Skip to content

fix(deps): bump golang.org/x/mod to v0.40.0 for GO-2026-6179/6180 - #2205

Merged
mchmarny merged 1 commit into
mainfrom
fix/bump-x-mod-v0.40.0
Aug 17, 2026
Merged

mchmarny merged 1 commit into
mainfrom
fix/bump-x-mod-v0.40.0

Conversation

@mchmarny

Copy link
Copy Markdown
Member

Summary

Bumps golang.org/x/mod from v0.39.0 to v0.40.0, clearing the two open high-severity Grype code-scanning alerts (GO-2026-6179, GO-2026-6180).

Motivation / Context

Code scanning alerts #801 and #802 flag golang.org/x/mod v0.39.0. Both are fixed in v0.40.0.

Advisory Issue
GO-2026-6179 A malicious GOPROXY could forge up to two sumdb tiles, bypassing the GOSUMDB check and persisting attacker-controlled module content to the local module cache.
GO-2026-6180 A malicious GOSUMDB could serve module content not contained within the transparency log.

Reachability: not exposed. Both advisories are in the module-checksum-database client (sumdb tile verification). AICR vendors only golang.org/x/mod/semver and golang.org/x/mod/sumdb/note; the affected sumdb client is neither vendored nor imported. govulncheck reports no x/mod finding before or after this change — the alerts match on the declared version in go.mod, not on reachable code. This is a hygiene bump to clear the scanner, not an incident response.

Fixes: N/A
Related: N/A

Type of Change

  • Build/CI/tooling

Component(s) Affected

  • Other: dependencies (go.mod, go.sum, vendor/modules.txt)

Implementation Notes

  • go.sum also updates golang.org/x/tools v0.48.0 -> v0.49.0, pulled in by x/mod v0.40.0's own go.mod. x/tools is not vendored, so it appears only in the module graph.
  • No vendored source changed. semver and sumdb/note are byte-identical between v0.39.0 and v0.40.0 (the fix lives entirely in the un-vendored sumdb client), so vendor/modules.txt records only the version marker. Build output is unchanged.

Testing

make lint            # golangci-lint: 0 issues
make test-shell      # pass
make license-check   # pass
make scan            # pass - 0 x/mod matches, 0 High/Critical
make tuning-check    # pass
make coverage-check  # pass
make api-diff        # pass - no incompatible changes since v0.19.0
make e2e             # pass - 24/24 chainsaw tests
govulncheck ./...    # no golang.org/x/mod finding

Full Go suite (-race, all packages) is green except one pre-existing, environment-only failure: pkg/oci/TestHelmV4_2_3ExplicitVersionPull fails on a local machine whose helm is v4.2.4 while .settings.yaml pins v4.2.3. Verified pre-existing by stashing this diff and reproducing the identical failure on unmodified main. CI installs the pinned helm, so it does not reproduce here.

Grype after the bump reports only 2 sub-threshold findings, both pre-existing with no fix available upstream (k8s.io/kubernetes GO-2025-3547 Low, golang.org/x/crypto GO-2026-5932 Unknown).

Risk Assessment

  • Low — Isolated change, well-tested, easy to revert

Rollout notes: Dependency pin bump only; no vendored source or build output changes, no API surface change (make api-diff clean). Revert by restoring the previous three-file diff.

Checklist

  • Tests pass locally (make test with -race)
  • Linter passes (make lint)
  • I did not skip/disable tests to make CI green
  • I added/updated tests for new functionality — N/A, dependency bump
  • I updated docs if user-facing behavior changed — N/A, no user-visible behavior change
  • Changes follow existing patterns in the codebase
  • Commits are cryptographically signed (git commit -S)
Grype code-scanning alerts 801 and 802 flag golang.org/x/mod v0.39.0 for
GO-2026-6179 and GO-2026-6180, both fixed in v0.40.0.

Both advisories are in the module-checksum-database client (sumdb tile
verification): a malicious GOPROXY could forge sumdb tiles, and a malicious
GOSUMDB could serve module content absent from the transparency log.

AICR vendors only golang.org/x/mod/semver and golang.org/x/mod/sumdb/note;
the affected sumdb client is neither vendored nor imported, so there is no
reachable exposure. govulncheck reports no x/mod finding before or after.
The vendored sources are byte-identical between v0.39.0 and v0.40.0, so this
is a pin bump only - no build output changes.

Signed-off-by: Mark Chmarny <mark@chmarny.com>
@mchmarny
mchmarny requested a review from a team as a code owner August 16, 2026 22:49
@mchmarny mchmarny added the theme/supply-chain SLSA, SBOM, Sigstore, and provenance verification label Aug 16, 2026
@mchmarny mchmarny self-assigned this Aug 16, 2026
@mchmarny
mchmarny enabled auto-merge (squash) August 16, 2026 22:49
@coderabbitai

coderabbitai Bot commented Aug 16, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Enterprise

Run ID: 40a580fe-0df5-48b3-9ea8-431730c2d546

📥 Commits

Reviewing files that changed from the base of the PR and between 0e0ca91 and 5e4946b.

⛔ Files ignored due to path filters (2)
  • go.sum is excluded by !**/*.sum
  • vendor/modules.txt is excluded by !vendor/**
📒 Files selected for processing (1)
  • go.mod

Included review availability: Your plan includes up to 12 reviews per rolling hour; 11 remain after this review.


📝 Walkthrough

Walkthrough

The pull request updates the direct golang.org/x/mod dependency in go.mod from v0.39.0 to v0.40.0. No exported or public entities change.

Estimated code review effort: 1 (Trivial) | ~2 minutes

Merge Risk: 🔵 Low · up to 5e494

This is a localized dependency-only change with no expected user-visible behavior change, but the generated module and vendor metadata should be confirmed synchronized before merge to avoid a CI failure.

Suggested reviewers: almaslennikov

🚥 Pre-merge checks | ✅ 4
✅ Passed checks (4 passed)
Check name Status Explanation
Description check ✅ Passed The description directly explains the dependency update, security alerts, scope, testing, and risk.
Title check ✅ Passed The title clearly identifies the dependency bump and its purpose of addressing the two security alerts.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch fix/bump-x-mod-v0.40.0

Comment @coderabbitai help to get the list of available commands.

@github-actions

Copy link
Copy Markdown
Contributor

Recipe evidence check

No leaf overlays affected by this PR.

This gate is warning-only and never blocks merge.

@github-actions

Copy link
Copy Markdown
Contributor

Coverage Report ✅

Metric Value
Coverage 83.1%
Threshold 80%
Status Pass
Coverage Badge
![Coverage](https://img.shields.io/badge/coverage-83.1%25-brightgreen)

No Go source files changed in this PR.

@mchmarny
mchmarny merged commit 68be22f into main Aug 17, 2026
72 of 73 checks passed
@mchmarny
mchmarny deleted the fix/bump-x-mod-v0.40.0 branch August 17, 2026 08:30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size/S theme/supply-chain SLSA, SBOM, Sigstore, and provenance verification

2 participants