Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update golang.org/x/crypto digest to 23b1b90 [SECURITY] - autoclosed #494

Closed

Conversation

renovate[bot]
Copy link
Contributor

@renovate renovate bot commented Jun 16, 2023

Mend Renovate

This PR contains the following updates:

Package Type Update Change
golang.org/x/crypto indirect digest 32db794 -> 23b1b90

GitHub Vulnerability Alerts

CVE-2022-27191

golang.org/x/crypto/ssh versions 0.0.0-20220214200702-86341886e292 and prior in Go through 1.16.15 and 1.17.x through 1.17.8 allows an attacker to crash a server in certain circumstances involving AddHostKey. Version 0.0.0-20220315160706-3147a52a75dd includes a fix for the vulnerability and support for SHA-2.

CVE-2021-43565

The x/crypto/ssh package before 0.0.0-20211202192323-5770296d904e of golang.org/x/crypto allows an unauthenticated attacker to panic an SSH server.


Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate. View repository job log here.

@renovate renovate bot added the security label Jun 16, 2023
@github-actions
Copy link

github-actions bot commented Jun 16, 2023

@renovate[bot] Yikes! You better fix it before anyone else finds out! Build has Failed!

@renovate renovate bot changed the title Update golang.org/x/crypto digest to 8e447d8 [SECURITY] Update golang.org/x/crypto digest to 0ff6005 [SECURITY] Jun 18, 2023
@renovate renovate bot force-pushed the renovate/go-golang.org/x/crypto-vulnerability branch from 0afa081 to 71bba01 Compare June 18, 2023 14:42
@renovate renovate bot changed the title Update golang.org/x/crypto digest to 0ff6005 [SECURITY] Update golang.org/x/crypto digest to 8e447d8 [SECURITY] Jun 22, 2023
@renovate renovate bot force-pushed the renovate/go-golang.org/x/crypto-vulnerability branch from 71bba01 to 35860f6 Compare June 22, 2023 20:20
@renovate renovate bot changed the title Update golang.org/x/crypto digest to 8e447d8 [SECURITY] Update golang.org/x/crypto digest to 183630a [SECURITY] Jun 25, 2023
@renovate renovate bot force-pushed the renovate/go-golang.org/x/crypto-vulnerability branch from 35860f6 to b910d3e Compare June 25, 2023 08:35
@renovate renovate bot changed the title Update golang.org/x/crypto digest to 183630a [SECURITY] Update golang.org/x/crypto digest to 8e447d8 [SECURITY] Jun 27, 2023
@renovate renovate bot force-pushed the renovate/go-golang.org/x/crypto-vulnerability branch from b910d3e to 5e1cce8 Compare June 27, 2023 02:12
@renovate renovate bot changed the title Update golang.org/x/crypto digest to 8e447d8 [SECURITY] Update golang.org/x/crypto digest to 183630a [SECURITY] Jun 28, 2023
@renovate renovate bot force-pushed the renovate/go-golang.org/x/crypto-vulnerability branch 3 times, most recently from 9dd47bc to 7c09463 Compare July 2, 2023 05:11
@renovate renovate bot changed the title Update golang.org/x/crypto digest to 183630a [SECURITY] Update golang.org/x/crypto digest to 8e447d8 [SECURITY] Jul 3, 2023
@renovate renovate bot force-pushed the renovate/go-golang.org/x/crypto-vulnerability branch from 7c09463 to 18be94f Compare July 3, 2023 02:43
@renovate renovate bot changed the title Update golang.org/x/crypto digest to 8e447d8 [SECURITY] Update golang.org/x/crypto digest to 183630a [SECURITY] Jul 4, 2023
@renovate renovate bot force-pushed the renovate/go-golang.org/x/crypto-vulnerability branch from 18be94f to 653fb89 Compare July 4, 2023 17:58
@renovate renovate bot changed the title Update golang.org/x/crypto digest to 183630a [SECURITY] Update golang.org/x/crypto digest to 23b1b90 [SECURITY] Jul 5, 2023
@renovate renovate bot force-pushed the renovate/go-golang.org/x/crypto-vulnerability branch from 653fb89 to 589a4f5 Compare July 5, 2023 21:10
@renovate renovate bot changed the title Update golang.org/x/crypto digest to 23b1b90 [SECURITY] Update golang.org/x/crypto digest to e984872 [SECURITY] Jul 6, 2023
@renovate renovate bot force-pushed the renovate/go-golang.org/x/crypto-vulnerability branch from 589a4f5 to 3fc9b26 Compare July 6, 2023 02:38
@renovate renovate bot changed the title Update golang.org/x/crypto digest to e984872 [SECURITY] Update golang.org/x/crypto digest to 23b1b90 [SECURITY] Jul 9, 2023
@renovate renovate bot force-pushed the renovate/go-golang.org/x/crypto-vulnerability branch from 3fc9b26 to 89228c5 Compare July 9, 2023 05:40
@renovate renovate bot changed the title Update golang.org/x/crypto digest to 23b1b90 [SECURITY] Update golang.org/x/crypto digest to 23b1b90 [SECURITY] - autoclosed Jul 10, 2023
@renovate renovate bot closed this Jul 10, 2023
@renovate renovate bot deleted the renovate/go-golang.org/x/crypto-vulnerability branch July 10, 2023 02:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

0 participants