Skip to content

build(deps): bump golang.org/x/crypto to v0.56.0 (CVE-2026-78662, CVE-2026-56855) - #287

Merged
BeautyyuYanli merged 1 commit into
langgenius:mainfrom
wylswz:fix/cve-crypto-bump
Sep 9, 2026
Merged

BeautyyuYanli merged 1 commit into
langgenius:mainfrom
wylswz:fix/cve-crypto-bump

Conversation

@wylswz

@wylswz wylswz commented Sep 9, 2026

Copy link
Copy Markdown
Contributor

Summary

Image scans report two high-severity vulnerabilities in golang.org/x/crypto v0.55.0, both fixed in v0.56.0:

CVE Severity Fixed in
CVE-2026-78662 high v0.56.0
CVE-2026-56855 high v0.56.0

x/crypto v0.56.0 raises its own go directive to 1.26.0, so this also moves:

  • the module go directive: 1.25.0 -> 1.26.0
  • docker/versions.yaml versions.golang: 1.25.0 -> 1.26.8 (latest 1.26 patch)
  • the fallback ARG GOLANG_VERSION default in docker/templates/test.dockerfile, kept in sync with versions.yaml

docker/versions.yaml is the single source of truth for the toolchain used by both the generated Dockerfiles and the Set up Go step in .github/workflows/build.yml, so it has to move together with the go directive — otherwise CI would rely on implicit toolchain download.

x/crypto v0.57.0 exists but was published less than a week ago, so v0.56.0 (the version named in the advisories) was chosen instead.

Test plan

  • go mod tidy -diff reports no pending changes
  • GOOS=linux GOARCH=amd64 go build cmd/server/main.go and cmd/dependencies/init.go succeed
  • CI build workflow (amd64 + arm64 Docker image builds) passes on Go 1.26.8

Generated with Devin

…-2026-56855)

Image scans flag two high-severity vulnerabilities in golang.org/x/crypto
v0.55.0, both fixed in v0.56.0:

- CVE-2026-78662
- CVE-2026-56855

x/crypto v0.56.0 raises its own go directive to 1.26.0, so the module's go
directive and the pinned Go toolchain in docker/versions.yaml (used by both
the Docker builds and the CI build workflow) move from 1.25.0 to 1.26.8.

v0.57.0 was skipped because it was published less than a week ago.

Generated with [Devin](https://devin.ai)

Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
@wylswz
wylswz requested a review from BeautyyuYanli September 9, 2026 07:44
@BeautyyuYanli
BeautyyuYanli merged commit 14be466 into langgenius:main Sep 9, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants