security: bump Go toolchain to 1.27.1 and vulnerable deps for v0.1.14 - #23
Merged
Merged
Conversation
A customer's syft/grype scan of the v0.1.13 linux binary (built with go1.25.8) flagged Go stdlib CVEs fixed in Go 1.25.13/1.26.6, plus outdated golang.org/x/net and google.golang.org/grpc pulled in transitively. - Bump the toolchain used to build release binaries to go1.27.1 (latest stable, well past the 1.26.6/1.25.13 security fixes) in both GitHub Actions workflows and go.mod's toolchain directive. - go get -u golang.org/x/net google.golang.org/grpc google.golang.org/protobuf golang.org/x/crypto golang.org/x/image (only x/net and grpc were present in the module graph; x/crypto and x/image are not dependencies of this module) + go mod tidy. - Fix a pre-existing non-constant format string in plugins/environment.go's usage message. It was already latent but only surfaces as a go vet build failure once go.mod's language version moves to 1.21+; output text is unchanged. No generator behavior changes. Co-Authored-By: Claude <noreply@anthropic.com>
Ryan-Amirthan
approved these changes
Sep 24, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
A customer's syft/grype scan of the v0.1.13
protoc-gen-openapi-linux-amd64binary (built with go1.25.8) flagged:golang.org/x/net(<0.55.0) andgoogle.golang.org/grpc(<1.82.2) pulled in transitivelyThis PR is dependency/toolchain only — no generator behavior changes.
Changes
go1.27.1(latest stable, well past the 1.26.6/1.25.13 security fixes).github/workflows/release.yml:setup-gogo-version: "1.27.1"(was^1.20).github/workflows/go.yml: same bump, for consistencygo.mod: addedtoolchain go1.27.1and thegodirective was auto-raised to1.26.0bygo get -ugo get -u golang.org/x/net golang.org/x/crypto golang.org/x/image google.golang.org/grpc google.golang.org/protobuf(onlyx/netandgrpcwere actually present in the module graph —x/crypto/x/imageare not dependencies of this module) +go mod tidygolang.org/x/net: v0.8.0 → v0.59.0 (≥0.55.0 ✅)google.golang.org/grpc: v1.54.0 → not directly imported by any package in this module, sogo mod tidydropped it from the explicit require list; the module graph still resolves it to v1.79.3 viagoogle.golang.org/genproto's own go.mod, but it is not linked into the shipped binary (confirmed viago list -deps ./cmd/protoc-gen-openapi/...and thego version -moutput below has no grpc entry at all)google.golang.org/protobuf: v1.30.0 → v1.36.12github.com/golang/protobuf: v1.5.3 → v1.5.4golang.org/x/crypto,golang.org/x/image: not present in the module graph (nothing to bump)fmt.Fprintfin the CLI usage message. It was always latent, but only surfaces as ago vetbuild failure (which blocksgo test) oncego.mod's language version moves to 1.21+. Output text is byte-for-byte identical ("%s is a gnostic plugin.\n"vsprogramName+" is a gnostic plugin.\n").Why
go.sumshrank by ~1500 lines: the old pinnedgoogle.golang.org/genproto@v0.0.0-20230526...(a 2023 pseudo-version from before that repo was split apart) has ago.modthat directlyrequires ~150 individualcloud.google.com/go/*service submodules, none of which this project ever imports — plus their own onward transitive deps (gonum plotting, PDF libs, x/mobile, x/exp, envoy xds, etc.). None of that was ever compiled into any binary here;go.sumjust has to record checksums for everything in the module graph. The 2026-era replacements (google.golang.org/genproto/googleapis/apiand.../rpc) were split out of that monorepo years ago and have minimalgo.mods (justgrpc/protobuf/a fewx/*indirects), so upgrading collapsed the graph accordingly. Nothing that was actually part of the built binary changed shape — verify withgo list -deps ./cmd/protoc-gen-openapi/...before/after.Verification
go build ./...andgo vet ./...— clean:go test ./...— all packages pass except two pre-existing, environment-dependent failures that I verified also fail onmainbefore this change with the same local toolchain (missing/mismatched localprotoc/diffbehavior, not code):cmd/protoc-gen-openapi(protoc-invoking tests) — fails the same way onmainextensions(TestExtensionHandlerWithLibraryExample) — fails the same way onmaingovulncheck ./...:Built the
linux/amd64release binary exactly asrelease.ymldoes and inspected it:Confirms: built with go1.27.1, and
golang.org/x/net,golang.org/x/crypto,golang.org/x/image, andgoogle.golang.org/grpcare not present in the shipped binary at all (they were never linked in — only the Go toolchain's own vendored copies ofx/net/x/cryptoinsidenet/http/crypto/tlswere relevant to the syft flag, and those are now updated simply by building with go1.27.1). Repeated the same build/inspect forlinux/arm64with identical results (go1.27.1, same dep set).Release steps for v0.1.14 (unchanged asset names)
fern-platform'sservers/self-hosted/Dockerfile.basedownloadsprotoc-gen-openapi-linux-amd64/protoc-gen-openapi-linux-arm64by exact name, so this release must keep producing those same filenames (it does —release.ymlis unchanged in that respect).main.git checkout main && git pullgit tag v0.1.14 && git push origin v0.1.14Releaseworkflow (.github/workflows/release.yml) triggers on thev*tag push, builds all 6 platform binaries with go1.27.1, and publishes them as a GitHub Release viasoftprops/action-gh-release, producing (among others):protoc-gen-openapi-linux-amd64protoc-gen-openapi-linux-arm64(same names as v0.1.13 — no Dockerfile.base change needed downstream)
protoc-gen-openapi-linux-amd64asset to confirm the flagged findings are gone.Generated with Claude Code