Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebase will rebase this PR
@dependabot recreate will recreate this PR, overwriting any edits that have been made to it
@dependabot merge will merge this PR after your CI passes on it
@dependabot squash and merge will squash and merge this PR after your CI passes on it
@dependabot cancel merge will cancel a previously requested merge and block automerging
@dependabot reopen will reopen this PR if it is closed
@dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
@dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
@dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
@dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
Bumps [golang.org/x/crypto](https://github.com/golang/crypto) from 0.4.0 to 0.7.0.
<details>
<summary>Commits</summary>
<ul>
<li><a href="https://github.com/golang/crypto/commit/776e461a4e6d8b372a43c72122c5c28cfc40dca2"><code>776e461</code></a> go.mod: update golang.org/x dependencies</li>
<li><a href="https://github.com/golang/crypto/commit/ebe92624d1428c68f92576e1d27cc65d62bc2f7e"><code>ebe9262</code></a> ssh: add support for <a href="mailto:aes256-gcm@openssh.com">aes256-gcm@openssh.com</a></li>
<li><a href="https://github.com/golang/crypto/commit/a9f661cb6e1b78478731da332a7b82f1e2fd779c"><code>a9f661c</code></a> go.mod: update golang.org/x dependencies</li>
<li><a href="https://github.com/golang/crypto/commit/310bfa40f1e490c722a9c86d8ede143d3d506be5"><code>310bfa4</code></a> cryptobyte: reject negative Unwrite argument</li>
<li><a href="https://github.com/golang/crypto/commit/59ff47295ca89b9497fc7964d4777b2a9edd1e22"><code>59ff472</code></a> all: fix some comments</li>
<li><a href="https://github.com/golang/crypto/commit/3d872d042823aed41f28af3b13beb27c0c9b1e35"><code>3d872d0</code></a> go.mod: update golang.org/x dependencies</li>
<li><a href="https://github.com/golang/crypto/commit/bc7d1d1eb54b3530da4f5ec31625c95d7df40231"><code>bc7d1d1</code></a> bcrypt: reject passwords longer than 72 bytes</li>
<li><a href="https://github.com/golang/crypto/commit/7e3ac2043e18f9cbc0c089cb28e73caac2c9d9d1"><code>7e3ac20</code></a> internal/wycheproof: also use Verify in TestECDSA</li>
<li><a href="https://github.com/golang/crypto/commit/23edec0b383afbf83bd3e94309cfe09a01a68a99"><code>23edec0</code></a> ssh: ensure that handshakeTransport goroutines have finished before Close ret...</li>
<li><a href="https://github.com/golang/crypto/commit/f495dc37d5f5cc59ca73af6acbbe0a741559792b"><code>f495dc3</code></a> acme: eliminate arbitrary timeouts in tests</li>
<li>See full diff in <a href="https://github.com/golang/crypto/compare/v0.4.0...v0.7.0">compare view</a></li>
</ul>
</details>
<br />
[](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.
[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)
---
<details>
<summary>Dependabot commands and options</summary>
<br />
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot squash and merge` will squash and merge this PR after your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge and block automerging
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
</details>
OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.
If you change your mind, just re-open this PR and I'll resolve any conflicts on it.
OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting `@dependabot ignore this major version` or `@dependabot ignore this minor version`. You can also ignore all major, minor, or patch releases for a dependency by adding an [`ignore` condition](https://docs.github.com/en/code-security/supply-chain-security/configuration-options-for-dependency-updates#ignore) with the desired `update_types` to your config file.
If you change your mind, just re-open this PR and I'll resolve any conflicts on it.
Pull request closed
This pull request cannot be reopened because the branch was deleted.
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Bumps golang.org/x/crypto from 0.4.0 to 0.7.0.
Commits
776e461go.mod: update golang.org/x dependenciesebe9262ssh: add support for aes256-gcm@openssh.coma9f661cgo.mod: update golang.org/x dependencies310bfa4cryptobyte: reject negative Unwrite argument59ff472all: fix some comments3d872d0go.mod: update golang.org/x dependenciesbc7d1d1bcrypt: reject passwords longer than 72 bytes7e3ac20internal/wycheproof: also use Verify in TestECDSA23edec0ssh: ensure that handshakeTransport goroutines have finished before Close ret...f495dc3acme: eliminate arbitrary timeouts in testsDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge and block automerging@dependabot reopenwill reopen this PR if it is closed@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting
@dependabot ignore this major versionor@dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding anignorecondition with the desiredupdate_typesto your config file.If you change your mind, just re-open this PR and I'll resolve any conflicts on it.
Pull request closed