Skip to content

Bump golang.org/x/crypto to v0.54.0 to fix critical/high Dependabot a… - #17

Open
ashraful88 wants to merge 1 commit into
masterfrom
fix/dependabot-x-crypto-critical-high
Open

ashraful88 wants to merge 1 commit into
masterfrom
fix/dependabot-x-crypto-critical-high

Conversation

@ashraful88

Copy link
Copy Markdown
Collaborator

…lerts

Resolves SSH package vulnerabilities (auth bypass via unenforced revoked status, PublicKeyCallback/VerifiedPublicKeyCallback authorization bypass, key/agent-forwarding constraint enforcement gaps, FIDO/U2F presence check bypass, client deadlock, and DoS via slow handshakes or large channel writes). Pulls in required transitive bumps to x/net, x/sys, and x/text, and raises the go directive to 1.25.0 per x/crypto's own module requirement.

…lerts

Resolves SSH package vulnerabilities (auth bypass via unenforced revoked
status, PublicKeyCallback/VerifiedPublicKeyCallback authorization bypass,
key/agent-forwarding constraint enforcement gaps, FIDO/U2F presence check
bypass, client deadlock, and DoS via slow handshakes or large channel
writes). Pulls in required transitive bumps to x/net, x/sys, and x/text,
and raises the go directive to 1.25.0 per x/crypto's own module
requirement.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR updates Go module dependencies to address Dependabot-reported security issues in golang.org/x/crypto (and related x/* modules), and updates module metadata accordingly.

Changes:

  • Bump golang.org/x/crypto to v0.54.0 (with transitive bumps to x/net, x/sys, x/text).
  • Raise the module go directive from 1.19 to 1.25.0.
  • Refresh go.sum to match the updated dependency graph.

Reviewed changes

Copilot reviewed 1 out of 2 changed files in this pull request and generated 1 comment.

File Description
go.mod Updates the module Go version directive and bumps indirect golang.org/x/* dependencies.
go.sum Updates checksums to reflect the dependency version bumps and go.mod hash entries.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment thread go.mod
module github.com/carousell/gin-prometheus-middleware

go 1.19
go 1.25.0
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants