build(deps): bump the go_modules group across 5 directories with 12 updates - #2
build(deps): bump the go_modules group across 5 directories with 12 updates#2dependabot[bot] wants to merge 1 commit into
Conversation
…pdates Bumps the go_modules group with 10 updates in the / directory: | Package | From | To | | --- | --- | --- | | [golang.org/x/crypto](https://github.com/golang/crypto) | `0.25.0` | `0.52.0` | | [golang.org/x/oauth2](https://github.com/golang/oauth2) | `0.16.0` | `0.27.0` | | [github.com/go-viper/mapstructure/v2](https://github.com/go-viper/mapstructure) | `2.0.0-alpha.1` | `2.4.0` | | [filippo.io/edwards25519](https://github.com/FiloSottile/edwards25519) | `1.1.0` | `1.1.1` | | [github.com/cloudflare/circl](https://github.com/cloudflare/circl) | `1.3.7` | `1.6.3` | | [github.com/docker/cli](https://github.com/docker/cli) | `25.0.0+incompatible` | `29.2.0+incompatible` | | [github.com/go-git/go-billy/v5](https://github.com/go-git/go-billy) | `5.5.0` | `5.9.0` | | [github.com/go-git/go-git/v5](https://github.com/go-git/go-git) | `5.11.0` | `5.19.2` | | [github.com/ulikunitz/xz](https://github.com/ulikunitz/xz) | `0.5.11` | `0.5.14` | | [golang.org/x/image](https://github.com/golang/image) | `0.18.0` | `0.41.0` | Bumps the go_modules group with 1 update in the /gokrazy/natlabapp.arm64/builddir/github.com/gokrazy/gokrazy/cmd/dhcp directory: [golang.org/x/net](https://github.com/golang/net). Bumps the go_modules group with 1 update in the /gokrazy/natlabapp/builddir/github.com/gokrazy/gokrazy/cmd/dhcp directory: [golang.org/x/net](https://github.com/golang/net). Bumps the go_modules group with 1 update in the /gokrazy/tsapp/builddir/github.com/gokrazy/breakglass directory: [golang.org/x/crypto](https://github.com/golang/crypto). Bumps the go_modules group with 1 update in the /gokrazy/tsapp/builddir/github.com/gokrazy/gokrazy/cmd/dhcp directory: [golang.org/x/net](https://github.com/golang/net). Updates `golang.org/x/crypto` from 0.25.0 to 0.52.0 - [Commits](golang/crypto@v0.25.0...v0.52.0) Updates `golang.org/x/net` from 0.27.0 to 0.54.0 - [Commits](golang/net@v0.23.0...v0.55.0) Updates `golang.org/x/oauth2` from 0.16.0 to 0.27.0 - [Commits](golang/oauth2@v0.16.0...v0.27.0) Updates `github.com/go-viper/mapstructure/v2` from 2.0.0-alpha.1 to 2.4.0 - [Release notes](https://github.com/go-viper/mapstructure/releases) - [Changelog](https://github.com/go-viper/mapstructure/blob/main/CHANGELOG.md) - [Commits](go-viper/mapstructure@v2.0.0-alpha.1...v2.4.0) Updates `filippo.io/edwards25519` from 1.1.0 to 1.1.1 - [Commits](FiloSottile/edwards25519@v1.1.0...v1.1.1) Updates `github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream` from 1.4.10 to 1.7.16 - [Release notes](https://github.com/aws/aws-sdk-go-v2/releases) - [Commits](aws/aws-sdk-go-v2@service/m2/v1.4.10...service/eksauth/v1.7.16) Updates `github.com/cloudflare/circl` from 1.3.7 to 1.6.3 - [Release notes](https://github.com/cloudflare/circl/releases) - [Commits](cloudflare/circl@v1.3.7...v1.6.3) Updates `github.com/docker/cli` from 25.0.0+incompatible to 29.2.0+incompatible - [Commits](docker/cli@v25.0.0...v29.2.0) Updates `github.com/go-git/go-billy/v5` from 5.5.0 to 5.9.0 - [Release notes](https://github.com/go-git/go-billy/releases) - [Commits](go-git/go-billy@v5.5.0...v5.9.0) Updates `github.com/go-git/go-git/v5` from 5.11.0 to 5.19.2 - [Release notes](https://github.com/go-git/go-git/releases) - [Changelog](https://github.com/go-git/go-git/blob/main/HISTORY.md) - [Commits](go-git/go-git@v5.11.0...v5.19.2) Updates `github.com/ulikunitz/xz` from 0.5.11 to 0.5.14 - [Commits](ulikunitz/xz@v0.5.11...v0.5.14) Updates `golang.org/x/image` from 0.18.0 to 0.41.0 - [Commits](golang/image@v0.18.0...v0.41.0) Updates `golang.org/x/net` from 0.23.0 to 0.55.0 - [Commits](golang/net@v0.23.0...v0.55.0) Updates `golang.org/x/net` from 0.23.0 to 0.55.0 - [Commits](golang/net@v0.23.0...v0.55.0) Updates `golang.org/x/crypto` from 0.17.0 to 0.52.0 - [Commits](golang/crypto@v0.25.0...v0.52.0) Updates `golang.org/x/net` from 0.23.0 to 0.55.0 - [Commits](golang/net@v0.23.0...v0.55.0) --- updated-dependencies: - dependency-name: golang.org/x/crypto dependency-version: 0.52.0 dependency-type: direct:production dependency-group: go_modules - dependency-name: golang.org/x/net dependency-version: 0.54.0 dependency-type: direct:production dependency-group: go_modules - dependency-name: golang.org/x/oauth2 dependency-version: 0.27.0 dependency-type: direct:production dependency-group: go_modules - dependency-name: github.com/go-viper/mapstructure/v2 dependency-version: 2.4.0 dependency-type: indirect dependency-group: go_modules - dependency-name: filippo.io/edwards25519 dependency-version: 1.1.1 dependency-type: indirect dependency-group: go_modules - dependency-name: github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream dependency-version: 1.7.16 dependency-type: indirect dependency-group: go_modules - dependency-name: github.com/cloudflare/circl dependency-version: 1.6.3 dependency-type: indirect dependency-group: go_modules - dependency-name: github.com/docker/cli dependency-version: 29.2.0+incompatible dependency-type: indirect dependency-group: go_modules - dependency-name: github.com/go-git/go-billy/v5 dependency-version: 5.9.0 dependency-type: indirect dependency-group: go_modules - dependency-name: github.com/go-git/go-git/v5 dependency-version: 5.19.2 dependency-type: indirect dependency-group: go_modules - dependency-name: github.com/ulikunitz/xz dependency-version: 0.5.14 dependency-type: indirect dependency-group: go_modules - dependency-name: golang.org/x/image dependency-version: 0.41.0 dependency-type: indirect dependency-group: go_modules - dependency-name: golang.org/x/net dependency-version: 0.55.0 dependency-type: indirect dependency-group: go_modules - dependency-name: golang.org/x/net dependency-version: 0.55.0 dependency-type: indirect dependency-group: go_modules - dependency-name: golang.org/x/crypto dependency-version: 0.52.0 dependency-type: indirect dependency-group: go_modules - dependency-name: golang.org/x/net dependency-version: 0.55.0 dependency-type: indirect dependency-group: go_modules ... Signed-off-by: dependabot[bot] <support@github.com>
There was a problem hiding this comment.
Cursor Bugbot has reviewed your changes and found 1 potential issue.
❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, have a team admin enable autofix in the Cursor dashboard.
Reviewed by Cursor Bugbot for commit fa0f82b. Configure here.
| golang.org/x/sync v0.0.0-20210220032951-036812b2e83c // indirect | ||
| golang.org/x/sys v0.20.0 // indirect | ||
| ) | ||
| go 1.25.0 |
There was a problem hiding this comment.
Gokrazy modules lost all dependencies
High Severity
Dependabot wiped the entire require blocks from these gokrazy builddir modules and emptied their go.sum files instead of bumping golang.org/x/net / golang.org/x/crypto. These directories have no .go sources, so go mod tidy treats every dependency as unused. Gokrazy image builds that rely on those pinned graphs will lose their dependency locks.
Additional Locations (2)
Reviewed by Cursor Bugbot for commit fa0f82b. Configure here.


Bumps the go_modules group with 10 updates in the / directory:
0.25.00.52.00.16.00.27.02.0.0-alpha.12.4.01.1.01.1.11.3.71.6.325.0.0+incompatible29.2.0+incompatible5.5.05.9.05.11.05.19.20.5.110.5.140.18.00.41.0Bumps the go_modules group with 1 update in the /gokrazy/natlabapp.arm64/builddir/github.com/gokrazy/gokrazy/cmd/dhcp directory: golang.org/x/net.
Bumps the go_modules group with 1 update in the /gokrazy/natlabapp/builddir/github.com/gokrazy/gokrazy/cmd/dhcp directory: golang.org/x/net.
Bumps the go_modules group with 1 update in the /gokrazy/tsapp/builddir/github.com/gokrazy/breakglass directory: golang.org/x/crypto.
Bumps the go_modules group with 1 update in the /gokrazy/tsapp/builddir/github.com/gokrazy/gokrazy/cmd/dhcp directory: golang.org/x/net.
Updates
golang.org/x/cryptofrom 0.25.0 to 0.52.0Commits
a1c0d99go.mod: update golang.org/x dependencies3c7c869ssh: fix deadlock on unexpected channel responses533fb3fssh: fix source-address critical option bypassabbc44dssh: fix incorrect operator ordere052873ssh: fix infinite loop on large channel writes due to integer overflowb61cf85ssh: enforce user presence verification for security keys9c2cd33ssh: enforce strict limits on DSA key parameters8907318ssh: reject RSA keys with excessively large moduliffd87b4ssh: fix panic when authority callbacks are nil4e7a738ssh: fix deadlock on unexpected global responsesUpdates
golang.org/x/netfrom 0.27.0 to 0.54.0Commits
7770ec4go.mod: update golang.org/x dependencies4ece7b6html: escape greater-than symbol in doctype identifiers08be507html: improve Noah's Ark clause performancea8fb2fehtml: properly render fostered elements in foreign content0dc5b7ahtml: properly check namespace in "in body" any other end taga452f3chtml: ignore duplicate attributes during tokenizationf865199quic: fix appendMaxDataFrame erroneously accumulating sentLimit210ed3cquic: establish a "happened-before" relationship between stream write and readad8140equic: fix buffer slicing when handling overlapping stream data23ee2efhttp2: avoid API changes when built with go1.27Updates
golang.org/x/oauth2from 0.16.0 to 0.27.0Commits
681b4d8jws: split token into fixed number of parts3f78298all: upgrade go directive to at least 1.23.0 [generated]109dabfendpoints: add links/provider for Discordac571faoauth2: fix docs for Config.DeviceAuth314ee5bendpoints: add patreon endpointb9c813bgoogle: add warning about externally-provided credentials49a531dall: make method and struct comments match the names22134a4README: don't recommend go get3e64809x/oauth2: add Token.ExpiresIn16a9973jwt: rename example to avoid vet errorUpdates
github.com/go-viper/mapstructure/v2from 2.0.0-alpha.1 to 2.4.0Release notes
Sourced from github.com/go-viper/mapstructure/v2's releases.
... (truncated)
Commits
b9794a5Merge pull request #119 from go-viper/string-to-weak-slice17cdcb0feat: add back previous StringToSlice as a weak function3caca36Merge pull request #117 from ErfanMomeniii/main9a861bcMerge pull request #107 from peczenyj/patch-286ed5b5refactor: updateace5b4echore: add interface any linter1a4f1aeMerge pull request #118 from go-viper/generic-testsa268909fix: lint17f1fd4test: add more commentsb48c856test: expand testsUpdates
filippo.io/edwards25519from 1.1.0 to 1.1.1Commits
d1c650aextra: initialize receiver in MultiScalarMultUpdates
github.com/aws/aws-sdk-go-v2/aws/protocol/eventstreamfrom 1.4.10 to 1.7.16Commits
e2e9697Release 2025-01-316576a09Regenerated Clientsf762573Update API modelc94df29add transfer manager doc header (#2990)880543crevert the revert on the transfer manager beta (#2993)8da49e5switch to code-generated waiters for remaining services (#2994)c7c6865Release 2025-01-3070f736cRegenerated Clients28731c2Update endpoints model3505e4bUpdate API modelUpdates
github.com/cloudflare/circlfrom 1.3.7 to 1.6.3Release notes
Sourced from github.com/cloudflare/circl's releases.
... (truncated)
Commits
24ae53cRelease CIRCL v1.6.3581020bRename method to oddMultiplesProjective.12209a4Removing unused cmov for jacobian points.fcba359ecc/p384: use of complete projective formulas for scalar multiplication.5e1bae8ecc/p384: handle point doubling in point addition with Jacobian coordinates.3416046Check opts for nil value.a763d47Release CIRCL v1.6.23c70bf9Bump x/crypto x/sys dependencies.3f0f15bRevert to using package-declared HPKE errors for shortkem instead of standard...23491bdAdding generic Power2Round method.Updates
github.com/docker/clifrom 25.0.0+incompatible to 29.2.0+incompatibleCommits
0b9d198Merge pull request #6764 from vvoland/update-docker9c9ec73vendor: github.com/moby/moby/client v0.2.2bab3e81vendor: github.com/moby/moby/api v1.53.02e64fc1Merge pull request #6367 from thaJeztah/template_slicejoin1f2ba2aMerge pull request #6760 from thaJeztah/container_create_fix_errore34a342templates: make "join" work with non-string slices and map valuesa86356dMerge pull request #6763 from thaJeztah/bump_mapstructure771660avendor: github.com/go-viper/mapstructure/v2 v2.5.09cff36bMerge pull request #6762 from thaJeztah/bump_x_deps08ed2bccli/command/container: make injecting config.json failures a warningUpdates
github.com/go-git/go-billy/v5from 5.5.0 to 5.9.0Release notes
Sourced from github.com/go-git/go-billy/v5's releases.
... (truncated)
Commits
237e529Merge pull request #206 from pjbgf/v5-improvements04edb39build: Add go-git integration testd8efefdosfs: preserve empty ChrootOS base07f2a0bMerge pull request #205 from pjbgf/v5-improvements25207c8build: Bump Go versions in workflows2fda229osfs: ChrootOS eval baseDir on creation427b27fMerge pull request #203 from pjbgf/v5-improvements7d5a23echroot: Reject symlink loops2c2287autil: avoid following symlinks in RemoveAll fallbackcbd88e9Fix mount path handlingUpdates
github.com/go-git/go-git/v5from 5.11.0 to 5.19.2Release notes
Sourced from github.com/go-git/go-git/v5's releases.
... (truncated)
Commits
3eeb238Merge pull request #2277 from go-git/checkout-v5008a78fgit: worktree, make the filesystem wrapper a symlink-safe boundary2263fb5Merge pull request #2268 from go-git/renovate/releases/v5.x-go-golang.org-x-t...77b7625build: Update module golang.org/x/text to v0.39.0 [SECURITY]85ea767Merge pull request #2267 from go-git/renovate/releases/v5.x-go-golang.org-x-n...198675abuild: Update module golang.org/x/net to v0.56.0 [SECURITY]4a0e66dMerge pull request #2254 from pjbgf/v5-dotgit-ref-name-containment3b306efstorage: dotgit, align reference-name safety with refname_is_safef3d0cc1storage: dotgit, reject path traversal in reference names979cfe9Merge pull request #2262 from joshblum/joshblum/to-slash-v5Updates
github.com/ulikunitz/xzfrom 0.5.11 to 0.5.14Commits
7184815Preparation of release v0.5.1488ddf1dAddress Security Issue GHSA-jc7w-c686-c4v9c8314b8Add new package xio with WriteCloserStack4f11dceUpdate README.md and SECURITY.md to address security questionsf56ebbfTODO.md: fix a typoUpdates
golang.org/x/imagefrom 0.18.0 to 0.41.0Commits
0d61147bmp: reject input with invalid palette indexfe8ae45tiff: limit PackBits decompression output size542a3d9go.mod: update golang.org/x dependencies5cbe89atiff: reject 0-size images3d5c9b6go.mod: update golang.org/x dependencies854c274font/sfnt: apply bounds checks before allocating read buffer96edba0webp: reject VP8X headers with too-large canvases23ae9edtiff: cap buffer growth to prevent OOM from malicious IFD offsete589e60webp: allow VP8L + VP8X(with alpha)fe7d73dgo.mod: update golang.org/x dependenciesUpdates
golang.org/x/netfrom 0.23.0 to 0.55.0Commits
7770ec4go.mod: update golang.org/x dependencies4ece7b6html: escape greater-than symbol in doctype identifiers08be507html: improve Noah's Ark clause performancea8fb2fehtml: properly render fostered elements in foreign content0dc5b7ahtml: properly check namespace in "in body" any other end taga452f3chtml: ignore duplicate attributes during tokenizationf865199quic: fix appendMaxDataFrame erroneously accumulating sentLimit210ed3cquic: establish a "happened-before" relationship between stream write and readad8140equic: fix buffer slicing when handling overlapping stream data23ee2efhttp2: avoid API changes when built with go1.27Updates
golang.org/x/netfrom 0.23.0 to 0.55.0Commits
7770ec4go.mod: update golang.org/x dependencies4ece7b6html: escape greater-than symbol in doctype identifiers08be507html: improve Noah's Ark clause performancea8fb2fehtml: properly render fostered elements in foreign content0dc5b7ahtml: properly check namespace in "in body" any other end taga452f3chtml: ignore duplicate attributes during tokenizationf865199quic: fix appendMaxDataFrame erroneously accumulating sentLimit210ed3cquic: establish a "happened-before" relationship between stream write and readad8140equic: fix buffer slicing when handling overlapping stream data23ee2efhttp2: avoid API changes when built with go1.27Updates
golang.org/x/cryptofrom 0.17.0 to 0.52.0Commits
a1c0d99go.mod: update golang.org/x dependencies3c7c869ssh: fix deadlock on unexpected channel responses533fb3fssh: fix source-address critical option bypassabbc44dssh: fix incorrect operator ordere052873ssh: fix infinite loop on large channel writes due to integer overflowb61cf85ssh: enforce user presence verification for security keys9c2cd33ssh: enforce strict limits on DSA key parameters8907318ssh: reject RSA keys with excessively large moduliffd87b4ssh: fix panic when authority callbacks are nil4e7a738ssh: fix deadlock on unexpected global responsesUpdates
golang.org/x/netfrom 0.23.0 to 0.55.0Commits
7770ec4go.mod: update golang.org/x dependencies4ece7b6html: escape greater-than symbol in doctype identifiers08be507html: improve Noah's Ark clause performancea8fb2fehtml: properly render fostered elements in foreign content0dc5b7ahtml: properly check namespace in "in body" any other end taga452f3chtml: ignore duplicate attributes during tokenizationf865199quic: fix appendMaxDataFrame erroneously accumulating sentLimit210ed3cquic: establish a "happened-before" relationship between stream write and readad8140equic: fix buffer slicing when handling overlapping stream data23ee2efhttp2: avoid API changes when built with go1.27Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditionsYou can disable automated security fix PRs for this repo from the Security Alerts page.
Note
Medium Risk
Wide bumps to crypto, net, and oauth2 affect networking and auth paths indirectly, and go-git/path-securejoin changes touch git-based tooling; risk is moderated because there are no first-party code edits, only lockfile updates.
Overview
Raises the module toolchain to Go 1.25 and refreshes
go.mod/go.sumacross the repo, including a broad bump ofgolang.org/x/*(notably crypto, net, oauth2, sys, tools) and several indirect build/release dependencies (AWS SDK v2, go-git stack, docker/cli, cloudflare/circl, cyphar/filepath-securejoin, ulikunitz/xz, etc.).google.golang.org/appengineis dropped from the indirect require list in the lockfile.For gokrazy embedded build stubs under
gokrazy/*/builddir/..., the PR alignsgoto 1.25.0 and strips the previousrequireblocks andgo.sumentries for dhcp/breakglass helper modules—those trees are now minimal two- or three-linego.modfiles only.No application Go source changes; impact is entirely on build tooling, transitive security fixes, and CI/developer Go version expectations.
Reviewed by Cursor Bugbot for commit fa0f82b. Bugbot is set up for automated code reviews on this repo. Configure here.