Skip to content

Commit eee8f21

Browse files
authored
Merge pull request #483 from andyzhangx/CVE-2025-0426
fix: CVE-2025-0426
2 parents c4932fb + e36a186 commit eee8f21

File tree

922 files changed

+61229
-24776
lines changed

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

922 files changed

+61229
-24776
lines changed

go.mod

Lines changed: 78 additions & 75 deletions
Original file line numberDiff line numberDiff line change
@@ -1,25 +1,27 @@
11
module sigs.k8s.io/sig-storage-local-static-provisioner
22

3-
go 1.22
3+
go 1.23.0
4+
5+
toolchain go1.23.1
46

57
require (
68
github.com/golang/glog v1.1.2
79
github.com/kubernetes-csi/csi-proxy/client v1.0.2
8-
github.com/onsi/ginkgo/v2 v2.9.4
9-
github.com/onsi/gomega v1.27.6
10+
github.com/onsi/ginkgo/v2 v2.13.0
11+
github.com/onsi/gomega v1.29.0
1012
github.com/prometheus/client_golang v1.16.0
1113
github.com/spf13/pflag v1.0.5
12-
golang.org/x/sys v0.28.0
14+
golang.org/x/sys v0.31.0
1315
gopkg.in/yaml.v2 v2.4.0
14-
k8s.io/api v0.28.12
15-
k8s.io/apimachinery v0.28.12
16-
k8s.io/apiserver v0.28.12
17-
k8s.io/client-go v0.28.12
18-
k8s.io/component-base v0.28.12
19-
k8s.io/klog/v2 v2.100.1
20-
k8s.io/kubernetes v1.28.12
16+
k8s.io/api v0.29.14
17+
k8s.io/apimachinery v0.29.14
18+
k8s.io/apiserver v0.29.14
19+
k8s.io/client-go v0.29.14
20+
k8s.io/component-base v0.29.14
21+
k8s.io/klog/v2 v2.110.1
22+
k8s.io/kubernetes v1.29.14
2123
k8s.io/pod-security-admission v0.0.0
22-
k8s.io/utils v0.0.0-20230406110748-d93618cff8a2
24+
k8s.io/utils v0.0.0-20230726121419-3b25d923346b
2325
sigs.k8s.io/sig-storage-lib-external-provisioner/v6 v6.3.0
2426
sigs.k8s.io/yaml v1.3.0
2527
)
@@ -39,12 +41,12 @@ require (
3941
github.com/coreos/go-semver v0.3.1 // indirect
4042
github.com/coreos/go-systemd/v22 v22.5.0 // indirect
4143
github.com/davecgh/go-spew v1.1.1 // indirect
42-
github.com/docker/distribution v2.8.2+incompatible // indirect
43-
github.com/emicklei/go-restful/v3 v3.9.0 // indirect
44+
github.com/distribution/reference v0.5.0 // indirect
45+
github.com/emicklei/go-restful/v3 v3.11.0 // indirect
4446
github.com/evanphx/json-patch v4.12.0+incompatible // indirect
4547
github.com/felixge/httpsnoop v1.0.3 // indirect
46-
github.com/fsnotify/fsnotify v1.6.0 // indirect
47-
github.com/go-logr/logr v1.2.4 // indirect
48+
github.com/fsnotify/fsnotify v1.7.0 // indirect
49+
github.com/go-logr/logr v1.3.0 // indirect
4850
github.com/go-logr/stdr v1.2.2 // indirect
4951
github.com/go-openapi/jsonpointer v0.19.6 // indirect
5052
github.com/go-openapi/jsonreference v0.20.2 // indirect
@@ -53,7 +55,7 @@ require (
5355
github.com/gogo/protobuf v1.3.2 // indirect
5456
github.com/golang/groupcache v0.0.0-20210331224755-41bb18bfe9da // indirect
5557
github.com/golang/protobuf v1.5.4 // indirect
56-
github.com/google/cel-go v0.16.1 // indirect
58+
github.com/google/cel-go v0.17.7 // indirect
5759
github.com/google/gnostic-models v0.6.8 // indirect
5860
github.com/google/go-cmp v0.6.0 // indirect
5961
github.com/google/gofuzz v1.2.0 // indirect
@@ -62,8 +64,9 @@ require (
6264
github.com/google/uuid v1.4.0 // indirect
6365
github.com/googleapis/enterprise-certificate-proxy v0.3.2 // indirect
6466
github.com/googleapis/gax-go/v2 v2.12.0 // indirect
67+
github.com/gorilla/websocket v1.5.0 // indirect
6568
github.com/grpc-ecosystem/go-grpc-prometheus v1.2.0 // indirect
66-
github.com/grpc-ecosystem/grpc-gateway/v2 v2.7.0 // indirect
69+
github.com/grpc-ecosystem/grpc-gateway/v2 v2.16.0 // indirect
6770
github.com/imdario/mergo v0.3.6 // indirect
6871
github.com/inconshreveable/mousetrap v1.1.0 // indirect
6972
github.com/josharian/intern v1.0.0 // indirect
@@ -76,39 +79,39 @@ require (
7679
github.com/modern-go/concurrent v0.0.0-20180306012644-bacd9c7ef1dd // indirect
7780
github.com/modern-go/reflect2 v1.0.2 // indirect
7881
github.com/munnerz/goautoneg v0.0.0-20191010083416-a7dc8b61c822 // indirect
82+
github.com/mxk/go-flowrate v0.0.0-20140419014527-cca7078d478f // indirect
7983
github.com/opencontainers/go-digest v1.0.0 // indirect
80-
github.com/opencontainers/selinux v1.10.0 // indirect
84+
github.com/opencontainers/selinux v1.11.0 // indirect
8185
github.com/pkg/errors v0.9.1 // indirect
8286
github.com/prometheus/client_model v0.4.0 // indirect
8387
github.com/prometheus/common v0.44.0 // indirect
8488
github.com/prometheus/procfs v0.10.1 // indirect
8589
github.com/spf13/cobra v1.7.0 // indirect
8690
github.com/stoewer/go-strcase v1.2.0 // indirect
87-
go.etcd.io/etcd/api/v3 v3.5.9 // indirect
88-
go.etcd.io/etcd/client/pkg/v3 v3.5.9 // indirect
89-
go.etcd.io/etcd/client/v3 v3.5.9 // indirect
91+
go.etcd.io/etcd/api/v3 v3.5.10 // indirect
92+
go.etcd.io/etcd/client/pkg/v3 v3.5.10 // indirect
93+
go.etcd.io/etcd/client/v3 v3.5.10 // indirect
9094
go.opencensus.io v0.24.0 // indirect
91-
go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc v0.35.0 // indirect
92-
go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.35.1 // indirect
93-
go.opentelemetry.io/otel v1.10.0 // indirect
94-
go.opentelemetry.io/otel/exporters/otlp/internal/retry v1.10.0 // indirect
95-
go.opentelemetry.io/otel/exporters/otlp/otlptrace v1.10.0 // indirect
96-
go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc v1.10.0 // indirect
97-
go.opentelemetry.io/otel/metric v0.31.0 // indirect
98-
go.opentelemetry.io/otel/sdk v1.10.0 // indirect
99-
go.opentelemetry.io/otel/trace v1.10.0 // indirect
100-
go.opentelemetry.io/proto/otlp v0.19.0 // indirect
95+
go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc v0.42.0 // indirect
96+
go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.44.0 // indirect
97+
go.opentelemetry.io/otel v1.19.0 // indirect
98+
go.opentelemetry.io/otel/exporters/otlp/otlptrace v1.19.0 // indirect
99+
go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc v1.19.0 // indirect
100+
go.opentelemetry.io/otel/metric v1.19.0 // indirect
101+
go.opentelemetry.io/otel/sdk v1.19.0 // indirect
102+
go.opentelemetry.io/otel/trace v1.19.0 // indirect
103+
go.opentelemetry.io/proto/otlp v1.0.0 // indirect
101104
go.uber.org/atomic v1.10.0 // indirect
102105
go.uber.org/multierr v1.11.0 // indirect
103106
go.uber.org/zap v1.19.0 // indirect
104-
golang.org/x/crypto v0.31.0 // indirect
105-
golang.org/x/exp v0.0.0-20220722155223-a9213eeb770e // indirect
107+
golang.org/x/crypto v0.36.0 // indirect
108+
golang.org/x/exp v0.0.0-20220827204233-334a2380cb91 // indirect
106109
golang.org/x/mod v0.17.0 // indirect
107-
golang.org/x/net v0.33.0 // indirect
110+
golang.org/x/net v0.37.0 // indirect
108111
golang.org/x/oauth2 v0.13.0 // indirect
109-
golang.org/x/sync v0.10.0 // indirect
110-
golang.org/x/term v0.27.0 // indirect
111-
golang.org/x/text v0.21.0 // indirect
112+
golang.org/x/sync v0.12.0 // indirect
113+
golang.org/x/term v0.30.0 // indirect
114+
golang.org/x/text v0.23.0 // indirect
112115
golang.org/x/time v0.3.0 // indirect
113116
golang.org/x/tools v0.21.1-0.20240508182429-e35e4ccd0d2d // indirect
114117
google.golang.org/api v0.149.0 // indirect
@@ -124,49 +127,49 @@ require (
124127
gopkg.in/warnings.v0 v0.1.2 // indirect
125128
gopkg.in/yaml.v3 v3.0.1 // indirect
126129
k8s.io/apiextensions-apiserver v0.0.0 // indirect
127-
k8s.io/cloud-provider v0.28.12 // indirect
128-
k8s.io/component-helpers v0.28.12 // indirect
129-
k8s.io/controller-manager v0.28.12 // indirect
130-
k8s.io/kms v0.28.12 // indirect
131-
k8s.io/kube-openapi v0.0.0-20230717233707-2695361300d9 // indirect
130+
k8s.io/cloud-provider v0.29.14 // indirect
131+
k8s.io/component-helpers v0.29.14 // indirect
132+
k8s.io/controller-manager v0.29.14 // indirect
133+
k8s.io/kms v0.29.14 // indirect
134+
k8s.io/kube-openapi v0.0.0-20231010175941-2dd684a91f00 // indirect
132135
k8s.io/kubectl v0.0.0 // indirect
133136
k8s.io/kubelet v0.0.0 // indirect
134137
k8s.io/legacy-cloud-providers v0.0.0 // indirect
135-
k8s.io/mount-utils v0.28.12 // indirect
136-
sigs.k8s.io/apiserver-network-proxy/konnectivity-client v0.1.2 // indirect
138+
k8s.io/mount-utils v0.29.14 // indirect
139+
sigs.k8s.io/apiserver-network-proxy/konnectivity-client v0.28.0 // indirect
137140
sigs.k8s.io/json v0.0.0-20221116044647-bc3834ca7abd // indirect
138-
sigs.k8s.io/structured-merge-diff/v4 v4.2.3 // indirect
141+
sigs.k8s.io/structured-merge-diff/v4 v4.4.1 // indirect
139142
)
140143

141144
replace (
142145
github.com/emicklei/go-restful => github.com/emicklei/go-restful/v3 v3.8.0
143-
k8s.io/api => k8s.io/api v0.28.12
144-
k8s.io/apiextensions-apiserver => k8s.io/apiextensions-apiserver v0.28.12
145-
k8s.io/apimachinery => k8s.io/apimachinery v0.28.12
146-
k8s.io/apiserver => k8s.io/apiserver v0.28.12
147-
k8s.io/cli-runtime => k8s.io/cli-runtime v0.28.12
148-
k8s.io/client-go => k8s.io/client-go v0.28.12
149-
k8s.io/cloud-provider => k8s.io/cloud-provider v0.28.12
150-
k8s.io/cluster-bootstrap => k8s.io/cluster-bootstrap v0.28.12
151-
k8s.io/code-generator => k8s.io/code-generator v0.28.12
152-
k8s.io/component-base => k8s.io/component-base v0.28.12
153-
k8s.io/component-helpers => k8s.io/component-helpers v0.28.12
154-
k8s.io/controller-manager => k8s.io/controller-manager v0.28.12
155-
k8s.io/cri-api => k8s.io/cri-api v0.28.12
156-
k8s.io/csi-translation-lib => k8s.io/csi-translation-lib v0.28.12
157-
k8s.io/dynamic-resource-allocation => k8s.io/dynamic-resource-allocation v0.28.12
158-
k8s.io/kube-aggregator => k8s.io/kube-aggregator v0.28.12
159-
k8s.io/kube-controller-manager => k8s.io/kube-controller-manager v0.28.12
160-
k8s.io/kube-proxy => k8s.io/kube-proxy v0.28.12
161-
k8s.io/kube-scheduler => k8s.io/kube-scheduler v0.28.12
162-
k8s.io/kubectl => k8s.io/kubectl v0.28.12
163-
k8s.io/kubelet => k8s.io/kubelet v0.28.12
164-
k8s.io/legacy-cloud-providers => k8s.io/legacy-cloud-providers v0.28.12
165-
k8s.io/metrics => k8s.io/metrics v0.28.12
166-
k8s.io/mount-utils => k8s.io/mount-utils v0.28.12
167-
k8s.io/node-api => k8s.io/node-api v0.28.12
168-
k8s.io/pod-security-admission => k8s.io/pod-security-admission v0.28.12
169-
k8s.io/sample-apiserver => k8s.io/sample-apiserver v0.28.12
170-
k8s.io/sample-cli-plugin => k8s.io/sample-cli-plugin v0.28.12
171-
k8s.io/sample-controller => k8s.io/sample-controller v0.28.12
146+
k8s.io/api => k8s.io/api v0.29.14
147+
k8s.io/apiextensions-apiserver => k8s.io/apiextensions-apiserver v0.29.14
148+
k8s.io/apimachinery => k8s.io/apimachinery v0.29.14
149+
k8s.io/apiserver => k8s.io/apiserver v0.29.14
150+
k8s.io/cli-runtime => k8s.io/cli-runtime v0.29.14
151+
k8s.io/client-go => k8s.io/client-go v0.29.14
152+
k8s.io/cloud-provider => k8s.io/cloud-provider v0.29.14
153+
k8s.io/cluster-bootstrap => k8s.io/cluster-bootstrap v0.29.14
154+
k8s.io/code-generator => k8s.io/code-generator v0.29.14
155+
k8s.io/component-base => k8s.io/component-base v0.29.14
156+
k8s.io/component-helpers => k8s.io/component-helpers v0.29.14
157+
k8s.io/controller-manager => k8s.io/controller-manager v0.29.14
158+
k8s.io/cri-api => k8s.io/cri-api v0.29.14
159+
k8s.io/csi-translation-lib => k8s.io/csi-translation-lib v0.29.14
160+
k8s.io/dynamic-resource-allocation => k8s.io/dynamic-resource-allocation v0.29.14
161+
k8s.io/kube-aggregator => k8s.io/kube-aggregator v0.29.14
162+
k8s.io/kube-controller-manager => k8s.io/kube-controller-manager v0.29.14
163+
k8s.io/kube-proxy => k8s.io/kube-proxy v0.29.14
164+
k8s.io/kube-scheduler => k8s.io/kube-scheduler v0.29.14
165+
k8s.io/kubectl => k8s.io/kubectl v0.29.14
166+
k8s.io/kubelet => k8s.io/kubelet v0.29.14
167+
k8s.io/legacy-cloud-providers => k8s.io/legacy-cloud-providers v0.29.14
168+
k8s.io/metrics => k8s.io/metrics v0.29.14
169+
k8s.io/mount-utils => k8s.io/mount-utils v0.29.14
170+
k8s.io/node-api => k8s.io/node-api v0.29.14
171+
k8s.io/pod-security-admission => k8s.io/pod-security-admission v0.29.14
172+
k8s.io/sample-apiserver => k8s.io/sample-apiserver v0.29.14
173+
k8s.io/sample-cli-plugin => k8s.io/sample-cli-plugin v0.29.14
174+
k8s.io/sample-controller => k8s.io/sample-controller v0.29.14
172175
)

0 commit comments

Comments
 (0)