Skip to content

Commit 5d18a2f

Browse files
Unpin x/sys pkg and upgrade dependencies to mitigate CVEs (#336)
1 parent 6d0cf95 commit 5d18a2f

File tree

3 files changed

+907
-23
lines changed

3 files changed

+907
-23
lines changed

CHANGELOG.md

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -11,6 +11,7 @@
1111
- Deprecate --feature.jwt.rotation CLI option
1212
- Add support for config file
1313
- Upgrade to Go 1.17.13 and alpine3.16 for build image
14+
- Unpin x/sys pkg and upgrade dependencies to mitigate CVEs
1415

1516
## [0.15.4](https://github.com/arangodb-helper/arangodb/tree/0.15.4) (2022-03-22)
1617
- Use github.com/golang-jwt/jwt

go.mod

Lines changed: 29 additions & 23 deletions
Original file line numberDiff line numberDiff line change
@@ -2,8 +2,6 @@ module github.com/arangodb-helper/arangodb
22

33
go 1.17
44

5-
replace golang.org/x/sys => golang.org/x/sys v0.0.0-20190813064441-fde4db37ae7a
6-
75
require (
86
github.com/arangodb-helper/go-certificates v0.0.0-20180821055445-9fca24fc2680
97
github.com/arangodb/go-driver v1.2.1
@@ -12,7 +10,7 @@ require (
1210
github.com/coreos/go-semver v0.3.0
1311
github.com/dchest/uniuri v0.0.0-20200228104902-7aecb25e1fe5
1412
github.com/fatih/color v1.9.0
15-
github.com/fsouza/go-dockerclient v1.6.5
13+
github.com/fsouza/go-dockerclient v1.8.3
1614
github.com/golang-jwt/jwt v3.2.2+incompatible
1715
github.com/kballard/go-shellquote v0.0.0-20180428030007-95032a82bc51
1816
github.com/mitchellh/go-homedir v1.1.0
@@ -21,39 +19,47 @@ require (
2119
github.com/ryanuber/columnize v2.1.0+incompatible
2220
github.com/spf13/cobra v1.0.0
2321
github.com/spf13/pflag v1.0.5
24-
github.com/stretchr/testify v1.5.1
25-
golang.org/x/crypto v0.0.0-20200622213623-75b288015ac9
22+
github.com/stretchr/testify v1.7.0
23+
golang.org/x/crypto v0.0.0-20220829220503-c86fa9a7ed90
2624
gopkg.in/ini.v1 v1.66.6
2725
)
2826

2927
require (
30-
github.com/Azure/go-ansiterm v0.0.0-20170929234023-d6e3b3328b78 // indirect
31-
github.com/Microsoft/go-winio v0.4.15-0.20200113171025-3fe6c5262873 // indirect
32-
github.com/Microsoft/hcsshim v0.8.7 // indirect
28+
github.com/Azure/go-ansiterm v0.0.0-20210617225240-d185dfc1b5a1 // indirect
29+
github.com/Microsoft/go-winio v0.5.2 // indirect
30+
github.com/Microsoft/hcsshim v0.9.3 // indirect
3331
github.com/arangodb/go-velocypack v0.0.0-20200318135517-5af53c29c67e // indirect
34-
github.com/containerd/containerd v1.3.0 // indirect
35-
github.com/containerd/continuity v0.0.0-20200228182428-0f16d7a0959c // indirect
32+
github.com/containerd/cgroups v1.0.3 // indirect
33+
github.com/containerd/containerd v1.6.6 // indirect
34+
github.com/containerd/continuity v0.2.2 // indirect
3635
github.com/davecgh/go-spew v1.1.1 // indirect
3736
github.com/docker/distribution v2.7.1+incompatible // indirect
38-
github.com/docker/docker v1.4.2-0.20191101170500-ac7306503d23 // indirect
37+
github.com/docker/docker v20.10.17+incompatible // indirect
3938
github.com/docker/go-connections v0.4.0 // indirect
4039
github.com/docker/go-units v0.4.0 // indirect
41-
github.com/gogo/protobuf v1.3.1 // indirect
42-
github.com/golang/protobuf v1.3.2 // indirect
40+
github.com/gogo/protobuf v1.3.2 // indirect
41+
github.com/golang/groupcache v0.0.0-20210331224755-41bb18bfe9da // indirect
42+
github.com/golang/protobuf v1.5.2 // indirect
4343
github.com/inconshreveable/mousetrap v1.0.0 // indirect
44-
github.com/konsorten/go-windows-terminal-sequences v1.0.1 // indirect
44+
github.com/konsorten/go-windows-terminal-sequences v1.0.3 // indirect
4545
github.com/mattn/go-colorable v0.1.7 // indirect
4646
github.com/mattn/go-isatty v0.0.12 // indirect
47+
github.com/moby/sys/mount v0.3.3 // indirect
48+
github.com/moby/sys/mountinfo v0.6.2 // indirect
49+
github.com/moby/term v0.0.0-20210619224110-3f7ff695adc6 // indirect
4750
github.com/morikuni/aec v1.0.0 // indirect
48-
github.com/opencontainers/go-digest v1.0.0-rc1 // indirect
49-
github.com/opencontainers/image-spec v1.0.1 // indirect
50-
github.com/opencontainers/runc v0.1.1 // indirect
51+
github.com/opencontainers/go-digest v1.0.0 // indirect
52+
github.com/opencontainers/image-spec v1.0.3-0.20211202183452-c5a74bcca799 // indirect
53+
github.com/opencontainers/runc v1.1.2 // indirect
5154
github.com/pavel-v-chernykh/keystore-go v2.1.0+incompatible // indirect
5255
github.com/pmezard/go-difflib v1.0.0 // indirect
53-
github.com/sirupsen/logrus v1.4.1 // indirect
54-
golang.org/x/sync v0.0.0-20200625203802-6e8e738ad208 // indirect
55-
golang.org/x/sys v0.0.0-20200625212154-ddb9806d33ae // indirect
56-
google.golang.org/genproto v0.0.0-20190819201941-24fa4b261c55 // indirect
57-
google.golang.org/grpc v1.27.1 // indirect
58-
gopkg.in/yaml.v2 v2.2.2 // indirect
56+
github.com/sirupsen/logrus v1.8.1 // indirect
57+
go.opencensus.io v0.23.0 // indirect
58+
golang.org/x/sync v0.0.0-20210220032951-036812b2e83c // indirect
59+
golang.org/x/sys v0.0.0-20220520151302-bc2c85ada10a // indirect
60+
golang.org/x/term v0.0.0-20220526004731-065cf7ba2467 // indirect
61+
google.golang.org/genproto v0.0.0-20211208223120-3a66f561d7aa // indirect
62+
google.golang.org/grpc v1.43.0 // indirect
63+
gopkg.in/yaml.v2 v2.4.0 // indirect
64+
gopkg.in/yaml.v3 v3.0.1 // indirect
5965
)

0 commit comments

Comments
 (0)