chore(deps): update module golang.org/x/crypto to v0.56.0 [security] - #426
Conversation
ℹ Artifact update noticeFile name: tools/readme/go.modIn order to perform the update(s) described in the table above, Renovate ran the
Details:
|
🛑 Changes requested — automated reviewThe patch creates a CI/development toolchain mismatch and updates published chart dependencies without the required chart-version cascade. |
NumaryBot
left a comment
There was a problem hiding this comment.
NumaryBot posted 1 new inline finding.
Summary: #426 (comment)
| module github.com/formancehq/helm/tools/readme | ||
|
|
||
| go 1.25.0 | ||
| go 1.26.0 |
There was a problem hiding this comment.
🔴 [blocker] Keep the declared Go version aligned with the Nix toolchain
Raising this module to Go 1.26 leaves flake.nix pinned to Go 1.25, although nix develop --command just pc runs go mod tidy and go run in this module. Environments with toolchain auto-download disabled will fail immediately, while others unexpectedly download an undeclared toolchain; update the Nix goVersion alongside this directive.
|
This PR is a Renovate security bump of Standards
No other confirmed material finding on this axis. The change is a mechanical, tooling-generated dependency bump confined to SpecThis axis has no confirmed material finding. The diff faithfully implements the PR body: Reviewed independently by GLM (glm-5.3-flash) and DeepSeek (deepseek-v4-pro-0813) via Shipfox; verified and synthesized by GLM. |
4a8fb33 to
60b1f68
Compare
|
This Renovate PR delivers the declared Standards
SpecThe PR body (Renovate) declares exactly one update:
Reviewed independently by GLM (glm-5.3-flash) and DeepSeek (deepseek-v4-pro-0813) via Shipfox; verified and synthesized by GLM. |
NumaryBot
left a comment
There was a problem hiding this comment.
NumaryBot posted 1 new inline finding.
Summary: #426 (comment)
| @@ -4,6 +4,6 @@ dependencies: | |||
| version: 1.6.0 | |||
| - name: postgresql | |||
| repository: oci://registry-1.docker.io/bitnamicharts | |||
There was a problem hiding this comment.
🔴 [blocker] Version the charts whose locks changed
The PostgreSQL lock update changes the packaged dependencies of console-v3, membership, portal, and formance, but none of their chart versions—or the cloudprem/formance cascade—were bumped, so existing-version consumers may never receive the new locks. Bump every affected chart through formance, or remove these unrelated lock changes, as required by CLAUDE.md lines 36–40.
|
This PR correctly bumps Standards
The postgresql hunk repeated across four lock files was checked and suppressed: SpecSpec source: the Renovate PR body, whose update table lists exactly one row — (a) Missing or partial requirements — none. The declared update is fully implemented: (b) Behaviour not asked for (scope creep):
(c) Implemented but wrong — none. The declared bump is internally consistent across Reviewed independently by GLM (glm-5.3-flash) and DeepSeek (deepseek-v4-pro-0813) via Shipfox; verified and synthesized by GLM. |
This PR contains the following updates:
v0.55.0->v0.56.0Warning
Some dependencies could not be looked up. Check the warning logs for more information.
Prevent DoS on deadlocked undecided channel in golang.org/x/crypto/ssh
CVE-2026-78662 / GO-2026-6354
More information
Details
Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection.
Now, we add an atomic established state, set when a channel becomes usable. Until such a time, handlePacket drops every packet other than the open confirmation/failure, without blocking and without tearing down the connection.
Severity
Unknown
References
This data is provided by OSV and the Go Vulnerability Database (CC-BY 4.0).
Prevent DoS on deadlocked established channel in golang.org/x/crypto/ssh
CVE-2026-56855 / GO-2026-6355
More information
Details
Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection.
Now, we handle all RFC 4254 channel messages; global requests are handled explicitly. Then, treat all other messages as a protocol error and tear the connection down instead of buffering and blocking.
Severity
Unknown
References
This data is provided by OSV and the Go Vulnerability Database (CC-BY 4.0).
Configuration
📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR has been generated by Renovate Bot.