Skip to content

security: [sc-19289] bump vulnerable dependencies - #31

Merged
devkoriel merged 1 commit into
mainfrom
sc-19289-challenger-dep-bumps
Aug 15, 2026
Merged

devkoriel merged 1 commit into
mainfrom
sc-19289-challenger-dep-bumps

Conversation

@devkoriel

Copy link
Copy Markdown
Contributor

Clears all 7 open critical alerts on this repo.

Change From To
golang.org/x/crypto v0.31.0 v0.52.0
go directive 1.24.0 1.25.13
CI go-version matrix 1.24.x 1.25.x
golangci-lint v1.64 v2.12.2
golangci-lint-action (older) v9.3.0, SHA-pinned
.golangci.yml v1 format v2

Why 1.25.13 and not 1.25.0

x/crypto v0.52.0 only requires go >= 1.25.0. I used 1.25.13 because Go 1.25.0 is itself affected by two standard-library advisories found while fixing poa-access-server:

  • GO-2026-5856 — Encrypted Client Hello privacy leak in crypto/tls, fixed in 1.25.12
  • GO-2026-6091 — Javascript regexp context tracking in html/template, fixed in 1.25.13

Taking the bare minimum would have satisfied the dependency while shipping a stdlib with two known advisories. 1.25.13 is the lowest patch clearing both, keeping this within the 1.25 line rather than jumping to 1.26.

The lint chain

golangci-lint v1.64 cannot target a 1.25 module, so it had to move, and moving it pulls two more changes:

  • .golangci.yml was converted with golangci-lint migrate, which succeeded cleanly here (217 lines to 123). Worth noting because the same command refuses to run on infestor's config, which is older still. This one was recent enough to convert automatically, so the conversion is the tool's own output rather than my hand-editing.
  • The action itself is bumped, because the older version invokes the linter with an --out-format flag that v2 removed.

Verification

go build ./..., go vet ./..., go test ./... and golangci-lint run (v2.12.2) all pass locally, the last reporting 0 issues. The baseline on unmodified main was already clean, so unlike most repos in this sweep there was no pre-existing breakage to separate out.

Refs sc-19289.

golang.org/x/crypto v0.31.0 -> v0.52.0, clearing 7 open critical
alerts. x/sys moves with it.

go directive 1.24.0 -> 1.25.13. x/crypto v0.52.0 only requires 1.25.0,
but Go 1.25.0 is itself affected by GO-2026-5856 (crypto/tls, fixed
1.25.12) and GO-2026-6091 (html/template, fixed 1.25.13). 1.25.13 is
the lowest 1.25 patch clearing both, so the bump does not ship a
knowingly vulnerable stdlib.

CI matrix 1.24.x -> 1.25.x to match the directive.

Lint had to move too: v1.64 cannot target a 1.25 module. .golangci.yml
converted to v2 with `golangci-lint migrate`, which succeeded cleanly
here (217 lines -> 123). The action itself is bumped as well, since the
older one passes an out-format flag that v2 removed.

Verified: go build, go vet, go test and golangci-lint v2.12.2 all pass,
the last with 0 issues.
@devkoriel devkoriel self-assigned this Aug 15, 2026
@devkoriel
devkoriel merged commit 532181f into main Aug 15, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant