From 7dc3a8b34b17b9cea84c9fd2e2d513dc6e1d5e2a Mon Sep 17 00:00:00 2001 From: Xi Xu Date: Mon, 13 Apr 2026 16:21:33 +0800 Subject: [PATCH] fix(api): bump go toolchain for security audit Raise the API module to go1.26.2 so setup-go stops selecting a vulnerable standard library release, and add a regression test that fails on affected 1.26.x toolchains. Closes #14 --- apps/api/go.mod | 2 +- apps/api/internal/testutil/toolchain_test.go | 57 ++++++++++++++++++++ 2 files changed, 58 insertions(+), 1 deletion(-) create mode 100644 apps/api/internal/testutil/toolchain_test.go diff --git a/apps/api/go.mod b/apps/api/go.mod index 8cdfc74..a29d1e1 100644 --- a/apps/api/go.mod +++ b/apps/api/go.mod @@ -1,6 +1,6 @@ module github.com/xdrop/monorepo -go 1.26.1 +go 1.26.2 require ( github.com/aws/aws-sdk-go-v2 v1.41.5 diff --git a/apps/api/internal/testutil/toolchain_test.go b/apps/api/internal/testutil/toolchain_test.go new file mode 100644 index 0000000..a4ba473 --- /dev/null +++ b/apps/api/internal/testutil/toolchain_test.go @@ -0,0 +1,57 @@ +package testutil + +import ( + "regexp" + "runtime" + "strconv" + "testing" +) + +var goReleaseVersionPattern = regexp.MustCompile(`^go(\d+)\.(\d+)(?:\.(\d+))?`) + +func TestRequiresPatchedGoToolchain(t *testing.T) { + t.Parallel() + + major, minor, patch, ok := parseGoReleaseVersion(runtime.Version()) + if !ok { + t.Skipf("skipping toolchain guard for non-release Go version %q", runtime.Version()) + } + + if major > 1 || (major == 1 && minor > 26) { + return + } + + if major == 1 && minor == 26 && patch < 2 { + t.Fatalf( + "Go toolchain %q is below the minimum patched version go1.26.2 required by the security audit", + runtime.Version(), + ) + } +} + +func parseGoReleaseVersion(version string) (int, int, int, bool) { + matches := goReleaseVersionPattern.FindStringSubmatch(version) + if matches == nil { + return 0, 0, 0, false + } + + major, err := strconv.Atoi(matches[1]) + if err != nil { + return 0, 0, 0, false + } + + minor, err := strconv.Atoi(matches[2]) + if err != nil { + return 0, 0, 0, false + } + + patch := 0 + if matches[3] != "" { + patch, err = strconv.Atoi(matches[3]) + if err != nil { + return 0, 0, 0, false + } + } + + return major, minor, patch, true +}