Summary
The shipped cudly image now fails the mandatory advisory scan because the root binary includes golang.org/x/crypto v0.53.0, which is affected by fixable advisory GO-2026-6303. The advisory is fixed in v0.55.0.
Current behavior
Every PR that runs CI - Build & Test fails in Build Docker Image at scripts/scan-shipped-image.sh, even when the PR does not touch Go dependencies. This currently blocks the open PR queue from satisfying the required green-CI merge gate.
Steps to reproduce
- Check out current
origin/main at ae331a0c4cbe6956b0b4a2ee33c45a5118076be8.
- Build the production image using the CI workflow.
- Run
bash scripts/scan-shipped-image.sh <image-tag>.
- Observe
FIXABLE GO-2026-6303 in golang.org/x/crypto fixed in v0.55.0 for /app/cudly and exit 1.
The failure is visible in Actions run 33205697618 from PR #1884.
Expected behavior
The shipped binary contains no dependency with a published fix for a detected advisory, and the Docker image scan exits 0.
Proposed fix
- Update
golang.org/x/crypto from v0.53.0 to at least v0.55.0 in the root module and keep the provider module dependency graph consistent where required.
- Run module tidy without unrelated dependency churn.
- Rebuild the production image and run
scripts/scan-shipped-image.sh against it.
- Run the root and affected provider module test suites plus the repository's pinned lint/security checks.
References
Severity
High. This is a fixable advisory in the shipped production binary and currently blocks every new PR from reaching a green merge gate.
Summary
The shipped
cudlyimage now fails the mandatory advisory scan because the root binary includesgolang.org/x/cryptov0.53.0, which is affected by fixable advisory GO-2026-6303. The advisory is fixed in v0.55.0.Current behavior
Every PR that runs
CI - Build & Testfails inBuild Docker Imageatscripts/scan-shipped-image.sh, even when the PR does not touch Go dependencies. This currently blocks the open PR queue from satisfying the required green-CI merge gate.Steps to reproduce
origin/mainatae331a0c4cbe6956b0b4a2ee33c45a5118076be8.bash scripts/scan-shipped-image.sh <image-tag>.FIXABLE GO-2026-6303 in golang.org/x/crypto fixed in v0.55.0for/app/cudlyand exit 1.The failure is visible in Actions run 33205697618 from PR #1884.
Expected behavior
The shipped binary contains no dependency with a published fix for a detected advisory, and the Docker image scan exits 0.
Proposed fix
golang.org/x/cryptofrom v0.53.0 to at least v0.55.0 in the root module and keep the provider module dependency graph consistent where required.scripts/scan-shipped-image.shagainst it.References
go.mod:67,providers/gcp/go.mod:60,providers/azure/go.mod:35Severity
High. This is a fixable advisory in the shipped production binary and currently blocks every new PR from reaching a green merge gate.