Skip to content

Commit 8ceef0e

Browse files
authored
updating dependenices and go version to address vulnerabilities CVE-2024-45338 (#487)
Signed-off-by: Adam D. Cornett <[email protected]>
1 parent a5c9d97 commit 8ceef0e

File tree

4 files changed

+139
-139
lines changed

4 files changed

+139
-139
lines changed

Dockerfile

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,4 @@
1-
FROM docker.io/golang:1.22 as build
1+
FROM docker.io/golang:1.23 as build
22

33
WORKDIR /tmp/src
44

Makefile

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -146,7 +146,7 @@ install.gofumpt:
146146

147147
# golangci-lint
148148
GOLANGCI_LINT = $(shell pwd)/out/golangci-lint
149-
GOLANGCI_LINT_VERSION ?= v1.52.2
149+
GOLANGCI_LINT_VERSION ?= v1.63.4
150150
install.golangci-lint: $(GOLANGCI_LINT)
151151
$(GOLANGCI_LINT):
152152
$(call go-install-tool,$(GOLANGCI_LINT),github.com/golangci/golangci-lint/cmd/golangci-lint@$(GOLANGCI_LINT_VERSION))\

go.mod

Lines changed: 37 additions & 37 deletions
Original file line numberDiff line numberDiff line change
@@ -1,8 +1,6 @@
11
module github.com/redhat-certification/chart-verifier
22

3-
go 1.22.4
4-
5-
toolchain go1.22.5
3+
go 1.23.5
64

75
require (
86
dario.cat/mergo v1.0.1
@@ -19,10 +17,10 @@ require (
1917
golang.org/x/mod v0.22.0
2018
gopkg.in/yaml.v3 v3.0.1
2119
helm.sh/helm/v3 v3.14.4
22-
k8s.io/api v0.29.6
23-
k8s.io/apimachinery v0.29.6
24-
k8s.io/client-go v0.29.6
25-
k8s.io/kubectl v0.29.6
20+
k8s.io/api v0.31.1
21+
k8s.io/apimachinery v0.31.1
22+
k8s.io/client-go v0.31.1
23+
k8s.io/kubectl v0.31.1
2624
)
2725

2826
require (
@@ -36,7 +34,8 @@ require (
3634
github.com/Masterminds/squirrel v1.5.4 // indirect
3735
github.com/asaskevich/govalidator v0.0.0-20200428143746-21a406dcc535 // indirect
3836
github.com/beorn7/perks v1.0.1 // indirect
39-
github.com/cespare/xxhash/v2 v2.2.0 // indirect
37+
github.com/blang/semver/v4 v4.0.0 // indirect
38+
github.com/cespare/xxhash/v2 v2.3.0 // indirect
4039
github.com/chai2010/gettext-go v1.0.2 // indirect
4140
github.com/containerd/containerd v1.7.20 // indirect
4241
github.com/containerd/errdefs v0.1.0 // indirect
@@ -57,13 +56,14 @@ require (
5756
github.com/fatih/color v1.16.0 // indirect
5857
github.com/felixge/httpsnoop v1.0.4 // indirect
5958
github.com/fsnotify/fsnotify v1.7.0 // indirect
59+
github.com/fxamacker/cbor/v2 v2.7.0 // indirect
6060
github.com/go-errors/errors v1.4.2 // indirect
6161
github.com/go-gorp/gorp/v3 v3.1.0 // indirect
62-
github.com/go-logr/logr v1.4.1 // indirect
62+
github.com/go-logr/logr v1.4.2 // indirect
6363
github.com/go-logr/stdr v1.2.2 // indirect
6464
github.com/go-openapi/jsonpointer v0.19.6 // indirect
6565
github.com/go-openapi/jsonreference v0.20.2 // indirect
66-
github.com/go-openapi/swag v0.22.3 // indirect
66+
github.com/go-openapi/swag v0.22.4 // indirect
6767
github.com/gobwas/glob v0.2.3 // indirect
6868
github.com/gogo/protobuf v1.3.2 // indirect
6969
github.com/golang/protobuf v1.5.4 // indirect
@@ -97,13 +97,12 @@ require (
9797
github.com/mattn/go-isatty v0.0.20 // indirect
9898
github.com/mattn/go-runewidth v0.0.9 // indirect
9999
github.com/mattn/go-shellwords v1.0.12 // indirect
100-
github.com/matttproud/golang_protobuf_extensions v1.0.4 // indirect
101100
github.com/mitchellh/copystructure v1.2.0 // indirect
102101
github.com/mitchellh/go-wordwrap v1.0.1 // indirect
103102
github.com/mitchellh/mapstructure v1.5.0 // indirect
104103
github.com/mitchellh/reflectwalk v1.0.2 // indirect
105104
github.com/moby/locker v1.0.1 // indirect
106-
github.com/moby/spdystream v0.2.0 // indirect
105+
github.com/moby/spdystream v0.4.0 // indirect
107106
github.com/moby/term v0.5.0 // indirect
108107
github.com/modern-go/concurrent v0.0.0-20180306012644-bacd9c7ef1dd // indirect
109108
github.com/modern-go/reflect2 v1.0.2 // indirect
@@ -116,10 +115,10 @@ require (
116115
github.com/peterbourgon/diskv v2.0.1+incompatible // indirect
117116
github.com/pkg/errors v0.9.1 // indirect
118117
github.com/pmezard/go-difflib v1.0.1-0.20181226105442-5d4384ee4fb2 // indirect
119-
github.com/prometheus/client_golang v1.17.0 // indirect
120-
github.com/prometheus/client_model v0.5.0 // indirect
121-
github.com/prometheus/common v0.44.0 // indirect
122-
github.com/prometheus/procfs v0.11.1 // indirect
118+
github.com/prometheus/client_golang v1.19.1 // indirect
119+
github.com/prometheus/client_model v0.6.1 // indirect
120+
github.com/prometheus/common v0.55.0 // indirect
121+
github.com/prometheus/procfs v0.15.1 // indirect
123122
github.com/rubenv/sql-migrate v1.5.2 // indirect
124123
github.com/russross/blackfriday/v2 v2.1.0 // indirect
125124
github.com/sagikazarmark/locafero v0.4.0 // indirect
@@ -131,43 +130,44 @@ require (
131130
github.com/spf13/cast v1.6.0 // indirect
132131
github.com/spf13/pflag v1.0.5 // indirect
133132
github.com/subosito/gotenv v1.6.0 // indirect
133+
github.com/x448/float16 v0.8.4 // indirect
134134
github.com/xeipuuv/gojsonpointer v0.0.0-20190905194746-02993c407bfb // indirect
135135
github.com/xeipuuv/gojsonreference v0.0.0-20180127040603-bd5ef7bd5415 // indirect
136136
github.com/xeipuuv/gojsonschema v1.2.0 // indirect
137137
github.com/xlab/treeprint v1.2.0 // indirect
138-
go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.49.0 // indirect
139-
go.opentelemetry.io/otel v1.24.0 // indirect
140-
go.opentelemetry.io/otel/metric v1.24.0 // indirect
141-
go.opentelemetry.io/otel/trace v1.24.0 // indirect
138+
go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.53.0 // indirect
139+
go.opentelemetry.io/otel v1.28.0 // indirect
140+
go.opentelemetry.io/otel/metric v1.28.0 // indirect
141+
go.opentelemetry.io/otel/trace v1.28.0 // indirect
142142
go.starlark.net v0.0.0-20230525235612-a134d8f9ddca // indirect
143143
go.uber.org/multierr v1.11.0 // indirect
144-
golang.org/x/crypto v0.31.0 // indirect
144+
golang.org/x/crypto v0.32.0 // indirect
145145
golang.org/x/exp v0.0.0-20230905200255-921286631fa9 // indirect
146-
golang.org/x/net v0.33.0 // indirect
147-
golang.org/x/oauth2 v0.18.0 // indirect
146+
golang.org/x/net v0.34.0 // indirect
147+
golang.org/x/oauth2 v0.21.0 // indirect
148148
golang.org/x/sync v0.10.0 // indirect
149-
golang.org/x/sys v0.28.0 // indirect
150-
golang.org/x/term v0.27.0 // indirect
149+
golang.org/x/sys v0.29.0 // indirect
150+
golang.org/x/term v0.28.0 // indirect
151151
golang.org/x/text v0.21.0 // indirect
152152
golang.org/x/time v0.5.0 // indirect
153-
google.golang.org/appengine v1.6.8 // indirect
154-
google.golang.org/genproto/googleapis/rpc v0.0.0-20240314234333-6e1732d8331c // indirect
155-
google.golang.org/grpc v1.62.1 // indirect
156-
google.golang.org/protobuf v1.33.0 // indirect
153+
google.golang.org/genproto/googleapis/rpc v0.0.0-20240701130421-f6361c86f094 // indirect
154+
google.golang.org/grpc v1.65.0 // indirect
155+
google.golang.org/protobuf v1.34.2 // indirect
156+
gopkg.in/evanphx/json-patch.v4 v4.12.0 // indirect
157157
gopkg.in/inf.v0 v0.9.1 // indirect
158158
gopkg.in/ini.v1 v1.67.0 // indirect
159159
gopkg.in/yaml.v2 v2.4.0 // indirect
160160
k8s.io/apiextensions-apiserver v0.29.0 // indirect
161161
k8s.io/apiserver v0.29.0 // indirect
162-
k8s.io/cli-runtime v0.29.6 // indirect
163-
k8s.io/component-base v0.29.6 // indirect
164-
k8s.io/klog/v2 v2.110.1 // indirect
165-
k8s.io/kube-openapi v0.0.0-20231010175941-2dd684a91f00 // indirect
166-
k8s.io/utils v0.0.0-20230726121419-3b25d923346b // indirect
162+
k8s.io/cli-runtime v0.31.1 // indirect
163+
k8s.io/component-base v0.31.1 // indirect
164+
k8s.io/klog/v2 v2.130.1 // indirect
165+
k8s.io/kube-openapi v0.0.0-20240228011516-70dd3763d340 // indirect
166+
k8s.io/utils v0.0.0-20240711033017-18e509b52bc8 // indirect
167167
oras.land/oras-go v1.2.6 // indirect
168168
sigs.k8s.io/json v0.0.0-20221116044647-bc3834ca7abd // indirect
169-
sigs.k8s.io/kustomize/api v0.13.5-0.20230601165947-6ce0bf390ce3 // indirect
170-
sigs.k8s.io/kustomize/kyaml v0.14.3-0.20230601165947-6ce0bf390ce3 // indirect
169+
sigs.k8s.io/kustomize/api v0.17.2 // indirect
170+
sigs.k8s.io/kustomize/kyaml v0.17.1 // indirect
171171
sigs.k8s.io/structured-merge-diff/v4 v4.4.1 // indirect
172-
sigs.k8s.io/yaml v1.3.0 // indirect
172+
sigs.k8s.io/yaml v1.4.0 // indirect
173173
)

0 commit comments

Comments
 (0)