Skip to content

Commit 9176bda

Browse files
authored
Merge pull request #511 from andyzhangx/CVE-2025-5187
fix: CVE-2025-5187
2 parents 7cd925a + 8484808 commit 9176bda

File tree

3,505 files changed

+212053
-1229264
lines changed

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

3,505 files changed

+212053
-1229264
lines changed

go.mod

Lines changed: 101 additions & 110 deletions
Original file line numberDiff line numberDiff line change
@@ -5,171 +5,162 @@ go 1.23.0
55
toolchain go1.23.1
66

77
require (
8-
github.com/golang/glog v1.1.2
8+
github.com/golang/glog v1.2.1
99
github.com/google/go-cmp v0.6.0
1010
github.com/kubernetes-csi/csi-proxy/client v1.0.2
11-
github.com/onsi/ginkgo/v2 v2.13.0
12-
github.com/onsi/gomega v1.29.0
13-
github.com/prometheus/client_golang v1.16.0
11+
github.com/onsi/ginkgo/v2 v2.19.0
12+
github.com/onsi/gomega v1.33.1
13+
github.com/prometheus/client_golang v1.19.1
1414
github.com/spf13/pflag v1.0.5
15-
golang.org/x/sys v0.32.0
15+
golang.org/x/sys v0.35.0
1616
gopkg.in/yaml.v2 v2.4.0
17-
k8s.io/api v0.29.14
18-
k8s.io/apimachinery v0.29.14
19-
k8s.io/apiserver v0.29.14
20-
k8s.io/client-go v0.29.14
21-
k8s.io/component-base v0.29.14
22-
k8s.io/klog/v2 v2.110.1
23-
k8s.io/kubernetes v1.29.14
17+
k8s.io/api v0.31.12
18+
k8s.io/apimachinery v0.31.12
19+
k8s.io/apiserver v0.31.12
20+
k8s.io/client-go v0.31.12
21+
k8s.io/component-base v0.31.12
22+
k8s.io/klog/v2 v2.130.1
23+
k8s.io/kubernetes v1.31.12
2424
k8s.io/pod-security-admission v0.0.0
25-
k8s.io/utils v0.0.0-20230726121419-3b25d923346b
25+
k8s.io/utils v0.0.0-20240711033017-18e509b52bc8
2626
sigs.k8s.io/sig-storage-lib-external-provisioner/v6 v6.3.0
27-
sigs.k8s.io/yaml v1.3.0
27+
sigs.k8s.io/yaml v1.4.0
2828
)
2929

3030
require (
31-
cloud.google.com/go/compute v1.23.3 // indirect
32-
cloud.google.com/go/compute/metadata v0.2.3 // indirect
33-
github.com/GoogleCloudPlatform/k8s-cloud-provider v1.18.1-0.20220218231025-f11817397a1b // indirect
3431
github.com/Microsoft/go-winio v0.6.0 // indirect
3532
github.com/NYTimes/gziphandler v1.1.1 // indirect
36-
github.com/antlr/antlr4/runtime/Go/antlr/v4 v4.0.0-20230305170008-8188dc5388df // indirect
33+
github.com/antlr4-go/antlr/v4 v4.13.0 // indirect
3734
github.com/asaskevich/govalidator v0.0.0-20190424111038-f61b66f89f4a // indirect
3835
github.com/beorn7/perks v1.0.1 // indirect
3936
github.com/blang/semver/v4 v4.0.0 // indirect
40-
github.com/cenkalti/backoff/v4 v4.2.1 // indirect
41-
github.com/cespare/xxhash/v2 v2.2.0 // indirect
37+
github.com/cenkalti/backoff/v4 v4.3.0 // indirect
38+
github.com/cespare/xxhash/v2 v2.3.0 // indirect
4239
github.com/coreos/go-semver v0.3.1 // indirect
43-
github.com/coreos/go-systemd/v22 v22.5.0 // indirect
44-
github.com/davecgh/go-spew v1.1.1 // indirect
40+
github.com/coreos/go-systemd/v22 v22.6.0 // indirect
41+
github.com/davecgh/go-spew v1.1.2-0.20180830191138-d8f796af33cc // indirect
4542
github.com/distribution/reference v0.5.0 // indirect
4643
github.com/emicklei/go-restful/v3 v3.11.0 // indirect
47-
github.com/evanphx/json-patch v4.12.0+incompatible // indirect
48-
github.com/felixge/httpsnoop v1.0.3 // indirect
44+
github.com/felixge/httpsnoop v1.0.4 // indirect
4945
github.com/fsnotify/fsnotify v1.7.0 // indirect
50-
github.com/go-logr/logr v1.3.0 // indirect
46+
github.com/fxamacker/cbor/v2 v2.7.0 // indirect
47+
github.com/go-logr/logr v1.4.2 // indirect
5148
github.com/go-logr/stdr v1.2.2 // indirect
5249
github.com/go-openapi/jsonpointer v0.19.6 // indirect
5350
github.com/go-openapi/jsonreference v0.20.2 // indirect
54-
github.com/go-openapi/swag v0.22.3 // indirect
55-
github.com/go-task/slim-sprig v0.0.0-20230315185526-52ccab3ef572 // indirect
51+
github.com/go-openapi/swag v0.22.4 // indirect
52+
github.com/go-task/slim-sprig/v3 v3.0.0 // indirect
5653
github.com/gogo/protobuf v1.3.2 // indirect
5754
github.com/golang/groupcache v0.0.0-20210331224755-41bb18bfe9da // indirect
5855
github.com/golang/protobuf v1.5.4 // indirect
59-
github.com/google/cel-go v0.17.7 // indirect
56+
github.com/google/cel-go v0.20.1 // indirect
6057
github.com/google/gnostic-models v0.6.8 // indirect
6158
github.com/google/gofuzz v1.2.0 // indirect
62-
github.com/google/pprof v0.0.0-20210720184732-4bb14d4b1be1 // indirect
63-
github.com/google/s2a-go v0.1.7 // indirect
64-
github.com/google/uuid v1.4.0 // indirect
65-
github.com/googleapis/enterprise-certificate-proxy v0.3.2 // indirect
66-
github.com/googleapis/gax-go/v2 v2.12.0 // indirect
59+
github.com/google/pprof v0.0.0-20240525223248-4bfdf5a9a2af // indirect
60+
github.com/google/uuid v1.6.0 // indirect
6761
github.com/gorilla/websocket v1.5.0 // indirect
6862
github.com/grpc-ecosystem/go-grpc-prometheus v1.2.0 // indirect
69-
github.com/grpc-ecosystem/grpc-gateway/v2 v2.16.0 // indirect
63+
github.com/grpc-ecosystem/grpc-gateway/v2 v2.20.0 // indirect
7064
github.com/imdario/mergo v0.3.6 // indirect
7165
github.com/inconshreveable/mousetrap v1.1.0 // indirect
7266
github.com/josharian/intern v1.0.0 // indirect
7367
github.com/json-iterator/go v1.1.12 // indirect
7468
github.com/mailru/easyjson v0.7.7 // indirect
75-
github.com/matttproud/golang_protobuf_extensions v1.0.4 // indirect
7669
github.com/miekg/dns v1.1.29 // indirect
77-
github.com/moby/spdystream v0.2.0 // indirect
78-
github.com/moby/sys/mountinfo v0.6.2 // indirect
70+
github.com/moby/spdystream v0.4.0 // indirect
71+
github.com/moby/sys/mountinfo v0.7.2 // indirect
72+
github.com/moby/sys/userns v0.1.0 // indirect
7973
github.com/modern-go/concurrent v0.0.0-20180306012644-bacd9c7ef1dd // indirect
8074
github.com/modern-go/reflect2 v1.0.2 // indirect
8175
github.com/munnerz/goautoneg v0.0.0-20191010083416-a7dc8b61c822 // indirect
8276
github.com/mxk/go-flowrate v0.0.0-20140419014527-cca7078d478f // indirect
8377
github.com/opencontainers/go-digest v1.0.0 // indirect
84-
github.com/opencontainers/selinux v1.11.0 // indirect
78+
github.com/opencontainers/runc v1.3.1 // indirect
79+
github.com/opencontainers/selinux v1.12.0 // indirect
8580
github.com/pkg/errors v0.9.1 // indirect
86-
github.com/prometheus/client_model v0.4.0 // indirect
87-
github.com/prometheus/common v0.44.0 // indirect
88-
github.com/prometheus/procfs v0.10.1 // indirect
89-
github.com/spf13/cobra v1.7.0 // indirect
81+
github.com/prometheus/client_model v0.6.1 // indirect
82+
github.com/prometheus/common v0.55.0 // indirect
83+
github.com/prometheus/procfs v0.15.1 // indirect
84+
github.com/spf13/cobra v1.8.1 // indirect
9085
github.com/stoewer/go-strcase v1.2.0 // indirect
91-
go.etcd.io/etcd/api/v3 v3.5.10 // indirect
92-
go.etcd.io/etcd/client/pkg/v3 v3.5.10 // indirect
93-
go.etcd.io/etcd/client/v3 v3.5.10 // indirect
94-
go.opencensus.io v0.24.0 // indirect
95-
go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc v0.42.0 // indirect
96-
go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.44.0 // indirect
97-
go.opentelemetry.io/otel v1.19.0 // indirect
98-
go.opentelemetry.io/otel/exporters/otlp/otlptrace v1.19.0 // indirect
99-
go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc v1.19.0 // indirect
100-
go.opentelemetry.io/otel/metric v1.19.0 // indirect
101-
go.opentelemetry.io/otel/sdk v1.19.0 // indirect
102-
go.opentelemetry.io/otel/trace v1.19.0 // indirect
103-
go.opentelemetry.io/proto/otlp v1.0.0 // indirect
104-
go.uber.org/atomic v1.10.0 // indirect
86+
github.com/stretchr/testify v1.10.0 // indirect
87+
github.com/x448/float16 v0.8.4 // indirect
88+
go.etcd.io/etcd/api/v3 v3.5.14 // indirect
89+
go.etcd.io/etcd/client/pkg/v3 v3.5.14 // indirect
90+
go.etcd.io/etcd/client/v3 v3.5.14 // indirect
91+
go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc v0.53.0 // indirect
92+
go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.53.0 // indirect
93+
go.opentelemetry.io/otel v1.28.0 // indirect
94+
go.opentelemetry.io/otel/exporters/otlp/otlptrace v1.28.0 // indirect
95+
go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc v1.27.0 // indirect
96+
go.opentelemetry.io/otel/metric v1.28.0 // indirect
97+
go.opentelemetry.io/otel/sdk v1.28.0 // indirect
98+
go.opentelemetry.io/otel/trace v1.28.0 // indirect
99+
