build(deps): x/crypto v0.56.0 へ更新(到達可能な DoS 脆弱性 2 件を解消) - #24
Merged
Merged
Conversation
govulncheck が x/crypto v0.55.0 に対し GO-2026-6354 / GO-2026-6355 を 到達可能(ssh.Dial 経由)と報告していた。v0.56.0 で修正済み。 更新後は Symbol Results が空(到達可能な脆弱性 0 件)。 残る GO-2026-5932 は x/crypto に修正版がなく(Fixed in N/A)、 本ツールのコードからは到達しないため対応しない。 Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
作業クローンの remote が GitLab 単一になっており、GitHub の master が Scoop manifest の出力先修正を含む 3 コミット先行していた。そのまま タグを打つと正本のリリースと bucket 更新が欠落するため、デュアルリモート 構成を復元して 3 者を揃えた経緯を残す。 Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
govulncheckがgolang.org/x/cryptov0.55.0 に対して 到達可能 な脆弱性 2 件を報告していたため更新する。検出内容(更新前)
いずれも本ツールの中核である
ssh.Dial(ssh.go:49)から到達する。変更
golang.org/x/cryptov0.55.0 → v0.56.0(go get ... @latest && go mod tidy)x/term/x/sysは連動更新なし(それぞれ v0.45.0 / v0.47.0 のまま)toolchain go1.26.6は変更なし(標準ライブラリ側の指摘は今回なし)検証
make check— build + vet + test + integration ビルド、すべて通過govulncheck ./...— Symbol Results が空(到達可能な脆弱性 0 件)、exit 0残る
GO-2026-5932は x/crypto に修正版が存在せず(Fixed in N/A)、本ツールのコードからは到達しないため対応しない。併せて記録した事項(
LESSONS.md)この作業中、作業クローンの remote が GitLab 単一に退化しており、GitHub の master が
574daf5 fix: write the Scoop manifest into bucket/を含む 3 コミット先行している状態を発見した。そのままタグを打つと正本(GitHub Releases)のリリースと Scoop bucket 更新が欠落するため、
デュアルリモート構成を復元して 3 者(local / origin / gitlab)を揃えた。経緯を
LESSONS.mdに追記している。