Skip to content

fix(deps): upgrade golang.org/x/crypto to v0.56.0 - #41

Open
plural-copilot[bot] wants to merge 1 commit into
mainfrom
agent/remediate-x-crypto-1790261746590
Open

plural-copilot[bot] wants to merge 1 commit into
mainfrom
agent/remediate-x-crypto-1790261746590

Conversation

@plural-copilot

Copy link
Copy Markdown

Summary

  • Select golang.org/x/crypto v0.56.0 in the root Soft Serve module and regenerate go.sum with Go tooling.
  • This remediates CVE-2026-78662 (fixed in v0.56.0), CVE-2026-56855 (fixed in v0.56.0), and CVE-2026-56854 (fixed in v0.55.0).
  • The coherent graph update also selects the versions required by x/crypto v0.56.0 (x/net v0.57.0, x/sys v0.47.0, x/term v0.45.0, x/text v0.41.0, and their required x/sync, x/mod, and x/tools selections). No application source changed.

Production evidence

The affected live Console-service source image is ghcr.io/pluralsh/git-server:v0.12.47 at digest sha256:8916e3db8f0b808c6145b66f5b6966d3003a9672dfc03a506ccf2891339ad2ca. Its affected target binary is usr/bin/soft, with selected vulnerable dependency golang.org/x/crypto v0.53.0.

Inspected build and packaging paths

  • Go modules/workspace: exactly one root go.mod/go.sum; no go.work, go.work.sum, or additional Go modules.
  • Binary entrypoint: cmd/soft/main.go builds soft.
  • Release packaging: .goreleaser.yml defines main: ./cmd/soft and binary_name: soft.
  • Image packaging: Dockerfile copies the built soft artifact to /usr/local/bin/soft.
  • CI/release: inspected .github/workflows/build.yml, coverage.yml, goreleaser.yml, and nightly.yml; the release/nightly workflows delegate release builds to shared GoReleaser workflows. The root has no Makefile/magefile/build scripts; .nfpm scripts are package lifecycle scripts and do not build soft.
  • No alternate source build path for the shipped binary was found.

Files changed

  • go.mod — raises the selected golang.org/x/crypto version and the dependency selections required by its module graph.
  • go.sum — regenerated checksums for that resolved graph.

Validation

Run in golang:1.26.6:

  • go mod verify — passed (all modules verified).
  • go list -m all | grep '^golang.org/x/crypto ' — passed (golang.org/x/crypto v0.56.0).
  • go build -mod=readonly -buildvcs=false -o /tmp/soft ./cmd/soft — passed.
  • /tmp/soft --help — passed.
  • go test -mod=readonly ./cmd/soft/... — passed.

The initial containerized build without -buildvcs=false failed only while reading Git VCS status due to repository ownership; the readonly build above passed with VCS stamping disabled.

Release scope

A rebuilt and published git-server image is required after merge for this remediation to reach a binary image. Promotion is a separate later action. This PR intentionally makes no Console GitOps, deployment manifest, or image-tag changes.

@plural-copilot plural-copilot Bot left a comment

Copy link
Copy Markdown
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This PR was generated by the codex Plural Agent Runtime. Here's some useful information you might want to know to evaluate the ai's perfomance:

Name Details
💬 Prompt Create exactly one remediation PR in this repository for all fixable vulnerabilities described below. Do not modify Console GitOps, deployment manifests, or image tags (those are out of scope and in another repo)....
🔗 Run history View run history

@socket-security

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatedgolang.org/​x/​crypto@​v0.53.0 ⏵ v0.56.074100100100100
Updatedgolang.org/​x/​sync@​v0.21.0 ⏵ v0.22.099 +1100100100100

View full report

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants