Skip to content

build(deps): bump golang.org/x/crypto in /encryption - #266

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/database/postgres/go_modules-24e67ca7f8
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/database/postgres/go_modules-24e67ca7f8

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 24, 2026 •

Copy link
Copy Markdown
Contributor

Bumps golang.org/x/crypto in /encryption from 0.54.0 to 0.57.0.

Updates golang.org/x/crypto from 0.54.0 to 0.57.0

Commits
  • 3f62bf1 go.mod: update golang.org/x dependencies
  • 86efde5 ssh: reject unexpected message types on established channels
  • a6cdac6 ssh: drop traffic on undecided channels
  • 39dc44e ssh: don't skip the source-address critical option in CheckCert
  • afebf4c x509roots/fallback/bundle: make subjectsEqual stricter on Go 1.27+
  • 89f4e9b x509roots/fallback: update bundle
  • 71488c4 ssh/knownhosts: compare only public key portions for revocation
  • 82adefa ssh: synchronize unexpected response test
  • c757c98 all: upgrade go directive to at least 1.26.0 [generated]
  • 593c81a ssh: correctly ignore pre-banner lines
  • Additional commits viewable in compare view

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file go Pull requests that update go code labels Sep 24, 2026
@dependabot
dependabot Bot force-pushed the dependabot/go_modules/database/postgres/go_modules-24e67ca7f8 branch from 6d3f751 to 6740bb5 Compare September 25, 2026 01:03
@dependabot dependabot Bot changed the title Bump golang.org/x/crypto in /encryption build(deps): bump golang.org/x/crypto in /encryption Sep 25, 2026
@dependabot
dependabot Bot force-pushed the dependabot/go_modules/database/postgres/go_modules-24e67ca7f8 branch from 6740bb5 to 1992e9c Compare September 25, 2026 03:05
@lei-wego

Copy link
Copy Markdown
Collaborator

@dependabot rebase

@dependabot
dependabot Bot force-pushed the dependabot/go_modules/database/postgres/go_modules-24e67ca7f8 branch from 1992e9c to 0d8add8 Compare September 25, 2026 05:05

@mike-wego mike-wego left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Holding this: it ships no fix that reaches pkg, and it forces Go 1.26 on consumers.

pkg imports only golang.org/x/crypto/hkdf (encryption/ecies/keys.go). The CVEs fixed in v0.55 and v0.56 (GO-2026-6303, GO-2026-6354, GO-2026-6355) are all in x/crypto/ssh, so none reach pkg.

v0.56+ needs Go 1.26, so this PR raises 15 modules from go 1.25.0 to go 1.26.0. pandora (1.24), flight-offer-aggregator (1.25.2) and partner-success-service (1.25.12) import affected modules and build from Dockerfiles pinned to golang:1.24/1.25 images. Those images set GOTOOLCHAIN=local, so the next pkg bump in those services passes CI (setup-go reads go.mod) and then fails the image build with go: go.mod requires go >= 1.26.0 (running go 1.25.12; GOTOOLCHAIN=local).

Could we close this and take the x/* bumps as a planned Go 1.26 floor, once those three services move their images to 1.26?

@dependabot
dependabot Bot force-pushed the dependabot/go_modules/database/postgres/go_modules-24e67ca7f8 branch 4 times, most recently from df74439 to ea18472 Compare October 2, 2026 03:33
Bumps [golang.org/x/crypto](https://github.com/golang/crypto) in `/encryption` from 0.54.0 to 0.57.0.


Updates `golang.org/x/crypto` from 0.54.0 to 0.57.0
- [Commits](golang/crypto@v0.54.0...v0.57.0)

---
updated-dependencies:
- dependency-name: golang.org/x/crypto
  dependency-version: 0.57.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-dependencies/golang.org/x/crypto
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/go_modules/database/postgres/go_modules-24e67ca7f8 branch from ea18472 to 924d457 Compare October 2, 2026 05:05
@yanyi-wego

Copy link
Copy Markdown
Contributor

@dependabot rebase

@dependabot @github

dependabot Bot commented on behalf of github Oct 2, 2026

Copy link
Copy Markdown
Contributor Author

Looks like this PR is already up-to-date with main! If you'd still like to recreate it from scratch, overwriting any edits, you can request @dependabot recreate.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file go Pull requests that update go code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants