Skip to content

chore(deps): security audit - upgrade 15+ modules, reachable vulns 39 -> 3 - #127

Open
suantea wants to merge 1 commit into
PIKACHUIM:mainfrom
suantea:chore/deps-audit
Open

suantea wants to merge 1 commit into
PIKACHUIM:mainfrom
suantea:chore/deps-audit

Conversation

@suantea

@suantea suantea commented Sep 30, 2026 •

Copy link
Copy Markdown
Collaborator

背景

issue #124 PR-3。原 PR 基于陈旧基线(92 文件),现 rebase 到最新 upstream/main,收敛为 3 个文件(go.mod / go.sum / frp/manager.go)。

govulncheck 实测结果

用同口径方法测量(本分支与 upstream/main 都先修正 service/caddy/manager.go 的编译错误,否则 govulncheck 无法完整分析调用图):

可达漏洞数
upstream/main 39
本分支 3

剩余 3 个:

ID 模块 修复版本
GO-2025-3585 github.com/beego/beego@v1.12.14 N/A
GO-2024-3331 github.com/beego/beego@v1.12.14 N/A
GO-2022-0572 github.com/beego/beego@v1.12.14 N/A

均来自 beego v1(djylb/nps 依赖链),上游无修复版本(Fixed in: N/A),只能通过升级 nps 上游或替换该依赖解决,暂记为已知项。

依赖升级明细

主要升级:

github.com/fatedier/frp          v0.67.0  → v0.70.1
github.com/go-acme/lego/v4       v4.14.2  → v4.25.2
github.com/caddyserver/caddy/v2  v2.11.1  → v2.11.4
github.com/caddyserver/certmagic v0.25.2  → v0.25.3
github.com/coreos/go-oidc/v3     v3.17.0  → v3.18.0
github.com/quic-go/quic-go       v0.59.0  → v0.60.0
github.com/Azure/go-ntlmssp      v0.0.0-2022... → v0.1.1
github.com/go-sql-driver/mysql   v1.8.1   → v1.9.3
golang.org/x/{crypto,net,text}   → 最新
grpc / otel 全家                 → 最新

go mod tidy 无僵尸依赖残留。

代码适配:frp v0.70 API 变更

v0.70 移除了 client.ServiceOptions 的 ProxyCfgs / VisitorCfgs 字段,改为必须通过 ConfigSourceAggregator 传入:

cfgSource := source.NewConfigSource()
if err := cfgSource.ReplaceAll(proxyCfgs, nil); err != nil {
    m.setClientError(id, err.Error())
    return fmt.Errorf("加载 FRP 代理配置失败: %w", err)
}
svc, err := client.NewService(client.ServiceOptions{
    Common:                 frpCfg,
    ConfigSourceAggregator: source.NewAggregator(cfgSource),
    ConfigFilePath:         "",
})

注意 ReplaceAll 的错误此前被忽略会导致「配置静默不生效」,因此这里显式处理并写入 last_error。

验收

  • go build ./... 通过
  • go vet ./... 通过
  • go mod tidy 后无 diff 残留
  • govulncheck ./...:可达漏洞 39 → 3

已知问题(非本 PR 引入)

upstream/main 的 service/caddy/manager.go:934 编译错误会导致 CI UNSTABLE,在 upstream/main 上同样复现。

- go get 升级 20+ 直接/间接依赖修复可达漏洞:
  frp v0.67.0→v0.70.1、lego v4.14.2→v4.25.2、caddy v2.11.1→v2.11.4、
  golang.org/x/{crypto,net,text}、grpc、otel 全家、quic-go、certmagic、
  coreos/go-oidc、go-jose、go-ntlmssp v0.0.0→v0.1.1、mysql 等
- frp v0.70 API 适配:ServiceOptions 移除 ProxyCfgs/VisitorCfgs 字段,
  改用 source.NewConfigSource + NewAggregator 传入内存配置
- go mod tidy 清理僵尸依赖,无残留

govulncheck 实测(与 upstream/main 同口径、同 caddy 编译修正):
  上游 39 个可达漏洞 → 本分支 3 个
剩余 3 个(GO-2025-3585 / GO-2024-3331 / GO-2022-0572)均来自
beego v1.12.14(nps 内嵌库,djylb/nps 依赖链),上游无修复版本,
Fixed in: N/A,暂记为已知项。

(issue PIKACHUIM#124 PR-3)

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant