Skip to content

fix: bump Go toolchain and golang.org/x/crypto, x/net, x/text to fix CVEs - #50

Open
sturman wants to merge 2 commits into
webdevops:mainfrom
sturman:fix/bump-x-crypto-net
Open

sturman wants to merge 2 commits into
webdevops:mainfrom
sturman:fix/bump-x-crypto-net

Conversation

@sturman

@sturman sturman commented Sep 25, 2026 •

Copy link
Copy Markdown

Bumps the Go toolchain and indirect dependencies to address known vulnerabilities reported by container image scanning (Microsoft Defender) and govulncheck. Stays on Go 1.25.

Module From To
Go toolchain go1.25.6 go1.25.14
golang.org/x/crypto v0.47.0 v0.55.0
golang.org/x/net v0.49.0 v0.57.0
golang.org/x/text v0.33.0 v0.41.0

Fixed vulnerabilities

Note: the published Docker images build with golang:1.25-alpine (GOTOOLCHAIN=local), so the toolchain bump mainly affects builds that honour the toolchain directive (e.g. release assets, local builds).

Verification (in Docker)

  • govulncheck ./... on golang:1.25-alpine and golang:1.25.6-alpine (GOTOOLCHAIN=auto → go1.25.14): no reachable vulnerabilities
  • go vet ./... and golangci-lint run: clean
  • docker build --target final-static (incl. make test + --help smoke test): OK

Remaining: GO-2026-6354 / GO-2026-6355 (x/crypto/ssh, not used) need x/crypto v0.56.0, which requires Go 1.26.

Update indirect dependencies to address known vulnerabilities:
- golang.org/x/crypto v0.47.0 -> v0.55.0
- golang.org/x/net v0.49.0 -> v0.57.0
- golang.org/x/text v0.33.0 -> v0.41.0
@sturman
sturman force-pushed the fix/bump-x-crypto-net branch from 33d3020 to bd554f5 Compare September 25, 2026 10:43
go1.25.6 is affected by multiple standard library vulnerabilities
(net/http, crypto/tls, crypto/x509, net/url, encoding/asn1, ...)
fixed in go1.25.7 through go1.25.13.
@sturman sturman changed the title fix: bump golang.org/x/crypto, x/net and x/text to fix CVEs fix: bump Go toolchain and golang.org/x/crypto, x/net, x/text to fix CVEs Oct 6, 2026
@sonarqubecloud

sonarqubecloud Bot commented Oct 6, 2026

Copy link
Copy Markdown

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant