Skip to content

chore(security): triage GO-2026-5932 in osv-scanner - #344

Merged
KeiaiLab-PHIL merged 1 commit into
mainfrom
chore/osv-ignore-openpgp
Oct 6, 2026
Merged

KeiaiLab-PHIL merged 1 commit into
mainfrom
chore/osv-ignore-openpgp

Conversation

@KeiaiLab-PHIL

Copy link
Copy Markdown
Contributor

Scorecard Vulnerabilities keeps one finding: GO-2026-5932,
"golang.org/x/crypto/openpgp is unmaintained". It is a module-level
advisory with no fixed version, so no bump can clear it.

The package is not in our build graph (go list -deps -test ./...
has no x/crypto/openpgp; govulncheck reports it at module level
only). Record that in osv-scanner.toml, which Scorecard reads,
with an expiry (2027-01-06) so it is re-reviewed. No CI gate
changes; govulncheck and Trivy run as before.

Co-Authored-By: Claude Opus 5.5 noreply@anthropic.com

🤖 Generated with Claude Code

Scorecard Vulnerabilities keeps one finding: GO-2026-5932,
"golang.org/x/crypto/openpgp is unmaintained". It is a module-level
advisory with no fixed version, so no bump can clear it.

The package is not in our build graph (go list -deps -test ./...
has no x/crypto/openpgp; govulncheck reports it at module level
only). Record that in osv-scanner.toml, which Scorecard reads,
with an expiry (2027-01-06) so it is re-reviewed. No CI gate
changes; govulncheck and Trivy run as before.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Signed-off-by: phil <phil@keiailab.com>
@KeiaiLab-PHIL
KeiaiLab-PHIL enabled auto-merge (squash) October 6, 2026 03:33
@KeiaiLab-PHIL
KeiaiLab-PHIL merged commit d77d295 into main Oct 6, 2026
14 checks passed
@KeiaiLab-PHIL
KeiaiLab-PHIL deleted the chore/osv-ignore-openpgp branch October 6, 2026 03:37
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant