Skip to content

chore(deps): update module golang.org/x/crypto to v0.56.0 [security] - #426

Merged
flemzord merged 2 commits into
mainfrom
renovate/security
Sep 10, 2026
Merged

flemzord merged 2 commits into
mainfrom
renovate/security

Conversation

@NumaryBot

@NumaryBot NumaryBot commented Sep 5, 2026 •

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Type Update Change
golang.org/x/crypto indirect minor v0.55.0 -> v0.56.0

Warning

Some dependencies could not be looked up. Check the warning logs for more information.


Prevent DoS on deadlocked undecided channel in golang.org/x/crypto/ssh

CVE-2026-78662 / GO-2026-6354

More information

Details

Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection.

Now, we add an atomic established state, set when a channel becomes usable. Until such a time, handlePacket drops every packet other than the open confirmation/failure, without blocking and without tearing down the connection.

Severity

Unknown

References

This data is provided by OSV and the Go Vulnerability Database (CC-BY 4.0).


Prevent DoS on deadlocked established channel in golang.org/x/crypto/ssh

CVE-2026-56855 / GO-2026-6355

More information

Details

Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection.

Now, we handle all RFC 4254 channel messages; global requests are handled explicitly. Then, treat all other messages as a protocol error and tear the connection down instead of buffering and blocking.

Severity

Unknown

References

This data is provided by OSV and the Go Vulnerability Database (CC-BY 4.0).


Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Enabled.

♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Renovate Bot.

@NumaryBot
NumaryBot requested a review from a team as a code owner September 5, 2026 02:36
@NumaryBot
NumaryBot enabled auto-merge (squash) September 5, 2026 02:36
@NumaryBot

Copy link
Copy Markdown
Contributor Author

ℹ Artifact update notice

File name: tools/readme/go.mod

In order to perform the update(s) described in the table above, Renovate ran the go get command, which resulted in the following additional change(s):

  • The go directive was updated for compatibility reasons

Details:

Package Change
go 1.25.0 -> 1.26.0

@NumaryBot

NumaryBot commented Sep 5, 2026 •

Copy link
Copy Markdown
Contributor Author

🛑 Changes requested — automated review

The patch creates a CI/development toolchain mismatch and updates published chart dependencies without the required chart-version cascade.

@NumaryBot NumaryBot left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

NumaryBot posted 1 new inline finding.

Summary: #426 (comment)

Comment thread tools/readme/go.mod
module github.com/formancehq/helm/tools/readme

go 1.25.0
go 1.26.0

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔴 [blocker] Keep the declared Go version aligned with the Nix toolchain

Raising this module to Go 1.26 leaves flake.nix pinned to Go 1.25, although nix develop --command just pc runs go mod tidy and go run in this module. Environments with toolchain auto-download disabled will fail immediately, while others unexpectedly download an undeclared toolchain; update the Nix goVersion alongside this directive.

@shipfox-ai

shipfox-ai Bot commented Sep 5, 2026

Copy link
Copy Markdown

This PR is a Renovate security bump of golang.org/x/crypto from v0.55.0 to v0.56.0 in tools/readme (the repo's only Go module), plus the declared collateral go directive bump 1.25.0 → 1.26.0. The dependency update itself is complete and internally consistent, and the diff touches exactly the two declared files. However, the go 1.26.0 directive is out of sync with the repository's pinned Go toolchain: flake.nix still pins Go 1.25, which every developer shell and the CI pre-commit pipeline use. Recommendation: approve with comments — the change is safe to merge from a dependency standpoint, but the toolchain pin in flake.nix should be raised to 26 (or the directive kept at 1.25.0) in a follow-up so the mandatory just pre-commit workflow runs hermetically again.

Standards

  1. Go toolchain mismatch: tools/readme/go.mod:3 declares go 1.26.0 while flake.nix pins Go 1.25 (moderate, environment/CI impact). flake.nix:15 sets goVersion = 25 and flake.nix:39 overlays go = final."go_1_${toString goVersion}", so both the Nix dev shell and CI (.github/workflows/pull_request.yml, Dirty job: nix develop --impure --command just pc) provide Go 1.25. The Justfile targets that run inside this module — tidy (go mod tidy) and template-readme (go run ./), both prerequisites of the mandatory pre-commit — now operate on a module demanding go >= 1.26.0. With the default GOTOOLCHAIN=auto, every pre-commit run silently downloads an undeclared, unpinned Go 1.26 toolchain (breaking hermetic reproducibility and adding a network dependency to CI); with GOTOOLCHAIN=local or without network access, go mod tidy / go run ./ fail outright. Fix by bumping goVersion to 26 in flake.nix in the same change (or keeping the directive at 1.25.0 if Go 1.26 is not intended), then re-running just pc.

No other confirmed material finding on this axis. The change is a mechanical, tooling-generated dependency bump confined to go.mod/go.sum; commit message matches the repo's conventional-commit style, and no documented chart/cascade rules apply.

Spec

This axis has no confirmed material finding. The diff faithfully implements the PR body: tools/readme/go.mod:23 declares golang.org/x/crypto v0.56.0 // indirect, tools/readme/go.sum:49-50 carries the matching h1: and /go.mod checksums, and every v0.55.0 reference is removed — verified against the actual files, with no stale entries and no other Go module in the repo left behind. The only other change, the go directive 1.25.0 → 1.26.0, is explicitly declared in the Renovate artifact-update notice, so it is authorized, not scope creep; no files beyond the two declared ones are touched.

Reviewed independently by GLM (glm-5.3-flash) and DeepSeek (deepseek-v4-pro-0813) via Shipfox; verified and synthesized by GLM.

@NumaryBot
NumaryBot requested a review from a team September 6, 2026 02:06
@shipfox-ai

shipfox-ai Bot commented Sep 8, 2026

Copy link
Copy Markdown

This Renovate PR delivers the declared golang.org/x/crypto v0.55.0 → v0.56.0 security bump in tools/readme/go.mod/go.sum correctly and completely. However, it also silently re-pins the Bitnami postgresql dependency (18.8.17 → 18.9.0) in four Chart.lock files with no corresponding Chart.yaml version bumps anywhere up the dependency tree — a direct breach of this repo's cascade rule that leaves the formance umbrella's locked dependencies changed while its consumer-facing version stays 2.6.0. It additionally raises the Go directive to 1.26.0 while the nix-pinned CI toolchain is Go 1.25. Recommendation: request changes. Please apply the version cascade (console-v3, membership, portal → cloudprem → formance) in this PR — or strip the lockfile changes — and either bump flake.nix goVersion to match or revert the go directive. Note this PR has automerge enabled, so these issues would otherwise merge unreviewed.

Standards

  1. Cascade rule violated — Chart.lock changes with zero version bumps (high). CLAUDE.md is explicit: "Any change to a Chart.lock means the chart that owns it must have its version bumped, and every chart that depends on it must also be bumped — all the way up to formance. No exceptions" — including the case where "a floating range resolved to a higher version." This diff changes charts/console-v3/Chart.lock, charts/formance/Chart.lock, charts/membership/Chart.lock, and charts/portal/Chart.lock (postgresql 18.8.17 → 18.9.0 via their 18.X floating ranges), yet no Chart.yaml appears in the diff at all: console-v3 stays 4.2.0, membership 3.6.3, portal 4.2.0, formance 2.6.0, and parent cloudprem stays 5.2.0. Per the rule, the required cascade is console-v3/membership/portal → cloudprem → formance, plus a formance self-bump (its own lock changed). Concrete impact: consumers pinning charts/formance 2.6.0 will silently receive different locked dependencies (new postgresql 18.9.0, new lock digests) under an unchanged chart version. CLAUDE.md step 5's cascade audit and step 6's expected-diff check both fail for this diff.

  2. Go toolchain mismatch — module requires Go 1.26.0, CI dev shell pins Go 1.25 (high). tools/readme/go.mod:3 now declares go 1.26.0, but flake.nix:15 pins goVersion = 25 (overlaid at line 39 as go_1_25), and .github/workflows/pull_request.yml:73 runs nix develop --impure --command just pc, which executes go mod tidy and go run ./ in tools/readme (Justfile tidy, template-readme). Under Go 1.25 this forces an automatic download of an undeclared Go 1.26 toolchain at CI time (breaking the hermetic nix environment), or outright failure under GOTOOLCHAIN=local. Bump flake.nix goVersion to 26, or revert the go directive if x/crypto v0.56.0 doesn't strictly require it.

Spec

The PR body (Renovate) declares exactly one update: golang.org/x/crypto | indirect | v0.55.0 -> v0.56.0. The declared requirement is fully implemented — tools/readme/go.mod:23 (golang.org/x/crypto v0.56.0 // indirect) with matching h1: and /go.mod checksums in tools/readme/go.sum:49-50 — and no stale v0.55.0 references remain. No declared requirement is missing. Two groups of undeclared scope creep:

  1. Four undeclared Chart.lock rewrites (high, within-axis). The body names no chart, lock, or postgresql change, yet the diff bumps postgresql 18.8.17 → 18.9.0 and refreshes digests/timestamps in charts/console-v3/Chart.lock, charts/formance/Chart.lock, charts/membership/Chart.lock, and charts/portal/Chart.lock. This silently alters the umbrella chart's pinned dependencies — behaviour never requested, and the same issue as Standards finding 1.

  2. Undeclared Go directive bump (low, within-axis). tools/readme/go.mod:3 changes go 1.25.0 → go 1.26.0. The PR body does not mention this change (contrary to what one candidate report claimed). Whether or not it is a Renovate compatibility side-effect, it is undeclared behaviour and carries the concrete CI/toolchain impact described in Standards finding 2.

Reviewed independently by GLM (glm-5.3-flash) and DeepSeek (deepseek-v4-pro-0813) via Shipfox; verified and synthesized by GLM.

@NumaryBot NumaryBot left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

NumaryBot posted 1 new inline finding.

Summary: #426 (comment)

@@ -4,6 +4,6 @@ dependencies:
version: 1.6.0
- name: postgresql
repository: oci://registry-1.docker.io/bitnamicharts

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔴 [blocker] Version the charts whose locks changed

The PostgreSQL lock update changes the packaged dependencies of console-v3, membership, portal, and formance, but none of their chart versions—or the cloudprem/formance cascade—were bumped, so existing-version consumers may never receive the new locks. Bump every affected chart through formance, or remove these unrelated lock changes, as required by CLAUDE.md lines 36–40.

@shipfox-ai

shipfox-ai Bot commented Sep 9, 2026

Copy link
Copy Markdown

This PR correctly bumps golang.org/x/crypto to v0.56.0 in the repo's only Go module (tools/readme), but it also silently re-pins the Bitnami postgresql subchart from 18.8.17 to 18.10.0 in four Chart.lock files without bumping any owning chart's version — a direct violation of this repo's documented cascade rule, and a consumer-facing change the PR body never declares. Recommendation: request changes (the fixes are mechanical: version-bump the four charts plus cloudprem, re-run just pre-commit, and note the postgresql drift in the PR body).

Standards

  1. HARD — Cascade rule not applied (CLAUDE.md, "The cascade rule"). Four Chart.lock files changed — charts/console-v3/Chart.lock, charts/formance/Chart.lock, charts/membership/Chart.lock, charts/portal/Chart.lock (all resolving the floating 18.X postgresql range to 18.10.0) — yet no Chart.yaml version changed anywhere in the diff (verified: charts/membership/Chart.yaml:25 3.6.3, charts/portal/Chart.yaml:29 4.2.0, charts/console-v3/Chart.yaml:32 4.2.0, charts/cloudprem/Chart.yaml:34 5.2.0, charts/formance/Chart.yaml:13 2.6.0). CLAUDE.md is explicit: "Any change to a Chart.lock means the chart that owns it must have its version bumped, and every chart that depends on it must also be bumped — all the way up to formance. No exceptions." Case 3 ("a floating range resolved to a higher version") applies exactly. Step 5 of the standard procedure requires each modified lock's owning chart to appear in the diff. Required cascade: bump membership, portal, console-v3 (each owning a changed lock), cloudprem (parent of all three), and formance (its own lock changed and it is the umbrella). Concrete impact: a consumer pinning formance 2.6.0 or membership 3.6.3 will, on helm dependency build, pull postgresql 18.10.0 with new digests under an unchanged chart version — precisely the "consumers never see the change" failure the rule exists to prevent.

  2. LOW — Go toolchain pin drift (tools/readme/go.mod:3, flake.nix). The diff raises the go directive to 1.26.0, while flake.nix still pins goVersion = 25 (→ go_1_25) and CI's "Dirty" job runs nix develop --impure --command just pc (.github/workflows/pull_request.yml:73), which executes go mod tidy / go run ./ in tools/readme via the Justfile. The pinned 1.25 toolchain no longer satisfies the module's requirement, so the Go tooling must self-switch (e.g. GOTOOLCHAIN=auto downloading an unpinned toolchain) to reconcile them. This is not currently breaking — the "Dirty" check passed on head SHA f805514 — so this is a minor hermeticity/pinning concern (raise flake.nix goVersion to 26 in a follow-up), not a merge blocker.

The postgresql hunk repeated across four lock files was checked and suppressed: CLAUDE.md mandates these files be generated by just pre-commit, so hand deduplication is prohibited. The hand-edit rule and conventional-commit style are respected.

Spec

Spec source: the Renovate PR body, whose update table lists exactly one row — golang.org/x/crypto | indirect | minor | v0.55.0 -> v0.56.0.

(a) Missing or partial requirements — none. The declared update is fully implemented: tools/readme/go.mod:23 now reads golang.org/x/crypto v0.56.0 // indirect, with matching v0.56.0 module and h1: checksums in tools/readme/go.sum:49-50, and no stale v0.55.0 reference remains. tools/readme is the repo's only Go module, so nothing was left behind. (The CVE fixes concern x/crypto/ssh, which is only an indirect dependency of a docs-generation tool, so the security value is nominal — but the target and location are correct.)

(b) Behaviour not asked for (scope creep):

  1. MEDIUM — Four undeclared Chart.lock rewrites shipping postgresql 18.8.17 → 18.10.0 in charts/console-v3/Chart.lock, charts/formance/Chart.lock, charts/membership/Chart.lock, charts/portal/Chart.lock, each with a new digest and generated: timestamp. The PR body's table names no chart, lock, or postgresql change anywhere. This is a side-effect of the chore: run pre-commit commit re-resolving the floating 18.X range, and it materially changes what consumers of these four published charts pin on helm dependency build. Arguably unavoidable repo hygiene given generated lockfiles, but it is unrequested, consumer-facing behaviour that should at minimum be disclosed in the PR body — and per the cascade rule it requires the version bumps listed under Standards.

  2. LOW — Undeclared go directive bump (tools/readme/go.mod:3, 1.25.0 → 1.26.0). Note: the PR body contains no Renovate artifact-update notice — the body jumps straight from the update table to the CVE sections — so the earlier claim that this change was "declared by the artifact notice" is not supported by the actual PR. The bump is very likely a mechanical requirement of x/crypto v0.56.0's own go directive rather than gratuitous, so it is flagged for awareness rather than as a breach; the toolchain-pinning consequence is tracked under Standards.

(c) Implemented but wrong — none. The declared bump is internally consistent across go.mod and go.sum, and no other module is affected.

Reviewed independently by GLM (glm-5.3-flash) and DeepSeek (deepseek-v4-pro-0813) via Shipfox; verified and synthesized by GLM.

@flemzord
flemzord merged commit 6dc1d69 into main Sep 10, 2026
4 of 5 checks passed
@flemzord
flemzord deleted the renovate/security branch September 10, 2026 09:52
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants