Repository navigation
fix(deps): upgrade golang.org/x/crypto to 0.52.0 (COMP-2448) - #71
Merged
cristianrcv merged 1 commit intoSep 14, 2026
Merged
Conversation
Addresses CVE-2026-39832 / GHSA-f5wc-c3c7-36mc: the ssh/agent client did not serialize constraint extensions when forwarding keys, silently dropping destination restrictions. x/crypto v0.52.0 requires go 1.25, so the go directive and the other golang.org/x modules move with it (MVS pulls net/sys/text/sync forward). See: https://github.com/seqeralabs/staticreg/security/dependabot/24 Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This was referenced Sep 14, 2026
munishchouhan
approved these changes
Sep 14, 2026
stefanoboriero
approved these changes
Sep 14, 2026
jonmarti
approved these changes
Sep 14, 2026
cristianrcv
deleted the
fix/COMP-2448-golang-x-crypto-agent-constraints
branch
September 14, 2026 16:58
cristianrcv
added a commit
that referenced
this pull request
Sep 15, 2026
PR #74 and #75 both proposed this upgrade to 5.9.0 and were closed without merging, so pgx stayed on the vulnerable 5.7.6 on master while COMP-2457/2458 read as resolved. This reopens the fix. Targets 5.9.2 rather than the advisories' minimum 5.9.0 so that the low-severity alert 11 (< 5.9.2) is cleared in the same change as the two critical alerts 10 and 13 (< 5.9.0). The go directive and the sibling golang.org/x modules are already current from the merged x/crypto upgrade (#71), so the diff is limited to go.mod and go.sum. Verified: go mod verify, go build ./..., go vet ./... and go test ./... all pass. Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
golang.org/x/cryptofromv0.38.0tov0.52.0x/cryptov0.52.0 requires go 1.25, so thegodirective and the siblinggolang.org/xmodules (net,sys,text,sync) move forward with it via MVSVerification
go build ./...,go vet ./...andgo test ./...all pass on this branch.JIRA
COMP-2448: Fix golang.org/x/crypto doesn't drop invoking agent constraints when forwarding keys
Security Advisory
https://github.com/seqeralabs/staticreg/security/dependabot/24
🤖 Generated with Claude Code