Upgrade go-git to v6.0.0-alpha.2 · Entire

Upgrade go-git to v6.0.0-alpha.2

d43e635→main·

Soph·2mo ago·17 files·+130 added/-164 removed

Closes the credential-leak advisory tracked as CVE-2026-41506
(GHSA-3xc5-wrhm-f963 / Dependabot alert #1). Our smart-HTTP path
already used Go's stdlib http.Client directly, which strips the
Authorization header on cross-host redirects since 1.8 — but
upgrading clears the alert and pulls in the upstream
http.followRedirects controls.

Alpha.2 is a major rewrite of plumbing/transport. Translation:

- *transport.Endpoint (struct) → *url.URL throughout. Field
accesses (.Scheme, .Host, .Path, .User, .Hostname()) are
unchanged. - transport.NewEndpoint → transport.ParseURL. - transport.AuthMethod (interface) is gone. Defined our own
auth.Method and gitproto.AuthMethod with a single
Authorizer(*http.Request) error method, satisfied by
*transporthttp.BasicAuth and *transporthttp.TokenAuth (whose
SetAuth methods were renamed to Authorizer). - transport.Service (typed) → string constants. Function
parameters take string. - transporthttp.NewTransport(*TransportOptions) →
NewTransport(Options) (value, not pointer). - transport.AdvertiseReferences → transport.AdvertiseRefs. - transport.UploadPackOptions → transport.UploadPackRequest;
transport.ReceivePackOptions → transport.ReceivePackRequest. - transport.Register / transport.Get were removed. The TestMain
shims in syncer/integration_test.go and cmd/git-sync/main_test.go
registered a custom HTTP transport for go-git's transport
registry, but our code never goes through that registry — it
hits the network through gitproto's own http.Client. Dropped
both shims as dead code.

Also dropped the now-unused Conn.Transport field; nothing in
git-sync read it.

Updated .golangci.yaml ireturn allowlist to permit the new
auth.Method interface where the previous transport.AuthMethod
allowance lived.

Co-Authored-By: Claude Opus 4.7 (1M context) noreply@anthropic.com

Changes

17

96 unmodified lines

97  
98  
99
100
100
101
102
103

96 unmodified lines

- github.com/go-git/go-git/v6/storage.Storer
        - github.com/go-git/go-git/v6/plumbing/storer.EncodedObjectIter
        - github.com/go-git/go-billy/v6.Filesystem
        - github.com/go-git/go-git/v6/plumbing/transport.AuthMethod
        - github.com/entirehq/git-sync/internal/auth.Method
    nolintlint:
      require-explanation: true
      require-specific: true
``

M.golangci.yaml+1/-1

22 unmodified lines

23 24 25 26 26 27 28 413 unmodified lines

442 443 444 446 445 446 447 448 449 450 451 453 452 453 454 455 49 unmodified lines

505 506 507 509 508 509 510 511 15 unmodified lines

527 528 529 531 530 531 532 533 12 unmodified lines

546 547 548 550 551 552 553 554 555 556 557 558 559

22 unmodified lines

"github.com/go-git/go-git/v6/plumbing/protocol/packp" "github.com/go-git/go-git/v6/plumbing/protocol/packp/capability" "github.com/go-git/go-git/v6/plumbing/transport" transporthttp "github.com/go-git/go-git/v6/plumbing/transport/http" "github.com/go-git/go-git/v6/storage/memory" )

413 unmodified lines

}

func (s *smartHTTPRepoServer) handleInfoRefs(w http.ResponseWriter, r *http.Request) { service := transport.Service(r.URL.Query().Get("service")) service := r.URL.Query().Get("service") if service != transport.UploadPackService && service != transport.ReceivePackService { http.Error(w, "missing service", http.StatusBadRequest) return }

var buf bytes.Buffer if err := transport.AdvertiseReferences(r.Context(), s.repo.Storer, &buf, service, false); err != nil { if err := transport.AdvertiseRefs(r.Context(), s.repo.Storer, &buf, service, false); err != nil { http.Error(w, err.Error(), http.StatusInternalServerError) return } 49 unmodified lines

var buf bytes.Buffer wc := nopWriteCloser{&buf}

err := transport.UploadPack(r.Context(), s.repo.Storer, r.Body, wc, &transport.UploadPackOptions{ err := transport.UploadPack(r.Context(), s.repo.Storer, r.Body, wc, &transport.UploadPackRequest{ StatelessRPC: true, }) if err != nil { 15 unmodified lines

var buf bytes.Buffer wc := nopWriteCloser{&buf}

err := transport.ReceivePack(r.Context(), s.repo.Storer, r.Body, wc, &transport.ReceivePackOptions{ err := transport.ReceivePack(r.Context(), s.repo.Storer, r.Body, wc, &transport.ReceivePackRequest{ StatelessRPC: true, }) if err != nil {

12 unmodified lines

type nopWriteCloser struct{ io.Writer }

func (nopWriteCloser) Close() error { return nil }

func TestMain(m *testing.M) { customHTTP := transporthttp.NewTransport(&transporthttp.TransportOptions{ Client: &http.Client{}, }) transport.Register("http", customHTTP) transport.Register("https", customHTTP)

os.Exit(m.Run()) }


Mcmd/git-sync/main_test.go+4/-15

3 unmodified lines

4 5 6 7 7 8 9 10 8 unmodified lines

19 20 21 22 22 23 24 25 26 28 29 30 27 28 29 30 31 32

3 unmodified lines

require ( github.com/go-git/go-billy/v6 v6.0.0-20260410103409-85b6241850b5 github.com/go-git/go-git/v6 v6.0.0-alpha.1 github.com/go-git/go-git/v6 v6.0.0-alpha.2 github.com/stretchr/testify v1.11.1 github.com/zalando/go-keyring v0.2.8 ) 8 unmodified lines

github.com/emirpasic/gods v1.18.1 // indirect github.com/go-git/gcfg/v2 v2.0.2 // indirect github.com/godbus/dbus/v5 v5.2.2 // indirect github.com/golang/groupcache v0.0.0-20241129210726-2c02b8208cf8 // indirect github.com/kevinburke/ssh_config v1.6.0 // indirect github.com/klauspost/cpuid/v2 v2.3.0 // indirect github.com/pjbgf/sha1cd v0.5.0 // indirect github.com/pmezard/go-difflib v1.0.0 // indirect github.com/sergi/go-diff v1.4.0 // indirect golang.org/x/crypto v0.48.0 // indirect golang.org/x/net v0.51.0 // indirect golang.org/x/sync v0.19.0 // indirect golang.org/x/crypto v0.50.0 // indirect golang.org/x/net v0.53.0 // indirect golang.org/x/sync v0.20.0 // indirect golang.org/x/sys v0.43.0 // indirect gopkg.in/yaml.v3 v3.0.1 // indirect )


Mgo.mod+4/-5

22 unmodified lines

23 24 25 26 27 28 29 26 27 28 29 30 31 32 33 32 33 34 17 unmodified lines

52 53 54 57 58 59 60 61 62 55 56 57 58 59 60 61 62 65 66 67 68 63 64 65 66 67 68 69

22 unmodified lines

github.com/go-git/gcfg/v2 v2.0.2/go.mod h1:/lv2NsxvhepuMrldsFilrgct6pxzpGdSRC13ydTLSLs= github.com/go-git/go-billy/v6 v6.0.0-20260410103409-85b6241850b5 h1:r5Y4Hn9QwQj+u6vN0Ib1MipHkanYaG8Zj0kxsnv8Bu4= github.com/go-git/go-billy/v6 v6.0.0-20260410103409-85b6241850b5/go.mod h1:CdBVp7CXl9l3sOyNEog46cP1Pvx/hjCe9AD0mtaIUYU= github.com/go-git/go-git-fixtures/v5 v5.1.2-0.20260122163445-0622d7459a67 h1:3hutPZF+/FBjR/9MdsLJ7e1mlt9pwHgwxMW7CrbmWII= github.com/go-git/go-git-fixtures/v5 v5.1.2-0.20260122163445-0622d7459a67/go.mod h1:xKt0pNHST9tYHvbiLxSY27CQWFwgIxBJuDrOE0JvbZw= github.com/go-git/go-git/v6 v6.0.0-alpha.1 h1:tGohX5luKeO50DZD0/Zqd5dYjJzKtub91S4I+1qFVIs= github.com/go-git/go-git/v6 v6.0.0-alpha.1/go.mod h1:qtzfNHlFsnq6vCw54aT4KvFWPK5bsOpTVtFC2sysdB8= github.com/go-git/go-git-fixtures/v6 v6.0.0-20260405195209-b16dd39735e0 h1:XoTsdvaghuVfIr7HpNTmFDLu2nz3I2iGqyn6Uk6MkJc= github.com/go-git/go-git-fixtures/v6 v6.0.0-20260405195209-b16dd39735e0/go.mod h1:1Lr7/vYEYyl6Ir9Ku0tKrCIRreM5zovv0Jdx2MPSM4s= github.com/go-git/go-git/v6 v6.0.0-alpha.2 h1:T3loNtDuAixNzXtlQxZhnYiYpaQ3CA4vn9RssAniEeI= github.com/go-git/go-git/v6 v6.0.0-alpha.2/go.mod h1:oCD3i19CTz7gBpeb11ZZqL91WzqbMq9avn5KpUYy/Ak= github.com/godbus/dbus/v5 v5.2.2 h1:TUR3TgtSVDmjiXOgAAyaZbYmIeP3DPkld3jgKGV8mXQ= github.com/godbus/dbus/v5 v5.2.2/go.mod h1:3AAv2+hPq5rdnr5txxxRwiGjPXamgoIHgz9FPBfOp3c= github.com/golang/groupcache v0.0.0-20241129210726-2c02b8208cf8 h1:f+oWsMOmNPc8JmEHVZIycC7hBoQxHH9pNKQORJNozsQ= github.com/golang/groupcache v0.0.0-20241129210726-2c02b8208cf8/go.mod h1:wcDNUvekVysuuOpQKo3191zZyTpiI6se1N1ULghS0sw= github.com/kevinburke/ssh_config v1.6.0 h1:J1FBfmuVosPHf5GRdltRLhPJtJpTlMdKTBjRgTaQBFY= github.com/kevinburke/ssh_config v1.6.0/go.mod h1:q2RIzfka+BXARoNexmF9gkxEX7DmvbW9P4hIVx2Kg4M= github.com/klauspost/cpuid/v2 v2.3.0 h1:S4CRMLnYUhGeDFDqkGriYKdfoFlDnMtqTiI/sFzhA9Y= 17 unmodified lines

github.com/stretchr/testify v1.11.1/go.mod h1:wZwfW3scLgRK+23gO65QZefKpKQRnfz6sD981Nm4B6U= github.com/zalando/go-keyring v0.2.8 h1:6sD/Ucpl7jNq10rM2pgqTs0sZ9V3qMrqfIIy5YPccHs= github.com/zalando/go-keyring v0.2.8/go.mod h1:tsMo+VpRq5NGyKfxoBVjCuMrG47yj8cmakZDO5QGii0= golang.org/x/crypto v0.48.0 h1:/VRzVqiRSggnhY7gNRxPauEQ5Drw9haKdM0jqfcCFts= golang.org/x/crypto v0.48.0/go.mod h1:r0kV5h3qnFPlQnBSrULhlsRfryS2pmewsg+XfMgkVos= golang.org/x/net v0.51.0 h1:94R/GTO7mt3/4wIKpcR5gkGmRLOuE/2hNGeWq/GBIFo= golang.org/x/net v0.51.0/go.mod h1:aamm+2QF5ogm02fjy5Bb7CQ0WMt1/WVM7FtyaTLlA9Y= golang.org/x/sync v0.19.0 h1:vV+1eWNmZ5geRlYjzm2adRgW2/mcpevXNg50YZtPCE4= golang.org/x/sync v0.19.0/go.mod h1:9KTHXmSnoGruLpwFjVSX0lNNA75CykiMECbovNTZqGI= golang.org/x/crypto v0.50.0 h1:zO47/JPrL6vsNkINmLoo/PH1gcxpls50DNogFvB5ZGI= golang.org/x/crypto v0.50.0/go.mod h1:3muZ7vA7PBCE6xgPX7nkzzjiUq87kRItoJQM1Yo8S+Q= golang.org/x/net v0.53.0 h1:d+qAbo5L0orcWAr0a9JweQpjXF19LMXJE8Ey7hwOdUA= golang.org/x/net v0.53.0/go.mod h1:JvMuJH7rrdiCfbeHoo3fCQU24Lf5JJwT9W3sJFulfgs= golang.org/x/sync v0.20.0 h1:e0PTpb7pjO8GAtTs2dQ6jYa5BWYlMuX047Dco/pItO4= golang.org/x/sync v0.20.0/go.mod h1:9xrNwdLfx4jkKbNva9FpL6vEN7evnE43NNNJQ2LF3+0= golang.org/x/sys v0.43.0 h1:Rlag2XtaFTxp19wS8MXlJwTvoh8ArU6ezoyFsMyCTNI= golang.org/x/sys v0.43.0/go.mod h1:4GL1E5IUh+htKOUEOaiffhrAeqysfVGipDYzABqnCmw= golang.org/x/term v0.40.0 h1:36e4zGLqU4yhjlmxEaagx2KuYbJq3EwY8K943ZsHcvg= golang.org/x/term v0.40.0/go.mod h1:w2P8uVp06p2iyKKuvXIm7N/y0UCRt3UfJTfZ7oOpglM= golang.org/x/text v0.34.0 h1:oL/Qq0Kdaqxa1KbNeMKwQq0reLCCaFtqu2eNuSeNHbk= golang.org/x/text v0.34.0/go.mod h1:homfLqTYRFyVYemLBFl5GgL/DWEiH5wcsQ5gSh1yziA= golang.org/x/term v0.42.0 h1:UiKe+zDFmJobeJ5ggPwOshJIVt6/Ft0rcfrXZDLWAWY= golang.org/x/term v0.42.0/go.mod h1:Dq/D+snpsbazcBG5+F9Q1n2rXV8Ma+71xEjTRufARgY= golang.org/x/text v0.36.0 h1:JfKh3XmcRPqZPKevfXVpI1wXPTqbkE5f7JA92a55Yxg= golang.org/x/text v0.36.0/go.mod h1:NIdBknypM8iqVmPiuco0Dh6P5Jcdk8lJL0CUebqK164= gopkg.in/check.v1 v0.0.0-20161208181325-20d25e280405/go.mod h1:Co6ibVJAznAaIkqp8huTwlJQCZ016jof/cbN4VW5Yz0= gopkg.in/check.v1 v1.0.0-20190902080502-41f04d3bba15 h1:YR8cESwS4TdDjEe65xsg0ogRM/Nc3DYOhEAlW+xobZo= gopkg.in/check.v1 v1.0.0-20190902080502-41f04d3bba15/go.mod h1:Co6ibVJAznAaIkqp8huTwlJQCZ016jof/cbN4VW5Yz0=