-
Notifications
You must be signed in to change notification settings - Fork 10
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
build(deps): bump github.com/ProtonMail/go-crypto from 1.0.0 to 1.1.2 #391
build(deps): bump github.com/ProtonMail/go-crypto from 1.0.0 to 1.1.2 #391
Conversation
Bumps [github.com/ProtonMail/go-crypto](https://github.com/ProtonMail/go-crypto) from 1.0.0 to 1.1.2. - [Release notes](https://github.com/ProtonMail/go-crypto/releases) - [Commits](ProtonMail/go-crypto@v1.0.0...v1.1.2) --- updated-dependencies: - dependency-name: github.com/ProtonMail/go-crypto dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <[email protected]>
Codecov ReportAll modified and coverable lines are covered by tests ✅
Additional details and impacted files@@ Coverage Diff @@
## main #391 +/- ##
==========================================
+ Coverage 65.39% 65.48% +0.08%
==========================================
Files 37 37
Lines 3263 3265 +2
==========================================
+ Hits 2134 2138 +4
+ Misses 975 973 -2
Partials 154 154 ☔ View full report in Codecov by Sentry. |
Investigating the failures here, which are due to differences in the signatures generated by v1.0.0 and v1.1.2:
The new |
While the The other diffs appear to be related to the creation time and issuer key ID sub-packets being made critical (see ProtonMail/go-crypto#208): Signature Packet, new CTB, 307 bytes Signature Packet, new CTB, 307 bytes
Version: 4 Version: 4
Type: Text Type: Text
Pk algo: RSA Pk algo: RSA
Hash algo: SHA256 Hash algo: SHA256
Hashed area: Hashed area:
Signature creation time: 2020-06-30 00:01:56 UTC | Signature creation time: 2020-06-30 00:01:56 UTC (critical)
Issuer: A20C27EE7FF7BA84 | Issuer: A20C27EE7FF7BA84 (critical)
Issuer Fingerprint: 12045C8C0B1004D058DE4BEDA20C27EE7FF7BA84 Issuer Fingerprint: 12045C8C0B1004D058DE4BEDA20C27EE7FF7BA84
Digest prefix: C22C | Digest prefix: 17DA
Level: 0 (signature over data) Level: 0 (signature over data) |
Add OptSignWithoutPGPSignatureSalt, which disables randomization of signature generation, and use that in the corpus to generate images deterministically. Update corpus images and related golden files to reflect the signatures generated by the new version of go-crypto.
2063ae3
to
071c3a8
Compare
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM
Bumps github.com/ProtonMail/go-crypto from 1.0.0 to 1.1.2.
Release notes
Sourced from github.com/ProtonMail/go-crypto's releases.
... (truncated)
Commits
2d2c789
feat(cleartext): Do not include line ending separator in plaintext (#242)f8b3f21
Remove cleartext Encode header argument #239 (#240)b97cc3c
feat: Validate input key size in SEIPDv2 decryption (#236)20ab0e4
Replace expiring curve448 integration test vector (#235)f6ad483
No v6 ECC keys with legacy OIDs (#234)77090fe
Fix ECDH using v6 keys (#233)7852179
Add support for keyserver preferences and preferred keyserver (closes #206) (...2add693
Add back crypto.Signer support for ECDSA signing keys (#227)0f7b935
ci: Fix CI for v1 interoptest (#229)b5837fa
ci: Change gosop branch for gopenpgp-v2 to gosop-gopenpgp-v2 (#224)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase
.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebase
will rebase this PR@dependabot recreate
will recreate this PR, overwriting any edits that have been made to it@dependabot merge
will merge this PR after your CI passes on it@dependabot squash and merge
will squash and merge this PR after your CI passes on it@dependabot cancel merge
will cancel a previously requested merge and block automerging@dependabot reopen
will reopen this PR if it is closed@dependabot close
will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot show <dependency name> ignore conditions
will show all of the ignore conditions of the specified dependency@dependabot ignore this major version
will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor version
will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependency
will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)