Skip to content

fix(deps): vuln golang.org/x/crypto (minor → v0.57.0) [internal/go.mod] - #163

Closed
gh-worker-campaigns-3e9aa4[bot] wants to merge 1 commit into
mainfrom
engraver-auto-version-upgrade/minorpatch/go/internal/2-1790577314
Closed

gh-worker-campaigns-3e9aa4[bot] wants to merge 1 commit into
mainfrom
engraver-auto-version-upgrade/minorpatch/go/internal/2-1790577314

Conversation

@gh-worker-campaigns-3e9aa4

Copy link
Copy Markdown

Summary: High-severity security update — 1 package upgraded (MINOR changes included)

Manifests changed:

  • internal/go.mod (go)

✅ Action Required: Please review the changes below. If they look good, approve and merge this PR.


Updates

Package From To Type Dep Type Vulnerabilities Fixed
golang.org/x/crypto v0.55.0 v0.57.0 minor Transitive 4 HIGH, 1 UNKNOWN

Security Details

🚨 Critical & High Severity (4 fixed)
Package CVE Severity Summary Unsafe Version Fixed In Case
golang.org/x/crypto GO-2026-6355 high Prevent DoS on deadlocked established channel in golang.org/x/crypto/ssh v0.55.0 0.56.0 -
golang.org/x/crypto CVE-2026-56855 high Prevent DoS on deadlocked established channel in golang.org/x/crypto/ssh v0.55.0 - -
golang.org/x/crypto GO-2026-6354 high Prevent DoS on deadlocked undecided channel in golang.org/x/crypto/ssh v0.55.0 0.56.0 -
golang.org/x/crypto CVE-2026-78662 high Prevent DoS on deadlocked undecided channel in golang.org/x/crypto/ssh v0.55.0 - -
ℹ️ Other Vulnerabilities (1)
Package CVE Severity Summary Unsafe Version Fixed In Case
golang.org/x/crypto GO-2026-5932 unknown The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues v0.55.0 - -

Review Checklist

Standard review:

  • Review changes for compatibility with your code
  • Check for breaking changes in release notes
  • Run tests locally or wait for CI
  • Approve and merge this PR

Update Mode: all_vulns

🤖 Generated by DataDog Automated Dependency Management System

Co-authored-by: gh-worker-campaigns-3e9aa4[bot] <244854796+gh-worker-campaigns-3e9aa4[bot]@users.noreply.github.com>
@gh-worker-campaigns-3e9aa4

Copy link
Copy Markdown
Author

Auto-rebase complete

Branch is up to date with main — rebased onto 00e9f36.


Auto-Rebase · Add no-auto-rebase to opt out

@dd-octo-sts-0c48d7
dd-octo-sts-0c48d7 Bot force-pushed the engraver-auto-version-upgrade/minorpatch/go/internal/2-1790577314 branch from 353e867 to 8243f57 Compare October 6, 2026 12:19
@hferentschik

Copy link
Copy Markdown
Collaborator

Closing this PR. The Go version bump in go.work is problematic.

We intentionally keep the codec module on the lowest Go version possible so that external users on older Go versions can import it without being forced to upgrade. The go.work should use the minimum Go version across all modules, not the maximum.

If a dependency requires a newer Go version, only the affected module should bump — the codec module and go.work should stay on go 1.25.6. A follow-up PR should be opened with that constraint in mind.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant