fix(security): bump Go to 1.25.10 to patch stdlib CVEs#122
Conversation
Addresses 4 govulncheck findings in go1.25.9 stdlib: - GO-2026-4982 & GO-2026-4980: XSS in html/template - GO-2026-4971: panic on NUL byte in net (Windows) - GO-2026-4918: HTTP/2 infinite loop in net/http All fixed in go1.25.10.
|
Warning Rate limit exceeded
You’ve run out of usage credits. Purchase more in the billing tab. ⌛ How to resolve this issue?After the wait time has elapsed, a review can be triggered using the We recommend that you space out your commits to avoid hitting the rate limit. 🚦 How do rate limits work?CodeRabbit enforces hourly rate limits for each developer per organization. Our paid plans have higher rate limits than the trial, open-source and free plans. In all cases, we re-allow further reviews after a brief timeout. Please see our FAQ for further information. ℹ️ Review info⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Run ID: 📒 Files selected for processing (3)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Codecov Report✅ All modified and coverable lines are covered by tests. 📢 Thoughts on this report? Let us know! |
Summary
1.25.9→1.25.10ingo.modand all CI workflow jobsgovulncheckfindings that were failing the Security Scan on mainVulnerabilities Fixed
html/templatehtml/templatenetDial/LookupPort(Windows)net/httpSETTINGS_MAX_FRAME_SIZETest plan
govulncheck ./...exits 0)