Skip to content

CIP-18: remove hard OpenPGP dependency from go-github v30 - #1

Merged
llebihan merged 1 commit into
lebtek-v30.1.0from
cip-18-remove-openpgp
Aug 29, 2026
Merged

llebihan merged 1 commit into
lebtek-v30.1.0from
cip-18-remove-openpgp

Conversation

@llebihan

Copy link
Copy Markdown

Summary

Backport the generic MessageSigner design from google#2935 onto the v30.1.0 maintenance base. This removes the hard golang.org/x/crypto/openpgp import that triggers GO-2026-5932 for downstream SDK consumers while preserving optional signing through a caller-supplied interface.

The fork exists solely to provide an immutable compatibility/security pin for LebtekOne while upstream ProjectDiscovery dependencies remain on go-github/v30.

Provenance

Validation

  • GOTOOLCHAIN=go1.27.0 GOWORK=off go test ./...
  • GOTOOLCHAIN=go1.27.0 GOWORK=off go vet ./...
  • Go 1.27 govulncheck: no reachable vulnerabilities
  • Isolated LebtekOne scanner: go test ./..., go vet ./..., OpenAPI dependency contract, and govulncheck all pass with zero vulnerabilities

Do not merge without explicit approval.

@llebihan

Copy link
Copy Markdown
Author

Downstream review: https://github.com/LebtekOrg/LebtekOne/pull/865 pins commit 1e7459df80cc6ae322fa347a0cc029b47fc2f078. The downstream PR is rebased onto current main and both required-ci and required-security are green, including all-module govulncheck and Syft/Grype. Both PRs remain open and unmerged pending explicit approval.

@llebihan
llebihan merged commit 430fd02 into lebtek-v30.1.0 Aug 29, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant