build(deps): bump golang.org/x/net from 0.53.0 to 0.55.0 in /hack/tools - #8904
build(deps): bump golang.org/x/net from 0.53.0 to 0.55.0 in /hack/tools#8904dependabot[bot] wants to merge 1 commit into
Conversation
|
Pipeline controller notification For optional jobs, comment This repository is configured in: LGTM mode |
📝 WalkthroughWalkthroughUpdates five indirect Possibly related PRs
Suggested reviewers: 🚥 Pre-merge checks | ✅ 11✅ Passed checks (11 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Comment |
|
Hi @dependabot[bot]. Thanks for your PR. I'm waiting for a openshift member to verify that this patch is reasonable to test. If it is, they should reply with Regular contributors should join the org to skip this step. Once the patch is verified, the new status will be reflected by the I understand the commands that are listed here. DetailsInstructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. |
|
[APPROVALNOTIFIER] This PR is NOT APPROVED This pull-request has been approved by: dependabot[bot] The full list of commands accepted by this bot can be found here. DetailsNeeds approval from an approver in each of these files:Approvers can indicate their approval by writing |
Bumps [golang.org/x/net](https://github.com/golang/net) from 0.53.0 to 0.55.0. - [Commits](golang/net@v0.53.0...v0.55.0) --- updated-dependencies: - dependency-name: golang.org/x/net dependency-version: 0.55.0 dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com>
b8337f9 to
075acf3
Compare
There was a problem hiding this comment.
Actionable comments posted: 1
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@hack/tools/go.mod`:
- Line 293: Update the golang.org/x/crypto dependency in the hack/tools module
to v0.52.0 or newer, then refresh hack/tools/go.sum and the corresponding vendor
metadata so the SSH fixes are included.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Repository YAML (base), Central YAML (inherited)
Review profile: CHILL
Plan: Enterprise
Run ID: e0873611-6673-4028-a7eb-14423b86a083
⛔ Files ignored due to path filters (123)
hack/tools/go.sumis excluded by!**/*.sumhack/tools/vendor/golang.org/x/crypto/hkdf/hkdf.gois excluded by!**/vendor/**hack/tools/vendor/golang.org/x/net/html/parse.gois excluded by!**/vendor/**hack/tools/vendor/golang.org/x/net/html/render.gois excluded by!**/vendor/**hack/tools/vendor/golang.org/x/net/html/token.gois excluded by!**/vendor/**hack/tools/vendor/golang.org/x/net/http2/README.mdis excluded by!**/vendor/**hack/tools/vendor/golang.org/x/net/http2/client_conn_pool.gois excluded by!**/vendor/**hack/tools/vendor/golang.org/x/net/http2/clientconn.gois excluded by!**/vendor/**hack/tools/vendor/golang.org/x/net/http2/config.gois excluded by!**/vendor/**hack/tools/vendor/golang.org/x/net/http2/hpack/tables.gois excluded by!**/vendor/**hack/tools/vendor/golang.org/x/net/http2/http2.gois excluded by!**/vendor/**hack/tools/vendor/golang.org/x/net/http2/server.gois excluded by!**/vendor/**hack/tools/vendor/golang.org/x/net/http2/server_common.gois excluded by!**/vendor/**hack/tools/vendor/golang.org/x/net/http2/server_wrap.gois excluded by!**/vendor/**hack/tools/vendor/golang.org/x/net/http2/transport.gois excluded by!**/vendor/**hack/tools/vendor/golang.org/x/net/http2/transport_common.gois excluded by!**/vendor/**hack/tools/vendor/golang.org/x/net/http2/transport_wrap.gois excluded by!**/vendor/**hack/tools/vendor/golang.org/x/net/http2/writesched.gois excluded by!**/vendor/**hack/tools/vendor/golang.org/x/net/http2/writesched_common.gois excluded by!**/vendor/**hack/tools/vendor/golang.org/x/net/http2/writesched_priority_rfc7540.gois excluded by!**/vendor/**hack/tools/vendor/golang.org/x/net/http2/writesched_priority_rfc9218.gois excluded by!**/vendor/**hack/tools/vendor/golang.org/x/net/http2/writesched_random.gois excluded by!**/vendor/**hack/tools/vendor/golang.org/x/net/http2/writesched_roundrobin.gois excluded by!**/vendor/**hack/tools/vendor/golang.org/x/net/idna/go118.gois excluded by!**/vendor/**hack/tools/vendor/golang.org/x/net/idna/idna.gois excluded by!**/vendor/**hack/tools/vendor/golang.org/x/net/idna/idna9.0.0.gois excluded by!**/vendor/**hack/tools/vendor/golang.org/x/net/idna/pre_go118.gois excluded by!**/vendor/**hack/tools/vendor/golang.org/x/net/idna/punycode.gois excluded by!**/vendor/**hack/tools/vendor/golang.org/x/net/idna/tables10.0.0.gois excluded by!**/vendor/**hack/tools/vendor/golang.org/x/net/idna/tables11.0.0.gois excluded by!**/vendor/**hack/tools/vendor/golang.org/x/net/idna/tables12.0.0.gois excluded by!**/vendor/**hack/tools/vendor/golang.org/x/net/idna/tables13.0.0.gois excluded by!**/vendor/**hack/tools/vendor/golang.org/x/net/idna/tables15.0.0.gois excluded by!**/vendor/**hack/tools/vendor/golang.org/x/net/idna/tables17.0.0.gois excluded by!**/vendor/**hack/tools/vendor/golang.org/x/net/idna/tables9.0.0.gois excluded by!**/vendor/**hack/tools/vendor/golang.org/x/net/idna/trie12.0.0.gois excluded by!**/vendor/**hack/tools/vendor/golang.org/x/net/idna/trie13.0.0.gois excluded by!**/vendor/**hack/tools/vendor/golang.org/x/net/internal/httpcommon/request.gois excluded by!**/vendor/**hack/tools/vendor/golang.org/x/sys/cpu/cpu.gois excluded by!**/vendor/**hack/tools/vendor/golang.org/x/sys/cpu/cpu_linux_riscv64.gois excluded by!**/vendor/**hack/tools/vendor/golang.org/x/sys/cpu/cpu_loong64.gois excluded by!**/vendor/**hack/tools/vendor/golang.org/x/sys/cpu/cpu_other_arm64.gois excluded by!**/vendor/**hack/tools/vendor/golang.org/x/sys/cpu/cpu_riscv64.gois excluded by!**/vendor/**hack/tools/vendor/golang.org/x/sys/cpu/cpu_windows.gois excluded by!**/vendor/**hack/tools/vendor/golang.org/x/sys/cpu/cpu_windows_arm64.gois excluded by!**/vendor/**hack/tools/vendor/golang.org/x/sys/cpu/zcpu_windows.gois excluded by!**/vendor/**hack/tools/vendor/golang.org/x/sys/unix/affinity_linux.gois excluded by!**/vendor/**hack/tools/vendor/golang.org/x/sys/unix/mkall.shis excluded by!**/vendor/**hack/tools/vendor/golang.org/x/sys/unix/mkerrors.shis excluded by!**/vendor/**hack/tools/vendor/golang.org/x/sys/unix/readv_unix.gois excluded by!**/vendor/**hack/tools/vendor/golang.org/x/sys/unix/syscall_darwin.gois excluded by!**/vendor/**hack/tools/vendor/golang.org/x/sys/unix/syscall_linux.gois excluded by!**/vendor/**hack/tools/vendor/golang.org/x/sys/unix/syscall_linux_arm.gois excluded by!**/vendor/**hack/tools/vendor/golang.org/x/sys/unix/syscall_linux_arm64.gois excluded by!**/vendor/**hack/tools/vendor/golang.org/x/sys/unix/syscall_linux_loong64.gois excluded by!**/vendor/**hack/tools/vendor/golang.org/x/sys/unix/syscall_linux_riscv64.gois excluded by!**/vendor/**hack/tools/vendor/golang.org/x/sys/unix/syscall_openbsd.gois excluded by!**/vendor/**hack/tools/vendor/golang.org/x/sys/unix/zerrors_linux.gois excluded by!**/vendor/**hack/tools/vendor/golang.org/x/sys/unix/zerrors_linux_386.gois excluded by!**/vendor/**hack/tools/vendor/golang.org/x/sys/unix/zerrors_linux_amd64.gois excluded by!**/vendor/**hack/tools/vendor/golang.org/x/sys/unix/zerrors_linux_arm.gois excluded by!**/vendor/**hack/tools/vendor/golang.org/x/sys/unix/zerrors_linux_arm64.gois excluded by!**/vendor/**hack/tools/vendor/golang.org/x/sys/unix/zerrors_linux_loong64.gois excluded by!**/vendor/**hack/tools/vendor/golang.org/x/sys/unix/zerrors_linux_mips.gois excluded by!**/vendor/**hack/tools/vendor/golang.org/x/sys/unix/zerrors_linux_mips64.gois excluded by!**/vendor/**hack/tools/vendor/golang.org/x/sys/unix/zerrors_linux_mips64le.gois excluded by!**/vendor/**hack/tools/vendor/golang.org/x/sys/unix/zerrors_linux_mipsle.gois excluded by!**/vendor/**hack/tools/vendor/golang.org/x/sys/unix/zerrors_linux_ppc.gois excluded by!**/vendor/**hack/tools/vendor/golang.org/x/sys/unix/zerrors_linux_ppc64.gois excluded by!**/vendor/**hack/tools/vendor/golang.org/x/sys/unix/zerrors_linux_ppc64le.gois excluded by!**/vendor/**hack/tools/vendor/golang.org/x/sys/unix/zerrors_linux_riscv64.gois excluded by!**/vendor/**hack/tools/vendor/golang.org/x/sys/unix/zerrors_linux_s390x.gois excluded by!**/vendor/**hack/tools/vendor/golang.org/x/sys/unix/zerrors_linux_sparc64.gois excluded by!**/vendor/**hack/tools/vendor/golang.org/x/sys/unix/zsyscall_linux.gois excluded by!**/vendor/**hack/tools/vendor/golang.org/x/sys/unix/zsyscall_openbsd_386.gois excluded by!**/vendor/**hack/tools/vendor/golang.org/x/sys/unix/zsyscall_openbsd_386.sis excluded by!**/vendor/**hack/tools/vendor/golang.org/x/sys/unix/zsyscall_openbsd_amd64.gois excluded by!**/vendor/**hack/tools/vendor/golang.org/x/sys/unix/zsyscall_openbsd_amd64.sis excluded by!**/vendor/**hack/tools/vendor/golang.org/x/sys/unix/zsyscall_openbsd_arm.gois excluded by!**/vendor/**hack/tools/vendor/golang.org/x/sys/unix/zsyscall_openbsd_arm.sis excluded by!**/vendor/**hack/tools/vendor/golang.org/x/sys/unix/zsyscall_openbsd_arm64.gois excluded by!**/vendor/**hack/tools/vendor/golang.org/x/sys/unix/zsyscall_openbsd_arm64.sis excluded by!**/vendor/**hack/tools/vendor/golang.org/x/sys/unix/zsyscall_openbsd_mips64.gois excluded by!**/vendor/**hack/tools/vendor/golang.org/x/sys/unix/zsyscall_openbsd_mips64.sis excluded by!**/vendor/**hack/tools/vendor/golang.org/x/sys/unix/zsyscall_openbsd_ppc64.gois excluded by!**/vendor/**hack/tools/vendor/golang.org/x/sys/unix/zsyscall_openbsd_ppc64.sis excluded by!**/vendor/**hack/tools/vendor/golang.org/x/sys/unix/zsyscall_openbsd_riscv64.gois excluded by!**/vendor/**hack/tools/vendor/golang.org/x/sys/unix/zsyscall_openbsd_riscv64.sis excluded by!**/vendor/**hack/tools/vendor/golang.org/x/sys/unix/zsysnum_linux_386.gois excluded by!**/vendor/**hack/tools/vendor/golang.org/x/sys/unix/zsysnum_linux_amd64.gois excluded by!