Skip to content

fix(deps): upgrade golang.org/x/crypto to v0.56.0 - #40

Open
plural-copilot[bot] wants to merge 1 commit into
mainfrom
agent/crypto-cve-remediation-1790258125338
Open

plural-copilot[bot] wants to merge 1 commit into
mainfrom
agent/crypto-cve-remediation-1790258125338

Conversation

@plural-copilot

Copy link
Copy Markdown

Summary

  • Upgrade golang.org/x/crypto from installed vulnerable v0.53.0 to v0.56.0 in the git-server source used to rebuild ghcr.io/pluralsh/git-server:v0.12.47.
  • Reconcile the compatible golang.org/x module graph and checksums required by the upgrade.
  • Changed files: go.mod (dependency versions) and go.sum (resolved checksums) only.

Vulnerability remediation

v0.56.0 fixes the following findings present in v0.53.0:

  • CVE-2026-78662: an SSH peer could flood requests on an undecided channel and deadlock the connection.
  • CVE-2026-56855: crafted messages on an established SSH channel could deadlock the connection.
  • CVE-2026-56854: source-address restrictions returned from several non-public-key SSH authentication callbacks were not enforced.

GO-2026-5932 is intentionally not addressed: the scanner reports no fixed version for that finding.

Validation

Ran with golang:1.26.6:

  • go mod verify — passed.
  • GOFLAGS=-buildvcs=false go build ./cmd/soft — passed. The flag is needed because VCS stamping cannot read status in the mounted test container.
  • GOFLAGS=-buildvcs=false go test $(go list ./... | grep -v "/testscript$") — passed for all non-testscript packages.
  • go test ./pkg/config/... ./pkg/ssh/... — passed.
  • go test ./... — attempted; non-testscript packages passed, but testscript failed because its internal build enables VCS stamping and cannot obtain VCS status in the container.

Deployment

Deployment promotion/image-tag changes await publication of the rebuilt image. No Plural service tag or GitOps deployment change is included in this PR.

@plural-copilot plural-copilot Bot left a comment

Copy link
Copy Markdown
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This PR was generated by the codex Plural Agent Runtime. Here's some useful information you might want to know to evaluate the ai's perfomance:

Name Details
💬 Prompt Create one focused remediation PR for the deployed Console service git-server image source. Do not make any GitOps image-tag/deployment changes....
🔗 Run history View run history

@socket-security

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatedgolang.org/​x/​crypto@​v0.53.0 ⏵ v0.56.074100100100100
Updatedgolang.org/​x/​sync@​v0.21.0 ⏵ v0.22.099 +1100100100100

View full report

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants