Skip to content

Commit 6558617

Browse files
committed
Update vulnerable hashicorp/vault and go-jose
1 parent 357217b commit 6558617

File tree

2 files changed

+53
-49
lines changed

2 files changed

+53
-49
lines changed

go.mod

Lines changed: 17 additions & 18 deletions
Original file line numberDiff line numberDiff line change
@@ -34,11 +34,11 @@ require (
3434
github.com/sirupsen/logrus v1.9.3
3535
github.com/spf13/cobra v1.6.1
3636
github.com/spf13/pflag v1.0.5
37-
github.com/stretchr/testify v1.8.4
37+
github.com/stretchr/testify v1.9.0
3838
github.com/tidwall/gjson v1.14.3
3939
github.com/zclconf/go-cty v1.12.1
40-
golang.org/x/crypto v0.23.0
41-
golang.org/x/mod v0.12.0
40+
golang.org/x/crypto v0.28.0
41+
golang.org/x/mod v0.17.0
4242
gopkg.in/go-playground/assert.v1 v1.2.1
4343
gopkg.in/yaml.v2 v2.4.0
4444
gopkg.in/yaml.v3 v3.0.1
@@ -47,7 +47,7 @@ require (
4747
require (
4848
github.com/aws/aws-sdk-go-v2/service/eks v1.22.1
4949
github.com/hashicorp/terraform-config-inspect v0.0.0-20210625153042-09f34846faab
50-
golang.org/x/sys v0.20.0 // indirect
50+
golang.org/x/sys v0.26.0 // indirect
5151
)
5252

5353
require (
@@ -64,7 +64,7 @@ require (
6464
github.com/aws/aws-sdk-go-v2/service/sts v1.17.5 // indirect
6565
github.com/aws/smithy-go v1.13.5 // indirect
6666
github.com/davecgh/go-spew v1.1.1 // indirect
67-
github.com/hashicorp/hcl v1.0.1-vault // indirect
67+
github.com/hashicorp/hcl v1.0.1-vault-6 // indirect
6868
github.com/hashicorp/hcl/v2 v2.15.0
6969
github.com/imdario/mergo v0.3.13
7070
github.com/inconshreveable/mousetrap v1.1.0 // indirect
@@ -78,16 +78,16 @@ require (
7878
github.com/slack-go/slack v0.11.3
7979
github.com/tidwall/match v1.1.1 // indirect
8080
github.com/tidwall/pretty v1.2.1 // indirect
81-
golang.org/x/text v0.15.0
82-
golang.org/x/tools v0.13.0 // indirect
81+
golang.org/x/text v0.19.0
82+
golang.org/x/tools v0.21.1-0.20240508182429-e35e4ccd0d2d // indirect
8383
golang.org/x/xerrors v0.0.0-20220907171357-04be3eba64a2 // indirect
8484
)
8585

8686
require (
8787
github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream v1.4.10 // indirect
8888
github.com/aws/aws-sdk-go-v2/internal/endpoints/v2 v2.4.20 // indirect
8989
github.com/gorilla/websocket v1.4.2 // indirect
90-
golang.org/x/sync v0.7.0
90+
golang.org/x/sync v0.8.0
9191
)
9292

9393
require (
@@ -136,6 +136,7 @@ require (
136136
github.com/aws/aws-sdk-go-v2/service/internal/checksum v1.1.21 // indirect
137137
github.com/aws/aws-sdk-go-v2/service/ssooidc v1.13.8 // indirect
138138
github.com/blang/semver v3.5.1+incompatible // indirect
139+
github.com/cenkalti/backoff/v4 v4.3.0 // indirect
139140
github.com/cloudflare/circl v1.3.3 // indirect
140141
github.com/containerd/console v1.0.3 // indirect
141142
github.com/containerd/continuity v0.4.2 // indirect
@@ -145,18 +146,17 @@ require (
145146
github.com/dimchansky/utfbom v1.1.1 // indirect
146147
github.com/docker/go-units v0.5.0 // indirect
147148
github.com/emirpasic/gods v1.18.1 // indirect
148-
github.com/frankban/quicktest v1.14.5 // indirect
149149
github.com/gabriel-vasile/mimetype v1.4.3 // indirect
150150
github.com/go-errors/errors v1.0.2-0.20180813162953-d98b870cc4e0 // indirect
151151
github.com/go-git/gcfg v1.5.1-0.20230307220236-3a3c6141e376 // indirect
152+
github.com/go-jose/go-jose/v4 v4.0.4 // indirect
152153
github.com/go-openapi/errors v0.21.0 // indirect
153154
github.com/go-openapi/strfmt v0.22.1 // indirect
154155
github.com/go-playground/locales v0.14.1 // indirect
155156
github.com/go-playground/universal-translator v0.18.1 // indirect
156157
github.com/go-playground/validator/v10 v10.19.0 // indirect
157158
github.com/golang-jwt/jwt/v4 v4.5.0 // indirect
158159
github.com/golang/groupcache v0.0.0-20210331224755-41bb18bfe9da // indirect
159-
github.com/golang/snappy v0.0.4 // indirect
160160
github.com/google/s2a-go v0.1.7 // indirect
161161
github.com/google/shlex v0.0.0-20181106134648-c34317bd91bf // indirect
162162
github.com/googleapis/enterprise-certificate-proxy v0.3.2 // indirect
@@ -166,10 +166,11 @@ require (
166166
github.com/hashicorp/go-multierror v1.1.1 // indirect
167167
github.com/hashicorp/go-retryablehttp v0.7.7 // indirect
168168
github.com/hashicorp/go-rootcerts v1.0.2 // indirect
169-
github.com/hashicorp/go-sockaddr v1.0.2 // indirect
169+
github.com/hashicorp/go-secure-stdlib/parseutil v0.1.8 // indirect
170+
github.com/hashicorp/go-secure-stdlib/strutil v0.1.2 // indirect
171+
github.com/hashicorp/go-sockaddr v1.0.7 // indirect
170172
github.com/hashicorp/terraform v0.15.3 // indirect
171-
github.com/hashicorp/vault/api v1.0.5-0.20210210214158-405eced08457 // indirect
172-
github.com/hashicorp/vault/sdk v0.1.14-0.20210322210658-b52b8b8c1264 // indirect
173+
github.com/hashicorp/vault/api v1.15.0 // indirect
173174
github.com/howeyc/gopass v0.0.0-20170109162249-bf9dde6d0d2c // indirect
174175
github.com/jbenet/go-context v0.0.0-20150711004518-d14ea06fba99 // indirect
175176
github.com/kevinburke/ssh_config v1.2.0 // indirect
@@ -182,7 +183,6 @@ require (
182183
github.com/oklog/ulid v1.3.1 // indirect
183184
github.com/opencontainers/image-spec v1.1.0 // indirect
184185
github.com/opencontainers/runc v1.1.5 // indirect
185-
github.com/pierrec/lz4 v2.5.2+incompatible // indirect
186186
github.com/pjbgf/sha1cd v0.3.0 // indirect
187187
github.com/prometheus/client_golang v1.14.0 // indirect
188188
github.com/rivo/uniseg v0.4.2 // indirect
@@ -198,12 +198,11 @@ require (
198198
go.mongodb.org/mongo-driver v1.14.0 // indirect
199199
go.mozilla.org/gopgagent v0.0.0-20170926210634-4d7ea76ff71a // indirect
200200
go.mozilla.org/sops/v3 v3.7.2 // indirect
201-
golang.org/x/term v0.20.0 // indirect
202-
golang.org/x/time v0.0.0-20220210224613-90d013bbcef8 // indirect
201+
golang.org/x/term v0.25.0 // indirect
202+
golang.org/x/time v0.7.0 // indirect
203203
google.golang.org/genproto/googleapis/api v0.0.0-20240528184218-531527333157 // indirect
204204
google.golang.org/genproto/googleapis/rpc v0.0.0-20240528184218-531527333157 // indirect
205205
gopkg.in/ini.v1 v1.44.0 // indirect
206-
gopkg.in/square/go-jose.v2 v2.5.1 // indirect
207206
gopkg.in/urfave/cli.v1 v1.20.0 // indirect
208207
gopkg.in/warnings.v0 v0.1.2 // indirect
209208
)
@@ -239,7 +238,7 @@ require (
239238
github.com/yashtewari/glob-intersection v0.1.0 // indirect
240239
github.com/zclconf/go-cty-yaml v1.0.3
241240
go.opencensus.io v0.24.0 // indirect
242-
golang.org/x/net v0.25.0 // indirect
241+
golang.org/x/net v0.30.0 // indirect
243242
google.golang.org/api v0.149.0 // indirect
244243
google.golang.org/genproto v0.0.0-20231211222908-989df2bf70f3 // indirect
245244
google.golang.org/grpc v1.65.0 // indirect

0 commit comments

Comments
 (0)