Skip to content

Security patch: bump Go 1.26.3 and gomarkdown#1073

Merged
fretz12 merged 1 commit into
release/1.7.xfrom
fredtzeng/cli-1.7.1-cve-fixes
Jun 1, 2026
Merged

Security patch: bump Go 1.26.3 and gomarkdown#1073
fretz12 merged 1 commit into
release/1.7.xfrom
fredtzeng/cli-1.7.1-cve-fixes

Conversation

@fretz12
Copy link
Copy Markdown

@fretz12 fretz12 commented Jun 1, 2026

What changed?

Security-only dependency bumps for CLI v1.7.1, shipping in the OSS server v1.31.1 admin-tools image.

  • Go toolchain 1.26.2 -> 1.26.3 — clears stdlib HIGH CVEs visible in admin-tools image scans (CVE-2026-39820, -42499, -39836, -33814, -33811, -42501).
  • github.com/gomarkdown/markdown v0.0.0-20250311... -> v0.0.0-20260411013819-759bbc3e3207 — clears GHSA-77fj-vx54-gvh7 / CVE-2026-40890. Indirect dep pulled in via the embedded UI server.

Security-only dependency bumps for CLI v1.7.1, shipping in the OSS server v1.31.1 admin-tools image.

  - Go toolchain 1.26.2 -> 1.26.3 — clears stdlib HIGH CVEs visible in admin-tools image scans (CVE-2026-39820, -42499, -39836, -33814, -33811, -42501).
  - github.com/gomarkdown/markdown v0.0.0-20250311... -> v0.0.0-20260411013819-759bbc3e3207 — clears GHSA-77fj-vx54-gvh7 / CVE-2026-40890. Indirect dep pulled in via the embedded UI server.
@fretz12 fretz12 requested a review from a team as a code owner June 1, 2026 22:33
@CLAassistant
Copy link
Copy Markdown

CLAassistant commented Jun 1, 2026

CLA assistant check
All committers have signed the CLA.

@fretz12 fretz12 requested a review from chaptersix June 1, 2026 22:35
@fretz12 fretz12 changed the base branch from main to release/1.7.x June 1, 2026 22:37
@chaptersix
Copy link
Copy Markdown
Contributor

chaptersix commented Jun 1, 2026

@fretz12

Indirect dep pulled in via the embedded UI server.

Should we just get the UI team to patch it? Are they patching this right now?

@fretz12 fretz12 merged commit d398407 into release/1.7.x Jun 1, 2026
10 checks passed
@fretz12 fretz12 deleted the fredtzeng/cli-1.7.1-cve-fixes branch June 1, 2026 23:19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants