Skip to content

Commit 567d33f

Browse files
authored
Merge pull request #2004 from authzed/docker-cve-2
bump Docker to address security scanners surfacing CVE
2 parents a26c026 + 85aef7a commit 567d33f

File tree

10 files changed

+236
-223
lines changed

10 files changed

+236
-223
lines changed

go.mod

+3-2
Original file line numberDiff line numberDiff line change
@@ -113,6 +113,7 @@ require (
113113
github.com/Yiling-J/theine-go v0.3.2
114114
github.com/gosimple/slug v1.14.0
115115
github.com/lithammer/fuzzysearch v1.1.8
116+
github.com/maypok86/otter v1.2.1
116117
)
117118

118119
require (
@@ -147,7 +148,7 @@ require (
147148
github.com/jjti/go-spancheck v0.6.1 // indirect
148149
github.com/klauspost/cpuid/v2 v2.0.9 // indirect
149150
github.com/lasiar/canonicalheader v1.1.1 // indirect
150-
github.com/maypok86/otter v1.2.1 // indirect
151+
github.com/moby/docker-image-spec v1.3.1 // indirect
151152
github.com/opencontainers/runtime-spec v1.0.3-0.20210326190908-1c3f411f0417 // indirect
152153
github.com/quasilyte/go-ruleguard/dsl v0.3.22 // indirect
153154
github.com/samber/slog-common v0.17.0 // indirect
@@ -208,7 +209,7 @@ require (
208209
github.com/davecgh/go-spew v1.1.2-0.20180830191138-d8f796af33cc // indirect
209210
github.com/denis-tingaikin/go-header v0.5.0 // indirect
210211
github.com/docker/cli v25.0.2+incompatible // indirect
211-
github.com/docker/docker v25.0.5+incompatible // indirect
212+
github.com/docker/docker v27.1.1+incompatible // indirect
212213
github.com/docker/go-connections v0.5.0 // indirect
213214
github.com/docker/go-units v0.5.0 // indirect
214215
github.com/emicklei/go-restful/v3 v3.11.0 // indirect

go.sum

+4-2
Original file line numberDiff line numberDiff line change
@@ -845,8 +845,8 @@ github.com/dlmiddlecote/sqlstats v1.0.2 h1:gSU11YN23D/iY50A2zVYwgXgy072khatTsIW6
845845
github.com/dlmiddlecote/sqlstats v1.0.2/go.mod h1:0CWaIh/Th+z2aI6Q9Jpfg/o21zmGxWhbByHgQSCUQvY=
846846
github.com/docker/cli v25.0.2+incompatible h1:6GEdvxwEA451/+Y3GtqIGn/MNjujQazUlxC6uGu8Tog=
847847
github.com/docker/cli v25.0.2+incompatible/go.mod h1:JLrzqnKDaYBop7H2jaqPtU4hHvMKP+vjCwu2uszcLI8=
848-
github.com/docker/docker v25.0.5+incompatible h1:UmQydMduGkrD5nQde1mecF/YnSbTOaPeFIeP5C4W+DE=
849-
github.com/docker/docker v25.0.5+incompatible/go.mod h1:eEKB0N0r5NX/I1kEveEz05bcu8tLC/8azJZsviup8Sk=
848+
github.com/docker/docker v27.1.1+incompatible h1:hO/M4MtV36kzKldqnA37IWhebRA+LnqqcqDja6kVaKY=
849+
github.com/docker/docker v27.1.1+incompatible/go.mod h1:eEKB0N0r5NX/I1kEveEz05bcu8tLC/8azJZsviup8Sk=
850850
github.com/docker/go-connections v0.5.0 h1:USnMq7hx7gwdVZq1L49hLXaFtUdTADjXGp+uj1Br63c=
851851
github.com/docker/go-connections v0.5.0/go.mod h1:ov60Kzw0kKElRwhNs9UlUHAE/F9Fe6GLaXnqyDdmEXc=
852852
github.com/docker/go-units v0.5.0 h1:69rxXcBk27SvSaaxTtLh/8llcHD8vYHT7WSdRZ/jvr4=
@@ -1351,6 +1351,8 @@ github.com/mitchellh/go-homedir v1.1.0 h1:lukF9ziXFxDFPkA1vsr5zpc1XuPDn/wFntq5mG
13511351
github.com/mitchellh/go-homedir v1.1.0/go.mod h1:SfyaCUpYCn1Vlf4IUYiD9fPX4A5wJrkLzIz1N1q0pr0=
13521352
github.com/mitchellh/mapstructure v1.5.0 h1:jeMsZIYE/09sWLaz43PL7Gy6RuMjD2eJVyuac5Z2hdY=
13531353
github.com/mitchellh/mapstructure v1.5.0/go.mod h1:bFUtVrKA4DC2yAKiSyO/QUcy7e+RRV2QTWOzhPopBRo=
1354+
github.com/moby/docker-image-spec v1.3.1 h1:jMKff3w6PgbfSa69GfNg+zN/XLhfXJGnEx3Nl2EsFP0=
1355+
github.com/moby/docker-image-spec v1.3.1/go.mod h1:eKmb5VW8vQEh/BAr2yvVNvuiJuY6UIocYsFu/DxxRpo=
13541356
github.com/moby/term v0.5.0 h1:xt8Q1nalod/v7BqbG21f8mQPqH+xAaC9C3N3wfWbVP0=
13551357
github.com/moby/term v0.5.0/go.mod h1:8FzsFHVUBGZdbDsJw/ot+X+d5HLUbvklYLJ9uGfcI3Y=
13561358
github.com/modern-go/concurrent v0.0.0-20180228061459-e0a39a4cb421/go.mod h1:6dJC0mAP4ikYIbvyc7fijjWJddQyLn8Ig3JB5CqoB9Q=

magefiles/go.mod

+35-32
Original file line numberDiff line numberDiff line change
@@ -4,67 +4,71 @@ go 1.22.4
44

55
require (
66
github.com/agnivade/wasmbrowsertest v0.8.0
7-
github.com/bufbuild/buf v1.30.0
7+
github.com/bufbuild/buf v1.35.1
88
github.com/ecordell/optgen v0.0.9
99
github.com/envoyproxy/protoc-gen-validate v1.0.4
1010
github.com/magefile/mage v1.15.0
1111
github.com/planetscale/vtprotobuf v0.5.1-0.20231212170721-e7d721933795
12-
golang.org/x/tools v0.19.0
12+
golang.org/x/tools v0.22.0
1313
google.golang.org/grpc/cmd/protoc-gen-go-grpc v1.3.0
14-
google.golang.org/protobuf v1.33.0
14+
google.golang.org/protobuf v1.34.2
1515
mvdan.cc/gofumpt v0.6.0
1616
)
1717

1818
require (
19-
buf.build/gen/go/bufbuild/protovalidate/protocolbuffers/go v1.33.0-20240221180331-f05a6f4403ce.1 // indirect
20-
connectrpc.com/connect v1.15.0 // indirect
19+
buf.build/gen/go/bufbuild/protovalidate/protocolbuffers/go v1.34.2-20240508200655-46a4cf4ba109.2 // indirect
20+
buf.build/gen/go/bufbuild/registry/connectrpc/go v1.16.2-20240610164129-660609bc46d3.1 // indirect
21+
buf.build/gen/go/bufbuild/registry/protocolbuffers/go v1.34.2-20240610164129-660609bc46d3.2 // indirect
22+
connectrpc.com/connect v1.16.2 // indirect
2123
connectrpc.com/otelconnect v0.7.0 // indirect
2224
github.com/Azure/go-ansiterm v0.0.0-20230124172434-306776ec8161 // indirect
2325
github.com/Microsoft/go-winio v0.6.1 // indirect
2426
github.com/antlr4-go/antlr/v4 v4.13.0 // indirect
25-
github.com/bufbuild/protocompile v0.9.0 // indirect
26-
github.com/bufbuild/protovalidate-go v0.6.0 // indirect
27-
github.com/bufbuild/protoyaml-go v0.1.8 // indirect
28-
github.com/cenkalti/backoff/v4 v4.2.1 // indirect
27+
github.com/bufbuild/protocompile v0.14.0 // indirect
28+
github.com/bufbuild/protoplugin v0.0.0-20240323223605-e2735f6c31ee // indirect
29+
github.com/bufbuild/protovalidate-go v0.6.2 // indirect
30+
github.com/bufbuild/protoyaml-go v0.1.9 // indirect
2931
github.com/chromedp/cdproto v0.0.0-20230802225258-3cf4e6d46a89 // indirect
3032
github.com/chromedp/chromedp v0.9.2 // indirect
3133
github.com/chromedp/sysutil v1.0.0 // indirect
3234
github.com/containerd/stargz-snapshotter/estargz v0.15.1 // indirect
33-
github.com/cpuguy83/go-md2man/v2 v2.0.3 // indirect
35+
github.com/cpuguy83/go-md2man/v2 v2.0.4 // indirect
3436
github.com/creasty/defaults v1.7.0 // indirect
3537
github.com/dave/jennifer v1.6.1 // indirect
36-
github.com/distribution/reference v0.5.0 // indirect
37-
github.com/docker/cli v25.0.4+incompatible // indirect
38+
github.com/distribution/reference v0.6.0 // indirect
39+
github.com/docker/cli v26.1.4+incompatible // indirect
3840
github.com/docker/distribution v2.8.3+incompatible // indirect
39-
github.com/docker/docker v25.0.5+incompatible // indirect
40-
github.com/docker/docker-credential-helpers v0.8.1 // indirect
41+
github.com/docker/docker v27.1.1+incompatible // indirect
42+
github.com/docker/docker-credential-helpers v0.8.2 // indirect
4143
github.com/docker/go-connections v0.5.0 // indirect
4244
github.com/docker/go-units v0.5.0 // indirect
4345
github.com/fatih/structtag v1.2.0 // indirect
4446
github.com/felixge/fgprof v0.9.4 // indirect
4547
github.com/felixge/httpsnoop v1.0.4 // indirect
46-
github.com/go-chi/chi/v5 v5.0.12 // indirect
48+
github.com/go-chi/chi/v5 v5.0.14 // indirect
4749
github.com/go-interpreter/wagon v0.6.0 // indirect
48-
github.com/go-logr/logr v1.4.1 // indirect
50+
github.com/go-logr/logr v1.4.2 // indirect
4951