**/vendor/**hack/tools/vendor/golang.org/x/sys/unix/zsysnum_linux_arm.gois excluded by!**/vendor/**hack/tools/vendor/golang.org/x/sys/unix/zsysnum_linux_arm64.gois excluded by!**/vendor/**hack/tools/vendor/golang.org/x/sys/unix/zsysnum_linux_loong64.gois excluded by!**/vendor/**hack/tools/vendor/golang.org/x/sys/unix/zsysnum_linux_mips.gois excluded by!**/vendor/**hack/tools/vendor/golang.org/x/sys/unix/zsysnum_linux_mips64.gois excluded by!**/vendor/**hack/tools/vendor/golang.org/x/sys/unix/zsysnum_linux_mips64le.gois excluded by!**/vendor/**hack/tools/vendor/golang.org/x/sys/unix/zsysnum_linux_mipsle.gois excluded by!**/vendor/**hack/tools/vendor/golang.org/x/sys/unix/zsysnum_linux_ppc.gois excluded by!**/vendor/**hack/tools/vendor/golang.org/x/sys/unix/zsysnum_linux_ppc64.gois excluded by!**/vendor/**hack/tools/vendor/golang.org/x/sys/unix/zsysnum_linux_ppc64le.gois excluded by!**/vendor/**hack/tools/vendor/golang.org/x/sys/unix/zsysnum_linux_riscv64.gois excluded by!**/vendor/**hack/tools/vendor/golang.org/x/sys/unix/zsysnum_linux_s390x.gois excluded by!**/vendor/**hack/tools/vendor/golang.org/x/sys/unix/zsysnum_linux_sparc64.gois excluded by!**/vendor/**hack/tools/vendor/golang.org/x/sys/unix/ztypes_linux.gois excluded by!**/vendor/**hack/tools/vendor/golang.org/x/sys/unix/ztypes_linux_386.gois excluded by!**/vendor/**hack/tools/vendor/golang.org/x/sys/unix/ztypes_linux_amd64.gois excluded by!**/vendor/**hack/tools/vendor/golang.org/x/sys/unix/ztypes_linux_arm.gois excluded by!**/vendor/**hack/tools/vendor/golang.org/x/sys/unix/ztypes_linux_arm64.gois excluded by!**/vendor/**hack/tools/vendor/golang.org/x/sys/unix/ztypes_linux_loong64.gois excluded by!**/vendor/**hack/tools/vendor/golang.org/x/sys/unix/ztypes_linux_mips.gois excluded by!**/vendor/**hack/tools/vendor/golang.org/x/sys/unix/ztypes_linux_mips64.gois excluded by!**/vendor/**hack/tools/vendor/golang.org/x/sys/unix/ztypes_linux_mips64le.gois excluded by!**/vendor/**hack/tools/vendor/golang.org/x/sys/unix/ztypes_linux_mipsle.gois excluded by!**/vendor/**hack/tools/vendor/golang.org/x/sys/unix/ztypes_linux_ppc.gois excluded by!**/vendor/**hack/tools/vendor/golang.org/x/sys/unix/ztypes_linux_ppc64.gois excluded by!**/vendor/**hack/tools/vendor/golang.org/x/sys/unix/ztypes_linux_ppc64le.gois excluded by!**/vendor/**hack/tools/vendor/golang.org/x/sys/unix/ztypes_linux_riscv64.gois excluded by!**/vendor/**hack/tools/vendor/golang.org/x/sys/unix/ztypes_linux_s390x.gois excluded by!**/vendor/**hack/tools/vendor/golang.org/x/sys/unix/ztypes_linux_sparc64.gois excluded by!**/vendor/**hack/tools/vendor/golang.org/x/sys/windows/syscall_windows.gois excluded by!**/vendor/**hack/tools/vendor/golang.org/x/sys/windows/types_windows.gois excluded by!**/vendor/**hack/tools/vendor/golang.org/x/sys/windows/zsyscall_windows.gois excluded by!**/vendor/**hack/tools/vendor/modules.txtis excluded by!**/vendor/**
📒 Files selected for processing (1)
hack/tools/go.mod
| go.yaml.in/yaml/v2 v2.4.3 // indirect | ||
| go.yaml.in/yaml/v3 v3.0.4 // indirect | ||
| golang.org/x/crypto v0.50.0 // indirect | ||
| golang.org/x/crypto v0.51.0 // indirect |
There was a problem hiding this comment.
🔒 Security & Privacy | 🟠 Major | ⚡ Quick win
🧩 Analysis chain
🏁 Script executed:
#!/usr/bin/env bash
set -euo pipefail
cd hack/tools
go list -deps ./... | grep -q '^golang.org/x/crypto/ssh$' && echo "affected SSH package is reachable"
govulncheck ./...Repository: openshift/hypershift
Length of output: 241
🏁 Script executed:
#!/usr/bin/env bash
set -euo pipefail
# Show the surrounding go.mod context and whether a go.sum exists in hack/tools.
echo "== hack/tools/go.mod (context) =="
sed -n '280,305p' hack/tools/go.mod
echo
echo "== hack/tools files =="
git ls-files hack/tools | sed -n '1,120p'
echo
echo "== occurrences of golang.org/x/crypto =="
rg -n 'golang.org/x/crypto|golang.org/x/ssh|golang.org/x/net|golang.org/x/sys' hack/tools -S || trueRepository: openshift/hypershift
Length of output: 50376
🌐 Web query:
golang.org/x/crypto v0.51.0 ssh vulnerability v0.52.0 CVE-2026-39830 CVE-2026-39834
💡 Result:
The Go packages golang.org/x/crypto v0.52.0 was released on May 22, 2026, to address multiple security vulnerabilities, including CVE-2026-39830 and CVE-2026-39834 [1]. All versions prior to v0.52.0 are considered affected [2][3][4]. CVE-2026-39830: A malicious SSH peer could send unsolicited global request responses to fill an internal buffer, which blocked the connection's read loop [3][5]. Because the blocked goroutine could not be released even by calling Close, this resulted in a resource leak per connection [3][6]. The fix involved modifying the code to discard unsolicited global responses [3][6]. CVE-2026-39834: An integer overflow vulnerability occurred when writing data larger than 4GB in a single Write call on an SSH channel [2][4]. This overflow in the internal payload size calculation caused the write loop to enter an infinite loop, continuously sending empty packets without making progress [7][4]. The fix replaced the size comparison with an int64 type to prevent truncation [2][4]. In addition to these, v0.52.0 addressed several other issues, such as server-side panics during authentication and bypasses of certificate restrictions [1]. Users are strongly advised to update to v0.52.0 or later to mitigate these security risks [4][1].
Citations:
- 1: https://www.openwall.com/lists/oss-security/2026/05/22/6
- 2: https://nvd.nist.gov/vuln/detail/CVE-2026-39834
- 3: https://osv.dev/vulnerability/CVE-2026-39830
- 4: GHSA-rm3j-f69w-wqmq
- 5: https://www.cve.org/CVERecord?id=CVE-2026-39830
- 6: https://nvd.nist.gov/vuln/detail/CVE-2026-39830
- 7: https://pkg.go.dev/vuln/GO-2026-5020
Bump golang.org/x/crypto to v0.52.0+
hack/tools imports golang.org/x/crypto/ssh, so v0.51.0 is still in the affected range for the SSH fixes. Update the pin and refresh hack/tools/go.sum and vendor metadata.
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@hack/tools/go.mod` at line 293, Update the golang.org/x/crypto dependency in
the hack/tools module to v0.52.0 or newer, then refresh hack/tools/go.sum and
the corresponding vendor metadata so the SSH fixes are included.
Sources: Path instructions, MCP tools
|
@dependabot[bot]: all tests passed! Full PR test history. Your PR dashboard. DetailsInstructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here. |
Bumps golang.org/x/net from 0.53.0 to 0.55.0.
Commits
7770ec4go.mod: update golang.org/x dependencies4ece7b6html: escape greater-than symbol in doctype identifiers08be507html: improve Noah's Ark clause performancea8fb2fehtml: properly render fostered elements in foreign content0dc5b7ahtml: properly check namespace in "in body" any other end taga452f3chtml: ignore duplicate attributes during tokenizationf865199quic: fix appendMaxDataFrame erroneously accumulating sentLimit210ed3cquic: establish a "happened-before" relationship between stream write and readad8140equic: fix buffer slicing when handling overlapping stream data23ee2efhttp2: avoid API changes when built with go1.27Summary by CodeRabbit