fix(deps): update module golang.org/x/crypto to v0.58.0 #36

Open
james wants to merge 1 commit from renovate/golang.org-x-crypto-0.x into main
Owner

This PR contains the following updates:

Package Change Age Confidence
golang.org/x/crypto v0.56.0 → v0.58.0 age confidence

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate CLI.

This PR contains the following updates: | Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) | |---|---|---|---| | [golang.org/x/crypto](https://pkg.go.dev/golang.org/x/crypto) | [`v0.56.0` → `v0.58.0`](https://cs.opensource.google/go/x/crypto/+/refs/tags/v0.56.0...refs/tags/v0.58.0) | ![age](https://developer.mend.io/api/mc/badges/age/go/golang.org%2fx%2fcrypto/v0.58.0?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/go/golang.org%2fx%2fcrypto/v0.56.0/v0.58.0?slim=true) | --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC42NS41IiwidXBkYXRlZEluVmVyIjoiNDQuNjUuNSIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOltdfQ==-->
fix(deps): update module golang.org/x/crypto to v0.57.0
Some checks failed
test / web (pull_request) Successful in 1m36s
test / coverage-badge (pull_request) Has been skipped
test / go (pull_request) Failing after 55s
renovate/artifacts Artifact file update failure
codecov/project 0.00% (No base report)
security-scan / security-scan (pull_request) Successful in 53s
codecov/patch 100.00% >= target 80%
56880c0ffc
Author
Owner

⚠️ Artifact update problem

Renovate failed to update an artifact related to this branch. You probably do not want to merge this PR as-is.

♻ Renovate will retry this branch, including artifacts, only when one of the following happens:

  • any of the package files in this branch needs updating, or
  • the branch becomes conflicted, or
  • you click the rebase/retry checkbox if found above, or
  • you rename this PR's title to start with "rebase!" to trigger it manually

The artifact failure details are included below:

File name: go.sum
spawn go ENOENT
### ⚠️ Artifact update problem Renovate failed to update an artifact related to this branch. You probably do not want to merge this PR as-is. ♻ Renovate will retry this branch, including artifacts, only when one of the following happens: - any of the package files in this branch needs updating, or - the branch becomes conflicted, or - you click the rebase/retry checkbox if found above, or - you rename this PR's title to start with "rebase!" to trigger it manually The artifact failure details are included below: ##### File name: go.sum ``` spawn go ENOENT ```

🔎 ojo scan results

Severity Count
🟠 HIGH 2
🟡 MEDIUM 1
🟢 LOW 1
⚪ UNKNOWN 1
Details (5)
Type Severity ID/Rule Location Description
vuln 🟠 HIGH CVE-2026-93687 [email protected] braces vulnerable to stack-exhaustion denial of service through deeply nested patterns
vuln 🟠 HIGH CVE-2026-93749 [email protected] source-map-js allows event-loop denial of service through indexed source-map section offsets
vuln 🟡 MEDIUM CVE-2026-104844 [email protected] PostCSS: Quadratic complexity in flat selector parsing allows CPU exhaustion
sast 🟢 LOW js-unreachable-code web/src/pages/Languages.tsx:39 this statement can never execute; it follows a return { byLang, byPlatform }; in the same block
vuln ⚪ UNKNOWN GO-2026-5932 golang.org/x/[email protected] The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues
<!-- ojo-scan-summary --> ### 🔎 ojo scan results | Severity | Count | |---|---| | 🟠 HIGH | 2 | | 🟡 MEDIUM | 1 | | 🟢 LOW | 1 | | ⚪ UNKNOWN | 1 | <details><summary>Details (5)</summary> | Type | Severity | ID/Rule | Location | Description | |---|---|---|---|---| | vuln | 🟠 HIGH | <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-93687" target="_blank" rel="noopener noreferrer">CVE-2026-93687</a> | [email protected] | braces vulnerable to stack-exhaustion denial of service through deeply nested patterns | | vuln | 🟠 HIGH | <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-93749" target="_blank" rel="noopener noreferrer">CVE-2026-93749</a> | [email protected] | source-map-js allows event-loop denial of service through indexed source-map section offsets | | vuln | 🟡 MEDIUM | <a href="https://github.com/postcss/postcss-selector-parser/security/advisories/GHSA-rj75-hqrm-r3gf" target="_blank" rel="noopener noreferrer">CVE-2026-104844</a> | [email protected] | PostCSS: Quadratic complexity in flat selector parsing allows CPU exhaustion | | sast | 🟢 LOW | js-unreachable-code | <a href="https://git.colibrisec.org/ColibriSec/balam/src/commit/546c88d3702a06e590f1f5e8714e013bbfe5a028/web/src/pages/Languages.tsx#L39" target="_blank" rel="noopener noreferrer">web/src/pages/Languages.tsx:39</a> | this statement can never execute; it follows a return { byLang, byPlatform }; in the same block | | vuln | ⚪ UNKNOWN | <a href="https://go.dev/issue/44226" target="_blank" rel="noopener noreferrer">GO-2026-5932</a> | golang.org/x/[email protected] | The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues | </details>

Codecov Results 📊

✅ Patch coverage is 100.00%. Project has 3214 uncovered lines.


Generated by Codecov Action

<!-- codecov-action-results --> ## Codecov Results 📊 :white_check_mark: Patch coverage is **100.00%**. Project has **3214** uncovered lines. --- *Generated by [Codecov Action](https://github.com/getsentry/codecov-action)*
james force-pushed renovate/golang.org-x-crypto-0.x from 56880c0ffc
Some checks failed
test / web (pull_request) Successful in 1m36s
test / coverage-badge (pull_request) Has been skipped
test / go (pull_request) Failing after 55s
renovate/artifacts Artifact file update failure
codecov/project 0.00% (No base report)
security-scan / security-scan (pull_request) Successful in 53s
codecov/patch 100.00% >= target 80%
to 546c88d370
Some checks failed
renovate/artifacts Artifact file update failure
security-scan / security-scan (pull_request) Successful in 1m24s
test / go (pull_request) Failing after 59s
codecov/project 0.00% (No base report)
codecov/patch 100.00% >= target 80%
test / web (pull_request) Successful in 1m17s
test / coverage-badge (pull_request) Has been skipped
2026-10-10 04:04:13 +00:00
Compare
james changed title from fix(deps): update module golang.org/x/crypto to v0.57.0 to fix(deps): update module golang.org/x/crypto to v0.58.0 2026-10-10 04:04:18 +00:00
Some checks failed
renovate/artifacts Artifact file update failure
security-scan / security-scan (pull_request) Successful in 1m24s
test / go (pull_request) Failing after 59s
codecov/project 0.00% (No base report)
codecov/patch 100.00% >= target 80%
test / web (pull_request) Successful in 1m17s
test / coverage-badge (pull_request) Has been skipped
This pull request doesn't have enough approvals yet. 0 of 1 approvals granted.
You are not authorized to merge this pull request.
View command line instructions

Checkout

From your project repository, check out a new branch and test the changes.
git fetch -u origin renovate/golang.org-x-crypto-0.x:renovate/golang.org-x-crypto-0.x
git switch renovate/golang.org-x-crypto-0.x
Sign in to join this conversation.
No reviewers
No labels
No milestone
No project
No assignees
2 participants
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
ColibriSec/balam!36
No description provided.