stacklok / stacklok/toolhive

Drop the GO-2026-5932 openpgp exclusion once rekor releases the migration

Open
#6,287 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

needs-triage
Dominant language
Go
Stars
2.2k
Forks
300
Avg merge
1d 15h
Merged PRs (30d)
184

Description

Summary

.github/workflows/security-scan.yml excludes GO-2026-5932golang.org/x/crypto/openpgp is deprecated by design, has no fixed version, and never will. The exclusion is currently correct, but it should not be permanent, and a suppression with no expiry tends to become one.

Why it exists

Nothing in ToolHive imports openpgp. It arrives four levels up:

pkg/skills/signer → sigstore-go/pkg/sign → rekor/pkg/pki → rekor/pkg/pki/pgp → golang.org/x/crypto/openpgp

rekor/pkg/pki is a pluggable signature-format registry, so importing it links every format, PGP included. There is no local call site to rewrite.

Every govulncheck trace is package-init reachability (signer.init calls sign.init, which eventually calls armor.init), not a call — the package is linked but never parses PGP data on any ToolHive path. The advisory is "unmaintained, unsafe by design" rather than a specific exploitable bug, and that risk only materialises when parsing untrusted PGP input.

What unblocks removal

Rekor already migrated to ProtonMail/go-crypto/openpgp in sigstore/rekor#2883, merged 2026-07-15. The latest release, v1.5.3, is from 2026-07-02 and predates it, so the fix is on main but unreleased.

Steps once a rekor release past v1.5.3 exists

  1. Bump github.com/sigstore/rekor (indirect, currently v1.5.3) — likely via a sigstore-go bump rather than directly.
  2. Confirm the advisory is gone: govulncheck ./... should no longer report GO-2026-5932.
  3. Remove GO-2026-5932 from IGNORED_VULNS in .github/workflows/security-scan.yml, along with its justification block.

stacklok/toolhive-core carries the same exclusion for the same reason and needs the same treatment — it has its own go.mod, so it is a separate bump.

Context: #6286.

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Wait for a Rekor release newer than v1.5.3, then inspect go.mod and .github/workflows/security-scan.yml in both ToolHive and toolhive-core. Bump the dependency as needed, run govulncheck ./..., and remove GO-2026-5932 plus its justification from each workflow once the advisory is absent.

Written by the indexing model from the issue text.

Assessment

Tech stack
github-actions, go
Domain
ci-cd, security
Issue type
Refactor
Difficulty
3/5
Estimated time
1-2 days
Activity status
Quiet
Clarity
Mostly clear
Newbie friendliness
55/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.