fix(api): bump go toolchain for security audit

Raise the API module to go1.26.2 so setup-go stops selecting a vulnerable standard library release, and add a regression test that fails on affected 1.26.x toolchains.

Closes #14
This commit is contained in:
xixu-me committed 2026-04-13 16:21:33 +08:00
1 parent 8ab90ce77b
commit 7dc3a8b34b
2 files changed
+58 -1

No files matched your search

+1 -1
View File
@@ -1,6 +1,6 @@
module github.com/xdrop/monorepo
go 1.26.1
go 1.26.2
require (
github.com/aws/aws-sdk-go-v2 v1.41.5
@@ -0,0 +1,57 @@
package testutil
import (
"regexp"
"runtime"
"strconv"
"testing"
)
var goReleaseVersionPattern = regexp.MustCompile(`^go(\d+)\.(\d+)(?:\.(\d+))?`)
func TestRequiresPatchedGoToolchain(t *testing.T) {
t.Parallel()
major, minor, patch, ok := parseGoReleaseVersion(runtime.Version())
if !ok {
t.Skipf("skipping toolchain guard for non-release Go version %q", runtime.Version())
}
if major > 1 || (major == 1 && minor > 26) {
return
}
if major == 1 && minor == 26 && patch < 2 {
t.Fatalf(
"Go toolchain %q is below the minimum patched version go1.26.2 required by the security audit",
runtime.Version(),
)
}
}
func parseGoReleaseVersion(version string) (int, int, int, bool) {
matches := goReleaseVersionPattern.FindStringSubmatch(version)
if matches == nil {
return 0, 0, 0, false
}
major, err := strconv.Atoi(matches[1])
if err != nil {
return 0, 0, 0, false
}
minor, err := strconv.Atoi(matches[2])
if err != nil {
return 0, 0, 0, false
}
patch := 0
if matches[3] != "" {
patch, err = strconv.Atoi(matches[3])
if err != nil {
return 0, 0, 0, false
}
}
return major, minor, patch, true
}