Adds a deterministic reachable-CVE gate: `govulncheck ./...` on every push/PR,
failing on any reachable vulnerability EXCEPT an explicit allow-list of
known-unfixable ones. Today the allow-list holds exactly the two pgx/v4 CVEs
(GO-2026-5004, GO-2026-4518) with no upstream fix (tracked in #4556), so the
gate is green now and turns red the moment a NEW vulnerability appears.
This is the deterministic layer under the `security` loop role: the role
audits with judgment, this blocks known CVEs mechanically. Also adds
`govulncheck` to the loop-triage watch list, so a newly-disclosed CVE that
reddens the gate on master auto-files a fix issue for the loop to bump the dep.
Make `govulncheck` a required status check on master to enforce it.
Verified locally: exit 3 with only the two allow-listed IDs -> gate PASS.
Claude-Session: https://claude.ai/code/session_01CmdEY7pYmV5zzwCjNJ4ykL
Co-authored-by: Claude <noreply@anthropic.com>
govulncheck reported 30 reachable vulnerabilities. Remediation:
- Pin `toolchain go1.25.12` and build CI on Go 1.25 (lint/tests workflows):
clears ~24 Go standard-library CVEs (crypto/tls, crypto/x509, net/http,
html/template, net/url, os, …) that were present under go1.24.7.
- Bump `golang.org/x/net` v0.38.0 -> v0.55.0 and `google.golang.org/grpc`
v1.71.1 -> v1.79.3 (grpc raises the module's Go directive to 1.25).
Result: govulncheck drops from 30 -> 2. The remaining two
(github.com/jackc/pgx/v4, github.com/jackc/pgproto3/v2) have no upstream fix
and require a pgx v5 migration — tracked separately; the govulncheck gate will
follow with those explicitly allow-listed until migrated.
Note: this raises go-micro's minimum Go to 1.25 (forced by the grpc security
bump). Verified: build, go vet, and the ai/agent/flow/store/registry/broker/
wrapper/cmd + grpc/net-dependent packages pass on 1.25.12.
Claude-Session: https://claude.ai/code/session_01CmdEY7pYmV5zzwCjNJ4ykL
Co-authored-by: Claude <noreply@anthropic.com>
The release action always bumped the PATCH, so genuine features (new providers,
`micro loop`, the security role, agent memory, …) all shipped as patches while
the minor stayed frozen at .3 (now on v6.3.18). By semver, backward-compatible
features are MINOR bumps.
Now the bump reflects what shipped, read from the CHANGELOG [Unreleased] section
(kept current by the coherence role):
- `### Added` / `### Changed` -> MINOR (vX.(M+1).0)
- fixes/docs only -> PATCH (vX.M.(P+1))
- breaking (`### Removed` / a "(breaking)" heading / BREAKING) -> skip the
automated release; a MAJOR stays a human decision.
Applied to both go-micro's loop-release.yml and the generic `micro loop`
template (guards a missing CHANGELOG.md -> patch). Verified against the current
CHANGELOG: next release resolves to v6.4.0 (features present), not v6.3.19.
Claude-Session: https://claude.ai/code/session_01CmdEY7pYmV5zzwCjNJ4ykL
Co-authored-by: Claude <noreply@anthropic.com>