Repository navigation
sec(deps): bump x/crypto to v0.55.0 for GO-2026-6303 - #1898
Conversation
- bump root, Azure, and GCP module graphs to x/crypto v0.55.0 - preserve source-mode tolerance for GO-2026-5932 with no fixed version - prove the shipped image scan fails before and passes after the bump
|
@coderabbitai review |
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Run ID: ⛔ Files ignored due to path filters (3)
📒 Files selected for processing (3)
Included review availability: 3 reviews are currently available. Your included PR review attempts over the past 7 days set your current allowance at 5 reviews per hour. 📝 WalkthroughWalkthroughThe root, Azure provider, and GCP provider Go modules upgrade selected ChangesGo dependency updates
Estimated code review effort: 1 (Trivial) | ~5 minutes Merge Risk: ⚪ Minimal · up to This localized dependency update removes the affected vulnerability from the shipped image without changing application code or behavior; no actionable merge-blocking risk remains after normal checks and review. 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
Full details: Linked Issues checkExplanation The changes satisfy the coding objectives in [ Full details: Out of Scope Changes checkExplanation The changes are limited to dependency version updates required for x/crypto remediation and module-graph consistency. No unrelated source, workflow, Dockerfile, scanner, provider SDK, or Go-directive changes are reported. Full details: Docstring CoverageExplanation No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0 files. (3 skipped: 3 unsupported.) ✨ Finishing Touches🧪 Generate unit tests (beta)
Comment |
Independent adversarial verification\n\nSHA reviewed:
|
|
Independent adversarial reviewHead reviewed: Verdict: clean for the linked P0 security issue. What I attacked:
Local evidence, all at head
CI diagnosis:
|
Independent adversarial reviewHead reviewed: Verdict: NO CONFIRMED FINDINGS. I found no current-head blocker for this PR. Attacked areas:
Commands and exit codes:
Findings: NO CONFIRMED FINDINGS. |
|
@coderabbitai full review |
✅ Action performedFull review finished. |
- bump root, Azure, and GCP module graphs to x/crypto v0.55.0 - preserve source-mode tolerance for GO-2026-5932 with no fixed version - prove the shipped image scan fails before and passes after the bump
Closes #1897
Summary
golang.org/x/cryptotov0.55.0in the root,providers/azure, andproviders/gcpmodule graphsreproduce this failure mode
Before
On
origin/main(ae331a0c4cbe6956b0b4a2ee33c45a5118076be8):After
On this branch:
GO-2026-6303no longer appears in the shipped image scan.Local verification
bash scripts/test-scan-shipped-image.shdocker buildx build --load -t cudly:issue-1897-before .bash scripts/scan-shipped-image.sh cudly:issue-1897-beforedocker buildx build --load -t cudly:issue-1897-after .bash scripts/scan-shipped-image.sh cudly:issue-1897-afterGOTOOLCHAIN=go1.26.6 GOWORK=off go list -m -json golang.org/x/cryptoGOTOOLCHAIN=go1.26.6 GOWORK=off go test -race -short ./...GOTOOLCHAIN=go1.26.6 GOWORK=off go test -race -short ./...inproviders/azureGOTOOLCHAIN=go1.26.6 GOWORK=off go test -race -short ./...inproviders/gcpGOTOOLCHAIN=go1.26.6 golangci-lint run --timeout=10mGOTOOLCHAIN=go1.26.6 go vet ./...GOTOOLCHAIN=go1.26.6 GOWORK=off govulncheck ./...in root,pkg,providers/aws,providers/azure, andproviders/gcpGOTOOLCHAIN=go1.26.6 GOWORK=off go vet -tags=e2e ./...intests/e2eGOTOOLCHAIN=go1.26.6 GOWORK=off gosec -fmt sarif -out /tmp/claude/... ./...in root,
pkg,providers/aws,providers/azure,providers/gcp, andtests/e2eDiff scope
Only these files changed:
go.modgo.sumproviders/azure/go.modproviders/azure/go.sumproviders/gcp/go.modproviders/gcp/go.sumSummary by CodeRabbit