Skip to content

v1.1.0-debug-5: fix: [CI-23219]: bump CI Go toolchain to 1.25.11 to match go.mod

Choose a tag to compare

@chhawchharia chhawchharia released this 01 Jul 06:05
The vuln remediation raised the go.mod directive to `go 1.25.0`, but the
.drone.yml build step still used `golang:1.22.7`. A 1.22 toolchain cannot
cleanly build a 1.25 module (auto-toolchain download is fragile and fails
under GOTOOLCHAIN=local), and it would compile the plugin binary with an
outdated Go stdlib, re-introducing stdlib CVEs into the image. Pin the build
image to the latest 1.25 patch (1.25.11), which also carries the stdlib fix
for CVE-2025-47910.

Co-authored-by: Cursor <cursoragent@cursor.com>