From 5b22b8e3a7d1ae9a3fcc4e894ae2e9d142bf8086 Mon Sep 17 00:00:00 2001 From: Lukasz Kasprzak Date: Mon, 14 Sep 2026 19:35:46 +0200 Subject: go 1.25, toolchain go1.26.8, x/text v0.41.0: fixes GO-2026-5970 and the reachable stdlib vulnerabilities --- docs/design.md | 6 +++++- 1 file changed, 5 insertions(+), 1 deletion(-) (limited to 'docs') diff --git a/docs/design.md b/docs/design.md index fb8988c..411eeba 100644 --- a/docs/design.md +++ b/docs/design.md @@ -735,7 +735,11 @@ Rules for the GUI to come: ## 14. Build, dependencies, release -- Go 1.24 or newer. `CGO_ENABLED=0`: static binaries on Linux and FreeBSD; +- Go 1.25 or newer (`golang.org/x/text` v0.39 fixed an infinite loop on + invalid input, GO-2026-5970, and needs it). `go.mod` pins the toolchain, + `go1.26.8`, so builds carry the standard library's security fixes: an + older `go` with `GOTOOLCHAIN=auto`, the default, downloads it itself. + `CGO_ENABLED=0`: static binaries on Linux and FreeBSD; on OpenBSD Go links against the system libc, as that platform requires. - Go dependencies: `golang.org/x/term` (key-at-a-time input) and `golang.org/x/text` (Unicode normalisation for `fold`). Everything else is -- cgit v1.3