fix(ci): require the Go release that patches encoding/xml

govulncheck fails the pipeline on GO-2026-6088: encoding/xml decodes
without a recursion depth guard, reachable from excelize's OpenFile,
GetRows and GetSheetList and from buildCRFixups directly. The parser is
fed spreadsheets downloaded over the network by the crawler, so the path
is real.

Raising the go directive to 1.26.6 in all three modules puts the fix
below every build rather than leaving it to whichever patch release the
runner happens to install.

govulncheck is clean on all three modules, and every suite passes on the
new toolchain — including the reader fidelity sweep, which matters here
because buildCRFixups depends on how encoding/xml normalises line endings.
This commit is contained in:
2026-08-14 10:44:26 +07:00
parent 151f2fb2cf
commit 9710524ced
3 changed files with 3 additions and 3 deletions
+1 -1
View File
@@ -1,6 +1,6 @@
module github.com/tiennm99/thptqg/assembler
go 1.26.5
go 1.26.6
require modernc.org/sqlite v1.56.0
+1 -1
View File
@@ -1,6 +1,6 @@
module github.com/tiennm99/thptqg/crawler
go 1.26.5
go 1.26.6
require (
golang.org/x/net v0.58.0
+1 -1
View File
@@ -1,6 +1,6 @@
module github.com/tiennm99/thptqg/parser
go 1.26.5
go 1.26.6
require (
github.com/pbnjay/grate v0.0.0-20231006022435-3f8e65d74a14