Skip to content

Bump actions/setup-go from 5.6.0 to 6.2.0#79

Merged
wesm merged 1 commit intomainfrom
dependabot/github_actions/actions/setup-go-6.2.0
Feb 5, 2026
Merged

Bump actions/setup-go from 5.6.0 to 6.2.0#79
wesm merged 1 commit intomainfrom
dependabot/github_actions/actions/setup-go-6.2.0

Conversation

@dependabot
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Feb 5, 2026

Bumps actions/setup-go from 5.6.0 to 6.2.0.

Release notes

Sourced from actions/setup-go's releases.

v6.2.0

What's Changed

Enhancements

Dependency updates

New Contributors

Full Changelog: actions/setup-go@v6...v6.2.0

v6.1.0

What's Changed

Enhancements

Dependency updates

New Contributors

Full Changelog: actions/setup-go@v6...v6.1.0

v6.0.0

What's Changed

Breaking Changes

Make sure your runner is on version v2.327.1 or later to ensure compatibility with this release. See Release Notes

Dependency Upgrades

... (truncated)

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [actions/setup-go](https://github.com/actions/setup-go) from 5.6.0 to 6.2.0.
- [Release notes](https://github.com/actions/setup-go/releases)
- [Commits](actions/setup-go@40f1582...7a3fe6c)

---
updated-dependencies:
- dependency-name: actions/setup-go
  dependency-version: 6.2.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Feb 5, 2026
@dependabot dependabot bot requested a review from wesm as a code owner February 5, 2026 21:53
@dependabot dependabot bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Feb 5, 2026
- uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4

- uses: actions/setup-go@40f1582b2485089dde7abd97c1529aa768e1baff # v5
- uses: actions/setup-go@7a3fe6cf4cb3a834922a1244abfce67bcef6a0c5 # v6.2.0
Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🚨 Unverified GitHub Action version update (high severity)

The actions/setup-go action was updated from v5 (commit 40f1582) to v6.2.0 (commit 7a3fe6c). This commit SHA must be verified against the official actions/setup-go repository to ensure it corresponds to the legitimate v6.2.0 release and has not been tampered with. Malicious workflow modifications can exfiltrate secrets (OAuth tokens, Gmail API credentials) or modify release artifacts.


Automated security review by Claude 4.5 Sonnet - Human review still required

- uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4

- uses: actions/setup-go@40f1582b2485089dde7abd97c1529aa768e1baff # v5
- uses: actions/setup-go@7a3fe6cf4cb3a834922a1244abfce67bcef6a0c5 # v6.2.0
Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🚨 Unverified GitHub Action version update (high severity)

The actions/setup-go action was updated from v5 (commit 40f1582) to v6.2.0 (commit 7a3fe6c). This commit SHA must be verified against the official actions/setup-go repository to ensure it corresponds to the legitimate v6.2.0 release and has not been tampered with. Malicious workflow modifications can exfiltrate secrets (OAuth tokens, Gmail API credentials) or modify release artifacts.


Automated security review by Claude 4.5 Sonnet - Human review still required

- uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4

- uses: actions/setup-go@40f1582b2485089dde7abd97c1529aa768e1baff # v5
- uses: actions/setup-go@7a3fe6cf4cb3a834922a1244abfce67bcef6a0c5 # v6.2.0
Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🚨 Unverified GitHub Action version update in release workflow (high severity)

The actions/setup-go action was updated from v5 (commit 40f1582) to v6.2.0 (commit 7a3fe6c) in the release workflow. This is especially critical as release workflows have access to release secrets and produce user-facing binaries. The commit SHA must be verified against the official repository to prevent supply chain attacks that could compromise distributed msgvault binaries.


Automated security review by Claude 4.5 Sonnet - Human review still required

- uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4

- uses: actions/setup-go@40f1582b2485089dde7abd97c1529aa768e1baff # v5
- uses: actions/setup-go@7a3fe6cf4cb3a834922a1244abfce67bcef6a0c5 # v6.2.0
Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🚨 Unverified GitHub Action version update in release workflow (high severity)

The actions/setup-go action was updated from v5 (commit 40f1582) to v6.2.0 (commit 7a3fe6c) in the release workflow. This is especially critical as release workflows have access to release secrets and produce user-facing binaries. The commit SHA must be verified against the official repository to prevent supply chain attacks that could compromise distributed msgvault binaries.


Automated security review by Claude 4.5 Sonnet - Human review still required

@github-actions
Copy link

github-actions bot commented Feb 5, 2026

Security Review: 4 High/Medium Issues Found

Claude's automated security review identified potential security concerns. Please review the inline comments.

Note: This is an automated review. False positives are possible. Please review each issue carefully and use your judgment.


Powered by Claude 4.5 Sonnet

@wesm wesm merged commit 486b921 into main Feb 5, 2026
3 checks passed
@dependabot dependabot bot deleted the dependabot/github_actions/actions/setup-go-6.2.0 branch February 5, 2026 22:16
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant