build(deps): bump golang.org/x/crypto from 0.55.0 to 0.57.0 in the go-minor-and-patch group across 1 directory - #585
Conversation
Bumps the go-minor-and-patch group with 1 update in the / directory: [golang.org/x/crypto](https://github.com/golang/crypto). Updates `golang.org/x/crypto` from 0.55.0 to 0.57.0 - [Commits](golang/crypto@v0.55.0...v0.57.0) --- updated-dependencies: - dependency-name: golang.org/x/crypto dependency-version: 0.57.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: go-minor-and-patch ... Signed-off-by: dependabot[bot] <support@github.com>
PR SummaryMedium Risk Overview The only application code touched is Test coverage is expanded so a future crypto bump is less likely to slip through silently: RIPEMD-160 known-answer vectors, Reviewed by Cursor Bugbot for commit 43417f3. Bugbot is set up for automated code reviews on this repo. Configure here. |
Cover the only direct x/crypto usage in the repo — ripemd160 in the keygen derivation pipeline — so the 0.55.0 -> 0.57.0 bump has a known-answer tripwire: - ripemd160 published KATs - Derive() round-trip: identity re-derives to the same address and its bech32 decodes back to 20 bytes - fundraiser vector now pins the exact sei1 address through the production cosmosAddress path (extracted from Derive) - two Derive calls do not collide Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
There was a problem hiding this comment.
Nothing material changed: the only new commit (43417f3, 'ci: retrigger checks') is empty, the diff is identical to my last review, and none of my earlier findings has been fixed, so they still stand. Codex again found nothing, so its reading adds nothing, and nothing in the diff blocks.
Non-blocking
1 finding on the changed lines, as inline comments.
- This is a Dependabot PR, but a second commit (98d0cf7) adds hand-written changes to
internal/keygen: thecosmosAddressrefactor and new tests. The PR body only describes the version bump. Reviewers who wave through dependency bumps won't see it, and@dependabot recreateor a rebase would drop it. Consider moving it to its own PR or mentioning it in the description.
seidroid review · decision approve · session e96e717f1f3344738f223c7ff18eeac0 · turn resp_claude_57ac031b6734636d4e4d9fc14237925b · item 90eac65130c8575ebe038e88313a7b34
Findings: 0 blocking | 2 non-blocking | 1 posted inline
| if err != nil { | ||
| t.Fatalf("bech32 convert back: %v", err) | ||
| } | ||
| if len(decoded) != 20 { |
There was a problem hiding this comment.
suggestion — The comment on line 68 says the decoded bech32 must equal ripemd160(sha256(pubkey)), but the test only checks that it is 20 bytes long. A wrong-but-valid address of the right length would still pass. Compare decoded with the hash of the public key from priv, or reword the comment so it matches what the test checks.
|
Heads-up for reviewers: this PR now carries two hand-written commits on top of the dependabot bump (98d0cf7, plus an empty retrigger commit 43417f3). What was added: test coverage pinning the repo's only direct
All green against |
Bumps the go-minor-and-patch group with 1 update in the / directory: golang.org/x/crypto.
Updates
golang.org/x/cryptofrom 0.55.0 to 0.57.0Commits
3f62bf1go.mod: update golang.org/x dependencies86efde5ssh: reject unexpected message types on established channelsa6cdac6ssh: drop traffic on undecided channels39dc44essh: don't skip the source-address critical option in CheckCertafebf4cx509roots/fallback/bundle: make subjectsEqual stricter on Go 1.27+89f4e9bx509roots/fallback: update bundle71488c4ssh/knownhosts: compare only public key portions for revocation82adefassh: synchronize unexpected response testc757c98all: upgrade go directive to at least 1.26.0 [generated]593c81assh: correctly ignore pre-banner linesDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions