From 0eae243c3f39706b6b322587bc14fd9d79c97a58 Mon Sep 17 00:00:00 2001 From: Ryan Richard Date: Mon, 24 Aug 2026 13:22:48 -0700 Subject: [PATCH] update CI to use golang 1.26.7 Signed-off-by: Ryan Richard --- dockerfiles/code-coverage-uploader/Dockerfile | 2 +- dockerfiles/crane/Dockerfile | 2 +- dockerfiles/gh-cli/Dockerfile | 2 +- dockerfiles/integration-test-runner-beta/Dockerfile | 2 +- dockerfiles/integration-test-runner/Dockerfile | 2 +- dockerfiles/test-cfssl/Dockerfile | 2 +- pipelines/dockerfile-builders/pipeline.yml | 2 +- pipelines/pull-requests/pipeline.yml | 2 +- pipelines/shared-helpers/test-binaries-image/Dockerfile | 2 +- pipelines/shared-helpers/test-binaries-image/Dockerfile_fips | 2 +- pipelines/shared-tasks/build-cli-binaries/task.yml | 2 +- pipelines/shared-tasks/confirm-built-with-fips/task.yml | 2 +- pipelines/shared-tasks/confirm-built-with-gofips140/task.yml | 2 +- pipelines/shared-tasks/confirm-version/task.yml | 2 +- pipelines/shared-tasks/format-release/task.yml | 2 +- pipelines/shared-tasks/run-go-vuln-scan/task.yml | 2 +- pipelines/shared-tasks/run-unit-tests/task.yml | 2 +- pipelines/shared-tasks/run-verify-go-generate/task.yml | 2 +- pipelines/shared-tasks/run-verify-go-mod-tidy/task.yml | 2 +- pipelines/shared-tasks/run-verify-lint/task.yml | 2 +- pipelines/shared-tasks/update-version-and-cli-docs/task.yml | 2 +- 21 files changed, 21 insertions(+), 21 deletions(-) diff --git a/dockerfiles/code-coverage-uploader/Dockerfile b/dockerfiles/code-coverage-uploader/Dockerfile index 678fce24f..bb3f7a0d4 100644 --- a/dockerfiles/code-coverage-uploader/Dockerfile +++ b/dockerfiles/code-coverage-uploader/Dockerfile @@ -9,6 +9,6 @@ RUN apt-get update && apt-get install -y curl && rm -rf /var/lib/apt/lists/* RUN curl -sfLo /tmp/codecov https://uploader.codecov.io/latest/linux/codecov RUN chmod +x /tmp/codecov -FROM golang:1.26.6 +FROM golang:1.26.7 RUN apt-get update -y && apt-get dist-upgrade -y COPY --from=builder /tmp/codecov /usr/local/bin/codecov diff --git a/dockerfiles/crane/Dockerfile b/dockerfiles/crane/Dockerfile index c6d64c06d..cc504b052 100644 --- a/dockerfiles/crane/Dockerfile +++ b/dockerfiles/crane/Dockerfile @@ -4,7 +4,7 @@ FROM gcr.io/go-containerregistry/crane as crane FROM mikefarah/yq:4.53.3 AS yq -FROM golang:1.26.6 +FROM golang:1.26.7 COPY --from=yq /usr/bin/yq /usr/local/bin COPY --from=crane /ko-app/crane /usr/local/bin ENTRYPOINT ["bash"] diff --git a/dockerfiles/gh-cli/Dockerfile b/dockerfiles/gh-cli/Dockerfile index c75a68e44..4f916c9cc 100644 --- a/dockerfiles/gh-cli/Dockerfile +++ b/dockerfiles/gh-cli/Dockerfile @@ -11,5 +11,5 @@ RUN curl \ https://github.com/cli/cli/releases/download/v2.40.0/gh_2.40.0_linux_amd64.tar.gz \ && tar -C /tmp --strip-components=1 -xzvf /tmp/gh.tar.gz -FROM golang:1.26.6 +FROM golang:1.26.7 COPY --from=builder /tmp/bin/gh /usr/local/bin/gh diff --git a/dockerfiles/integration-test-runner-beta/Dockerfile b/dockerfiles/integration-test-runner-beta/Dockerfile index f0f570df1..9922614b8 100644 --- a/dockerfiles/integration-test-runner-beta/Dockerfile +++ b/dockerfiles/integration-test-runner-beta/Dockerfile @@ -37,7 +37,7 @@ RUN google-chrome --version # Install Go. The download URL that can be used below for any version of Go can be found on https://go.dev/dl/ ENV PATH /usr/local/go/bin:$PATH -RUN curl -fsSL https://go.dev/dl/go1.26.6.linux-amd64.tar.gz -o /tmp/go.tar.gz && \ +RUN curl -fsSL https://go.dev/dl/go1.26.7.linux-amd64.tar.gz -o /tmp/go.tar.gz && \ tar -C /usr/local -xzf /tmp/go.tar.gz && \ rm /tmp/go.tar.gz && \ go version diff --git a/dockerfiles/integration-test-runner/Dockerfile b/dockerfiles/integration-test-runner/Dockerfile index d5b6f3e38..82abefb9c 100644 --- a/dockerfiles/integration-test-runner/Dockerfile +++ b/dockerfiles/integration-test-runner/Dockerfile @@ -37,7 +37,7 @@ RUN google-chrome --version # Install Go. The download URL that can be used below for any version of Go can be found on https://go.dev/dl/ ENV PATH /usr/local/go/bin:$PATH -RUN curl -fsSL https://go.dev/dl/go1.26.6.linux-amd64.tar.gz -o /tmp/go.tar.gz && \ +RUN curl -fsSL https://go.dev/dl/go1.26.7.linux-amd64.tar.gz -o /tmp/go.tar.gz && \ tar -C /usr/local -xzf /tmp/go.tar.gz && \ rm /tmp/go.tar.gz && \ go version diff --git a/dockerfiles/test-cfssl/Dockerfile b/dockerfiles/test-cfssl/Dockerfile index eae3934c0..b7e018c7a 100644 --- a/dockerfiles/test-cfssl/Dockerfile +++ b/dockerfiles/test-cfssl/Dockerfile @@ -11,7 +11,7 @@ FROM cfssl/cfssl:v1.6.5 as cfssl # We just need any basic unix with bash, but we can pick the same # base image that they use, just in case they did any dynamic linking. -FROM golang:1.26.6 +FROM golang:1.26.7 # Thier Docerfile https://github.com/cloudflare/cfssl/blob/master/Dockerfile # calls their Makefile https://github.com/cloudflare/cfssl/blob/master/Makefile diff --git a/pipelines/dockerfile-builders/pipeline.yml b/pipelines/dockerfile-builders/pipeline.yml index dcbb2d5fb..ab5cae017 100644 --- a/pipelines/dockerfile-builders/pipeline.yml +++ b/pipelines/dockerfile-builders/pipeline.yml @@ -38,7 +38,7 @@ meta: # These version numbers should be updated periodically. codegen-versions: &codegen-versions # Choose which version of Golang to use in the codegen container images. - BUILD_ARG_GO_VERSION: '1.26.6' + BUILD_ARG_GO_VERSION: '1.26.7' # Choose which version of sigs.k8s.io/controller-tools/cmd/controller-gen to install # in the codegen container images. BUILD_ARG_CONTROLLER_GEN_VERSION: 0.21.0 diff --git a/pipelines/pull-requests/pipeline.yml b/pipelines/pull-requests/pipeline.yml index ba1788430..5a9749763 100644 --- a/pipelines/pull-requests/pipeline.yml +++ b/pipelines/pull-requests/pipeline.yml @@ -593,7 +593,7 @@ jobs: type: registry-image source: repository: golang - tag: '1.26.6' + tag: '1.26.7' inputs: - name: pinniped-pr outputs: diff --git a/pipelines/shared-helpers/test-binaries-image/Dockerfile b/pipelines/shared-helpers/test-binaries-image/Dockerfile index 8992bd583..5c4d086af 100644 --- a/pipelines/shared-helpers/test-binaries-image/Dockerfile +++ b/pipelines/shared-helpers/test-binaries-image/Dockerfile @@ -3,7 +3,7 @@ # Copyright 2020-2026 the Pinniped contributors. All Rights Reserved. # SPDX-License-Identifier: Apache-2.0 -FROM golang:1.26.6-bookworm as build-env +FROM golang:1.26.7-bookworm as build-env WORKDIR /work COPY . . ARG GOPROXY diff --git a/pipelines/shared-helpers/test-binaries-image/Dockerfile_fips b/pipelines/shared-helpers/test-binaries-image/Dockerfile_fips index 7d227000c..9507543f7 100644 --- a/pipelines/shared-helpers/test-binaries-image/Dockerfile_fips +++ b/pipelines/shared-helpers/test-binaries-image/Dockerfile_fips @@ -6,7 +6,7 @@ # we need a separate dockerfile for the fips test image so that the integration tests # use the right ciphers etc. -FROM golang:1.26.6-bookworm as build-env +FROM golang:1.26.7-bookworm as build-env WORKDIR /work COPY . . ARG GOPROXY diff --git a/pipelines/shared-tasks/build-cli-binaries/task.yml b/pipelines/shared-tasks/build-cli-binaries/task.yml index 76f1f03fc..124178fc3 100644 --- a/pipelines/shared-tasks/build-cli-binaries/task.yml +++ b/pipelines/shared-tasks/build-cli-binaries/task.yml @@ -7,7 +7,7 @@ image_resource: type: registry-image source: repository: golang - tag: '1.26.6' + tag: '1.26.7' inputs: - name: pinniped - name: pinniped-ci diff --git a/pipelines/shared-tasks/confirm-built-with-fips/task.yml b/pipelines/shared-tasks/confirm-built-with-fips/task.yml index 155c4806f..da343f8bc 100644 --- a/pipelines/shared-tasks/confirm-built-with-fips/task.yml +++ b/pipelines/shared-tasks/confirm-built-with-fips/task.yml @@ -10,6 +10,6 @@ image_resource: type: registry-image source: repository: golang - tag: '1.26.6' + tag: '1.26.7' run: path: pinniped-ci/pipelines/shared-tasks/confirm-built-with-fips/task.sh diff --git a/pipelines/shared-tasks/confirm-built-with-gofips140/task.yml b/pipelines/shared-tasks/confirm-built-with-gofips140/task.yml index 76881cabe..a95a2fbbe 100644 --- a/pipelines/shared-tasks/confirm-built-with-gofips140/task.yml +++ b/pipelines/shared-tasks/confirm-built-with-gofips140/task.yml @@ -10,6 +10,6 @@ image_resource: type: registry-image source: repository: golang - tag: '1.26.6' + tag: '1.26.7' run: path: pinniped-ci/pipelines/shared-tasks/confirm-built-with-gofips140/task.sh diff --git a/pipelines/shared-tasks/confirm-version/task.yml b/pipelines/shared-tasks/confirm-version/task.yml index 17be4226e..2f2841277 100644 --- a/pipelines/shared-tasks/confirm-version/task.yml +++ b/pipelines/shared-tasks/confirm-version/task.yml @@ -10,7 +10,7 @@ image_resource: type: registry-image source: repository: golang - tag: '1.26.6' + tag: '1.26.7' run: # Confirm that the correct git sha was baked into the executables and that they log the version as their # first line of output. Do this by directly running the server binary from the rootfs of the built image. diff --git a/pipelines/shared-tasks/format-release/task.yml b/pipelines/shared-tasks/format-release/task.yml index b223947ec..83f1194c0 100644 --- a/pipelines/shared-tasks/format-release/task.yml +++ b/pipelines/shared-tasks/format-release/task.yml @@ -7,7 +7,7 @@ image_resource: type: registry-image source: repository: golang - tag: '1.26.6' + tag: '1.26.7' inputs: - name: pinniped - name: release-semver diff --git a/pipelines/shared-tasks/run-go-vuln-scan/task.yml b/pipelines/shared-tasks/run-go-vuln-scan/task.yml index 45362c56c..64ae13d24 100644 --- a/pipelines/shared-tasks/run-go-vuln-scan/task.yml +++ b/pipelines/shared-tasks/run-go-vuln-scan/task.yml @@ -7,7 +7,7 @@ image_resource: type: registry-image source: repository: golang - tag: '1.26.6' + tag: '1.26.7' inputs: - name: pinniped - name: pinniped-ci diff --git a/pipelines/shared-tasks/run-unit-tests/task.yml b/pipelines/shared-tasks/run-unit-tests/task.yml index 45e43af54..79c58a9d9 100644 --- a/pipelines/shared-tasks/run-unit-tests/task.yml +++ b/pipelines/shared-tasks/run-unit-tests/task.yml @@ -7,7 +7,7 @@ image_resource: type: registry-image source: repository: golang - tag: '1.26.6' + tag: '1.26.7' inputs: - name: pinniped - name: pinniped-ci diff --git a/pipelines/shared-tasks/run-verify-go-generate/task.yml b/pipelines/shared-tasks/run-verify-go-generate/task.yml index c80243a10..1c71c9789 100644 --- a/pipelines/shared-tasks/run-verify-go-generate/task.yml +++ b/pipelines/shared-tasks/run-verify-go-generate/task.yml @@ -7,7 +7,7 @@ image_resource: type: registry-image source: repository: golang - tag: '1.26.6' + tag: '1.26.7' inputs: - name: pinniped - name: pinniped-ci diff --git a/pipelines/shared-tasks/run-verify-go-mod-tidy/task.yml b/pipelines/shared-tasks/run-verify-go-mod-tidy/task.yml index c0a7405d1..d40c08494 100644 --- a/pipelines/shared-tasks/run-verify-go-mod-tidy/task.yml +++ b/pipelines/shared-tasks/run-verify-go-mod-tidy/task.yml @@ -7,7 +7,7 @@ image_resource: type: registry-image source: repository: golang - tag: '1.26.6' + tag: '1.26.7' inputs: - name: pinniped - name: pinniped-ci diff --git a/pipelines/shared-tasks/run-verify-lint/task.yml b/pipelines/shared-tasks/run-verify-lint/task.yml index eb751501b..e78746503 100644 --- a/pipelines/shared-tasks/run-verify-lint/task.yml +++ b/pipelines/shared-tasks/run-verify-lint/task.yml @@ -7,7 +7,7 @@ image_resource: type: registry-image source: repository: golang - tag: '1.26.6' + tag: '1.26.7' inputs: - name: pinniped - name: pinniped-ci diff --git a/pipelines/shared-tasks/update-version-and-cli-docs/task.yml b/pipelines/shared-tasks/update-version-and-cli-docs/task.yml index d4f0095ae..9c5a72ac9 100644 --- a/pipelines/shared-tasks/update-version-and-cli-docs/task.yml +++ b/pipelines/shared-tasks/update-version-and-cli-docs/task.yml @@ -7,7 +7,7 @@ image_resource: type: registry-image source: repository: golang - tag: '1.26.6' + tag: '1.26.7' inputs: - name: pinniped-ci - name: github-final-release