Skip to content

chore(deps): bump golang.org/x/crypto from 0.54.0 to 0.57.0 - #65

Closed
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/go_modules/golang.org/x/crypto-0.55.0
Closed

dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/go_modules/golang.org/x/crypto-0.55.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 16, 2026 •

Copy link
Copy Markdown
Contributor

Bumps golang.org/x/crypto from 0.54.0 to 0.57.0.

Commits
  • 3f62bf1 go.mod: update golang.org/x dependencies
  • 86efde5 ssh: reject unexpected message types on established channels
  • a6cdac6 ssh: drop traffic on undecided channels
  • 39dc44e ssh: don't skip the source-address critical option in CheckCert
  • afebf4c x509roots/fallback/bundle: make subjectsEqual stricter on Go 1.27+
  • 89f4e9b x509roots/fallback: update bundle
  • 71488c4 ssh/knownhosts: compare only public key portions for revocation
  • 82adefa ssh: synchronize unexpected response test
  • c757c98 all: upgrade go directive to at least 1.26.0 [generated]
  • 593c81a ssh: correctly ignore pre-banner lines
  • Additional commits viewable in compare view

@dependabot @github

dependabot Bot commented on behalf of github Aug 16, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: dependencies, go. Please create them before Dependabot can add them to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@bodaay

bodaay commented Oct 5, 2026

Copy link
Copy Markdown
Owner

@dependabot rebase

@dependabot dependabot Bot changed the title chore(deps): bump golang.org/x/crypto from 0.52.0 to 0.55.0 chore(deps): bump golang.org/x/crypto from 0.52.0 to 0.57.0 Oct 5, 2026
@dependabot
dependabot Bot force-pushed the dependabot/go_modules/golang.org/x/crypto-0.55.0 branch from 9034eb6 to 5bab362 Compare October 5, 2026 08:34
@bodaay

bodaay commented Oct 5, 2026

Copy link
Copy Markdown
Owner

Holding this PR — it needs a deliberate Go 1.26 upgrade first.

golang.org/x/crypto v0.57.0 requires Go 1.26, so this PR also changes go.mod from go 1.25.14 to go 1.26.0. That has three consequences:

  • Docker Build fails. The Dockerfile builds with golang:1.25-alpine, so go mod download cannot satisfy go 1.26.0.
  • govulncheck fails. Go 1.26.0 itself has 24 known standard-library vulnerabilities that our code reaches. The directive should be the latest 1.26.x patch, not .0.
  • The scanner pin must move too. govulncheck is pinned to v1.7.0 because v1.8.0+ needs Go 1.26. It should move to the latest version as part of the upgrade.

To unblock: do one PR that bumps go.mod to the latest 1.26.x, the Dockerfile builder to golang:1.26-alpine, and govulncheck to the latest version. Then @dependabot rebase this one.

🤖 Generated with Claude Code

@bodaay bodaay mentioned this pull request Oct 5, 2026
@bodaay

bodaay commented Oct 5, 2026

Copy link
Copy Markdown
Owner

@dependabot rebase

Bumps [golang.org/x/crypto](https://github.com/golang/crypto) from 0.54.0 to 0.57.0.
- [Commits](golang/crypto@v0.54.0...v0.57.0)

---
updated-dependencies:
- dependency-name: golang.org/x/crypto
  dependency-version: 0.55.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot changed the title chore(deps): bump golang.org/x/crypto from 0.52.0 to 0.57.0 chore(deps): bump golang.org/x/crypto from 0.54.0 to 0.57.0 Oct 5, 2026
@dependabot
dependabot Bot force-pushed the dependabot/go_modules/golang.org/x/crypto-0.55.0 branch from 5bab362 to b47a244 Compare October 5, 2026 10:06
@bodaay

bodaay commented Oct 5, 2026

Copy link
Copy Markdown
Owner

Superseded: golang.org/x/crypto 0.57.0 is applied in the PR that also removes Dependabot (the project now does monthly manual dependency checks — see docs/MAINTENANCE.md).

@bodaay bodaay closed this Oct 5, 2026
@dependabot @github

dependabot Bot commented on behalf of github Oct 5, 2026

Copy link
Copy Markdown
Contributor Author

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@dependabot
dependabot Bot deleted the dependabot/go_modules/golang.org/x/crypto-0.55.0 branch October 5, 2026 10:14
alghanim pushed a commit to alghanim/SimpleAuth that referenced this pull request Oct 9, 2026
Unblocks Dependabot bodaay#65: golang.org/x/crypto v0.57.0 requires Go 1.26.
Uses the latest 1.26 patch (1.26.8) rather than 1.26.0, which has 24
known reachable standard-library vulnerabilities. Moves govulncheck to
v1.8.0, which needs Go 1.26.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
alghanim pushed a commit to alghanim/SimpleAuth that referenced this pull request Oct 9, 2026
…0 notes

- Delete .github/dependabot.yml. Dependencies are now reviewed once a month
  by a maintainer, following the new docs/MAINTENANCE.md (exact commands for
  the Go toolchain, Go/JS/Python/.NET deps, pinned Actions, tests, release).
  govulncheck still runs on every push/PR and weekly.
- golang.org/x/crypto 0.54.0 -> 0.57.0 (supersedes Dependabot bodaay#65), with
  x/net 0.58.0, x/sync 0.23.0, x/sys 0.48.0, x/text 0.42.0.
- CHANGELOG v2.3.0: admin console rework, Go 1.26 upgrade note, dependency
  and CI changes, Dependabot removal.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant