From b3b344a9d2b105aed8217d48a598f753cf0f297e Mon Sep 17 00:00:00 2001 From: "renovate[bot]" <29139614+renovate[bot]@users.noreply.github.com> Date: Tue, 5 Mar 2024 03:26:37 +0000 Subject: [PATCH 1/2] Update module github.com/golang-jwt/jwt/v5 to v5.2.1 --- go.mod | 2 +- go.sum | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/go.mod b/go.mod index 3a073dc7..2507b647 100644 --- a/go.mod +++ b/go.mod @@ -167,7 +167,7 @@ require ( replace ( github.com/aws/aws-sdk-go => github.com/aws/aws-sdk-go v1.50.30 github.com/containerd/containerd => github.com/containerd/containerd v1.7.13 - github.com/dgrijalva/jwt-go => github.com/golang-jwt/jwt/v5 v5.2.0 + github.com/dgrijalva/jwt-go => github.com/golang-jwt/jwt/v5 v5.2.1 github.com/docker/distribution => github.com/docker/distribution v0.0.0-20191216044856-a8371794149d github.com/docker/docker => github.com/moby/moby v25.0.3+incompatible github.com/gogo/protobuf => github.com/gogo/protobuf v1.3.2 diff --git a/go.sum b/go.sum index 18fe032c..b76c18f0 100644 --- a/go.sum +++ b/go.sum @@ -239,7 +239,7 @@ github.com/gobwas/glob v0.2.3/go.mod h1:d3Ez4x06l9bZtSvzIay5+Yzi0fmZzPgnTbPcKjJA github.com/gogo/googleapis v1.1.0/go.mod h1:gf4bu3Q80BeJ6H1S1vYPm8/ELATdvryBaNFGgqEef3s= github.com/gogo/protobuf v1.3.2 h1:Ov1cvc58UF3b5XjBnZv7+opcTcQFZebYjWzi34vdm4Q= github.com/gogo/protobuf v1.3.2/go.mod h1:P1XiOD3dCwIKUDQYPy72D8LYyHL2YPYrpS2s69NZV8Q= -github.com/golang-jwt/jwt/v5 v5.2.0/go.mod h1:pqrtFR0X4osieyHYxtmOUWsAWrfe1Q5UVIyoH402zdk= +github.com/golang-jwt/jwt/v5 v5.2.1/go.mod h1:pqrtFR0X4osieyHYxtmOUWsAWrfe1Q5UVIyoH402zdk= github.com/golang/glog v0.0.0-20160126235308-23def4e6c14b/go.mod h1:SBH7ygxi8pfUlaOkMMuAQtPIUF8ecWP5IEl/CR7VP2Q= github.com/golang/groupcache v0.0.0-20160516000752-02826c3e7903/go.mod h1:cIg4eruTrX1D+g88fzRXU5OdNfaM+9IcxsU14FzY7Hc= github.com/golang/groupcache v0.0.0-20190702054246-869f871628b6/go.mod h1:cIg4eruTrX1D+g88fzRXU5OdNfaM+9IcxsU14FzY7Hc= From 807b19e978aed1043f77e3092f5692d2ed81b086 Mon Sep 17 00:00:00 2001 From: Marian Steinbach Date: Tue, 5 Mar 2024 08:45:35 +0100 Subject: [PATCH 2/2] Update .nancy-ignore --- .nancy-ignore | 3 +++ 1 file changed, 3 insertions(+) diff --git a/.nancy-ignore b/.nancy-ignore index a49138ac..01b8a1c7 100644 --- a/.nancy-ignore +++ b/.nancy-ignore @@ -1,2 +1,5 @@ # pkg:golang/k8s.io/apiserver@v0.29.0 CVE-2020-8561 until=2024-03-31 + +# pkg:golang/helm.sh/helm/v3@v3.14.2 +CVE-2019-25210 until=2024-03-31