Skip to content

Commit 639c188

Browse files
authored
fix: go-git security issue GHSA-mw99-9chc-xw7r (#1844)
Signed-off-by: Keming <[email protected]>
1 parent 457f5fd commit 639c188

File tree

2 files changed

+77
-11
lines changed

2 files changed

+77
-11
lines changed

go.mod

Lines changed: 15 additions & 11 deletions
Original file line numberDiff line numberDiff line change
@@ -18,7 +18,7 @@ require (
1818
github.com/docker/go-units v0.5.0
1919
github.com/gizak/termui/v3 v3.1.0
2020
github.com/gliderlabs/ssh v0.3.5
21-
github.com/go-git/go-git/v5 v5.4.2
21+
github.com/go-git/go-git/v5 v5.11.0
2222
github.com/golang/mock v1.6.0
2323
github.com/google/uuid v1.3.1
2424
github.com/hashicorp/go-getter v1.7.3
@@ -56,17 +56,19 @@ require (
5656
cloud.google.com/go/compute/metadata v0.2.3 // indirect
5757
cloud.google.com/go/iam v0.13.0 // indirect
5858
cloud.google.com/go/storage v1.28.1 // indirect
59+
dario.cat/mergo v1.0.0 // indirect
5960
github.com/AdaLogics/go-fuzz-headers v0.0.0-20230106234847-43070de90fa1 // indirect
6061
github.com/Azure/go-ansiterm v0.0.0-20210617225240-d185dfc1b5a1 // indirect
6162
github.com/BurntSushi/toml v1.3.2 // indirect
6263
github.com/Microsoft/go-winio v0.6.1 // indirect
63-
github.com/ProtonMail/go-crypto v0.0.0-20210428141323-04723f9f07d7 // indirect
64+
github.com/ProtonMail/go-crypto v0.0.0-20230828082145-3c4c8a2d2371 // indirect
6465
github.com/acomagu/bufpipe v1.0.3 // indirect
6566
github.com/anmitsu/go-shlex v0.0.0-20200514113438-38f4b401e2be // indirect
6667
github.com/aws/aws-sdk-go v1.44.122 // indirect
6768
github.com/aymanbagabas/go-osc52/v2 v2.0.1 // indirect
6869
github.com/bgentry/go-netrc v0.0.0-20140422174119-9fd32a8b3d3d // indirect
6970
github.com/bmizerany/assert v0.0.0-20160611221934-b7ed37b82869 // indirect
71+
github.com/cloudflare/circl v1.3.3 // indirect
7072
github.com/cockroachdb/logtags v0.0.0-20230118201751-21c54148d20b // indirect
7173
github.com/cockroachdb/redact v1.1.5 // indirect
7274
github.com/containerd/continuity v0.4.1 // indirect
@@ -81,11 +83,11 @@ require (
8183
github.com/davecgh/go-spew v1.1.1 // indirect
8284
github.com/docker/distribution v2.8.2+incompatible // indirect
8385
github.com/docker/docker-credential-helpers v0.7.0 // indirect
84-
github.com/emirpasic/gods v1.12.0 // indirect
86+
github.com/emirpasic/gods v1.18.1 // indirect
8587
github.com/fsnotify/fsnotify v1.6.0 // indirect
8688
github.com/getsentry/sentry-go v0.18.0 // indirect
87-
github.com/go-git/gcfg v1.5.0 // indirect
88-
github.com/go-git/go-billy/v5 v5.3.1 // indirect
89+
github.com/go-git/gcfg v1.5.1-0.20230307220236-3a3c6141e376 // indirect
90+
github.com/go-git/go-billy/v5 v5.5.0 // indirect
8991
github.com/go-logr/logr v1.2.4 // indirect
9092
github.com/go-logr/stdr v1.2.2 // indirect
9193
github.com/go-ole/go-ole v1.2.6 // indirect
@@ -96,7 +98,7 @@ require (
9698
github.com/golang/groupcache v0.0.0-20210331224755-41bb18bfe9da // indirect
9799
github.com/golang/protobuf v1.5.3 // indirect
98100
github.com/golang/snappy v0.0.4 // indirect
99-
github.com/google/go-cmp v0.5.9 // indirect
101+
github.com/google/go-cmp v0.6.0 // indirect
100102
github.com/google/pprof v0.0.0-20230705174524-200ffdc848b8 // indirect
101103
github.com/google/s2a-go v0.1.3 // indirect
102104
github.com/google/shlex v0.0.0-20191202100458-e7afc7fbc510 // indirect
@@ -117,7 +119,7 @@ require (
117119
github.com/jbenet/go-context v0.0.0-20150711004518-d14ea06fba99 // indirect
118120
github.com/jmespath/go-jmespath v0.4.0 // indirect
119121
github.com/json-iterator/go v1.1.12 // indirect
120-
github.com/kevinburke/ssh_config v0.0.0-20201106050909-4977a11b4351 // indirect
122+
github.com/kevinburke/ssh_config v1.2.0 // indirect
121123
github.com/klauspost/compress v1.16.3 // indirect
122124
github.com/klauspost/cpuid/v2 v2.2.5 // indirect
123125
github.com/klauspost/pgzip v1.2.6-0.20220930104621-17e8dac29df8 // indirect
@@ -152,15 +154,17 @@ require (
152154
github.com/pelletier/go-toml/v2 v2.0.8 // indirect
153155
github.com/petermattis/goid v0.0.0-20230518223814-80aa455d8761 // indirect
154156
github.com/pierrec/lz4/v4 v4.1.18 // indirect
157+
github.com/pjbgf/sha1cd v0.3.0 // indirect
155158
github.com/pmezard/go-difflib v1.0.0 // indirect
156159
github.com/power-devops/perfstat v0.0.0-20221212215047-62379fc7944b // indirect
157160
github.com/rivo/uniseg v0.4.4 // indirect
158-
github.com/rogpeppe/go-internal v1.9.0 // indirect
161+
github.com/rogpeppe/go-internal v1.11.0 // indirect
159162
github.com/russross/blackfriday/v2 v2.1.0 // indirect
160163
github.com/sasha-s/go-deadlock v0.3.1 // indirect
161164
github.com/segmentio/backo-go v1.0.0 // indirect
162165
github.com/sergi/go-diff v1.1.0 // indirect
163166
github.com/shirou/gopsutil/v3 v3.23.6 // indirect
167+
github.com/skeema/knownhosts v1.2.1 // indirect
164168
github.com/spf13/afero v1.9.5 // indirect
165169
github.com/spf13/cast v1.5.1 // indirect
166170
github.com/spf13/jwalterweatherman v1.1.0 // indirect
@@ -173,7 +177,7 @@ require (
173177
github.com/tonistiigi/fsutil v0.0.0-20230105215944-fb433841cbfa // indirect
174178
github.com/ulikunitz/xz v0.5.11 // indirect
175179
github.com/vbatts/tar-split v0.11.3 // indirect
176-
github.com/xanzy/ssh-agent v0.3.0 // indirect
180+
github.com/xanzy/ssh-agent v0.3.3 // indirect
177181
github.com/xrash/smetrics v0.0.0-20201216005158-039620a65673 // indirect
178182
github.com/yusufpapurcu/wmi v1.2.3 // indirect
179183
go.opencensus.io v0.24.0 // indirect
@@ -186,11 +190,11 @@ require (
186190
go.opentelemetry.io/proto/otlp v0.19.0 // indirect
187191
golang.org/x/exp v0.0.0-20230711023510-fffb14384f22 // indirect
188192
golang.org/x/mod v0.12.0 // indirect
189-
golang.org/x/net v0.17.0 // indirect
193+
golang.org/x/net v0.19.0 // indirect
190194
golang.org/x/oauth2 v0.7.0 // indirect
191195
golang.org/x/sys v0.15.0 // indirect
192196
golang.org/x/text v0.14.0 // indirect
193-
golang.org/x/tools v0.12.0 // indirect
197+
golang.org/x/tools v0.13.0 // indirect
194198
golang.org/x/xerrors v0.0.0-20220907171357-04be3eba64a2 // indirect
195199
google.golang.org/api v0.122.0 // indirect
196200
google.golang.org/appengine v1.6.7 // indirect

0 commit comments

Comments
 (0)