Skip to content

Bump github.com/ProtonMail/go-crypto from 1.4.1 to 1.5.0 in /dependency/retrieval in the go-modules group - #1714

Merged
paketo-bot-reviewer merged 1 commit into
mainfrom
dependabot/go_modules/dependency/retrieval/go-modules-b76e187b01
Sep 29, 2026
Merged

paketo-bot-reviewer merged 1 commit into
mainfrom
dependabot/go_modules/dependency/retrieval/go-modules-b76e187b01

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 29, 2026

Copy link
Copy Markdown
Contributor

Bumps the go-modules group in /dependency/retrieval with 1 update: github.com/ProtonMail/go-crypto.

Updates github.com/ProtonMail/go-crypto from 1.4.1 to 1.5.0

Release notes

Sourced from github.com/ProtonMail/go-crypto's releases.

Release v1.5.0

What's Changed

Full Changelog: ProtonMail/go-crypto@v1.4.1...v1.5.0

Commits
  • 9f896c8 fix: Reduce risk of invalid slice access (#331)
  • 1252688 fix: Do not accept malformed ecdh input (#329)
  • ac21ec5 fix: PKESK empty message decryption (#330)
  • d697e70 Reject embedded signatures in primary key binding signatures (#325)
  • d1dc24f Don't panic on unknown AEAD mode in v5/v6 SKESK packets (#322)
  • f7bfe56 Guard against nil issuer key ID on v2 message read path (#319)
  • 4fa2a8d Guard against nil issuer key ID when checking trailing signature (#320)
  • 0c1128b Implement ML-KEM, ML-DSA, and SLH-DSA (#316)
  • 46ad6f0 openpgp: prevent panic when candidate identity has no self-signature (#313)
  • 93713a4 Fix RSA precompute after prime swap (#317)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the go-modules group in /dependency/retrieval with 1 update: [github.com/ProtonMail/go-crypto](https://github.com/ProtonMail/go-crypto).


Updates `github.com/ProtonMail/go-crypto` from 1.4.1 to 1.5.0
- [Release notes](https://github.com/ProtonMail/go-crypto/releases)
- [Commits](ProtonMail/go-crypto@v1.4.1...v1.5.0)

---
updated-dependencies:
- dependency-name: github.com/ProtonMail/go-crypto
  dependency-version: 1.5.0
  dependency-type: indirect
  update-type: version-update:semver-minor
  dependency-group: go-modules
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file go Pull requests that update Go code labels Sep 29, 2026
@dependabot
dependabot Bot requested review from a team as code owners September 29, 2026 16:53
@dependabot
dependabot Bot requested review from pacostas and paketo-bot-reviewer and removed request for a team September 29, 2026 16:53
@paketo-bot paketo-bot added the semver:patch A change requiring a patch version bump label Sep 29, 2026
@paketo-bot-reviewer
paketo-bot-reviewer merged commit a65f886 into main Sep 29, 2026
11 of 12 checks passed
@paketo-bot-reviewer
paketo-bot-reviewer deleted the dependabot/go_modules/dependency/retrieval/go-modules-b76e187b01 branch September 29, 2026 17:04
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file go Pull requests that update Go code semver:patch A change requiring a patch version bump

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants