Skip to content

Bump golang.org/x/crypto and golang.org/x/sys - #3269

Closed
acts-1631 wants to merge 1 commit into
DNSCrypt:masterfrom
acts-1631:deps-xcrypto-xsys
Closed

Bump golang.org/x/crypto and golang.org/x/sys#3269
acts-1631 wants to merge 1 commit into
DNSCrypt:masterfrom
acts-1631:deps-xcrypto-xsys

Conversation

@acts-1631

Copy link
Copy Markdown

Bumps golang.org/x/crypto 0.53.0 -> 0.54.0 and golang.org/x/sys
0.46.0 -> 0.47.0. These are the two golang.org/x modules dependabot
didn't open PRs for (circl #3257, miekg/dns #3261, kardianos/service
#3265 and powerman/check #3266 cover the rest).

Running go mod tidy also drops the unused github.com/miekg/dns module
and a few stale indirect deps. That same cleanup is in #3257, so
whichever merges first the other should rebase cleanly.

Vendor tree regenerated. Build, go vet and the test suite pass locally.

It would also be appreciated if a new release could be cut whenever
Go security fixes need to land, so downstream users can pick them up
without having to build from source.

Updates x/crypto 0.53.0 -> 0.54.0 and x/sys 0.46.0 -> 0.47.0, the
two golang.org/x modules that dependabot did not pick up (PRs DNSCrypt#3257,
DNSCrypt#3261, DNSCrypt#3265, DNSCrypt#3266 cover circl, miekg/dns, kardianos/service and
powerman/check but not these).

go mod tidy also drops the unused github.com/miekg/dns module and a
few stale indirect deps; the same cleanup shows up in DNSCrypt#3257, so
whichever merges first the other rebases cleanly. The vendor tree
was regenerated to match.
@jedisct1 jedisct1 closed this Jul 8, 2026
@jedisct1

jedisct1 commented Jul 8, 2026

Copy link
Copy Markdown
Member

None of the security issues affecting the current dependencies are relevant to DNSCrypt-proxy.

With supply chain attacks being all the rage, I can't merge such pull requests. Hope you understand.

@acts-1631

Copy link
Copy Markdown
Author

Okay, no problem. I'll still ask that you please consider keeping the deps up to date yourself then as we follow new Go releases with regular security updates. Cutting a dnscrypt-proxy release when affected dependencies are vulnerable would be much appreciated for distros. Thanks for the quick reply.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants