Skip to content

Bump dependencies and min go version to 1.23#294

Merged
lubux merged 1 commit intomainfrom
chore/bump-go-and-circl
Jan 7, 2026
Merged

Bump dependencies and min go version to 1.23#294
lubux merged 1 commit intomainfrom
chore/bump-go-and-circl

Conversation

@lubux
Copy link
Copy Markdown
Member

@lubux lubux commented Sep 15, 2025

Update to:
go 1.23.0
github.com/cloudflare/circl v1.6.1
golang.org/x/crypto v0.41.0


Security dependency scanning tools are alerting on:

golang.org/x/crypto          v0.33.0    0.35.0  GHSA-hcg3-q754-cr77
github.com/cloudflare/circl  v1.6.0     1.6.1    GHSA-2x5j-vhc8-9cwm 

The OpenPGP operations are not affected by these vulnerabilities, but we should bump at some point.

@rskhor
Copy link
Copy Markdown

rskhor commented Jan 5, 2026

@lubux Hi Lukas, thanks so much for your work on this package, as well as ProtonMail/gopenpgp! Just wanted to check – would you be merging this version bump anytime soon? Or did you perhaps encounter an issue with these changes?

go 1.23.0
github.com/cloudflare/circl v1.6.2
golang.org/x/crypto v0.41.0
@lubux lubux force-pushed the chore/bump-go-and-circl branch from 678ae64 to b1ff3d5 Compare January 7, 2026 13:21
@lubux lubux merged commit b6bdd12 into main Jan 7, 2026
9 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants