Skip to content

Commit 818b9f6

Browse files
Update packages that have vulnerabilities (#1708)
* update packages that had vulnerabilities * update more packages
1 parent b446a0e commit 818b9f6

File tree

4 files changed

+115
-608
lines changed

4 files changed

+115
-608
lines changed

go.mod

Lines changed: 7 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -31,9 +31,10 @@ require (
3131
)
3232

3333
replace (
34-
github.com/golang-jwt/jwt/v4 => github.com/golang-jwt/jwt/v4 v4.5.1
34+
github.com/golang-jwt/jwt/v4 => github.com/golang-jwt/jwt/v4 v4.5.2
35+
github.com/golang-jwt/jwt/v5 => github.com/golang-jwt/jwt/v5 v5.2.2
3536
golang.org/x/crypto => golang.org/x/crypto v0.31.0
36-
golang.org/x/net => golang.org/x/net v0.33.0
37+
golang.org/x/net => golang.org/x/net v0.38.0
3738
)
3839

3940
require (
@@ -82,12 +83,12 @@ require (
8283
github.com/prometheus/common v0.61.0 // indirect
8384
github.com/prometheus/procfs v0.15.1 // indirect
8485
github.com/x448/float16 v0.8.4 // indirect
85-
golang.org/x/crypto v0.32.0 // indirect
86+
golang.org/x/crypto v0.36.0 // indirect
8687
golang.org/x/net v0.34.0 // indirect
8788
golang.org/x/oauth2 v0.24.0 // indirect
88-
golang.org/x/sys v0.29.0 // indirect
89-
golang.org/x/term v0.27.0 // indirect
90-
golang.org/x/text v0.21.0 // indirect
89+
golang.org/x/sys v0.31.0 // indirect
90+
golang.org/x/term v0.30.0 // indirect
91+
golang.org/x/text v0.23.0 // indirect
9192
golang.org/x/time v0.8.0 // indirect
9293
golang.org/x/tools v0.28.0 // indirect
9394
google.golang.org/protobuf v1.36.1 // indirect

go.sum

Lines changed: 13 additions & 10 deletions
Original file line numberDiff line numberDiff line change
@@ -84,10 +84,10 @@ github.com/go-task/slim-sprig/v3 v3.0.0 h1:sUs3vkvUymDpBKi3qH1YSqBQk9+9D/8M2mN1v
8484
github.com/go-task/slim-sprig/v3 v3.0.0/go.mod h1:W848ghGpv3Qj3dhTPRyJypKRiqCdHZiAzKg9hl15HA8=
8585
github.com/gogo/protobuf v1.3.2 h1:Ov1cvc58UF3b5XjBnZv7+opcTcQFZebYjWzi34vdm4Q=
8686
github.com/gogo/protobuf v1.3.2/go.mod h1:P1XiOD3dCwIKUDQYPy72D8LYyHL2YPYrpS2s69NZV8Q=
87-
github.com/golang-jwt/jwt/v4 v4.5.1 h1:JdqV9zKUdtaa9gdPlywC3aeoEsR681PlKC+4F5gQgeo=
88-
github.com/golang-jwt/jwt/v4 v4.5.1/go.mod h1:m21LjoU+eqJr34lmDMbreY2eSTRJ1cv77w39/MY0Ch0=
89-
github.com/golang-jwt/jwt/v5 v5.2.1 h1:OuVbFODueb089Lh128TAcimifWaLhJwVflnrgM17wHk=
90-
github.com/golang-jwt/jwt/v5 v5.2.1/go.mod h1:pqrtFR0X4osieyHYxtmOUWsAWrfe1Q5UVIyoH402zdk=
87+
github.com/golang-jwt/jwt/v4 v4.5.2 h1:YtQM7lnr8iZ+j5q71MGKkNw9Mn7AjHM68uc9g5fXeUI=
88+
github.com/golang-jwt/jwt/v4 v4.5.2/go.mod h1:m21LjoU+eqJr34lmDMbreY2eSTRJ1cv77w39/MY0Ch0=
89+
github.com/golang-jwt/jwt/v5 v5.2.2 h1:Rl4B7itRWVtYIHFrSNd7vhTiz9UpLdi6gZhZ3wEeDy8=
90+
github.com/golang-jwt/jwt/v5 v5.2.2/go.mod h1:pqrtFR0X4osieyHYxtmOUWsAWrfe1Q5UVIyoH402zdk=
9191
github.com/golang/protobuf v1.2.0/go.mod h1:6lQm79b+lXiMfvg/cZm0SGofjICqVBUtrP5yJMmIC1U=
9292
github.com/golang/protobuf v1.4.0-rc.1/go.mod h1:ceaxUfeHdC40wWswd/P6IGgMaK3YpKi5j83Wpe3EHw8=
9393
github.com/golang/protobuf v1.4.0-rc.1.0.20200221234624-67d41d38c208/go.mod h1:xKAWHe0F5eneWXFV3EuXVDTCmh+JuBKY0li0aMyXATA=
@@ -209,8 +209,8 @@ golang.org/x/mod v0.6.0-dev.0.20220419223038-86c51ed26bb4/go.mod h1:jJ57K6gSWd91
209209
golang.org/x/mod v0.12.0/go.mod h1:iBbtSCu2XBx23ZKBPSOrRkjjQPZFPuis4dIYUhu/chs=
210210
golang.org/x/mod v0.15.0/go.mod h1:hTbmBsO62+eylJbnUtE2MGJUyE7QWk4xUqPFrRgJ+7c=
211211
golang.org/x/mod v0.17.0/go.mod h1:hTbmBsO62+eylJbnUtE2MGJUyE7QWk4xUqPFrRgJ+7c=
212-
golang.org/x/net v0.33.0 h1:74SYHlV8BIgHIFC/LrYkOGIwL19eTYXQ5wc6TBuO36I=
213-
golang.org/x/net v0.33.0/go.mod h1:HXLR5J+9DxmrqMwG9qjGCxZ+zKXxBru04zlTvWlWuN4=
212+
golang.org/x/net v0.38.0 h1:vRMAPTMaeGqVhG5QyLJHqNDwecKTomGeqbnfZyKlBI8=
213+
golang.org/x/net v0.38.0/go.mod h1:ivrbrMbzFq5J41QOQh0siUuly180yBYtLp+CKbEaFx8=
214214
golang.org/x/oauth2 v0.24.0 h1:KTBBxWqUa0ykRPLtV69rRto9TLXcqYkeswu48x/gvNE=
215215
golang.org/x/oauth2 v0.24.0/go.mod h1:XYTD2NtWslqkgxebSiOHnXEap4TF09sJSc7H1sXbhtI=
216216
golang.org/x/sync v0.0.0-20180314180146-1d60e4601c6f/go.mod h1:RxMgew5VJxzue5/jJTE5uejpjVlOe/izrB70Jof72aM=
@@ -222,6 +222,7 @@ golang.org/x/sync v0.3.0/go.mod h1:FU7BRWz2tNW+3quACPkgCx/L+uEAv1htQ0V83Z9Rj+Y=
222222
golang.org/x/sync v0.6.0/go.mod h1:Czt+wKu1gCyEFDUtn0jG5QVvpJ6rzVqr5aXyt9drQfk=
223223
golang.org/x/sync v0.7.0/go.mod h1:Czt+wKu1gCyEFDUtn0jG5QVvpJ6rzVqr5aXyt9drQfk=
224224
golang.org/x/sync v0.10.0/go.mod h1:Czt+wKu1gCyEFDUtn0jG5QVvpJ6rzVqr5aXyt9drQfk=
225+
golang.org/x/sync v0.12.0/go.mod h1:1dzgHSNfp02xaA81J2MS99Qcpr2w7fw1gpm99rleRqA=
225226
golang.org/x/sys v0.0.0-20180909124046-d0be0721c37e/go.mod h1:STP8DvDyc/dI5b8T5hshtkjS+E42TnysNCUPdjciGhY=
226227
golang.org/x/sys v0.0.0-20190904154756-749cb33beabd/go.mod h1:h1NjWce9XRLGQEsW7wpKNCjG9DtNlClVuFLEZdDNbEs=
227228
golang.org/x/sys v0.0.0-20191005200804-aed5e4c7ecf9/go.mod h1:h1NjWce9XRLGQEsW7wpKNCjG9DtNlClVuFLEZdDNbEs=
@@ -234,15 +235,17 @@ golang.org/x/sys v0.12.0/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg=
234235
golang.org/x/sys v0.17.0/go.mod h1:/VUhepiaJMQUp4+oa/7Zr1D23ma6VTLIYjOOTFZPUcA=
235236
golang.org/x/sys v0.20.0/go.mod h1:/VUhepiaJMQUp4+oa/7Zr1D23ma6VTLIYjOOTFZPUcA=
236237
golang.org/x/sys v0.28.0/go.mod h1:/VUhepiaJMQUp4+oa/7Zr1D23ma6VTLIYjOOTFZPUcA=
237-
golang.org/x/sys v0.29.0 h1:TPYlXGxvx1MGTn2GiZDhnjPA9wZzZeGKHHmKhHYvgaU=
238-
golang.org/x/sys v0.29.0/go.mod h1:/VUhepiaJMQUp4+oa/7Zr1D23ma6VTLIYjOOTFZPUcA=
238+
golang.org/x/sys v0.31.0 h1:ioabZlmFYtWhL+TRYpcnNlLwhyxaM9kWTDEmfnprqik=
239+
golang.org/x/sys v0.31.0/go.mod h1:BJP2sWEmIv4KK5OTEluFJCKSidICx8ciO85XgH3Ak8k=
239240
golang.org/x/telemetry v0.0.0-20240228155512-f48c80bd79b2/go.mod h1:TeRTkGYfJXctD9OcfyVLyj2J3IxLnKwHJR8f4D8a3YE=
240-
golang.org/x/term v0.27.0 h1:WP60Sv1nlK1T6SupCHbXzSaN0b9wUmsPoRS9b61A23Q=
241241
golang.org/x/term v0.27.0/go.mod h1:iMsnZpn0cago0GOrHO2+Y7u7JPn5AylBrcoWkElMTSM=
242+
golang.org/x/term v0.30.0 h1:PQ39fJZ+mfadBm0y5WlL4vlM7Sx1Hgf13sMIY2+QS9Y=
243+
golang.org/x/term v0.30.0/go.mod h1:NYYFdzHoI5wRh/h5tDMdMqCqPJZEuNqVR5xJLd/n67g=
242244
golang.org/x/text v0.3.0/go.mod h1:NqM8EUOU14njkJ3fqMW+pc6Ldnwhi/IjpwHt7yyuwOQ=
243245
golang.org/x/text v0.3.7/go.mod h1:u+2+/6zg+i71rQMx5EYifcz6MCKuco9NR6JIITiCfzQ=
244-
golang.org/x/text v0.21.0 h1:zyQAAkrwaneQ066sspRyJaG9VNi/YJ1NfzcGB3hZ/qo=
245246
golang.org/x/text v0.21.0/go.mod h1:4IBbMaMmOPCJ8SecivzSH54+73PCFmPWxNTLm+vZkEQ=
247+
golang.org/x/text v0.23.0 h1:D71I7dUrlY+VX0gQShAThNGHFxZ13dGLBHQLVl1mJlY=
248+
golang.org/x/text v0.23.0/go.mod h1:/BLNzu4aZCJ1+kcD0DNRotWKage4q2rGVAg4o22unh4=
246249
golang.org/x/time v0.8.0 h1:9i3RxcPv3PZnitoVGMPDKZSq1xW1gK1Xy3ArNOGZfEg=
247250
golang.org/x/time v0.8.0/go.mod h1:3BpzKBy/shNhVucY/MWOyx10tF3SFh9QdLuxbVysPQM=
248251
golang.org/x/tools v0.0.0-20180917221912-90fa682c2a6e/go.mod h1:n7NCudcB/nEzxVGmLbDWY5pfWTLqBcC2KZ6jyYvM4mQ=

scripts/e2e/go.mod

Lines changed: 15 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -19,6 +19,11 @@ require (
1919
k8s.io/klog/v2 v2.130.1
2020
)
2121

22+
replace (
23+
github.com/golang-jwt/jwt/v4 => github.com/golang-jwt/jwt/v4 v4.5.2
24+
golang.org/x/net => golang.org/x/net v0.38.0
25+
)
26+
2227
require (
2328
github.com/Azure/go-autorest v14.2.0+incompatible // indirect
2429
github.com/Azure/go-autorest/autorest/adal v0.9.22 // indirect
@@ -29,19 +34,19 @@ require (
2934
github.com/Azure/go-autorest/tracing v0.6.0 // indirect
3035
github.com/davecgh/go-spew v1.1.2-0.20180830191138-d8f796af33cc // indirect
3136
github.com/dimchansky/utfbom v1.1.1 // indirect
32-
github.com/emicklei/go-restful v2.16.0+incompatible // indirect
37+
github.com/emicklei/go-restful/v3 v3.11.0 // indirect
3338
github.com/fsnotify/fsnotify v1.8.0 // indirect
39+
github.com/fxamacker/cbor/v2 v2.7.0 // indirect
3440
github.com/go-logr/logr v1.4.2 // indirect
3541
github.com/go-openapi/jsonpointer v0.21.0 // indirect
3642
github.com/go-openapi/jsonreference v0.20.2 // indirect
3743
github.com/go-openapi/swag v0.23.0 // indirect
3844
github.com/gogo/protobuf v1.3.2 // indirect
3945
github.com/golang-jwt/jwt/v4 v4.5.0 // indirect
4046
github.com/golang/protobuf v1.5.4 // indirect
41-
github.com/google/gnostic v0.5.7-v3refs // indirect
47+
github.com/google/gnostic-models v0.6.8 // indirect
4248
github.com/google/go-cmp v0.6.0 // indirect
4349
github.com/google/gofuzz v1.2.0 // indirect
44-
github.com/imdario/mergo v0.3.13 // indirect
4550
github.com/josharian/intern v1.0.0 // indirect
4651
github.com/json-iterator/go v1.1.12 // indirect
4752
github.com/mailru/easyjson v0.7.7 // indirect
@@ -50,19 +55,20 @@ require (
5055
github.com/modern-go/reflect2 v1.0.2 // indirect
5156
github.com/munnerz/goautoneg v0.0.0-20191010083416-a7dc8b61c822 // indirect
5257
github.com/nxadm/tail v1.4.11 // indirect
58+
github.com/pkg/errors v0.9.1 // indirect
5359
github.com/spf13/pflag v1.0.5 // indirect
54-
golang.org/x/crypto v0.35.0 // indirect
60+
github.com/x448/float16 v0.8.4 // indirect
61+
golang.org/x/crypto v0.36.0 // indirect
5562
golang.org/x/net v0.35.0 // indirect
5663
golang.org/x/oauth2 v0.24.0 // indirect
57-
golang.org/x/sys v0.30.0 // indirect
58-
golang.org/x/term v0.29.0 // indirect
59-
golang.org/x/text v0.22.0 // indirect
64+
golang.org/x/sys v0.31.0 // indirect
65+
golang.org/x/term v0.30.0 // indirect
66+
golang.org/x/text v0.23.0 // indirect
6067
golang.org/x/time v0.8.0 // indirect
61-
google.golang.org/appengine v1.6.7 // indirect
6268
google.golang.org/protobuf v1.36.1 // indirect
69+
gopkg.in/evanphx/json-patch.v4 v4.12.0 // indirect
6370
gopkg.in/inf.v0 v0.9.1 // indirect
6471
gopkg.in/tomb.v1 v1.0.0-20141024135613-dd632973f1e7 // indirect
65-
gopkg.in/yaml.v2 v2.4.0 // indirect
6672
gopkg.in/yaml.v3 v3.0.1 // indirect
6773
k8s.io/kube-openapi v0.0.0-20241105132330-32ad38e42d3f // indirect
6874
k8s.io/utils v0.0.0-20241104100929-3ea5e8cea738 // indirect

0 commit comments

Comments
 (0)