encore.dev icon indicating copy to clipboard operation
encore.dev copied to clipboard

Update go.mod dependencies

Open HectorMalot opened this issue 4 months ago • 0 comments

Hi team,

Context: I realize this repository only holds the contract for development purposes, but some vulnerability scanners - such as Snyk - light up when scanning this, and updating the contract seemed like the more future proof solution than asking everyone to set these warnings to ignore independently.

This PR updates pgx/v5 from v5.2.0 to v5.7.6. This addresses the following vulnerabilities:

GO-2024-2606: SQL injection in github.com/jackc/pgproto3 and github.com/jackc/pgx - resolved in v.5.5.3 GO-2024-2567: Panic in Pipeline when PgConn is busy or closed in github.com/jackc/pgx - resolved in v.5.5.1

It also updates the transitive dependencies. Highlights:

  • golang.org/x/crypt from v0.0.0-20220829220503-c86fa9a7ed90 to v0.42.0 . This addresses
    • GO-2023-2402: Man-in-the-middle attacker can compromise integrity of secure channel in golang.org/x/crypto
    • GO-2024-3321: Misuse of connection.serverAuthenticate may cause authorization bypass in golang.org/x/crypto
    • GO-2025-3487: Potential denial of service in golang.org/x/crypto
  • Introduces github.com/stretchr/testify as a dependency, required for the updated version of pgx/v5
  • Removes go.uber.org/atomic as a dependency (no longer required)

Finally, it updates from go 1.18 to 1.24.

HectorMalot avatar Sep 29 '25 13:09 HectorMalot