security: [sc-19289] bump vulnerable dependencies - #31
Merged
Merged
Conversation
golang.org/x/crypto v0.31.0 -> v0.52.0, clearing 7 open critical alerts. x/sys moves with it. go directive 1.24.0 -> 1.25.13. x/crypto v0.52.0 only requires 1.25.0, but Go 1.25.0 is itself affected by GO-2026-5856 (crypto/tls, fixed 1.25.12) and GO-2026-6091 (html/template, fixed 1.25.13). 1.25.13 is the lowest 1.25 patch clearing both, so the bump does not ship a knowingly vulnerable stdlib. CI matrix 1.24.x -> 1.25.x to match the directive. Lint had to move too: v1.64 cannot target a 1.25 module. .golangci.yml converted to v2 with `golangci-lint migrate`, which succeeded cleanly here (217 lines -> 123). The action itself is bumped as well, since the older one passes an out-format flag that v2 removed. Verified: go build, go vet, go test and golangci-lint v2.12.2 all pass, the last with 0 issues.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Clears all 7 open critical alerts on this repo.
golang.org/x/cryptogo-versionmatrixgolangci-lintgolangci-lint-action.golangci.ymlWhy 1.25.13 and not 1.25.0
x/crypto v0.52.0 only requires
go >= 1.25.0. I used 1.25.13 because Go 1.25.0 is itself affected by two standard-library advisories found while fixing poa-access-server:GO-2026-5856— Encrypted Client Hello privacy leak incrypto/tls, fixed in 1.25.12GO-2026-6091— Javascript regexp context tracking inhtml/template, fixed in 1.25.13Taking the bare minimum would have satisfied the dependency while shipping a stdlib with two known advisories. 1.25.13 is the lowest patch clearing both, keeping this within the 1.25 line rather than jumping to 1.26.
The lint chain
golangci-lint v1.64 cannot target a 1.25 module, so it had to move, and moving it pulls two more changes:
.golangci.ymlwas converted withgolangci-lint migrate, which succeeded cleanly here (217 lines to 123). Worth noting because the same command refuses to run on infestor's config, which is older still. This one was recent enough to convert automatically, so the conversion is the tool's own output rather than my hand-editing.--out-formatflag that v2 removed.Verification
go build ./...,go vet ./...,go test ./...andgolangci-lint run(v2.12.2) all pass locally, the last reporting 0 issues. The baseline on unmodifiedmainwas already clean, so unlike most repos in this sweep there was no pre-existing breakage to separate out.Refs sc-19289.