Skip to content

RED-193207 - bump hashicorp/go-plugin to v1.7.0#22

Open
oshribr wants to merge 2 commits intomainfrom
oshribr-vault-plugin-versions-RED-193207
Open

RED-193207 - bump hashicorp/go-plugin to v1.7.0#22
oshribr wants to merge 2 commits intomainfrom
oshribr-vault-plugin-versions-RED-193207

Conversation

@oshribr
Copy link
Copy Markdown

@oshribr oshribr commented Apr 23, 2026

Raises hashicorp/go-plugin from v1.0.1 to v1.7.0 so the plugin binary supports the containerized-plugin handshake required by Vault 1.15+ (v1.20+ent in customer environments). MVS pulled transitive deps
forward: go-hclog v0.14.1 -> v1.6.3, yamux -> v0.1.2, oklog/run ->
v1.1.0, x/{crypto,net,sys,text}, protobuf, fatih/color.

Bumps the module's go directive to 1.26 and pins Go 1.26.2 in both the CI and release workflows.

Raises hashicorp/go-plugin from v1.0.1 to v1.7.0 so the plugin binary
supports the containerized-plugin handshake required by Vault 1.15+
(v1.20+ent in customer environments). MVS pulled transitive deps
forward: go-hclog v0.14.1 -> v1.6.3, yamux -> v0.1.2, oklog/run ->
v1.1.0, x/{crypto,net,sys,text}, protobuf, fatih/color.

Bumps the module's go directive to 1.26 and pins Go 1.26.2 in both the
CI and release workflows.
@jit-ci
Copy link
Copy Markdown

jit-ci Bot commented Apr 23, 2026

Hi, I’m Jit, a friendly security platform designed to help developers build secure applications from day zero with an MVS (Minimal viable security) mindset.

In case there are security findings, they will be communicated to you as a comment inside the PR.

Hope you’ll enjoy using Jit.

Questions? Comments? Want to learn more? Get in touch with us.

@jit-ci
Copy link
Copy Markdown

jit-ci Bot commented Apr 23, 2026

🛡️ Jit Security Scan Results

CRITICAL HIGH MEDIUM

✅ No security findings were detected in this PR


Security scan by Jit

Modernizes the Go module/build cache action to the current major. v2
is on an archived Node 12 runtime; v5 runs on Node 20 which matches
the runner's other actions.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant