fix(deps): bump golang.org/x/mod to v0.40.0 for GO-2026-6179/6180 - #2205
Conversation
Grype code-scanning alerts 801 and 802 flag golang.org/x/mod v0.39.0 for GO-2026-6179 and GO-2026-6180, both fixed in v0.40.0. Both advisories are in the module-checksum-database client (sumdb tile verification): a malicious GOPROXY could forge sumdb tiles, and a malicious GOSUMDB could serve module content absent from the transparency log. AICR vendors only golang.org/x/mod/semver and golang.org/x/mod/sumdb/note; the affected sumdb client is neither vendored nor imported, so there is no reachable exposure. govulncheck reports no x/mod finding before or after. The vendored sources are byte-identical between v0.39.0 and v0.40.0, so this is a pin bump only - no build output changes. Signed-off-by: Mark Chmarny <mark@chmarny.com>
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: ASSERTIVE Plan: Enterprise Run ID: ⛔ Files ignored due to path filters (2)
📒 Files selected for processing (1)
Included review availability: Your plan includes up to 12 reviews per rolling hour; 11 remain after this review. 📝 WalkthroughWalkthroughThe pull request updates the direct Estimated code review effort: 1 (Trivial) | ~2 minutes Merge Risk: 🔵 Low · up to This is a localized dependency-only change with no expected user-visible behavior change, but the generated module and vendor metadata should be confirmed synchronized before merge to avoid a CI failure. Suggested reviewers: 🚥 Pre-merge checks | ✅ 4✅ Passed checks (4 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Comment |
Recipe evidence checkNo leaf overlays affected by this PR. This gate is warning-only and never blocks merge. |
Coverage Report ✅
Coverage BadgeNo Go source files changed in this PR. |
Summary
Bumps
golang.org/x/modfrom v0.39.0 to v0.40.0, clearing the two open high-severity Grype code-scanning alerts (GO-2026-6179, GO-2026-6180).Motivation / Context
Code scanning alerts #801 and #802 flag
golang.org/x/modv0.39.0. Both are fixed in v0.40.0.Reachability: not exposed. Both advisories are in the module-checksum-database client (sumdb tile verification). AICR vendors only
golang.org/x/mod/semverandgolang.org/x/mod/sumdb/note; the affectedsumdbclient is neither vendored nor imported.govulncheckreports nox/modfinding before or after this change — the alerts match on the declared version ingo.mod, not on reachable code. This is a hygiene bump to clear the scanner, not an incident response.Fixes: N/A
Related: N/A
Type of Change
Component(s) Affected
go.mod,go.sum,vendor/modules.txt)Implementation Notes
go.sumalso updatesgolang.org/x/toolsv0.48.0 -> v0.49.0, pulled in byx/modv0.40.0's owngo.mod.x/toolsis not vendored, so it appears only in the module graph.semverandsumdb/noteare byte-identical between v0.39.0 and v0.40.0 (the fix lives entirely in the un-vendoredsumdbclient), sovendor/modules.txtrecords only the version marker. Build output is unchanged.Testing
Full Go suite (
-race, all packages) is green except one pre-existing, environment-only failure:pkg/oci/TestHelmV4_2_3ExplicitVersionPullfails on a local machine whose helm is v4.2.4 while.settings.yamlpins v4.2.3. Verified pre-existing by stashing this diff and reproducing the identical failure on unmodifiedmain. CI installs the pinned helm, so it does not reproduce here.Grype after the bump reports only 2 sub-threshold findings, both pre-existing with no fix available upstream (
k8s.io/kubernetesGO-2025-3547 Low,golang.org/x/cryptoGO-2026-5932 Unknown).Risk Assessment
Rollout notes: Dependency pin bump only; no vendored source or build output changes, no API surface change (
make api-diffclean). Revert by restoring the previous three-file diff.Checklist
make testwith-race)make lint)git commit -S)