Repository navigation
fix: Fix CVE-2026-56854 by bumping golang.org/x/crypto and our Go version - #660
Anton-Kalpakchiev wants to merge 2 commits into
Conversation
… from 1.24 to 1.27 Before this commit, the Kraken repo is vulnerable to X [ref](https://github.com/uber/kraken/actions/runs/34343753316/job/102440351025?pr=659#step:3:357), as shown by our security scanner. To fix it, we need to bump `golang.org/x/crypto` from 0.46.0 to 0.55.0, which requires Go 1.26+. Thus, in this commit I bump both.
golang.org/x/crypto and our Go version
|
Not blocking the CVE fix, but two runtime behavior changes ride along with it. They 1. GOMAXPROCS now follows the cgroup CPU limitFrom the Kraken has no Suggestion: pin it, then remove the block after load testing. 2. Green Tea GC becomes the default, with no opt-outThis comes from the toolchain, not the directive. Agent and origin hold large blob caches and big piece buffers, so expect a different Suggestion: soak-test origin and agent at production memory limits, and watch RSS. |
|
Also why not go only up-to go 1.26 to fix the CVE, Does anything needs 1.27 ? Kraken is a public library, for anyone importing it would set a hard floor. |
Before this commit, the Kraken repo is vulnerable to CVE-2026-56854, as shown by our security scanner. To fix it, we need to bump
golang.org/x/cryptofrom 0.46.0 to 0.55.0, which requires Go 1.26+. Thus, in this commit I bump both.This should be ok, as Go is renowned for its backwards compatability.