Skip to content

chore: update Go build and release toolchains to 1.27 - #666

Open
rjmackay wants to merge 1 commit into
segmentio:masterfrom
rjmackay:chore-go-1.27.1
Open

rjmackay wants to merge 1 commit into
segmentio:masterfrom
rjmackay:chore-go-1.27.1

Conversation

@rjmackay

@rjmackay rjmackay commented Sep 27, 2026 •

Copy link
Copy Markdown

The Docker image embeds Go 1.25.7, which Docker Scout flags for one critical and 15 high standard-library findings. Rebuilding with Go 1.27.1 removes those findings.

What changed

  • Bump the Docker builder to golang:1.27.1-alpine.
  • Use Go 1.27.x for release builds and coverage.
  • Add Go 1.27.x to the install, test, and distribution matrices, retaining the existing compatibility checks.

The module's minimum Go version and dependencies are unchanged. Related: #661, which proposed Go 1.26.2 and was closed without merging.

Validation

  • Local Linux ARM64 Docker build and chamber version / null-backend chamber exec smoke tests passed.
  • make test and go vet ./... passed with Go 1.27.1.
  • go mod tidy left go.mod and go.sum unchanged.
  • Scout on the rebuilt upstream image: 0 critical, 0 high, 2 medium, 1 low. Remaining findings affect unchanged third-party modules.
  • Workflow lint reports the same ten outdated-action diagnostics as the base branch, with no new diagnostics.

@rjmackay
rjmackay requested a review from a team as a code owner September 27, 2026 22:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant