Repository navigation
Bump dependencies to fix known vulnerabilities - #371
Merged
Merged
Conversation
…, x/sys, go-pkcs12, go-ntlmssp)
mbyczkowski
marked this pull request as ready for review
September 23, 2026 17:26
randradesq
approved these changes
Sep 23, 2026
randradesq
approved these changes
Sep 23, 2026
This was referenced Sep 23, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Why
certigo's
go.modpins 6 modules at versions with 26 published Go vulnerability advisories.govulncheck ./...finds 3 that certigo's own code can reach:pkcs12.ToPEMcan accept a PKCS#12 file encoded with the wrong password. certigo calls it to read PKCS#12 files (lib/certs.go:365).x/text/unicode/norm, which can loop forever on invalid UTF-8.idna.ToUnicode, which accepts Punycode labels that decode to plain ASCII.It finds no call path to the other 23. Scanners that match by version still flag every certigo build that includes them.
What
This bumps 7 modules to newer minor or patch releases. It has no major bumps and needs no newer Go. It also bumps golangci-lint in the Lint job from v2.3.0 to v2.13.2, so Lint passes again.
golang.org/x/cryptogolang.org/x/net(indirect)golang.org/x/text(indirect)golang.org/x/sys(indirect)golang.org/x/term(indirect)software.sslmate.com/src/go-pkcs12github.com/Azure/go-ntlmssp(indirect)All 26 advisory IDs
golang.org/x/crypto: GO-2026-5005, GO-2026-5006, GO-2026-5013, GO-2026-5014, GO-2026-5015, GO-2026-5016, GO-2026-5017, GO-2026-5018, GO-2026-5019, GO-2026-5020, GO-2026-5021, GO-2026-5023, GO-2026-5033, GO-2026-6303golang.org/x/net: GO-2026-4918, GO-2026-5025, GO-2026-5026, GO-2026-5027, GO-2026-5028, GO-2026-5029, GO-2026-5030, GO-2026-5942golang.org/x/text: GO-2026-5970golang.org/x/sys: GO-2026-5024software.sslmate.com/src/go-pkcs12: GO-2026-5052github.com/Azure/go-ntlmssp: GO-2026-5543How
golang.org/xmodule moves to its newest release that still supports Go 1.25. The next release of each needs Go 1.26.x/cryptov0.55.0 requiresx/sysv0.47.0,x/termv0.45.0 andx/textv0.41.0, so those three follow it.goline ingo.modnow reads1.25.0instead of1.25. The newx/releases declarego 1.25.0, and Go orders1.25before1.25.0, sogo getrewrites the line. Both lines mean Go 1.25, and any Go 1.25 release still builds certigo.zcryptoandzlintdo not change. They have no advisories, and master holds zcrypto back on purpose for Windows (c30a3d6, e835bb6).stable, which is now 1.27. golangci-lint v2.3.0 cannot load packages compiled by Go 1.27, so Lint failed on any PR, whatever it changed. v2.3.0 fails the same way on master's code. v2.13.2 is the latest release, and it accepts.golangci.yamlas is.Three advisories remain in
govulncheck -scan module. certigo cannot reach any of them:x/crypto/ssh. Onlyx/cryptov0.56.0 fixes them, and it needs Go 1.26. certigo does not buildx/crypto/ssh. It links onlyx/crypto/ssh/terminal.x/crypto/openpgpas unmaintained. No fixed version exists. certigo does not import it.Risk
Low. certigo's own code does not change, and every bump is a minor or patch release. One behavior changes: go-pkcs12 v0.7.3 rejects malformed PKCS#12 files that v0.7.0 accepted or crashed on. These are files with a PBMAC1 key length under 20 or over 64 bytes, or a PBES2 IV that does not match the AES block size. certigo now prints an error for them.
Testing
CI builds and tests with Go
stableonly (1.27 today). These checks cover the rest:govulncheck ./...withGOOSset to darwin, linux and windows: 3 reachable advisories before, 0 after.govulncheck -scan module: 29 advisories before, 3 after (listed above).GOTOOLCHAIN=go1.25.5 go vet ./...andGOTOOLCHAIN=go1.25.5 go test ./...pass.PATH=<dir with go1.25.5 certigo>:$PATH cram tests/*.t.CGO_ENABLED=0builds with go1.25.5 pass for all 5 release targets: darwin/amd64, darwin/arm64, linux/amd64, linux/arm64 and windows/amd64. The compile check job builds amd64 only.Bigger picture
x/cryptov0.48.0).go installusers and release downloads get these fixes.Generated with Claude Code