Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

fix(deps): update golang.org/x/crypto digest to 23b1b90 [security] - autoclosed #636

Closed

Conversation

renovate[bot]
Copy link

@renovate renovate bot commented Feb 18, 2023

Mend Renovate

This PR contains the following updates:

Package Type Update Change
golang.org/x/crypto require digest 0c6587e -> 23b1b90

GitHub Vulnerability Alerts

CVE-2022-27191

golang.org/x/crypto/ssh versions 0.0.0-20220214200702-86341886e292 and prior in Go through 1.16.15 and 1.17.x through 1.17.8 allows an attacker to crash a server in certain circumstances involving AddHostKey. Version 0.0.0-20220315160706-3147a52a75dd includes a fix for the vulnerability and support for SHA-2.

CVE-2021-43565

The x/crypto/ssh package before 0.0.0-20211202192323-5770296d904e of golang.org/x/crypto allows an unauthenticated attacker to panic an SSH server.

CVE-2020-29652

A nil pointer dereference in the golang.org/x/crypto/ssh component through v0.0.0-20201203163018-be400aefbc4c for Go allows remote attackers to cause a denial of service against SSH servers.


Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate. View repository job log here.

@renovate renovate bot requested a review from moul as a code owner February 18, 2023 10:08
@trafico-bot trafico-bot bot added the 🔍 Ready for Review Pull Request is not reviewed yet label Feb 18, 2023
@renovate renovate bot changed the title fix(deps): update golang.org/x/crypto digest to ebe9262 [security] fix(deps): update golang.org/x/crypto digest to a9f661c [security] Feb 18, 2023
@renovate renovate bot force-pushed the renovate/go-golang.org/x/crypto-vulnerability branch from 0450da1 to f24406d Compare February 18, 2023 21:35
@renovate renovate bot changed the title fix(deps): update golang.org/x/crypto digest to a9f661c [security] fix(deps): update golang.org/x/crypto digest to ebe9262 [security] Feb 19, 2023
@renovate renovate bot force-pushed the renovate/go-golang.org/x/crypto-vulnerability branch from f24406d to a4094da Compare February 19, 2023 04:19
@renovate renovate bot changed the title fix(deps): update golang.org/x/crypto digest to ebe9262 [security] fix(deps): update golang.org/x/crypto digest to a9f661c [security] Feb 19, 2023
@renovate renovate bot force-pushed the renovate/go-golang.org/x/crypto-vulnerability branch from a4094da to 77174e7 Compare February 19, 2023 08:26
@renovate renovate bot changed the title fix(deps): update golang.org/x/crypto digest to a9f661c [security] fix(deps): update golang.org/x/crypto digest to ebe9262 [security] Feb 19, 2023
@renovate renovate bot force-pushed the renovate/go-golang.org/x/crypto-vulnerability branch from 77174e7 to fcddfe1 Compare February 19, 2023 16:25
@renovate renovate bot changed the title fix(deps): update golang.org/x/crypto digest to ebe9262 [security] fix(deps): update golang.org/x/crypto digest to a9f661c [security] Feb 19, 2023
@renovate renovate bot force-pushed the renovate/go-golang.org/x/crypto-vulnerability branch from fcddfe1 to 849dd76 Compare February 19, 2023 20:45
@renovate renovate bot changed the title fix(deps): update golang.org/x/crypto digest to a9f661c [security] fix(deps): update golang.org/x/crypto digest to ebe9262 [security] Feb 20, 2023
@renovate renovate bot force-pushed the renovate/go-golang.org/x/crypto-vulnerability branch from 849dd76 to b367b95 Compare February 20, 2023 06:12
@renovate renovate bot changed the title fix(deps): update golang.org/x/crypto digest to ebe9262 [security] fix(deps): update golang.org/x/crypto digest to a9f661c [security] Feb 20, 2023
@renovate renovate bot force-pushed the renovate/go-golang.org/x/crypto-vulnerability branch from b367b95 to c53b33f Compare February 20, 2023 13:03
@renovate renovate bot changed the title fix(deps): update golang.org/x/crypto digest to a9f661c [security] fix(deps): update golang.org/x/crypto digest to ebe9262 [security] Feb 20, 2023
@renovate renovate bot force-pushed the renovate/go-golang.org/x/crypto-vulnerability branch from c53b33f to c89a6b1 Compare February 20, 2023 17:23
@renovate renovate bot changed the title fix(deps): update golang.org/x/crypto digest to ebe9262 [security] fix(deps): update golang.org/x/crypto digest to a9f661c [security] Feb 20, 2023
@renovate renovate bot force-pushed the renovate/go-golang.org/x/crypto-vulnerability branch from c89a6b1 to ea3d153 Compare February 20, 2023 19:51
@renovate renovate bot changed the title fix(deps): update golang.org/x/crypto digest to a9f661c [security] fix(deps): update golang.org/x/crypto digest to ebe9262 [security] Feb 21, 2023
@renovate renovate bot force-pushed the renovate/go-golang.org/x/crypto-vulnerability branch from ea3d153 to d814fd0 Compare February 21, 2023 00:30
@renovate renovate bot changed the title fix(deps): update golang.org/x/crypto digest to ebe9262 [security] fix(deps): update golang.org/x/crypto digest to a9f661c [security] Feb 21, 2023
@renovate renovate bot force-pushed the renovate/go-golang.org/x/crypto-vulnerability branch from d814fd0 to 9364f06 Compare February 21, 2023 08:30
@renovate renovate bot changed the title fix(deps): update golang.org/x/crypto digest to a9f661c [security] fix(deps): update golang.org/x/crypto digest to ebe9262 [security] Feb 23, 2023
@renovate renovate bot force-pushed the renovate/go-golang.org/x/crypto-vulnerability branch from 9364f06 to 02e5079 Compare February 23, 2023 11:47
@renovate renovate bot changed the title fix(deps): update golang.org/x/crypto digest to ebe9262 [security] fix(deps): update golang.org/x/crypto digest to a9f661c [security] Feb 23, 2023
@renovate renovate bot force-pushed the renovate/go-golang.org/x/crypto-vulnerability branch from 02e5079 to 8b9b009 Compare February 23, 2023 20:46
@renovate renovate bot changed the title fix(deps): update golang.org/x/crypto digest to a9f661c [security] fix(deps): update golang.org/x/crypto digest to ebe9262 [security] Feb 24, 2023
@renovate renovate bot force-pushed the renovate/go-golang.org/x/crypto-vulnerability branch from 8b9b009 to 1a2420e Compare February 24, 2023 10:40
@renovate renovate bot changed the title fix(deps): update golang.org/x/crypto digest to 183630a [security] fix(deps): update golang.org/x/crypto digest to 8e447d8 [security] Jul 5, 2023
@renovate renovate bot force-pushed the renovate/go-golang.org/x/crypto-vulnerability branch from ad7e761 to 39ba32b Compare July 5, 2023 00:49
@renovate renovate bot changed the title fix(deps): update golang.org/x/crypto digest to 8e447d8 [security] fix(deps): update golang.org/x/crypto digest to e984872 [security] Jul 5, 2023
@renovate renovate bot force-pushed the renovate/go-golang.org/x/crypto-vulnerability branch from 39ba32b to 8988a0f Compare July 5, 2023 17:34
@renovate renovate bot changed the title fix(deps): update golang.org/x/crypto digest to e984872 [security] fix(deps): update golang.org/x/crypto digest to 23b1b90 [security] Jul 5, 2023
@renovate renovate bot force-pushed the renovate/go-golang.org/x/crypto-vulnerability branch from 8988a0f to 1361819 Compare July 5, 2023 22:33
@renovate renovate bot changed the title fix(deps): update golang.org/x/crypto digest to 23b1b90 [security] fix(deps): update golang.org/x/crypto digest to e984872 [security] Jul 6, 2023
