fix(deps): clear known vulnerabilities in what ships; build on the Go line CI tests (M462 #4984)
- golang.org/x/text v0.37.0 -> v0.39.0 (GO-2026-5970, infinite loop on invalid input, reachable from pgxpool). x/sync follows to v0.21.0. - web lockfile: in-range updates from `npm audit fix` for devalue (high) and svelte (moderate), both of which ship in the browser bundle. package.json is unchanged. - Dockerfile builder golang:1.25 -> golang:1.26. CI has tested on 1.26 since the ci-go migration while the image was still compiled with 1.25, left over from the April skeleton; the shipped binary now uses the toolchain the tests ran on. govulncheck under golang:1.26-bookworm (go1.26.8) reports 0 vulnerabilities reachable from our code. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
+1
-1
@@ -7,7 +7,7 @@ RUN npm ci
|
||||
COPY web/ ./
|
||||
RUN npm run build
|
||||
|
||||
FROM golang:1.25-bookworm AS builder
|
||||
FROM golang:1.26-bookworm AS builder
|
||||
WORKDIR /src
|
||||
COPY go.mod go.sum ./
|
||||
RUN go mod download
|
||||
|
||||
Reference in New Issue
Block a user