8000 Bump `golang.org/x/crypto` from `0.24.0` to `0.31.0` in `/bootstrap` to Fix Potential Authorization Bypass by gitworkflows · Pull Request #29 · anthdm/superkit · GitHub
[go: up one dir, main page]
More Web Proxy on the site http://driver.im/
Skip to content

Bump golang.org/x/crypto from 0.24.0 to 0.31.0 in /bootstrap to Fix Potential Authorization Bypass #29

New issue 8000

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

gitworkflows
Copy link

This PR updates golang.org/x/crypto from version 0.24.0 to 0.31.0 i 8797 n the /bootstrap directory to address a potential security issue related to the misuse of ServerConfig.PublicKeyCallback, which could lead to an authorization bypass.

Key Changes:

  • Upgraded golang.org/x/crypto to 0.31.0 to incorporate security fixes and improvements.
  • Mitigates the risk of improperly handling PublicKeyCallback, which could allow unauthorized access in certain configurations.
  • Ensures compatibility with the latest security patches and upstream improvements.

References:

This update is essential to maintaining security and reliability in authentication mechanisms. Please review and merge at your earliest convenience. 🚀

…o_modules group across 1 directory (#1)

* Update go.mod

* Update go.sum
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant
0