Skip to content

build: Go 1.27.1 and engine v0.5.0 (do not merge until grpc GO-2026-6443 is resolved) - #10

Merged
tannevaled merged 2 commits into
mainfrom
go-1.27-upgrade
Oct 4, 2026
Merged

tannevaled merged 2 commits into
mainfrom
go-1.27-upgrade

Conversation

@tannevaled

Copy link
Copy Markdown
Contributor

Go floor 1.27.1 and engine v0.5.0. Build, vet and tests pass under Go 1.27.1.

Blocking security finding, not merged: govulncheck reports GO-2026-6443 in google.golang.org/grpc v1.84.0 (the latest released version): a server panic on requests missing both the authority and Host headers. browserproxy.Server.HandlerListener reaches it, so a remote client can crash the service. The fix exists only in pre-release versions (v1.85.0-dev). This branch keeps v1.84.0. Decide: a pinned pre-release, a request-level guard that rejects empty authority/Host before gRPC, or waiting for the release.

🤖 Generated with Claude Code

tannevaled and others added 2 commits October 4, 2026 20:59
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
…ng Host/authority)

No released grpc carries the fix yet; the pre-release is pinned deliberately.
govulncheck under Go 1.27.1: no code-affected findings.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@tannevaled
tannevaled merged commit 63a7d43 into main Oct 4, 2026
8 checks passed
@tannevaled
tannevaled deleted the go-1.27-upgrade branch October 4, 2026 19:16
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant