Conversation
Bumps [github.com/ProtonMail/go-crypto](https://github.com/ProtonMail/go-crypto) from 1.0.0 to 1.1.2. - [Release notes](https://github.com/ProtonMail/go-crypto/releases) - [Commits](ProtonMail/go-crypto@v1.0.0...v1.1.2) --- updated-dependencies: - dependency-name: github.com/ProtonMail/go-crypto dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <[email protected]>
Codecov ReportAll modified and coverable lines are covered by tests ✅
Additional details and impacted files@@ Coverage Diff @@
## main #391 +/- ##
==========================================
+ Coverage 65.39% 65.48% +0.08%
==========================================
Files 37 37
Lines 3263 3265 +2
==========================================
+ Hits 2134 2138 +4
+ Misses 975 973 -2
Partials 154 154 ☔ View full report in Codecov by Sentry. |
|
Investigating the failures here, which are due to differences in the signatures generated by v1.0.0 and v1.1.2: The new |
|
While the The other diffs appear to be related to the creation time and issuer key ID sub-packets being made critical (see ProtonMail/go-crypto#208): Signature Packet, new CTB, 307 bytes Signature Packet, new CTB, 307 bytes
Version: 4 Version: 4
Type: Text Type: Text
Pk algo: RSA Pk algo: RSA
Hash algo: SHA256 Hash algo: SHA256
Hashed area: Hashed area:
Signature creation time: 2020-06-30 00:01:56 UTC | Signature creation time: 2020-06-30 00:01:56 UTC (critical)
Issuer: A20C27EE7FF7BA84 | Issuer: A20C27EE7FF7BA84 (critical)
Issuer Fingerprint: 12045C8C0B1004D058DE4BEDA20C27EE7FF7BA84 Issuer Fingerprint: 12045C8C0B1004D058DE4BEDA20C27EE7FF7BA84
Digest prefix: C22C | Digest prefix: 17DA
Level: 0 (signature over data) Level: 0 (signature over data) |
Add OptSignWithoutPGPSignatureSalt, which disables randomization of signature generation, and use that in the corpus to generate images deterministically. Update corpus images and related golden files to reflect the signatures generated by the new version of go-crypto.
2063ae3 to
071c3a8
Compare
Bumps github.com/ProtonMail/go-crypto from 1.0.0 to 1.1.2.
Release notes
Sourced from github.com/ProtonMail/go-crypto's releases.
... (truncated)
Commits
2d2c789feat(cleartext): Do not include line ending separator in plaintext (#242)f8b3f21Remove cleartext Encode header argument #239 (#240)b97cc3cfeat: Validate input key size in SEIPDv2 decryption (#236)20ab0e4Replace expiring curve448 integration test vector (#235)f6ad483No v6 ECC keys with legacy OIDs (#234)77090feFix ECDH using v6 keys (#233)7852179Add support for keyserver preferences and preferred keyserver (closes #206) (...2add693Add back crypto.Signer support for ECDSA signing keys (#227)0f7b935ci: Fix CI for v1 interoptest (#229)b5837faci: Change gosop branch for gopenpgp-v2 to gosop-gopenpgp-v2 (#224)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge and block automerging@dependabot reopenwill reopen this PR if it is closed@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)