Recordsgolanggolang.org/x/cryptofailure issue
Failure signature
PROJECT_PROCESS ERR_ASSERTION Evidence gap ×13
Evidence quality: legacy-evidence-incomplete · First recorded: 2026-08-21 · Last seen: 2026-08-27
Where it was measured
PASS means the release recorded a passing observation at PROJECT_PROCESS and no record of this failure. That is the nearest thing to absence this network can report, not a proof of it.
- v0.55.0 PASS 13 passing observations
- v0.54.0 FAIL
- v0.52.0 PASS 14 passing observations
- v0.36.0 FAIL
- v0.27.0 FAIL
- v0.26.0 FAIL
- v0.20.0 FAIL
- v0.19.0 FAIL
- v0.0.0-20220331220935-ae2d96664a29 FAIL
Where it reproduced
- os=linux · runtime=go@1.26 ×7 2026-08-21 → 2026-08-26
- executionContext=node · moduleSystem=cjs · os=linux · runtime=node@22.23 ×6 2026-08-26 → 2026-08-27
Nearest known PASS/FAIL boundaries
The two adjacent releases the verdict changes across. Releases nothing measured do not close the gap; they are counted instead.
-
Last passing release v0.0.0-20210322153248-0c34fe9e7dc2 → first failing release v0.0.0-20220331220935-ae2d96664a29
Releases between them never measured at this stage: 2
What differs across the boundary
- golang.org/x/net v0.0.0-20210226172049-e18ecbb05110 → — hypothesis
- golang.org/x/sys v0.0.0-20201119102817-f84b799fce68 → — hypothesis
- golang.org/x/term v0.0.0-20201126162022-7de9c90e9dd1 → — hypothesis
A version that moved across the boundary is a candidate, not a cause. Only a receipt that recorded the failure and the tree it resolved in the same run is marked as evidence.
-
Last failing release v0.0.0-20220331220935-ae2d96664a29 → first passing release v0.3.0
What differs across the boundary
- golang.org/x/net v0.2.0 → — hypothesis
- golang.org/x/sys v0.2.0 → — hypothesis
- golang.org/x/term v0.2.0 → — hypothesis
A version that moved across the boundary is a candidate, not a cause. Only a receipt that recorded the failure and the tree it resolved in the same run is marked as evidence.
-
Last passing release v0.11.1-0.20230711161743-2e82bdd1719d → first failing release v0.19.0
What differs across the boundary
- golang.org/x/net v0.10.0 → v0.10.0, v0.21.0 hypothesis
- golang.org/x/sys v0.10.0, v0.47.0 → v0.17.0 hypothesis
- golang.org/x/term v0.10.0 → v0.17.0 hypothesis
A version that moved across the boundary is a candidate, not a cause. Only a receipt that recorded the failure and the tree it resolved in the same run is marked as evidence.
-
Last failing release v0.20.0 → first passing release v0.21.0
What differs across the boundary
- golang.org/x/net v0.21.0, v0.23.0 → v0.21.0 hypothesis
- golang.org/x/sys v0.18.0 → v0.17.0 hypothesis
- golang.org/x/term v0.18.0 → v0.17.0 hypothesis
A version that moved across the boundary is a candidate, not a cause. Only a receipt that recorded the failure and the tree it resolved in the same run is marked as evidence.
-
Last passing release v0.25.0 → first failing release v0.26.0
One side of this boundary has no resolved dependency tree, so nothing could be compared.
-
Last failing release v0.27.0 → first passing release v0.31.0
What differs across the boundary
- golang.org/x/sys v0.28.0 → v0.25.0 hypothesis
- golang.org/x/term v0.27.0 → v0.24.0 hypothesis
A version that moved across the boundary is a candidate, not a cause. Only a receipt that recorded the failure and the tree it resolved in the same run is marked as evidence.
-
Last passing release v0.33.0 → first failing release v0.36.0
One side of this boundary has no resolved dependency tree, so nothing could be compared.
-
Last failing release v0.36.0 → first passing release v0.41.0
One side of this boundary has no resolved dependency tree, so nothing could be compared.
-
Last passing release v0.52.0 → first failing release v0.54.0
What differs across the boundary
- golang.org/x/net v0.54.0, v0.55.0 → v0.56.0, v0.57.0 hypothesis
- golang.org/x/sys v0.45.0 → v0.47.0 hypothesis
- golang.org/x/term v0.43.0 → v0.45.0 hypothesis
A version that moved across the boundary is a candidate, not a cause. Only a receipt that recorded the failure and the tree it resolved in the same run is marked as evidence.
-
Last failing release v0.54.0 → first passing release v0.55.0
What differs across the boundary
- golang.org/x/net v0.57.0 → v0.56.0, v0.57.0 hypothesis
A version that moved across the boundary is a candidate, not a cause. Only a receipt that recorded the failure and the tree it resolved in the same run is marked as evidence.
Dependency versions across releases
What each release of this package resolved its children to. A child whose version moved is listed first: that is where an upgrade changed something underneath you.
| Library | v0.55.0 | v0.54.0 | v0.52.0 | v0.36.0 | v0.27.0 | v0.26.0 | v0.20.0 | v0.19.0 | v0.0.0-20220331220935-ae2d96664a29 |
|---|---|---|---|---|---|---|---|---|---|
| golang.org/x/net | v0.57.0 | v0.57.0 | v0.55.0 | v0.21.0 | v0.21.0 | — | v0.21.0 | v0.21.0 | — |
| golang.org/x/sys | v0.47.0 | v0.47.0 | v0.45.0 | v0.31.0 | v0.25.0 | — | v0.17.0 | v0.17.0 | — |
| golang.org/x/term | v0.45.0 | v0.45.0 | v0.43.0 | v0.30.0 | v0.24.0 | — | v0.17.0 | v0.17.0 | — |
Moved: 3 · unchanged at every release: 0
An edge records that a resolver placed one release beside another on a real machine. It is not a claim that the two work together; that question is answered by samples and contracts, not by presence here.
Evidence gaps
- The evidence for this failure was not preserved, so it has no established cause. Its stored hash is provenance, not an identity.
- No resolved dependency tree for v0.25.0 or for v0.26.0, so the versions either side of the boundary could not be compared.
- No failure domain was inferred for this failure.
Published answers for the affected releases
- golang.org/x/crypto v0.54.0: hkdf.New This network offers one thing: a sample that builds. It ran the sample in a sandbox and kept the signed receipt. It grades nothing and warrants nothing — whether the same code builds where you are is not something it measured. HOWhkdf.New MIT-0 · 2026-08-30
- golang.org/x/crypto v0.54.0: scrypt.Key This network offers one thing: a sample that builds. It ran the sample in a sandbox and kept the signed receipt. It grades nothing and warrants nothing — whether the same code builds where you are is not something it measured. HOWscrypt.Key MIT-0 · 2026-08-30
- golang.org/x/crypto v0.54.0: blake2b.New256 This network offers one thing: a sample that builds. It ran the sample in a sandbox and kept the signed receipt. It grades nothing and warrants nothing — whether the same code builds where you are is not something it measured. HOWblake2b.New256go 1.26 MIT-0 · 2026-08-30
- golang.org/x/crypto v0.36.0: scrypt.Key This network offers one thing: a sample that builds. It ran the sample in a sandbox and kept the signed receipt. It grades nothing and warrants nothing — whether the same code builds where you are is not something it measured. HOWscrypt.Key MIT-0 · 2026-09-02
- golang.org/x/crypto v0.36.0: bcrypt.CompareHashAndPassword, bcrypt.Cost, bcrypt.GenerateFromPassword This network offers one thing: a sample that builds. It ran the sample in a sandbox and kept the signed receipt. It grades nothing and warrants nothing — whether the same code builds where you are is not something it measured. HOWgolang.org/x/crypto/bcrypt.CompareHashAndPasswordgolang.org/x/crypto/bcrypt.Costgolang.org/x/crypto/bcrypt.GenerateFromPassword MIT-0 · 2026-08-27
- golang.org/x/crypto v0.36.0: chacha20poly1305.NewX This network offers one thing: a sample that builds. It ran the sample in a sandbox and kept the signed receipt. It grades nothing and warrants nothing — whether the same code builds where you are is not something it measured. HOWchacha20poly1305.NewXgo 1.26.6 MIT-0 · 2026-08-26