From 5b1ab2c56825f9602d7044287897015c8d199c01 Mon Sep 17 00:00:00 2001 From: Niklas Ye Date: Sat, 19 Sep 2026 18:05:06 +0200 Subject: [PATCH] Move x/crypto to v0.55.0, clear of the ssh CVEs v0.10.1's image published, but scan-image refused it. trivy reports ten HIGH advisories against golang.org/x/crypto v0.49.0, CVE-2026-39828 through CVE-2026-56854, all of them in x/crypto/ssh and its agent and knownhosts packages. The last is fixed in 0.55.0 and the rest in 0.52.0. None of them is reachable here. The server imports x/crypto/bcrypt and nothing else from the module, and the image is FROM scratch, holding a single binary. But trivy scans at module granularity and cannot tell that. Shipping a known-vulnerable module version on the strength of a reachability argument is not the call to make inside a dependency pin, so the version moves instead. 9abf07f was wrong to call v0.49.0 the newest release that keeps go.mod at go 1.25.9. v0.55.0 keeps it there too; the directive is unchanged here. What had held it at 1.26 was the x/sys v0.48.0 that v0.57.0 pulled in. The `go get golang.org/x/sys@v0.42.0` meant to undo that then downgraded x/crypto to v0.49.0 to match, without being asked. x/sys now sits at v0.47.0, the version x/crypto v0.55.0 requires. Checked before tagging rather than by the pipeline: the gate passes, the Dockerfile builds on its Go 1.25 builder, and trivy, run locally with the same flags as `make security-image` (HIGH and CRITICAL, fixed only), exits 0 on the image that build produced. --- go.mod | 4 ++-- go.sum | 8 ++++---- 2 files changed, 6 insertions(+), 6 deletions(-) diff --git a/go.mod b/go.mod index fba4603..107dfe2 100644 --- a/go.mod +++ b/go.mod @@ -4,7 +4,7 @@ go 1.25.9 require ( github.com/go-chi/chi/v5 v5.2.5 - golang.org/x/crypto v0.49.0 + golang.org/x/crypto v0.55.0 modernc.org/sqlite v1.50.1 ) @@ -14,7 +14,7 @@ require ( github.com/mattn/go-isatty v0.0.20 // indirect github.com/ncruces/go-strftime v1.0.0 // indirect github.com/remyoudompheng/bigfft v0.0.0-20230129092748-24d4a6f8daec // indirect - golang.org/x/sys v0.42.0 // indirect + golang.org/x/sys v0.47.0 // indirect modernc.org/libc v1.72.3 // indirect modernc.org/mathutil v1.7.1 // indirect modernc.org/memory v1.11.0 // indirect diff --git a/go.sum b/go.sum index 03a49e2..8acc724 100644 --- a/go.sum +++ b/go.sum @@ -14,15 +14,15 @@ github.com/ncruces/go-strftime v1.0.0 h1:HMFp8mLCTPp341M/ZnA4qaf7ZlsbTc+miZjCLOF github.com/ncruces/go-strftime v1.0.0/go.mod h1:Fwc5htZGVVkseilnfgOVb9mKy6w1naJmn9CehxcKcls= github.com/remyoudompheng/bigfft v0.0.0-20230129092748-24d4a6f8daec h1:W09IVJc94icq4NjY3clb7Lk8O1qJ8BdBEF8z0ibU0rE= github.com/remyoudompheng/bigfft v0.0.0-20230129092748-24d4a6f8daec/go.mod h1:qqbHyh8v60DhA7CoWK5oRCqLrMHRGoxYCSS9EjAz6Eo= -golang.org/x/crypto v0.49.0 h1:+Ng2ULVvLHnJ/ZFEq4KdcDd/cfjrrjjNSXNzxg0Y4U4= -golang.org/x/crypto v0.49.0/go.mod h1:ErX4dUh2UM+CFYiXZRTcMpEcN8b/1gxEuv3nODoYtCA= +golang.org/x/crypto v0.55.0 h1:+KWHjbgOaAQ66dh/YlkZKHlz9ZUlq61AFirAR9ntP8M= +golang.org/x/crypto v0.55.0/go.mod h1:uq0V9dE/fzQuJtbnL+2EhWOE63vo164FY8xqEnV9xis= golang.org/x/mod v0.33.0 h1:tHFzIWbBifEmbwtGz65eaWyGiGZatSrT9prnU8DbVL8= golang.org/x/mod v0.33.0/go.mod h1:swjeQEj+6r7fODbD2cqrnje9PnziFuw4bmLbBZFrQ5w= golang.org/x/sync v0.20.0 h1:e0PTpb7pjO8GAtTs2dQ6jYa5BWYlMuX047Dco/pItO4= golang.org/x/sync v0.20.0/go.mod h1:9xrNwdLfx4jkKbNva9FpL6vEN7evnE43NNNJQ2LF3+0= golang.org/x/sys v0.6.0/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg= -golang.org/x/sys v0.42.0 h1:omrd2nAlyT5ESRdCLYdm3+fMfNFE/+Rf4bDIQImRJeo= -golang.org/x/sys v0.42.0/go.mod h1:4GL1E5IUh+htKOUEOaiffhrAeqysfVGipDYzABqnCmw= +golang.org/x/sys v0.47.0 h1:o7XGOvZQCADBQQ4Y7VNq2dRWQR7JmOUW8Kxx4ZsNgWs= +golang.org/x/sys v0.47.0/go.mod h1:4GL1E5IUh+htKOUEOaiffhrAeqysfVGipDYzABqnCmw= golang.org/x/tools v0.42.0 h1:uNgphsn75Tdz5Ji2q36v/nsFSfR/9BRFvqhGBaJGd5k= golang.org/x/tools v0.42.0/go.mod h1:Ma6lCIwGZvHK6XtgbswSoWroEkhugApmsXyrUmBhfr0= modernc.org/cc/v4 v4.28.2 h1:3tQ0lf2ADtoby2EtSP+J7IE2SHwEJdP8ioR59wx7XpY=