This release includes 3 security fixes for security teams reviewing exposed deployments.
Published 1mo
Deployment Automation
✓ No known CVEs patched
This release patches 3 known CVEs
Topics
api
auto-update
cross-platform
desktop-app
electron
electron-updater
+8 more
go
mongodb
s3
self-hosted
software-updates
tauri
tuf
update-server
Affected surfaces
deps
Summary
AI summaryUpdated Go runtime and dependencies to address stdlib and crypto CVE-2026 security issues.
Full changelog
Security
- Updated Go to 1.26.3 (
go.mod,Dockerfile, CI workflow) to fix stdlib CVE-2026-* issues. - Updated
golang.org/x/cryptoto 0.52.0 to fix CVE-2026-* issues. - Updated
golang.org/x/netto 0.55.0 to fix CVE-2026-* issues.
Security Fixes
- dep: CVE-2026-* — updated Go stdlib via go.mod, Dockerfile, and CI to version 1.26.3
- dep: CVE-2026-* — upgraded golang.org/x/crypto to 0.52.0
- dep: CVE-2026-* — upgraded golang.org/x/net to 0.55.0
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About FaynoSync
Self-hosted Dynamic Update Server with statistics, supporting multiple updaters. Flexible features for seamless app updates and insights.
Beta — feedback welcome: [email protected]