Skip to content

Move to Go 1.26.8 and clear reachable dependency vulnerabilities - #394

Merged
dpage merged 4 commits into
mainfrom
security-dep-bumps
Sep 14, 2026
Merged

dpage merged 4 commits into
mainfrom
security-dep-bumps

Conversation

@dpage

@dpage dpage commented Aug 7, 2026 •

Copy link
Copy Markdown
Member

Background

Codacy currently reports a large pile of SCA advisories against this
repository, and most of them are noise in the sense that nothing in the
Workbench actually calls the vulnerable code. Rather than bump things on
the strength of the advisory list, I ran govulncheck across all four Go
modules to establish which vulnerabilities are genuinely reachable from
our own call graphs. Four came back, and this change clears all four.

Advisory Component Fixed in Where it is reached
GO-2026-5970 golang.org/x/text v0.33.0 v0.39.0 pgxpool setup in all three services, and server/src/internal/auth/common_passwords.go:105
GO-2026-5856 crypto/tls (ECH privacy leak) go1.26.5 all four modules
GO-2026-5039 net/textproto (unescaped input in errors) go1.26.4 pkg, server, alerter
GO-2026-5037 crypto/x509 (hostname parsing DoS) go1.26.4 all four modules

What changed

The Go version moves to 1.26.5 in the four module files, the three
service Dockerfile builder stages, and the CI and release workflows.

The release workflow is the one that actually mattered: it built the
published binaries with 1.26.2, so the standard library advisories
would have shipped in released artefacts no matter what the module files
said. Codacy was in fact resolving some findings against that pin rather
than against go.mod (affectedVersion: v1.26.2).

Where a workflow repeats the Go version inside an if: guard, the guard
moved along with the matrix value. Bumping only the matrix would have
left those conditions unmatchable and silently stopped the coverage and
publish steps from running, which is a quieter failure than a red build.

golang.org/x/text goes to v0.40.0, the current release, rather than
stopping at the v0.39.0 floor govulncheck reports. go mod tidy also
advanced golang.org/x/sync to v0.22.0 as a resolution side effect.

On the client, ECharts moves to v6.1.0 for a cross-site scripting
advisory, and postcss, js-yaml and brace-expansion are refreshed
transitively via npm audit fix. npm audit now reports no known
vulnerabilities, where it previously reported one moderate and four high.

Verification

  • govulncheck reports zero affected symbols in all four modules,
    down from three, three, four and four respectively. What it still
    lists are golang.org/x/crypto/ssh and ssh/agent advisories that no
    Workbench code calls.
  • All three services build, and pkg, collector and alerter test
    suites pass in full.
  • Client: lint clean (0 errors, 40 pre-existing warnings), production
    build succeeds, and 3,488 tests across 171 files pass.

Two things a reviewer should know rather than discover:

No production code is modified, so there is no new coverage to add.

Related

Separately from this PR, I triaged the 40 code-level Codacy security
findings (SQL injection, hardcoded secrets, cookie flags, timing
attacks) and ignored them with recorded justifications; all 40 were
false positives in test code, with none in production code. Open
security items went from 155 to 115, and the 115 that remain are the
dependency advisories this PR addresses.

Summary by CodeRabbit

  • Security

    • Updated Go and text-processing components to address four reachable vulnerabilities.
    • Updated web charting and related packages, leaving the web client with no known vulnerabilities.
  • Maintenance

    • Standardized builds, releases, and automated checks on Go 1.26.5.
    • Updated the web client’s charting capabilities to ECharts 6.1.0.
    • Refreshed supporting dependencies and release tooling.
  • Documentation

    • Added these security improvements to the unreleased changelog.

@coderabbitai

coderabbitai Bot commented Aug 7, 2026 •

Copy link
Copy Markdown

Review Change StackReview Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Essentials

Run ID: 2dd1d2cd-4e58-4f25-b71e-76e9977cd650

📥 Commits

Reviewing files that changed from the base of the PR and between ccb30ce and 42e1758.

📒 Files selected for processing (1)
  • .github/workflows/release.yml

Included review availability: 2 reviews are currently available. Your included PR review attempts over the past 7 days set your current allowance at 5 reviews per hour.


Walkthrough

The PR standardizes Go 1.26.5 across modules, Docker builders, CI, E2E, and release workflows. It updates indirect Go dependencies, upgrades ECharts to 6.1.0, refreshes the pinned release action, and documents the dependency changes.

Changes

Toolchain and module updates

Layer / File(s) Summary
Go modules and builder images
alerter/src/go.mod, collector/go.mod, server/src/go.mod, pkg/go.mod, alerter/Dockerfile, collector/Dockerfile, server/Dockerfile
Go modules and builder images now use Go 1.26.5. Service modules update golang.org/x/sync and golang.org/x/text where applicable.

CI and release alignment

Layer / File(s) Summary
CI and release toolchain alignment
.github/workflows/ci-*.yml, .github/workflows/release.yml
CI matrices, quality checks, coverage steps, artifact uploads, E2E setup, and release builds now target Go 1.26.5. The release workflow also refreshes the pinned softprops/action-gh-release v3 revision.

Client dependency and changelog updates

Layer / File(s) Summary
Client dependency updates
client/package.json, docs/changelog.md
The client upgrades ECharts to 6.1.0. The changelog records the Go, Go dependency, ECharts, and transitive dependency updates.

Estimated code review effort: 2 (Simple) | ~10 minutes

Merge Risk: ⚪ Minimal · up to 42e17

This dependency and toolchain refresh addresses known vulnerabilities without changing production code. Reported validation is successful, so the change is ready to merge.

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly describes the Go toolchain and dependency vulnerability updates. However, it names Go 1.26.8, while the changes update the repository to Go 1.26.5.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch security-dep-bumps

Comment @coderabbitai help to get the list of available commands.

@codacy-production

codacy-production Bot commented Aug 7, 2026 •

Copy link
Copy Markdown

Up to standards ✅

🟢 Issues 0 issues

Results:
0 new issues

View in Codacy

🟢 Metrics 0 complexity · 0 duplication

Metric Results
Complexity 0
Duplication 0

View in Codacy

NEW Get contextual insights on your PRs based on Codacy's metrics, along with PR and Jira context, without leaving GitHub. Enable AI reviewer
TIP This summary will be updated as you push new changes.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@pkg/go.mod`:
- Line 3: Add pkg/** to the path filters for the lint, vet, and test jobs in
ci-server.yml, ci-alerter.yml, and ci-collector.yml, matching the service image
build behavior in ci-docker.yml.
🪄 Autofix

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro

Run ID: 55d8e3be-c0c3-4cf2-a662-c30fe3c6ec89

📥 Commits

Reviewing files that changed from the base of the PR and between 19c645d and ccb30ce.

⛔ Files ignored due to path filters (4)
  • alerter/src/go.sum is excluded by !**/*.sum
  • client/package-lock.json is excluded by !**/package-lock.json
  • collector/go.sum is excluded by !**/*.sum
  • server/src/go.sum is excluded by !**/*.sum
📒 Files selected for processing (14)
  • .github/workflows/ci-alerter.yml
  • .github/workflows/ci-collector.yml
  • .github/workflows/ci-e2e.yml
  • .github/workflows/ci-server.yml
  • .github/workflows/release.yml
  • alerter/Dockerfile
  • alerter/src/go.mod
  • client/package.json
  • collector/Dockerfile
  • collector/go.mod
  • docs/changelog.md
  • pkg/go.mod
  • server/Dockerfile
  • server/src/go.mod

Comment thread pkg/go.mod Outdated
@dpage
dpage force-pushed the security-dep-bumps branch 2 times, most recently from 12181e6 to 1d63282 Compare September 11, 2026 12:15

@AntTheLimey AntTheLimey left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The changelog line "The client now reports no known vulnerabilities"
doesn't hold up against a fresh npm audit: it currently reports 7
(5 moderate, 2 high), down from 11 on main, all inside the vitest
dev-dependency tree and therefore not shipped in the built client, but
the sentence claims zero, and the same entry credits refreshing
js-yaml while js-yaml is still one of the two high findings. The
entry is also wrong the other way: it names four cleared
vulnerabilities, where govulncheck on main reports 14 reachable in
server, 14 in alerter, 9 in pkg and 7 in collector, all cleared by
this same bump. The fix is better than advertised. One edit fixes
both: say what was measured, so a later CVE audit can trust the
enumeration.

Two non-blocking notes: the title still says Go 1.26.5, but the
follow-up commit moved every pinned location (workflows, Dockerfiles,
all four go.mod files) to 1.26.8 consistently, so it's just the title
that's stale. And CodeRabbit's comment on pkg/go.mod is right that
ci-server.yml, ci-alerter.yml, and ci-collector.yml don't watch
pkg/** the way ci-docker.yml does, so a future pkg-only change would
rebuild and publish service images without running their lint/vet/test
jobs; this PR happens to dodge that because every commit here also
touches each service's own go.mod.

Everything else checks out against measurement: govulncheck reports
zero reachable vulnerabilities in all four Go modules on this branch,
versus 7/14/14/9 reachable stdlib issues on main, all fixed by the
go1.26.8 pin; all three service modules build cleanly against the
local pkg replace; gofmt and golangci-lint are clean everywhere;
npm ci and npm run lint pass on the client; and collector coverage
measures the same 85.9% on main and on this branch, so the four
failing collector CI jobs are the inherited COVERAGE_MIN=86 ratchet,
not a regression from this change.

No conflicts against #419 or #420 (merge-tree resolves cleanly against
both); the only shared file is docs/changelog.md, and neither sibling
touches a module file, Dockerfile, or workflow this PR changes.

Codacy reports a large number of SCA advisories against this repository,
but most of them are not reachable from Workbench code, so I ran
govulncheck across all four Go modules to find the ones that actually
are. Four came back, and this change clears all of them.

Three are standard library issues fixed in the 1.26.4 and 1.26.5 patch
releases: a privacy leak in the crypto/tls Encrypted Client Hello
handling, arbitrary input included unescaped in net/textproto error
messages, and inefficient candidate hostname parsing in crypto/x509.
The fourth is an infinite loop in golang.org/x/text normalisation,
reached through pgxpool connection setup in all three services and
directly from the server's password dictionary handling.

The Go version is raised in the four module files, in the collector,
server and alerter Dockerfile builder stages, and in the CI and release
workflows. The release workflow is the important one, because it
previously built the published binaries with the affected toolchain, so
the advisories would have shipped regardless of what the module files
said. Where a workflow repeats the version in an `if:` guard, the guard
moved with the matrix value; leaving those behind would have silently
stopped the coverage and publish steps from matching.

golang.org/x/text goes to v0.40.0, which is the current release rather
than the v0.39.0 floor govulncheck reports. go mod tidy also advanced
golang.org/x/sync to v0.22.0 as a resolution side effect.

On the client, ECharts moves to v6.1.0 to resolve a cross-site
scripting advisory, and postcss, js-yaml and brace-expansion are
refreshed transitively; npm audit now reports no known vulnerabilities.

govulncheck reports zero affected symbols in all four modules after
this change, down from three, three, four and four. The remaining
advisories it lists are golang.org/x/crypto/ssh and ssh/agent issues
that no Workbench code calls.

No production code changes, so there is no new test coverage to add.
Trivy flags go 1.26.5 against seven stdlib CVEs fixed in 1.26.6, so
the toolchain bump this branch made has been overtaken. Go to 1.26.8,
the current 1.26.x patch, rather than the bare 1.26.6 minimum.
ci-docker.yml already rebuilds the service images when the shared pkg
module changes, but ci-server.yml, ci-alerter.yml and ci-collector.yml
only watched their own directories, so a pkg-only change could publish
images without running the services' lint, vet and test jobs. Add pkg/**
to the push and pull_request path filters of all three.
The changelog entry claimed four cleared vulnerabilities and a clean
client audit; neither matched a fresh measurement. Restate it with the
govulncheck figures actually measured on the previous toolchain (ten
reachable advisories in the server, ten in the alerter, seven in pkg
and six in the collector, all cleared by this change) and the npm audit
figures before and after.

Move the vitest development dependencies to v4.1.11, which is a patch
release within the existing major, and refresh the transitive postcss,
js-yaml, nanoid, brace-expansion, fflate and vite packages so that npm
audit reports no findings. None of these ship in the built client.
@dpage dpage changed the title Move to Go 1.26.5 and clear reachable dependency vulnerabilities Move to Go 1.26.8 and clear reachable dependency vulnerabilities Sep 14, 2026
@dpage
dpage force-pushed the security-dep-bumps branch from 1d63282 to dc91a81 Compare September 14, 2026 10:05
@dpage

dpage commented Sep 14, 2026

Copy link
Copy Markdown
Member Author

Thanks, all three points were right. I've rebased onto main and rewritten the changelog entry around what govulncheck and npm audit actually report: on main it finds 10 reachable advisories in the server, 10 in the alerter, 7 in pkg and 6 in the collector (govulncheck 1.6.0, scanned with a 1.26.3 toolchain, which I suspect is why my numbers sit below yours), and zero in all four on this branch. On the client I bumped the vitest packages to 4.1.11 (a patch release within the same major) and let npm audit fix refresh the transitive js-yaml, postcss, nanoid, brace-expansion, fflate and vite, so audit now really does report nothing; the old entry's js-yaml claim is gone. The three service CI workflows now watch pkg/** as ci-docker.yml does. The collector CI jobs were the inherited 86% ratchet as you say (it measures 88.1% here), and the title is fixed.

@dpage
dpage merged commit 7b663ac into main Sep 14, 2026
28 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants