chore: upgrade Go toolchain 1.25 & zoekt version - #1112

Merged
brendan-kellam merged 3 commits into
mainfrom
brendan/upgrade-go-1.25
Apr 14, 2026
Merged

chore: upgrade Go toolchain 1.25 & zoekt version#1112
brendan-kellam merged 3 commits into
mainfrom
brendan/upgrade-go-1.25

Conversation

@brendan-kellam

@brendan-kellambrendan-kellam commented Apr 14, 2026

Copy link
Copy Markdown
Contributor

bump zoekt dependency & upgrade to go 1.25

Summary by CodeRabbit

  • Bug Fixes

    • Patched critical and high-severity security vulnerabilities in Go standard library through an upgrade to Go toolchain version 1.25, addressing CVE-2025-68121 and multiple additional Go standard library CVEs affecting the runtime and security subsystems.
  • Chores

    • Updated vendored dependencies and build infrastructure to maintain compatibility with the latest Go toolchain version, ensuring secure and stable operations.

Resolves CVE-2025-68121 (CRITICAL, crypto/tls certificate validation
during TLS session resumption) and multiple HIGH/MEDIUM Go stdlib CVEs
across all zoekt binaries.
Also pulls latest zoekt submodule (dec971a, bump dependencies #9)
which updates go.mod to go 1.25.0.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
@github-actions

This comment has been minimized.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
@coderabbitai

coderabbitaiBot commented Apr 14, 2026

Copy link
Copy Markdown
Contributor

Walkthrough

The pull request updates the Go toolchain from version 1.23.4 to 1.25, addressing CVE-2025-68121 and additional Go standard library vulnerabilities. The Dockerfile Go builder image and vendor/zoekt submodule are updated correspondingly.

Changes

Cohort / File(s)Summary
Go Toolchain Upgrade
CHANGELOG.md, Dockerfile
Version bump from Go 1.23.4 to 1.25, with updated Alpine base image from alpine3.19 to alpine. Changelog entry documenting CVE remediation added.
Submodule Update
vendor/zoekt
Git submodule reference advanced from 4a11080 to dec971a commit.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~8 minutes

Possibly related PRs

  • chore: Bump zoekt #921: Updates vendor/zoekt submodule to the base commit (4a1108…) from which this PR advances it further to dec971a.
🚥 Pre-merge checks | ✅ 3
✅ Passed checks (3 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Title check✅ PassedThe title accurately and concisely summarizes the main changes: upgrading Go toolchain to 1.25 and zoekt version, matching all three file modifications (Dockerfile, CHANGELOG, vendor/zoekt).

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch brendan/upgrade-go-1.25

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🧹 Nitpick comments (1)
Dockerfile (1)

19-19: Pin the Go builder image more tightly to keep builds reproducible.

golang:1.25-alpine is a floating tag; patch/Alpine drift can cause non-deterministic CI behavior. Pin to a specific patch version (e.g., golang:1.25.0-alpine) or digest instead.

🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.
In `@Dockerfile` at line 19, The Dockerfile uses a floating builder image tag
"golang:1.25-alpine" in the FROM instruction which can cause non-deterministic
builds; update the FROM line to pin the Go builder to a specific patch version
(e.g., "golang:1.25.0-alpine") or, better, to an immutable digest for
reproducibility, ensuring the image reference is stable for CI and local builds.
🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.
Nitpick comments:
In `@Dockerfile`:
- Line 19: The Dockerfile uses a floating builder image tag "golang:1.25-alpine"
in the FROM instruction which can cause non-deterministic builds; update the
FROM line to pin the Go builder to a specific patch version (e.g.,
"golang:1.25.0-alpine") or, better, to an immutable digest for reproducibility,
ensuring the image reference is stable for CI and local builds.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: a1e93270-e7bf-4067-829f-d7257ef6a7df

📥 Commits

Reviewing files that changed from the base of the PR and between 5420c3d and bf87d88.

📒 Files selected for processing (3)
  • CHANGELOG.md
  • Dockerfile
  • vendor/zoekt

@brendan-kellambrendan-kellam changed the title chore: upgrade Go toolchain from 1.23.4 to 1.25chore: upgrade Go toolchain 1.25 & zoekt versionApr 14, 2026
@brendan-kellam
brendan-kellam merged commit 775164c into mainApr 14, 2026
9 checks passed
@brendan-kellam
brendan-kellam deleted the brendan/upgrade-go-1.25 branch April 14, 2026 23:05
@github-actionsgithub-actionsBot mentioned this pull request Apr 14, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@brendan-kellam
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all \u003cpre\u003e\u003ccode\u003e blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks"); } } catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); } })(); (function(){ try { var __m = "github.com"; var __re = new RegExp('^' + "github\\.com" + '
Skip to content

chore: upgrade Go toolchain 1.25 & zoekt version - #1112

Merged
brendan-kellam merged 3 commits into
mainfrom
brendan/upgrade-go-1.25
Apr 14, 2026
Merged

chore: upgrade Go toolchain 1.25 & zoekt version#1112
brendan-kellam merged 3 commits into
mainfrom
brendan/upgrade-go-1.25

Conversation

@brendan-kellam

@brendan-kellambrendan-kellam commented Apr 14, 2026

Copy link
Copy Markdown
Contributor

bump zoekt dependency & upgrade to go 1.25

Summary by CodeRabbit

  • Bug Fixes

    • Patched critical and high-severity security vulnerabilities in Go standard library through an upgrade to Go toolchain version 1.25, addressing CVE-2025-68121 and multiple additional Go standard library CVEs affecting the runtime and security subsystems.
  • Chores

    • Updated vendored dependencies and build infrastructure to maintain compatibility with the latest Go toolchain version, ensuring secure and stable operations.

Resolves CVE-2025-68121 (CRITICAL, crypto/tls certificate validation
during TLS session resumption) and multiple HIGH/MEDIUM Go stdlib CVEs
across all zoekt binaries.
Also pulls latest zoekt submodule (dec971a, bump dependencies #9)
which updates go.mod to go 1.25.0.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
@github-actions

This comment has been minimized.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
@coderabbitai

coderabbitaiBot commented Apr 14, 2026

Copy link
Copy Markdown
Contributor

Walkthrough

The pull request updates the Go toolchain from version 1.23.4 to 1.25, addressing CVE-2025-68121 and additional Go standard library vulnerabilities. The Dockerfile Go builder image and vendor/zoekt submodule are updated correspondingly.

Changes

Cohort / File(s)Summary
Go Toolchain Upgrade
CHANGELOG.md, Dockerfile
Version bump from Go 1.23.4 to 1.25, with updated Alpine base image from alpine3.19 to alpine. Changelog entry documenting CVE remediation added.
Submodule Update
vendor/zoekt
Git submodule reference advanced from 4a11080 to dec971a commit.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~8 minutes

Possibly related PRs

  • chore: Bump zoekt #921: Updates vendor/zoekt submodule to the base commit (4a1108…) from which this PR advances it further to dec971a.
🚥 Pre-merge checks | ✅ 3
✅ Passed checks (3 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Title check✅ PassedThe title accurately and concisely summarizes the main changes: upgrading Go toolchain to 1.25 and zoekt version, matching all three file modifications (Dockerfile, CHANGELOG, vendor/zoekt).

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch brendan/upgrade-go-1.25

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🧹 Nitpick comments (1)
Dockerfile (1)

19-19: Pin the Go builder image more tightly to keep builds reproducible.

golang:1.25-alpine is a floating tag; patch/Alpine drift can cause non-deterministic CI behavior. Pin to a specific patch version (e.g., golang:1.25.0-alpine) or digest instead.

🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.
In `@Dockerfile` at line 19, The Dockerfile uses a floating builder image tag
"golang:1.25-alpine" in the FROM instruction which can cause non-deterministic
builds; update the FROM line to pin the Go builder to a specific patch version
(e.g., "golang:1.25.0-alpine") or, better, to an immutable digest for
reproducibility, ensuring the image reference is stable for CI and local builds.
🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.
Nitpick comments:
In `@Dockerfile`:
- Line 19: The Dockerfile uses a floating builder image tag "golang:1.25-alpine"
in the FROM instruction which can cause non-deterministic builds; update the
FROM line to pin the Go builder to a specific patch version (e.g.,
"golang:1.25.0-alpine") or, better, to an immutable digest for reproducibility,
ensuring the image reference is stable for CI and local builds.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: a1e93270-e7bf-4067-829f-d7257ef6a7df

📥 Commits

Reviewing files that changed from the base of the PR and between 5420c3d and bf87d88.

📒 Files selected for processing (3)
  • CHANGELOG.md
  • Dockerfile
  • vendor/zoekt

@brendan-kellambrendan-kellam changed the title chore: upgrade Go toolchain from 1.23.4 to 1.25chore: upgrade Go toolchain 1.25 & zoekt versionApr 14, 2026
@brendan-kellam
brendan-kellam merged commit 775164c into mainApr 14, 2026
9 checks passed
@brendan-kellam
brendan-kellam deleted the brendan/upgrade-go-1.25 branch April 14, 2026 23:05
@github-actionsgithub-actionsBot mentioned this pull request Apr 14, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@brendan-kellam
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

chore: upgrade Go toolchain 1.25 & zoekt version - #1112

Merged
brendan-kellam merged 3 commits into
mainfrom
brendan/upgrade-go-1.25
Apr 14, 2026
Merged

chore: upgrade Go toolchain 1.25 & zoekt version#1112
brendan-kellam merged 3 commits into
mainfrom
brendan/upgrade-go-1.25

Conversation

@brendan-kellam

@brendan-kellambrendan-kellam commented Apr 14, 2026

Copy link
Copy Markdown
Contributor

bump zoekt dependency & upgrade to go 1.25

Summary by CodeRabbit

  • Bug Fixes

    • Patched critical and high-severity security vulnerabilities in Go standard library through an upgrade to Go toolchain version 1.25, addressing CVE-2025-68121 and multiple additional Go standard library CVEs affecting the runtime and security subsystems.
  • Chores

    • Updated vendored dependencies and build infrastructure to maintain compatibility with the latest Go toolchain version, ensuring secure and stable operations.

Resolves CVE-2025-68121 (CRITICAL, crypto/tls certificate validation
during TLS session resumption) and multiple HIGH/MEDIUM Go stdlib CVEs
across all zoekt binaries.
Also pulls latest zoekt submodule (dec971a, bump dependencies #9)
which updates go.mod to go 1.25.0.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
@github-actions

This comment has been minimized.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
@coderabbitai

coderabbitaiBot commented Apr 14, 2026

Copy link
Copy Markdown
Contributor

Walkthrough

The pull request updates the Go toolchain from version 1.23.4 to 1.25, addressing CVE-2025-68121 and additional Go standard library vulnerabilities. The Dockerfile Go builder image and vendor/zoekt submodule are updated correspondingly.

Changes

Cohort / File(s)Summary
Go Toolchain Upgrade
CHANGELOG.md, Dockerfile
Version bump from Go 1.23.4 to 1.25, with updated Alpine base image from alpine3.19 to alpine. Changelog entry documenting CVE remediation added.
Submodule Update
vendor/zoekt
Git submodule reference advanced from 4a11080 to dec971a commit.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~8 minutes

Possibly related PRs

  • chore: Bump zoekt #921: Updates vendor/zoekt submodule to the base commit (4a1108…) from which this PR advances it further to dec971a.
🚥 Pre-merge checks | ✅ 3
✅ Passed checks (3 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Title check✅ PassedThe title accurately and concisely summarizes the main changes: upgrading Go toolchain to 1.25 and zoekt version, matching all three file modifications (Dockerfile, CHANGELOG, vendor/zoekt).

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch brendan/upgrade-go-1.25

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🧹 Nitpick comments (1)
Dockerfile (1)

19-19: Pin the Go builder image more tightly to keep builds reproducible.

golang:1.25-alpine is a floating tag; patch/Alpine drift can cause non-deterministic CI behavior. Pin to a specific patch version (e.g., golang:1.25.0-alpine) or digest instead.

🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.
In `@Dockerfile` at line 19, The Dockerfile uses a floating builder image tag
"golang:1.25-alpine" in the FROM instruction which can cause non-deterministic
builds; update the FROM line to pin the Go builder to a specific patch version
(e.g., "golang:1.25.0-alpine") or, better, to an immutable digest for
reproducibility, ensuring the image reference is stable for CI and local builds.
🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.
Nitpick comments:
In `@Dockerfile`:
- Line 19: The Dockerfile uses a floating builder image tag "golang:1.25-alpine"
in the FROM instruction which can cause non-deterministic builds; update the
FROM line to pin the Go builder to a specific patch version (e.g.,
"golang:1.25.0-alpine") or, better, to an immutable digest for reproducibility,
ensuring the image reference is stable for CI and local builds.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: a1e93270-e7bf-4067-829f-d7257ef6a7df

📥 Commits

Reviewing files that changed from the base of the PR and between 5420c3d and bf87d88.

📒 Files selected for processing (3)
  • CHANGELOG.md
  • Dockerfile
  • vendor/zoekt

@brendan-kellambrendan-kellam changed the title chore: upgrade Go toolchain from 1.23.4 to 1.25chore: upgrade Go toolchain 1.25 & zoekt versionApr 14, 2026
@brendan-kellam
brendan-kellam merged commit 775164c into mainApr 14, 2026
9 checks passed
@brendan-kellam
brendan-kellam deleted the brendan/upgrade-go-1.25 branch April 14, 2026 23:05
@github-actionsgithub-actionsBot mentioned this pull request Apr 14, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@brendan-kellam
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length \u003e 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

chore: upgrade Go toolchain 1.25 & zoekt version - #1112

Merged
brendan-kellam merged 3 commits into
mainfrom
brendan/upgrade-go-1.25
Apr 14, 2026
Merged

chore: upgrade Go toolchain 1.25 & zoekt version#1112
brendan-kellam merged 3 commits into
mainfrom
brendan/upgrade-go-1.25

Conversation

@brendan-kellam

@brendan-kellambrendan-kellam commented Apr 14, 2026

Copy link
Copy Markdown
Contributor

bump zoekt dependency & upgrade to go 1.25

Summary by CodeRabbit

  • Bug Fixes

    • Patched critical and high-severity security vulnerabilities in Go standard library through an upgrade to Go toolchain version 1.25, addressing CVE-2025-68121 and multiple additional Go standard library CVEs affecting the runtime and security subsystems.
  • Chores

    • Updated vendored dependencies and build infrastructure to maintain compatibility with the latest Go toolchain version, ensuring secure and stable operations.

Resolves CVE-2025-68121 (CRITICAL, crypto/tls certificate validation
during TLS session resumption) and multiple HIGH/MEDIUM Go stdlib CVEs
across all zoekt binaries.
Also pulls latest zoekt submodule (dec971a, bump dependencies #9)
which updates go.mod to go 1.25.0.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
@github-actions

This comment has been minimized.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
@coderabbitai

coderabbitaiBot commented Apr 14, 2026

Copy link
Copy Markdown
Contributor

Walkthrough

The pull request updates the Go toolchain from version 1.23.4 to 1.25, addressing CVE-2025-68121 and additional Go standard library vulnerabilities. The Dockerfile Go builder image and vendor/zoekt submodule are updated correspondingly.

Changes

Cohort / File(s)Summary
Go Toolchain Upgrade
CHANGELOG.md, Dockerfile
Version bump from Go 1.23.4 to 1.25, with updated Alpine base image from alpine3.19 to alpine. Changelog entry documenting CVE remediation added.
Submodule Update
vendor/zoekt
Git submodule reference advanced from 4a11080 to dec971a commit.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~8 minutes

Possibly related PRs

  • chore: Bump zoekt #921: Updates vendor/zoekt submodule to the base commit (4a1108…) from which this PR advances it further to dec971a.
🚥 Pre-merge checks | ✅ 3
✅ Passed checks (3 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Title check✅ PassedThe title accurately and concisely summarizes the main changes: upgrading Go toolchain to 1.25 and zoekt version, matching all three file modifications (Dockerfile, CHANGELOG, vendor/zoekt).

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch brendan/upgrade-go-1.25

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🧹 Nitpick comments (1)
Dockerfile (1)

19-19: Pin the Go builder image more tightly to keep builds reproducible.

golang:1.25-alpine is a floating tag; patch/Alpine drift can cause non-deterministic CI behavior. Pin to a specific patch version (e.g., golang:1.25.0-alpine) or digest instead.

🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.
In `@Dockerfile` at line 19, The Dockerfile uses a floating builder image tag
"golang:1.25-alpine" in the FROM instruction which can cause non-deterministic
builds; update the FROM line to pin the Go builder to a specific patch version
(e.g., "golang:1.25.0-alpine") or, better, to an immutable digest for
reproducibility, ensuring the image reference is stable for CI and local builds.
🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.
Nitpick comments:
In `@Dockerfile`:
- Line 19: The Dockerfile uses a floating builder image tag "golang:1.25-alpine"
in the FROM instruction which can cause non-deterministic builds; update the
FROM line to pin the Go builder to a specific patch version (e.g.,
"golang:1.25.0-alpine") or, better, to an immutable digest for reproducibility,
ensuring the image reference is stable for CI and local builds.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: a1e93270-e7bf-4067-829f-d7257ef6a7df

📥 Commits

Reviewing files that changed from the base of the PR and between 5420c3d and bf87d88.

📒 Files selected for processing (3)
  • CHANGELOG.md
  • Dockerfile
  • vendor/zoekt

@brendan-kellambrendan-kellam changed the title chore: upgrade Go toolchain from 1.23.4 to 1.25chore: upgrade Go toolchain 1.25 & zoekt versionApr 14, 2026
@brendan-kellam
brendan-kellam merged commit 775164c into mainApr 14, 2026
9 checks passed
@brendan-kellam
brendan-kellam deleted the brendan/upgrade-go-1.25 branch April 14, 2026 23:05
@github-actionsgithub-actionsBot mentioned this pull request Apr 14, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@brendan-kellam
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

chore: upgrade Go toolchain 1.25 & zoekt version - #1112

Merged
brendan-kellam merged 3 commits into
mainfrom
brendan/upgrade-go-1.25
Apr 14, 2026
Merged

chore: upgrade Go toolchain 1.25 & zoekt version#1112
brendan-kellam merged 3 commits into
mainfrom
brendan/upgrade-go-1.25

Conversation

@brendan-kellam

@brendan-kellambrendan-kellam commented Apr 14, 2026

Copy link
Copy Markdown
Contributor

bump zoekt dependency & upgrade to go 1.25

Summary by CodeRabbit

  • Bug Fixes

    • Patched critical and high-severity security vulnerabilities in Go standard library through an upgrade to Go toolchain version 1.25, addressing CVE-2025-68121 and multiple additional Go standard library CVEs affecting the runtime and security subsystems.
  • Chores

    • Updated vendored dependencies and build infrastructure to maintain compatibility with the latest Go toolchain version, ensuring secure and stable operations.

Resolves CVE-2025-68121 (CRITICAL, crypto/tls certificate validation
during TLS session resumption) and multiple HIGH/MEDIUM Go stdlib CVEs
across all zoekt binaries.
Also pulls latest zoekt submodule (dec971a, bump dependencies #9)
which updates go.mod to go 1.25.0.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
@github-actions

This comment has been minimized.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
@coderabbitai

coderabbitaiBot commented Apr 14, 2026

Copy link
Copy Markdown
Contributor

Walkthrough

The pull request updates the Go toolchain from version 1.23.4 to 1.25, addressing CVE-2025-68121 and additional Go standard library vulnerabilities. The Dockerfile Go builder image and vendor/zoekt submodule are updated correspondingly.

Changes

Cohort / File(s)Summary
Go Toolchain Upgrade
CHANGELOG.md, Dockerfile
Version bump from Go 1.23.4 to 1.25, with updated Alpine base image from alpine3.19 to alpine. Changelog entry documenting CVE remediation added.
Submodule Update
vendor/zoekt
Git submodule reference advanced from 4a11080 to dec971a commit.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~8 minutes

Possibly related PRs

  • chore: Bump zoekt #921: Updates vendor/zoekt submodule to the base commit (4a1108…) from which this PR advances it further to dec971a.
🚥 Pre-merge checks | ✅ 3
✅ Passed checks (3 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Title check✅ PassedThe title accurately and concisely summarizes the main changes: upgrading Go toolchain to 1.25 and zoekt version, matching all three file modifications (Dockerfile, CHANGELOG, vendor/zoekt).

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch brendan/upgrade-go-1.25

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🧹 Nitpick comments (1)
Dockerfile (1)

19-19: Pin the Go builder image more tightly to keep builds reproducible.

golang:1.25-alpine is a floating tag; patch/Alpine drift can cause non-deterministic CI behavior. Pin to a specific patch version (e.g., golang:1.25.0-alpine) or digest instead.

🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.
In `@Dockerfile` at line 19, The Dockerfile uses a floating builder image tag
"golang:1.25-alpine" in the FROM instruction which can cause non-deterministic
builds; update the FROM line to pin the Go builder to a specific patch version
(e.g., "golang:1.25.0-alpine") or, better, to an immutable digest for
reproducibility, ensuring the image reference is stable for CI and local builds.
🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.
Nitpick comments:
In `@Dockerfile`:
- Line 19: The Dockerfile uses a floating builder image tag "golang:1.25-alpine"
in the FROM instruction which can cause non-deterministic builds; update the
FROM line to pin the Go builder to a specific patch version (e.g.,
"golang:1.25.0-alpine") or, better, to an immutable digest for reproducibility,
ensuring the image reference is stable for CI and local builds.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: a1e93270-e7bf-4067-829f-d7257ef6a7df

📥 Commits

Reviewing files that changed from the base of the PR and between 5420c3d and bf87d88.

📒 Files selected for processing (3)
  • CHANGELOG.md
  • Dockerfile
  • vendor/zoekt

@brendan-kellambrendan-kellam changed the title chore: upgrade Go toolchain from 1.23.4 to 1.25chore: upgrade Go toolchain 1.25 & zoekt versionApr 14, 2026
@brendan-kellam
brendan-kellam merged commit 775164c into mainApr 14, 2026
9 checks passed
@brendan-kellam
brendan-kellam deleted the brendan/upgrade-go-1.25 branch April 14, 2026 23:05
@github-actionsgithub-actionsBot mentioned this pull request Apr 14, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@brendan-kellam
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

chore: upgrade Go toolchain 1.25 & zoekt version - #1112

Merged
brendan-kellam merged 3 commits into
mainfrom
brendan/upgrade-go-1.25
Apr 14, 2026
Merged

chore: upgrade Go toolchain 1.25 & zoekt version#1112
brendan-kellam merged 3 commits into
mainfrom
brendan/upgrade-go-1.25

Conversation

@brendan-kellam

@brendan-kellambrendan-kellam commented Apr 14, 2026

Copy link
Copy Markdown
Contributor

bump zoekt dependency & upgrade to go 1.25

Summary by CodeRabbit

  • Bug Fixes

    • Patched critical and high-severity security vulnerabilities in Go standard library through an upgrade to Go toolchain version 1.25, addressing CVE-2025-68121 and multiple additional Go standard library CVEs affecting the runtime and security subsystems.
  • Chores

    • Updated vendored dependencies and build infrastructure to maintain compatibility with the latest Go toolchain version, ensuring secure and stable operations.

Resolves CVE-2025-68121 (CRITICAL, crypto/tls certificate validation
during TLS session resumption) and multiple HIGH/MEDIUM Go stdlib CVEs
across all zoekt binaries.
Also pulls latest zoekt submodule (dec971a, bump dependencies #9)
which updates go.mod to go 1.25.0.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
@github-actions

This comment has been minimized.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
@coderabbitai

coderabbitaiBot commented Apr 14, 2026

Copy link
Copy Markdown
Contributor

Walkthrough

The pull request updates the Go toolchain from version 1.23.4 to 1.25, addressing CVE-2025-68121 and additional Go standard library vulnerabilities. The Dockerfile Go builder image and vendor/zoekt submodule are updated correspondingly.

Changes

Cohort / File(s)Summary
Go Toolchain Upgrade
CHANGELOG.md, Dockerfile
Version bump from Go 1.23.4 to 1.25, with updated Alpine base image from alpine3.19 to alpine. Changelog entry documenting CVE remediation added.
Submodule Update
vendor/zoekt
Git submodule reference advanced from 4a11080 to dec971a commit.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~8 minutes

Possibly related PRs

  • chore: Bump zoekt #921: Updates vendor/zoekt submodule to the base commit (4a1108…) from which this PR advances it further to dec971a.
🚥 Pre-merge checks | ✅ 3
✅ Passed checks (3 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Title check✅ PassedThe title accurately and concisely summarizes the main changes: upgrading Go toolchain to 1.25 and zoekt version, matching all three file modifications (Dockerfile, CHANGELOG, vendor/zoekt).

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch brendan/upgrade-go-1.25

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🧹 Nitpick comments (1)
Dockerfile (1)

19-19: Pin the Go builder image more tightly to keep builds reproducible.

golang:1.25-alpine is a floating tag; patch/Alpine drift can cause non-deterministic CI behavior. Pin to a specific patch version (e.g., golang:1.25.0-alpine) or digest instead.

🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.
In `@Dockerfile` at line 19, The Dockerfile uses a floating builder image tag
"golang:1.25-alpine" in the FROM instruction which can cause non-deterministic
builds; update the FROM line to pin the Go builder to a specific patch version
(e.g., "golang:1.25.0-alpine") or, better, to an immutable digest for
reproducibility, ensuring the image reference is stable for CI and local builds.
🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.
Nitpick comments:
In `@Dockerfile`:
- Line 19: The Dockerfile uses a floating builder image tag "golang:1.25-alpine"
in the FROM instruction which can cause non-deterministic builds; update the
FROM line to pin the Go builder to a specific patch version (e.g.,
"golang:1.25.0-alpine") or, better, to an immutable digest for reproducibility,
ensuring the image reference is stable for CI and local builds.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: a1e93270-e7bf-4067-829f-d7257ef6a7df

📥 Commits

Reviewing files that changed from the base of the PR and between 5420c3d and bf87d88.

📒 Files selected for processing (3)
  • CHANGELOG.md
  • Dockerfile
  • vendor/zoekt

@brendan-kellambrendan-kellam changed the title chore: upgrade Go toolchain from 1.23.4 to 1.25chore: upgrade Go toolchain 1.25 & zoekt versionApr 14, 2026
@brendan-kellam
brendan-kellam merged commit 775164c into mainApr 14, 2026
9 checks passed
@brendan-kellam
brendan-kellam deleted the brendan/upgrade-go-1.25 branch April 14, 2026 23:05
@github-actionsgithub-actionsBot mentioned this pull request Apr 14, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@brendan-kellam
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

chore: upgrade Go toolchain 1.25 & zoekt version - #1112

Merged
brendan-kellam merged 3 commits into
mainfrom
brendan/upgrade-go-1.25
Apr 14, 2026
Merged

chore: upgrade Go toolchain 1.25 & zoekt version#1112
brendan-kellam merged 3 commits into
mainfrom
brendan/upgrade-go-1.25

Conversation

@brendan-kellam

@brendan-kellambrendan-kellam commented Apr 14, 2026

Copy link
Copy Markdown
Contributor

bump zoekt dependency & upgrade to go 1.25

Summary by CodeRabbit

  • Bug Fixes

    • Patched critical and high-severity security vulnerabilities in Go standard library through an upgrade to Go toolchain version 1.25, addressing CVE-2025-68121 and multiple additional Go standard library CVEs affecting the runtime and security subsystems.
  • Chores

    • Updated vendored dependencies and build infrastructure to maintain compatibility with the latest Go toolchain version, ensuring secure and stable operations.

Resolves CVE-2025-68121 (CRITICAL, crypto/tls certificate validation
during TLS session resumption) and multiple HIGH/MEDIUM Go stdlib CVEs
across all zoekt binaries.
Also pulls latest zoekt submodule (dec971a, bump dependencies #9)
which updates go.mod to go 1.25.0.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
@github-actions

This comment has been minimized.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
@coderabbitai

coderabbitaiBot commented Apr 14, 2026

Copy link
Copy Markdown
Contributor

Walkthrough

The pull request updates the Go toolchain from version 1.23.4 to 1.25, addressing CVE-2025-68121 and additional Go standard library vulnerabilities. The Dockerfile Go builder image and vendor/zoekt submodule are updated correspondingly.

Changes

Cohort / File(s)Summary
Go Toolchain Upgrade
CHANGELOG.md, Dockerfile
Version bump from Go 1.23.4 to 1.25, with updated Alpine base image from alpine3.19 to alpine. Changelog entry documenting CVE remediation added.
Submodule Update
vendor/zoekt
Git submodule reference advanced from 4a11080 to dec971a commit.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~8 minutes

Possibly related PRs

  • chore: Bump zoekt #921: Updates vendor/zoekt submodule to the base commit (4a1108…) from which this PR advances it further to dec971a.
🚥 Pre-merge checks | ✅ 3
✅ Passed checks (3 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Title check✅ PassedThe title accurately and concisely summarizes the main changes: upgrading Go toolchain to 1.25 and zoekt version, matching all three file modifications (Dockerfile, CHANGELOG, vendor/zoekt).

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch brendan/upgrade-go-1.25

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🧹 Nitpick comments (1)
Dockerfile (1)

19-19: Pin the Go builder image more tightly to keep builds reproducible.

golang:1.25-alpine is a floating tag; patch/Alpine drift can cause non-deterministic CI behavior. Pin to a specific patch version (e.g., golang:1.25.0-alpine) or digest instead.

🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.
In `@Dockerfile` at line 19, The Dockerfile uses a floating builder image tag
"golang:1.25-alpine" in the FROM instruction which can cause non-deterministic
builds; update the FROM line to pin the Go builder to a specific patch version
(e.g., "golang:1.25.0-alpine") or, better, to an immutable digest for
reproducibility, ensuring the image reference is stable for CI and local builds.
🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.
Nitpick comments:
In `@Dockerfile`:
- Line 19: The Dockerfile uses a floating builder image tag "golang:1.25-alpine"
in the FROM instruction which can cause non-deterministic builds; update the
FROM line to pin the Go builder to a specific patch version (e.g.,
"golang:1.25.0-alpine") or, better, to an immutable digest for reproducibility,
ensuring the image reference is stable for CI and local builds.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: a1e93270-e7bf-4067-829f-d7257ef6a7df

📥 Commits

Reviewing files that changed from the base of the PR and between 5420c3d and bf87d88.

📒 Files selected for processing (3)
  • CHANGELOG.md
  • Dockerfile
  • vendor/zoekt

@brendan-kellambrendan-kellam changed the title chore: upgrade Go toolchain from 1.23.4 to 1.25chore: upgrade Go toolchain 1.25 & zoekt versionApr 14, 2026
@brendan-kellam
brendan-kellam merged commit 775164c into mainApr 14, 2026
9 checks passed
@brendan-kellam
brendan-kellam deleted the brendan/upgrade-go-1.25 branch April 14, 2026 23:05
@github-actionsgithub-actionsBot mentioned this pull request Apr 14, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@brendan-kellam
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

chore: upgrade Go toolchain 1.25 & zoekt version - #1112

Merged
brendan-kellam merged 3 commits into
mainfrom
brendan/upgrade-go-1.25
Apr 14, 2026
Merged

chore: upgrade Go toolchain 1.25 & zoekt version#1112
brendan-kellam merged 3 commits into
mainfrom
brendan/upgrade-go-1.25

Conversation

@brendan-kellam

@brendan-kellambrendan-kellam commented Apr 14, 2026

Copy link
Copy Markdown
Contributor

bump zoekt dependency & upgrade to go 1.25

Summary by CodeRabbit

  • Bug Fixes

    • Patched critical and high-severity security vulnerabilities in Go standard library through an upgrade to Go toolchain version 1.25, addressing CVE-2025-68121 and multiple additional Go standard library CVEs affecting the runtime and security subsystems.
  • Chores

    • Updated vendored dependencies and build infrastructure to maintain compatibility with the latest Go toolchain version, ensuring secure and stable operations.

Resolves CVE-2025-68121 (CRITICAL, crypto/tls certificate validation
during TLS session resumption) and multiple HIGH/MEDIUM Go stdlib CVEs
across all zoekt binaries.
Also pulls latest zoekt submodule (dec971a, bump dependencies #9)
which updates go.mod to go 1.25.0.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
@github-actions

This comment has been minimized.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
@coderabbitai

coderabbitaiBot commented Apr 14, 2026

Copy link
Copy Markdown
Contributor

Walkthrough

The pull request updates the Go toolchain from version 1.23.4 to 1.25, addressing CVE-2025-68121 and additional Go standard library vulnerabilities. The Dockerfile Go builder image and vendor/zoekt submodule are updated correspondingly.

Changes

Cohort / File(s)Summary
Go Toolchain Upgrade
CHANGELOG.md, Dockerfile
Version bump from Go 1.23.4 to 1.25, with updated Alpine base image from alpine3.19 to alpine. Changelog entry documenting CVE remediation added.
Submodule Update
vendor/zoekt
Git submodule reference advanced from 4a11080 to dec971a commit.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~8 minutes

Possibly related PRs

  • chore: Bump zoekt #921: Updates vendor/zoekt submodule to the base commit (4a1108…) from which this PR advances it further to dec971a.
🚥 Pre-merge checks | ✅ 3
✅ Passed checks (3 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Title check✅ PassedThe title accurately and concisely summarizes the main changes: upgrading Go toolchain to 1.25 and zoekt version, matching all three file modifications (Dockerfile, CHANGELOG, vendor/zoekt).

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch brendan/upgrade-go-1.25

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🧹 Nitpick comments (1)
Dockerfile (1)

19-19: Pin the Go builder image more tightly to keep builds reproducible.

golang:1.25-alpine is a floating tag; patch/Alpine drift can cause non-deterministic CI behavior. Pin to a specific patch version (e.g., golang:1.25.0-alpine) or digest instead.

🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.
In `@Dockerfile` at line 19, The Dockerfile uses a floating builder image tag
"golang:1.25-alpine" in the FROM instruction which can cause non-deterministic
builds; update the FROM line to pin the Go builder to a specific patch version
(e.g., "golang:1.25.0-alpine") or, better, to an immutable digest for
reproducibility, ensuring the image reference is stable for CI and local builds.
🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.
Nitpick comments:
In `@Dockerfile`:
- Line 19: The Dockerfile uses a floating builder image tag "golang:1.25-alpine"
in the FROM instruction which can cause non-deterministic builds; update the
FROM line to pin the Go builder to a specific patch version (e.g.,
"golang:1.25.0-alpine") or, better, to an immutable digest for reproducibility,
ensuring the image reference is stable for CI and local builds.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: a1e93270-e7bf-4067-829f-d7257ef6a7df

📥 Commits

Reviewing files that changed from the base of the PR and between 5420c3d and bf87d88.

📒 Files selected for processing (3)
  • CHANGELOG.md
  • Dockerfile
  • vendor/zoekt

@brendan-kellambrendan-kellam changed the title chore: upgrade Go toolchain from 1.23.4 to 1.25chore: upgrade Go toolchain 1.25 & zoekt versionApr 14, 2026
@brendan-kellam
brendan-kellam merged commit 775164c into mainApr 14, 2026
9 checks passed
@brendan-kellam
brendan-kellam deleted the brendan/upgrade-go-1.25 branch April 14, 2026 23:05
@github-actionsgithub-actionsBot mentioned this pull request Apr 14, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@brendan-kellam