@renovate renovate bot force-pushed the renovate/go-golang.org/x/crypto-vulnerability branch from 1361819 to 170a28e Compare July 6, 2023 02:15
@renovate renovate bot changed the title fix(deps): update golang.org/x/crypto digest to e984872 [security] fix(deps): update golang.org/x/crypto digest to 23b1b90 [security] Jul 6, 2023
@renovate renovate bot force-pushed the renovate/go-golang.org/x/crypto-vulnerability branch from 170a28e to 73155ae Compare July 6, 2023 06:24
@renovate renovate bot changed the title fix(deps): update golang.org/x/crypto digest to 23b1b90 [security] fix(deps): update golang.org/x/crypto digest to e984872 [security] Jul 6, 2023
@renovate renovate bot force-pushed the renovate/go-golang.org/x/crypto-vulnerability branch from 73155ae to 9b4a810 Compare July 6, 2023 13:43
@renovate renovate bot changed the title fix(deps): update golang.org/x/crypto digest to e984872 [security] fix(deps): update golang.org/x/crypto digest to 23b1b90 [security] Jul 6, 2023
@renovate renovate bot force-pushed the renovate/go-golang.org/x/crypto-vulnerability branch from 9b4a810 to f17db2c Compare July 6, 2023 21:46
@renovate renovate bot changed the title fix(deps): update golang.org/x/crypto digest to 23b1b90 [security] fix(deps): update golang.org/x/crypto digest to e984872 [security] Jul 7, 2023
@renovate renovate bot force-pushed the renovate/go-golang.org/x/crypto-vulnerability branch from f17db2c to 06ca4e3 Compare July 7, 2023 02:24
@renovate renovate bot changed the title fix(deps): update golang.org/x/crypto digest to e984872 [security] fix(deps): update golang.org/x/crypto digest to 23b1b90 [security] Jul 7, 2023
@renovate renovate bot force-pushed the renovate/go-golang.org/x/crypto-vulnerability branch from 06ca4e3 to 97c206f Compare July 7, 2023 04:34
@renovate renovate bot changed the title fix(deps): update golang.org/x/crypto digest to 23b1b90 [security] fix(deps): update golang.org/x/crypto digest to e984872 [security] Jul 7, 2023
@renovate renovate bot force-pushed the renovate/go-golang.org/x/crypto-vulnerability branch from 97c206f to 564cb5b Compare July 7, 2023 07:33
@renovate renovate bot changed the title fix(deps): update golang.org/x/crypto digest to e984872 [security] fix(deps): update golang.org/x/crypto digest to 23b1b90 [security] Jul 7, 2023
@renovate renovate bot force-pushed the renovate/go-golang.org/x/crypto-vulnerability branch from 564cb5b to 38332c0 Compare July 7, 2023 22:24
@renovate renovate bot changed the title fix(deps): update golang.org/x/crypto digest to 23b1b90 [security] fix(deps): update golang.org/x/crypto digest to e984872 [security] Jul 8, 2023
@renovate renovate bot force-pushed the renovate/go-golang.org/x/crypto-vulnerability branch from 38332c0 to 03aed95 Compare July 8, 2023 06:26
@renovate renovate bot changed the title fix(deps): update golang.org/x/crypto digest to e984872 [security] fix(deps): update golang.org/x/crypto digest to 23b1b90 [security] Jul 9, 2023
@renovate renovate bot force-pushed the renovate/go-golang.org/x/crypto-vulnerability branch from 03aed95 to bcf5853 Compare July 9, 2023 03:09
@renovate renovate bot changed the title fix(deps): update golang.org/x/crypto digest to 23b1b90 [security] fix(deps): update golang.org/x/crypto digest to 23b1b90 [security] - autoclosed Jul 9, 2023
@renovate renovate bot closed this Jul 9, 2023
@renovate renovate bot deleted the renovate/go-golang.org/x/crypto-vulnerability branch July 9, 2023 09:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
🔍 Ready for Review Pull Request is not reviewed yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

0 participants