Skip to content

[Cycode] Fix for vulnerable manifest file dependency - golang.org/x/crypto updated to version 0.52.0#100

Open
cycode-security[bot] wants to merge 1 commit into
mainfrom
cycode-fix-suggestion-manifest-dependency-update-58b65424-414e-413d-a96e-0b1b707609ec
Open

[Cycode] Fix for vulnerable manifest file dependency - golang.org/x/crypto updated to version 0.52.0#100
cycode-security[bot] wants to merge 1 commit into
mainfrom
cycode-fix-suggestion-manifest-dependency-update-58b65424-414e-413d-a96e-0b1b707609ec

Conversation

@cycode-security

@cycode-security cycode-security Bot commented Jul 7, 2026

Copy link
Copy Markdown

Cycode Vulnerable Dependencies Update

This pull request updates the following manifest file:

File Path Number of packages to update
go.mod 1

📂 go.mod

1 package will be updated to resolve vulnerabilities:

Package Name Current Version Updated Version
golang.org/x/crypto 0.41.0 0.52.0

Note

Medium Risk
Touches a security-sensitive transitive/direct crypto dependency used for bcrypt password operations; risk is mainly regression or subtle crypto behavior across a large version jump, mitigated by the narrow manifest-only change.

Overview
Bumps the direct golang.org/x/crypto dependency in go.mod from 0.41.0 to 0.52.0 to address reported vulnerabilities (Cycode manifest update). There are no application code changes in this diff.

The module is used in-repo for password hashing via bcrypt (e.g. internal/api/crypto/hash.go), so the upgrade affects the crypto library version resolved at build time rather than new behavior in this PR.

Reviewed by Cursor Bugbot for commit c3df78a. Configure here.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants