Skip to content

Commit 7a1a531

Browse files
authored
Merge pull request #389 from devtron-labs/fix-dependabot-security-advisory
sync: new dependabot security fixes
2 parents 30c2244 + 25acb6b commit 7a1a531

3,051 files changed

Lines changed: 558481 additions & 147483 deletions

File tree

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

authenticator/go.mod

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -25,7 +25,7 @@ require (
2525
github.com/davecgh/go-spew v1.1.1 // indirect
2626
github.com/emicklei/go-restful/v3 v3.11.0 // indirect
2727
github.com/fxamacker/cbor/v2 v2.7.0 // indirect
28-
github.com/go-jose/go-jose/v4 v4.1.3 // indirect
28+
github.com/go-jose/go-jose/v4 v4.1.4 // indirect
2929
github.com/go-logr/logr v1.4.3 // indirect
3030
github.com/go-openapi/jsonpointer v0.21.0 // indirect
3131
github.com/go-openapi/jsonreference v0.20.2 // indirect

authenticator/go.sum

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -10,8 +10,8 @@ github.com/emicklei/go-restful/v3 v3.11.0 h1:rAQeMHw1c7zTmncogyy8VvRZwtkmkZ4FxER
1010
github.com/emicklei/go-restful/v3 v3.11.0/go.mod h1:6n3XBCmQQb25CM2LCACGz8ukIrRry+4bhvbpWn3mrbc=
1111
github.com/fxamacker/cbor/v2 v2.7.0 h1:iM5WgngdRBanHcxugY4JySA0nk1wZorNOpTgCMedv5E=
1212
github.com/fxamacker/cbor/v2 v2.7.0/go.mod h1:pxXPTn3joSm21Gbwsv0w9OSA2y1HFR9qXEeXQVeNoDQ=
13-
github.com/go-jose/go-jose/v4 v4.1.3 h1:CVLmWDhDVRa6Mi/IgCgaopNosCaHz7zrMeF9MlZRkrs=
14-
github.com/go-jose/go-jose/v4 v4.1.3/go.mod h1:x4oUasVrzR7071A4TnHLGSPpNOm2a21K9Kf04k1rs08=
13+
github.com/go-jose/go-jose/v4 v4.1.4 h1:moDMcTHmvE6Groj34emNPLs/qtYXRVcd6S7NHbHz3kA=
14+
github.com/go-jose/go-jose/v4 v4.1.4/go.mod h1:x4oUasVrzR7071A4TnHLGSPpNOm2a21K9Kf04k1rs08=
1515
github.com/go-logr/logr v1.4.3 h1:CjnDlHq8ikf6E492q6eKboGOC0T8CDaOvkHCIg8idEI=
1616
github.com/go-logr/logr v1.4.3/go.mod h1:9T104GzyrTigFIr8wt5mBrctHMim0Nb2HLGrmQ40KvY=
1717
github.com/go-openapi/jsonpointer v0.19.6/go.mod h1:osyAmYz/mB/C3I+WsTTSgw1ONzaLJoLCyoi6/zppojs=

authenticator/vendor/github.com/go-jose/go-jose/v4/asymmetric.go

Lines changed: 9 additions & 1 deletion
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

authenticator/vendor/github.com/go-jose/go-jose/v4/cipher/key_wrap.go

Lines changed: 9 additions & 1 deletion
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

authenticator/vendor/github.com/go-jose/go-jose/v4/symmetric.go

Lines changed: 18 additions & 8 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

authenticator/vendor/modules.txt

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -14,7 +14,7 @@ github.com/emicklei/go-restful/v3/log
1414
# github.com/fxamacker/cbor/v2 v2.7.0
1515
## explicit; go 1.17
1616
github.com/fxamacker/cbor/v2
17-
# github.com/go-jose/go-jose/v4 v4.1.3
17+
# github.com/go-jose/go-jose/v4 v4.1.4
1818
## explicit; go 1.24.0
1919
github.com/go-jose/go-jose/v4
2020
github.com/go-jose/go-jose/v4/cipher

chart-sync/go.mod

Lines changed: 35 additions & 39 deletions
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,7 @@ module github.com/devtron-labs/chart-sync
22

33
go 1.25.0
44

5-
replace github.com/devtron-labs/common-lib => github.com/devtron-labs/devtron-services/common-lib v0.0.0-20260415070948-6353c1c123c3
5+
replace github.com/devtron-labs/common-lib => github.com/devtron-labs/devtron-services/common-lib v0.0.0-20260415113300-e49850611af6
66

77
require (
88
github.com/caarlos0/env v3.5.0+incompatible
@@ -11,23 +11,23 @@ require (
1111
github.com/go-pg/pg v6.15.1+incompatible
1212
github.com/google/wire v0.6.0
1313
github.com/pkg/errors v0.9.1
14-
github.com/prometheus/client_golang v1.22.0
14+
github.com/prometheus/client_golang v1.23.2
1515
go.uber.org/zap v1.27.0
1616
golang.org/x/exp v0.0.0-20250506013437-ce4c2cf36ca6
17-
helm.sh/helm/v3 v3.18.6
17+
helm.sh/helm/v3 v3.20.1
1818
)
1919

2020
require (
2121
github.com/Azure/go-ansiterm v0.0.0-20250102033503-faa5f7b0171c // indirect
2222
github.com/MakeNowJust/heredoc v1.0.0 // indirect
23-
github.com/Masterminds/semver/v3 v3.3.0 // indirect
23+
github.com/Masterminds/semver/v3 v3.4.0 // indirect
2424
github.com/aws/aws-sdk-go v1.55.7 // indirect
2525
github.com/beorn7/perks v1.0.1 // indirect
2626
github.com/blang/semver/v4 v4.0.0 // indirect
2727
github.com/cenkalti/backoff/v5 v5.0.2 // indirect
2828
github.com/cespare/xxhash/v2 v2.3.0 // indirect
2929
github.com/chai2010/gettext-go v1.0.2 // indirect
30-
github.com/containerd/containerd v1.7.27 // indirect
30+
github.com/containerd/containerd v1.7.30 // indirect
3131
github.com/containerd/errdefs v1.0.0 // indirect
3232
github.com/containerd/log v0.1.0 // indirect
3333
github.com/containerd/platforms v0.2.1 // indirect
@@ -36,20 +36,17 @@ require (
3636
github.com/emicklei/go-restful/v3 v3.12.2 // indirect
3737
github.com/evanphx/json-patch v5.9.11+incompatible // indirect
3838
github.com/exponent-io/jsonpath v0.0.0-20210407135951-1de76d718b3f // indirect
39-
github.com/fxamacker/cbor/v2 v2.7.0 // indirect
39+
github.com/fxamacker/cbor/v2 v2.9.0 // indirect
4040
github.com/go-errors/errors v1.4.2 // indirect
4141
github.com/go-logr/logr v1.4.3 // indirect
4242
github.com/go-logr/stdr v1.2.2 // indirect
4343
github.com/go-openapi/jsonpointer v0.21.1 // indirect
4444
github.com/go-openapi/jsonreference v0.21.0 // indirect
4545
github.com/go-openapi/swag v0.23.1 // indirect
46-
github.com/gogo/protobuf v1.3.2 // indirect
4746
github.com/google/btree v1.1.3 // indirect
48-
github.com/google/gnostic-models v0.6.9 // indirect
47+
github.com/google/gnostic-models v0.7.0 // indirect
4948
github.com/google/go-cmp v0.7.0 // indirect
50-
github.com/google/shlex v0.0.0-20191202100458-e7afc7fbc510 // indirect
5149
github.com/google/uuid v1.6.0 // indirect
52-
github.com/gorilla/websocket v1.5.4-0.20250319132907-e064f32e3674 // indirect
5350
github.com/gregjones/httpcache v0.0.0-20190611155906-901d90724c79 // indirect
5451
github.com/hashicorp/errwrap v1.1.0 // indirect
5552
github.com/hashicorp/go-multierror v1.1.1 // indirect
@@ -62,66 +59,65 @@ require (
6259
github.com/liggitt/tabwriter v0.0.0-20181228230101-89fcab3d43de // indirect
6360
github.com/mailru/easyjson v0.9.0 // indirect
6461
github.com/mitchellh/go-wordwrap v1.0.1 // indirect
65-
github.com/moby/spdystream v0.5.0 // indirect
6662
github.com/moby/term v0.5.2 // indirect
6763
github.com/modern-go/concurrent v0.0.0-20180306012644-bacd9c7ef1dd // indirect
68-
github.com/modern-go/reflect2 v1.0.2 // indirect
64+
github.com/modern-go/reflect2 v1.0.3-0.20250322232337-35a7c28c31ee // indirect
6965
github.com/monochromegane/go-gitignore v0.0.0-20200626010858-205db1a8cc00 // indirect
7066
github.com/munnerz/goautoneg v0.0.0-20191010083416-a7dc8b61c822 // indirect
71-
github.com/mxk/go-flowrate v0.0.0-20140419014527-cca7078d478f // indirect
7267
github.com/onsi/ginkgo v1.16.5 // indirect
7368
github.com/opencontainers/go-digest v1.0.0 // indirect
7469
github.com/opencontainers/image-spec v1.1.1 // indirect
7570
github.com/peterbourgon/diskv v2.0.1+incompatible // indirect
71+
github.com/pmezard/go-difflib v1.0.1-0.20181226105442-5d4384ee4fb2 // indirect
7672
github.com/prometheus/client_model v0.6.2 // indirect
77-
github.com/prometheus/common v0.64.0 // indirect
73+
github.com/prometheus/common v0.66.1 // indirect
7874
github.com/prometheus/procfs v0.16.1 // indirect
7975
github.com/russross/blackfriday/v2 v2.1.0 // indirect
8076
github.com/sirupsen/logrus v1.9.3 // indirect
81-
github.com/spf13/cobra v1.9.1 // indirect
82-
github.com/spf13/pflag v1.0.7 // indirect
77+
github.com/spf13/cobra v1.10.2 // indirect
78+
github.com/spf13/pflag v1.0.10 // indirect
8379
github.com/x448/float16 v0.8.4 // indirect
8480
github.com/xlab/treeprint v1.2.0 // indirect
8581
go.opentelemetry.io/auto/sdk v1.2.1 // indirect
86-
go.opentelemetry.io/otel v1.39.0 // indirect
87-
go.opentelemetry.io/otel/metric v1.39.0 // indirect
88-
go.opentelemetry.io/otel/trace v1.39.0 // indirect
82+
go.opentelemetry.io/otel v1.43.0 // indirect
83+
go.opentelemetry.io/otel/metric v1.43.0 // indirect
84+
go.opentelemetry.io/otel/trace v1.43.0 // indirect
8985
go.uber.org/multierr v1.11.0 // indirect
90-
go.yaml.in/yaml/v2 v2.4.2 // indirect
91-
go.yaml.in/yaml/v3 v3.0.3 // indirect
86+
go.yaml.in/yaml/v2 v2.4.3 // indirect
87+
go.yaml.in/yaml/v3 v3.0.4 // indirect
9288
golang.org/x/crypto v0.46.0 // indirect
9389
golang.org/x/net v0.48.0 // indirect
9490
golang.org/x/oauth2 v0.34.0 // indirect
9591
golang.org/x/sync v0.19.0 // indirect
96-
golang.org/x/sys v0.39.0 // indirect
97-
golang.org/x/term v0.38.0 // indirect
98-
golang.org/x/text v0.32.0 // indirect
92+
golang.org/x/sys v0.42.0 // indirect
93+
golang.org/x/term v0.39.0 // indirect
94+
golang.org/x/text v0.33.0 // indirect
9995
golang.org/x/time v0.12.0 // indirect
10096
google.golang.org/genproto/googleapis/rpc v0.0.0-20251202230838-ff82c1b0f217 // indirect
10197
google.golang.org/grpc v1.79.3 // indirect
10298
google.golang.org/protobuf v1.36.10 // indirect
103-
gopkg.in/evanphx/json-patch.v4 v4.12.0 // indirect
99+
gopkg.in/evanphx/json-patch.v4 v4.13.0 // indirect
104100
gopkg.in/inf.v0 v0.9.1 // indirect
105101
gopkg.in/yaml.v2 v2.4.0 // indirect
106102
gopkg.in/yaml.v3 v3.0.1 // indirect
107-
k8s.io/api v0.33.3 // indirect
108-
k8s.io/apiextensions-apiserver v0.33.3 // indirect
109-
k8s.io/apimachinery v0.33.3 // indirect
110-
k8s.io/cli-runtime v0.33.3 // indirect
111-
k8s.io/client-go v0.33.3 // indirect
112-
k8s.io/component-base v0.33.3 // indirect
103+
k8s.io/api v0.35.1 // indirect
104+
k8s.io/apiextensions-apiserver v0.35.1 // indirect
105+
k8s.io/apimachinery v0.35.1 // indirect
106+
k8s.io/cli-runtime v0.35.1 // indirect
107+
k8s.io/client-go v0.35.1 // indirect
108+
k8s.io/component-base v0.35.1 // indirect
113109
k8s.io/klog/v2 v2.130.1 // indirect
114-
k8s.io/kube-openapi v0.0.0-20250318190949-c8a335a9a2ff // indirect
115-
k8s.io/kubectl v0.33.3 // indirect
116-
k8s.io/utils v0.0.0-20250502105355-0f33e8f1c979 // indirect
110+
k8s.io/kube-openapi v0.0.0-20250910181357-589584f1c912 // indirect
111+
k8s.io/kubectl v0.35.1 // indirect
112+
k8s.io/utils v0.0.0-20251002143259-bc988d571ff4 // indirect
117113
mellium.im/sasl v0.3.2 // indirect
118114
oras.land/oras-go/v2 v2.6.0 // indirect
119-
sigs.k8s.io/json v0.0.0-20241014173422-cfa47c3a1cc8 // indirect
120-
sigs.k8s.io/kustomize/api v0.19.0 // indirect
121-
sigs.k8s.io/kustomize/kyaml v0.19.0 // indirect
115+
sigs.k8s.io/json v0.0.0-20250730193827-2d320260d730 // indirect
116+
sigs.k8s.io/kustomize/api v0.20.1 // indirect
117+
sigs.k8s.io/kustomize/kyaml v0.20.1 // indirect
122118
sigs.k8s.io/randfill v1.0.0 // indirect
123-
sigs.k8s.io/structured-merge-diff/v4 v4.7.0 // indirect
124-
sigs.k8s.io/yaml v1.5.0 // indirect
119+
sigs.k8s.io/structured-merge-diff/v6 v6.3.0 // indirect
120+
sigs.k8s.io/yaml v1.6.0 // indirect
125121
)
126122

127123
replace (

0 commit comments

Comments
 (0)