Skip to content

Conversation

@cowbon
Copy link
Collaborator

@cowbon cowbon commented Dec 22, 2025

Upgrade golang.org/x/crypto version to address advisories
CVE-2025-47913
CVE-2025-47914
CVE-2025-58181

Upgrade golang.org/x/crypto version to address advisories
[CVE-2025-47913](GHSA-56w8-48fp-6mgv)
[CVE-2025-47914](GHSA-f6x5-jh6r-wrfv)
[CVE-2025-58181](GHSA-j5w8-q4qc-rx2x)

Signed-off-by: Ian Chin Wang <[email protected]>
@cowbon cowbon requested review from jraman567 and setrofim December 22, 2025 16:04
@jraman567
Copy link
Collaborator

Thanks, Tom!

crypto package must be at 0.43.0. So, your update to 0.45.0 looks good to me.

Let's wait for one more review.

Copy link
Collaborator

@jraman567 jraman567 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM! Thanks, Tom!

@cowbon cowbon merged commit c46900d into veraison:main Dec 22, 2025
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants