fix(snyk): remediate high-and-above vulnerabilities on feat/CLI-1825 - #728
Open
prodsec-github-automation wants to merge 6 commits into
Open
fix(snyk): remediate high-and-above vulnerabilities on feat/CLI-1825#728prodsec-github-automation wants to merge 6 commits into
prodsec-github-automation wants to merge 6 commits into
Conversation
…ource Applied by snyk fix --agentic via the Snyk ProdSec CircleCI orb, from feat/CLI-1825 at 8eaf699. These changes are generated. Review them before merging.
✅ Snyk checks have passed. No issues have been found so far.
💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse. |
✅ Snyk checks have passed. No issues have been found so far.
💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse. |
PR Reviewer Guide 🔍
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Snyk agentic fix
The Snyk Open Source scan of
feat/CLI-1825reported vulnerabilities at or above high severity. This branch was produced bysnyk fix --agenticworking on those.Whether that scan also failed the build depends on the Enhanced Gate, which blocks only once a vulnerability has passed its remediation SLA — so this pull request may exist for a build that is green.
5 of 5 fixed.
Fixed
go.modgolang.org/x/cryptoandgolang.org/x/net. No breaking API changes are documented, and the risk to typical application behavior is low. Key Changes: - Security: Rejects path traversal in reference names to prevent vulnerabilities. - Security: Hardens the worktree filesystem against symlink-related issues. - Fix: Corrects how index entries are stored on Windows. Source: GitHub Release v5.19.2go.modv5.19.1tov5.19.2. The release contains security updates and bug fixes. Key Changes: - Updates to dependencies such asgolang.org/x/cryptoandgolang.org/x/netfor security purposes. [1] - A security fix to reject path traversal in reference names. [1] - A bug fix for handling backslashes in index entries on Windows. [1] There are no documented breaking API changes in this patch release. The changes are focused on improving security and fixing platform-specific bugs. Source: GitHub Release Notesgo.modstorage/filesystem/dotgitpackage is the introduction of stricter validation to reject path traversal in reference names. While this is a security enhancement, it is a behavioral change that could cause issues if an application was inadvertently relying on the previous, less strict validation. This change elevates the risk to medium, as it may require verification. Other changes include dependency updates and a fix for handling backslashes on Windows. Recommendation: Verify that any logic creating or handling git reference names does not rely on paths that could now be rejected as traversal attempts.go.modgolang.org/x/crypto/sshthat addresses two Denial of Service (DoS) vulnerabilities. Key Changes: - CVE-2026-56855: Fixes a deadlock vulnerability where a malicious peer could hang an established connection. The server will now treat certain malformed messages as a protocol error and terminate the connection instead of blocking. - CVE-2026-78662: Fixes a deadlock vulnerability on channels that are not yet fully established. The server will now drop unexpected packets on these channels without blocking. Risk Assessment: This upgrade is assessed as medium risk. While these are critical security fixes, the change in error handling—specifically, tearing down connections upon protocol errors where they might have previously hung—is a behavioral change. Systems with non-compliant or custom SSH clients may experience unexpected connection drops that require verification. Source: Security Announcementgo.modgolang.org/x/crypto/sshthat addresses two Denial of Service (DoS) vulnerabilities. Key Changes: - CVE-2026-56855: Fixes a deadlock vulnerability where a malicious peer could hang an established connection. The server will now treat certain malformed messages as a protocol error and terminate the connection instead of blocking. - CVE-2026-78662: Fixes a deadlock vulnerability on channels that are not yet fully established. The server will now drop unexpected packets on these channels without blocking. Risk Assessment: This upgrade is assessed as medium risk. While these are critical security fixes, the change in error handling—specifically, tearing down connections upon protocol errors where they might have previously hung—is a behavioral change. Systems with non-compliant or custom SSH clients may experience unexpected connection drops that require verification. Source: Security AnnouncementThis is not necessarily a complete fix. The build on this pull request runs the same Open Source scan and quality gate, so its result — not this description — is the verdict on what is left.
Changes
Snyk ProdSec orb · build 21055 · model
claude-opus-4-8Note
Medium Risk
Security fixes in go-git and x/crypto can change runtime behavior (rejected refs/paths, stricter SSH teardown); verify git contributor collection and any SSH remotes still work as expected.
Overview
This PR only updates dependency versions in
go.mod/go.sumto address Snyk high-severity findings; there is no application code change.github.com/go-git/go-git/v5moves from v5.19.1 to v5.19.2, pulling in path-traversal and symlink hardening (including stricter reference-name validation and safer worktree filesystem behavior). That matters for git-based flows such as contributor collection that use go-git’s filesystem storage.golang.org/x/cryptois bumped indirectly (v0.54.0 → v0.56.0) for SSH DoS/deadlock fixes (malformed traffic may now end connections instead of hanging).golang.org/x/mod,golang.org/x/text, andgolang.org/x/toolsare minor patch bumps aligned with the go-git upgrade.Reviewed by Cursor Bugbot for commit 7598b3f. Bugbot is set up for automated code reviews on this repo. Configure here.