Repository navigation
Host Provisioner v0.39.7
Upgrade golang.org/x/crypto to v0.56.0 to address CVE-2026-56855 and CVE-2026-78662 in the SSH channel dispatch used by host provisioning. Keep the existing reviewed Docker Machine compatibility changes.
- Source: c396df5 (merged PR #6).
- Main validation run: https://github.com/PastureStack/host-provisioner/actions/runs/34137894997
- Main security run: https://github.com/PastureStack/host-provisioner/actions/runs/34137895006
- Complete package tests, race checks, vet/source validation, two focused SSH regression tests, CodeQL, and two byte-identical package builds passed.
- Product scan: no Critical/High findings or secrets; the retained module-level GO-2026-5932 OpenPGP finding is not an SSH finding and the shipped application does not import OpenPGP.
- Build-image kernel-header findings remain separately identified in CI evidence and are not shipped in the CGO-disabled Go executable.
The attached SHA-256 file, Go build metadata, product scan and source revision identify the exact released artifact. This component release alone does not prove the aggregate Server image or a production deployment has passed its security gate.