Skip to content

Bump golang.org/x/crypto from 0.36.0 to 0.45.0#3

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/golang.org/x/crypto-0.45.0
Open

Bump golang.org/x/crypto from 0.36.0 to 0.45.0#3
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/golang.org/x/crypto-0.45.0

Bump golang.org/x/crypto from 0.36.0 to 0.45.0

7b2524c
Select commit
Loading
Failed to load commit list.
Kusari Inspector / Kusari Inspector succeeded Nov 20, 2025 in 1m 1s

Security Analysis Passed

No security issues found

Details

Kusari Inspector

Kusari Analysis Results:

Proceed with these changes

✅ No Flagged Issues Detected
All values appear to be within acceptable risk parameters.

Both dependency and code security analyses unanimously recommend proceeding with this Dependabot update. This is a beneficial security update that fixes a known vulnerability (CVE-2025-47913) in golang.org/x/crypto, updating from the vulnerable v0.36.0 to v0.45.0. While the CVE is low severity with very low exploitation probability, updating cryptographic dependencies is a security best practice. The code analysis confirms zero security issues across all categories, with successful govulncheck validation showing no known vulnerabilities. The update comes from trusted Go extended libraries with no identified risks or business impact concerns.

Note

View full detailed analysis result for more information on the output and the checks that were run.


@kusari-inspector rerun - Trigger a re-analysis of this PR
@kusari-inspector feedback [your message] - Send feedback to our AI and team
See Kusari's documentation for setup and configuration.
Commit: 7b2524c, performed at: 2025-11-20T02:02:55Z