Skip to content

Conversation

@nicholasngai
Copy link
Contributor

@nicholasngai nicholasngai commented Oct 17, 2025

Description:

Cherry-picking #665 onto v5.

Related issue:

Closes #664.

Check list:

  • Mark if documentation changes are required.
  • Mark if tests were added or updated to cover the changes.

@nicholasngai nicholasngai requested a review from a team as a code owner October 17, 2025 19:08
@nicholasngai nicholasngai changed the title Fall back to downloading from go.dev/dl instead of storage.googleapiscom/golang [v5] Fall back to downloading from go.dev/dl instead of storage.googleapiscom/golang Oct 17, 2025
@nicholasngai nicholasngai changed the title [v5] Fall back to downloading from go.dev/dl instead of storage.googleapiscom/golang [v5] Fall back to downloading from go.dev/dl instead of storage.googleapis.com/golang Oct 17, 2025
@aparnajyothi-y
Copy link
Contributor

Hello @nicholasngai, Thanks for this pull request. Could you also include the audit-related fixes as part of this change, just for the releases/v5 branch to move forward.

@nicholasngai
Copy link
Contributor Author

Hi @aparnajyothi-y! What audit-related fixes are you referring to?

@nicholasngai
Copy link
Contributor Author

@aparnajyothi-y Hey, just bumping this question. :)

@rolandshoemaker
Copy link

@nicholasngai I believe @aparnajyothi-y is referring to https://github.com/actions/setup-go/actions/runs/18602396198/job/53580106842?pr=666, some npm packages need to be updated to resolve security issues.

@aparnajyothi-y
Copy link
Contributor

Hi @nicholasngai, apologies for the delay and thank you for following up. Yes, as @rolandshoemaker pointed out, I was referring to the security audit fixes needed for the releases/v5 branch by running npm audit fix command. specifically updating the npm packages flagged in the audit report to ensure we resolve the security warnings. It would be great if we could include those updates along with this change so the v5 branch stays compliant.
Let me know if you need any details and thanks again for your contribution!

@nicholasngai
Copy link
Contributor Author

@aparnajyothi-y Sorry for the delay here! I ran npm audit fix on all the branches. Do you mind helping me getting them all merged in? Thanks!

@aparnajyothi-y
Copy link
Contributor

Hi @nicholasngai , the checks are still failing, but given the community interest and the broader value of this update, we’re moving forward with incorporating these changes so that the v5 branch remains fully compliant for release.

Please let me know if you need any additional details. Thanks again for your contribution and really appreciate the effort!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants