Skip to content

fix(deps): upgrade golang.org/x/crypto to 0.52.0 (COMP-2448) - #71

Merged
cristianrcv merged 1 commit into
masterfrom
fix/COMP-2448-golang-x-crypto-agent-constraints
Sep 14, 2026
Merged

cristianrcv merged 1 commit into
masterfrom
fix/COMP-2448-golang-x-crypto-agent-constraints

Conversation

@cristianrcv

Copy link
Copy Markdown
Contributor

Summary

  • Upgrades golang.org/x/crypto from v0.38.0 to v0.52.0
  • Resolves CVE-2026-39832 / GHSA-f5wc-c3c7-36mc (ssh/agent dropped constraint extensions when forwarding keys)
  • x/crypto v0.52.0 requires go 1.25, so the go directive and the sibling golang.org/x modules (net, sys, text, sync) move forward with it via MVS

Verification

go build ./..., go vet ./... and go test ./... all pass on this branch.

JIRA

COMP-2448: Fix golang.org/x/crypto doesn't drop invoking agent constraints when forwarding keys

Security Advisory

https://github.com/seqeralabs/staticreg/security/dependabot/24

🤖 Generated with Claude Code

Addresses CVE-2026-39832 / GHSA-f5wc-c3c7-36mc: the ssh/agent client did
not serialize constraint extensions when forwarding keys, silently
dropping destination restrictions.

x/crypto v0.52.0 requires go 1.25, so the go directive and the other
golang.org/x modules move with it (MVS pulls net/sys/text/sync forward).

See: https://github.com/seqeralabs/staticreg/security/dependabot/24

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@cristianrcv
cristianrcv merged commit a4459a5 into master Sep 14, 2026
8 checks passed
@cristianrcv
cristianrcv deleted the fix/COMP-2448-golang-x-crypto-agent-constraints branch September 14, 2026 16:58
cristianrcv added a commit that referenced this pull request Sep 15, 2026
PR #74 and #75 both proposed this upgrade to 5.9.0 and were closed
without merging, so pgx stayed on the vulnerable 5.7.6 on master while
COMP-2457/2458 read as resolved. This reopens the fix.

Targets 5.9.2 rather than the advisories' minimum 5.9.0 so that the
low-severity alert 11 (< 5.9.2) is cleared in the same change as the
two critical alerts 10 and 13 (< 5.9.0).

The go directive and the sibling golang.org/x modules are already
current from the merged x/crypto upgrade (#71), so the diff is limited
to go.mod and go.sum.

Verified: go mod verify, go build ./..., go vet ./... and go test ./...
all pass.

Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants