Skip to content

build(deps): bump golang.org/x/crypto from 0.55.0 to 0.57.0 in the go-minor-and-patch group across 1 directory - #585

Open
dependabot[bot] wants to merge 3 commits into
mainfrom
dependabot/go_modules/go-minor-and-patch-24e67ca7f8
Open

dependabot[bot] wants to merge 3 commits into
mainfrom
dependabot/go_modules/go-minor-and-patch-24e67ca7f8

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 30, 2026

Copy link
Copy Markdown
Contributor

Bumps the go-minor-and-patch group with 1 update in the / directory: golang.org/x/crypto.

Updates golang.org/x/crypto from 0.55.0 to 0.57.0

Commits
  • 3f62bf1 go.mod: update golang.org/x dependencies
  • 86efde5 ssh: reject unexpected message types on established channels
  • a6cdac6 ssh: drop traffic on undecided channels
  • 39dc44e ssh: don't skip the source-address critical option in CheckCert
  • afebf4c x509roots/fallback/bundle: make subjectsEqual stricter on Go 1.27+
  • 89f4e9b x509roots/fallback: update bundle
  • 71488c4 ssh/knownhosts: compare only public key portions for revocation
  • 82adefa ssh: synchronize unexpected response test
  • c757c98 all: upgrade go directive to at least 1.26.0 [generated]
  • 593c81a ssh: correctly ignore pre-banner lines
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the go-minor-and-patch group with 1 update in the / directory: [golang.org/x/crypto](https://github.com/golang/crypto).


Updates `golang.org/x/crypto` from 0.55.0 to 0.57.0
- [Commits](golang/crypto@v0.55.0...v0.57.0)

---
updated-dependencies:
- dependency-name: golang.org/x/crypto
  dependency-version: 0.57.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file go Pull requests that update go code labels Sep 30, 2026
@cursor

cursor Bot commented Sep 30, 2026 •

Copy link
Copy Markdown

PR Summary

Medium Risk
Touches the dependency used for Cosmos address hashing and the keygen.Derive path used by release integration tests for mnemonics/secrets; behavior is intended unchanged but regressions would affect generated identities.

Overview
Bumps golang.org/x/crypto from 0.55.0 to 0.57.0 and refreshes related indirect golang.org/x/* entries in go.mod / go.sum (sync, sys, term, text, mod, tools).

The only application code touched is internal/keygen: address derivation is extracted into cosmosAddress (same ripemd160/sha256/bech32 pipeline as before) so tests can call the production path directly.

Test coverage is expanded so a future crypto bump is less likely to slip through silently: RIPEMD-160 known-answer vectors, Derive() round-trip and uniqueness checks, and the Cosmos fundraiser vector now asserts the exact sei1… string via cosmosAddress instead of only checking the sei1 prefix.

Reviewed by Cursor Bugbot for commit 43417f3. Bugbot is set up for automated code reviews on this repo. Configure here.

bdchatham and others added 2 commits October 1, 2026 15:46
Cover the only direct x/crypto usage in the repo — ripemd160 in the
keygen derivation pipeline — so the 0.55.0 -> 0.57.0 bump has a
known-answer tripwire:

- ripemd160 published KATs
- Derive() round-trip: identity re-derives to the same address and
  its bech32 decodes back to 20 bytes
- fundraiser vector now pins the exact sei1 address through the
  production cosmosAddress path (extracted from Derive)
- two Derive calls do not collide

Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>

@seidroid seidroid Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Nothing material changed: the only new commit (43417f3, 'ci: retrigger checks') is empty, the diff is identical to my last review, and none of my earlier findings has been fixed, so they still stand. Codex again found nothing, so its reading adds nothing, and nothing in the diff blocks.

Non-blocking

1 finding on the changed lines, as inline comments.

  • This is a Dependabot PR, but a second commit (98d0cf7) adds hand-written changes to internal/keygen: the cosmosAddress refactor and new tests. The PR body only describes the version bump. Reviewers who wave through dependency bumps won't see it, and @dependabot recreate or a rebase would drop it. Consider moving it to its own PR or mentioning it in the description.

seidroid review · decision approve · session e96e717f1f3344738f223c7ff18eeac0 · turn resp_claude_57ac031b6734636d4e4d9fc14237925b · item 90eac65130c8575ebe038e88313a7b34

Findings: 0 blocking | 2 non-blocking | 1 posted inline

if err != nil {
t.Fatalf("bech32 convert back: %v", err)
}
if len(decoded) != 20 {

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

suggestion — The comment on line 68 says the decoded bech32 must equal ripemd160(sha256(pubkey)), but the test only checks that it is 20 bytes long. A wrong-but-valid address of the right length would still pass. Compare decoded with the hash of the public key from priv, or reword the comment so it matches what the test checks.

@devin-ai-integration

Copy link
Copy Markdown
Contributor

Heads-up for reviewers: this PR now carries two hand-written commits on top of the dependabot bump (98d0cf7, plus an empty retrigger commit 43417f3).

What was added: test coverage pinning the repo's only direct x/crypto consumer — ripemd160 in internal/keygen's Derive() pipeline (the identity path the release-test Secret depends on):

  • RIPEMD-160 published known-answer vectors — a direct tripwire on the bumped dependency
  • Derive() round-trip: the returned identity re-derives to the same address and its bech32 decodes back to 20 bytes
  • The cosmos-sdk fundraiser vector now asserts the exact sei1… address through the production cosmosAddress path (extracted from Derive, no behavior change)
  • Two Derive() calls must not collide

All green against x/crypto 0.57.0. Caveat: @dependabot recreate or a rebase would drop these commits — if that happens the coverage should land via its own PR instead.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file go Pull requests that update go code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant