Skip to content

Commit 8e21378

Browse files
Merge pull request #1236 from shannon/OCPBUGS-53868
OCPBUGS-53868: Bump github.com/golang-jwt/jwt
2 parents 93f614d + 815aff6 commit 8e21378

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

52 files changed

+2120
-950
lines changed

go.mod

Lines changed: 7 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -19,7 +19,7 @@ require (
1919
github.com/aws/aws-sdk-go v1.44.205
2020
github.com/davecgh/go-spew v1.1.1
2121
github.com/ghodss/yaml v1.0.0
22-
github.com/golang-jwt/jwt v3.2.2+incompatible
22+
github.com/golang-jwt/jwt/v5 v5.2.2
2323
github.com/google/go-cmp v0.5.9
2424
github.com/google/uuid v1.3.0
2525
github.com/gophercloud/gophercloud v0.18.0
@@ -162,6 +162,12 @@ require (
162162
)
163163

164164
replace (
165+
// CVE-2025-30204
166+
// By replacing we can avoid bumping the go version making the backport
167+
// possible for old releases.
168+
github.com/golang-jwt/jwt/v4 => github.com/golang-jwt/jwt/v4 v4.5.2
169+
github.com/golang-jwt/jwt/v5 => github.com/golang-jwt/jwt/v5 v5.2.2
170+
165171
// CVE-2025-22868
166172
// This is from tag v0.26.openshift.1
167173
golang.org/x/oauth2 => github.com/openshift/golang-oauth2 v0.26.1-0.20250310184649-06a918c6239d

go.sum

Lines changed: 4 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -317,11 +317,10 @@ github.com/gogo/protobuf v1.3.1/go.mod h1:SlYgWuQ5SjCEi6WLHjHCa1yvBfUnHcTbrrZtXP
317317
github.com/gogo/protobuf v1.3.2 h1:Ov1cvc58UF3b5XjBnZv7+opcTcQFZebYjWzi34vdm4Q=
318318
github.com/gogo/protobuf v1.3.2/go.mod h1:P1XiOD3dCwIKUDQYPy72D8LYyHL2YPYrpS2s69NZV8Q=
319319
github.com/goji/httpauth v0.0.0-20160601135302-2da839ab0f4d/go.mod h1:nnjvkQ9ptGaCkuDUx6wNykzzlUixGxvkme+H/lnzb+A=
320-
github.com/golang-jwt/jwt v3.2.2+incompatible h1:IfV12K8xAKAnZqdXVzCZ+TOjboZ2keLg81eXfW3O+oY=
321-
github.com/golang-jwt/jwt v3.2.2+incompatible/go.mod h1:8pz2t5EyA70fFQQSrl6XZXzqecmYZeUEB8OUGHkxJ+I=
322-
github.com/golang-jwt/jwt/v4 v4.0.0/go.mod h1:/xlHOz8bRuivTWchD4jCa+NbatV+wEUSzwAxVc6locg=
323-
github.com/golang-jwt/jwt/v4 v4.2.0 h1:besgBTC8w8HjP6NzQdxwKH9Z5oQMZ24ThTrHp3cZ8eU=
324-
github.com/golang-jwt/jwt/v4 v4.2.0/go.mod h1:/xlHOz8bRuivTWchD4jCa+NbatV+wEUSzwAxVc6locg=
320+
github.com/golang-jwt/jwt/v4 v4.5.2 h1:YtQM7lnr8iZ+j5q71MGKkNw9Mn7AjHM68uc9g5fXeUI=
321+
github.com/golang-jwt/jwt/v4 v4.5.2/go.mod h1:m21LjoU+eqJr34lmDMbreY2eSTRJ1cv77w39/MY0Ch0=
322+
github.com/golang-jwt/jwt/v5 v5.2.2 h1:Rl4B7itRWVtYIHFrSNd7vhTiz9UpLdi6gZhZ3wEeDy8=
323+
github.com/golang-jwt/jwt/v5 v5.2.2/go.mod h1:pqrtFR0X4osieyHYxtmOUWsAWrfe1Q5UVIyoH402zdk=
325324
github.com/golang/glog v0.0.0-20160126235308-23def4e6c14b/go.mod h1:SBH7ygxi8pfUlaOkMMuAQtPIUF8ecWP5IEl/CR7VP2Q=
326325
github.com/golang/groupcache v0.0.0-20160516000752-02826c3e7903/go.mod h1:cIg4eruTrX1D+g88fzRXU5OdNfaM+9IcxsU14FzY7Hc=
327326
github.com/golang/groupcache v0.0.0-20190702054246-869f871628b6/go.mod h1:cIg4eruTrX1D+g88fzRXU5OdNfaM+9IcxsU14FzY7Hc=

pkg/storage/ibmcos/ibmcos.go

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -27,7 +27,7 @@ import (
2727
"github.com/IBM/ibm-cos-sdk-go/service/s3/s3manager"
2828
"github.com/IBM/platform-services-go-sdk/resourcecontrollerv2"
2929
"github.com/IBM/platform-services-go-sdk/resourcemanagerv2"
30-
"github.com/golang-jwt/jwt"
30+
"github.com/golang-jwt/jwt/v5"
3131
configapiv1 "github.com/openshift/api/config/v1"
3232
imageregistryv1 "github.com/openshift/api/imageregistry/v1"
3333
operatorapi "github.com/openshift/api/operator/v1"

vendor/github.com/golang-jwt/jwt/MIGRATION_GUIDE.md

Lines changed: 0 additions & 22 deletions
This file was deleted.

vendor/github.com/golang-jwt/jwt/README.md

Lines changed: 0 additions & 113 deletions
This file was deleted.

vendor/github.com/golang-jwt/jwt/claims.go

Lines changed: 0 additions & 146 deletions
This file was deleted.

vendor/github.com/golang-jwt/jwt/errors.go

Lines changed: 0 additions & 59 deletions
This file was deleted.

0 commit comments

Comments
 (0)