Skip to content

bump: crypto v0.55.0 -> v0.56.0 (CVE-2026-56855, CVE-2026-78662) - #70

Merged
kycheng merged 1 commit into
alauda-v2.6.2from
alauda-19
Sep 15, 2026
Merged

kycheng merged 1 commit into
alauda-v2.6.2from
alauda-19

Conversation

@kycheng

@kycheng kycheng commented Sep 15, 2026

Copy link
Copy Markdown
Collaborator

Bumps golang.org/x/crypto to v0.56.0 to fix CVE-2026-56855 (SSH DoS via crafted messages, MEDIUM) and CVE-2026-78662 (SSH DoS via channel request flooding, MEDIUM).

Flagged by trivy scan of the gitlab-binary embedded binary in the gitlab-chart alauda-18.8.6 build pipeline.

🤖 Generated with Claude Code

CVE-2026-56855 (SSH DoS via crafted messages) + CVE-2026-78662
(SSH DoS via channel request flooding).

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
@kycheng
kycheng merged commit 0132ddb into alauda-v2.6.2 Sep 15, 2026
9 of 17 checks passed
@kycheng
kycheng deleted the alauda-19 branch September 15, 2026 03:08
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants