Repository navigation
chore(deps): bump golang.org/x/crypto from 0.54.0 to 0.57.0 - #65
dependabot[bot] wants to merge 1 commit into
Conversation
LabelsThe following labels could not be found: Please fix the above issues or remove invalid values from |
|
@dependabot rebase |
9034eb6 to
5bab362
Compare
|
Holding this PR — it needs a deliberate Go 1.26 upgrade first.
To unblock: do one PR that bumps 🤖 Generated with Claude Code |
|
@dependabot rebase |
Bumps [golang.org/x/crypto](https://github.com/golang/crypto) from 0.54.0 to 0.57.0. - [Commits](golang/crypto@v0.54.0...v0.57.0) --- updated-dependencies: - dependency-name: golang.org/x/crypto dependency-version: 0.55.0 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
5bab362 to
b47a244
Compare
|
Superseded: |
|
OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting If you change your mind, just re-open this PR and I'll resolve any conflicts on it. |
Unblocks Dependabot bodaay#65: golang.org/x/crypto v0.57.0 requires Go 1.26. Uses the latest 1.26 patch (1.26.8) rather than 1.26.0, which has 24 known reachable standard-library vulnerabilities. Moves govulncheck to v1.8.0, which needs Go 1.26. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…0 notes - Delete .github/dependabot.yml. Dependencies are now reviewed once a month by a maintainer, following the new docs/MAINTENANCE.md (exact commands for the Go toolchain, Go/JS/Python/.NET deps, pinned Actions, tests, release). govulncheck still runs on every push/PR and weekly. - golang.org/x/crypto 0.54.0 -> 0.57.0 (supersedes Dependabot bodaay#65), with x/net 0.58.0, x/sync 0.23.0, x/sys 0.48.0, x/text 0.42.0. - CHANGELOG v2.3.0: admin console rework, Go 1.26 upgrade note, dependency and CI changes, Dependabot removal. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Bumps golang.org/x/crypto from 0.54.0 to 0.57.0.
Commits
3f62bf1go.mod: update golang.org/x dependencies86efde5ssh: reject unexpected message types on established channelsa6cdac6ssh: drop traffic on undecided channels39dc44essh: don't skip the source-address critical option in CheckCertafebf4cx509roots/fallback/bundle: make subjectsEqual stricter on Go 1.27+89f4e9bx509roots/fallback: update bundle71488c4ssh/knownhosts: compare only public key portions for revocation82adefassh: synchronize unexpected response testc757c98all: upgrade go directive to at least 1.26.0 [generated]593c81assh: correctly ignore pre-banner lines