Bump golang.org/x/crypto from 0.41.0 to 0.52.0 - #11
Merged
Conversation
Contributor
|
@dependabot rebase Rebasing to pick up the CI fix merged in #12 (Go matrix 1.21.x to 1.24.x, golangci-lint v2.12.2). The lint failure on this PR was caused by that stale toolchain mismatch, not by the dependency bump. Ref [sc-19289]. |
dependabot
Bot
force-pushed
the
dependabot/go_modules/golang.org/x/crypto-0.52.0
branch
from
August 11, 2026 03:35
d672c64 to
ee9a4e2
Compare
Contributor
|
@dependabot rebase Rebasing onto main now that #13 switched pkg/tor/onion.go to the standard library crypto/sha3, which clears the govet inline finding that was blocking this PR. Ref [sc-19289]. |
Bumps [golang.org/x/crypto](https://github.com/golang/crypto) from 0.41.0 to 0.52.0. - [Commits](golang/crypto@v0.41.0...v0.52.0) --- updated-dependencies: - dependency-name: golang.org/x/crypto dependency-version: 0.52.0 dependency-type: direct:production ... Signed-off-by: dependabot[bot] <support@github.com>
dependabot
Bot
force-pushed
the
dependabot/go_modules/golang.org/x/crypto-0.52.0
branch
from
August 11, 2026 12:56
ee9a4e2 to
afdd267
Compare
devkoriel
approved these changes
Aug 11, 2026
devkoriel
left a comment
Contributor
There was a problem hiding this comment.
Pure go.mod/go.sum bump to golang.org/x/crypto v0.52.0, CI green after #12 (CI toolchain) and #13 (stdlib crypto/sha3). Clears CVE-2026-42508, CVE-2026-39830 through 39834 and CVE-2026-46595. Ref [sc-19289].
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps golang.org/x/crypto from 0.41.0 to 0.52.0.
Commits
a1c0d99go.mod: update golang.org/x dependencies3c7c869ssh: fix deadlock on unexpected channel responses533fb3fssh: fix source-address critical option bypassabbc44dssh: fix incorrect operator ordere052873ssh: fix infinite loop on large channel writes due to integer overflowb61cf85ssh: enforce user presence verification for security keys9c2cd33ssh: enforce strict limits on DSA key parameters8907318ssh: reject RSA keys with excessively large moduliffd87b4ssh: fix panic when authority callbacks are nil4e7a738ssh: fix deadlock on unexpected global responsesMost Recent Ignore Conditions Applied to This Pull Request