Skip to content

bump: crypto v0.55.0 -> v0.56.0 + go-git v5.19.1 -> v5.19.2 (CVE-2026-71556 HIGH) - #43

Merged
kycheng merged 1 commit into
alauda-v4.3.3from
alauda-36
Sep 15, 2026
Merged

kycheng merged 1 commit into
alauda-v4.3.3from
alauda-36

Conversation

@kycheng

@kycheng kycheng commented Sep 15, 2026

Copy link
Copy Markdown
Collaborator

Two crypto bumps flagged by trivy scan of the gitlab-binary embedded gomplate in the gitlab-chart alauda-18.8.6 build pipeline:

  • golang.org/x/crypto v0.55.0 -> v0.56.0 (CVE-2026-56855 SSH DoS via crafted messages, CVE-2026-78662 SSH DoS via channel request flooding, MEDIUM)
  • github.com/go-git/go-git/v5 v5.19.1 -> v5.19.2 (CVE-2026-71556 arbitrary file r/w via symlink resolution, HIGH; CVE-2026-71557 MEDIUM)

🤖 Generated with Claude Code

- golang.org/x/crypto v0.55.0 -> v0.56.0 (CVE-2026-56855, CVE-2026-78662)
- github.com/go-git/go-git/v5 v5.19.1 -> v5.19.2 (CVE-2026-71556 HIGH)

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
@kycheng
kycheng merged commit b0b562d into alauda-v4.3.3 Sep 15, 2026
1 check passed
@kycheng
kycheng deleted the alauda-36 branch September 15, 2026 03:08
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants