Skip to content

Commit

Permalink
Merge pull request #1075 from weaveworks/sec-update-grpc
Browse files Browse the repository at this point in the history
chore(deps): Update google.golang.org/grpc and golang.org/x/net
  • Loading branch information
yitsushi authored Oct 31, 2023
2 parents 7c9d9d7 + 17087f8 commit 63102b3
Show file tree
Hide file tree
Showing 2 changed files with 65 additions and 648 deletions.
29 changes: 9 additions & 20 deletions go.mod
Original file line number Diff line number Diff line change
Expand Up @@ -15,7 +15,6 @@ require (
github.com/aws/aws-sdk-go-v2/service/s3 v1.38.5
github.com/cyphar/filepath-securejoin v0.2.4
github.com/elgohr/go-localstack v1.0.20
github.com/fluxcd/flux2/v2 v2.1.1
github.com/fluxcd/pkg/apis/event v0.5.2
github.com/fluxcd/pkg/apis/meta v1.1.2
github.com/fluxcd/pkg/runtime v0.42.0
Expand All @@ -41,8 +40,8 @@ require (
github.com/weaveworks/tf-controller/api v0.0.0-00010101000000-000000000000
github.com/weaveworks/tf-controller/tfctl v0.0.0-00010101000000-000000000000
github.com/zclconf/go-cty v1.13.2
golang.org/x/net v0.15.0
google.golang.org/grpc v1.55.0
golang.org/x/net v0.17.0
google.golang.org/grpc v1.56.3
google.golang.org/protobuf v1.31.0
gopkg.in/yaml.v2 v2.4.0
k8s.io/api v0.28.0
Expand Down Expand Up @@ -95,20 +94,12 @@ require (
github.com/evanphx/json-patch/v5 v5.6.0 // indirect
github.com/exponent-io/jsonpath v0.0.0-20210407135951-1de76d718b3f // indirect
github.com/fatih/color v1.13.0 // indirect
github.com/fluxcd/helm-controller/api v0.36.1 // indirect
github.com/fluxcd/image-automation-controller/api v0.36.1 // indirect
github.com/fluxcd/image-reflector-controller/api v0.30.0 // indirect
github.com/fluxcd/kustomize-controller/api v1.1.0 // indirect
github.com/fluxcd/notification-controller/api v1.1.0 // indirect
github.com/fluxcd/pkg/apis/acl v0.1.0 // indirect
github.com/fluxcd/pkg/apis/kustomize v1.1.1 // indirect
github.com/fluxcd/pkg/kustomize v1.3.4 // indirect
github.com/fluxcd/pkg/oci v0.31.0 // indirect
github.com/fluxcd/pkg/ssa v0.32.0 // indirect
github.com/fluxcd/pkg/tar v0.2.0 // indirect
github.com/fluxcd/pkg/version v0.2.2 // indirect
github.com/fsnotify/fsnotify v1.6.0 // indirect
github.com/go-errors/errors v1.4.2 // indirect
github.com/go-git/go-git/v5 v5.9.0 // indirect
github.com/go-logr/zapr v1.2.4 // indirect
github.com/go-openapi/jsonpointer v0.19.6 // indirect
github.com/go-openapi/jsonreference v0.20.2 // indirect
Expand All @@ -119,11 +110,11 @@ require (
github.com/google/btree v1.1.2 // indirect
github.com/google/gnostic v0.6.9 // indirect
github.com/google/go-cmp v0.5.9 // indirect
github.com/google/go-containerregistry v0.16.1 // indirect
github.com/google/gofuzz v1.2.0 // indirect
github.com/google/shlex v0.0.0-20191202100458-e7afc7fbc510 // indirect
github.com/gregjones/httpcache v0.0.0-20190611155906-901d90724c79 // indirect
github.com/hako/durafmt v0.0.0-20210608085754-5c1018a4e16b // indirect
github.com/hashicorp/errwrap v1.1.0 // indirect
github.com/hashicorp/go-version v1.6.0 // indirect
github.com/hashicorp/hcl v1.0.0 // indirect
github.com/huandu/xstrings v1.3.3 // indirect
Expand Down Expand Up @@ -162,6 +153,7 @@ require (
github.com/prometheus/procfs v0.10.1 // indirect
github.com/rivo/uniseg v0.2.0 // indirect
github.com/russross/blackfriday/v2 v2.1.0 // indirect
github.com/sergi/go-diff v1.3.1 // indirect
github.com/shopspring/decimal v1.2.0 // indirect
github.com/shurcooL/githubv4 v0.0.0-20190718010115-4ba037080260 // indirect
github.com/shurcooL/graphql v0.0.0-20181231061246-d48a9a75455f // indirect
Expand All @@ -175,18 +167,18 @@ require (
go.starlark.net v0.0.0-20230525235612-a134d8f9ddca // indirect
go.uber.org/multierr v1.11.0 // indirect
go.uber.org/zap v1.25.0 // indirect
golang.org/x/crypto v0.13.0 // indirect
golang.org/x/crypto v0.14.0 // indirect
golang.org/x/mod v0.12.0 // indirect
golang.org/x/oauth2 v0.9.0 // indirect
golang.org/x/sync v0.3.0 // indirect
golang.org/x/sys v0.12.0 // indirect
golang.org/x/term v0.12.0 // indirect
golang.org/x/sys v0.13.0 // indirect
golang.org/x/term v0.13.0 // indirect
golang.org/x/text v0.13.0 // indirect
golang.org/x/time v0.3.0 // indirect
golang.org/x/tools v0.13.0 // indirect
gomodules.xyz/jsonpatch/v2 v2.4.0 // indirect
google.golang.org/appengine v1.6.7 // indirect
google.golang.org/genproto/googleapis/rpc v0.0.0-20230525234030-28d5490b6b19 // indirect
google.golang.org/genproto/googleapis/rpc v0.0.0-20231016165738-49dd2c1f3d0b // indirect
gopkg.in/inf.v0 v0.9.1 // indirect
gopkg.in/ini.v1 v1.67.0 // indirect
gopkg.in/yaml.v3 v3.0.1 // indirect
Expand All @@ -204,9 +196,6 @@ replace (
// v0.15.1-0.20220809152546-4850a69faedb is actually the v0.16.1a tag of the fork
github.com/hashicorp/terraform-exec v0.16.1 => github.com/tf-controller/terraform-exec v0.15.1-0.20220809152546-4850a69faedb

// Fix CVE-2023-32731
google.golang.org/grpc => google.golang.org/grpc v1.53.0

k8s.io/api => k8s.io/api v0.27.4
k8s.io/apimachinery => k8s.io/apimachinery v0.27.4
k8s.io/client-go => k8s.io/client-go v0.27.4
Expand Down
Loading

0 comments on commit 63102b3

Please sign in to comment.