Skip to content

Commit f193151

Browse files
committed
fix(deps): bump vulnerable dependencies to patched versions
- Upgrade buger/jsonparser from v1.1.1 to v1.1.2 (CVE-2026-32285) - Upgrade go-jose/go-jose/v4 from v4.1.3 to v4.1.4 (CVE-2026-34986) - Upgrade lodash from 4.17.23 to 4.18.0 (CVE-2026-4800, CVE-2026-2950)
1 parent e189f99 commit f193151

4 files changed

Lines changed: 11 additions & 11 deletions

File tree

go.mod

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -13,7 +13,7 @@ require (
1313
github.com/appleboy/gofight/v2 v2.2.1
1414
github.com/appleboy/graceful v1.3.0
1515
github.com/asdine/storm/v3 v3.2.1
16-
github.com/buger/jsonparser v1.1.1
16+
github.com/buger/jsonparser v1.1.2
1717
github.com/dgraph-io/badger/v4 v4.9.1
1818
github.com/gin-contrib/logger v1.2.6
1919
github.com/gin-gonic/gin v1.12.0
@@ -80,7 +80,7 @@ require (
8080
github.com/fukata/golang-stats-api-handler v1.0.0 // indirect
8181
github.com/gabriel-vasile/mimetype v1.4.13 // indirect
8282
github.com/gin-contrib/sse v1.1.0 // indirect
83-
github.com/go-jose/go-jose/v4 v4.1.3 // indirect
83+
github.com/go-jose/go-jose/v4 v4.1.4 // indirect
8484
github.com/go-logr/logr v1.4.3 // indirect
8585
github.com/go-logr/stdr v1.2.2 // indirect
8686
github.com/go-playground/locales v0.14.1 // indirect

go.sum

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -74,8 +74,8 @@ github.com/bsm/ginkgo/v2 v2.12.0 h1:Ny8MWAHyOepLGlLKYmXG4IEkioBysk6GpaRTLC8zwWs=
7474
github.com/bsm/ginkgo/v2 v2.12.0/go.mod h1:SwYbGRRDovPVboqFv0tPTcG1sN61LM1Z4ARdbAV9g4c=
7575
github.com/bsm/gomega v1.27.10 h1:yeMWxP2pV2fG3FgAODIY8EiRE3dy0aeFYt4l7wh6yKA=
7676
github.com/bsm/gomega v1.27.10/go.mod h1:JyEr/xRbxbtgWNi8tIEVPUYZ5Dzef52k01W3YH0H+O0=
77-
github.com/buger/jsonparser v1.1.1 h1:2PnMjfWD7wBILjqQbt530v576A/cAbQvEW9gGIpYMUs=
78-
github.com/buger/jsonparser v1.1.1/go.mod h1:6RYKKt7H4d4+iWqouImQ9R2FZql3VbhNgx27UK13J/0=
77+
github.com/buger/jsonparser v1.1.2 h1:frqHqw7otoVbk5M8LlE/L7HTnIq2v9RX6EJ48i9AxJk=
78+
github.com/buger/jsonparser v1.1.2/go.mod h1:6RYKKt7H4d4+iWqouImQ9R2FZql3VbhNgx27UK13J/0=
7979
github.com/bytedance/gopkg v0.1.3 h1:TPBSwH8RsouGCBcMBktLt1AymVo2TVsBVCY4b6TnZ/M=
8080
github.com/bytedance/gopkg v0.1.3/go.mod h1:576VvJ+eJgyCzdjS+c4+77QF3p7ubbtiKARP3TxducM=
8181
github.com/bytedance/sonic v1.15.0 h1:/PXeWFaR5ElNcVE84U0dOHjiMHQOwNIx3K4ymzh/uSE=
@@ -154,8 +154,8 @@ github.com/gin-contrib/sse v1.1.0 h1:n0w2GMuUpWDVp7qSpvze6fAu9iRxJY4Hmj6AmBOU05w
154154
github.com/gin-contrib/sse v1.1.0/go.mod h1:hxRZ5gVpWMT7Z0B0gSNYqqsSCNIJMjzvm6fqCz9vjwM=
155155
github.com/gin-gonic/gin v1.12.0 h1:b3YAbrZtnf8N//yjKeU2+MQsh2mY5htkZidOM7O0wG8=
156156
github.com/gin-gonic/gin v1.12.0/go.mod h1:VxccKfsSllpKshkBWgVgRniFFAzFb9csfngsqANjnLc=
157-
github.com/go-jose/go-jose/v4 v4.1.3 h1:CVLmWDhDVRa6Mi/IgCgaopNosCaHz7zrMeF9MlZRkrs=
158-
github.com/go-jose/go-jose/v4 v4.1.3/go.mod h1:x4oUasVrzR7071A4TnHLGSPpNOm2a21K9Kf04k1rs08=
157+
github.com/go-jose/go-jose/v4 v4.1.4 h1:moDMcTHmvE6Groj34emNPLs/qtYXRVcd6S7NHbHz3kA=
158+
github.com/go-jose/go-jose/v4 v4.1.4/go.mod h1:x4oUasVrzR7071A4TnHLGSPpNOm2a21K9Kf04k1rs08=
159159
github.com/go-kit/log v0.1.0/go.mod h1:zbhenjAZHb184qTLMA9ZjW7ThYL0H2mk7Q6pNt4vbaY=
160160
github.com/go-logfmt/logfmt v0.5.0/go.mod h1:wCYkCAKZfumFQihp8CzCvQ3paCTfi41vtzG1KdI/P7A=
161161
github.com/go-logr/logr v1.2.2/go.mod h1:jdQByPbusPIv2/zmleS9BjJVeZ6kBagPoEUsqbVz/1A=

rpc/example/node/package-lock.json

Lines changed: 4 additions & 4 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

rpc/example/node/package.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -5,7 +5,7 @@
55
"async": "^3.2.6",
66
"@grpc/grpc-js": "^1.12.6",
77
"google-protobuf": "^3.21.4",
8-
"lodash": "^4.17.23",
8+
"lodash": "^4.18.0",
99
"minimist": ">=1.2.8"
1010
}
1111
}

0 commit comments

Comments
 (0)