Skip to content

Commit 280f5d2

Browse files
solve security issues (#258)
* solve security issues
1 parent fc278fb commit 280f5d2

File tree

9 files changed

+169
-12
lines changed

9 files changed

+169
-12
lines changed

venona/Dockerfile

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,4 @@
1-
FROM golang:1.16.3-alpine3.12 as build
1+
FROM golang:1.17.6-alpine3.15 as build
22

33
RUN apk -U add --no-cache git make ca-certificates && update-ca-certificates
44

@@ -23,7 +23,7 @@ RUN go mod verify
2323
# compile
2424
RUN make build
2525

26-
FROM alpine:3.12
26+
FROM alpine:3.15
2727

2828
# copy ca-certs and user details
2929
COPY --from=build /etc/ssl/certs/ca-certificates.crt /etc/ssl/certs/

venona/VERSION

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1 +1 @@
1-
1.6.10
1+
1.7.1

venona/build/Dockerfile.tester

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,4 @@
1-
FROM golang:1.16.3-alpine3.12 AS os
1+
FROM golang:1.17.6-alpine3.15 AS os
22

33
RUN apk -U add --no-cache ca-certificates git make gcc g++ bash && update-ca-certificates
44
RUN go get github.com/client9/misspell/cmd/misspell && \

venona/go.mod

Lines changed: 47 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,12 +1,11 @@
11
module github.com/codefresh-io/go/venona
22

3-
go 1.16
3+
go 1.17
44

55
require (
66
github.com/gorilla/mux v1.8.0
77
github.com/hashicorp/go-retryablehttp v0.6.7
88
github.com/inconshreveable/log15 v0.0.0-20200109203555-b30bc20e4fd1
9-
github.com/mattn/go-colorable v0.1.6 // indirect
109
github.com/newrelic/go-agent/v3 v3.10.0
1110
github.com/newrelic/go-agent/v3/integrations/nrgorilla v1.1.0
1211
github.com/spf13/cobra v1.1.3
@@ -18,5 +17,51 @@ require (
1817
k8s.io/api v0.20.4
1918
k8s.io/apimachinery v0.20.4
2019
k8s.io/client-go v0.20.4
20+
)
2121

22+
require (
23+
github.com/davecgh/go-spew v1.1.1 // indirect
24+
github.com/evanphx/json-patch v4.9.0+incompatible // indirect
25+
github.com/fsnotify/fsnotify v1.4.9 // indirect
26+
github.com/go-logr/logr v0.2.0 // indirect
27+
github.com/go-stack/stack v1.8.0 // indirect
28+
github.com/gogo/protobuf v1.3.1 // indirect
29+
github.com/golang/protobuf v1.4.3 // indirect
30+
github.com/google/gofuzz v1.1.0 // indirect
31+
github.com/googleapis/gnostic v0.4.1 // indirect
32+
github.com/hashicorp/go-cleanhttp v0.5.1 // indirect
33+
github.com/hashicorp/hcl v1.0.0 // indirect
34+
github.com/inconshreveable/mousetrap v1.0.0 // indirect
35+
github.com/json-iterator/go v1.1.10 // indirect
36+
github.com/magiconair/properties v1.8.1 // indirect
37+
github.com/mattn/go-colorable v0.1.6 // indirect
38+
github.com/mattn/go-isatty v0.0.12 // indirect
39+
github.com/mitchellh/mapstructure v1.1.2 // indirect
40+
github.com/modern-go/concurrent v0.0.0-20180306012644-bacd9c7ef1dd // indirect
41+
github.com/modern-go/reflect2 v1.0.1 // indirect
42+
github.com/pelletier/go-toml v1.2.0 // indirect
43+
github.com/pkg/errors v0.9.1 // indirect
44+
github.com/pmezard/go-difflib v1.0.0 // indirect
45+
github.com/spf13/afero v1.2.2 // indirect
46+
github.com/spf13/cast v1.3.0 // indirect
47+
github.com/spf13/jwalterweatherman v1.0.0 // indirect
48+
github.com/subosito/gotenv v1.2.0 // indirect
49+
golang.org/x/crypto v0.0.0-20201002170205-7f63de1d35b0 // indirect
50+
golang.org/x/net v0.0.0-20201110031124-69a78807bb2b // indirect
51+
golang.org/x/oauth2 v0.0.0-20200107190931-bf48bf16ab8d // indirect
52+
golang.org/x/sys v0.0.0-20201112073958-5cba982894dd // indirect
53+
golang.org/x/text v0.3.4 // indirect
54+
golang.org/x/time v0.0.0-20200630173020-3af7569d3a1e // indirect
55+
google.golang.org/appengine v1.6.5 // indirect
56+
google.golang.org/genproto v0.0.0-20200526211855-cb27e3aa2013 // indirect
57+
google.golang.org/grpc v1.27.1 // indirect
58+
google.golang.org/protobuf v1.25.0 // indirect
59+
gopkg.in/inf.v0 v0.9.1 // indirect
60+
gopkg.in/ini.v1 v1.51.0 // indirect
61+
gopkg.in/yaml.v3 v3.0.0-20200313102051-9f266ea9e77c // indirect
62+
k8s.io/klog/v2 v2.4.0 // indirect
63+
k8s.io/kube-openapi v0.0.0-20201113171705-d219536bb9fd // indirect
64+
k8s.io/utils v0.0.0-20201110183641-67b214c5f920 // indirect
65+
sigs.k8s.io/structured-merge-diff/v4 v4.0.2 // indirect
66+
sigs.k8s.io/yaml v1.2.0 // indirect
2267
)

venona/scripts/mock.sh

100644100755
File mode changed.

venona/scripts/test-fmt.sh

100644100755
File mode changed.

venonactl/Dockerfile

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,4 @@
1-
FROM golang:1.16.3-alpine3.12 as build
1+
FROM golang:1.17.6-alpine3.15 as build
22

33
WORKDIR /venona
44

@@ -18,7 +18,7 @@ RUN VERSION=$(cat VERSION) \
1818
-X github.com/codefresh-io/venona/venonactl/cmd.commit=${COMMIT} -X github.com/codefresh-io/venona/venonactl/cmd.date=${DATE}" \
1919
-o venona
2020

21-
FROM alpine:3.12
21+
FROM alpine:3.15
2222

2323
RUN apk add --update ca-certificates
2424

venonactl/VERSION

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1 +1 @@
1-
1.6.10
1+
1.7.1

venonactl/go.mod

Lines changed: 115 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
module github.com/codefresh-io/venona/venonactl
22

3-
go 1.16
3+
go 1.17
44

55
require (
66
github.com/Masterminds/semver v1.5.0
@@ -9,19 +9,131 @@ require (
99
github.com/codefresh-io/go-sdk v0.24.0
1010
github.com/dustin/go-humanize v1.0.0
1111
github.com/inconshreveable/log15 v0.0.0-20201112154412-8562bdadbbac
12-
github.com/mattn/go-colorable v0.1.8 // indirect
1312
github.com/olekukonko/tablewriter v0.0.5
1413
github.com/spf13/cobra v1.1.3
1514
github.com/spf13/viper v1.7.1
1615
github.com/stretchr/objx v0.3.0
17-
golang.org/x/sys v0.0.0-20210320140829-1e4c9ba3b0c4 // indirect
1816
gopkg.in/yaml.v2 v2.4.0
1917
helm.sh/helm/v3 v3.5.3
2018
k8s.io/api v0.20.4
2119
k8s.io/apimachinery v0.20.4
2220
k8s.io/client-go v0.20.4
2321
)
2422

23+
require (
24+
cloud.google.com/go v0.54.0 // indirect
25+
github.com/Azure/go-ansiterm v0.0.0-20170929234023-d6e3b3328b78 // indirect
26+
github.com/Azure/go-autorest v14.2.0+incompatible // indirect
27+
github.com/Azure/go-autorest/autorest v0.11.1 // indirect
28+
github.com/Azure/go-autorest/autorest/adal v0.9.5 // indirect
29+
github.com/Azure/go-autorest/autorest/date v0.3.0 // indirect
30+
github.com/Azure/go-autorest/logger v0.2.0 // indirect
31+
github.com/Azure/go-autorest/tracing v0.6.0 // indirect
32+
github.com/Masterminds/goutils v1.1.1 // indirect
33+
github.com/Masterminds/semver/v3 v3.1.1 // indirect
34+
github.com/Microsoft/go-winio v0.4.16 // indirect
35+
github.com/Microsoft/hcsshim v0.8.14 // indirect
36+
github.com/PuerkitoBio/purell v1.1.1 // indirect
37+
github.com/PuerkitoBio/urlesc v0.0.0-20170810143723-de5bf2ad4578 // indirect
38+
github.com/beorn7/perks v1.0.1 // indirect
39+
github.com/cespare/xxhash/v2 v2.1.1 // indirect
40+
github.com/containerd/cgroups v0.0.0-20200531161412-0dbf7f05ba59 // indirect
41+
github.com/containerd/containerd v1.4.3 // indirect
42+
github.com/containerd/continuity v0.0.0-20201208142359-180525291bb7 // indirect
43+
github.com/cyphar/filepath-securejoin v0.2.2 // indirect
44+
github.com/davecgh/go-spew v1.1.1 // indirect
45+
github.com/deislabs/oras v0.10.0 // indirect
46+
github.com/docker/cli v20.10.3+incompatible // indirect
47+
github.com/docker/distribution v2.7.1+incompatible // indirect
48+
github.com/docker/docker v1.4.2-0.20200203170920-46ec8731fbce // indirect
49+
github.com/docker/docker-credential-helpers v0.6.3 // indirect
50+
github.com/docker/go-connections v0.4.0 // indirect
51+
github.com/docker/go-metrics v0.0.0-20180209012529-399ea8c73916 // indirect
52+
github.com/docker/go-units v0.4.0 // indirect
53+
github.com/emicklei/go-restful v2.9.5+incompatible // indirect
54+
github.com/evanphx/json-patch v4.9.0+incompatible // indirect
55+
github.com/fatih/color v1.7.0 // indirect
56+
github.com/form3tech-oss/jwt-go v3.2.2+incompatible // indirect
57+
github.com/fsnotify/fsnotify v1.4.9 // indirect
58+
github.com/ghodss/yaml v1.0.0 // indirect
59+
github.com/go-logr/logr v0.2.0 // indirect
60+
github.com/go-openapi/jsonpointer v0.19.3 // indirect
61+
github.com/go-openapi/jsonreference v0.19.3 // indirect
62+
github.com/go-openapi/spec v0.19.3 // indirect
63+
github.com/go-openapi/swag v0.19.5 // indirect
64+
github.com/go-stack/stack v1.8.0 // indirect
65+
github.com/gogo/protobuf v1.3.1 // indirect
66+
github.com/golang/groupcache v0.0.0-20200121045136-8c9f03a8e57e // indirect
67+
github.com/golang/protobuf v1.4.3 // indirect
68+
github.com/google/btree v1.0.0 // indirect
69+
github.com/google/gofuzz v1.1.0 // indirect
70+
github.com/google/uuid v1.1.2 // indirect
71+
github.com/googleapis/gnostic v0.4.1 // indirect
72+
github.com/gorilla/mux v1.7.3 // indirect
73+
github.com/gosuri/uitable v0.0.4 // indirect
74+
github.com/gregjones/httpcache v0.0.0-20180305231024-9cad4c3443a7 // indirect
75+
github.com/hashicorp/hcl v1.0.0 // indirect
76+
github.com/huandu/xstrings v1.3.1 // indirect
77+
github.com/imdario/mergo v0.3.11 // indirect
78+
github.com/inconshreveable/mousetrap v1.0.0 // indirect
79+
github.com/json-iterator/go v1.1.10 // indirect
80+
github.com/liggitt/tabwriter v0.0.0-20181228230101-89fcab3d43de // indirect
81+
github.com/magiconair/properties v1.8.1 // indirect
82+
github.com/mailru/easyjson v0.7.0 // indirect
83+
github.com/mattn/go-colorable v0.1.8 // indirect
84+
github.com/mattn/go-isatty v0.0.12 // indirect
85+
github.com/mattn/go-runewidth v0.0.9 // indirect
86+
github.com/matttproud/golang_protobuf_extensions v1.0.2-0.20181231171920-c182affec369 // indirect
87+
github.com/mitchellh/copystructure v1.0.0 // indirect
88+
github.com/mitchellh/mapstructure v1.1.2 // indirect
89+
github.com/mitchellh/reflectwalk v1.0.0 // indirect
90+
github.com/modern-go/concurrent v0.0.0-20180306012644-bacd9c7ef1dd // indirect
91+
github.com/modern-go/reflect2 v1.0.1 // indirect
92+
github.com/morikuni/aec v1.0.0 // indirect
93+
github.com/opencontainers/go-digest v1.0.0 // indirect
94+
github.com/opencontainers/image-spec v1.0.1 // indirect
95+
github.com/opencontainers/runc v0.1.1 // indirect
96+
github.com/pelletier/go-toml v1.2.0 // indirect
97+
github.com/peterbourgon/diskv v2.0.1+incompatible // indirect
98+
github.com/pkg/errors v0.9.1 // indirect
99+
github.com/prometheus/client_golang v1.7.1 // indirect
100+
github.com/prometheus/client_model v0.2.0 // indirect
101+
github.com/prometheus/common v0.10.0 // indirect
102+
github.com/prometheus/procfs v0.2.0 // indirect
103+
github.com/sirupsen/logrus v1.7.0 // indirect
104+
github.com/spf13/afero v1.2.2 // indirect
105+
github.com/spf13/cast v1.3.1 // indirect
106+
github.com/spf13/jwalterweatherman v1.0.0 // indirect
107+
github.com/spf13/pflag v1.0.5 // indirect
108+
github.com/subosito/gotenv v1.2.0 // indirect
109+
github.com/xeipuuv/gojsonpointer v0.0.0-20180127040702-4e3ac2762d5f // indirect
110+
github.com/xeipuuv/gojsonreference v0.0.0-20180127040603-bd5ef7bd5415 // indirect
111+
github.com/xeipuuv/gojsonschema v1.2.0 // indirect
112+
go.opencensus.io v0.22.3 // indirect
113+
golang.org/x/crypto v0.0.0-20201221181555-eec23a3978ad // indirect
114+
golang.org/x/net v0.0.0-20201110031124-69a78807bb2b // indirect
115+
golang.org/x/oauth2 v0.0.0-20200107190931-bf48bf16ab8d // indirect
116+
golang.org/x/sync v0.0.0-20201207232520-09787c993a3a // indirect
117+
golang.org/x/sys v0.0.0-20210320140829-1e4c9ba3b0c4 // indirect
118+
golang.org/x/term v0.0.0-20201117132131-f5c789dd3221 // indirect
119+
golang.org/x/text v0.3.4 // indirect
120+
golang.org/x/time v0.0.0-20200630173020-3af7569d3a1e // indirect
121+
google.golang.org/appengine v1.6.5 // indirect
122+
google.golang.org/genproto v0.0.0-20201110150050-8816d57aaa9a // indirect
123+
google.golang.org/grpc v1.27.1 // indirect
124+
google.golang.org/protobuf v1.25.0 // indirect
125+
gopkg.in/inf.v0 v0.9.1 // indirect
126+
gopkg.in/ini.v1 v1.51.0 // indirect
127+
k8s.io/apiextensions-apiserver v0.20.2 // indirect
128+
k8s.io/cli-runtime v0.20.2 // indirect
129+
k8s.io/klog/v2 v2.4.0 // indirect
130+
k8s.io/kube-openapi v0.0.0-20201113171705-d219536bb9fd // indirect
131+
k8s.io/utils v0.0.0-20201110183641-67b214c5f920 // indirect
132+
sigs.k8s.io/kustomize v2.0.3+incompatible // indirect
133+
sigs.k8s.io/structured-merge-diff/v4 v4.0.2 // indirect
134+
sigs.k8s.io/yaml v1.2.0 // indirect
135+
)
136+
25137
replace (
26138
github.com/docker/distribution => github.com/docker/distribution v0.0.0-20191216044856-a8371794149d
27139
github.com/docker/docker => github.com/moby/moby v17.12.0-ce-rc1.0.20200618181300-9dc6525e6118+incompatible

0 commit comments

Comments
 (0)