Skip to content

Commit 8eab95c

Browse files
committed
Bump github.com/golang-jwt/jwt from 3.2.1 to github.com/golang-jwt/jwt/v4 4.5.2
Steps executed: - change import path to "github.com/golang-jwt/jwt/v4" - execute `go get github.com/golang-jwt/jwt/v4; go mod tidy` - execute `./scripts/updatebom.sh` Reference: - https://pkg.go.dev/vuln/GO-2025-3553 - https://github.com/golang-jwt/jwt/blob/main/MIGRATION_GUIDE.md Signed-off-by: Chun-Hung Tseng <[email protected]>
1 parent e0b2726 commit 8eab95c

File tree

6 files changed

+48
-9
lines changed

6 files changed

+48
-9
lines changed

auth/jwt.go

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -21,7 +21,7 @@ import (
2121
"errors"
2222
"time"
2323

24-
"github.com/golang-jwt/jwt"
24+
"github.com/golang-jwt/jwt/v4"
2525
"go.uber.org/zap"
2626
)
2727

auth/jwt_test.go

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -20,7 +20,7 @@ import (
2020
"testing"
2121
"time"
2222

23-
"github.com/golang-jwt/jwt"
23+
"github.com/golang-jwt/jwt/v4"
2424
"github.com/stretchr/testify/require"
2525
"go.uber.org/zap"
2626
)

auth/options.go

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -21,7 +21,7 @@ import (
2121
"io/ioutil"
2222
"time"
2323

24-
"github.com/golang-jwt/jwt"
24+
"github.com/golang-jwt/jwt/v4"
2525
)
2626

2727
const (

bill-of-materials.json

Lines changed: 39 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -17,6 +17,15 @@
1717
}
1818
]
1919
},
20+
{
21+
"project": "github.com/cespare/xxhash/v2",
22+
"licenses": [
23+
{
24+
"type": "MIT License",
25+
"confidence": 1
26+
}
27+
]
28+
},
2029
{
2130
"project": "github.com/coreos/go-semver/semver",
2231
"licenses": [
@@ -63,7 +72,7 @@
6372
]
6473
},
6574
{
66-
"project": "github.com/golang-jwt/jwt",
75+
"project": "github.com/golang-jwt/jwt/v4",
6776
"licenses": [
6877
{
6978
"type": "MIT License",
@@ -369,7 +378,7 @@
369378
]
370379
},
371380
{
372-
"project": "golang.org/x/sys",
381+
"project": "golang.org/x/sys/unix",
373382
"licenses": [
374383
{
375384
"type": "BSD 3-clause \"New\" or \"Revised\" License",
@@ -396,7 +405,25 @@
396405
]
397406
},
398407
{
399-
"project": "google.golang.org/genproto",
408+
"project": "google.golang.org/genproto/googleapis/api/httpbody",
409+
"licenses": [
410+
{
411+
"type": "Apache License 2.0",
412+
"confidence": 1
413+
}
414+
]
415+
},
416+
{
417+
"project": "google.golang.org/genproto/googleapis/rpc/status",
418+
"licenses": [
419+
{
420+
"type": "Apache License 2.0",
421+
"confidence": 1
422+
}
423+
]
424+
},
425+
{
426+
"project": "google.golang.org/genproto/protobuf/field_mask",
400427
"licenses": [
401428
{
402429
"type": "Apache License 2.0",
@@ -413,6 +440,15 @@
413440
}
414441
]
415442
},
443+
{
444+
"project": "google.golang.org/protobuf",
445+
"licenses": [
446+
{
447+
"type": "BSD 3-clause \"New\" or \"Revised\" License",
448+
"confidence": 0.9663865546218487
449+
}
450+
]
451+
},
416452
{
417453
"project": "gopkg.in/cheggaaa/pb.v1",
418454
"licenses": [

go.mod

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -13,7 +13,7 @@ require (
1313
github.com/creack/pty v1.1.11
1414
github.com/dustin/go-humanize v0.0.0-20171111073723-bb3d318650d4
1515
github.com/gogo/protobuf v1.3.2
16-
github.com/golang-jwt/jwt v3.2.1+incompatible
16+
github.com/golang-jwt/jwt/v4 v4.5.2
1717
github.com/golang/groupcache v0.0.0-20160516000752-02826c3e7903
1818
github.com/golang/protobuf v1.5.4
1919
github.com/google/btree v1.0.0
@@ -51,6 +51,7 @@ require (
5151
require (
5252
github.com/beorn7/perks v1.0.1 // indirect
5353
github.com/cespare/xxhash/v2 v2.2.0 // indirect
54+
github.com/coreos/license-bill-of-materials v0.0.0-20190913234955-13baff47494e // indirect
5455
github.com/davecgh/go-spew v1.1.1 // indirect
5556
github.com/fatih/color v1.7.0 // indirect
5657
github.com/gorilla/websocket v1.4.2 // indirect

go.sum

Lines changed: 4 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -22,6 +22,8 @@ github.com/coreos/go-semver v0.2.0 h1:3Jm3tLmsgAYcjC+4Up7hJrFBPr+n7rAqYeSw/SZazu
2222
github.com/coreos/go-semver v0.2.0/go.mod h1:nnelYz7RCh+5ahJtPPxZlU+153eP4D4r3EedlOD2RNk=
2323
github.com/coreos/go-systemd v0.0.0-20180511133405-39ca1b05acc7 h1:u9SHYsPQNyt5tgDm3YN7+9dYrpK96E5wFilTFWIDZOM=
2424
github.com/coreos/go-systemd v0.0.0-20180511133405-39ca1b05acc7/go.mod h1:F5haX7vjVVG0kc13fIWeqUViNPyEJxv/OmvnBo0Yme4=
25+
github.com/coreos/license-bill-of-materials v0.0.0-20190913234955-13baff47494e h1:vHRufSa2k8tfkcDdia1vJFa+oiBvvPxW94mg76PPAoA=
26+
github.com/coreos/license-bill-of-materials v0.0.0-20190913234955-13baff47494e/go.mod h1:4xMOusJ7xxc84WclVxKT8+lNfGYDwojOUC2OQNCwcj4=
2527
github.com/coreos/pkg v0.0.0-20160727233714-3ac0863d7acf h1:CAKfRE2YtTUIjjh1bkBtyYFaUT/WmOqsJjgtihT0vMI=
2628
github.com/coreos/pkg v0.0.0-20160727233714-3ac0863d7acf/go.mod h1:E3G3o1h8I7cfcXa63jLwjI0eiQQMgzzUDFVpN/nH/eA=
2729
github.com/creack/pty v1.1.11 h1:07n33Z8lZxZ2qwegKbObQohDhXDQxiMMz1NOUGYlesw=
@@ -44,8 +46,8 @@ github.com/go-stack/stack v1.8.0/go.mod h1:v0f6uXyyMGvRgIKkXu+yp6POWl0qKG85gN/me
4446
github.com/gogo/protobuf v1.1.1/go.mod h1:r8qH/GZQm5c6nD/R0oafs1akxWv10x8SbQlK7atdtwQ=
4547
github.com/gogo/protobuf v1.3.2 h1:Ov1cvc58UF3b5XjBnZv7+opcTcQFZebYjWzi34vdm4Q=
4648
github.com/gogo/protobuf v1.3.2/go.mod h1:P1XiOD3dCwIKUDQYPy72D8LYyHL2YPYrpS2s69NZV8Q=
47-
github.com/golang-jwt/jwt v3.2.1+incompatible h1:73Z+4BJcrTC+KczS6WvTPvRGOp1WmfEP4Q1lOd9Z/+c=
48-
github.com/golang-jwt/jwt v3.2.1+incompatible/go.mod h1:8pz2t5EyA70fFQQSrl6XZXzqecmYZeUEB8OUGHkxJ+I=
49+
github.com/golang-jwt/jwt/v4 v4.5.2 h1:YtQM7lnr8iZ+j5q71MGKkNw9Mn7AjHM68uc9g5fXeUI=
50+
github.com/golang-jwt/jwt/v4 v4.5.2/go.mod h1:m21LjoU+eqJr34lmDMbreY2eSTRJ1cv77w39/MY0Ch0=
4951
github.com/golang/glog v0.0.0-20160126235308-23def4e6c14b/go.mod h1:SBH7ygxi8pfUlaOkMMuAQtPIUF8ecWP5IEl/CR7VP2Q=
5052
github.com/golang/groupcache v0.0.0-20160516000752-02826c3e7903 h1:LbsanbbD6LieFkXbj9YNNBupiGHJgFeLpO0j0Fza1h8=
5153
github.com/golang/groupcache v0.0.0-20160516000752-02826c3e7903/go.mod h1:cIg4eruTrX1D+g88fzRXU5OdNfaM+9IcxsU14FzY7Hc=

0 commit comments

Comments
 (0)