Skip to content

fix(deps): remediate golang.org/x/crypto CVEs - #43

Open
plural-copilot[bot] wants to merge 1 commit into
mainfrom
agent/crypto-cve-remediation-1790353532790
Open

plural-copilot[bot] wants to merge 1 commit into
mainfrom
agent/crypto-cve-remediation-1790353532790

Conversation

@plural-copilot

Copy link
Copy Markdown

Summary

  • Updates the direct golang.org/x/crypto requirement from v0.53.0 to v0.56.0.
  • Regenerates the minimal coherent Go module graph and checksums required by that release (x/net, x/sync, x/sys, x/text, x/tools, and related indirect metadata).
  • go list -m all confirms the resolved golang.org/x/crypto version is v0.56.0.

Security scope

  • Remediates CVE-2026-78662 and CVE-2026-56855, whose stated fixed release is v0.56.0.
  • Also satisfies CVE-2026-56854, whose stated fixed release is v0.55.0.
  • GO-2026-5932 is intentionally not remediated by a speculative change: it has no fixed version, and this PR does not claim that the x/crypto upgrade fixes it.
  • CVE-2026-93990 (libexpat) is a runtime OS-package finding handled separately in the Console image-build repository; it is out of scope for this application-source/module change.

Validation

Run in a Docker golang:1.26.6 environment:

go mod verify
go mod tidy -diff
go list -m all | grep '^golang.org/x/crypto '
go test -count=1 ./pkg/backend ./pkg/ssh ./pkg/sshutils

All passed; the resolved-module check printed golang.org/x/crypto v0.56.0.

Deployment follow-up

No GitOps, deployment manifest, or image-tag promotion changes are included. The Console image pipeline must rebuild and publish git-server from this source commit before a later image promotion/deployment.

@plural-copilot plural-copilot Bot left a comment

Copy link
Copy Markdown
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This PR was generated by the codex Plural Agent Runtime. Here's some useful information you might want to know to evaluate the ai's perfomance:

Name Details
💬 Prompt Create one focused remediation PR in this repository for the application source of the live git-server image ghcr.io/pluralsh/git-server:v0.12.47 (currently scanned digest sha256:8916e3db8f0b808c6145b66f5b6966d3003a9672dfc03a506ccf2891339ad2ca)....
🔗 Run history View run history

@socket-security

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatedgolang.org/​x/​crypto@​v0.53.0 ⏵ v0.56.074100100100100
Updatedgolang.org/​x/​sync@​v0.21.0 ⏵ v0.22.099 +1100100100100

View full report

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants