Update Go crypto dependencies and align the Go toolchain - #20
Merged
Merged
Conversation
Select x/crypto v0.52.0 and its required x/sys v0.45.0. Align the minimum Go version to 1.25.7 and development and CI toolchain to 1.26.8 while preserving runtime source and existing compatibility vectors.
piotr-roslaniec
changed the base branch from
codex/deps-protobuf-runtime
to
dev
September 29, 2026 09:10
|
Merged into Before merging, Checks on the merged head:
Full report: agent-docs/pr-integration/20.md (local). |
piotr-roslaniec
added a commit
that referenced
this pull request
Sep 29, 2026
Merge origin/dev (contains #18/#20/#21) into the input-guards branch. Auto-merged cleanly (no textual conflicts); key choices: - go.mod/go.sum: adopt origin/dev toolchain and dependencies (go 1.25.7, toolchain go1.26.8, x/crypto v0.52.0, x/sys v0.45.0, protobuf v1.33.0, btcd v0.24.2, btcec/v2 v2.2.0, btcutil v1.1.5, bigmod v0.1.0) per the integration contract. - crypto/mta/proofs.go: keep #12 decoder guards (ProofBobWC 12-part arity, Bytes nil-receiver panics) plus dev's CT/sampling changes; changes were in disjoint regions and both survived.
piotr-roslaniec
added a commit
that referenced
this pull request
Sep 29, 2026
Merge current origin/dev (includes #18/#20/#21) into the PR #14 branch. Conflict choices: - No textual conflicts; clean automatic merge. - Go toolchain/deps kept from origin/dev (go 1.25.7, toolchain go1.26.8, x/crypto v0.52.0, x/sys v0.45.0, protobuf v1.33.0, btcd v0.24.2, btcec/v2 v2.2.0, btcutil v1.1.5, bigmod v0.1.0). - Preserved PR #14 changes on top of dev: BaseParty fatal-error latch (abort/abortedWith) and keygen unmarshalVSSCommitment part-count guard in ecdsa/keygen/round_3.go.
This was referenced Sep 29, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Depends on #19 and is stacked on
codex/deps-protobuf-runtime.Upgrade
golang.org/x/cryptoto v0.52.0 and its requiredgolang.org/x/systo v0.45.0. These versions cover the 25 current x/crypto Dependabot alerts and the single x/sys alert, including the published June 2026 SSH fixes. The inherited protobuf update remains v1.33.0.Raise the Go minimum to 1.25.7 and select Go 1.26.8 in the module and both CI workflows. This aligns with keep-core #4312; downstream adoption requires the Go upgrade. Modern module pruning makes existing indirect dependencies explicit without upgrading their versions. The selected x/sys version supersedes the older upgrade in #11/#17 and must be retained when those branches are integrated.
Validation on the final stacked commit with Go 1.26.8:
The library imports RIPEMD-160 from x/crypto. This removes advisory-affected dependency versions without claiming that the SSH vulnerabilities were reachable through tss-lib.
Full test CI and formatting CI passed at the current head
a1dc49cecbe436d45e03cf4c6ebe2e5f042691e5. These workflows were dispatched explicitly because this stacked PR does not target master.