Skip to content

chore: upgrade Go and dependencies - #198

Open
vlnst wants to merge 8 commits into
httpjamesm:mainfrom
vlnst:chore/upgrade-go
Open

vlnst wants to merge 8 commits into
httpjamesm:mainfrom
vlnst:chore/upgrade-go

Conversation

@vlnst

@vlnst vlnst commented Oct 7, 2026 •

Copy link
Copy Markdown
Contributor

Upgrades Go and all direct dependencies. govulncheck ./... went from 14 reachable vulnerabilities (x/net, x/text, jwt/v4, incl. GO-2025-3553 in /proxy) to 0.

Changes

  • Dockerfile: golang:1.22.1-alpine3.19 → golang:1.27-alpine (gets Go patch releases on rebuild)
  • go.mod: go 1.19 → go 1.25.0 (required by new x/net)
Module From To
gin v1.10.0 v1.12.0
goquery v1.9.1 v1.13.0
resty/v2 v2.12.0 v2.17.2
gin-healthcheck v1.6.2 v1.7.18
testify v1.9.0 v1.12.1
jwt v4.5.0 v5.3.1
chroma v0.10.0 v2.27.0

Release notes reviewed; the only code changes are the jwt v5 and chroma v2 import paths.

Notes

  • jwt v5: tokens signed with v4 still verify.
  • chroma v2: added the two new monokai classes (.fm, .or) to syntax.css. Visible change: Java braces now render in the default text colour instead of pink.

Testing

go build, go vet, go test, govulncheck after each upgrade; Docker image builds and passes its health check; question pages with code blocks compared locally against the old chroma.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant