Skip to content

chore(deps): update module golang.org/x/crypto to v0.56.0 [security] - #214

Merged
NumaryBot merged 1 commit into
mainfrom
renovate/security
Sep 5, 2026
Merged

NumaryBot merged 1 commit into
mainfrom
renovate/security

Conversation

@NumaryBot

@NumaryBot NumaryBot commented Sep 3, 2026 •

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Type Update Change
golang.org/x/crypto indirect minor v0.55.0 -> v0.56.0

Prevent DoS on deadlocked established channel in golang.org/x/crypto/ssh

CVE-2026-56855 / GO-2026-6355

More information

Details

Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection.

Now, we handle all RFC 4254 channel messages; global requests are handled explicitly. Then, treat all other messages as a protocol error and tear the connection down instead of buffering and blocking.

Severity

Unknown

References

This data is provided by OSV and the Go Vulnerability Database (CC-BY 4.0).


Prevent DoS on deadlocked undecided channel in golang.org/x/crypto/ssh

CVE-2026-78662 / GO-2026-6354

More information

Details

Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection.

Now, we add an atomic established state, set when a channel becomes usable. Until such a time, handlePacket drops every packet other than the open confirmation/failure, without blocking and without tearing down the connection.

Severity

Unknown

References

This data is provided by OSV and the Go Vulnerability Database (CC-BY 4.0).


Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Enabled.

♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Renovate Bot.

@NumaryBot
NumaryBot requested a review from a team as a code owner September 3, 2026 02:22
@NumaryBot
NumaryBot enabled auto-merge (squash) September 3, 2026 02:22
@NumaryBot

Copy link
Copy Markdown
Contributor Author

ℹ Artifact update notice

File name: go.mod

In order to perform the update(s) described in the table above, Renovate ran the go get command, which resulted in the following additional change(s):

  • The go directive was updated for compatibility reasons

Details:

Package Change
go 1.25.0 -> 1.26.0

@NumaryBot

NumaryBot commented Sep 3, 2026 •

Copy link
Copy Markdown
Contributor Author

✅ Approve — automated review

The dependency and checksum updates are consistent, and the Go 1.26 directive matches the repository's configured development toolchain.

No findings.

@NumaryBot
NumaryBot merged commit 6739dfe into main Sep 5, 2026
10 of 15 checks passed
@NumaryBot
NumaryBot deleted the renovate/security branch September 5, 2026 02:36
@shipfox-ai

shipfox-ai Bot commented Sep 5, 2026

Copy link
Copy Markdown

This PR is a Renovate security bump of golang.org/x/crypto from v0.55.0 to v0.56.0, touching only go.mod and go.sum. I verified the manifests are internally consistent (no stale v0.55.0 entries remain; the h1:/go.mod hash pair was updated together in go.sum), and that the accompanying go directive bump (1.25.0 → 1.26.0) is a mechanical compatibility consequence of the new module graph that also brings go.mod in line with the repo's pre-existing Go 1.26 Nix environment (flake.nix already pinned go_1_26 before this PR). No source code, CI, or build configuration changed. Recommendation: approve.

Standards

No confirmed material findings. The repo contains no documented standards (no CODING_STANDARDS.md, CONTRIBUTING.md, or AGENTS.md), and the diff contains no functions, types, or logic for baseline smells to attach to. The one candidate — a "Divergent Change" claim that the go directive bump rides along with the dependency update — was investigated and dismissed: go.mod/go.sum are tool-managed manifests, both edits result from a single go get operation (Go only raises the go directive when the upgraded module graph requires it), and the bump resolves a pre-existing mismatch with flake.nix's go_1_26 toolchain rather than bundling an unrelated concern.

Spec

No confirmed material findings; no spec document is available in the review context. The single candidate — Codex's "scope creep" flag on the go 1.25.0 → 1.26.0 directive bump in go.mod:4 — was verified against the code and resolved: the bump is the standard go get compatibility behavior for a module whose graph requires Go 1.26, it aligns go.mod with the repo's documented Go 1.26 development environment, and CI builds/tests run under that toolchain (.github/workflows/main.yml uses nix develop), so there is no compatibility or correctness impact beyond the intended one. Residual note: the new checksum values in go.sum:275-276 could not be verified offline, but Go's checksum verification is enforced by CI pre-commit (tidy) and build jobs, so any mismatch would fail the pipeline rather than merge.

Reviewed independently by GLM (glm-5.3-flash) and DeepSeek (deepseek-v4-pro-0813) via Shipfox; verified and synthesized by GLM.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Development

Successfully merging this pull request may close these issues.

2 participants