Skip to content

fix: update Go dependencies to resolve security vulnerabilities - #884

Open
marcusburghardt wants to merge 2 commits into
complytime:mainfrom
marcusburghardt:fix/security-update-go-dependencies
Open

marcusburghardt wants to merge 2 commits into
complytime:mainfrom
marcusburghardt:fix/security-update-go-dependencies

Conversation

@marcusburghardt

Copy link
Copy Markdown
Member

Updates indirect Go dependencies to resolve open OSV vulnerabilities
flagged by OpenSSF Scorecard (code scanning alert #26).

Changes

Commit 1: golang.org/x/crypto v0.55.0 → v0.56.0

  • Resolves GO-2026-6354 (CVE-2026-78662): SSH DoS via deadlocked undecided channel
  • Resolves GO-2026-6355 (CVE-2026-56855): SSH DoS via deadlocked established channel

Commit 2: golang.org/x/mod v0.39.0 → v0.40.0

  • Resolves GO-2026-6179 (CVE-2026-56865): sumdb tlog tile verification bypass
  • Resolves GO-2026-6180 (CVE-2026-56864): unauthenticated hashes in sumdb Lookup

Note

GO-2026-5932 (golang.org/x/crypto/openpgp unmaintained) will persist — the
project does not use the openpgp subpackage but the advisory covers the entire
module with no fix version.

Validation

  • go mod verify: all modules verified
  • go build ./...: passes
  • make lint: 0 issues
  • make vet: passes
  • Unit tests: no regressions (pre-existing environment-specific failures unchanged)

…abilities

Bumps golang.org/x/crypto from v0.55.0 to v0.56.0 to resolve SSH DoS
vulnerabilities in the ssh subpackage.

See: https://osv.dev/GO-2026-6354
See: https://osv.dev/GO-2026-6355

Assisted-by: OpenCode (claude-opus-4-6)
Signed-off-by: Marcus Burghardt <maburgha@redhat.com>
…lities

Bumps golang.org/x/mod from v0.39.0 to v0.40.0 to resolve sumdb
verification bypass and unauthenticated hash vulnerabilities.

See: https://osv.dev/GO-2026-6179
See: https://osv.dev/GO-2026-6180

Assisted-by: OpenCode (claude-opus-4-6)
Signed-off-by: Marcus Burghardt <maburgha@redhat.com>
@marcusburghardt
marcusburghardt force-pushed the fix/security-update-go-dependencies branch from 8f1b9bd to a14a8d8 Compare September 29, 2026 08:54

@gxmiranda gxmiranda left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

Status: Ready for Review 👀

Development

Successfully merging this pull request may close these issues.

2 participants