)]}'
{
  "commit": "a98589711da5e9d935e8d690cfca92892e86d557",
  "tree": "681997c43c4dc353d23a6ba6410a87018a104cab",
  "parents": [
    "cfbd73ba33fc6a3635b3a63096fd6c6bff9d73e8"
  ],
  "author": {
    "name": "Roland Shoemaker",
    "email": "roland@golang.org",
    "time": "Wed Jun 09 11:31:27 2021 -0700"
  },
  "committer": {
    "name": "Filippo Valsorda",
    "email": "filippo@golang.org",
    "time": "Mon Jul 12 20:58:00 2021 +0000"
  },
  "message": "crypto/tls: test key type when casting\n\nWhen casting the certificate public key in generateClientKeyExchange,\ncheck the type is appropriate. This prevents a panic when a server\nagrees to a RSA based key exchange, but then sends an ECDSA (or\nother) certificate.\n\nFixes #47143\nFixes CVE-2021-34558\n\nThanks to Imre Rad for reporting this issue.\n\nChange-Id: Iabccacca6052769a605cccefa1216a9f7b7f6aea\nReviewed-on: https://team-review.git.corp.google.com/c/golang/go-private/+/1116723\nReviewed-by: Filippo Valsorda \u003cvalsorda@google.com\u003e\nReviewed-by: Katie Hockman \u003ckatiehockman@google.com\u003e\nReviewed-on: https://go-review.googlesource.com/c/go/+/334031\nTrust: Filippo Valsorda \u003cfilippo@golang.org\u003e\nRun-TryBot: Filippo Valsorda \u003cfilippo@golang.org\u003e\nTryBot-Result: Go Bot \u003cgobot@golang.org\u003e\nReviewed-by: Dmitri Shuralyov \u003cdmitshur@golang.org\u003e\n",
  "tree_diff": [
    {
      "type": "modify",
      "old_id": "8cfbd734f15f22c372a439ee218f3bbb12842a42",
      "old_mode": 33188,
      "old_path": "src/crypto/tls/key_agreement.go",
      "new_id": "c28a64f3a8b8c5a2eeae3f62cee7966cf7b7a4d4",
      "new_mode": 33188,
      "new_path": "src/crypto/tls/key_agreement.go"
    }
  ]
}
