What would you like to be added?
Go 1.26.1 and 1.25.8 were released yesterday; they include fixes for CVEs: CVE-2026-27137, CVE-2026-27138, CVE-2026-27142, CVE-2026-25679 and CVE-2026-27139. According to our Dependency management documentation, we want to stay on the latest patch version. This means updating our stable branches to 1.25.8 and main to 1.26.1.
Progress track:
Please review the previous issues and their corresponding pull requests, such as #21364 and #21254.
Why is this needed?
To keep the project up to date with the latest Go versions. And address CVE-2026-27137, CVE-2026-27138, CVE-2026-27142, CVE-2026-25679 and CVE-2026-27139.
What would you like to be added?
Go 1.26.1 and 1.25.8 were released yesterday; they include fixes for CVEs: CVE-2026-27137, CVE-2026-27138, CVE-2026-27142, CVE-2026-25679 and CVE-2026-27139. According to our Dependency management documentation, we want to stay on the latest patch version. This means updating our stable branches to 1.25.8 and
mainto 1.26.1.Progress track:
main: go v1.26.1 - Bump Go to 1.26.1 #21459release-3.6: go v1.25.8 - [release-3.6] Bump Go to 1.25.8 #21463release-3.5: go v1.25.8 - [release-3.5] Bump Go to 1.25.8 #21462release-3.4: go v1.25.8 - [release-3.4] Bump Go to 1.25.8 #21461CHANGELOG- Changelog: Add entries for 3.4.42, 3.5.28, 3.6.9 releases #21511main: go v1.25.8 - Bump go to 1.25.8 bbolt#1156release-1.4: v1.25.8 - [release-1.4] Bump go to 1.25.8 bbolt#1157release-1.3: v1.25.8 - [release-1.3] Bump go to 1.25.8 bbolt#1158main: go v1.25.8 - Bump go to 1.25.8 raft#395release-3.6: go v1.25.8 - [release-3.6] Bump go to 1.25.8 raft#396etcd-io/gofailmaster: go v1.25.8 - Bump golang version to 1.25.8 gofail#144etcd-io/augermain: go v1.26.1 - Bump go to 1.26.1 auger#445etcd-io/etcd-operator: go v1.26.1 - Bump golang version to 1.26.1 etcd-operator#306etcd-io/protodoc: go v1.25.8 - Bump go version to 1.25.8 protodoc#32Please review the previous issues and their corresponding pull requests, such as #21364 and #21254.
Why is this needed?
To keep the project up to date with the latest Go versions. And address CVE-2026-27137, CVE-2026-27138, CVE-2026-27142, CVE-2026-25679 and CVE-2026-27139.