.6 -- so the 1.26.8 pin already covered them. 1.27.1 is the current release, and pinning the newer of the two supported majors is the position that needs the least maintenance. 1.26.8 was chosen while looking only within the 1.26 line; 1.27 was current the whole time. Co-Authored-By: Claude Opus 5 --- .github/workflows/ci.yml | 2 +- .github/workflows/release.yml | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index f6e89aa..c288710 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -10,7 +10,7 @@ permissions: contents: read env: - GO_VERSION: '1.26.8' + GO_VERSION: '1.27.1' GOLANGCI_LINT_VERSION: v2.9.0 GOVULNCHECK_VERSION: v1.3.0 GORELEASER_VERSION: v2.9.0 diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 98ad8a0..e4ea1aa 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -16,7 +16,7 @@ permissions: attestations: write env: - GO_VERSION: '1.26.8' + GO_VERSION: '1.27.1' GORELEASER_VERSION: v2.9.0 COSIGN_VERSION: v2.4.1 From 7898a6a43503e8b8ca3f3f2164864229eb2a13a9 Mon Sep 17 00:00:00 2001 From: packetloss404 Date: Sat, 5 Sep 2026 13:37:46 -0500 Subject: [PATCH 3/3] Revert "ci: pin Go 1.27.1" This reverts commit 872e276. golangci-lint v2.9.0, the version CI pins, is itself built with Go 1.26 and cannot typecheck a 1.27 standard library. The lint job panicked outright: panic: file requires newer Go version go1.27 (application built with go1.26) So the CI toolchain cannot move ahead of the linter's own build, which the "pin the newer supported major" reasoning missed. 1.26.8 stays, and it loses nothing: every reachable stdlib advisory is fixed by go1.26.6, so vulncheck is green on 1.26.8 as well. Moving to 1.27 needs a golangci-lint release built against it, and is a separate change. Co-Authored-By: Claude Opus 5 --- .github/workflows/ci.yml | 2 +- .github/workflows/release.yml | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index c288710..f6e89aa 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -10,7 +10,7 @@ permissions: contents: read env: - GO_VERSION: '1.27.1' + GO_VERSION: '1.26.8' GOLANGCI_LINT_VERSION: v2.9.0 GOVULNCHECK_VERSION: v1.3.0 GORELEASER_VERSION: v2.9.0 diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index e4ea1aa..98ad8a0 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -16,7 +16,7 @@ permissions: attestations: write env: - GO_VERSION: '1.27.1' + GO_VERSION: '1.26.8' GORELEASER_VERSION: v2.9.0 COSIGN_VERSION: v2.4.1