stacklok / stacklok/toolhive-core

Drop the GO-2026-5932 openpgp exclusion once rekor releases the migration

Open
#231 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

needs-triage
Dominant language
Go
Stars
2
Forks
4
Avg merge
1d 12h
Merged PRs (30d)
46

Description

Summary

.github/workflows/security.yml excludes GO-2026-5932golang.org/x/crypto/openpgp is deprecated by design, has no fixed version, and never will. Correct today, but it should not be permanent.

Why it exists

Nothing in this module imports openpgp. It arrives four levels up:

container/signer → sigstore-go/pkg/sign → rekor/pkg/pki → rekor/pkg/pki/pgp → golang.org/x/crypto/openpgp

rekor/pkg/pki is a pluggable signature-format registry, so importing it links every format, PGP included. There is no local call site to rewrite.

Every govulncheck trace is package-init reachability, not a call — the package is linked but never parses PGP data. The advisory is "unmaintained, unsafe by design" rather than a specific exploitable bug.

The exclusion arrived with the container/signer port; before that, nothing here linked sigstore-go/pkg/sign, so the advisory was unreachable.

What unblocks removal

Rekor already migrated to ProtonMail/go-crypto/openpgp in sigstore/rekor#2883, merged 2026-07-15, after the v1.5.3 release (2026-07-02). It is on main but unreleased.

Steps once a rekor release past v1.5.3 exists

  1. Bump github.com/sigstore/rekor (indirect, currently v1.5.3), likely via sigstore-go.
  2. Confirm with govulncheck ./....
  3. Remove GO-2026-5932 from IGNORED_VULNS in .github/workflows/security.yml and its justification block.

Note the surrounding check step should stay — it fails on any vulnerability not explicitly listed, which is stricter than the bare action it replaced. Only the entry goes.

stacklok/toolhive carries the same exclusion and needs the same bump against its own go.mod.

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Wait for a Rekor release after v1.5.3, then inspect the indirect Rekor dependency and .github/workflows/security.yml. Bump the dependency, run govulncheck ./..., and remove only the GO-2026-5932 entry and its justification block; the surrounding vulnerability check should remain.

Written by the indexing model from the issue text.

Assessment

Tech stack
github-actions, go
Domain
ci-cd, security
Issue type
Refactor
Difficulty
3/5
Estimated time
1-2 days
Activity status
Quiet
Clarity
Clearly specified
Newbie friendliness
55/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.