I don't see any call to PublicKeyCallback inside chezmoi sources, so it is not affected and the vendored library doesn't require a bump. Closing the bug as INVALID.