Recordsgolanggolang.org/x/cryptofailure issue
Failure signature
PROJECT_PROCESS Evidence gap ×1
Evidence quality: legacy-evidence-incomplete · First recorded: 2026-08-21 · Last seen: 2026-08-26
golang.org/x/crypto/bcrypt.CompareHashAndPassword golang.org/x/crypto/bcrypt.Cost golang.org/x/crypto/bcrypt.DefaultCost golang.org/x/crypto/bcrypt.ErrMismatchedHashAndPassword golang.org/x/crypto/bcrypt.ErrPasswordTooLong golang.org/x/crypto/bcrypt.GenerateFromPassword golang.org/x/crypto/bcrypt.InvalidCostError golang.org/x/crypto/bcrypt.MaxCost golang.org/x/crypto/bcrypt.MinCost golang.org/x/crypto/chacha20poly1305.KeySize golang.org/x/crypto/chacha20poly1305.New golang.org/x/crypto/chacha20poly1305.NewX golang.org/x/crypto/chacha20poly1305.NonceSize golang.org/x/crypto/chacha20poly1305.NonceSizeX golang.org/x/crypto/chacha20poly1305.Overhead
Where it was measured
PASS means the release recorded a passing observation at PROJECT_PROCESS and no record of this failure. That is the nearest thing to absence this network can report, not a proof of it.
- v0.42.0 PASS 1 passing observations
- v0.41.0 PASS 9 passing observations
- v0.36.0 FAIL
- v0.33.0 PASS 1 passing observations
- v0.31.0 PASS 4 passing observations
- v0.27.0 PASS 39 passing observations
- v0.26.0 FAIL
- v0.25.0 PASS 2 passing observations
- v0.23.0 PASS 5 passing observations
Where it reproduced
- os=linux · runtime=go@1.26 ×1 2026-08-21 → 2026-08-26
Nearest known PASS/FAIL boundaries
The two adjacent releases the verdict changes across. Releases nothing measured do not close the gap; they are counted instead.
-
Last passing release v0.25.0 → first failing release v0.26.0
One side of this boundary has no resolved dependency tree, so nothing could be compared.
-
Last failing release v0.26.0 → first passing release v0.27.0
What differs across the boundary
- golang.org/x/net v0.21.0 → — hypothesis
- golang.org/x/sys v0.25.0 → — hypothesis
- golang.org/x/term v0.24.0 → — hypothesis
A version that moved across the boundary is a candidate, not a cause. Only a receipt that recorded the failure and the tree it resolved in the same run is marked as evidence.
-
Last passing release v0.33.0 → first failing release v0.36.0
One side of this boundary has no resolved dependency tree, so nothing could be compared.
-
Last failing release v0.36.0 → first passing release v0.41.0
One side of this boundary has no resolved dependency tree, so nothing could be compared.
Dependency versions across releases
What each release of this package resolved its children to. A child whose version moved is listed first: that is where an upgrade changed something underneath you.
| Library | v0.42.0 | v0.36.0 | v0.31.0 | v0.27.0 | v0.26.0 | v0.23.0 |
|---|---|---|---|---|---|---|
| golang.org/x/net | v0.43.0 | v0.21.0 | v0.21.0 | v0.21.0 | — | — |
| golang.org/x/sys | v0.36.0 | v0.31.0 | v0.28.0 | v0.25.0 | — | — |
| golang.org/x/term | v0.35.0 | v0.30.0 | v0.27.0 | v0.24.0 | — | — |
Moved: 3 · unchanged at every release: 0
An edge records that a resolver placed one release beside another on a real machine. It is not a claim that the two work together; that question is answered by samples and contracts, not by presence here.
Evidence gaps
- The evidence for this failure was not preserved, so it has no established cause. Its stored hash is provenance, not an identity.
- No resolved dependency tree for v0.25.0 or for v0.26.0, so the versions either side of the boundary could not be compared.
- No failure domain was inferred for this failure.
Published answers for the affected releases
- golang.org/x/crypto v0.36.0: scrypt.Key This network offers one thing: a sample that builds. It ran the sample in a sandbox and kept the signed receipt. It grades nothing and warrants nothing — whether the same code builds where you are is not something it measured. HOWscrypt.Key MIT-0 · 2026-09-02
- golang.org/x/crypto v0.36.0: bcrypt.CompareHashAndPassword, bcrypt.Cost, bcrypt.GenerateFromPassword This network offers one thing: a sample that builds. It ran the sample in a sandbox and kept the signed receipt. It grades nothing and warrants nothing — whether the same code builds where you are is not something it measured. HOWgolang.org/x/crypto/bcrypt.CompareHashAndPasswordgolang.org/x/crypto/bcrypt.Costgolang.org/x/crypto/bcrypt.GenerateFromPassword MIT-0 · 2026-08-27
- golang.org/x/crypto v0.36.0: chacha20poly1305.NewX This network offers one thing: a sample that builds. It ran the sample in a sandbox and kept the signed receipt. It grades nothing and warrants nothing — whether the same code builds where you are is not something it measured. HOWchacha20poly1305.NewXgo 1.26.6 MIT-0 · 2026-08-26
- golang.org/x/crypto v0.26.0: argon2.IDKey, argon2.Key This network offers one thing: a sample that builds. It ran the sample in a sandbox and kept the signed receipt. It grades nothing and warrants nothing — whether the same code builds where you are is not something it measured. HOWargon2.IDKeyargon2.Keygo 1.26.6 MIT-0 · 2026-08-27
- golang.org/x/crypto v0.26.0 This network offers one thing: a sample that builds. It ran the sample in a sandbox and kept the signed receipt. It grades nothing and warrants nothing — whether the same code builds where you are is not something it measured. HOW MIT-0 · 2026-08-21