Skip to content

Bump minimum Go version to 1.26 - #287

Merged
pk910 merged 2 commits into
masterfrom
pk910/go-1.26
Sep 11, 2026
Merged

pk910 merged 2 commits into
masterfrom
pk910/go-1.26

Conversation

@pk910

@pk910 pk910 commented Sep 11, 2026

Copy link
Copy Markdown
Member

Summary

Moves the project to Go 1.26. Dependencies have started to require it (goose v3.28.0 in #284), and since the CI toolchain runs with GOTOOLCHAIN=local those dependabot updates currently fail before the first go command:

go: go.mod requires go >= 1.26.0 (running go 1.25.14; GOTOOLCHAIN=local)

Changes

  • go.mod go directive 1.25.7 → 1.26.0
  • go-version: 1.26.x in _shared-check.yaml, _shared-build.yaml (all four build jobs) and dependabot-fix.yml
  • Dockerfile build stage on golang:1.26
  • staticcheck pin v0.7.0 → v0.8.1 (the release whose go directive is 1.26; v0.7.0 targets 1.25)
  • Build requirement docs in README, CLAUDE.md and docs/app-users.md
  • Two dead contractNonce++ statements removed in scenarios/xentoken/deployment.go; staticcheck v0.8 reports them as SA4006 and would fail the check job

Verification (with the go1.26.0 toolchain)

  • go mod tidy makes no further change, go vet, gofmt -s, scripts/check-core-imports.sh, the with_blob_v1,ckzg build and the full test suite pass
  • make generate-symbols produces no diff, so the yaegi symbol files are unaffected
  • staticcheck v0.8.1 over all packages except plugin/symbols reports nothing

Once merged, #284 can be rebased and should pass.

The trailing contractNonce++ after the last contract of each deployment
sequence is never read. staticcheck v0.8 reports it as SA4006.
Dependencies have started to require Go 1.26 (goose v3.28.0 in #284), and
the CI toolchain is pinned with GOTOOLCHAIN=local, so those updates fail
before the first go command. Move the go directive, every workflow
go-version, the Docker build image and the docs to 1.26, and bump the
pinned staticcheck to v0.8.1, the release built against the 1.26
toolchain.
@redpandabot

redpandabot Bot commented Sep 11, 2026

Copy link
Copy Markdown

Summary

Clean, well-scoped Go 1.26 bump: go.mod directive, all four CI jobs, the dependabot-fix job and the Docker build base are consistently moved to 1.26, docs updated, and the staticcheck pin is bumped to v0.8.1 (whose go directive is confirmed 1.26.0 vs v0.7.0's 1.25). The two removed contractNonce++ statements are genuine trailing dead stores — I traced both and they are never read after their scope, while the one increment that feeds the XENCrypto decision (line 73) was correctly kept — so the xentoken deployment change is behavior-preserving.

Issues

  • 🟡 go.mod:3 — go.mod floor pins the first 1.26 release, which carries ~34 known stdlib CVEs — OSV returns 34 vulns for go 1.26.0 itself (e.g. GO-2026-4599 crypto/x509 email-constraint bypass, GO-2026-4600 x509 verification panic), all fixed only in 1.26.1. This is mitigated in practice — CI uses go-version: 1.26.x and Docker golang:1.26, both floating tags that resolve to patched releases, and the directive doesn't pin the toolchain — so real builds aren't affected, and the current 1.25.7 floor has similar endemic vulns. But the PR (and its verification) is built against the exact vulnerable 1.26.0 release; setting the directive to go 1.26.1 would make the stated minimum a patched floor at no cost.

Reviewed @ f2825aec
"First we travel, then we tell the wife."

@pk910
pk910 merged commit 415012e into master Sep 11, 2026
3 checks passed
@pk910
pk910 deleted the pk910/go-1.26 branch September 11, 2026 06:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant