Skip to content

ci: bump GitHub Actions (checkout v7, pages v6/v5) + Go 1.25.12 (CVE GO-2026-5856) - #30

Merged
kamir merged 2 commits into
mainfrom
ci/bump-github-actions-v7
Jul 11, 2026
Merged

ci: bump GitHub Actions (checkout v7, pages v6/v5) + Go 1.25.12 (CVE GO-2026-5856)#30
kamir merged 2 commits into
mainfrom
ci/bump-github-actions-v7

Conversation

@kamir

@kamir kamir commented Jul 11, 2026

Copy link
Copy Markdown
Contributor

Rolls up dependabot PRs #26, #27, #28 into a single PR.

All three touch .github/workflows/docs.yml, so merging them one-by-one triggers a 3-way rebase cascade. Bundling them is one CI run + one merge.

Action From To Files
actions/checkout v6 v7 build-and-release.yml (x2), security.yml, docs.yml
actions/configure-pages v5 v6 docs.yml
actions/upload-pages-artifact v3 v5 docs.yml

Closes #26, closes #27, closes #28.

🤖 Generated with Claude Code

…s-artifact v5)

Rolls up dependabot PRs #26/#27/#28 into one PR to avoid a 3-way
docs.yml rebase cascade (all three touch the same workflow file).

- actions/checkout        v6 -> v7  (build-and-release.yml x2, security.yml, docs.yml)
- actions/configure-pages v5 -> v6  (docs.yml)
- actions/upload-pages-artifact v3 -> v5 (docs.yml)

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
@kamir kamir changed the title ci: bump GitHub Actions (checkout v7, configure-pages v6, upload-pages-artifact v5) ci: bump GitHub Actions (checkout v7, pages v6/v5) + Go 1.26 (CVE GO-2026-5856) Jul 11, 2026
Freshly-disclosed Go stdlib CVE GO-2026-5856 (Encrypted Client Hello
privacy leak in crypto/tls), found in crypto/tls@go1.25.11, fixed in
go1.25.12. kshark's TLS probers call the affected path, so govulncheck
exits 3 on go1.25.11.

Pin the exact patch 1.25.12 (now in the actions/go-versions manifest)
rather than the floating '1.25'. Deliberately NOT 1.26: golangci-lint
v2.6.0 is built against the 1.25 toolchain and panics loading 1.26
packages (go/types crash, lint exit 2). 1.25.12 clears the CVE while
keeping the pinned linter working. Bump both together when moving to 1.26.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
@kamir
kamir force-pushed the ci/bump-github-actions-v7 branch from 55827af to ddc0e7a Compare July 11, 2026 09:10
@kamir kamir changed the title ci: bump GitHub Actions (checkout v7, pages v6/v5) + Go 1.26 (CVE GO-2026-5856) ci: bump GitHub Actions (checkout v7, pages v6/v5) + Go 1.25.12 (CVE GO-2026-5856) Jul 11, 2026
@kamir
kamir merged commit 29b2054 into main Jul 11, 2026
2 checks passed
@kamir
kamir deleted the ci/bump-github-actions-v7 branch July 11, 2026 09:12
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant