Skip to content

chore: bump Go toolchain to 1.26.4 (CVE-2026-42504, CVE-2026-27145, CVE-2026-42507)#759

Open
plural-copilot[bot] wants to merge 1 commit into
mainfrom
chore/bump-go-1.26.4
Open

chore: bump Go toolchain to 1.26.4 (CVE-2026-42504, CVE-2026-27145, CVE-2026-42507)#759
plural-copilot[bot] wants to merge 1 commit into
mainfrom
chore/bump-go-1.26.4

Conversation

@plural-copilot

@plural-copilot plural-copilot Bot commented Jun 5, 2026

Copy link
Copy Markdown
Contributor

Summary

Bumps the Go toolchain from 1.26.3 to 1.26.4 to remediate three stdlib CVEs detected by Trivy in the ghcr.io/pluralsh/console image (usr/local/bin/plural).

CVEs Fixed

CVE Severity Fix
CVE-2026-42504 High 7.5 Go 1.26.4
CVE-2026-27145 Medium 6.5 Go 1.26.4
CVE-2026-42507 Medium 5.3 Go 1.26.4

@plural-copilot plural-copilot Bot left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This PR was generated by the codex Plural Agent Runtime. Here's some useful information you might want to know to evaluate the ai's perfomance:

Name Details
💬 Prompt ## Task: Bump Go from 1.26.3 → 1.26.4 and open a PR...
🔗 Run history View run history

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants