Skip to content

chore(deps): bump golang.org/x/crypto from 0.41.0 to 0.45.0#394

Merged
kp2099 merged 1 commit intomainfrom
chore(deps)/bump-x-crypto
Dec 5, 2025
Merged

chore(deps): bump golang.org/x/crypto from 0.41.0 to 0.45.0#394
kp2099 merged 1 commit intomainfrom
chore(deps)/bump-x-crypto

Conversation

@tenthirtyam
Copy link
Copy Markdown
Collaborator

@tenthirtyam tenthirtyam commented Dec 2, 2025

Description

  • Bumps golang.org/x/crypto from 0.41.0 to 0.45.0.
  • Bumps github.com/hashicorp/packer-plugin-sdk from 0.6.3 to 0.6.4.
  • Requires a bump of Go to 1.24.0 or later; using latest 1.24.10.

Ref:

Resolved Issues

Changes to Security Controls

None.

@tenthirtyam tenthirtyam added this to the v2.0.0 milestone Dec 2, 2025
@tenthirtyam tenthirtyam requested a review from kp2099 December 2, 2025 15:04
@tenthirtyam tenthirtyam self-assigned this Dec 2, 2025
@tenthirtyam tenthirtyam requested a review from a team as a code owner December 2, 2025 15:04
@tenthirtyam tenthirtyam added the dependencies Dependencies label Dec 2, 2025
Copilot AI review requested due to automatic review settings December 2, 2025 15:04
@tenthirtyam tenthirtyam added the chore Chore label Dec 2, 2025
Copy link
Copy Markdown

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR updates golang.org/x/crypto from version 0.41.0 to 0.45.0 to address security vulnerabilities CVE-2025-58181 and CVE-2025-47914. The update requires bumping the Go version to 1.24.10, which also triggers updates to several related golang.org/x packages.

Key changes:

  • Updates Go from 1.23.12 to 1.24.10
  • Upgrades golang.org/x/crypto from 0.41.0 to 0.45.0 to resolve security CVEs
  • Updates related golang.org/x dependencies (net, sys, mod, sync, term, text, tools) to compatible versions

Reviewed changes

Copilot reviewed 3 out of 4 changed files in this pull request and generated no comments.

File Description
go.mod Updates Go version directive to 1.24.10 and bumps golang.org/x dependencies
go.sum Updates checksums for all upgraded golang.org/x packages
README.md Updates documented Go requirement to 1.24.10
.go-version Updates Go version specification to 1.24.10

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

- Bumps golang.org/x/crypto from 0.41.0 to 0.45.0.
- Bumps github.com/hashicorp/packer-plugin-sdk from 0.6.3 to 0.6.4.
- Requires a bump of Go to 1.24.0 or later; using latest 1.24.10.

Ref:
- CVE-2025-58181
- CVE-2025-47914

Signed-off-by: Ryan Johnson <ryan.johnson@broadcom.com>
@tenthirtyam tenthirtyam force-pushed the chore(deps)/bump-x-crypto branch from 0bcd838 to 367cfe2 Compare December 2, 2025 15:42
@kp2099 kp2099 merged commit ce03d94 into main Dec 5, 2025
14 checks passed
@kp2099 kp2099 deleted the chore(deps)/bump-x-crypto branch December 5, 2025 03:56
@github-actions
Copy link
Copy Markdown

I'm going to lock this pull request because it has been closed for 30 days. This helps our maintainers find and focus on the active issues.

If you have found a problem that seems related to this change, please open a new issue and complete the issue template so we can capture all the details necessary to investigate further.

@github-actions github-actions bot locked as resolved and limited conversation to collaborators Jan 29, 2026
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

chore Chore dependencies Dependencies

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants