Resolve Dependabot Security Alerts with golang.org/x/crypto · Entire
Dependabot Alerts Summary for entireio/git-sync
Here's the summary of entireio/git-sync Dependabot alerts:
13 open alerts — all golang.org/x/crypto
Currently pinned at v0.51.0 (indirect dependency); all are fixed in v0.52.0. Severity breakdown:
| Severity | Count | Notable |
|---|---|---|
| 🔴 Critical | 7 | Agent key-constraint bypass on forwarding; SSH cert @revoked auth bypass; FIDO/U2F presence-check bypass; server deadlock/infinite loop DoS |
| 🟠 High | 3 | Pathological RSA/DSA DoS; byte-arithmetic underflow panic; crafted-object parsing |
| 🟡 Medium | 3 | Client panic on pathological input; channel-reject memory leak; cert-restriction bypass |
Most are in the SSH implementation (x/crypto/ssh).
Fixed (7) — no action
x/net (→0.55.0) and 4× go-git/v6 alerts are already resolved.
Recommendation
A single bump closes all 13 open alerts:
go get golang.org/x/crypto@v0.52.0 && go mod tidy
Since it's an indirect dependency, it may get pulled up by bumping whatever requires it, but pinning directly via go get works too.
Bumping Direct Dependencies
Findings
Here’s what I found:
Bumping direct deps doesn't help
There are no newer releases of any of the four direct dependencies (go-git/v6, go-billy/v6, cobra, testify), and go-git itself requires x/crypto@v0.51.0. So there's no direct-dep bump that would pull in the fix — go mod tidy keeps it at 0.51.0.
The dependency is also genuinely used (not stale) — go-git's object hashing (crypto/sha3) and ProtonMail's openpgp both pull it in — so it can't just be dropped.
The Fix
Go's minimal version selection lets you pin an indirect dependency above what your deps request. I ran:
go get golang.org/x/crypto@v0.52.0 && go mod tidy
Result — go.mod now has golang.org/x/crypto v0.52.0 // indirect, which closes all 13 open alerts.
- ✅
go build ./...— clean - ✅
go test ./...— all packages pass
The only change is x/crypto v0.51.0 → v0.52.0 in go.mod/go.sum.
PR Opened
Here’s the commit link to apply these changes: PR #104
- Branch
soph/bump-x-crypto-0.52pushed. - Single commit bumping
x/crypto v0.51.0 → v0.52.0(go.mod/go.sum only). - Closes all 13 open Dependabot alerts.
- Build + full test suite verified green.
Why Not Go Even Newer?
To recap the "why not newer" answer: v0.52.0 is the minimal version that clears all 13 alerts, giving the smallest, most-targeted diff (just x/crypto). v0.54.0 works fine too but drags in x/net, x/sys, and x/text bumps — a wider review surface for no additional security benefit. MVS treats 0.52.0 as a floor, not a ceiling, so nothing stops it rising later when a dependency actually needs it.
Next Steps
If you'd rather go to 0.54.0 after all, just say so and I'll amend the PR.
Commit Updates
Now amending the commit and updating the PR:
- Bump
golang.org/x/crypto to v0.54.0 - Closes 13 open Dependabot alerts (7 critical, 3 high, 3 medium), all in the x/crypto SSH implementation.
- The dependency is pulled in transitively via go-git and ProtonMail openpgp; go-git still requires v0.51.0 and has no newer release, so we pin the indirect dependency directly via MVS.
- Bumps to the latest x/crypto, which also lifts x/net to v0.56.0 and x/sys to v0.47.0.