Skip to content

build(deps): bump golang.org/x/crypto from 0.43.0 to 0.45.0 in the crypto-hardware group#13443

Closed
dependabot[bot] wants to merge 1 commit intomasterfrom
dependabot/go_modules/crypto-hardware-dd7da38a6b
Closed

build(deps): bump golang.org/x/crypto from 0.43.0 to 0.45.0 in the crypto-hardware group#13443
dependabot[bot] wants to merge 1 commit intomasterfrom
dependabot/go_modules/crypto-hardware-dd7da38a6b

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot bot commented on behalf of github Dec 2, 2025

Bumps the crypto-hardware group with 1 update: golang.org/x/crypto.

Updates golang.org/x/crypto from 0.43.0 to 0.45.0

Commits
  • 4e0068c go.mod: update golang.org/x dependencies
  • e79546e ssh: curb GSSAPI DoS risk by limiting number of specified OIDs
  • f91f7a7 ssh/agent: prevent panic on malformed constraint
  • 2df4153 acme/autocert: let automatic renewal work with short lifetime certs
  • bcf6a84 acme: pass context to request
  • b4f2b62 ssh: fix error message on unsupported cipher
  • 79ec3a5 ssh: allow to bind to a hostname in remote forwarding
  • 122a78f go.mod: update golang.org/x dependencies
  • c0531f9 all: eliminate vet diagnostics
  • 0997000 all: fix some comments
  • Additional commits viewable in compare view

Dependabot compatibility score

You can trigger a rebase of this PR by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Note
Automatic rebases have been disabled on this pull request as it has been open for over 30 days.

@dependabot dependabot bot added the dependencies Pull requests that update a dependency file label Dec 2, 2025
@github-project-automation github-project-automation bot moved this to 📌 Triage in FilOz Dec 2, 2025
@Kubuxu
Copy link
Copy Markdown
Contributor

Kubuxu commented Dec 2, 2025

Hold this one as it removes the optimised keccak implementation from F3.

@rjan90 rjan90 moved this from 📌 Triage to 🔎 Awaiting Review in FilOz Dec 3, 2025
Bumps the crypto-hardware group with 1 update: [golang.org/x/crypto](https://github.com/golang/crypto).


Updates `golang.org/x/crypto` from 0.43.0 to 0.45.0
- [Commits](golang/crypto@v0.43.0...v0.45.0)

---
updated-dependencies:
- dependency-name: golang.org/x/crypto
  dependency-version: 0.45.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: crypto-hardware
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot force-pushed the dependabot/go_modules/crypto-hardware-dd7da38a6b branch from 0e74a5f to f555414 Compare January 1, 2026 23:01
Copy link
Copy Markdown
Member

@rvagg rvagg left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Same as filecoin-project/go-f3#1055

Keccak is now not asm optimised using /x/crypto, need to review use of the dependency in here to see what the impact is for us and whether we need to adopt an alternative.

Keep an eye on ethereum/go-ethereum#33323, or do something ourselves in filecoin-project if nobody else trusted does.

@github-project-automation github-project-automation bot moved this from 🔎 Awaiting Review to ⌨️ In Progress in FilOz Jan 5, 2026
@BigLep BigLep moved this from ⌨️ In Progress to 🐱 Todo in FilOz Jan 6, 2026
@rvagg
Copy link
Copy Markdown
Member

rvagg commented Jan 27, 2026

rvagg added a commit to filecoin-project/go-f3 that referenced this pull request Jan 28, 2026
… x/crypto

Replace all usage of golang.org/x/crypto/sha3.NewLegacyKeccak256() with
github.com/filecoin-project/go-keccak, which vendors the assembly-optimised
Keccak permutation from x/crypto@v0.43.0. Starting with x/crypto v0.44.0,
the upstream package removed its amd64 assembly in favor of Go's standard
library crypto/sha3, which does not provide an assembly fast path for
legacy Keccak functions.

With the keccak dependency decoupled, upgrade golang.org/x/crypto to v0.47.0.

Ref: #1055
Ref: filecoin-project/lotus#13443
Ref: ethereum/go-ethereum#33323
rvagg added a commit that referenced this pull request Jan 28, 2026
… x/crypto

Replace all usage of golang.org/x/crypto/sha3.NewLegacyKeccak256() with
github.com/filecoin-project/go-keccak, which vendors the assembly-optimised
Keccak permutation from x/crypto@v0.43.0. Starting with x/crypto v0.44.0,
the upstream package removed its amd64 assembly in favor of Go's standard
library crypto/sha3, which does not provide an assembly fast path for
legacy Keccak functions.

With the keccak dependency decoupled, upgrade golang.org/x/crypto to v0.47.0.

Ref: filecoin-project/go-f3#1055
Ref: #13443
Ref: ethereum/go-ethereum#33323
rvagg added a commit that referenced this pull request Jan 28, 2026
… x/crypto

Replace all usage of golang.org/x/crypto/sha3.NewLegacyKeccak256() with
github.com/filecoin-project/go-keccak, which vendors the assembly-optimised
Keccak permutation from x/crypto@v0.43.0. Starting with x/crypto v0.44.0,
the upstream package removed its amd64 assembly in favor of Go's standard
library crypto/sha3, which does not provide an assembly fast path for
legacy Keccak functions.

With the keccak dependency decoupled, upgrade golang.org/x/crypto to v0.47.0.

Ref: filecoin-project/go-f3#1055
Ref: #13443
Ref: ethereum/go-ethereum#33323
rvagg added a commit that referenced this pull request Jan 28, 2026
… x/crypto

Replace all usage of golang.org/x/crypto/sha3.NewLegacyKeccak256() with
github.com/filecoin-project/go-keccak, which vendors the assembly-optimised
Keccak permutation from x/crypto@v0.43.0. Starting with x/crypto v0.44.0,
the upstream package removed its amd64 assembly in favor of Go's standard
library crypto/sha3, which does not provide an assembly fast path for
legacy Keccak functions.

With the keccak dependency decoupled, upgrade golang.org/x/crypto to v0.47.0.

Ref: filecoin-project/go-f3#1055
Ref: #13443
Ref: ethereum/go-ethereum#33323
rvagg added a commit that referenced this pull request Jan 28, 2026
… x/crypto

Replace all usage of golang.org/x/crypto/sha3.NewLegacyKeccak256() with
github.com/filecoin-project/go-keccak, which vendors the assembly-optimised
Keccak permutation from x/crypto@v0.43.0. Starting with x/crypto v0.44.0,
the upstream package removed its amd64 assembly in favor of Go's standard
library crypto/sha3, which does not provide an assembly fast path for
legacy Keccak functions.

With the keccak dependency decoupled, upgrade golang.org/x/crypto to v0.47.0.

Ref: filecoin-project/go-f3#1055
Ref: #13443
Ref: ethereum/go-ethereum#33323
@rvagg rvagg closed this in 034217e Jan 29, 2026
@github-project-automation github-project-automation bot moved this from 🐱 Todo to 🎉 Done in FilOz Jan 29, 2026
@dependabot @github
Copy link
Copy Markdown
Contributor Author

dependabot bot commented on behalf of github Jan 29, 2026

This pull request was built based on a group rule. Closing it will not ignore any of these versions in future pull requests.

To ignore these dependencies, configure ignore rules in dependabot.yml

@dependabot dependabot bot deleted the dependabot/go_modules/crypto-hardware-dd7da38a6b branch January 29, 2026 12:53
rvagg added a commit to filecoin-project/go-f3 that referenced this pull request Jan 29, 2026
… x/crypto (#1064)

Replace all usage of golang.org/x/crypto/sha3.NewLegacyKeccak256() with
github.com/filecoin-project/go-keccak, which vendors the assembly-optimised
Keccak permutation from x/crypto@v0.43.0. Starting with x/crypto v0.44.0,
the upstream package removed its amd64 assembly in favor of Go's standard
library crypto/sha3, which does not provide an assembly fast path for
legacy Keccak functions.

With the keccak dependency decoupled, upgrade golang.org/x/crypto to v0.47.0.

Closes: #1055
Ref: filecoin-project/lotus#13443
Ref: ethereum/go-ethereum#33323
rjan90 pushed a commit that referenced this pull request Feb 5, 2026
… x/crypto (#13477)

Replace all usage of golang.org/x/crypto/sha3.NewLegacyKeccak256() with
github.com/filecoin-project/go-keccak, which vendors the assembly-optimised
Keccak permutation from x/crypto@v0.43.0. Starting with x/crypto v0.44.0,
the upstream package removed its amd64 assembly in favor of Go's standard
library crypto/sha3, which does not provide an assembly fast path for
legacy Keccak functions.

With the keccak dependency decoupled, upgrade golang.org/x/crypto to v0.47.0.

Ref: filecoin-project/go-f3#1055
Ref: ethereum/go-ethereum#33323
Closes: #13476
Closes: #13443
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

Status: 🎉 Done

Development

Successfully merging this pull request may close these issues.

4 participants