fix(snyk): remediate high-and-above vulnerabilities on feat/IANDT-27-contributors-post-invoke-hook - #734
Open
prodsec-github-automation wants to merge 2 commits into
Conversation
…ource Applied by snyk fix --agentic via the Snyk ProdSec CircleCI orb, from feat/IANDT-27-contributors-post-invoke-hook at 1898045. These changes are generated. Review them before merging.
✅ Snyk checks have passed. No issues have been found so far.
💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse. |
✅ Snyk checks have passed. No issues have been found so far.
💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse. |
PR Reviewer Guide 🔍
|
Base automatically changed from
feat/IANDT-27-contributors-post-invoke-hook
to
main
September 4, 2026 15:23
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Snyk agentic fix
The Snyk Open Source scan of
feat/IANDT-27-contributors-post-invoke-hookreported vulnerabilities at or above high severity. This branch was produced bysnyk fix --agenticworking on those.Whether that scan also failed the build depends on the Enhanced Gate, which blocks only once a vulnerability has passed its remediation SLA — so this pull request may exist for a build that is green.
5 of 5 fixed.
Fixed
go.modgolang.org/x/cryptoandgolang.org/x/net. No breaking API changes are documented, and the risk to typical application behavior is low. Key Changes: - Security: Rejects path traversal in reference names to prevent vulnerabilities. - Security: Hardens the worktree filesystem against symlink-related issues. - Fix: Corrects how index entries are stored on Windows. Source: GitHub Release v5.19.2go.modv5.19.1tov5.19.2. The release contains security updates and bug fixes. Key Changes: - Updates to dependencies such asgolang.org/x/cryptoandgolang.org/x/netfor security purposes. [1] - A security fix to reject path traversal in reference names. [1] - A bug fix for handling backslashes in index entries on Windows. [1] There are no documented breaking API changes in this patch release. The changes are focused on improving security and fixing platform-specific bugs. Source: GitHub Release Notesgo.modstorage/filesystem/dotgitpackage is the introduction of stricter validation to reject path traversal in reference names. While this is a security enhancement, it is a behavioral change that could cause issues if an application was inadvertently relying on the previous, less strict validation. This change elevates the risk to medium, as it may require verification. Other changes include dependency updates and a fix for handling backslashes on Windows. Recommendation: Verify that any logic creating or handling git reference names does not rely on paths that could now be rejected as traversal attempts.go.modgolang.org/x/crypto/sshthat addresses two Denial of Service (DoS) vulnerabilities. Key Changes: - CVE-2026-56855: Fixes a deadlock vulnerability where a malicious peer could hang an established connection. The server will now treat certain malformed messages as a protocol error and terminate the connection instead of blocking. - CVE-2026-78662: Fixes a deadlock vulnerability on channels that are not yet fully established. The server will now drop unexpected packets on these channels without blocking. Risk Assessment: This upgrade is assessed as medium risk. While these are critical security fixes, the change in error handling—specifically, tearing down connections upon protocol errors where they might have previously hung—is a behavioral change. Systems with non-compliant or custom SSH clients may experience unexpected connection drops that require verification. Source: Security Announcementgo.modgolang.org/x/crypto/sshthat addresses two Denial of Service (DoS) vulnerabilities. Key Changes: - CVE-2026-56855: Fixes a deadlock vulnerability where a malicious peer could hang an established connection. The server will now treat certain malformed messages as a protocol error and terminate the connection instead of blocking. - CVE-2026-78662: Fixes a deadlock vulnerability on channels that are not yet fully established. The server will now drop unexpected packets on these channels without blocking. Risk Assessment: This upgrade is assessed as medium risk. While these are critical security fixes, the change in error handling—specifically, tearing down connections upon protocol errors where they might have previously hung—is a behavioral change. Systems with non-compliant or custom SSH clients may experience unexpected connection drops that require verification. Source: Security AnnouncementThis is not necessarily a complete fix. The build on this pull request runs the same Open Source scan and quality gate, so its result — not this description — is the verdict on what is left.
Changes
Snyk ProdSec orb · build 21136 · model
claude-opus-4-8Note
Medium Risk
Security patches touch go-git path validation and x/crypto SSH connection handling, which can change behavior for malformed refs or non-compliant SSH peers even though application code is unchanged.
Overview
This PR updates only
go.modandgo.sumto remediate high-severity Open Source findings reported by Snyk (agentic fix).github.com/go-git/go-git/v5is bumped v5.19.1 → v5.19.2, addressing symlink and directory-traversal issues in git plumbing and filesystem storage. That dependency is used in contributor/git workflows (e.g.internal/contributors/collect.go), so the patch mainly tightens reference-name validation and worktree symlink handling rather than changing application code here.Transitive
golang.org/xmodules are also raised:golang.org/x/cryptov0.54.0 → v0.56.0 (SSH DoS/deadlock fixes), plus minor bumps togolang.org/x/mod,golang.org/x/text, andgolang.org/x/toolsto align with the upgraded tree.No first-party Go source changes; reviewers should treat this like a security-focused dependency bump and sanity-check git/SSH-related paths if anything relied on previously lax reference handling.
Reviewed by Cursor Bugbot for commit de785ec. Bugbot is set up for automated code reviews on this repo. Configure here.