Conversation
- go get 升级 20+ 直接/间接依赖修复可达漏洞:
frp v0.67.0→v0.70.1、lego v4.14.2→v4.25.2、caddy v2.11.1→v2.11.4、
golang.org/x/{crypto,net,text}、grpc、otel 全家、quic-go、certmagic、
coreos/go-oidc、go-jose、go-ntlmssp v0.0.0→v0.1.1、mysql 等
- frp v0.70 API 适配:ServiceOptions 移除 ProxyCfgs/VisitorCfgs 字段,
改用 source.NewConfigSource + NewAggregator 传入内存配置
- go mod tidy 清理僵尸依赖,无残留
govulncheck 实测(与 upstream/main 同口径、同 caddy 编译修正):
上游 39 个可达漏洞 → 本分支 3 个
剩余 3 个(GO-2025-3585 / GO-2024-3331 / GO-2022-0572)均来自
beego v1.12.14(nps 内嵌库,djylb/nps 依赖链),上游无修复版本,
Fixed in: N/A,暂记为已知项。
(issue PIKACHUIM#124 PR-3)
suantea
force-pushed
the
chore/deps-audit
branch
from
September 30, 2026 06:57
0bad90d to
e7c92e4
Compare
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
背景
issue #124 PR-3。原 PR 基于陈旧基线(92 文件),现 rebase 到最新
upstream/main,收敛为 3 个文件(go.mod/go.sum/frp/manager.go)。govulncheck 实测结果
用同口径方法测量(本分支与 upstream/main 都先修正
service/caddy/manager.go的编译错误,否则 govulncheck 无法完整分析调用图):upstream/main剩余 3 个:
github.com/beego/beego@v1.12.14github.laiyagushi.com/beego/beego@v1.12.14github.laiyagushi.com/beego/beego@v1.12.14均来自
beego v1(djylb/nps依赖链),上游无修复版本(Fixed in: N/A),只能通过升级 nps 上游或替换该依赖解决,暂记为已知项。依赖升级明细
主要升级:
go mod tidy无僵尸依赖残留。代码适配:frp v0.70 API 变更
v0.70 移除了
client.ServiceOptions的ProxyCfgs/VisitorCfgs字段,改为必须通过ConfigSourceAggregator传入:注意
ReplaceAll的错误此前被忽略会导致「配置静默不生效」,因此这里显式处理并写入last_error。验收
go build ./...通过go vet ./...通过go mod tidy后无 diff 残留govulncheck ./...:可达漏洞 39 → 3已知问题(非本 PR 引入)
upstream/main的service/caddy/manager.go:934编译错误会导致 CIUNSTABLE,在 upstream/main 上同样复现。