Skip to content

chore(deps): update module golang.org/x/crypto to v0.56.0 [security] - #126

Merged
NumaryBot merged 1 commit into
mainfrom
renovate/security
Sep 6, 2026
Merged

NumaryBot merged 1 commit into
mainfrom
renovate/security

Conversation

@NumaryBot

@NumaryBot NumaryBot commented Sep 3, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Type Update Change
golang.org/x/crypto indirect minor v0.55.0 -> v0.56.0

Prevent DoS on deadlocked established channel in golang.org/x/crypto/ssh

CVE-2026-56855 / GO-2026-6355

More information

Details

Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection.

Now, we handle all RFC 4254 channel messages; global requests are handled explicitly. Then, treat all other messages as a protocol error and tear the connection down instead of buffering and blocking.

Severity

Unknown

References

This data is provided by OSV and the Go Vulnerability Database (CC-BY 4.0).


Prevent DoS on deadlocked undecided channel in golang.org/x/crypto/ssh

CVE-2026-78662 / GO-2026-6354

More information

Details

Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection.

Now, we add an atomic established state, set when a channel becomes usable. Until such a time, handlePacket drops every packet other than the open confirmation/failure, without blocking and without tearing down the connection.

Severity

Unknown

References

This data is provided by OSV and the Go Vulnerability Database (CC-BY 4.0).


Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Renovate Bot.

@NumaryBot
NumaryBot requested a review from a team as a code owner September 3, 2026 02:21
@NumaryBot
NumaryBot enabled auto-merge (squash) September 3, 2026 02:21
@NumaryBot

NumaryBot commented Sep 3, 2026

Copy link
Copy Markdown
Contributor Author

✅ Approve — automated review

The patch consistently updates golang.org/x/crypto to v0.56.0 with matching module checksums. No regressions or dependency inconsistencies are evident.

No findings.

@NumaryBot
NumaryBot merged commit a48a7d0 into main Sep 6, 2026
7 of 11 checks passed
@NumaryBot
NumaryBot deleted the renovate/security branch September 6, 2026 02:10
@shipfox-ai

shipfox-ai Bot commented Sep 6, 2026

Copy link
Copy Markdown

This PR is a purely mechanical dependency bump of the indirect module golang.org/x/crypto from v0.55.0 to v0.56.0, touching only go.mod (one require line) and go.sum (the corresponding h1: and /go.mod checksum pair). I verified the diff against the checkout: go.mod:230 now requires v0.56.0 // indirect, and go.sum:564–565 carry the matching v0.56.0 checksums with no stale v0.55.0 entries remaining. The separate pkg/client module does not reference golang.org/x/crypto, so no cross-module consistency issue arises. Given the PR's stated security motivation, moving to the patched version is the correct and complete remediation. No documented-standard violation, no baseline smell, and no spec gap, scope creep, or suspect implementation was confirmed. Recommendation: approve.

Standards

No confirmed material finding. The diff contains no Go source, names, or logic, so the documented standards (Justfile tidy/lint/generate/tests targets, pkg/client/CONTRIBUTING.md generated-code rule) are not applicable; the module files are internally consistent as go mod tidy would produce them. No baseline smell applies — the two-file spread is the required shape of a Go dependency bump, and each file is edited for exactly one reason.

Spec

No confirmed material finding. The diff exactly implements the PR body's single requirement ("golang.org/x/crypto | indirect | minor | v0.55.0 -> v0.56.0"): the indirect require line and both go.sum checksums were updated together, no other module or file was touched, and the // indirect annotation is preserved.

Reviewed independently by GLM (glm-5.3-flash) and DeepSeek (deepseek-v4-pro-0813) via Shipfox; verified and synthesized by GLM.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Development

Successfully merging this pull request may close these issues.

2 participants