Upgrade go-git to v6.0.0-alpha.2 · Entire
Upgrade go-git to v6.0.0-alpha.2
d43e635→main·
Soph·2mo ago·17 files·+130 added/-164 removed
Closes the credential-leak advisory tracked as CVE-2026-41506
(GHSA-3xc5-wrhm-f963 / Dependabot alert #1). Our smart-HTTP path
already used Go's stdlib http.Client directly, which strips the
Authorization header on cross-host redirects since 1.8 — but
upgrading clears the alert and pulls in the upstream
http.followRedirects controls.
Alpha.2 is a major rewrite of plumbing/transport. Translation:
- *transport.Endpoint (struct) → *url.URL throughout. Field
accesses (.Scheme, .Host, .Path, .User, .Hostname()) are
unchanged.
- transport.NewEndpoint → transport.ParseURL.
- transport.AuthMethod (interface) is gone. Defined our own
auth.Method and gitproto.AuthMethod with a single
Authorizer(*http.Request) error method, satisfied by
*transporthttp.BasicAuth and *transporthttp.TokenAuth (whose
SetAuth methods were renamed to Authorizer).
- transport.Service (typed) → string constants. Function
parameters take string.
- transporthttp.NewTransport(*TransportOptions) →
NewTransport(Options) (value, not pointer).
- transport.AdvertiseReferences → transport.AdvertiseRefs.
- transport.UploadPackOptions → transport.UploadPackRequest;
transport.ReceivePackOptions → transport.ReceivePackRequest.
- transport.Register / transport.Get were removed. The TestMain
shims in syncer/integration_test.go and cmd/git-sync/main_test.go
registered a custom HTTP transport for go-git's transport
registry, but our code never goes through that registry — it
hits the network through gitproto's own http.Client. Dropped
both shims as dead code.
Also dropped the now-unused Conn.Transport field; nothing in
git-sync read it.
Updated .golangci.yaml ireturn allowlist to permit the new
auth.Method interface where the previous transport.AuthMethod
allowance lived.
Co-Authored-By: Claude Opus 4.7 (1M context) noreply@anthropic.com
Changes
17
M.golangci.yaml+1/-1
cmd/git-sync
Mmain_test.go+4/-15
Mgo.mod+4/-5
Mgo.sum+14/-16
internal
auth
Mauth.go+13/-5
Mauth_test.go+19/-23
Mentiredb.go+3/-4
gitproto
Mfetch_test.go+13/-13
Mpush_test.go+3/-3
Mrefs.go+1/-1
Msmarthttp.go+37/-34
Msmarthttp_test.go+6/-9
strategy/bootstrap
Mbootstrap_test.go+2/-2
syncer
Mauth_test.go+3/-3
Mintegration_test.go+3/-26
Msyncer.go+1/-1
pkg/gitsync
Mclient_test.go+3/-3
96 unmodified lines
97
98
99
100
100
101
102
103
96 unmodified lines
- github.com/go-git/go-git/v6/storage.Storer
- github.com/go-git/go-git/v6/plumbing/storer.EncodedObjectIter
- github.com/go-git/go-billy/v6.Filesystem
- github.com/go-git/go-git/v6/plumbing/transport.AuthMethod
- github.com/entirehq/git-sync/internal/auth.Method
nolintlint:
require-explanation: true
require-specific: true
``
M.golangci.yaml+1/-1
22 unmodified lines
23 24 25 26 26 27 28 413 unmodified lines
442 443 444 446 445 446 447 448 449 450 451 453 452 453 454 455 49 unmodified lines
505 506 507 509 508 509 510 511 15 unmodified lines
527 528 529 531 530 531 532 533 12 unmodified lines
546 547 548 550 551 552 553 554 555 556 557 558 559
22 unmodified lines
"github.com/go-git/go-git/v6/plumbing/protocol/packp" "github.com/go-git/go-git/v6/plumbing/protocol/packp/capability" "github.com/go-git/go-git/v6/plumbing/transport" transporthttp "github.com/go-git/go-git/v6/plumbing/transport/http" "github.com/go-git/go-git/v6/storage/memory" )
413 unmodified lines
}
func (s *smartHTTPRepoServer) handleInfoRefs(w http.ResponseWriter, r *http.Request) { service := transport.Service(r.URL.Query().Get("service")) service := r.URL.Query().Get("service") if service != transport.UploadPackService && service != transport.ReceivePackService { http.Error(w, "missing service", http.StatusBadRequest) return }
var buf bytes.Buffer if err := transport.AdvertiseReferences(r.Context(), s.repo.Storer, &buf, service, false); err != nil { if err := transport.AdvertiseRefs(r.Context(), s.repo.Storer, &buf, service, false); err != nil { http.Error(w, err.Error(), http.StatusInternalServerError) return } 49 unmodified lines
var buf bytes.Buffer wc := nopWriteCloser{&buf}
err := transport.UploadPack(r.Context(), s.repo.Storer, r.Body, wc, &transport.UploadPackOptions{ err := transport.UploadPack(r.Context(), s.repo.Storer, r.Body, wc, &transport.UploadPackRequest{ StatelessRPC: true, }) if err != nil { 15 unmodified lines
var buf bytes.Buffer wc := nopWriteCloser{&buf}
err := transport.ReceivePack(r.Context(), s.repo.Storer, r.Body, wc, &transport.ReceivePackOptions{ err := transport.ReceivePack(r.Context(), s.repo.Storer, r.Body, wc, &transport.ReceivePackRequest{ StatelessRPC: true, }) if err != nil {
12 unmodified lines
type nopWriteCloser struct{ io.Writer }
func (nopWriteCloser) Close() error { return nil }
func TestMain(m *testing.M) { customHTTP := transporthttp.NewTransport(&transporthttp.TransportOptions{ Client: &http.Client{}, }) transport.Register("http", customHTTP) transport.Register("https", customHTTP)
os.Exit(m.Run()) }
Mcmd/git-sync/main_test.go+4/-15
3 unmodified lines
4 5 6 7 7 8 9 10 8 unmodified lines
19 20 21 22 22 23 24 25 26 28 29 30 27 28 29 30 31 32
3 unmodified lines
