Skip to content

Commit 5344650

Browse files
authored
fix: upgrade Go to 1.25.12 (#12602)
fix: upgrade Go to 1.25.12 (CVE-2026-39822) The release image Trivy scan blocks on CVE-2026-39822 in the Go stdlib (os.Root symlink following / directory traversal, HIGH), present in the Go 1.25.11 binary and fixed in 1.25.12. Bump the go directive in go.mod to 1.25.12 (this drives the golang-alpine build image the docker-build job derives from go.mod) and update the pinned GOLANG_BUILD_IMAGE in release.yml to the matching 1.25.12 digest. Signed-off-by: Julian Koberg <julian.koberg@kiteworks.com>
1 parent 8481d02 commit 5344650

3 files changed

Lines changed: 10 additions & 2 deletions

File tree

‎.github/workflows/release.yml‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -16,7 +16,7 @@ on:
1616
env:
1717
NODE_VERSION: '24'
1818
PNPM_VERSION: '10.28.1'
19-
GOLANG_BUILD_IMAGE: 'golang:1.25.11-alpine3.23@sha256:c05ba4b73604069d376c4f41346b05374335b5ca0c46fb6dfede5a59f5196931'
19+
GOLANG_BUILD_IMAGE: 'golang:1.25.12-alpine3.23@sha256:cc985ef6f9c3bf9ece7488129c9abe0a150388ccdfa428d886fc709dca0b230a'
2020

2121
jobs:
2222
determine-release-type:
Lines changed: 8 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,8 @@
1+
Security: Upgrade Go to 1.25.12
2+
3+
Bumped the Go toolchain used to build the release binaries and Docker images
4+
from 1.25.11 to 1.25.12. Go 1.25.11 is affected by CVE-2026-39822 (os.Root
5+
symlink following allows directory traversal), which is fixed in 1.25.12 and
6+
was blocking the release image security scan.
7+
8+
https://github.com/owncloud/ocis/pull/12602

‎go.mod‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
module github.com/owncloud/ocis/v2
22

3-
go 1.25.11
3+
go 1.25.12
44

55
require (
66
dario.cat/mergo v1.0.2

0 commit comments

Comments
 (0)