build(deps): bump golang.org/x/crypto in /encryption - #266
dependabot[bot] wants to merge 1 commit into
Conversation
6d3f751 to
6740bb5
Compare
6740bb5 to
1992e9c
Compare
|
@dependabot rebase |
1992e9c to
0d8add8
Compare
There was a problem hiding this comment.
Holding this: it ships no fix that reaches pkg, and it forces Go 1.26 on consumers.
pkg imports only golang.org/x/crypto/hkdf (encryption/ecies/keys.go). The CVEs fixed in v0.55 and v0.56 (GO-2026-6303, GO-2026-6354, GO-2026-6355) are all in x/crypto/ssh, so none reach pkg.
v0.56+ needs Go 1.26, so this PR raises 15 modules from go 1.25.0 to go 1.26.0. pandora (1.24), flight-offer-aggregator (1.25.2) and partner-success-service (1.25.12) import affected modules and build from Dockerfiles pinned to golang:1.24/1.25 images. Those images set GOTOOLCHAIN=local, so the next pkg bump in those services passes CI (setup-go reads go.mod) and then fails the image build with go: go.mod requires go >= 1.26.0 (running go 1.25.12; GOTOOLCHAIN=local).
Could we close this and take the x/* bumps as a planned Go 1.26 floor, once those three services move their images to 1.26?
df74439 to
ea18472
Compare
Bumps [golang.org/x/crypto](https://github.com/golang/crypto) in `/encryption` from 0.54.0 to 0.57.0. Updates `golang.org/x/crypto` from 0.54.0 to 0.57.0 - [Commits](golang/crypto@v0.54.0...v0.57.0) --- updated-dependencies: - dependency-name: golang.org/x/crypto dependency-version: 0.57.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: go-dependencies/golang.org/x/crypto ... Signed-off-by: dependabot[bot] <support@github.com>
ea18472 to
924d457
Compare
|
@dependabot rebase |
|
Looks like this PR is already up-to-date with main! If you'd still like to recreate it from scratch, overwriting any edits, you can request |
Bumps golang.org/x/crypto in
/encryptionfrom 0.54.0 to 0.57.0.Updates
golang.org/x/cryptofrom 0.54.0 to 0.57.0Commits
3f62bf1go.mod: update golang.org/x dependencies86efde5ssh: reject unexpected message types on established channelsa6cdac6ssh: drop traffic on undecided channels39dc44essh: don't skip the source-address critical option in CheckCertafebf4cx509roots/fallback/bundle: make subjectsEqual stricter on Go 1.27+89f4e9bx509roots/fallback: update bundle71488c4ssh/knownhosts: compare only public key portions for revocation82adefassh: synchronize unexpected response testc757c98all: upgrade go directive to at least 1.26.0 [generated]593c81assh: correctly ignore pre-banner lines