Skip to content

Commit e7a944b

Browse files
fix security vuln (#334)
1 parent 16f8f83 commit e7a944b

File tree

6 files changed

+320
-300
lines changed

6 files changed

+320
-300
lines changed

.deploy/cf-runtime/Chart.yaml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -2,5 +2,5 @@ apiVersion: v2
22
name: cf-runtime
33
description: A Helm chart for Codefresh Runner
44
type: application
5-
version: 1.9.10
6-
appVersion: "1.9.10"
5+
version: 1.9.11
6+
appVersion: "1.9.11"

.deploy/cf-runtime/values.yaml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -24,7 +24,7 @@ dockerRegistry: "quay.io" # Registry prefix for the runtime images (default quay
2424
newRelicLicense: "" # NEWRELIC_LICENSE_KEY (for app-proxy and runner deployments)
2525

2626
runner: # Runner Deployment
27-
image: "codefresh/venona:1.9.10"
27+
image: "codefresh/venona:1.9.11"
2828
env: {}
2929
## e.g:
3030
# env:

venona/VERSION

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1 +1 @@
1-
1.9.10
1+
1.9.11

venonactl/VERSION

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1 +1 @@
1-
1.9.10
1+
1.9.11

venonactl/go.mod

Lines changed: 79 additions & 75 deletions
Original file line numberDiff line numberDiff line change
@@ -5,75 +5,76 @@ go 1.19
55
require (
66
github.com/Masterminds/semver v1.5.0
77
github.com/Masterminds/sprig v2.22.0+incompatible
8-
github.com/briandowns/spinner v1.12.0
9-
github.com/codefresh-io/go-sdk v0.24.0
10-
github.com/dustin/go-humanize v1.0.0
11-
github.com/inconshreveable/log15 v0.0.0-20201112154412-8562bdadbbac
8+
github.com/briandowns/spinner v1.23.0
9+
github.com/codefresh-io/go-sdk v0.52.0
10+
github.com/dustin/go-humanize v1.0.1
11+
github.com/inconshreveable/log15 v2.16.0+incompatible
1212
github.com/olekukonko/tablewriter v0.0.5
13-
github.com/spf13/cobra v1.5.0
14-
github.com/spf13/viper v1.7.1
15-
github.com/stretchr/objx v0.4.0
13+
github.com/spf13/cobra v1.6.1
14+
github.com/spf13/viper v1.15.0
15+
github.com/stretchr/objx v0.5.0
1616
gopkg.in/yaml.v2 v2.4.0
17-
helm.sh/helm/v3 v3.10.2
18-
k8s.io/api v0.26.0
19-
k8s.io/apimachinery v0.26.0
20-
k8s.io/client-go v0.26.0
17+
helm.sh/helm/v3 v3.11.1
18+
k8s.io/api v0.26.2
19+
k8s.io/apimachinery v0.26.2
20+
k8s.io/client-go v0.26.2
2121
)
2222

2323
require (
24-
github.com/Azure/go-ansiterm v0.0.0-20210617225240-d185dfc1b5a1 // indirect
24+
github.com/Azure/go-ansiterm v0.0.0-20230124172434-306776ec8161 // indirect
2525
github.com/Masterminds/goutils v1.1.1 // indirect
26-
github.com/Masterminds/semver/v3 v3.1.1 // indirect
27-
github.com/Microsoft/go-winio v0.5.1 // indirect
28-
github.com/Microsoft/hcsshim v0.9.3 // indirect
26+
github.com/Masterminds/semver/v3 v3.2.0 // indirect
27+
github.com/Microsoft/go-winio v0.6.0 // indirect
28+
github.com/Microsoft/hcsshim v0.9.7 // indirect
2929
github.com/beorn7/perks v1.0.1 // indirect
30-
github.com/cespare/xxhash/v2 v2.1.2 // indirect
31-
github.com/containerd/containerd v1.6.6 // indirect
32-
github.com/containerd/continuity v0.2.2 // indirect
30+
github.com/cespare/xxhash/v2 v2.2.0 // indirect
31+
github.com/containerd/containerd v1.6.19 // indirect
32+
github.com/containerd/continuity v0.3.0 // indirect
3333
github.com/davecgh/go-spew v1.1.1 // indirect
34-
github.com/docker/cli v20.10.17+incompatible // indirect
34+
github.com/docker/cli v23.0.1+incompatible // indirect
3535
github.com/docker/distribution v2.8.1+incompatible // indirect
36-
github.com/docker/docker v20.10.17+incompatible // indirect
37-
github.com/docker/docker-credential-helpers v0.6.4 // indirect
36+
github.com/docker/docker v23.0.1+incompatible // indirect
37+
github.com/docker/docker-credential-helpers v0.7.0 // indirect
3838
github.com/docker/go-connections v0.4.0 // indirect
3939
github.com/docker/go-metrics v0.0.1 // indirect
40-
github.com/docker/go-units v0.4.0 // indirect
41-
github.com/emicklei/go-restful/v3 v3.9.0 // indirect
40+
github.com/docker/go-units v0.5.0 // indirect
41+
github.com/emicklei/go-restful/v3 v3.10.1 // indirect
4242
github.com/evanphx/json-patch v5.6.0+incompatible // indirect
43-
github.com/fatih/color v1.13.0 // indirect
44-
github.com/fsnotify/fsnotify v1.4.9 // indirect
45-
github.com/go-errors/errors v1.0.1 // indirect
43+
github.com/fatih/color v1.14.1 // indirect
44+
github.com/fsnotify/fsnotify v1.6.0 // indirect
45+
github.com/go-errors/errors v1.4.2 // indirect
4646
github.com/go-logr/logr v1.2.3 // indirect
47-
github.com/go-openapi/jsonpointer v0.19.5 // indirect
48-
github.com/go-openapi/jsonreference v0.20.0 // indirect
49-
github.com/go-openapi/swag v0.19.14 // indirect
50-
github.com/go-stack/stack v1.8.0 // indirect
47+
github.com/go-openapi/jsonpointer v0.19.6 // indirect
48+
github.com/go-openapi/jsonreference v0.20.2 // indirect
49+
github.com/go-openapi/swag v0.22.3 // indirect
50+
github.com/go-stack/stack v1.8.1 // indirect
5151
github.com/gogo/protobuf v1.3.2 // indirect
5252
github.com/golang/protobuf v1.5.2 // indirect
53-
github.com/google/btree v1.0.1 // indirect
54-
github.com/google/gnostic v0.5.7-v3refs // indirect
53+
github.com/google/btree v1.1.2 // indirect
54+
github.com/google/gnostic v0.6.9 // indirect
5555
github.com/google/go-cmp v0.5.9 // indirect
56+
github.com/google/go-querystring v1.1.0 // indirect
5657
github.com/google/gofuzz v1.2.0 // indirect
5758
github.com/google/shlex v0.0.0-20191202100458-e7afc7fbc510 // indirect
58-
github.com/google/uuid v1.2.0 // indirect
59+
github.com/google/uuid v1.3.0 // indirect
5960
github.com/gorilla/mux v1.8.0 // indirect
60-
github.com/gregjones/httpcache v0.0.0-20180305231024-9cad4c3443a7 // indirect
61+
github.com/gregjones/httpcache v0.0.0-20190611155906-901d90724c79 // indirect
6162
github.com/hashicorp/hcl v1.0.0 // indirect
62-
github.com/huandu/xstrings v1.3.2 // indirect
63-
github.com/imdario/mergo v0.3.12 // indirect
64-
github.com/inconshreveable/mousetrap v1.0.0 // indirect
63+
github.com/huandu/xstrings v1.4.0 // indirect
64+
github.com/imdario/mergo v0.3.13 // indirect
65+
github.com/inconshreveable/mousetrap v1.1.0 // indirect
6566
github.com/josharian/intern v1.0.0 // indirect
6667
github.com/json-iterator/go v1.1.12 // indirect
67-
github.com/klauspost/compress v1.13.6 // indirect
68+
github.com/klauspost/compress v1.16.0 // indirect
6869
github.com/liggitt/tabwriter v0.0.0-20181228230101-89fcab3d43de // indirect
69-
github.com/magiconair/properties v1.8.1 // indirect
70-
github.com/mailru/easyjson v0.7.6 // indirect
71-
github.com/mattn/go-colorable v0.1.12 // indirect
72-
github.com/mattn/go-isatty v0.0.14 // indirect
73-
github.com/mattn/go-runewidth v0.0.9 // indirect
74-
github.com/matttproud/golang_protobuf_extensions v1.0.2-0.20181231171920-c182affec369 // indirect
70+
github.com/magiconair/properties v1.8.7 // indirect
71+
github.com/mailru/easyjson v0.7.7 // indirect
72+
github.com/mattn/go-colorable v0.1.13 // indirect
73+
github.com/mattn/go-isatty v0.0.17 // indirect
74+
github.com/mattn/go-runewidth v0.0.14 // indirect
75+
github.com/matttproud/golang_protobuf_extensions v1.0.4 // indirect
7576
github.com/mitchellh/copystructure v1.2.0 // indirect
76-
github.com/mitchellh/mapstructure v1.4.1 // indirect
77+
github.com/mitchellh/mapstructure v1.5.0 // indirect
7778
github.com/mitchellh/reflectwalk v1.0.2 // indirect
7879
github.com/moby/locker v1.0.1 // indirect
7980
github.com/modern-go/concurrent v0.0.0-20180306012644-bacd9c7ef1dd // indirect
@@ -82,44 +83,47 @@ require (
8283
github.com/morikuni/aec v1.0.0 // indirect
8384
github.com/munnerz/goautoneg v0.0.0-20191010083416-a7dc8b61c822 // indirect
8485
github.com/opencontainers/go-digest v1.0.0 // indirect
85-
github.com/opencontainers/image-spec v1.0.3-0.20211202183452-c5a74bcca799 // indirect
86-
github.com/opencontainers/runc v1.1.2 // indirect
87-
github.com/pelletier/go-toml v1.9.3 // indirect
86+
github.com/opencontainers/image-spec v1.1.0-rc2 // indirect
87+
github.com/opencontainers/runc v1.1.4 // indirect
88+
github.com/pelletier/go-toml/v2 v2.0.7 // indirect
8889
github.com/peterbourgon/diskv v2.0.1+incompatible // indirect
8990
github.com/pkg/errors v0.9.1 // indirect
90-
github.com/prometheus/client_golang v1.12.1 // indirect
91-
github.com/prometheus/client_model v0.2.0 // indirect
92-
github.com/prometheus/common v0.32.1 // indirect
93-
github.com/prometheus/procfs v0.7.3 // indirect
94-
github.com/sirupsen/logrus v1.8.1 // indirect
95-
github.com/spf13/afero v1.2.2 // indirect
96-
github.com/spf13/cast v1.4.1 // indirect
97-
github.com/spf13/jwalterweatherman v1.0.0 // indirect
91+
github.com/prometheus/client_golang v1.14.0 // indirect
92+
github.com/prometheus/client_model v0.3.0 // indirect
93+
github.com/prometheus/common v0.41.0 // indirect
94+
github.com/prometheus/procfs v0.9.0 // indirect
95+
github.com/rivo/uniseg v0.4.4 // indirect
96+
github.com/sirupsen/logrus v1.9.0 // indirect
97+
github.com/spf13/afero v1.9.5 // indirect
98+
github.com/spf13/cast v1.5.0 // indirect
99+
github.com/spf13/jwalterweatherman v1.1.0 // indirect
98100
github.com/spf13/pflag v1.0.5 // indirect
99-
github.com/subosito/gotenv v1.2.0 // indirect
101+
github.com/subosito/gotenv v1.4.2 // indirect
100102
github.com/xlab/treeprint v1.1.0 // indirect
101-
go.starlark.net v0.0.0-20200306205701-8dd3e2ee1dd5 // indirect
102-
golang.org/x/crypto v0.0.0-20220525230936-793ad666bf5e // indirect
103-
golang.org/x/net v0.3.1-0.20221206200815-1e63c2f08a10 // indirect
104-
golang.org/x/oauth2 v0.0.0-20220223155221-ee480838109b // indirect
105-
golang.org/x/sync v0.0.0-20220722155255-886fb9371eb4 // indirect
106-
golang.org/x/sys v0.3.0 // indirect
107-
golang.org/x/term v0.3.0 // indirect
108-
golang.org/x/text v0.5.0 // indirect
109-
golang.org/x/time v0.0.0-20220210224613-90d013bbcef8 // indirect
103+
go.starlark.net v0.0.0-20230302034142-4b1e35fe2254 // indirect
104+
golang.org/x/crypto v0.7.0 // indirect
105+
golang.org/x/mod v0.9.0 // indirect
106+
golang.org/x/net v0.8.0 // indirect
107+
golang.org/x/oauth2 v0.6.0 // indirect
108+
golang.org/x/sync v0.1.0 // indirect
109+
golang.org/x/sys v0.6.0 // indirect
110+
golang.org/x/term v0.6.0 // indirect
111+
golang.org/x/text v0.8.0 // indirect
112+
golang.org/x/time v0.3.0 // indirect
113+
golang.org/x/tools v0.7.0 // indirect
110114
google.golang.org/appengine v1.6.7 // indirect
111-
google.golang.org/genproto v0.0.0-20220502173005-c8bf987b8c21 // indirect
112-
google.golang.org/grpc v1.47.0 // indirect
115+
google.golang.org/genproto v0.0.0-20230306155012-7f2fa6fef1f4 // indirect
116+
google.golang.org/grpc v1.53.0 // indirect
113117
google.golang.org/protobuf v1.28.1 // indirect
114118
gopkg.in/inf.v0 v0.9.1 // indirect
115-
gopkg.in/ini.v1 v1.51.0 // indirect
119+
gopkg.in/ini.v1 v1.67.0 // indirect
116120
gopkg.in/yaml.v3 v3.0.1 // indirect
117-
k8s.io/cli-runtime v0.25.2 // indirect
118-
k8s.io/klog/v2 v2.80.1 // indirect
119-
k8s.io/kube-openapi v0.0.0-20221012153701-172d655c2280 // indirect
120-
k8s.io/utils v0.0.0-20221107191617-1a15be271d1d // indirect
121-
oras.land/oras-go v1.2.0 // indirect
122-
sigs.k8s.io/json v0.0.0-20220713155537-f223a00ba0e2 // indirect
121+
k8s.io/cli-runtime v0.26.2 // indirect
122+
k8s.io/klog/v2 v2.90.1 // indirect
123+
k8s.io/kube-openapi v0.0.0-20230303024457-afdc3dddf62d // indirect
124+
k8s.io/utils v0.0.0-20230220204549-a5ecb0141aa5 // indirect
125+
oras.land/oras-go v1.2.2 // indirect
126+
sigs.k8s.io/json v0.0.0-20221116044647-bc3834ca7abd // indirect
123127
sigs.k8s.io/kustomize/api v0.12.1 // indirect
124128
sigs.k8s.io/kustomize/kyaml v0.13.9 // indirect
125129
sigs.k8s.io/structured-merge-diff/v4 v4.2.3 // indirect

0 commit comments

Comments
 (0)