Skip to content

Commit cd9256f

Browse files
authored
Merge pull request #68 from splitio/vulnerabilities
Vulnerabilities
2 parents e9e508b + 71ef4e8 commit cd9256f

File tree

4 files changed

+22
-22
lines changed

4 files changed

+22
-22
lines changed

.github/workflows/ci.yml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -18,7 +18,7 @@ jobs:
1818
runs-on: ubuntu-latest
1919
steps:
2020
- name: Checkout code
21-
uses: actions/checkout@v5
21+
uses: actions/checkout@v6
2222
with:
2323
fetch-depth: 0
2424

@@ -27,7 +27,7 @@ jobs:
2727

2828
- name: Version validation
2929
if: ${{ github.event_name == 'pull_request' }}
30-
uses: mukunku/tag-exists-action@v1.6.0
30+
uses: mukunku/tag-exists-action@v1.7.0
3131
id: checkTag
3232
with:
3333
tag: v${{ env.VERSION }}
@@ -43,7 +43,7 @@ jobs:
4343
- name: Setup Go version
4444
uses: actions/setup-go@v6
4545
with:
46-
go-version: '^1.20.7'
46+
go-version: '^1.26.1'
4747

4848
- name: Build binaries for host machine
4949
run: make splitd splitcli

go.mod

Lines changed: 6 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -1,14 +1,14 @@
11
module github.com/splitio/splitd
22

3-
go 1.24.0
3+
go 1.26.1
44

55
require (
66
github.com/gin-gonic/gin v1.10.0
77
github.com/splitio/go-split-commons/v9 v9.1.0
88
github.com/splitio/go-toolkit/v5 v5.4.1
99
github.com/stretchr/testify v1.11.1
1010
github.com/vmihailenco/msgpack/v5 v5.3.5
11-
golang.org/x/sync v0.18.0
11+
golang.org/x/sync v0.20.0
1212
gopkg.in/yaml.v3 v3.0.1
1313
)
1414

@@ -39,10 +39,10 @@ require (
3939
github.com/ugorji/go/codec v1.2.12 // indirect
4040
github.com/vmihailenco/tagparser/v2 v2.0.0 // indirect
4141
golang.org/x/arch v0.8.0 // indirect
42-
golang.org/x/crypto v0.45.0 // indirect
42+
golang.org/x/crypto v0.49.0 // indirect
4343
golang.org/x/exp v0.0.0-20231006140011-7918f672742d // indirect
44-
golang.org/x/net v0.47.0 // indirect
45-
golang.org/x/sys v0.38.0 // indirect
46-
golang.org/x/text v0.31.0 // indirect
44+
golang.org/x/net v0.52.0 // indirect
45+
golang.org/x/sys v0.42.0 // indirect
46+
golang.org/x/text v0.35.0 // indirect
4747
google.golang.org/protobuf v1.34.1 // indirect
4848
)

go.sum

Lines changed: 10 additions & 10 deletions
Original file line numberDiff line numberDiff line change
@@ -83,20 +83,20 @@ github.com/vmihailenco/tagparser/v2 v2.0.0/go.mod h1:Wri+At7QHww0WTrCBeu4J6bNtoV
8383
golang.org/x/arch v0.0.0-20210923205945-b76863e36670/go.mod h1:5om86z9Hs0C8fWVUuoMHwpExlXzs5Tkyp9hOrfG7pp8=
8484
golang.org/x/arch v0.8.0 h1:3wRIsP3pM4yUptoR96otTUOXI367OS0+c9eeRi9doIc=
8585
golang.org/x/arch v0.8.0/go.mod h1:FEVrYAQjsQXMVJ1nsMoVVXPZg6p2JE2mx8psSWTDQys=
86-
golang.org/x/crypto v0.45.0 h1:jMBrvKuj23MTlT0bQEOBcAE0mjg8mK9RXFhRH6nyF3Q=
87-
golang.org/x/crypto v0.45.0/go.mod h1:XTGrrkGJve7CYK7J8PEww4aY7gM3qMCElcJQ8n8JdX4=
86+
golang.org/x/crypto v0.49.0 h1:+Ng2ULVvLHnJ/ZFEq4KdcDd/cfjrrjjNSXNzxg0Y4U4=
87+
golang.org/x/crypto v0.49.0/go.mod h1:ErX4dUh2UM+CFYiXZRTcMpEcN8b/1gxEuv3nODoYtCA=
8888
golang.org/x/exp v0.0.0-20231006140011-7918f672742d h1:jtJma62tbqLibJ5sFQz8bKtEM8rJBtfilJ2qTU199MI=
8989
golang.org/x/exp v0.0.0-20231006140011-7918f672742d/go.mod h1:ldy0pHrwJyGW56pPQzzkH36rKxoZW1tw7ZJpeKx+hdo=
90-
golang.org/x/net v0.47.0 h1:Mx+4dIFzqraBXUugkia1OOvlD6LemFo1ALMHjrXDOhY=
91-
golang.org/x/net v0.47.0/go.mod h1:/jNxtkgq5yWUGYkaZGqo27cfGZ1c5Nen03aYrrKpVRU=
92-
golang.org/x/sync v0.18.0 h1:kr88TuHDroi+UVf+0hZnirlk8o8T+4MrK6mr60WkH/I=
93-
golang.org/x/sync v0.18.0/go.mod h1:9KTHXmSnoGruLpwFjVSX0lNNA75CykiMECbovNTZqGI=
90+
golang.org/x/net v0.52.0 h1:He/TN1l0e4mmR3QqHMT2Xab3Aj3L9qjbhRm78/6jrW0=
91+
golang.org/x/net v0.52.0/go.mod h1:R1MAz7uMZxVMualyPXb+VaqGSa3LIaUqk0eEt3w36Sw=
92+
golang.org/x/sync v0.20.0 h1:e0PTpb7pjO8GAtTs2dQ6jYa5BWYlMuX047Dco/pItO4=
93+
golang.org/x/sync v0.20.0/go.mod h1:9xrNwdLfx4jkKbNva9FpL6vEN7evnE43NNNJQ2LF3+0=
9494
golang.org/x/sys v0.5.0/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg=
9595
golang.org/x/sys v0.6.0/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg=
96-
golang.org/x/sys v0.38.0 h1:3yZWxaJjBmCWXqhN1qh02AkOnCQ1poK6oF+a7xWL6Gc=
97-
golang.org/x/sys v0.38.0/go.mod h1:OgkHotnGiDImocRcuBABYBEXf8A9a87e/uXjp9XT3ks=
98-
golang.org/x/text v0.31.0 h1:aC8ghyu4JhP8VojJ2lEHBnochRno1sgL6nEi9WGFGMM=
99-
golang.org/x/text v0.31.0/go.mod h1:tKRAlv61yKIjGGHX/4tP1LTbc13YSec1pxVEWXzfoeM=
96+
golang.org/x/sys v0.42.0 h1:omrd2nAlyT5ESRdCLYdm3+fMfNFE/+Rf4bDIQImRJeo=
97+
golang.org/x/sys v0.42.0/go.mod h1:4GL1E5IUh+htKOUEOaiffhrAeqysfVGipDYzABqnCmw=
98+
golang.org/x/text v0.35.0 h1:JOVx6vVDFokkpaq1AEptVzLTpDe9KGpj5tR4/X+ybL8=
99+
golang.org/x/text v0.35.0/go.mod h1:khi/HExzZJ2pGnjenulevKNX1W67CUy0AsXcNubPGCA=
100100
google.golang.org/protobuf v1.34.1 h1:9ddQBjfCyZPOHPUiPxpYESBLc+T8P3E+Vo4IbKZgFWg=
101101
google.golang.org/protobuf v1.34.1/go.mod h1:c6P6GXX6sHbq/GpV6MGZEdwhWPcYBgnhAHhKbcUYpos=
102102
gopkg.in/check.v1 v0.0.0-20161208181325-20d25e280405 h1:yhCVgyC4o1eVCa2tZl7eS0r+SDo693bJlVdllGtEeKM=

infra/sidecar.Dockerfile

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,5 @@
11
# ----- Builder image
2-
ARG GOLANG_VERSION=1.24.0
2+
ARG GOLANG_VERSION=1.26.1
33
FROM golang:${GOLANG_VERSION}-bookworm AS builder
44

55
ARG FIPS_MODE
@@ -20,9 +20,9 @@ RUN export GITHUB_SHA="${COMMIT_SHA}" && bash -c '\
2020
fi'
2121

2222
# ----- Runner image
23-
FROM debian:bookworm-20250203-slim AS runner
23+
FROM debian:bookworm-slim AS runner
2424

25-
ARG YQ_VERSION=v4.44.6
25+
ARG YQ_VERSION=v4.52.4
2626

2727
RUN DEBIAN_FRONTEND=noninteractive \
2828
apt-get update && \

0 commit comments

Comments
 (0)