Skip to content

Commit e0a70d5

Browse files
authored
[Sync] Update project files from source repository (c870de4) (#26)
* sync(ci): update tool versions and action hashes * fix(deps): upgrade dependencies to resolve CVE-2026-25882 and CVE-2026-27141 - github.com/gofiber/fiber/v2: v2.52.11 → v2.52.12 (fixes CVE-2026-25882 DoS via Route Parameter Overflow) - golang.org/x/net: v0.50.0 → v0.51.0 (fixes CVE-2026-27141 HTTP/2 server panic) - Additional indirect dependency upgrades via magex deps:update
1 parent 5f847cf commit e0a70d5

5 files changed

Lines changed: 691 additions & 179 deletions

File tree

.github/env/10-mage-x.env

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -62,7 +62,7 @@ MAGE_X_FORMAT_EXCLUDE_PATHS=vendor,node_modules,.git,.idea
6262
MAGE_X_GITLEAKS_VERSION=8.30.0
6363
MAGE_X_GOFUMPT_VERSION=v0.9.2
6464
MAGE_X_GOLANGCI_LINT_VERSION=v2.10.1
65-
MAGE_X_GORELEASER_VERSION=v2.13.3
65+
MAGE_X_GORELEASER_VERSION=v2.14.1
6666
MAGE_X_GOVULNCHECK_VERSION=v1.1.4
6767
MAGE_X_GO_SECONDARY_VERSION=1.24.x
6868
MAGE_X_GO_VERSION=1.24.x

.github/workflows/codeql-analysis.yml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -46,7 +46,7 @@ jobs:
4646

4747
# Initializes the CodeQL tools for scanning.
4848
- name: Initialize CodeQL
49-
uses: github/codeql-action/init@9e907b5e64f6b83e7804b09294d44122997950d6 # v4.32.3
49+
uses: github/codeql-action/init@89a39a4e59826350b863aa6b6252a07ad50cf83e # v4.32.4
5050
with:
5151
languages: ${{ matrix.language }}
5252
# If you wish to specify custom queries, you can do so here or in a config file.
@@ -57,7 +57,7 @@ jobs:
5757
# Autobuild attempts to build any compiled languages (C/C++, C#, or Java).
5858
# If this step fails, then you should remove it and run the build manually (see below)
5959
- name: Autobuild
60-
uses: github/codeql-action/autobuild@9e907b5e64f6b83e7804b09294d44122997950d6 # v4.32.3
60+
uses: github/codeql-action/autobuild@89a39a4e59826350b863aa6b6252a07ad50cf83e # v4.32.4
6161

6262
# ℹ️ Command-line programs to run using the OS shell.
6363
# 📚 https://git.io/JvXDl
@@ -67,4 +67,4 @@ jobs:
6767
# uses a compiled language
6868

6969
- name: Perform CodeQL Analysis
70-
uses: github/codeql-action/analyze@9e907b5e64f6b83e7804b09294d44122997950d6 # v4.32.3
70+
uses: github/codeql-action/analyze@89a39a4e59826350b863aa6b6252a07ad50cf83e # v4.32.4

.github/workflows/scorecard.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -68,7 +68,7 @@ jobs:
6868
# Upload the results as artifacts (optional). Commenting out will disable uploads of run results in SARIF
6969
# format to the repository Actions tab.
7070
- name: "Upload artifact"
71-
uses: actions/upload-artifact@b7c566a772e6b6bfb58ed0dc250532a479d7789f # v6.0.0
71+
uses: actions/upload-artifact@bbbca2ddaa5d8feaa63e36b76fdaad77386f024f # v7.0.0
7272
with:
7373
name: SARIF file
7474
path: results.sarif
@@ -77,6 +77,6 @@ jobs:
7777
# Upload the results to GitHub's code scanning dashboard (optional).
7878
# Commenting out will disable the upload of results to your repo's Code Scanning dashboard
7979
- name: "Upload to code-scanning"
80-
uses: github/codeql-action/upload-sarif@9e907b5e64f6b83e7804b09294d44122997950d6 # v4.32.3
80+
uses: github/codeql-action/upload-sarif@89a39a4e59826350b863aa6b6252a07ad50cf83e # v4.32.4
8181
with:
8282
sarif_file: results.sarif

go.mod

Lines changed: 51 additions & 53 deletions
Original file line numberDiff line numberDiff line change
@@ -4,71 +4,70 @@ go 1.25.4
44

55
require (
66
github.com/bsv-blockchain/go-chaintracks v1.1.2
7-
github.com/bsv-blockchain/go-p2p-message-bus v0.1.9
8-
github.com/bsv-blockchain/go-sdk v1.2.17
7+
github.com/bsv-blockchain/go-p2p-message-bus v0.1.11
8+
github.com/bsv-blockchain/go-sdk v1.2.18
99
github.com/bsv-blockchain/go-teranode-p2p-client v0.1.1
1010
github.com/bsv-blockchain/teranode v0.13.2
11-
github.com/gofiber/fiber/v2 v2.52.11
11+
github.com/gofiber/fiber/v2 v2.52.12
1212
github.com/golang-migrate/migrate/v4 v4.19.1
1313
github.com/google/uuid v1.6.0
1414
github.com/spf13/viper v1.21.0
1515
github.com/swaggo/swag v1.16.6
1616
github.com/valyala/fasthttp v1.69.0
1717
gopkg.in/yaml.v3 v3.0.1
18-
modernc.org/sqlite v1.45.0
18+
modernc.org/sqlite v1.46.1
1919
)
2020

2121
require (
2222
github.com/DATA-DOG/go-sqlmock v1.5.2 // indirect
23-
github.com/IBM/sarama v1.46.3 // indirect
23+
github.com/IBM/sarama v1.47.0 // indirect
2424
github.com/KyleBanks/depth v1.2.1 // indirect
2525
github.com/aerospike/aerospike-client-go/v8 v8.6.0 // indirect
2626
github.com/andybalholm/brotli v1.2.0 // indirect
27-
github.com/aws/aws-sdk-go-v2 v1.41.1 // indirect
28-
github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream v1.7.4 // indirect
29-
github.com/aws/aws-sdk-go-v2/config v1.32.7 // indirect
30-
github.com/aws/aws-sdk-go-v2/credentials v1.19.7 // indirect
31-
github.com/aws/aws-sdk-go-v2/feature/ec2/imds v1.18.17 // indirect
32-
github.com/aws/aws-sdk-go-v2/feature/s3/manager v1.22.0 // indirect
33-
github.com/aws/aws-sdk-go-v2/internal/configsources v1.4.17 // indirect
34-
github.com/aws/aws-sdk-go-v2/internal/endpoints/v2 v2.7.17 // indirect
27+
github.com/aws/aws-sdk-go-v2 v1.41.2 // indirect
28+
github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream v1.7.5 // indirect
29+
github.com/aws/aws-sdk-go-v2/config v1.32.10 // indirect
30+
github.com/aws/aws-sdk-go-v2/credentials v1.19.10 // indirect
31+
github.com/aws/aws-sdk-go-v2/feature/ec2/imds v1.18.18 // indirect
32+
github.com/aws/aws-sdk-go-v2/feature/s3/manager v1.22.4 // indirect
33+
github.com/aws/aws-sdk-go-v2/internal/configsources v1.4.18 // indirect
34+
github.com/aws/aws-sdk-go-v2/internal/endpoints/v2 v2.7.18 // indirect
3535
github.com/aws/aws-sdk-go-v2/internal/ini v1.8.4 // indirect
36-
github.com/aws/aws-sdk-go-v2/internal/v4a v1.4.17 // indirect
37-
github.com/aws/aws-sdk-go-v2/service/internal/accept-encoding v1.13.4 // indirect
38-
github.com/aws/aws-sdk-go-v2/service/internal/checksum v1.9.8 // indirect
39-
github.com/aws/aws-sdk-go-v2/service/internal/presigned-url v1.13.17 // indirect
40-
github.com/aws/aws-sdk-go-v2/service/internal/s3shared v1.19.17 // indirect
41-
github.com/aws/aws-sdk-go-v2/service/s3 v1.96.0 // indirect
42-
github.com/aws/aws-sdk-go-v2/service/signin v1.0.5 // indirect
43-
github.com/aws/aws-sdk-go-v2/service/sso v1.30.9 // indirect
44-
github.com/aws/aws-sdk-go-v2/service/ssooidc v1.35.13 // indirect
45-
github.com/aws/aws-sdk-go-v2/service/sts v1.41.6 // indirect
46-
github.com/aws/smithy-go v1.24.0 // indirect
36+
github.com/aws/aws-sdk-go-v2/internal/v4a v1.4.18 // indirect
37+
github.com/aws/aws-sdk-go-v2/service/internal/accept-encoding v1.13.5 // indirect
38+
github.com/aws/aws-sdk-go-v2/service/internal/checksum v1.9.10 // indirect
39+
