fix(deps): clear known vulnerabilities in what ships; build on the Go line CI tests (M462 #4984)

- golang.org/x/text v0.37.0 -> v0.39.0 (GO-2026-5970, infinite loop on
  invalid input, reachable from pgxpool). x/sync follows to v0.21.0.
- web lockfile: in-range updates from `npm audit fix` for devalue (high)
  and svelte (moderate), both of which ship in the browser bundle.
  package.json is unchanged.
- Dockerfile builder golang:1.25 -> golang:1.26. CI has tested on 1.26
  since the ci-go migration while the image was still compiled with 1.25,
  left over from the April skeleton; the shipped binary now uses the
  toolchain the tests ran on. govulncheck under golang:1.26-bookworm
  (go1.26.8) reports 0 vulnerabilities reachable from our code.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
2026-10-06 09:51:37 -04:00
co-authored by Claude Opus 5.5
parent 327d49428f
commit 3217e10168
4 changed files with 96 additions and 155 deletions
+1 -1
View File
@@ -7,7 +7,7 @@ RUN npm ci
COPY web/ ./
RUN npm run build
FROM golang:1.25-bookworm AS builder
FROM golang:1.26-bookworm AS builder
WORKDIR /src
COPY go.mod go.sum ./
RUN go mod download