logo

Database

Non-upgradable dependencies In golang.org/x/crypto

Description

The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues The golang.org/x/crypto/openpgp package is unsafe by design, has numerous known security issues, is not maintained, and should not be used.

If you are required to interoperate with OpenPGP systems and need a maintained package, consider github.com/ProtonMail/go-crypto/openpgp which is a maintained fork that aims to be a drop-in replacement for this package.

Mitigation

Update Impact

Minimal update. May introduce new vulnerabilities or breaking changes.

Ecosystem
Component
FLAT-SY1XY – Vulnerability | Fluid Attacks Database