github.com/aws/aws-sdk-go-v2/service/internal/presigned-url v1.13.18 // indirect
40+
github.com/aws/aws-sdk-go-v2/service/internal/s3shared v1.19.18 // indirect
41+
github.com/aws/aws-sdk-go-v2/service/s3 v1.96.2 // indirect
42+
github.com/aws/aws-sdk-go-v2/service/signin v1.0.6 // indirect
43+
github.com/aws/aws-sdk-go-v2/service/sso v1.30.11 // indirect
44+
github.com/aws/aws-sdk-go-v2/service/ssooidc v1.35.15 // indirect
45+
github.com/aws/aws-sdk-go-v2/service/sts v1.41.7 // indirect
46+
github.com/aws/smithy-go v1.24.2 // indirect
4747
github.com/benbjohnson/clock v1.3.5 // indirect
4848
github.com/beorn7/perks v1.0.1 // indirect
49-
github.com/bsv-blockchain/go-batcher v1.2.7 // indirect
50-
github.com/bsv-blockchain/go-bt/v2 v2.5.3 // indirect
49+
github.com/bsv-blockchain/go-batcher v1.2.9 // indirect
50+
github.com/bsv-blockchain/go-bt/v2 v2.6.0 // indirect
5151
github.com/bsv-blockchain/go-chaincfg v1.5.4 // indirect
5252
github.com/bsv-blockchain/go-lockfree-queue v1.1.2 // indirect
5353
github.com/bsv-blockchain/go-safe-conversion v1.1.2 // indirect
54-
github.com/bsv-blockchain/go-subtree v1.1.8 // indirect
54+
github.com/bsv-blockchain/go-subtree v1.2.0 // indirect
5555
github.com/bsv-blockchain/go-tx-map v1.3.2 // indirect
56-
github.com/bsv-blockchain/go-wire v1.1.3 // indirect
56+
github.com/bsv-blockchain/go-wire v1.2.1 // indirect
5757
github.com/cenkalti/backoff/v5 v5.0.3 // indirect
5858
github.com/cespare/xxhash v1.1.0 // indirect
5959
github.com/cespare/xxhash/v2 v2.3.0 // indirect
60-
github.com/clipperhouse/uax29/v2 v2.6.0 // indirect
60+
github.com/clipperhouse/uax29/v2 v2.7.0 // indirect
6161
github.com/davecgh/go-spew v1.1.2-0.20180830191138-d8f796af33cc // indirect
6262
github.com/davidlazar/go-crypto v0.0.0-20200604182044-b73af7476f6c // indirect
63-
github.com/decred/dcrd/dcrec/secp256k1/v4 v4.4.0 // indirect
63+
github.com/decred/dcrd/dcrec/secp256k1/v4 v4.4.1 // indirect
6464
github.com/dgraph-io/badger/v4 v4.9.1 // indirect
6565
github.com/dgraph-io/ristretto/v2 v2.4.0 // indirect
6666
github.com/dolthub/maphash v0.1.0 // indirect
6767
github.com/dolthub/swiss v0.2.1 // indirect
6868
github.com/dunglas/httpsfv v1.1.0 // indirect
6969
github.com/dustin/go-humanize v1.0.1 // indirect
7070
github.com/eapache/go-resiliency v1.7.0 // indirect
71-
github.com/eapache/go-xerial-snappy v0.0.0-20230731223053-c322873962e3 // indirect
7271
github.com/eapache/queue v1.1.0 // indirect
7372
github.com/emicklei/go-restful/v3 v3.13.0 // indirect
7473
github.com/filecoin-project/go-clock v0.1.0 // indirect
@@ -94,25 +93,24 @@ require (
9493
github.com/go-openapi/swag/yamlutils v0.25.4 // indirect
9594
github.com/go-viper/mapstructure/v2 v2.5.0 // indirect
9695
github.com/gogo/protobuf v1.3.2 // indirect
97-
github.com/golang/snappy v1.0.0 // indirect
9896
github.com/google/flatbuffers v25.12.19+incompatible // indirect
9997
github.com/google/gnostic-models v0.7.1 // indirect
10098
github.com/google/go-cmp v0.7.0 // indirect
10199
github.com/google/gopacket v1.1.19 // indirect
102100
github.com/gorilla/websocket v1.5.4-0.20250319132907-e064f32e3674 // indirect
103101
github.com/grpc-ecosystem/go-grpc-middleware/providers/prometheus v1.1.0 // indirect
104102
github.com/grpc-ecosystem/go-grpc-middleware/v2 v2.3.3 // indirect
105-
github.com/grpc-ecosystem/grpc-gateway/v2 v2.27.8 // indirect
103+
github.com/grpc-ecosystem/grpc-gateway/v2 v2.28.0 // indirect
106104
github.com/grpc-ecosystem/grpc-opentracing v0.0.0-20180507213350-8e809c8a8645 // indirect
107105
github.com/hashicorp/go-uuid v1.0.3 // indirect
108106
github.com/hashicorp/golang-lru v1.0.2 // indirect
109107
github.com/hashicorp/golang-lru/v2 v2.0.7 // indirect
110108
github.com/huin/goupnp v1.3.0 // indirect
111-
github.com/ipfs/boxo v0.36.0 // indirect
109+
github.com/ipfs/boxo v0.37.0 // indirect
112110
github.com/ipfs/go-cid v0.6.0 // indirect
113111
github.com/ipfs/go-datastore v0.9.1 // indirect
114112
github.com/ipfs/go-log/v2 v2.9.1 // indirect
115-
github.com/ipld/go-ipld-prime v0.21.0 // indirect
113+
github.com/ipld/go-ipld-prime v0.22.0 // indirect
116114
github.com/jackpal/go-nat-pmp v1.0.2 // indirect
117115
github.com/jbenet/go-temp-err-catcher v0.1.0 // indirect
118116
github.com/jcmturner/aescts/v2 v2.0.0 // indirect
@@ -127,15 +125,15 @@ require (
127125
github.com/klauspost/cpuid/v2 v2.3.0 // indirect
128126
github.com/koron/go-ssdp v0.1.0 // indirect
129127
github.com/kpango/fastime v1.1.10 // indirect
130-
github.com/labstack/echo/v4 v4.15.0 // indirect
128+
github.com/labstack/echo/v4 v4.15.1 // indirect
131129
github.com/labstack/gommon v0.4.2 // indirect
132130
github.com/lib/pq v1.11.2 // indirect
133131
github.com/libp2p/go-buffer-pool v0.1.0 // indirect
134132
github.com/libp2p/go-cidranger v1.1.0 // indirect
135133
github.com/libp2p/go-flow-metrics v0.3.0 // indirect
136134
github.com/libp2p/go-libp2p v0.47.0 // indirect
137135
github.com/libp2p/go-libp2p-asn-util v0.4.1 // indirect
138-
github.com/libp2p/go-libp2p-kad-dht v0.37.1 // indirect
136+
github.com/libp2p/go-libp2p-kad-dht v0.38.0 // indirect
139137
github.com/libp2p/go-libp2p-kbucket v0.8.0 // indirect
140138
github.com/libp2p/go-libp2p-pubsub v0.15.0 // indirect
141139
github.com/libp2p/go-libp2p-record v0.3.1 // indirect
@@ -152,7 +150,7 @@ require (
152150
github.com/marten-seemann/tcp v0.0.0-20210406111302-dfbc87cc63fd // indirect
153151
github.com/mattn/go-colorable v0.1.14 // indirect
154152
github.com/mattn/go-isatty v0.0.20 // indirect
155-
github.com/mattn/go-runewidth v0.0.19 // indirect
153+
github.com/mattn/go-runewidth v0.0.20 // indirect
156154
github.com/mgutz/ansi v0.0.0-20200706080929-d51e80ef957d // indirect
157155
github.com/miekg/dns v1.1.72 // indirect
158156
github.com/mikioh/tcpinfo v0.0.0-20190314235526-30a79bb1804b // indirect
@@ -182,29 +180,29 @@ require (
182180
github.com/pion/datachannel v1.6.0 // indirect
183181
github.com/pion/dtls/v2 v2.2.12 // indirect
184182
github.com/pion/dtls/v3 v3.1.2 // indirect
185-
github.com/pion/ice/v4 v4.2.0 // indirect
183+
github.com/pion/ice/v4 v4.2.1 // indirect
186184
github.com/pion/interceptor v0.1.44 // indirect
187185
github.com/pion/logging v0.2.4 // indirect
188186
github.com/pion/mdns/v2 v2.1.0 // indirect
189187
github.com/pion/randutil v0.1.0 // indirect
190188
github.com/pion/rtcp v1.2.16 // indirect
191189
github.com/pion/rtp v1.10.1 // indirect
192190
github.com/pion/sctp v1.9.2 // indirect
193-
github.com/pion/sdp/v3 v3.0.17 // indirect
191+
github.com/pion/sdp/v3 v3.0.18 // indirect
194192
github.com/pion/srtp/v3 v3.0.10 // indirect
195193
github.com/pion/stun v0.6.1 // indirect
196194
github.com/pion/stun/v3 v3.1.1 // indirect
197195
github.com/pion/transport/v2 v2.2.10 // indirect
198196
github.com/pion/transport/v4 v4.0.1 // indirect
199197
github.com/pion/turn/v4 v4.1.4 // indirect
200-
github.com/pion/webrtc/v4 v4.2.6 // indirect
198+
github.com/pion/webrtc/v4 v4.2.9 // indirect
201199
github.com/pkg/errors v0.9.1 // indirect
202200
github.com/pmezard/go-difflib v1.0.1-0.20181226105442-5d4384ee4fb2 // indirect
203-
github.com/polydawn/refmt v0.89.0 // indirect
201+
github.com/polydawn/refmt v0.89.1-0.20231129105047-37766d95467a // indirect
204202
github.com/prometheus/client_golang v1.23.2 // indirect
205203
github.com/prometheus/client_model v0.6.2 // indirect
206204
github.com/prometheus/common v0.67.5 // indirect
207-
github.com/prometheus/procfs v0.19.2 // indirect
205+
github.com/prometheus/procfs v0.20.1 // indirect
208206
github.com/quic-go/qpack v0.6.0 // indirect
209207
github.com/quic-go/quic-go v0.59.0 // indirect
210208
github.com/quic-go/webtransport-go v0.10.0 // indirect
@@ -247,32 +245,32 @@ require (
247245
go.yaml.in/yaml/v2 v2.4.3 // indirect
248246
go.yaml.in/yaml/v3 v3.0.4 // indirect
249247
golang.org/x/crypto v0.48.0 // indirect
250-
golang.org/x/exp v0.0.0-20260211191109-2735e65f0518 // indirect
248+
golang.org/x/exp v0.0.0-20260218203240-3dfff04db8fa // indirect
251249
golang.org/x/mod v0.33.0 // indirect
252-
golang.org/x/net v0.50.0 // indirect
250+
golang.org/x/net v0.51.0 // indirect
253251
golang.org/x/oauth2 v0.35.0 // indirect
254252
golang.org/x/sync v0.19.0 // indirect
255253
golang.org/x/sys v0.41.0 // indirect
256-
golang.org/x/telemetry v0.0.0-20260211191001-d65f0a9c301c // indirect
254+
golang.org/x/telemetry v0.0.0-20260213145524-e0ab670178e1 // indirect
257255
golang.org/x/term v0.40.0 // indirect
258256
golang.org/x/text v0.34.0 // indirect
259257
golang.org/x/time v0.14.0 // indirect
260258
golang.org/x/tools v0.42.0 // indirect
261259
gonum.org/v1/gonum v0.17.0 // indirect
262-
google.golang.org/genproto/googleapis/api v0.0.0-20260209200024-4cfbd4190f57 // indirect
263-
google.golang.org/genproto/googleapis/rpc v0.0.0-20260209200024-4cfbd4190f57 // indirect
264-
google.golang.org/grpc v1.78.0 // indirect
260+
google.golang.org/genproto/googleapis/api v0.0.0-20260226221140-a57be14db171 // indirect
261+
google.golang.org/genproto/googleapis/rpc v0.0.0-20260226221140-a57be14db171 // indirect
262+
google.golang.org/grpc v1.79.1 // indirect
265263
google.golang.org/protobuf v1.36.11 // indirect
266264
gopkg.in/evanphx/json-patch.v4 v4.13.0 // indirect
267265
gopkg.in/inf.v0 v0.9.1 // indirect
268-
k8s.io/api v0.35.1 // indirect
269-
k8s.io/apimachinery v0.35.1 // indirect
270-
k8s.io/client-go v0.35.1 // indirect
266+
k8s.io/api v0.35.2 // indirect
267+
k8s.io/apimachinery v0.35.2 // indirect
268+
k8s.io/client-go v0.35.2 // indirect
271269
k8s.io/klog/v2 v2.130.1 // indirect
272270
k8s.io/kube-openapi v0.0.0-20260127142750-a19766b6e2d4 // indirect
273271
k8s.io/utils v0.0.0-20260210185600-b8788abfbbc2 // indirect
274272
lukechampine.com/blake3 v1.4.1 // indirect
275-
modernc.org/libc v1.67.7 // indirect
273+
modernc.org/libc v1.68.1 // indirect
276274
modernc.org/mathutil v1.7.1 // indirect
277275
modernc.org/memory v1.11.0 // indirect
278276
sigs.k8s.io/json v0.0.0-20250730193827-2d320260d730 // indirect

0 commit comments

Comments
 (0)