require ( github.com/go-git/go-billy/v6 v6.0.0-20260410103409-85b6241850b5 github.com/go-git/go-git/v6 v6.0.0-alpha.1 github.com/go-git/go-git/v6 v6.0.0-alpha.2 github.com/stretchr/testify v1.11.1 github.com/zalando/go-keyring v0.2.8 ) 8 unmodified lines
github.com/emirpasic/gods v1.18.1 // indirect github.com/go-git/gcfg/v2 v2.0.2 // indirect github.com/godbus/dbus/v5 v5.2.2 // indirect github.com/golang/groupcache v0.0.0-20241129210726-2c02b8208cf8 // indirect github.com/kevinburke/ssh_config v1.6.0 // indirect github.com/klauspost/cpuid/v2 v2.3.0 // indirect github.com/pjbgf/sha1cd v0.5.0 // indirect github.com/pmezard/go-difflib v1.0.0 // indirect github.com/sergi/go-diff v1.4.0 // indirect golang.org/x/crypto v0.48.0 // indirect golang.org/x/net v0.51.0 // indirect golang.org/x/sync v0.19.0 // indirect golang.org/x/crypto v0.50.0 // indirect golang.org/x/net v0.53.0 // indirect golang.org/x/sync v0.20.0 // indirect golang.org/x/sys v0.43.0 // indirect gopkg.in/yaml.v3 v3.0.1 // indirect )
Mgo.mod+4/-5
22 unmodified lines
23 24 25 26 27 28 29 26 27 28 29 30 31 32 33 32 33 34 17 unmodified lines
52 53 54 57 58 59 60 61 62 55 56 57 58 59 60 61 62 65 66 67 68 63 64 65 66 67 68 69
22 unmodified lines
github.com/go-git/gcfg/v2 v2.0.2/go.mod h1:/lv2NsxvhepuMrldsFilrgct6pxzpGdSRC13ydTLSLs= github.com/go-git/go-billy/v6 v6.0.0-20260410103409-85b6241850b5 h1:r5Y4Hn9QwQj+u6vN0Ib1MipHkanYaG8Zj0kxsnv8Bu4= github.com/go-git/go-billy/v6 v6.0.0-20260410103409-85b6241850b5/go.mod h1:CdBVp7CXl9l3sOyNEog46cP1Pvx/hjCe9AD0mtaIUYU= github.com/go-git/go-git-fixtures/v5 v5.1.2-0.20260122163445-0622d7459a67 h1:3hutPZF+/FBjR/9MdsLJ7e1mlt9pwHgwxMW7CrbmWII= github.com/go-git/go-git-fixtures/v5 v5.1.2-0.20260122163445-0622d7459a67/go.mod h1:xKt0pNHST9tYHvbiLxSY27CQWFwgIxBJuDrOE0JvbZw= github.com/go-git/go-git/v6 v6.0.0-alpha.1 h1:tGohX5luKeO50DZD0/Zqd5dYjJzKtub91S4I+1qFVIs= github.com/go-git/go-git/v6 v6.0.0-alpha.1/go.mod h1:qtzfNHlFsnq6vCw54aT4KvFWPK5bsOpTVtFC2sysdB8= github.com/go-git/go-git-fixtures/v6 v6.0.0-20260405195209-b16dd39735e0 h1:XoTsdvaghuVfIr7HpNTmFDLu2nz3I2iGqyn6Uk6MkJc= github.com/go-git/go-git-fixtures/v6 v6.0.0-20260405195209-b16dd39735e0/go.mod h1:1Lr7/vYEYyl6Ir9Ku0tKrCIRreM5zovv0Jdx2MPSM4s= github.com/go-git/go-git/v6 v6.0.0-alpha.2 h1:T3loNtDuAixNzXtlQxZhnYiYpaQ3CA4vn9RssAniEeI= github.com/go-git/go-git/v6 v6.0.0-alpha.2/go.mod h1:oCD3i19CTz7gBpeb11ZZqL91WzqbMq9avn5KpUYy/Ak= github.com/godbus/dbus/v5 v5.2.2 h1:TUR3TgtSVDmjiXOgAAyaZbYmIeP3DPkld3jgKGV8mXQ= github.com/godbus/dbus/v5 v5.2.2/go.mod h1:3AAv2+hPq5rdnr5txxxRwiGjPXamgoIHgz9FPBfOp3c= github.com/golang/groupcache v0.0.0-20241129210726-2c02b8208cf8 h1:f+oWsMOmNPc8JmEHVZIycC7hBoQxHH9pNKQORJNozsQ= github.com/golang/groupcache v0.0.0-20241129210726-2c02b8208cf8/go.mod h1:wcDNUvekVysuuOpQKo3191zZyTpiI6se1N1ULghS0sw= github.com/kevinburke/ssh_config v1.6.0 h1:J1FBfmuVosPHf5GRdltRLhPJtJpTlMdKTBjRgTaQBFY= github.com/kevinburke/ssh_config v1.6.0/go.mod h1:q2RIzfka+BXARoNexmF9gkxEX7DmvbW9P4hIVx2Kg4M= github.com/klauspost/cpuid/v2 v2.3.0 h1:S4CRMLnYUhGeDFDqkGriYKdfoFlDnMtqTiI/sFzhA9Y= 17 unmodified lines
github.com/stretchr/testify v1.11.1/go.mod h1:wZwfW3scLgRK+23gO65QZefKpKQRnfz6sD981Nm4B6U= github.com/zalando/go-keyring v0.2.8 h1:6sD/Ucpl7jNq10rM2pgqTs0sZ9V3qMrqfIIy5YPccHs= github.com/zalando/go-keyring v0.2.8/go.mod h1:tsMo+VpRq5NGyKfxoBVjCuMrG47yj8cmakZDO5QGii0= golang.org/x/crypto v0.48.0 h1:/VRzVqiRSggnhY7gNRxPauEQ5Drw9haKdM0jqfcCFts= golang.org/x/crypto v0.48.0/go.mod h1:r0kV5h3qnFPlQnBSrULhlsRfryS2pmewsg+XfMgkVos= golang.org/x/net v0.51.0 h1:94R/GTO7mt3/4wIKpcR5gkGmRLOuE/2hNGeWq/GBIFo= golang.org/x/net v0.51.0/go.mod h1:aamm+2QF5ogm02fjy5Bb7CQ0WMt1/WVM7FtyaTLlA9Y= golang.org/x/sync v0.19.0 h1:vV+1eWNmZ5geRlYjzm2adRgW2/mcpevXNg50YZtPCE4= golang.org/x/sync v0.19.0/go.mod h1:9KTHXmSnoGruLpwFjVSX0lNNA75CykiMECbovNTZqGI= golang.org/x/crypto v0.50.0 h1:zO47/JPrL6vsNkINmLoo/PH1gcxpls50DNogFvB5ZGI= golang.org/x/crypto v0.50.0/go.mod h1:3muZ7vA7PBCE6xgPX7nkzzjiUq87kRItoJQM1Yo8S+Q= golang.org/x/net v0.53.0 h1:d+qAbo5L0orcWAr0a9JweQpjXF19LMXJE8Ey7hwOdUA= golang.org/x/net v0.53.0/go.mod h1:JvMuJH7rrdiCfbeHoo3fCQU24Lf5JJwT9W3sJFulfgs= golang.org/x/sync v0.20.0 h1:e0PTpb7pjO8GAtTs2dQ6jYa5BWYlMuX047Dco/pItO4= golang.org/x/sync v0.20.0/go.mod h1:9xrNwdLfx4jkKbNva9FpL6vEN7evnE43NNNJQ2LF3+0= golang.org/x/sys v0.43.0 h1:Rlag2XtaFTxp19wS8MXlJwTvoh8ArU6ezoyFsMyCTNI= golang.org/x/sys v0.43.0/go.mod h1:4GL1E5IUh+htKOUEOaiffhrAeqysfVGipDYzABqnCmw= golang.org/x/term v0.40.0 h1:36e4zGLqU4yhjlmxEaagx2KuYbJq3EwY8K943ZsHcvg= golang.org/x/term v0.40.0/go.mod h1:w2P8uVp06p2iyKKuvXIm7N/y0UCRt3UfJTfZ7oOpglM= golang.org/x/text v0.34.0 h1:oL/Qq0Kdaqxa1KbNeMKwQq0reLCCaFtqu2eNuSeNHbk= golang.org/x/text v0.34.0/go.mod h1:homfLqTYRFyVYemLBFl5GgL/DWEiH5wcsQ5gSh1yziA= golang.org/x/term v0.42.0 h1:UiKe+zDFmJobeJ5ggPwOshJIVt6/Ft0rcfrXZDLWAWY= golang.org/x/term v0.42.0/go.mod h1:Dq/D+snpsbazcBG5+F9Q1n2rXV8Ma+71xEjTRufARgY= golang.org/x/text v0.36.0 h1:JfKh3XmcRPqZPKevfXVpI1wXPTqbkE5f7JA92a55Yxg= golang.org/x/text v0.36.0/go.mod h1:NIdBknypM8iqVmPiuco0Dh6P5Jcdk8lJL0CUebqK164= gopkg.in/check.v1 v0.0.0-20161208181325-20d25e280405/go.mod h1:Co6ibVJAznAaIkqp8huTwlJQCZ016jof/cbN4VW5Yz0= gopkg.in/check.v1 v1.0.0-20190902080502-41f04d3bba15 h1:YR8cESwS4TdDjEe65xsg0ogRM/Nc3DYOhEAlW+xobZo= gopkg.in/check.v1 v1.0.0-20190902080502-41f04d3bba15/go.mod h1:Co6ibVJAznAaIkqp8huTwlJQCZ016jof/cbN4VW5Yz0=