CriticalUpdate golang.org/x/crypto to fix a critical vulnerability(GHSA-x527)
Fix: 0.52.06.0/10
Update golang.org/x/crypto to fix a critical vulnerability(GHSA-x527)
Fix: 0.52.06.0/10golang.org/x/crypto: Invoking VerifiedPublicKeyCallback permissions skip enforcement golang.org/x/crypto is declared as "v0.29.0" and used as a production Go dependency of this repo. Severity: critical (CVSS 10.0). Reported via GHSA-x527-x647-q7gg (GHSA).
Upgrade golang.org/x/crypto to 0.52.0 or later — low effort (minor version bump).
to claim this mission.
▸Why this score?
Formula
0.60 × impact (10.0) + 0.40 × ecosystem value (0.0) = 6.0
Impact inputs
- CVSS: 10.0
- Severity: critical
- Dependency type: production
- Advisory age: 70d
Ecosystem value inputs
- Repo stars: 0
- Open issues: 0
- Downstream dependents: not tracked yet
Effort inputs
- Semver bump: minor
- Migration guide: not tracked yet
Why low confidence
- · No lock file was parsed for this dependency, so the currently-installed version is estimated from its declared range rather than confirmed.
- · The number of packages depending on this repo's published package couldn't be checked, so ecosystem value is based on stars and issue activity only.
- · Changelog and migration-guide data wasn't available for this dependency's own upstream repository, so the effort estimate is based on the semver version bump alone.
Source
GHSA advisory GHSA-x527-x647-q7gg for golang.org/x/crypto