fix(deps): update module github.com/russellhaering/goxmldsig to v1.6.0 (#32)
Some checks failed
Release / Create Release (push) Has been skipped
Release / Publish Docker Images (push) Has been skipped
Release / Tag release (push) Failing after 6s

This PR contains the following updates:

| Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
| [github.com/russellhaering/goxmldsig](https://github.com/russellhaering/goxmldsig) | `v1.5.0` → `v1.6.0` | ![age](https://developer.mend.io/api/mc/badges/age/go/github.com%2frussellhaering%2fgoxmldsig/v1.6.0?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/go/github.com%2frussellhaering%2fgoxmldsig/v1.5.0/v1.6.0?slim=true) |

---

### Release Notes

<details>
<summary>russellhaering/goxmldsig (github.com/russellhaering/goxmldsig)</summary>

### [`v1.6.0`](https://github.com/russellhaering/goxmldsig/releases/tag/v1.6.0)

[Compare Source](https://github.com/russellhaering/goxmldsig/compare/v1.5.0...v1.6.0)

#### What's Changed

- **Security:** Fix possible signature validation bypass caused by loop variable capture in `validateSignature` (GHSA-479m-364c-43vc)
- Bump minimum Go version to 1.23
- Bump `github.com/beevik/etree` to v1.6.0
- Add fuzz tests for XML signature validation and canonicalization

**Full Changelog**: <https://github.com/russellhaering/goxmldsig/compare/v1.5.0...v1.6.0>

</details>

---

### Configuration

📅 **Schedule**: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.

♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update again.

---

 - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box

---

This PR has been generated by [Renovate Bot](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My43Ny44IiwidXBkYXRlZEluVmVyIjoiNDMuNzcuOCIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOlsidHlwZS9kZXBlbmRlbmNpZXMiXX0=-->

Reviewed-on: #32
Co-authored-by: renovate[bot] <renovate-bot@git.tainton.uk>
Co-committed-by: renovate[bot] <renovate-bot@git.tainton.uk>
This commit was merged in pull request #32.
This commit is contained in:
2026-03-21 10:38:08 +00:00
committed by Luke Tainton
parent 36b2a1583d
commit 33aff642b1
2 changed files with 3 additions and 1 deletions

2
go.sum
View File

@@ -46,6 +46,8 @@ github.com/russellhaering/goxmldsig v1.4.0 h1:8UcDh/xGyQiyrW+Fq5t8f+l2DLB1+zlhYz
github.com/russellhaering/goxmldsig v1.4.0/go.mod h1:gM4MDENBQf7M+V824SGfyIUVFWydB7n0KkEubVJl+Tw=
github.com/russellhaering/goxmldsig v1.5.0 h1:AU2UkkYIUOTyZRbe08XMThaOCelArgvNfYapcmSjBNw=
github.com/russellhaering/goxmldsig v1.5.0/go.mod h1:x98CjQNFJcWfMxeOrMnMKg70lvDP6tE0nTaeUnjXDmk=
github.com/russellhaering/goxmldsig v1.6.0 h1:8fdWXEPh2k/NZNQBPFNoVfS3JmzS4ZprY/sAOpKQLks=
github.com/russellhaering/goxmldsig v1.6.0/go.mod h1:TrnaquDcYxWXfJrOjeMBTX4mLBeYAqaHEyUeWPxZlBM=
github.com/stretchr/objx v0.1.0/go.mod h1:HFkY916IF+rwdDfMAkV7OtwuqBVzrE8GR6GFx+wExME=
github.com/stretchr/testify v1.6.1/go.mod h1:6Fq8oRcR53rry900zMqJjRRixrwX3KX962/h/Wwjteg=
golang.org/x/crypto v0.25.0 h1:ypSNr+bnYL2YhwoMt2zPxHFmbAN1KZs/njMG3hxUp30=