• Home
  • Features
  • Pricing
  • Docs
  • Announcements
  • Sign In

stacklok / toolhive / 30292044720

27 Jul 2026 06:03PM UTC coverage: 69.609% (+0.008%) from 69.601%
30292044720

push

github

web-flow
Bump klauspost/compress to v1.18.7 (#6041)

GO-2026-5841 (GHSA-259r-337f-4rfw), an out-of-bounds read in
github.com/klauspost/compress/s2, is fixed in v1.18.7. We were on
v1.18.6, so govulncheck fails on main and on every open PR.

The advisory is newly published rather than newly introduced: the same
Go Vulnerability Check passed on PR #6031 at 17:08 and failed at 17:52
on a test-only delta. govulncheck queries the advisory database at run
time, so nothing in the tree changed -- the database did.

Bumped rather than added to the workflow's IGNORED_VULNS. That list is
reserved for advisories with no available fix (GO-2026-5932, openpgp
deprecated-by-design) or an unavoidable toolchain lag (GO-2026-5037/38/39,
pending a setup-go manifest refresh), each with a written justification.
This one has a fixed version, so excluding it would misuse that
mechanism.

The dependency stays indirect: it reaches us via prometheus/client_golang
-> klauspost/compress/zstd. Only zstd is used, not the affected s2
package, so exposure was low -- but the fix is one line, so reachability
does not need arguing.

80600 of 115789 relevant lines covered (69.61%)

86.25 hits per line

Source File
Press 'n' to go to next uncovered line, 'b' for previous

80.56
/pkg/transport/proxy/httpsse/http_proxy.go


Source Not Available

STATUS · Troubleshooting · Open an Issue · Sales · Support · CAREERS · ENTERPRISE · START FREE TRIAL · SCHEDULE DEMO
ANNOUNCEMENTS · TWITTER · TOS & SLA · Supported CI Services · What's a CI service? · Automated Testing

© 2026 Coveralls, Inc