Skip to content

Commit 79eb623

Browse files
committed
OCPBUGS-53867: Bump github.com/golang-jwt/jwt
1 parent fc8b445 commit 79eb623

26 files changed

+11
-1750
lines changed

cmd/move-blobs/go.mod

Lines changed: 9 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -29,3 +29,12 @@ require (
2929
golang.org/x/sys v0.15.0 // indirect
3030
golang.org/x/text v0.14.0 // indirect
3131
)
32+
33+
34+
replace (
35+
// CVE-2025-30204
36+
// By replacing we can avoid bumping the go version making the backport
37+
// possible for old releases.
38+
github.com/golang-jwt/jwt/v4 => github.com/golang-jwt/jwt/v4 v4.5.2
39+
github.com/golang-jwt/jwt/v5 => github.com/golang-jwt/jwt/v5 v5.2.2
40+
)

go.mod

Lines changed: 1 addition & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -25,7 +25,7 @@ require (
2525
github.com/aws/aws-sdk-go v1.50.35
2626
github.com/davecgh/go-spew v1.1.1
2727
github.com/ghodss/yaml v1.0.0
28-
github.com/golang-jwt/jwt v3.2.2+incompatible
28+
github.com/golang-jwt/jwt/v5 v5.2.1
2929
github.com/google/go-cmp v0.5.9
3030
github.com/google/uuid v1.6.0
3131
github.com/googleapis/gax-go/v2 v2.11.0
@@ -96,7 +96,6 @@ require (
9696
github.com/go-stack/stack v1.8.0 // indirect
9797
github.com/gogo/protobuf v1.3.2 // indirect
9898
github.com/golang-jwt/jwt/v4 v4.5.0 // indirect
99-
github.com/golang-jwt/jwt/v5 v5.2.1 // indirect
10099
github.com/golang/groupcache v0.0.0-20210331224755-41bb18bfe9da // indirect
101100
github.com/golang/protobuf v1.5.3 // indirect
102101
github.com/google/cel-go v0.12.6 // indirect

go.sum

Lines changed: 0 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -730,8 +730,6 @@ github.com/godbus/dbus/v5 v5.0.4/go.mod h1:xhWf0FNVPg57R7Z0UbKHbJfkEywrmjJnf7w5x
730730
github.com/gogo/protobuf v1.3.2 h1:Ov1cvc58UF3b5XjBnZv7+opcTcQFZebYjWzi34vdm4Q=
731731
github.com/gogo/protobuf v1.3.2/go.mod h1:P1XiOD3dCwIKUDQYPy72D8LYyHL2YPYrpS2s69NZV8Q=
732732
github.com/goji/httpauth v0.0.0-20160601135302-2da839ab0f4d/go.mod h1:nnjvkQ9ptGaCkuDUx6wNykzzlUixGxvkme+H/lnzb+A=
733-
github.com/golang-jwt/jwt v3.2.2+incompatible h1:IfV12K8xAKAnZqdXVzCZ+TOjboZ2keLg81eXfW3O+oY=
734-
github.com/golang-jwt/jwt v3.2.2+incompatible/go.mod h1:8pz2t5EyA70fFQQSrl6XZXzqecmYZeUEB8OUGHkxJ+I=
735733
github.com/golang-jwt/jwt/v4 v4.5.2 h1:YtQM7lnr8iZ+j5q71MGKkNw9Mn7AjHM68uc9g5fXeUI=
736734
github.com/golang-jwt/jwt/v4 v4.5.2/go.mod h1:m21LjoU+eqJr34lmDMbreY2eSTRJ1cv77w39/MY0Ch0=
737735
github.com/golang-jwt/jwt/v5 v5.2.2 h1:Rl4B7itRWVtYIHFrSNd7vhTiz9UpLdi6gZhZ3wEeDy8=

pkg/storage/ibmcos/ibmcos.go

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -27,7 +27,7 @@ import (
2727
"github.com/IBM/ibm-cos-sdk-go/service/s3/s3manager"
2828
"github.com/IBM/platform-services-go-sdk/resourcecontrollerv2"
2929
"github.com/IBM/platform-services-go-sdk/resourcemanagerv2"
30-
"github.com/golang-jwt/jwt"
30+
"github.com/golang-jwt/jwt/v5"
3131
configapiv1 "github.com/openshift/api/config/v1"
3232
imageregistryv1 "github.com/openshift/api/imageregistry/v1"
3333
operatorapi "github.com/openshift/api/operator/v1"

vendor/github.com/golang-jwt/jwt/.gitignore

Lines changed: 0 additions & 4 deletions
This file was deleted.

vendor/github.com/golang-jwt/jwt/LICENSE

Lines changed: 0 additions & 9 deletions
This file was deleted.

vendor/github.com/golang-jwt/jwt/MIGRATION_GUIDE.md

Lines changed: 0 additions & 22 deletions
This file was deleted.

vendor/github.com/golang-jwt/jwt/README.md

Lines changed: 0 additions & 113 deletions
This file was deleted.

0 commit comments

Comments
 (0)