Non-upgradable dependencies In golang.org/x/crypto
Description
The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues The golang.org/x/crypto/openpgp package is unsafe by design, has numerous known security issues, is not maintained, and should not be used.
If you are required to interoperate with OpenPGP systems and need a maintained package, consider github.com/ProtonMail/go-crypto/openpgp which is a maintained fork that aims to be a drop-in replacement for this package.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component |
|---|---|
go |
Aliases
1. 2.
References
1.