Skip to content

Endor Labs Version Upgrade: Bump golang.org/x/crypto from v0.21.0 to v0.57.0 - #1

Open
endor-labs-pro[bot] wants to merge 1 commit into
masterfrom
endorlabs-4302/go_modules/dot-/golang.org/x/crypto-v0.57.0
Open

endor-labs-pro[bot] wants to merge 1 commit into
masterfrom
endorlabs-4302/go_modules/dot-/golang.org/x/crypto-v0.57.0

Conversation

@endor-labs-pro

@endor-labs-pro endor-labs-pro Bot commented Oct 3, 2026

Copy link
Copy Markdown

Endor Labs Automated Dependency Update

Summary

This PR updates dependencies to improve security:

📦 Dependencies Updated

Project Dependency Name Update Version (From ➡️ To) Update Risk
shipstation/hydra golang.org/x/crypto v0.21.0 ➡️ v0.57.0 LOW View Details

Security Impact

Summary of Fixed Issues

Severity Count
⛔ Critical 7
🔴 High 12
🟠 Medium 15
🔍 Findings fixed in this pull request (Click to expand)
Advisory Dependency Reachability Function Reachability Severity
GHSA-vgwf-h737-ff37 Reachable Unreachable ⛔ Critical
GHSA-5cgq-3rg8-m6cv Reachable Unreachable ⛔ Critical
GHSA-89gr-r52h-f8rx Reachable Unreachable ⛔ Critical
GHSA-f5wc-c3c7-36mc Reachable Unreachable ⛔ Critical
GO-2026-5026 Reachable Potentially Reachable ⛔ Critical
GHSA-jppx-rxg9-jmrx Reachable Unreachable ⛔ Critical
GHSA-rm3j-f69w-wqmq Reachable Unreachable ⛔ Critical
GO-2026-5942 Reachable Potentially Reachable 🔴 High
GO-2026-4918 Reachable Potentially Reachable 🔴 High
GO-2026-6355 Reachable Unreachable 🔴 High
GO-2026-6303 Reachable Unreachable 🔴 High
GHSA-w879-237q-wc7r Reachable Unreachable 🔴 High
GO-2026-4559 Reachable Reachable 🔴 High
GHSA-56w8-48fp-6mgv Reachable Unreachable 🔴 High
GO-2026-5970 Reachable Potentially Reachable 🔴 High
GHSA-w32m-9786-jp63 Reachable Unreachable 🔴 High
GHSA-q4h4-gmj2-qvw2 Reachable Unreachable 🔴 High
GO-2026-6354 Reachable Potentially Reachable 🔴 High
GHSA-v778-237x-gjrc Reachable Unreachable 🔴 High
GO-2026-5029 Reachable Potentially Reachable 🟠 Medium
GHSA-qxp5-gwg8-xv66 Reachable Reachable 🟠 Medium
GHSA-j5w8-q4qc-rx2x Reachable Unreachable 🟠 Medium
GHSA-hcg3-q754-cr77 Reachable Unreachable 🟠 Medium
GHSA-f6x5-jh6r-wrfv Reachable Unreachable 🟠 Medium
GHSA-5cv4-jp36-h3mw Reachable Potentially Reachable 🟠 Medium
GHSA-vvgc-356p-c3xw Reachable Unreachable 🟠 Medium
GHSA-9m57-25v3-79x9 Reachable Unreachable 🟠 Medium
GO-2026-5027 Reachable Potentially Reachable 🟠 Medium
GO-2026-4441 Reachable Unreachable 🟠 Medium
GHSA-qpw4-5x99-6vjp Reachable Unreachable 🟠 Medium
GHSA-78mq-xcr3-xm33 Reachable Unreachable 🟠 Medium
GHSA-w4gw-w5jq-g9jh Reachable Unreachable 🟠 Medium
GO-2026-5030 Reachable Unreachable 🟠 Medium
GO-2026-5025 Reachable Unreachable 🟠 Medium

Remediation Risk

Remediation Risk: LOW

Remediation Risk Factors:

  • Potential Conflicts: 6

    • Major Version Conflicts ℹ️ : 0
    • Minor Version Conflicts ℹ️ : 6
  • Breaking Changes: 0


Reminders

  • Ignore: If you don't wish to receive this update again, simply close this PR.
  • Test: Remember to ensure your tests pass and ensure this change doesn't impact your application before you merge.

Generated by Endor Labs

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants