Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update dependencies #696

Merged
merged 2 commits into from
Jul 13, 2022
Merged

Update dependencies #696

merged 2 commits into from
Jul 13, 2022

Conversation

pjbgf
Copy link
Member

@pjbgf pjbgf commented Jul 13, 2022

This addresses GHSA-r48q-9g5r-8q2h, due to v2.16.0 including emicklei/go-restful@9266625.

Dependencies

  • github.com/aws/aws-sdk-go to version 1.44.53.
  • github.com/aws/aws-sdk-go-v2 to version 1.16.7.
  • github.com/aws/aws-sdk-go-v2/config to version 1.15.14.
  • github.com/aws/aws-sdk-go-v2/credentials to version 1.12.9.
  • github.com/aws/aws-sdk-go-v2/service/kms to version 1.17.5.
  • github.com/aws/aws-sdk-go-v2/service/sts to version 1.16.9.
  • golang.org/x/net to version 0.0.0-20220708220712-1185a9018129.
  • google.golang.org/api to version 0.87.0.
  • google.golang.org/genproto to version 0.0.0-20220712132514-bdd2acd4974d.
  • google.golang.org/grpc to version 1.48.0.

Paulo Gomes added 2 commits July 13, 2022 13:13
This addresses CVE-2022-1996, due to v2.16.0 including
emicklei/go-restful@9266625.

Signed-off-by: Paulo Gomes <paulo.gomes@weave.works>
- github.com/aws/aws-sdk-go to version 1.44.53.
- github.com/aws/aws-sdk-go-v2 to version 1.16.7.
- github.com/aws/aws-sdk-go-v2/config to version 1.15.14.
- github.com/aws/aws-sdk-go-v2/credentials to version 1.12.9.
- github.com/aws/aws-sdk-go-v2/service/kms to version 1.17.5.
- github.com/aws/aws-sdk-go-v2/service/sts to version 1.16.9.
- golang.org/x/net to version 0.0.0-20220708220712-1185a9018129.
- google.golang.org/api to version 0.87.0.
- google.golang.org/genproto to version 0.0.0-20220712132514-bdd2acd4974d.
- google.golang.org/grpc to version 1.48.0.

Signed-off-by: Paulo Gomes <paulo.gomes@weave.works>
@pjbgf pjbgf merged commit fa4facb into fluxcd:main Jul 13, 2022
@pjbgf pjbgf deleted the update-deps branch July 13, 2022 12:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants