From 37790718c0bf103935ddc6e228e5a0996d25545b Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Mon, 21 Sep 2026 11:04:22 +0000 Subject: [PATCH 1/2] Bump golang from 1.26.8-alpine3.24 to 1.27.1-alpine3.24 Bumps golang from 1.26.8-alpine3.24 to 1.27.1-alpine3.24. --- updated-dependencies: - dependency-name: golang dependency-version: 1.27.1-alpine3.24 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] --- Dockerfile | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/Dockerfile b/Dockerfile index 0930b72..750bc6d 100644 --- a/Dockerfile +++ b/Dockerfile @@ -1,6 +1,6 @@ # hadolint global ignore=DL3047,DL4001,DL4006 # Multi-stage build for Go application -FROM golang:1.26.8-alpine3.24 AS builder +FROM golang:1.27.1-alpine3.24 AS builder # Ensure base packages are up-to-date to pick up security fixes before installing build deps RUN apk update && apk upgrade --available --no-cache From 70c9f5776e53b154b346c160a58f7a48930c5b5c Mon Sep 17 00:00:00 2001 From: "copilot-swe-agent[bot]" <198982749+Copilot@users.noreply.github.com> Date: Mon, 28 Sep 2026 22:05:50 +0000 Subject: [PATCH 2/2] Sync setup-go with Docker toolchain Co-authored-by: juliojimenez <648113+juliojimenez@users.noreply.github.com> --- .github/workflows/tests.yml | 14 +++++++------- CLAUDE.md | 2 +- 2 files changed, 8 insertions(+), 8 deletions(-) diff --git a/.github/workflows/tests.yml b/.github/workflows/tests.yml index 3664de3..42041e0 100644 --- a/.github/workflows/tests.yml +++ b/.github/workflows/tests.yml @@ -16,7 +16,7 @@ jobs: - name: 🔧 Setup Go uses: actions/setup-go@v7 with: - go-version: '1.26.8' + go-version: '1.27.1' cache: true - name: 📦 Download dependencies @@ -63,7 +63,7 @@ jobs: - name: 🔧 Setup Go uses: actions/setup-go@v7 with: - go-version: '1.26.8' + go-version: '1.27.1' cache: true - name: 📦 Install CycloneDX CLI @@ -132,7 +132,7 @@ jobs: - name: 🔧 Setup Go uses: actions/setup-go@v7 with: - go-version: '1.26.8' + go-version: '1.27.1' cache: true - name: 🔍 Run golangci-lint @@ -178,7 +178,7 @@ jobs: - name: 🔧 Setup Go uses: actions/setup-go@v7 with: - go-version: '1.26.8' + go-version: '1.27.1' cache: true - name: 🏗️ Build for ${{ matrix.goos }}/${{ matrix.goarch }} @@ -312,7 +312,7 @@ jobs: - name: 🔧 Setup Go uses: actions/setup-go@v7 with: - go-version: '1.26.8' + go-version: '1.27.1' cache: true - name: 🏗️ Build @@ -349,7 +349,7 @@ jobs: - name: 🔧 Setup Go uses: actions/setup-go@v7 with: - go-version: '1.26.8' + go-version: '1.27.1' cache: true - name: ⚡ Run benchmarks @@ -375,7 +375,7 @@ jobs: - name: 🔧 Setup Go uses: actions/setup-go@v7 with: - go-version: '1.26.8' + go-version: '1.27.1' cache: true - name: 🔍 Run Trivy vulnerability scanner diff --git a/CLAUDE.md b/CLAUDE.md index 68df2a4..777a7c2 100644 --- a/CLAUDE.md +++ b/CLAUDE.md @@ -45,7 +45,7 @@ docker build --platform linux/amd64 -t clickbom:test . docker run --rm --platform linux/amd64 --entrypoint /usr/local/bin/cyclonedx clickbom:test --version ``` -[go.mod](go.mod) declares `go 1.25` as the minimum language version; the toolchain actually used is **Go 1.26.8** in both CI ([.github/workflows/tests.yml](.github/workflows/tests.yml), all `setup-go` steps) and the Dockerfile builder (`golang:1.26.8-alpine3.24`). Keep those two in lockstep and on the newest 1.26.x patch: the `test_security` job runs `govulncheck ./...` against that exact toolchain and fails on any reachable stdlib CVE (with 1.26.4 it reported six), which is the intended signal that the shipped binary needs a rebuild. Dependabot bumps the Dockerfile tag; bump `setup-go` in the same PR. (`govulncheck@latest`, x/vuln ≥ 1.8, also refuses to run on anything older than 1.26.) Pre-commit hooks ([.pre-commit-config.yaml](.pre-commit-config.yaml)) run `gofmt`, `goimports -local github.com/ClickHouse/ClickBOM`, `go test -short -race`, `go mod tidy`, `gocyclo -over 26`, and `golangci-lint --fix`. +[go.mod](go.mod) declares `go 1.25` as the minimum language version; the toolchain actually used is **Go 1.27.1** in both CI ([.github/workflows/tests.yml](.github/workflows/tests.yml), all `setup-go` steps) and the Dockerfile builder (`golang:1.27.1-alpine3.24`). Keep those two in lockstep and on the newest 1.27.x patch: the `test_security` job runs `govulncheck ./...` against that exact toolchain and fails on any reachable stdlib CVE (with 1.26.4 it reported six), which is the intended signal that the shipped binary needs a rebuild. Dependabot bumps the Dockerfile tag; bump `setup-go` in the same PR. (`govulncheck@latest`, x/vuln ≥ 1.8, also refuses to run on anything older than 1.26.) Pre-commit hooks ([.pre-commit-config.yaml](.pre-commit-config.yaml)) run `gofmt`, `goimports -local github.com/ClickHouse/ClickBOM`, `go test -short -race`, `go mod tidy`, `gocyclo -over 26`, and `golangci-lint --fix`. ## Architecture