github.com/go-logr/stdr v1.2.2 // indirect
5052
github.com/gobwas/httphead v0.1.0 // indirect
5153
github.com/gobwas/pool v0.2.1 // indirect
5254
github.com/gobwas/ws v1.2.1 // indirect
53-
github.com/gofrs/uuid/v5 v5.0.0 // indirect
55+
github.com/gofrs/uuid/v5 v5.2.0 // indirect
5456
github.com/gogo/protobuf v1.3.2 // indirect
5557
github.com/google/cel-go v0.20.1 // indirect
5658
github.com/google/go-cmp v0.6.0 // indirect
57-
github.com/google/go-containerregistry v0.19.0 // indirect
58-
github.com/google/pprof v0.0.0-20240227163752-401108e1b7e7 // indirect
59+
github.com/google/go-containerregistry v0.19.2 // indirect
60+
github.com/google/pprof v0.0.0-20240622144329-c177fd99eaa9 // indirect
61+
github.com/grpc-ecosystem/grpc-gateway/v2 v2.20.0 // indirect
5962
github.com/iancoleman/strcase v0.3.0 // indirect
6063
github.com/inconshreveable/mousetrap v1.1.0 // indirect
6164
github.com/jdx/go-netrc v1.0.0 // indirect
6265
github.com/josharian/intern v1.0.0 // indirect
63-
github.com/klauspost/compress v1.17.7 // indirect
66+
github.com/klauspost/compress v1.17.9 // indirect
6467
github.com/klauspost/pgzip v1.2.6 // indirect
6568
github.com/lyft/protoc-gen-star/v2 v2.0.3 // indirect
6669
github.com/mailru/easyjson v0.7.7 // indirect
6770
github.com/mitchellh/go-homedir v1.1.0 // indirect
71+
github.com/moby/docker-image-spec v1.3.1 // indirect
6872
github.com/moby/term v0.5.0 // indirect
6973
github.com/morikuni/aec v1.0.0 // indirect
7074
github.com/opencontainers/go-digest v1.0.0 // indirect
@@ -76,7 +80,7 @@ require (
7680
github.com/russross/blackfriday/v2 v2.1.0 // indirect
7781
github.com/sirupsen/logrus v1.9.3 // indirect
7882
github.com/spf13/afero v1.10.0 // indirect
79-
github.com/spf13/cobra v1.8.0 // indirect
83+
github.com/spf13/cobra v1.8.1 // indirect
8084
github.com/spf13/pflag v1.0.5 // indirect
8185
github.com/stoewer/go-strcase v1.3.0 // indirect
8286
github.com/vbatts/tar-split v0.11.5 // indirect
@@ -86,19 +90,18 @@ require (
8690
go.opentelemetry.io/otel/metric v1.24.0 // indirect
8791
go.opentelemetry.io/otel/sdk v1.24.0 // indirect
8892
go.opentelemetry.io/otel/trace v1.24.0 // indirect
89-
go.opentelemetry.io/proto/otlp v1.1.0 // indirect
9093
go.uber.org/atomic v1.11.0 // indirect
9194
go.uber.org/multierr v1.11.0 // indirect
9295
go.uber.org/zap v1.27.0 // indirect
93-
golang.org/x/crypto v0.22.0 // indirect
94-
golang.org/x/exp v0.0.0-20240222234643-814bf88cf225 // indirect
95-
golang.org/x/mod v0.16.0 // indirect
96-
golang.org/x/net v0.24.0 // indirect
97-
golang.org/x/sync v0.6.0 // indirect
98-
golang.org/x/sys v0.19.0 // indirect
99-
golang.org/x/term v0.19.0 // indirect
100-
golang.org/x/text v0.14.0 // indirect
101-
google.golang.org/genproto/googleapis/api v0.0.0-20240304212257-790db918fca8 // indirect
102-
google.golang.org/genproto/googleapis/rpc v0.0.0-20240304212257-790db918fca8 // indirect
96+
golang.org/x/crypto v0.24.0 // indirect
97+
golang.org/x/exp v0.0.0-20240613232115-7f521ea00fb8 // indirect
98+
golang.org/x/mod v0.18.0 // indirect
99+
golang.org/x/net v0.26.0 // indirect
100+
golang.org/x/sync v0.7.0 // indirect
101+
golang.org/x/sys v0.21.0 // indirect
102+
golang.org/x/term v0.21.0 // indirect
103+
golang.org/x/text v0.16.0 // indirect
104+
google.golang.org/genproto/googleapis/api v0.0.0-20240617180043-68d350f18fd4 // indirect
105+
google.golang.org/genproto/googleapis/rpc v0.0.0-20240617180043-68d350f18fd4 // indirect
103106
gopkg.in/yaml.v3 v3.0.1 // indirect
104107
)

0 commit comments

Comments
 (0)