stacklok / stacklok/toolhive-core
Drop the GO-2026-5932 openpgp exclusion once rekor releases the migration
Nobody has claimed this yet.
- Dominant language
- Go
- Stars
- 2
- Forks
- 4
- Avg merge
- 1d 12h
- Merged PRs (30d)
- 46
Description
Summary
.github/workflows/security.yml excludes GO-2026-5932 — golang.org/x/crypto/openpgp is deprecated by design, has no fixed version, and never will. Correct today, but it should not be permanent.
Why it exists
Nothing in this module imports openpgp. It arrives four levels up:
container/signer → sigstore-go/pkg/sign → rekor/pkg/pki → rekor/pkg/pki/pgp → golang.org/x/crypto/openpgp
rekor/pkg/pki is a pluggable signature-format registry, so importing it links every format, PGP included. There is no local call site to rewrite.
Every govulncheck trace is package-init reachability, not a call — the package is linked but never parses PGP data. The advisory is "unmaintained, unsafe by design" rather than a specific exploitable bug.
The exclusion arrived with the container/signer port; before that, nothing here linked sigstore-go/pkg/sign, so the advisory was unreachable.
What unblocks removal
Rekor already migrated to ProtonMail/go-crypto/openpgp in sigstore/rekor#2883, merged 2026-07-15, after the v1.5.3 release (2026-07-02). It is on main but unreleased.
Steps once a rekor release past v1.5.3 exists
- Bump
github.com/sigstore/rekor(indirect, currently v1.5.3), likely viasigstore-go. - Confirm with
govulncheck ./.... - Remove
GO-2026-5932fromIGNORED_VULNSin.github/workflows/security.ymland its justification block.
Note the surrounding check step should stay — it fails on any vulnerability not explicitly listed, which is stricter than the bare action it replaced. Only the entry goes.
stacklok/toolhive carries the same exclusion and needs the same bump against its own go.mod.
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Wait for a Rekor release after v1.5.3, then inspect the indirect Rekor dependency and .github/workflows/security.yml. Bump the dependency, run govulncheck ./..., and remove only the GO-2026-5932 entry and its justification block; the surrounding vulnerability check should remain.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- github-actions, go
- Domain
- ci-cd, security
- Issue type
- Refactor
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Activity status
- Quiet
- Clarity
- Clearly specified
- Newbie friendliness
- 55/100