Repository navigation
fix: Native CLI builds use the patched Go runtime - #1627
Conversation
Use the patched Go release that fixes GO-2026-5856 so CLI security scans and future native builds no longer use the vulnerable crypto/tls standard library.
|
Important Review skippedReview was skipped due to path filters ⛔ Files ignored due to path filters (1)
CodeRabbit blocks several paths by default. You can override this behavior by explicitly including those paths in the path filters. For example, including ⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: CHILL Plan: Pro Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
No issues found across 1 file
You’re at about 93% of the monthly reviewed-line limit. You may want to disable incremental reviews to conserve quota. Reviews will continue until that limit is exceeded. If you need help avoiding interruptions, please contact contact@cubic.dev.
Summary
GO-2026-5856.User Impact
crypto/tlsstandard library.Changes
cli/.go-version.go.modandgo.workatgo 1.26; they intentionally declare only the language/toolchain minor version.cli/.go-versionis outside the shared input trigger rules.Verification
go versionreportsgo1.26.5 darwin/arm64.scripts/check-go-cli.shpassed for all Go modules and native dist verification.scripts/test-go-cli-toolchain.shpassed.govulncheck ./...reportedNo vulnerabilities foundforcli/common,cli/dispatcher,cli/project-runner, andcli/release-automation.v3-betabase and was not caused by the concurrent C# refactor PR.