Skip to content

Commit 70882eb

Browse files
committed
fix: resolve CVE-2023-44487 and CVE-2025-22872 by updating dependencies
- Update k8s.io/apimachinery from v0.28.3 to v0.29.0 (fixes CVE-2023-44487) - Update golang.org/x/net from v0.36.0 to v0.38.0 (fixes CVE-2025-22872) - Update k8s.io/api and k8s.io/client-go to v0.29.0 for compatibility - Update sigs.k8s.io/controller-runtime to v0.17.0 for compatibility All tests pass and code compiles successfully.
1 parent 7fbc1a4 commit 70882eb

File tree

2 files changed

+89
-115
lines changed

2 files changed

+89
-115
lines changed

go.mod

Lines changed: 27 additions & 27 deletions
Original file line numberDiff line numberDiff line change
@@ -5,27 +5,28 @@ go 1.23.0
55
toolchain go1.23.3
66

77
require (
8-
github.com/go-logr/logr v1.2.4
9-
github.com/onsi/ginkgo/v2 v2.11.0
10-
github.com/onsi/gomega v1.27.10
11-
go.uber.org/zap v1.25.0
12-
k8s.io/api v0.28.3
13-
k8s.io/apimachinery v0.28.3
14-
k8s.io/client-go v0.28.3
8+
github.com/go-logr/logr v1.4.1
9+
github.com/onsi/ginkgo/v2 v2.14.0
10+
github.com/onsi/gomega v1.30.0
11+
go.uber.org/zap v1.26.0
12+
golang.org/x/net v0.38.0 // indirect
13+
k8s.io/api v0.29.0
14+
k8s.io/apimachinery v0.29.0
15+
k8s.io/client-go v0.29.0
1516
// k8s.io/utils v0.0.0-20230209194617-a36077c30491
16-
sigs.k8s.io/controller-runtime v0.16.3
17+
sigs.k8s.io/controller-runtime v0.17.0
1718
)
1819

19-
require k8s.io/utils v0.0.0-20230406110748-d93618cff8a2
20+
require k8s.io/utils v0.0.0-20230726121419-3b25d923346b
2021

2122
require (
2223
github.com/beorn7/perks v1.0.1 // indirect
2324
github.com/cespare/xxhash/v2 v2.2.0 // indirect
2425
github.com/davecgh/go-spew v1.1.1 // indirect
2526
github.com/emicklei/go-restful/v3 v3.11.0 // indirect
26-
github.com/evanphx/json-patch/v5 v5.6.0 // indirect
27-
github.com/fsnotify/fsnotify v1.6.0 // indirect
28-
github.com/go-logr/zapr v1.2.4 // indirect
27+
github.com/evanphx/json-patch/v5 v5.8.0 // indirect
28+
github.com/fsnotify/fsnotify v1.7.0 // indirect
29+
github.com/go-logr/zapr v1.3.0 // indirect
2930
github.com/go-openapi/jsonpointer v0.19.6 // indirect
3031
github.com/go-openapi/jsonreference v0.20.2 // indirect
3132
github.com/go-openapi/swag v0.22.3 // indirect
@@ -42,35 +43,34 @@ require (
4243
github.com/josharian/intern v1.0.0 // indirect
4344
github.com/json-iterator/go v1.1.12 // indirect
4445
github.com/mailru/easyjson v0.7.7 // indirect
45-
github.com/matttproud/golang_protobuf_extensions v1.0.4 // indirect
46+
github.com/matttproud/golang_protobuf_extensions/v2 v2.0.0 // indirect
4647
github.com/modern-go/concurrent v0.0.0-20180306012644-bacd9c7ef1dd // indirect
4748
github.com/modern-go/reflect2 v1.0.2 // indirect
4849
github.com/munnerz/goautoneg v0.0.0-20191010083416-a7dc8b61c822 // indirect
4950
github.com/pkg/errors v0.9.1 // indirect
50-
github.com/prometheus/client_golang v1.16.0 // indirect
51-
github.com/prometheus/client_model v0.4.0 // indirect
52-
github.com/prometheus/common v0.44.0 // indirect
53-
github.com/prometheus/procfs v0.10.1 // indirect
51+
github.com/prometheus/client_golang v1.18.0 // indirect
52+
github.com/prometheus/client_model v0.5.0 // indirect
53+
github.com/prometheus/common v0.45.0 // indirect
54+
github.com/prometheus/procfs v0.12.0 // indirect
5455
github.com/spf13/pflag v1.0.5 // indirect
5556
go.uber.org/multierr v1.11.0 // indirect
5657
golang.org/x/exp v0.0.0-20220722155223-a9213eeb770e // indirect
57-
golang.org/x/net v0.36.0 // indirect
5858
golang.org/x/oauth2 v0.27.0 // indirect
59-
golang.org/x/sys v0.30.0 // indirect
60-
golang.org/x/term v0.29.0 // indirect
61-
golang.org/x/text v0.22.0 // indirect
59+
golang.org/x/sys v0.31.0 // indirect
60+
golang.org/x/term v0.30.0 // indirect
61+
golang.org/x/text v0.23.0 // indirect
6262
golang.org/x/time v0.3.0 // indirect
6363
golang.org/x/tools v0.21.1-0.20240508182429-e35e4ccd0d2d // indirect
6464
gomodules.xyz/jsonpatch/v2 v2.4.0 // indirect
6565
google.golang.org/protobuf v1.33.0 // indirect
6666
gopkg.in/inf.v0 v0.9.1 // indirect
6767
gopkg.in/yaml.v2 v2.4.0 // indirect
6868
gopkg.in/yaml.v3 v3.0.1 // indirect
69-
k8s.io/apiextensions-apiserver v0.28.3 // indirect
70-
k8s.io/component-base v0.28.3 // indirect
71-
k8s.io/klog/v2 v2.100.1 // indirect
72-
k8s.io/kube-openapi v0.0.0-20230717233707-2695361300d9 // indirect
69+
k8s.io/apiextensions-apiserver v0.29.0 // indirect
70+
k8s.io/component-base v0.29.0 // indirect
71+
k8s.io/klog/v2 v2.110.1 // indirect
72+
k8s.io/kube-openapi v0.0.0-20231010175941-2dd684a91f00 // indirect
7373
sigs.k8s.io/json v0.0.0-20221116044647-bc3834ca7abd // indirect
74-
sigs.k8s.io/structured-merge-diff/v4 v4.2.3 // indirect
75-
sigs.k8s.io/yaml v1.3.0 // indirect
74+
sigs.k8s.io/structured-merge-diff/v4 v4.4.1 // indirect
75+
sigs.k8s.io/yaml v1.4.0 // indirect
7676
)

0 commit comments

Comments
 (0)