go.opentelemetry.io/proto/otlp v1.3.1 // indirect
105100
go.uber.org/multierr v1.11.0 // indirect
106-
go.uber.org/zap v1.19.0 // indirect
107-
golang.org/x/crypto v0.37.0 // indirect
108-
golang.org/x/exp v0.0.0-20220827204233-334a2380cb91 // indirect
109-
golang.org/x/mod v0.17.0 // indirect
110-
golang.org/x/net v0.39.0 // indirect
111-
golang.org/x/oauth2 v0.13.0 // indirect
112-
golang.org/x/sync v0.13.0 // indirect
113-
golang.org/x/term v0.31.0 // indirect
114-
golang.org/x/text v0.24.0 // indirect
101+
go.uber.org/zap v1.26.0 // indirect
102+
golang.org/x/crypto v0.41.0 // indirect
103+
golang.org/x/exp v0.0.0-20230515195305-f3d0a9c9a5cc // indirect
104+
golang.org/x/mod v0.26.0 // indirect
105+
golang.org/x/net v0.43.0 // indirect
106+
golang.org/x/oauth2 v0.30.0 // indirect
107+
golang.org/x/sync v0.16.0 // indirect
108+
golang.org/x/term v0.34.0 // indirect
109+
golang.org/x/text v0.28.0 // indirect
115110
golang.org/x/time v0.3.0 // indirect
116-
golang.org/x/tools v0.21.1-0.20240508182429-e35e4ccd0d2d // indirect
117-
google.golang.org/api v0.149.0 // indirect
118-
google.golang.org/appengine v1.6.7 // indirect
111+
golang.org/x/tools v0.35.0 // indirect
119112
google.golang.org/genproto v0.0.0-20231120223509-83a465c0220f // indirect
120-
google.golang.org/genproto/googleapis/api v0.0.0-20231106174013-bbf56f31fb17 // indirect
121-
google.golang.org/genproto/googleapis/rpc v0.0.0-20231106174013-bbf56f31fb17 // indirect
122-
google.golang.org/grpc v1.59.0 // indirect
123-
google.golang.org/protobuf v1.33.0 // indirect
124-
gopkg.in/gcfg.v1 v1.2.3 // indirect
113+
google.golang.org/genproto/googleapis/api v0.0.0-20240528184218-531527333157 // indirect
114+
google.golang.org/genproto/googleapis/rpc v0.0.0-20240701130421-f6361c86f094 // indirect
115+
google.golang.org/grpc v1.65.0 // indirect
116+
google.golang.org/protobuf v1.36.8 // indirect
117+
gopkg.in/evanphx/json-patch.v4 v4.12.0 // indirect
125118
gopkg.in/inf.v0 v0.9.1 // indirect
126119
gopkg.in/natefinch/lumberjack.v2 v2.2.1 // indirect
127-
gopkg.in/warnings.v0 v0.1.2 // indirect
128120
gopkg.in/yaml.v3 v3.0.1 // indirect
129121
k8s.io/apiextensions-apiserver v0.0.0 // indirect
130-
k8s.io/cloud-provider v0.29.14 // indirect
131-
k8s.io/component-helpers v0.29.14 // indirect
132-
k8s.io/controller-manager v0.29.14 // indirect
133-
k8s.io/kms v0.29.14 // indirect
134-
k8s.io/kube-openapi v0.0.0-20231010175941-2dd684a91f00 // indirect
122+
k8s.io/cloud-provider v0.31.12 // indirect
123+
k8s.io/component-helpers v0.31.12 // indirect
124+
k8s.io/controller-manager v0.31.12 // indirect
125+
k8s.io/kms v0.31.12 // indirect
126+
k8s.io/kube-openapi v0.0.0-20240228011516-70dd3763d340 // indirect
135127
k8s.io/kubectl v0.0.0 // indirect
136128
k8s.io/kubelet v0.0.0 // indirect
137-
k8s.io/legacy-cloud-providers v0.0.0 // indirect
138-
k8s.io/mount-utils v0.29.14 // indirect
139-
sigs.k8s.io/apiserver-network-proxy/konnectivity-client v0.28.0 // indirect
129+
k8s.io/mount-utils v0.31.12 // indirect
130+
sigs.k8s.io/apiserver-network-proxy/konnectivity-client v0.30.3 // indirect
140131
sigs.k8s.io/json v0.0.0-20221116044647-bc3834ca7abd // indirect
141132
sigs.k8s.io/structured-merge-diff/v4 v4.4.1 // indirect
142133
)
143134

144135
replace (
145136
github.com/emicklei/go-restful => github.com/emicklei/go-restful/v3 v3.8.0
146-
k8s.io/api => k8s.io/api v0.29.14
147-
k8s.io/apiextensions-apiserver => k8s.io/apiextensions-apiserver v0.29.14
148-
k8s.io/apimachinery => k8s.io/apimachinery v0.29.14
149-
k8s.io/apiserver => k8s.io/apiserver v0.29.14
150-
k8s.io/cli-runtime => k8s.io/cli-runtime v0.29.14
151-
k8s.io/client-go => k8s.io/client-go v0.29.14
152-
k8s.io/cloud-provider => k8s.io/cloud-provider v0.29.14
153-
k8s.io/cluster-bootstrap => k8s.io/cluster-bootstrap v0.29.14
154-
k8s.io/code-generator => k8s.io/code-generator v0.29.14
155-
k8s.io/component-base => k8s.io/component-base v0.29.14
156-
k8s.io/component-helpers => k8s.io/component-helpers v0.29.14
157-
k8s.io/controller-manager => k8s.io/controller-manager v0.29.14
158-
k8s.io/cri-api => k8s.io/cri-api v0.29.14
159-
k8s.io/csi-translation-lib => k8s.io/csi-translation-lib v0.29.14
160-
k8s.io/dynamic-resource-allocation => k8s.io/dynamic-resource-allocation v0.29.14
161-
k8s.io/kube-aggregator => k8s.io/kube-aggregator v0.29.14
162-
k8s.io/kube-controller-manager => k8s.io/kube-controller-manager v0.29.14
163-
k8s.io/kube-proxy => k8s.io/kube-proxy v0.29.14
164-
k8s.io/kube-scheduler => k8s.io/kube-scheduler v0.29.14
165-
k8s.io/kubectl => k8s.io/kubectl v0.29.14
166-
k8s.io/kubelet => k8s.io/kubelet v0.29.14
137+
k8s.io/api => k8s.io/api v0.31.12
138+
k8s.io/apiextensions-apiserver => k8s.io/apiextensions-apiserver v0.31.12
139+
k8s.io/apimachinery => k8s.io/apimachinery v0.31.12
140+
k8s.io/apiserver => k8s.io/apiserver v0.31.12
141+
k8s.io/cli-runtime => k8s.io/cli-runtime v0.31.12
142+
k8s.io/client-go => k8s.io/client-go v0.31.12
143+
k8s.io/cloud-provider => k8s.io/cloud-provider v0.31.12
144+
k8s.io/cluster-bootstrap => k8s.io/cluster-bootstrap v0.31.12
145+
k8s.io/code-generator => k8s.io/code-generator v0.31.12
146+
k8s.io/component-base => k8s.io/component-base v0.31.12
147+
k8s.io/component-helpers => k8s.io/component-helpers v0.31.12
148+
k8s.io/controller-manager => k8s.io/controller-manager v0.31.12
149+
k8s.io/cri-api => k8s.io/cri-api v0.31.12
150+
k8s.io/csi-translation-lib => k8s.io/csi-translation-lib v0.31.12
151+
k8s.io/dynamic-resource-allocation => k8s.io/dynamic-resource-allocation v0.31.12
152+
k8s.io/kube-aggregator => k8s.io/kube-aggregator v0.31.12
153+
k8s.io/kube-controller-manager => k8s.io/kube-controller-manager v0.31.12
154+
k8s.io/kube-proxy => k8s.io/kube-proxy v0.31.12
155+
k8s.io/kube-scheduler => k8s.io/kube-scheduler v0.31.12
156+
k8s.io/kubectl => k8s.io/kubectl v0.31.12
157+
k8s.io/kubelet => k8s.io/kubelet v0.31.12
167158
k8s.io/legacy-cloud-providers => k8s.io/legacy-cloud-providers v0.29.14
168-
k8s.io/metrics => k8s.io/metrics v0.29.14
169-
k8s.io/mount-utils => k8s.io/mount-utils v0.29.14
170-
k8s.io/node-api => k8s.io/node-api v0.29.14
171-
k8s.io/pod-security-admission => k8s.io/pod-security-admission v0.29.14
172-
k8s.io/sample-apiserver => k8s.io/sample-apiserver v0.29.14
173-
k8s.io/sample-cli-plugin => k8s.io/sample-cli-plugin v0.29.14
174-
k8s.io/sample-controller => k8s.io/sample-controller v0.29.14
159+
k8s.io/metrics => k8s.io/metrics v0.31.12
160+
k8s.io/mount-utils => k8s.io/mount-utils v0.31.12
161+
k8s.io/node-api => k8s.io/node-api v0.31.12
162+
k8s.io/pod-security-admission => k8s.io/pod-security-admission v0.31.12
163+
k8s.io/sample-apiserver => k8s.io/sample-apiserver v0.31.12
164+
k8s.io/sample-cli-plugin => k8s.io/sample-cli-plugin v0.31.12
165+
k8s.io/sample-controller => k8s.io/sample-controller v0.31.12
175166
)

0 commit comments

Comments
 (0)