Skip to content

sec(deps): bump x/crypto to v0.55.0 for GO-2026-6303 - #1898

Merged
cristim merged 1 commit into
mainfrom
sec/bump-x-crypto-go-2026-6303
Aug 28, 2026
Merged

cristim merged 1 commit into
mainfrom
sec/bump-x-crypto-go-2026-6303

Conversation

@cristim

@cristim cristim commented Aug 28, 2026 •

Copy link
Copy Markdown
Member

Closes #1897

Summary

  • bump golang.org/x/crypto to v0.55.0 in the root, providers/azure, and
    providers/gcp module graphs
  • keep the change scoped to the six dependency files those modules own
  • re-run the shipped-image gate locally because source-mode scans alone do not
    reproduce this failure mode

Before

On origin/main (ae331a0c4cbe6956b0b4a2ee33c45a5118076be8):

/app/cudly (built with go1.26.6)
  FIXABLE  GO-2026-6303  in golang.org/x/crypto  fixed in v0.55.0
  no fix   GO-2026-5932  in golang.org/x/crypto  (tolerated: no published fix)

After

On this branch:

/app/cudly (built with go1.26.6)
  no fix   GO-2026-5932  in golang.org/x/crypto  (tolerated: no published fix)

GO-2026-6303 no longer appears in the shipped image scan.

Local verification

  • bash scripts/test-scan-shipped-image.sh
  • docker buildx build --load -t cudly:issue-1897-before .
  • bash scripts/scan-shipped-image.sh cudly:issue-1897-before
  • docker buildx build --load -t cudly:issue-1897-after .
  • bash scripts/scan-shipped-image.sh cudly:issue-1897-after
  • GOTOOLCHAIN=go1.26.6 GOWORK=off go list -m -json golang.org/x/crypto
  • GOTOOLCHAIN=go1.26.6 GOWORK=off go test -race -short ./...
  • GOTOOLCHAIN=go1.26.6 GOWORK=off go test -race -short ./... in
    providers/azure
  • GOTOOLCHAIN=go1.26.6 GOWORK=off go test -race -short ./... in
    providers/gcp
  • GOTOOLCHAIN=go1.26.6 golangci-lint run --timeout=10m
  • GOTOOLCHAIN=go1.26.6 go vet ./...
  • GOTOOLCHAIN=go1.26.6 GOWORK=off govulncheck ./... in root, pkg,
    providers/aws, providers/azure, and providers/gcp
  • GOTOOLCHAIN=go1.26.6 GOWORK=off go vet -tags=e2e ./... in tests/e2e
  • GOTOOLCHAIN=go1.26.6 GOWORK=off gosec -fmt sarif -out /tmp/claude/... ./...
    in root, pkg, providers/aws, providers/azure, providers/gcp, and
    tests/e2e

Diff scope

Only these files changed:

  • go.mod
  • go.sum
  • providers/azure/go.mod
  • providers/azure/go.sum
  • providers/gcp/go.mod
  • providers/gcp/go.sum

Summary by CodeRabbit

  • Chores
    • Updated foundational components supporting the application and cloud provider integrations.
    • Incorporates upstream improvements related to networking, security, synchronization, terminal support, and text processing.
    • No new user-facing features or changes to public interfaces.

- bump root, Azure, and GCP module graphs to x/crypto v0.55.0
- preserve source-mode tolerance for GO-2026-5932 with no fixed version
- prove the shipped image scan fails before and passes after the bump
@cristim

cristim commented Aug 28, 2026

Copy link
Copy Markdown
Member Author

@coderabbitai review

@coderabbitai

coderabbitai Bot commented Aug 28, 2026 •

Copy link
Copy Markdown
Contributor

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: cdbf9929-1f63-4b09-a490-ab89c39c0cba

📥 Commits

Reviewing files that changed from the base of the PR and between ae331a0 and 1b8de06.

⛔ Files ignored due to path filters (3)
  • go.sum is excluded by !**/*.sum
  • providers/azure/go.sum is excluded by !**/*.sum
  • providers/gcp/go.sum is excluded by !**/*.sum
📒 Files selected for processing (3)
  • go.mod
  • providers/azure/go.mod
  • providers/gcp/go.mod

Included review availability: 3 reviews are currently available. Your included PR review attempts over the past 7 days set your current allowance at 5 reviews per hour.


📝 Walkthrough

Walkthrough

The root, Azure provider, and GCP provider Go modules upgrade selected golang.org/x/* dependencies. The root module also upgrades golang.org/x/term. golang.org/x/oauth2 remains unchanged.

Changes

Go dependency updates

Layer / File(s) Summary
Root module dependency upgrades
go.mod
The root module upgrades x/crypto, x/net, x/sync, x/sys, x/text, and x/term. x/oauth2 remains unchanged.
Provider module dependency alignment
providers/azure/go.mod, providers/gcp/go.mod
The Azure and GCP provider modules upgrade direct x/sync and related indirect x/* dependencies.

Estimated code review effort: 1 (Trivial) | ~5 minutes

Merge Risk: ⚪ Minimal · up to 1b8de

This localized dependency update removes the affected vulnerability from the shipped image without changing application code or behavior; no actionable merge-blocking risk remains after normal checks and review.

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly identifies the main change: upgrading x/crypto to v0.55.0 to address GO-2026-6303.
Linked Issues check ✅ Passed The changes satisfy the coding objectives in [#1897]. The root, Azure, and GCP module graphs upgrade x/crypto to v0.55.0, maintain dependency consistency, and avoid unrelated dependency changes. The P…
Out of Scope Changes check ✅ Passed The changes are limited to dependency version updates required for x/crypto remediation and module-graph consistency. No unrelated source, workflow, Dockerfile, scanner, provider SDK, or Go-directive …
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Full details: Linked Issues check

Explanation

The changes satisfy the coding objectives in [#1897]. The root, Azure, and GCP module graphs upgrade x/crypto to v0.55.0, maintain dependency consistency, and avoid unrelated dependency changes. The PR objectives also report successful shipped-image scanning and required validation checks.

Full details: Out of Scope Changes check

Explanation

The changes are limited to dependency version updates required for x/crypto remediation and module-graph consistency. No unrelated source, workflow, Dockerfile, scanner, provider SDK, or Go-directive changes are reported.

Full details: Docstring Coverage

Explanation

No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0 files. (3 skipped: 3 unsupported.)

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch sec/bump-x-crypto-go-2026-6303

Comment @coderabbitai help to get the list of available commands.

@cristim cristim added triaged Item has been triaged priority/p0 Drop everything; same-day fix severity/high Significant harm urgency/now Drop other things impact/all-users Affects every user effort/s Hours type/security Security finding labels Aug 28, 2026
@cristim

cristim commented Aug 28, 2026

Copy link
Copy Markdown
Member Author

Independent adversarial verification\n\nSHA reviewed: 1b8de061554745fe6387eb9e2e897be3690919b6\nLinked issue: #1897\n\nVerdict: the six-file dependency update addresses the actual blocker behind the red Docker-image scans on open PRs. I found no confirmed scope creep, provider SDK churn, or scanner-masking behavior in this branch.\n\nWhat I attacked:\n- Diff scope: verified the branch changes only go.mod, go.sum, providers/azure/go.mod, providers/azure/go.sum, providers/gcp/go.mod, and providers/gcp/go.sum.\n- Module selection: verified root, Azure, and GCP each resolve golang.org/x/crypto v0.55.0 with module GoVersion: 1.25.0.\n- Actual failing path: built the shipped image at origin/main and reproduced the failure in scripts/scan-shipped-image.sh with FIXABLE GO-2026-6303 in golang.org/x/crypto fixed in v0.55.0 on /app/cudly.\n- Remediation path: rebuilt the same image on this branch and re-ran the same shipped-image scan. GO-2026-6303 disappeared; only GO-2026-5932 remained, which the scanner marks tolerated because no published fix exists.\n- Source-only false-green trap: rechecked the source-mode scans because this repo has already hit the case where source-mode stays green while the shipped binary is still vulnerable. Source-mode govulncheck is clean at the symbol level in root, pkg, providers/aws, providers/azure, and providers/gcp, so the artifact scan is the decisive evidence here.\n- Regression risk: root, Azure, and GCP module tests passed with GOTOOLCHAIN=go1.26.6 GOWORK=off go test -race -short ./...; root go vet ./..., golangci-lint run --timeout=10m, and standalone gosec scans also passed.\n- Historical container behavior: docker run ... /app/cudly --version exits 2 both before and after because the binary does not implement that flag; --help remains the same. That is not a regression from this bump.\n\nConclusion: merge should wait only on CI and CodeRabbit for this exact head. Once those are clean, this PR is the correct unblocker for #1884 and #1885.

@coderabbitai

coderabbitai Bot commented Aug 28, 2026 •

Copy link
Copy Markdown
Contributor
⚠️ Action not completed

Already reviewed the last commit. Use @coderabbitai full review to rerun a review of the entire changeset.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

@cristim

cristim commented Aug 28, 2026

Copy link
Copy Markdown
Member Author

Independent adversarial review

Head reviewed: 1b8de061554745fe6387eb9e2e897be3690919b6
Base reviewed: ae331a0c4cbe6956b0b4a2ee33c45a5118076be8
Linked issue: #1897

Verdict: clean for the linked P0 security issue.
Findings: NO ACTIONABLE FINDINGS.
Blockers: none for this exact head.

What I attacked:

  • Scope: the diff is limited to go.mod, go.sum, providers/azure/go.mod, providers/azure/go.sum, providers/gcp/go.mod, and providers/gcp/go.sum.
  • Dependency intent: root, Azure, and GCP resolve golang.org/x/crypto v0.55.0, with module GoVersion: 1.25.0, and no provider SDK or Go directive upgrades.
  • Generated sums: root/Azure/GCP go mod tidy -diff is empty. The root x/tools v0.48.0 checksum is explained by golang.org/x/text v0.41.0 in the module graph.
  • Remaining module scope: pkg and providers/aws do not declare or resolve golang.org/x/crypto; they only retain their pre-existing x/sync v0.21.0.
  • Failing-before evidence: Actions run 33205697618 failed in Build Docker Image because /app/cudly carried FIXABLE GO-2026-6303 in golang.org/x/crypto fixed in v0.55.0; /usr/local/bin/migrate was clean.
  • Shipped artifact after fix: no-cache local image scan found two Go binaries, /app/cudly and /usr/local/bin/migrate; no fixable advisory remained and GO-2026-6303 did not appear. The only printed advisory was GO-2026-5932, tolerated by the scanner because no fixed version exists.
  • Binary behavior: no-cache image /app/cudly --version exits 2 because that flag is not implemented; /app/cudly --help exits 0. That is existing behavior, not a dependency-bump regression.
  • Reuse and over-engineering: no new helper code, scanner allowlist, workflow change, provider SDK churn, or unrelated code path was introduced.

Local evidence, all at head 1b8de061554745fe6387eb9e2e897be3690919b6 in detached worktree /tmp/cudly-pr1898-review-1b8de061.8tYgpL:

  • git diff --name-status ae331a0c4cbe6956b0b4a2ee33c45a5118076be8..HEAD: exit 0, six dependency files only.
  • GOTOOLCHAIN=go1.26.6 GOWORK=off go list -m -json golang.org/x/crypto: exit 0 in root, providers/azure, and providers/gcp; all resolved v0.55.0.
  • GOTOOLCHAIN=go1.26.6 GOWORK=off go mod tidy -diff: exit 0 and empty in root, providers/azure, and providers/gcp.
  • GOTOOLCHAIN=go1.26.6 GOWORK=off go test -race -short ./...: exit 0 in root, providers/azure, and providers/gcp.
  • GOTOOLCHAIN=go1.26.6 go run github.com/golangci/golangci-lint/v2/cmd/golangci-lint@v2.10.1 run --timeout=10m: exit 0.
  • GOTOOLCHAIN=go1.26.6 go vet ./...: exit 0.
  • GOTOOLCHAIN=go1.26.6 go run github.com/fzipp/gocyclo/cmd/gocyclo@v0.6.0 -over 10 -ignore '_test\\.go' .: exit 0 with no findings.
  • GOTOOLCHAIN=go1.26.6 GOWORK=off go run golang.org/x/vuln/cmd/govulncheck@v1.1.4 ./...: exit 0 in root, pkg, providers/aws, providers/azure, providers/gcp, and tests/e2e.
  • GOTOOLCHAIN=go1.26.6 GOWORK=off go run github.com/securego/gosec/v2/cmd/gosec@v2.28.0 -fmt sarif -out /tmp/cudly-pr1898-gosec-<module>.sarif ./...: exit 0 in all six modules; each SARIF file had results=0.
  • npm audit --audit-level=high in frontend: exit 0, found 0 vulnerabilities.
  • docker buildx build --no-cache --load -t cudly-pr1898-review:nocache-1b8de061 --build-arg VERSION=1b8de061554745fe6387eb9e2e897be3690919b6 .: exit 0.
  • bash scripts/scan-shipped-image.sh cudly-pr1898-review:nocache-1b8de061: exit 0; scanned /app/cudly and /usr/local/bin/migrate; no fixable advisory.

CI diagnosis:

  • First CI attempt for run 33209923175 failed in Lint Code before normal linting: golangci-lint config verify timed out fetching https://golangci-lint.run/jsonschema/golangci.v2.10.jsonschema.json. This was an external schema/network timeout in the action verify phase, not a lint finding.
  • Current live PR status is green at the same head: CI - Build & Test run 33209923175 completed successfully on the rerun, CI Success is success, pre-commit and AWS/Azure sanity checks are success, and the PR merge state is CLEAN.

@cristim

cristim commented Aug 28, 2026

Copy link
Copy Markdown
Member Author

Independent adversarial review

Head reviewed: 1b8de061554745fe6387eb9e2e897be3690919b6
Base checked: ae331a0c4cbe6956b0b4a2ee33c45a5118076be8
Linked issue: #1897, from Closes #1897 in the PR body

Verdict: NO CONFIRMED FINDINGS. I found no current-head blocker for this PR.

Attacked areas:

  • Scope: live PR diff and local diff vs origin/main are exactly six module files: go.mod, go.sum, providers/azure/go.mod, providers/azure/go.sum, providers/gcp/go.mod, providers/gcp/go.sum. No Dockerfile, workflow, scanner, source, provider SDK, or Go directive change is present.
  • Dependency graph and compatibility: root, Azure, and GCP resolve golang.org/x/crypto v0.55.0. The updated golang.org/x/* modules report GoVersion: 1.25.0, compatible with the pinned go 1.26.6 toolchain. The extra root x/tools v0.48.0 checksum is accounted for by golang.org/x/text@v0.41.0's module file.
  • Shipped image: built fresh with cache disabled as cudly:pr1898-review-1b8de061; image id sha256:bcd1c6910d0110c485b3d3f9feb506c9b919fdbb9fda22e777baf5aaa74d6492, linux/arm64, created 2026-08-28T21:31:00.159640875Z.
  • Runtime behavior: /app/cudly --help exits 0. /app/cudly --version exits 2 with the existing "flag provided but not defined" behavior because this binary has no version flag.
  • Shipped-image security scan: scripts/scan-shipped-image.sh cudly:pr1898-review-1b8de061 exits 0. It scans /app/cudly and /usr/local/bin/migrate; GO-2026-6303 is absent. The only remaining advisory observed is GO-2026-5932 in golang.org/x/crypto, tolerated because it has no published fixed version.
  • Review dimensions: completeness, correctness, security, bugs, duplication, and over-engineering all came back clean against the reachable behavior and module-only scope.
  • CI and reviews: current check rollup is all success and merge state is CLEAN. CI attempt 2 is green. Attempt 1's lint failure was a remote schema-fetch timeout during golangci-lint config verify, not a lint finding. Current CodeRabbit state is non-substantive: no actionable comments and no review threads.

Commands and exit codes:

  • gh pr view 1898 --repo LeanerCloud/CUDly --json headRefOid,baseRefOid,mergeStateStatus,mergeable,statusCheckRollup exit 0: head 1b8de061554745fe6387eb9e2e897be3690919b6, mergeable MERGEABLE, non-success checks [].
  • git status --short --branch exit 0 in /private/tmp/claude/pr1898-review.gtvGT1: clean detached HEAD.
  • git diff --name-only origin/main...HEAD exit 0: six expected files only.
  • GOTOOLCHAIN=go1.26.6 GOWORK=off go list -m -json golang.org/x/crypto golang.org/x/net golang.org/x/sync golang.org/x/sys golang.org/x/text golang.org/x/term exit 0 in root, Azure, and GCP for the applicable modules.
  • GOTOOLCHAIN=go1.26.6 GOWORK=off go mod tidy -diff exit 0 in root, Azure, and GCP with no diff.
  • docker buildx build --no-cache --load -t cudly:pr1898-review-1b8de061 . exit 0.
  • docker run --rm --entrypoint /app/cudly cudly:pr1898-review-1b8de061 --help exit 0.
  • docker run --rm --entrypoint /app/cudly cudly:pr1898-review-1b8de061 --version exit 2, expected current behavior.
  • bash scripts/test-scan-shipped-image.sh exit 0.
  • bash scripts/scan-shipped-image.sh cudly:pr1898-review-1b8de061 exit 0.
  • GOTOOLCHAIN=go1.26.6 GOWORK=off go test -race -short ./... exit 0 in root, Azure, and GCP.
  • GOTOOLCHAIN=go1.26.6 go vet ./..., gocyclo -over 10 -ignore '_test\.go' ., and GOTOOLCHAIN=go1.26.6 golangci-lint run --timeout=10m exit 0 locally. Note: local golangci-lint binary is v2.11.4; CI's pinned v2.10.1 is green remotely.
  • GOTOOLCHAIN=go1.26.6 GOWORK=off govulncheck ./... exit 0 in root, Azure, GCP, pkg, AWS, and e2e modules.
  • GOTOOLCHAIN=go1.26.6 GOWORK=off gosec -fmt sarif -out /private/tmp/claude/gosec-pr1898-*.sarif ./... exit 0 in root, Azure, GCP, pkg, AWS, and e2e modules; all SARIF result counts were 0.

Findings: NO CONFIRMED FINDINGS.

@cristim

cristim commented Aug 28, 2026

Copy link
Copy Markdown
Member Author

@coderabbitai full review

@coderabbitai

coderabbitai Bot commented Aug 28, 2026 •

Copy link
Copy Markdown
Contributor
✅ Action performed

Full review finished.

@cristim
cristim merged commit 2905648 into main Aug 28, 2026
42 of 44 checks passed
cristim added a commit that referenced this pull request Sep 27, 2026
- bump root, Azure, and GCP module graphs to x/crypto v0.55.0
- preserve source-mode tolerance for GO-2026-5932 with no fixed version
- prove the shipped image scan fails before and passes after the bump
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

effort/s Hours impact/all-users Affects every user priority/p0 Drop everything; same-day fix severity/high Significant harm triaged Item has been triaged type/security Security finding urgency/now Drop other things

Projects

None yet

Development

Successfully merging this pull request may close these issues.

sec(deps): bump x/crypto for GO-2026-6303 blocking shipped-image scan

1 participant