Skip to content

chore(deps): bump golang.org/x/crypto to v0.53.0 and golang.org/x/sys to v0.46.0 - #782

Closed
Stensel8 wants to merge 5 commits into
winboat-org:mainfrom
Stensel8:main
Closed

Stensel8 wants to merge 5 commits into
winboat-org:mainfrom
Stensel8:main

Conversation

@Stensel8

@Stensel8 Stensel8 commented May 22, 2026 •

Copy link
Copy Markdown

Bumps golang.org/x/crypto from v0.43.0 to v0.53.0 and golang.org/x/sys from v0.37.0 to v0.46.0 in /guest_server.

Copilot AI review requested due to automatic review settings May 22, 2026 13:01

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Note

Copilot was unable to run its full agentic suite in this review.

Updates the guest_server Go dependencies to newer golang.org/x/* versions.

Changes:

  • Bumped golang.org/x/crypto from v0.43.0 to v0.45.0
  • Bumped golang.org/x/sys from v0.37.0 to v0.38.0

Reviewed changes

Copilot reviewed 1 out of 2 changed files in this pull request and generated no comments.

File Description
guest_server/go.mod Updates required module versions for x/crypto and x/sys
guest_server/go.sum Refreshes checksum entries to match the upgraded module versions

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment thread guest_server/go.sum Outdated
golang.org/x/crypto v0.43.0 h1:dduJYIi3A3KOfdGOHX8AVZ/jGiyPa3IbBozJ5kNuE04=
golang.org/x/crypto v0.43.0/go.mod h1:BFbav4mRNlXJL4wNeejLpWxB7wMbc79PdRGhWKncxR0=
golang.org/x/crypto v0.45.0 h1:jMBrvKuj23MTlT0bQEOBcAE0mjg8mK9RXFhRH6nyF3Q=
golang.org/x/crypto v0.45.0/go.mod h1:XTGrrkGJve7CYK7J8PEww4aY7gM3qMCElcJQ8n8JdX4=

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Can we go newer than 0.45 without breaking compatibility?

@waffles-dev
waffles-dev self-requested a review May 29, 2026 10:37
@Stensel8 Stensel8 changed the title chore(deps): bump golang.org/x/crypto from 0.43.0 to 0.45.0 chore(deps): bump golang.org/x/crypto to v0.53.0 and golang.org/x/sys to v0.46.0 Jun 8, 2026
@Stensel8

Stensel8 commented Jun 8, 2026

Copy link
Copy Markdown
Author

Bumped both packages further to their latest versions: golang.org/x/crypto to v0.53.0 and golang.org/x/sys to v0.46.0.

I'm on Linux only so no runtime test on Windows, but cross-compile for amd64 and arm64 succeeds and go vet is clean:

$ GOOS=windows GOARCH=amd64 go build -v -o winboat-amd64.exe .
winboat-server

$ GOOS=windows GOARCH=arm64 go build -v -o winboat-arm64.exe .
winboat-server

$ GOOS=windows GOARCH=amd64 go vet ./...
(no output, clean)

$ file winboat-amd64.exe winboat-arm64.exe
winboat-amd64.exe: PE32+ executable for MS Windows 6.01 (console), x86-64, 15 sections
winboat-arm64.exe: PE32+ executable for MS Windows 6.01 (console), ARM64, 13 sections

$ go list -m golang.org/x/crypto golang.org/x/sys
golang.org/x/crypto v0.53.0
golang.org/x/sys v0.46.0

Stensel8 and others added 3 commits August 8, 2026 20:30
This workflow file sets up CodeQL analysis for multiple programming languages, including Go, JavaScript/TypeScript, and Actions. It defines triggers for pushes and pull requests to the main branch, as well as a scheduled run.
Co-authored-by: TibixDev <tibix@fhs.sh>
Co-authored-by: TibixDev <tibix@fhs.sh>
pull Bot and others added 2 commits September 22, 2026 01:08
* fix: Secure guest API path handling

* feat: add a Russian Comment to the Linux desktop entry

The generated .desktop file only carries the English Comment that
electron-builder takes from package.json description, so on a Russian
desktop the entry shows nothing but the app name.

Comment is left to electron-builder: computeDesktopEntry assigns
desktopMeta.Comment from linux.description (falling back to the
package.json description) after merging linux.desktop.entry, so a
Comment key placed there would be overwritten anyway. Comment[ru] is
untouched by that and lands in the file as written.

* feat: add Keywords to the Linux desktop entry

electron-builder writes Name, Comment, Categories, Exec, Icon and
StartupWMClass, but never Keywords, so the entry is only findable by
its name. Added an English list and a Russian one.

Keywords[ru] repeats the English terms, because a Russian locale reads
Keywords[ru] instead of Keywords, not on top of it. Dropping them there
would break searching for "rdp" or "docker" the moment the desktop is
set to Russian.

StartupWMClass is not touched: computeDesktopEntry already emits it
(desktopName from package.json, productName otherwise).

* Use zip -X for winboat_guest_server

on openSUSE, this is enough to make the whole package build
bit-reproducible, because we have a zip patch that
makes it normalize mtimes as well.

* docs: fix typo targetted -> targeted (#863)

Signed-off-by: Vaibhav Srivastava <vaibhavsri1712@gmail.com>

* fix: Validate rdpArgs shape on config load to prevent silent launch failure (#837)

A hand edited winboat.config.json can hold rdpArgs entries that do not match
RdpArg, most commonly an array of plain strings. Nothing validated them on
load, so they reached the FreeRDP command line as undefined and every app
launch failed with no window, no dialog and no line in winboat.log.

Validate each rdpArgs entry when the config is read, drop the malformed ones
and log a visible error naming them and the expected shape. A value that is
not an array falls back to the default. Well formed configs are untouched,
and the file on disk is not rewritten.

Fixes #836

* fix: Recognize all auto-restart policies for Auto Start Container (#848)

* fix: Recognize all auto-restart policies for Auto Start Container

The Auto Start Container switch read the compose restart policy with a
strict equality check against `unless-stopped`, so the two other policies
that also bring the container back on their own (`always` and the legacy
`on-failure` default) rendered as OFF.

Installs created before 4fefd6d shipped `restart: on-failure`. For those
users the switch showed OFF while Docker still restarted the container,
and because `origAutoStartContainer` matched, the Save button stayed
disabled - leaving no in-app way to write `restart: no`.

Read the policy against a shared AUTOSTART_RESTART_POLICIES list instead,
and track whether the on-disk policy is non-canonical so Save stays
reachable and one save normalizes the file to `unless-stopped` or `no`.

Fixes #474

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01S4SjzSmXacb2MCxt2WcHSa

* refactor: Drop legacy restart policy handling per review

1.0 will require a fresh install and config, so the compatibility bits for
older WinBoat installs are no longer needed:

- `on-failure` is no longer treated as auto start. It was only recognized
  because it was the pre-4fefd6d default; nothing writes it anymore.
- Removed `hasLegacyRestartPolicy` and its save-gate clause, which existed
  solely to let stranded installs normalize a non-canonical policy.

The genuine auto start handling stays: `unless-stopped` and `always` both
bring the container back on their own, so both read as enabled rather than
only the one value we happen to write.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01S4SjzSmXacb2MCxt2WcHSa

---------

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>

---------

Signed-off-by: Vaibhav Srivastava <vaibhavsri1712@gmail.com>
Co-authored-by: TibixDev <tibix@fhs.sh>
Co-authored-by: Wehrwolfmann <256216494+wehrwolfmann@users.noreply.github.com>
Co-authored-by: Bernhard M. Wiedemann <bwiedemann@suse.de>
Co-authored-by: Vaibhav Srivastava <vaibhavsri1712@gmail.com>
Co-authored-by: Tibix <fuloptibi03@gmail.com>
Co-authored-by: Thiago Mafra <mfryh1537@proton.me>
Co-authored-by: Paritosh . <109455621+Pager-dot@users.noreply.github.com>
Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
@Stensel8 Stensel8 closed this by deleting the head repository Sep 21, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants