Recordsgolanggolang.org/x/cryptofailure issue
Failure signature
UNKNOWN exit 1 Evidence gap ×1
assertion 6 failed: expected <str>, got <str> · exit status 1
Evidence quality: complete · go · unclassified-diagnostic · outer go run · gap stage-unknown · First recorded: 2026-09-04 · Last seen: 2026-09-04
sha256:b70fe2c76582…
golang.org/x/crypto/bcrypt.CompareHashAndPassword golang.org/x/crypto/bcrypt.Cost golang.org/x/crypto/bcrypt.GenerateFromPassword golang.org/x/crypto/bcrypt.InvalidCostError golang.org/x/crypto/bcrypt.MaxCost golang.org/x/crypto/bcrypt.MinCost
Where it was measured
PASS means the release recorded a passing observation at UNKNOWN and no record of this failure. That is the nearest thing to absence this network can report, not a proof of it.
- v0.54.0 not measured
- v0.52.0 not measured
- v0.50.0 not measured
- v0.48.0 FAIL
- v0.42.0 not measured
- v0.41.0 not measured
- v0.37.0 not measured
Where it reproduced
- os=linux · runtime=go@1.26 ×1 2026-09-04 → 2026-09-04
Nearest known PASS/FAIL boundaries
No release either side of this failure recorded a passing observation at this stage, so where it starts and stops is not established.
Dependency versions across releases
What each release of this package resolved its children to. A child whose version moved is listed first: that is where an upgrade changed something underneath you.
| Library | v0.54.0 | v0.52.0 | v0.50.0 | v0.48.0 | v0.42.0 | v0.37.0 |
|---|---|---|---|---|---|---|
| golang.org/x/net | v0.57.0 | v0.55.0 | v0.53.0 | v0.50.0 | v0.43.0 | v0.21.0 |
| golang.org/x/sys | v0.47.0 | v0.45.0 | v0.44.0 | v0.47.0 | v0.36.0 | v0.32.0 |
| golang.org/x/term | v0.45.0 | v0.43.0 | v0.42.0 | v0.40.0 | v0.35.0 | v0.31.0 |
Moved: 3 · unchanged at every release: 0
An edge records that a resolver placed one release beside another on a real machine. It is not a claim that the two work together; that question is answered by samples and contracts, not by presence here.
Evidence gaps
- The evidence for this failure was not preserved, so it has no established cause. Its stored hash is provenance, not an identity.
- The captured output could not establish: stage-unknown.
- No release in this window recorded a passing observation at UNKNOWN.
- Releases in this window never measured at UNKNOWN: 6
- No failure domain was inferred for this failure.
Published answers for the affected releases
- golang.org/x/crypto v0.48.0: sha3.NewShake256 This network offers one thing: a sample that builds. It ran the sample in a sandbox and kept the signed receipt. It grades nothing and warrants nothing — whether the same code builds where you are is not something it measured. HOWgolang.org/x/crypto/sha3.NewShake256 MIT-0 · 2026-09-04
- golang.org/x/crypto v0.48.0: sha3.New256 This network offers one thing: a sample that builds. It ran the sample in a sandbox and kept the signed receipt. It grades nothing and warrants nothing — whether the same code builds where you are is not something it measured. HOWgolang.org/x/crypto/sha3.New256 MIT-0 · 2026-09-04
- golang.org/x/crypto v0.48.0: bcrypt.ErrHashTooShort This network offers one thing: a sample that builds. It ran the sample in a sandbox and kept the signed receipt. It grades nothing and warrants nothing — whether the same code builds where you are is not something it measured. HOWgolang.org/x/crypto/bcrypt.ErrHashTooShort MIT-0 · 2026-09-04