# Upgrade go-git to v6.0.0-alpha.2

`d43e635`→[main](/content/gh/entireio/git-sync/commits/main/index.html)·  
  
Soph·2mo ago·17 files·+130 added/-164 removed

Closes the credential-leak advisory tracked as CVE-2026-41506  
(GHSA-3xc5-wrhm-f963 / Dependabot alert #1). Our smart-HTTP path  
already used Go's stdlib http.Client directly, which strips the  
Authorization header on cross-host redirects since 1.8 — but  
upgrading clears the alert and pulls in the upstream  
http.followRedirects controls.

Alpha.2 is a major rewrite of plumbing/transport. Translation:

\- \*transport.Endpoint (struct) → \*url.URL throughout. Field  
accesses (.Scheme, .Host, .Path, .User, .Hostname()) are  
unchanged.
\- transport.NewEndpoint → transport.ParseURL.
\- transport.AuthMethod (interface) is gone. Defined our own  
auth.Method and gitproto.AuthMethod with a single  
Authorizer(\*http.Request) error method, satisfied by  
\*transporthttp.BasicAuth and \*transporthttp.TokenAuth (whose  
SetAuth methods were renamed to Authorizer).
\- transport.Service (typed) → string constants. Function  
parameters take string.
\- transporthttp.NewTransport(\*TransportOptions) →  
NewTransport(Options) (value, not pointer).
\- transport.AdvertiseReferences → transport.AdvertiseRefs.
\- transport.UploadPackOptions → transport.UploadPackRequest;  
transport.ReceivePackOptions → transport.ReceivePackRequest.
\- transport.Register / transport.Get were removed. The TestMain  
shims in syncer/integration_test.go and cmd/git-sync/main_test.go  
registered a custom HTTP transport for go-git's transport  
registry, but our code never goes through that registry — it  
hits the network through gitproto's own http.Client. Dropped  
both shims as dead code.

Also dropped the now-unused Conn.Transport field; nothing in  
git-sync read it.

Updated .golangci.yaml ireturn allowlist to permit the new  
auth.Method interface where the previous transport.AuthMethod  
allowance lived.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

## Changes

17

- M.golangci.yaml+1/-1
- cmd/git-sync

- Mmain_test.go+4/-15
- Mgo.mod+4/-5
- Mgo.sum+14/-16
- internal

- auth

- Mauth.go+13/-5
 - Mauth_test.go+19/-23
 - Mentiredb.go+3/-4

- gitproto

- Mfetch_test.go+13/-13
 - Mpush_test.go+3/-3
 - Mrefs.go+1/-1
 - Msmarthttp.go+37/-34
 - Msmarthttp_test.go+6/-9

- strategy/bootstrap

- Mbootstrap_test.go+2/-2

- syncer

- Mauth_test.go+3/-3
 - Mintegration_test.go+3/-26
 - Msyncer.go+1/-1

- pkg/gitsync

- Mclient_test.go+3/-3

```  
96 unmodified lines

97  
98  
99
100
100
101
102
103

96 unmodified lines

- github.com/go-git/go-git/v6/storage.Storer
        - github.com/go-git/go-git/v6/plumbing/storer.EncodedObjectIter
        - github.com/go-git/go-billy/v6.Filesystem
        - github.com/go-git/go-git/v6/plumbing/transport.AuthMethod
        - github.com/entirehq/git-sync/internal/auth.Method
    nolintlint:
      require-explanation: true
      require-specific: true
``

M.golangci.yaml+1/-1

```
22 unmodified lines

23
24
25
26
26
27
28
413 unmodified lines

442
443
444
446
445
446
447
448
449
450
451
453
452
453
454
455
49 unmodified lines

505
506
507
509
508
509
510
511
15 unmodified lines

527
528
529
531
530
531
532
533
12 unmodified lines

546
547
548
550
551
552
553
554
555
556
557
558
559

22 unmodified lines

"github.com/go-git/go-git/v6/plumbing/protocol/packp"
	"github.com/go-git/go-git/v6/plumbing/protocol/packp/capability"
	"github.com/go-git/go-git/v6/plumbing/transport"
	transporthttp "github.com/go-git/go-git/v6/plumbing/transport/http"
	"github.com/go-git/go-git/v6/storage/memory"
)

413 unmodified lines

}

func (s *smartHTTPRepoServer) handleInfoRefs(w http.ResponseWriter, r *http.Request) {
	service := transport.Service(r.URL.Query().Get("service"))
	service := r.URL.Query().Get("service")
	if service != transport.UploadPackService && service != transport.ReceivePackService {
		http.Error(w, "missing service", http.StatusBadRequest)
		return
	}

var buf bytes.Buffer
	if err := transport.AdvertiseReferences(r.Context(), s.repo.Storer, &buf, service, false); err != nil {
	if err := transport.AdvertiseRefs(r.Context(), s.repo.Storer, &buf, service, false); err != nil {
		http.Error(w, err.Error(), http.StatusInternalServerError)
		return
	}
49 unmodified lines

var buf bytes.Buffer
	wc := nopWriteCloser{&buf}

err := transport.UploadPack(r.Context(), s.repo.Storer, r.Body, wc, &transport.UploadPackOptions{
	err := transport.UploadPack(r.Context(), s.repo.Storer, r.Body, wc, &transport.UploadPackRequest{
		StatelessRPC: true,
	})
	if err != nil {
15 unmodified lines

var buf bytes.Buffer
	wc := nopWriteCloser{&buf}

err := transport.ReceivePack(r.Context(), s.repo.Storer, r.Body, wc, &transport.ReceivePackOptions{
	err := transport.ReceivePack(r.Context(), s.repo.Storer, r.Body, wc, &transport.ReceivePackRequest{
		StatelessRPC: true,
	})
	if err != nil {

12 unmodified lines

type nopWriteCloser struct{ io.Writer }

func (nopWriteCloser) Close() error { return nil }

func TestMain(m *testing.M) {
	customHTTP := transporthttp.NewTransport(&transporthttp.TransportOptions{
		Client: &http.Client{},
	})
	transport.Register("http", customHTTP)
	transport.Register("https", customHTTP)

os.Exit(m.Run())
}
```

Mcmd/git-sync/main_test.go+4/-15

```
3 unmodified lines

4
5
6
7
7
8
9
10
8 unmodified lines

19
20
21
22
22
23
24
25
26
28
29
30
27
28
29
30
31
32

3 unmodified lines

require (
	github.com/go-git/go-billy/v6 v6.0.0-20260410103409-85b6241850b5
	github.com/go-git/go-git/v6 v6.0.0-alpha.1
	github.com/go-git/go-git/v6 v6.0.0-alpha.2
	github.com/stretchr/testify v1.11.1
	github.com/zalando/go-keyring v0.2.8
)
8 unmodified lines

github.com/emirpasic/gods v1.18.1 // indirect
	github.com/go-git/gcfg/v2 v2.0.2 // indirect
	github.com/godbus/dbus/v5 v5.2.2 // indirect
	github.com/golang/groupcache v0.0.0-20241129210726-2c02b8208cf8 // indirect
	github.com/kevinburke/ssh_config v1.6.0 // indirect
	github.com/klauspost/cpuid/v2 v2.3.0 // indirect
	github.com/pjbgf/sha1cd v0.5.0 // indirect
	github.com/pmezard/go-difflib v1.0.0 // indirect
	github.com/sergi/go-diff v1.4.0 // indirect
	golang.org/x/crypto v0.48.0 // indirect
	golang.org/x/net v0.51.0 // indirect
	golang.org/x/sync v0.19.0 // indirect
	golang.org/x/crypto v0.50.0 // indirect
	golang.org/x/net v0.53.0 // indirect
	golang.org/x/sync v0.20.0 // indirect
	golang.org/x/sys v0.43.0 // indirect
	gopkg.in/yaml.v3 v3.0.1 // indirect
)
```

Mgo.mod+4/-5

```
22 unmodified lines

23
24
25
26
27
28
29
26
27
28
29
30
31
32
33
32
33
34
17 unmodified lines

52
53
54
57
58
59
60
61
62
55
56
57
58
59
60
61
62
65
66
67
68
63
64
65
66
67
68
69

22 unmodified lines

github.com/go-git/gcfg/v2 v2.0.2/go.mod h1:/lv2NsxvhepuMrldsFilrgct6pxzpGdSRC13ydTLSLs=
github.com/go-git/go-billy/v6 v6.0.0-20260410103409-85b6241850b5 h1:r5Y4Hn9QwQj+u6vN0Ib1MipHkanYaG8Zj0kxsnv8Bu4=
github.com/go-git/go-billy/v6 v6.0.0-20260410103409-85b6241850b5/go.mod h1:CdBVp7CXl9l3sOyNEog46cP1Pvx/hjCe9AD0mtaIUYU=
github.com/go-git/go-git-fixtures/v5 v5.1.2-0.20260122163445-0622d7459a67 h1:3hutPZF+/FBjR/9MdsLJ7e1mlt9pwHgwxMW7CrbmWII=
github.com/go-git/go-git-fixtures/v5 v5.1.2-0.20260122163445-0622d7459a67/go.mod h1:xKt0pNHST9tYHvbiLxSY27CQWFwgIxBJuDrOE0JvbZw=
github.com/go-git/go-git/v6 v6.0.0-alpha.1 h1:tGohX5luKeO50DZD0/Zqd5dYjJzKtub91S4I+1qFVIs=
github.com/go-git/go-git/v6 v6.0.0-alpha.1/go.mod h1:qtzfNHlFsnq6vCw54aT4KvFWPK5bsOpTVtFC2sysdB8=
github.com/go-git/go-git-fixtures/v6 v6.0.0-20260405195209-b16dd39735e0 h1:XoTsdvaghuVfIr7HpNTmFDLu2nz3I2iGqyn6Uk6MkJc=
github.com/go-git/go-git-fixtures/v6 v6.0.0-20260405195209-b16dd39735e0/go.mod h1:1Lr7/vYEYyl6Ir9Ku0tKrCIRreM5zovv0Jdx2MPSM4s=
github.com/go-git/go-git/v6 v6.0.0-alpha.2 h1:T3loNtDuAixNzXtlQxZhnYiYpaQ3CA4vn9RssAniEeI=
github.com/go-git/go-git/v6 v6.0.0-alpha.2/go.mod h1:oCD3i19CTz7gBpeb11ZZqL91WzqbMq9avn5KpUYy/Ak=
github.com/godbus/dbus/v5 v5.2.2 h1:TUR3TgtSVDmjiXOgAAyaZbYmIeP3DPkld3jgKGV8mXQ=
github.com/godbus/dbus/v5 v5.2.2/go.mod h1:3AAv2+hPq5rdnr5txxxRwiGjPXamgoIHgz9FPBfOp3c=
github.com/golang/groupcache v0.0.0-20241129210726-2c02b8208cf8 h1:f+oWsMOmNPc8JmEHVZIycC7hBoQxHH9pNKQORJNozsQ=
github.com/golang/groupcache v0.0.0-20241129210726-2c02b8208cf8/go.mod h1:wcDNUvekVysuuOpQKo3191zZyTpiI6se1N1ULghS0sw=
github.com/kevinburke/ssh_config v1.6.0 h1:J1FBfmuVosPHf5GRdltRLhPJtJpTlMdKTBjRgTaQBFY=
github.com/kevinburke/ssh_config v1.6.0/go.mod h1:q2RIzfka+BXARoNexmF9gkxEX7DmvbW9P4hIVx2Kg4M=
github.com/klauspost/cpuid/v2 v2.3.0 h1:S4CRMLnYUhGeDFDqkGriYKdfoFlDnMtqTiI/sFzhA9Y=
17 unmodified lines

