Skip to content

Commit d0eb7e3

Browse files
authored
OCPBUGS-33326: Mitigate CVE-2023-45288 (#104)
https://issues.redhat.com/browse/OCPBUGS-33326 Upgrades assisted-service dependencies so that golang.org/x/net is upgraded to version 0.24.0 which mitigates this CVE.
1 parent a0fb7f6 commit d0eb7e3

File tree

528 files changed

+23052
-2127
lines changed

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

528 files changed

+23052
-2127
lines changed

Makefile

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -157,7 +157,7 @@ kustomize: ## Download kustomize locally if necessary.
157157

158158
ENVTEST = $(shell pwd)/bin/setup-envtest
159159
envtest: ## Download envtest-setup locally if necessary.
160-
$(call go-get-tool,$(ENVTEST),sigs.k8s.io/controller-runtime/tools/setup-envtest@latest)
160+
$(call go-get-tool,$(ENVTEST),sigs.k8s.io/controller-runtime/tools/setup-envtest@v0.0.0-20240315194348-5aaf1190f880)
161161

162162
MOCKGEN = $(shell pwd)/bin/mockgen
163163
mockgen: ## Download mockgen locally if necessary.

go.mod

Lines changed: 26 additions & 25 deletions
Original file line numberDiff line numberDiff line change
@@ -12,16 +12,16 @@ require (
1212
github.com/go-openapi/swag v0.22.4
1313
github.com/golang/mock v1.6.0
1414
github.com/onsi/ginkgo v1.16.5
15-
github.com/onsi/gomega v1.27.10
15+
github.com/onsi/gomega v1.28.1
1616
github.com/openshift/cluster-api-provider-agent/api v0.0.0-20230918065757-81658c4ddf2f
1717
github.com/openshift/custom-resource-status v1.1.2
1818
github.com/openshift/hive/apis v0.0.0-20220222213051-def9088fdb5a
1919
github.com/pkg/errors v0.9.1
20-
github.com/sirupsen/logrus v1.9.0
21-
github.com/thoas/go-funk v0.9.2
22-
k8s.io/api v0.28.2
23-
k8s.io/apimachinery v0.28.2
24-
k8s.io/client-go v0.28.2
20+
github.com/sirupsen/logrus v1.9.3
21+
github.com/thoas/go-funk v0.9.3
22+
k8s.io/api v0.28.4
23+
k8s.io/apimachinery v0.28.4
24+
k8s.io/client-go v0.28.4
2525
k8s.io/utils v0.0.0-20230726121419-3b25d923346b
2626
sigs.k8s.io/cluster-api v1.5.1
2727
sigs.k8s.io/controller-runtime v0.16.2
@@ -61,39 +61,40 @@ require (
6161
github.com/golang/groupcache v0.0.0-20210331224755-41bb18bfe9da // indirect
6262
github.com/golang/protobuf v1.5.3 // indirect
6363
github.com/google/gnostic-models v0.6.8 // indirect
64-
github.com/google/go-cmp v0.5.9 // indirect
64+
github.com/google/go-cmp v0.6.0 // indirect
6565
github.com/google/gofuzz v1.2.0 // indirect
66-
github.com/google/uuid v1.3.1 // indirect
66+
github.com/google/uuid v1.6.0 // indirect
6767
github.com/imdario/mergo v0.3.16 // indirect
6868
github.com/jinzhu/inflection v1.0.0 // indirect
69-
github.com/jinzhu/now v1.1.4 // indirect
69+
github.com/jinzhu/now v1.1.5 // indirect
7070
github.com/josharian/intern v1.0.0 // indirect
7171
github.com/json-iterator/go v1.1.12 // indirect
72+
github.com/lib/pq v1.10.9 // indirect
7273
github.com/mailru/easyjson v0.7.7 // indirect
73-
github.com/matttproud/golang_protobuf_extensions v1.0.4 // indirect
74+
github.com/matttproud/golang_protobuf_extensions/v2 v2.0.0 // indirect
7475
github.com/mitchellh/mapstructure v1.5.0 // indirect
7576
github.com/modern-go/concurrent v0.0.0-20180306012644-bacd9c7ef1dd // indirect
7677
github.com/modern-go/reflect2 v1.0.2 // indirect
7778
github.com/munnerz/goautoneg v0.0.0-20191010083416-a7dc8b61c822 // indirect
7879
github.com/nxadm/tail v1.4.8 // indirect
7980
github.com/oklog/ulid v1.3.1 // indirect
80-
github.com/openshift/api v0.0.0-20230915112357-693d4b64813c // indirect
81-
github.com/openshift/assisted-service v1.0.10-0.20230830164851-6573b5d7021d // indirect
82-
github.com/prometheus/client_golang v1.16.0 // indirect
83-
github.com/prometheus/client_model v0.4.0 // indirect
84-
github.com/prometheus/common v0.44.0 // indirect
85-
github.com/prometheus/procfs v0.11.1 // indirect
81+
github.com/openshift/api v0.0.0-20231031181504-3be12e93388f // indirect
82+
github.com/openshift/assisted-service v1.0.10-0.20240506174859-4577ef6f4cf1 // indirect
83+
github.com/prometheus/client_golang v1.17.0 // indirect
84+
github.com/prometheus/client_model v0.5.0 // indirect
85+
github.com/prometheus/common v0.45.0 // indirect
86+
github.com/prometheus/procfs v0.12.0 // indirect
8687
github.com/spf13/pflag v1.0.6-0.20210604193023-d5e0c0615ace // indirect
8788
github.com/vincent-petithory/dataurl v1.0.0 // indirect
8889
go.mongodb.org/mongo-driver v1.10.0 // indirect
8990
go.uber.org/multierr v1.11.0 // indirect
9091
go.uber.org/zap v1.25.0 // indirect
9192
golang.org/x/exp v0.0.0-20230905200255-921286631fa9 // indirect
92-
golang.org/x/net v0.17.0 // indirect
93+
golang.org/x/net v0.24.0 // indirect
9394
golang.org/x/oauth2 v0.12.0 // indirect
94-
golang.org/x/sys v0.13.0 // indirect
95-
golang.org/x/term v0.13.0 // indirect
96-
golang.org/x/text v0.13.0 // indirect
95+
golang.org/x/sys v0.19.0 // indirect
96+
golang.org/x/term v0.19.0 // indirect
97+
golang.org/x/text v0.14.0 // indirect
9798
golang.org/x/time v0.3.0 // indirect
9899
gomodules.xyz/jsonpatch/v2 v2.4.0 // indirect
99100
google.golang.org/appengine v1.6.8 // indirect
@@ -102,18 +103,18 @@ require (
102103
gopkg.in/tomb.v1 v1.0.0-20141024135613-dd632973f1e7 // indirect
103104
gopkg.in/yaml.v2 v2.4.0 // indirect
104105
gopkg.in/yaml.v3 v3.0.1 // indirect
105-
gorm.io/gorm v1.24.5 // indirect
106+
gorm.io/gorm v1.25.7 // indirect
106107
k8s.io/apiextensions-apiserver v0.28.2 // indirect
107-
k8s.io/component-base v0.28.2 // indirect
108+
k8s.io/component-base v0.28.4 // indirect
108109
k8s.io/klog/v2 v2.100.1 // indirect
109110
k8s.io/kube-openapi v0.0.0-20230918164632-68afd615200d // indirect
110111
sigs.k8s.io/json v0.0.0-20221116044647-bc3834ca7abd // indirect
111112
sigs.k8s.io/structured-merge-diff/v4 v4.3.0 // indirect
112-
sigs.k8s.io/yaml v1.3.0 // indirect
113+
sigs.k8s.io/yaml v1.4.0 // indirect
113114
)
114115

115116
replace (
116-
github.com/openshift/assisted-service/api => github.com/openshift/assisted-service/api v0.0.0-20240207192840-bc922bad5830
117-
github.com/openshift/assisted-service/models => github.com/openshift/assisted-service/models v0.0.0-20240207192840-bc922bad5830
117+
github.com/openshift/assisted-service/api => github.com/openshift/assisted-service/api v0.0.0-20240506174859-4577ef6f4cf1
118+
github.com/openshift/assisted-service/models => github.com/openshift/assisted-service/models v0.0.0-20240506174859-4577ef6f4cf1
118119
github.com/openshift/cluster-api-provider-agent/api => ./api
119120
)

0 commit comments

Comments
 (0)