CriticalGoUpdate golang.org/x/crypto to fix a critical vulnerability
Low effort SpIob/deptend-go-test-fixture ⚠ low confidence
5.4/10
golang.org/x/crypto: Invoking VerifiedPublicKeyCallback permissions skip enforcement Affects golang.org/x/crypto (declared as "v0.29.0"), used as a production dependency of this repo. Severity: critical. Source: GHSA-x527-x647-q7gg (GHSA).
Upgrade golang.org/x/crypto to 0.52.0 or later (minor version bump).
to claim this mission.
▸Why this score?
Formula
0.60 × impact (9.0) + 0.40 × ecosystem value (0.0) = 5.4
Impact inputs
- CVSS: unknown
- Severity: critical
- Dependency type: production
- Advisory age: 31d
Ecosystem value inputs
- Repo stars: 0
- Open issues: 0
- Downstream dependents: not tracked yet
Effort inputs
- Semver bump: minor
- Migration guide: not tracked yet
Why low confidence
- · No lock file was parsed for this dependency, so the currently-installed version is estimated from its declared range rather than confirmed.
- · No CVSS score was available for this advisory; the impact score falls back to a severity-based estimate.
- · The number of packages that depend on this one isn't tracked yet, so ecosystem value is based on stars and issue activity only.
- · Changelog and migration-guide data isn't ingested yet, so the effort estimate is based on the semver version bump alone.
Source
GHSA advisory GHSA-x527-x647-q7gg for golang.org/x/crypto