fix(snyk): remediate high-and-above vulnerabilities on feat/CLI-1826 - #762
Open
prodsec-github-automation wants to merge 16 commits into
Open
fix(snyk): remediate high-and-above vulnerabilities on feat/CLI-1826#762prodsec-github-automation wants to merge 16 commits into
prodsec-github-automation wants to merge 16 commits into
Conversation
…ource Applied by snyk fix --agentic via the Snyk ProdSec CircleCI orb, from feat/CLI-1826 at 431ac21. These changes are generated. Review them before merging.
✅ Snyk checks have passed. No issues have been found so far.
💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse. |
✅ Snyk checks have passed. No issues have been found so far.
💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse. |
PR Reviewer Guide 🔍
|
robertolopezlopez
force-pushed
the
feat/CLI-1826
branch
from
September 8, 2026 07:57
431ac21 to
60bbb10
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Snyk agentic fix
The Snyk Open Source scan of
feat/CLI-1826reported vulnerabilities at or above high severity. This branch was produced bysnyk fix --agenticworking on those.Whether that scan also failed the build depends on the Enhanced Gate, which blocks only once a vulnerability has passed its remediation SLA — so this pull request may exist for a build that is green.
3 of 5 fixed.
Fixed
go.modgolang.org/x/cryptoandgolang.org/x/net. No breaking API changes are documented, and the risk to typical application behavior is low. Key Changes: - Security: Rejects path traversal in reference names to prevent vulnerabilities. - Security: Hardens the worktree filesystem against symlink-related issues. - Fix: Corrects how index entries are stored on Windows. Source: GitHub Release v5.19.2go.modv5.19.1tov5.19.2. The release contains security updates and bug fixes. Key Changes: - Updates to dependencies such asgolang.org/x/cryptoandgolang.org/x/netfor security purposes. [1] - A security fix to reject path traversal in reference names. [1] - A bug fix for handling backslashes in index entries on Windows. [1] There are no documented breaking API changes in this patch release. The changes are focused on improving security and fixing platform-specific bugs. Source: GitHub Release Notesgo.modstorage/filesystem/dotgitpackage is the introduction of stricter validation to reject path traversal in reference names. While this is a security enhancement, it is a behavioral change that could cause issues if an application was inadvertently relying on the previous, less strict validation. This change elevates the risk to medium, as it may require verification. Other changes include dependency updates and a fix for handling backslashes on Windows. Recommendation: Verify that any logic creating or handling git reference names does not rely on paths that could now be rejected as traversal attempts.Not fixed
go.modgolang.org/x/crypto/sshthat addresses two Denial of Service (DoS) vulnerabilities. Key Changes: - CVE-2026-56855: Fixes a deadlock vulnerability where a malicious peer could hang an established connection. The server will now treat certain malformed messages as a protocol error and terminate the connection instead of blocking. - CVE-2026-78662: Fixes a deadlock vulnerability on channels that are not yet fully established. The server will now drop unexpected packets on these channels without blocking. Risk Assessment: This upgrade is assessed as medium risk. While these are critical security fixes, the change in error handling—specifically, tearing down connections upon protocol errors where they might have previously hung—is a behavioral change. Systems with non-compliant or custom SSH clients may experience unexpected connection drops that require verification. Source: Security Announcementgo.modgolang.org/x/crypto/sshthat addresses two Denial of Service (DoS) vulnerabilities. Key Changes: - CVE-2026-56855: Fixes a deadlock vulnerability where a malicious peer could hang an established connection. The server will now treat certain malformed messages as a protocol error and terminate the connection instead of blocking. - CVE-2026-78662: Fixes a deadlock vulnerability on channels that are not yet fully established. The server will now drop unexpected packets on these channels without blocking. Risk Assessment: This upgrade is assessed as medium risk. While these are critical security fixes, the change in error handling—specifically, tearing down connections upon protocol errors where they might have previously hung—is a behavioral change. Systems with non-compliant or custom SSH clients may experience unexpected connection drops that require verification. Source: Security AnnouncementA row marked Fix available: No has no upgrade path for
snyk fixto take. One marked Yes does, but needed a change the agent would not make unattended — those are the rows to look at first.This is not necessarily a complete fix. The build on this pull request runs the same Open Source scan and quality gate, so its result — not this description — is the verdict on what is left.
Changes
Snyk ProdSec orb · build 21456 · model
claude-opus-4-8Note
Low Risk
Patch-only dependency bump with security hardening; low API break risk, with a small chance that unusual git reference paths fail after stricter validation.
Overview
Bumps
github.com/go-git/go-git/v5from v5.19.1 to v5.19.2 ingo.modand refreshesgo.sum, with no application code changes.This patch addresses Snyk-reported high issues (symlink/path traversal in reference names and worktree filesystem handling). Stricter validation may reject reference names that previously slipped through; the main consumer is
internal/contributors/collect, which opens local repos for contributor collection.Remaining
golang.org/x/crypto/sshDoS findings were not upgraded in this PR.Reviewed by Cursor Bugbot for commit d526c00. Bugbot is set up for automated code reviews on this repo. Configure here.