github.com/stretchr/testify v1.11.1/go.mod h1:wZwfW3scLgRK+23gO65QZefKpKQRnfz6sD981Nm4B6U=
github.com/zalando/go-keyring v0.2.8 h1:6sD/Ucpl7jNq10rM2pgqTs0sZ9V3qMrqfIIy5YPccHs=
github.com/zalando/go-keyring v0.2.8/go.mod h1:tsMo+VpRq5NGyKfxoBVjCuMrG47yj8cmakZDO5QGii0=
golang.org/x/crypto v0.48.0 h1:/VRzVqiRSggnhY7gNRxPauEQ5Drw9haKdM0jqfcCFts=
golang.org/x/crypto v0.48.0/go.mod h1:r0kV5h3qnFPlQnBSrULhlsRfryS2pmewsg+XfMgkVos=
golang.org/x/net v0.51.0 h1:94R/GTO7mt3/4wIKpcR5gkGmRLOuE/2hNGeWq/GBIFo=
golang.org/x/net v0.51.0/go.mod h1:aamm+2QF5ogm02fjy5Bb7CQ0WMt1/WVM7FtyaTLlA9Y=
golang.org/x/sync v0.19.0 h1:vV+1eWNmZ5geRlYjzm2adRgW2/mcpevXNg50YZtPCE4=
golang.org/x/sync v0.19.0/go.mod h1:9KTHXmSnoGruLpwFjVSX0lNNA75CykiMECbovNTZqGI=
golang.org/x/crypto v0.50.0 h1:zO47/JPrL6vsNkINmLoo/PH1gcxpls50DNogFvB5ZGI=
golang.org/x/crypto v0.50.0/go.mod h1:3muZ7vA7PBCE6xgPX7nkzzjiUq87kRItoJQM1Yo8S+Q=
golang.org/x/net v0.53.0 h1:d+qAbo5L0orcWAr0a9JweQpjXF19LMXJE8Ey7hwOdUA=
golang.org/x/net v0.53.0/go.mod h1:JvMuJH7rrdiCfbeHoo3fCQU24Lf5JJwT9W3sJFulfgs=
golang.org/x/sync v0.20.0 h1:e0PTpb7pjO8GAtTs2dQ6jYa5BWYlMuX047Dco/pItO4=
golang.org/x/sync v0.20.0/go.mod h1:9xrNwdLfx4jkKbNva9FpL6vEN7evnE43NNNJQ2LF3+0=
golang.org/x/sys v0.43.0 h1:Rlag2XtaFTxp19wS8MXlJwTvoh8ArU6ezoyFsMyCTNI=
golang.org/x/sys v0.43.0/go.mod h1:4GL1E5IUh+htKOUEOaiffhrAeqysfVGipDYzABqnCmw=
golang.org/x/term v0.40.0 h1:36e4zGLqU4yhjlmxEaagx2KuYbJq3EwY8K943ZsHcvg=
golang.org/x/term v0.40.0/go.mod h1:w2P8uVp06p2iyKKuvXIm7N/y0UCRt3UfJTfZ7oOpglM=
golang.org/x/text v0.34.0 h1:oL/Qq0Kdaqxa1KbNeMKwQq0reLCCaFtqu2eNuSeNHbk=
golang.org/x/text v0.34.0/go.mod h1:homfLqTYRFyVYemLBFl5GgL/DWEiH5wcsQ5gSh1yziA=
golang.org/x/term v0.42.0 h1:UiKe+zDFmJobeJ5ggPwOshJIVt6/Ft0rcfrXZDLWAWY=
golang.org/x/term v0.42.0/go.mod h1:Dq/D+snpsbazcBG5+F9Q1n2rXV8Ma+71xEjTRufARgY=
golang.org/x/text v0.36.0 h1:JfKh3XmcRPqZPKevfXVpI1wXPTqbkE5f7JA92a55Yxg=
golang.org/x/text v0.36.0/go.mod h1:NIdBknypM8iqVmPiuco0Dh6P5Jcdk8lJL0CUebqK164=
gopkg.in/check.v1 v0.0.0-20161208181325-20d25e280405/go.mod h1:Co6ibVJAznAaIkqp8huTwlJQCZ016jof/cbN4VW5Yz0=
gopkg.in/check.v1 v1.0.0-20190902080502-41f04d3bba15 h1:YR8cESwS4TdDjEe65xsg0ogRM/Nc3DYOhEAlW+xobZo=
gopkg.in/check.v1 v1.0.0-20190902080502-41f04d3bba15/go.mod h1:Co6ibVJAznAaIkqp8huTwlJQCZ016jof/cbN4VW5Yz0=
