Skip to content

chore(deps): update module golang.org/x/crypto to v0.55.0 [security] - #840

Merged
descope[bot] merged 1 commit into
mainfrom
renovate/go-golang.org-x-crypto-vulnerability
Aug 29, 2026
Merged

chore(deps): update module golang.org/x/crypto to v0.55.0 [security]#840
descope[bot] merged 1 commit into
mainfrom
renovate/go-golang.org-x-crypto-vulnerability

Conversation

@descope

@descope descope Bot commented Aug 29, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
golang.org/x/crypto v0.53.0v0.55.0 age confidence

Source-address critical option not enforced for non-public-key auth callbacks in golang.org/x/crypto/ssh

CVE-2026-56854 / GO-2026-6303

More information

Details

The source-address critical option in the Permissions returned by an authentication callback was only enforced for the PublicKeyCallback and VerifiedPublicKeyCallback paths, extending the fix for CVE-2026-46595. Permissions returned by the PasswordCallback, KeyboardInteractiveCallback, NoClientAuthCallback, and GSSAPIWithMICConfig.AllowLogin callbacks were not validated against the client's remote address, so a source-address restriction set by those callbacks was silently ignored. The check is now applied to the Permissions returned by any authentication callback.

Severity

Unknown

References

This data is provided by OSV and the Go Vulnerability Database (CC-BY 4.0).


Configuration

📅 Schedule: (in timezone Asia/Jerusalem)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate.

@descope descope Bot added the security label Aug 29, 2026
@descope
descope Bot enabled auto-merge (squash) August 29, 2026 03:57
@descope

descope Bot commented Aug 29, 2026

Copy link
Copy Markdown
Contributor Author

ℹ️ Artifact update notice

File name: descope/gin/go.mod

In order to perform the update(s) described in the table above, Renovate ran the go get command, which resulted in the following additional change(s):

  • 3 additional dependencies were updated

Details:

Package Change
golang.org/x/net v0.56.0 -> v0.57.0
golang.org/x/sys v0.46.0 -> v0.47.0
golang.org/x/text v0.39.0 -> v0.41.0
File name: go.mod

In order to perform the update(s) described in the table above, Renovate ran the go get command, which resulted in the following additional change(s):

  • 1 additional dependency was updated

Details:

Package Change
golang.org/x/sys v0.46.0 -> v0.47.0

@descope
descope Bot merged commit f1f66e9 into main Aug 29, 2026
15 checks passed
@descope
descope Bot deleted the renovate/go-golang.org-x-crypto-vulnerability branch August 29, 2026 03:59
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants