Skip to content

Commit 314b324

Browse files
authored
fix: Bump Go version and Dependencies (#23)
* Update npm packages * bump go version * Bump Helm package to address vuln * Add changeset
1 parent 7629235 commit 314b324

File tree

5 files changed

+513
-681
lines changed

5 files changed

+513
-681
lines changed

.changeset/good-friends-repeat.md

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,5 @@
1+
---
2+
"helm-migrate-values": patch
3+
---
4+
5+
Update to Go and Packages to address security reports

go.mod

Lines changed: 75 additions & 97 deletions
Original file line numberDiff line numberDiff line change
@@ -1,76 +1,63 @@
11
module github.com/octopusdeploylabs/helm-migrate-values
22

3-
go 1.23.0
3+
go 1.25.5
44

55
require (
6-
github.com/Masterminds/sprig/v3 v3.2.3
6+
github.com/Masterminds/sprig/v3 v3.3.0
77
github.com/pkg/errors v0.9.1
8-
github.com/spf13/cobra v1.8.1
9-
github.com/spf13/pflag v1.0.5
10-
github.com/stretchr/testify v1.8.4
8+
github.com/spf13/cobra v1.10.1
9+
github.com/spf13/pflag v1.0.10
10+
github.com/stretchr/testify v1.11.1
1111
gopkg.in/yaml.v2 v2.4.0
12-
helm.sh/helm/v3 v3.15.2
13-
k8s.io/client-go v0.30.0
12+
helm.sh/helm/v3 v3.19.4
13+
k8s.io/client-go v0.34.2
1414
)
1515

1616
require (
17-
github.com/AdaLogics/go-fuzz-headers v0.0.0-20230811130428-ced1acdcaa24 // indirect
18-
github.com/Azure/go-ansiterm v0.0.0-20210617225240-d185dfc1b5a1 // indirect
19-
github.com/BurntSushi/toml v1.3.2 // indirect
17+
dario.cat/mergo v1.0.1 // indirect
18+
github.com/Azure/go-ansiterm v0.0.0-20250102033503-faa5f7b0171c // indirect
19+
github.com/BurntSushi/toml v1.5.0 // indirect
2020
github.com/MakeNowJust/heredoc v1.0.0 // indirect
2121
github.com/Masterminds/goutils v1.1.1 // indirect
22-
github.com/Masterminds/semver/v3 v3.2.1 // indirect
22+
github.com/Masterminds/semver/v3 v3.4.0 // indirect
2323
github.com/Masterminds/squirrel v1.5.4 // indirect
24-
github.com/Microsoft/hcsshim v0.11.4 // indirect
25-
github.com/asaskevich/govalidator v0.0.0-20200428143746-21a406dcc535 // indirect
26-
github.com/beorn7/perks v1.0.1 // indirect
27-
github.com/cespare/xxhash/v2 v2.2.0 // indirect
24+
github.com/asaskevich/govalidator v0.0.0-20230301143203-a9d515a09cc2 // indirect
25+
github.com/blang/semver/v4 v4.0.0 // indirect
2826
github.com/chai2010/gettext-go v1.0.2 // indirect
29-
github.com/containerd/containerd v1.7.12 // indirect
27+
github.com/containerd/containerd v1.7.29 // indirect
28+
github.com/containerd/errdefs v0.3.0 // indirect
3029
github.com/containerd/log v0.1.0 // indirect
31-
github.com/cyphar/filepath-securejoin v0.2.4 // indirect
32-
github.com/davecgh/go-spew v1.1.1 // indirect
33-
github.com/distribution/reference v0.5.0 // indirect
34-
github.com/docker/cli v25.0.1+incompatible // indirect
35-
github.com/docker/distribution v2.8.3+incompatible // indirect
36-
github.com/docker/docker v25.0.6+incompatible // indirect
37-
github.com/docker/docker-credential-helpers v0.7.0 // indirect
38-
github.com/docker/go-connections v0.5.0 // indirect
39-
github.com/docker/go-metrics v0.0.1 // indirect
40-
github.com/emicklei/go-restful/v3 v3.11.0 // indirect
41-
github.com/evanphx/json-patch v5.7.0+incompatible // indirect
42-
github.com/exponent-io/jsonpath v0.0.0-20151013193312-d6023ce2651d // indirect
30+
github.com/containerd/platforms v0.2.1 // indirect
31+
github.com/cyphar/filepath-securejoin v0.6.1 // indirect
32+
github.com/davecgh/go-spew v1.1.2-0.20180830191138-d8f796af33cc // indirect
33+
github.com/emicklei/go-restful/v3 v3.12.2 // indirect
34+
github.com/evanphx/json-patch v5.9.11+incompatible // indirect
35+
github.com/exponent-io/jsonpath v0.0.0-20210407135951-1de76d718b3f // indirect
4336
github.com/fatih/color v1.13.0 // indirect
44-
github.com/felixge/httpsnoop v1.0.3 // indirect
37+
github.com/fxamacker/cbor/v2 v2.9.0 // indirect
4538
github.com/go-errors/errors v1.4.2 // indirect
4639
github.com/go-gorp/gorp/v3 v3.1.0 // indirect
47-
github.com/go-logr/logr v1.4.1 // indirect
48-
github.com/go-logr/stdr v1.2.2 // indirect
49-
github.com/go-openapi/jsonpointer v0.19.6 // indirect
40+
github.com/go-logr/logr v1.4.2 // indirect
41+
github.com/go-openapi/jsonpointer v0.21.0 // indirect
5042
github.com/go-openapi/jsonreference v0.20.2 // indirect
51-
github.com/go-openapi/swag v0.22.3 // indirect
43+
github.com/go-openapi/swag v0.23.0 // indirect
5244
github.com/gobwas/glob v0.2.3 // indirect
5345
github.com/gogo/protobuf v1.3.2 // indirect
54-
github.com/golang/protobuf v1.5.4 // indirect
55-
github.com/google/btree v1.0.1 // indirect
56-
github.com/google/gnostic-models v0.6.8 // indirect
57-
github.com/google/go-cmp v0.6.0 // indirect
58-
github.com/google/gofuzz v1.2.0 // indirect
59-
github.com/google/shlex v0.0.0-20191202100458-e7afc7fbc510 // indirect
60-
github.com/google/uuid v1.3.0 // indirect
61-
github.com/gorilla/mux v1.8.0 // indirect
62-
github.com/gorilla/websocket v1.5.0 // indirect
46+
github.com/google/btree v1.1.3 // indirect
47+
github.com/google/gnostic-models v0.7.0 // indirect
48+
github.com/google/go-cmp v0.7.0 // indirect
49+
github.com/google/uuid v1.6.0 // indirect
50+
github.com/gorilla/websocket v1.5.4-0.20250319132907-e064f32e3674 // indirect
6351
github.com/gosuri/uitable v0.0.4 // indirect
64-
github.com/gregjones/httpcache v0.0.0-20180305231024-9cad4c3443a7 // indirect
52+
github.com/gregjones/httpcache v0.0.0-20190611155906-901d90724c79 // indirect
6553
github.com/hashicorp/errwrap v1.1.0 // indirect
6654
github.com/hashicorp/go-multierror v1.1.1 // indirect
67-
github.com/huandu/xstrings v1.4.0 // indirect
68-
github.com/imdario/mergo v0.3.13 // indirect
55+
github.com/huandu/xstrings v1.5.0 // indirect
6956
github.com/inconshreveable/mousetrap v1.1.0 // indirect
70-
github.com/jmoiron/sqlx v1.3.5 // indirect
57+
github.com/jmoiron/sqlx v1.4.0 // indirect
7158
github.com/josharian/intern v1.0.0 // indirect
7259
github.com/json-iterator/go v1.1.12 // indirect
73-
github.com/klauspost/compress v1.16.0 // indirect
60+
github.com/klauspost/compress v1.18.0 // indirect
7461
github.com/lann/builder v0.0.0-20180802200727-47ae307949d0 // indirect
7562
github.com/lann/ps v0.0.0-20150810152359-62de8c46ede0 // indirect
7663
github.com/lib/pq v1.10.9 // indirect
@@ -79,68 +66,59 @@ require (
7966
github.com/mattn/go-colorable v0.1.13 // indirect
8067
github.com/mattn/go-isatty v0.0.17 // indirect
8168
github.com/mattn/go-runewidth v0.0.9 // indirect
82-
github.com/matttproud/golang_protobuf_extensions v1.0.4 // indirect
8369
github.com/mitchellh/copystructure v1.2.0 // indirect
8470
github.com/mitchellh/go-wordwrap v1.0.1 // indirect
8571
github.com/mitchellh/reflectwalk v1.0.2 // indirect
86-
github.com/moby/locker v1.0.1 // indirect
87-
github.com/moby/spdystream v0.2.0 // indirect
88-
github.com/moby/term v0.5.0 // indirect
72+
github.com/moby/spdystream v0.5.0 // indirect
73+
github.com/moby/term v0.5.2 // indirect
8974
github.com/modern-go/concurrent v0.0.0-20180306012644-bacd9c7ef1dd // indirect
90-
github.com/modern-go/reflect2 v1.0.2 // indirect
75+
github.com/modern-go/reflect2 v1.0.3-0.20250322232337-35a7c28c31ee // indirect
9176
github.com/monochromegane/go-gitignore v0.0.0-20200626010858-205db1a8cc00 // indirect
9277
github.com/munnerz/goautoneg v0.0.0-20191010083416-a7dc8b61c822 // indirect
9378
github.com/mxk/go-flowrate v0.0.0-20140419014527-cca7078d478f // indirect
9479
github.com/opencontainers/go-digest v1.0.0 // indirect
95-
github.com/opencontainers/image-spec v1.1.0-rc6 // indirect
80+
github.com/opencontainers/image-spec v1.1.1 // indirect
9681
github.com/peterbourgon/diskv v2.0.1+incompatible // indirect
97-
github.com/pmezard/go-difflib v1.0.0 // indirect
98-
github.com/prometheus/client_golang v1.16.0 // indirect
99-
github.com/prometheus/client_model v0.4.0 // indirect
100-
github.com/prometheus/common v0.44.0 // indirect
101-
github.com/prometheus/procfs v0.10.1 // indirect
102-
github.com/rubenv/sql-migrate v1.5.2 // indirect
82+
github.com/pmezard/go-difflib v1.0.1-0.20181226105442-5d4384ee4fb2 // indirect
83+
github.com/rubenv/sql-migrate v1.8.0 // indirect
10384
github.com/russross/blackfriday/v2 v2.1.0 // indirect
104-
github.com/shopspring/decimal v1.3.1 // indirect
85+
github.com/santhosh-tekuri/jsonschema/v6 v6.0.2 // indirect
86+
github.com/shopspring/decimal v1.4.0 // indirect
10587
github.com/sirupsen/logrus v1.9.3 // indirect
106-
github.com/spf13/cast v1.5.0 // indirect
107-
github.com/xeipuuv/gojsonpointer v0.0.0-20190905194746-02993c407bfb // indirect
108-
github.com/xeipuuv/gojsonreference v0.0.0-20180127040603-bd5ef7bd5415 // indirect
109-
github.com/xeipuuv/gojsonschema v1.2.0 // indirect
88+
github.com/spf13/cast v1.7.0 // indirect
89+
github.com/x448/float16 v0.8.4 // indirect
11090
github.com/xlab/treeprint v1.2.0 // indirect
111-
go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.45.0 // indirect
112-
go.opentelemetry.io/otel v1.19.0 // indirect
113-
go.opentelemetry.io/otel/metric v1.19.0 // indirect
114-
go.opentelemetry.io/otel/trace v1.19.0 // indirect
115-
go.starlark.net v0.0.0-20230525235612-a134d8f9ddca // indirect
116-
golang.org/x/crypto v0.21.0 // indirect
117-
golang.org/x/net v0.23.0 // indirect
118-
golang.org/x/oauth2 v0.10.0 // indirect
119-
golang.org/x/sync v0.6.0 // indirect
120-
golang.org/x/sys v0.18.0 // indirect
121-
golang.org/x/term v0.18.0 // indirect
122-
golang.org/x/text v0.14.0 // indirect
123-
golang.org/x/time v0.3.0 // indirect
124-
google.golang.org/appengine v1.6.7 // indirect
125-
google.golang.org/genproto/googleapis/rpc v0.0.0-20230822172742-b8732ec3820d // indirect
126-
google.golang.org/grpc v1.58.3 // indirect
127-
google.golang.org/protobuf v1.33.0 // indirect
91+
go.yaml.in/yaml/v2 v2.4.2 // indirect
92+
go.yaml.in/yaml/v3 v3.0.4 // indirect
93+
golang.org/x/crypto v0.45.0 // indirect
94+
golang.org/x/net v0.47.0 // indirect
95+
golang.org/x/oauth2 v0.30.0 // indirect
96+
golang.org/x/sync v0.18.0 // indirect
97+
golang.org/x/sys v0.38.0 // indirect
98+
golang.org/x/term v0.37.0 // indirect
99+
golang.org/x/text v0.31.0 // indirect
100+
golang.org/x/time v0.12.0 // indirect
101+
google.golang.org/genproto/googleapis/rpc v0.0.0-20250303144028-a0af3efb3deb // indirect
102+
google.golang.org/grpc v1.72.1 // indirect
103+
google.golang.org/protobuf v1.36.5 // indirect
104+
gopkg.in/evanphx/json-patch.v4 v4.12.0 // indirect
128105
gopkg.in/inf.v0 v0.9.1 // indirect
129106
gopkg.in/yaml.v3 v3.0.1 // indirect
130-
k8s.io/api v0.30.0 // indirect
131-
k8s.io/apiextensions-apiserver v0.30.0 // indirect
132-
k8s.io/apimachinery v0.30.0 // indirect
133-
k8s.io/apiserver v0.30.0 // indirect
134-
k8s.io/cli-runtime v0.30.0 // indirect
135-
k8s.io/component-base v0.30.0 // indirect
136-
k8s.io/klog/v2 v2.120.1 // indirect
137-
k8s.io/kube-openapi v0.0.0-20240228011516-70dd3763d340 // indirect
138-
k8s.io/kubectl v0.30.0 // indirect
139-
k8s.io/utils v0.0.0-20230726121419-3b25d923346b // indirect
140-
oras.land/oras-go v1.2.5 // indirect
141-
sigs.k8s.io/json v0.0.0-20221116044647-bc3834ca7abd // indirect
142-
sigs.k8s.io/kustomize/api v0.13.5-0.20230601165947-6ce0bf390ce3 // indirect
143-
sigs.k8s.io/kustomize/kyaml v0.14.3-0.20230601165947-6ce0bf390ce3 // indirect
144-
sigs.k8s.io/structured-merge-diff/v4 v4.4.1 // indirect
145-
sigs.k8s.io/yaml v1.4.0 // indirect
107+
k8s.io/api v0.34.2 // indirect
108+
k8s.io/apiextensions-apiserver v0.34.2 // indirect
109+
k8s.io/apimachinery v0.34.2 // indirect
110+
k8s.io/apiserver v0.34.2 // indirect
111+
k8s.io/cli-runtime v0.34.2 // indirect
112+
k8s.io/component-base v0.34.2 // indirect
113+
k8s.io/klog/v2 v2.130.1 // indirect
114+
k8s.io/kube-openapi v0.0.0-20250710124328-f3f2b991d03b // indirect
115+
k8s.io/kubectl v0.34.2 // indirect
116+
k8s.io/utils v0.0.0-20250604170112-4c0f3b243397 // indirect
117+
oras.land/oras-go/v2 v2.6.0 // indirect
118+
sigs.k8s.io/json v0.0.0-20241014173422-cfa47c3a1cc8 // indirect
119+
sigs.k8s.io/kustomize/api v0.20.1 // indirect
120+
sigs.k8s.io/kustomize/kyaml v0.20.1 // indirect
121+
sigs.k8s.io/randfill v1.0.0 // indirect
122+
sigs.k8s.io/structured-merge-diff/v6 v6.3.0 // indirect
123+
sigs.k8s.io/yaml v1.6.0 // indirect
146124
)

0 commit comments

Comments
 (0)