[go] update toolchain go 1.26.4 -> 1.26.5

https://groups.google.com/g/golang-announce/c/OrmQE_Yp5Sc

Vulnerability #1: GO-2026-5856
    Invoking Encrypted Client Hello privacy leak in crypto/tls
  More info: https://pkg.go.dev/vuln/GO-2026-5856
  Standard library
    Found in: crypto/tls@go1.26.4
    Fixed in: crypto/tls@go1.26.5
    Example traces found:
      #1: reapi/proxy.go:86:24: reapi.Serve calls grpc.Server.Serve, which eventually calls tls.Conn.Handshake
      #2: build/statusz.go:73:15: build.NewStatuszServer calls http.Server.Serve, which eventually calls tls.Conn.HandshakeContext
      #3: hashfs/fs.go:854:22: hashfs.HashFS.ReadFile calls io.ReadFull, which eventually calls tls.Conn.Read
      #4: o11y/trace/trace.go:593:20: trace.Tracer.Close calls bufio.Writer.Flush, which calls tls.Conn.Write
      #5: subcmd/version/version.go:262:36: version.Command.sisoCommit calls http.Client.Do, which eventually calls tls.Dialer.DialContext

Change-Id: I2ceab1efec11ee980ac8d3e2b9506d00baa8583d
Reviewed-on: https://chromium-review.googlesource.com/c/build/+/8082661
Auto-Submit: Fumitoshi Ukai <ukai@google.com>
Commit-Queue: Fumitoshi Ukai <ukai@google.com>
Reviewed-by: Richard Wang <richardwa@google.com>
Reviewed-by: Philipp Wollermann <philwo@google.com>
8 files changed
tree: dfdbcda8bea21b5c65a3e9ac88fb4bea9f3a801a
  1. bench/
  2. gong/
  3. hashigo/
  4. infra/
  5. kajiya/
  6. kzipinfo/
  7. remote-apis/
  8. runmc/
  9. siso/
  10. .gitignore
  11. .golangci.yml
  12. .style.yapf
  13. BUILD_OWNERS
  14. BUILD_TEAM_OWNERS
  15. CONTRIBUTING.md
  16. LICENSE
  17. OWNERS
  18. PRESUBMIT.py
  19. README.md
  20. WATCHLISTS
README.md

build.git repository

This repository contains tools developed and owned by the Chrome Build Team.

Quick start

The steps for getting the code are:

  1. Install depot_tools
  2. Run git clone https://chromium.googlesource.com/build

We use the standard Go module workflow to work on our projects.

Links