build(deps): bump github.com/ethereum/go-ethereum from 1.17.5 to 1.17.6 in the dependencies group - #294
build(deps): bump github.com/ethereum/go-ethereum from 1.17.5 to 1.17.6 in the dependencies group#294dependabot[bot] wants to merge 2 commits into
Conversation
Bumps the dependencies group with 1 update: [github.com/ethereum/go-ethereum](https://github.com/ethereum/go-ethereum). Updates `github.com/ethereum/go-ethereum` from 1.17.5 to 1.17.6 - [Release notes](https://github.com/ethereum/go-ethereum/releases) - [Commits](ethereum/go-ethereum@v1.17.5...v1.17.6) --- updated-dependencies: - dependency-name: github.com/ethereum/go-ethereum dependency-version: 1.17.6 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: dependencies ... Signed-off-by: dependabot[bot] <support@github.com>
There was a problem hiding this comment.
Summary
Dependabot bump of go-ethereum 1.17.5 → 1.17.6 plus the transitive dependency updates it implies, with the yaegi plugin symbols regenerated (three new symbols verified against v1.17.6 source). The geth bump itself is clean, but the implied golang.org/x/mod bump lands on v0.39.0, which carries two open OSV advisories fixed only in v0.40.0 — a trivial override fixes it.
Issues
- 🔴
go.mod:92— golang.org/x/mod v0.39.0 has open OSV advisories — see the thread on that line
Reviewed @ 33bdc244
"Bad pennies always come back." — Hungarian variant
| go.uber.org/multierr v1.11.0 // indirect | ||
| golang.org/x/crypto v0.55.0 // indirect | ||
| golang.org/x/mod v0.38.0 // indirect | ||
| golang.org/x/mod v0.39.0 // indirect |
There was a problem hiding this comment.
🔴 golang.org/x/mod v0.39.0 has open OSV advisories
OSV reports GO-2026-6179 (tlog tile verification bypass, CVE-2026-56865) and GO-2026-6180 (unauthenticated hashes in sumdb Lookup, CVE-2026-56864) against x/mod < 0.40.0. The vulnerable symbols live in golang.org/x/mod/sumdb, which nothing in this repo imports (x/mod is indirect, no direct imports found), so runtime exposure is likely nil — but v0.40.0 fixes both and MVS will accept an explicit require golang.org/x/mod v0.40.0 even with geth 1.17.6 requiring v0.39.0.
Bumps the dependencies group with 1 update: github.com/ethereum/go-ethereum.
Updates
github.com/ethereum/go-ethereumfrom 1.17.5 to 1.17.6Release notes
Sourced from github.com/ethereum/go-ethereum's releases.
... (truncated)
Commits
3d84c6bversion: release 1.17.6 (#35770)bb81e22cmd/geth, core, eth: add flag to disable precompile cache (#35753)c6e3a0dcore/txpool/blobpool: bound what the blob buffer holds (#35766)5b5c9d0core, core/types: hash the receipts alongside execution (#35738)2aaf1a1ethdb/memorydb: don't treat batch delete of the empty key as a range delete (...c1c2f8dgo.mod: update otel to 1.46.0 (#35754)23408c2core/state: fix EIP number in selfdestruct comment (#35759)89def4acore, params: schedule amsterdam fork on sepolia (#35734)a5b90d2core, eth, miner, cmd/evm: ensure the parallel state processor records otel s...19bdbb0eth/protocols/snap: port optimizations into snap v2 (#35705)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions