Skip to content

chore: bump deps#51

Merged
avidal merged 1 commit intomainfrom
avidal/bump-go
Apr 2, 2026
Merged

chore: bump deps#51
avidal merged 1 commit intomainfrom
avidal/bump-go

Conversation

@avidal
Copy link
Copy Markdown
Collaborator

@avidal avidal commented Apr 2, 2026

None of the CVEs filed against earlier versions of Go are applicable to commit-headless, but this ensures that security/vuln scans of images that copy in commit-headless don't trigger an error.

closes #47 #48 #49 #50

@avidal avidal requested a review from a team as a code owner April 2, 2026 15:38
@avidal avidal changed the title chore: bump go to 1.25.8 minimum to address vulns chore: bump deps Apr 2, 2026
The important bump is to the Go toolchain to address some stdlib
vulnerabilities and prevent security scanners from flagging images that
COPY commit-headless.

But, might as well rev the other dependencies while we're at it.
@avidal avidal merged commit 2fb5f49 into main Apr 2, 2026
14 checks passed
@avidal avidal deleted the avidal/bump-go branch April 2, 2026 16:51
github-actions Bot added a commit that referenced this pull request Apr 2, 2026
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants