Skip to content

(security) golang: bump Go version to 1.26.6-1 - #18437

Open
bot-for-go[bot] wants to merge 2 commits into
3.0-devfrom
user/app/bot-for-go/go-1.26.6-1
Open

(security) golang: bump Go version to 1.26.6-1#18437
bot-for-go[bot] wants to merge 2 commits into
3.0-devfrom
user/app/bot-for-go/go-1.26.6-1

Conversation

@bot-for-go

@bot-for-go bot-for-go Bot commented Aug 14, 2026

Copy link
Copy Markdown

Hi! 👋 I'm the Microsoft team's bot. This is an automated pull request I generated to bump the Go version to 1.26.6-1.

This update contains security fixes.

I'm not able to run the Azure Linux pipelines yet, so the Microsoft release runner will need to finalize this PR.

Finalization steps:

  • Trigger Source Tarball Publishing with:
    Full Name:
    go1.26.6-20260813.3.src.tar.gz
    
    URL:
    https://github.com/microsoft/go/releases/download/v1.26.6-1/go1.26.6-20260813.3.src.tar.gz
    
  • Trigger the Buddy Build with:
    First field:
    PR-18437
    
    Core spec:
    golang
    
  • Post a PR comment with the URL of the triggered Buddy Build.
  • Mark this draft PR as ready for review.

Thanks!

@bot-for-go bot-for-go Bot added 3.0-dev PRs Destined for AzureLinux 3.0 Automatic PR labels Aug 14, 2026
@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
There may be pipelines that require an authorized user to comment /azp run to run.

@dagood

Copy link
Copy Markdown
Member

@dagood
Davis Goodin (dagood) marked this pull request as ready for review August 14, 2026 17:25
@dagood
Davis Goodin (dagood) requested a review from a team as a code owner August 14, 2026 17:25
@Kanishk-Bansal Kanishk Bansal (Kanishk-Bansal) added the ready-for-stable-review PR has passed initial review and is now ready for a second-level stable maintainer review label Aug 14, 2026

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

need to remove the CVE-2026-39821.patch as this is fixed in the version as per https://pkg.go.dev/vuln/GO-2026-5026

@Kanishk-Bansal Kanishk Bansal (Kanishk-Bansal) removed the ready-for-stable-review PR has passed initial review and is now ready for a second-level stable maintainer review label Aug 14, 2026
Signed-off-by: Kanishk Bansal <kanbansal@microsoft.com>
Comment thread SPECS/golang/golang.spec
# bootstrap 04
Source5: https://github.com/microsoft/go/releases/download/v1.24.13-1/go1.24.13-20260204.5.src.tar.gz

Patch1: CVE-2026-39821.patch

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

patch removed from spec folder in pr #18438

@Kanishk-Bansal

Copy link
Copy Markdown

/azurepipelines run

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 1 pipeline(s).
1 pipeline(s) were filtered out due to trigger conditions.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

3.0-dev PRs Destined for AzureLinux 3.0 Automatic PR CVE-fixed-by-upgrade CVE fixed by package upgrade Packaging security

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants