Skip to content

Commit ecfdfc4

Browse files
Revert "updating go pkgs to mitigate snyk findngs"
This reverts commit de80d4a.
1 parent de80d4a commit ecfdfc4

File tree

3 files changed

+109
-38
lines changed

3 files changed

+109
-38
lines changed

go.mod

Lines changed: 8 additions & 10 deletions
Original file line numberDiff line numberDiff line change
@@ -3,15 +3,15 @@ module github.com/CMSgov/bcda-app
33
go 1.24.4
44

55
require (
6-
github.com/BurntSushi/toml v1.5.0
6+
github.com/BurntSushi/toml v0.4.1
77
github.com/DATA-DOG/go-sqlmock v1.5.0
88
github.com/aws/aws-lambda-go v1.47.0
99
github.com/aws/aws-sdk-go v1.49.6
1010
github.com/cenkalti/backoff/v4 v4.1.3
1111
github.com/dgrijalva/jwt-go v3.2.1-0.20180309185540-3c771ce311b7+incompatible
1212
github.com/go-chi/chi/v5 v5.2.3
1313
github.com/go-chi/render v1.0.1
14-
github.com/go-testfixtures/testfixtures/v3 v3.18.0
14+
github.com/go-testfixtures/testfixtures/v3 v3.5.0
1515
github.com/golang-migrate/migrate/v4 v4.18.3
1616
github.com/golang/protobuf v1.5.4 // indirect
1717
github.com/google/fhir/go v0.7.4
@@ -33,7 +33,7 @@ require (
3333
github.com/spf13/viper v1.9.0
3434
github.com/stretchr/testify v1.10.0
3535
github.com/tsenart/vegeta v12.7.0+incompatible
36-
github.com/urfave/cli v1.22.17
36+
github.com/urfave/cli v1.22.9
3737
golang.org/x/crypto v0.41.0 // indirect
3838
golang.org/x/text v0.28.0
3939
gotest.tools/gotestsum v1.6.2
@@ -51,7 +51,6 @@ require (
5151
require (
5252
github.com/containerd/errdefs v1.0.0 // indirect
5353
github.com/containerd/errdefs/pkg v0.3.0 // indirect
54-
github.com/goccy/go-yaml v1.18.0 // indirect
5554
github.com/gorilla/websocket v1.4.2 // indirect
5655
github.com/jackc/pgpassfile v1.0.0 // indirect
5756
github.com/jackc/pgservicefile v0.0.0-20240606120523-5a60cdf6a761 // indirect
@@ -68,15 +67,15 @@ require (
6867
go.uber.org/atomic v1.7.0 // indirect
6968
go.uber.org/goleak v1.3.0 // indirect
7069
google.golang.org/genproto/googleapis/rpc v0.0.0-20250603155806-513f23925822 // indirect
71-
gopkg.in/yaml.v2 v2.4.0 // indirect
7270
)
7371

7472
require (
7573
bitbucket.org/creachadair/stringset v0.0.10 // indirect
7674
github.com/bmizerany/perks v0.0.0-20141205001514-d9a9656a3a4b // indirect
7775
github.com/c2h5oh/datasize v0.0.0-20200825124411-48ed595a09d2 // indirect
78-
github.com/cpuguy83/go-md2man/v2 v2.0.7 // indirect
76+
github.com/cpuguy83/go-md2man/v2 v2.0.0 // indirect
7977
github.com/davecgh/go-spew v1.1.1 // indirect
78+
github.com/denisenkom/go-mssqldb v0.9.0 // indirect
8079
github.com/dgryski/go-gk v0.0.0-20200319235926-a69029f61654 // indirect
8180
github.com/dgryski/go-lttb v0.0.0-20180810165845-318fcdf10a77 // indirect
8281
github.com/dnephin/pflag v1.0.7 // indirect
@@ -98,6 +97,7 @@ require (
9897
github.com/magiconair/properties v1.8.6 // indirect
9998
github.com/mailru/easyjson v0.7.7 // indirect
10099
github.com/mattn/go-isatty v0.0.20 // indirect
100+
github.com/mattn/go-sqlite3 v2.0.3+incompatible // indirect
101101
github.com/modern-go/concurrent v0.0.0-20180306012644-bacd9c7ef1dd // indirect
102102
github.com/modern-go/reflect2 v1.0.2 // indirect
103103
github.com/nbutton23/zxcvbn-go v0.0.0-20180912185939-ae427f1e4c1d // indirect
@@ -120,15 +120,13 @@ require (
120120
golang.org/x/mod v0.26.0 // indirect
121121
golang.org/x/net v0.43.0 // indirect
122122
golang.org/x/sync v0.16.0 // indirect
123-
golang.org/x/sys v0.36.0 // indirect
123+
golang.org/x/sys v0.35.0 // indirect
124124
golang.org/x/term v0.34.0 // indirect
125125
golang.org/x/tools v0.35.0 // indirect
126126
gonum.org/v1/gonum v0.11.0 // indirect
127127
google.golang.org/grpc v1.67.0 // indirect
128128
google.golang.org/protobuf v1.36.6 // indirect
129129
gopkg.in/ini.v1 v1.66.6 // indirect
130+
gopkg.in/yaml.v2 v2.4.0 // indirect
130131
gopkg.in/yaml.v3 v3.0.1 // indirect
131132
)
132-
133-
// Security fix: Ensure all yaml.v2 dependencies use at least v2.2.4 to fix CVE-2022-3064
134-
replace gopkg.in/yaml.v2 => gopkg.in/yaml.v2 v2.4.0

0 commit comments

Comments
 (0)