Skip to content

(security) golang: bump Go version to 1.25.13-1 - #18438

Draft
bot-for-go[bot] wants to merge 2 commits into
3.0-devfrom
user/app/bot-for-go/go-1.25.13-1
Draft

(security) golang: bump Go version to 1.25.13-1#18438
bot-for-go[bot] wants to merge 2 commits into
3.0-devfrom
user/app/bot-for-go/go-1.25.13-1

Conversation

@bot-for-go

@bot-for-go bot-for-go Bot commented Aug 14, 2026

Copy link
Copy Markdown

Hi! 👋 I'm the Microsoft team's bot. This is an automated pull request I generated to bump the Go version to 1.25.13-1.

This update contains security fixes.

I'm not able to run the Azure Linux pipelines yet, so the Microsoft release runner will need to finalize this PR.

Finalization steps:

  • Trigger Source Tarball Publishing with:
    Full Name:
    go1.25.13-20260813.2.src.tar.gz
    
    URL:
    https://github.com/microsoft/go/releases/download/v1.25.13-1/go1.25.13-20260813.2.src.tar.gz
    
  • Trigger the Buddy Build with:
    First field:
    PR-18438
    
    Core spec:
    golang-1.25
    
  • Post a PR comment with the URL of the triggered Buddy Build.
  • Mark this draft PR as ready for review.

Thanks!

@bot-for-go bot-for-go Bot added 3.0-dev PRs Destined for AzureLinux 3.0 Automatic PR labels Aug 14, 2026
@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
There may be pipelines that require an authorized user to comment /azp run to run.

@dagood

Copy link
Copy Markdown
Member

@dagood
Davis Goodin (dagood) marked this pull request as ready for review August 14, 2026 17:25
@dagood
Davis Goodin (dagood) requested a review from a team as a code owner August 14, 2026 17:25

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

need to remove the CVE-2026-39821.patch as this is fixed in the version as per https://pkg.go.dev/vuln/GO-2026-5026

Signed-off-by: Kanishk Bansal <kanbansal@microsoft.com>
@Kanishk-Bansal

Copy link
Copy Markdown

we need to merge #18437
so that the check of Source Signature Check (SPECS) can pass.

@Kanishk-Bansal

Copy link
Copy Markdown

/azurepipelines run

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 1 pipeline(s).
1 pipeline(s) were filtered out due to trigger conditions.

@Kanishk-Bansal

Copy link
Copy Markdown

/azurepipelines run

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 1 pipeline(s).
1 pipeline(s) were filtered out due to trigger conditions.

@Kanishk-Bansal
Kanishk Bansal (Kanishk-Bansal) marked this pull request as draft August 15, 2026 10:05
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

3.0-dev PRs Destined for AzureLinux 3.0 Automatic PR CVE-fixed-by-upgrade CVE fixed by package upgrade Packaging security

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants