Skip to content

Commit 026dc77

Browse files
committed
bump dependencies to fix CVE alerts
Signed-off-by: Tim Ramlot <[email protected]>
1 parent 5dd5ef8 commit 026dc77

File tree

4 files changed

+332
-1019
lines changed

4 files changed

+332
-1019
lines changed

Dockerfile

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,5 @@
11
# Build the manager binary
2-
FROM golang:1.19 as builder
2+
FROM golang:1.21 as builder
33

44
WORKDIR /workspace
55
# Copy the Go Modules manifests

cmd/root.go

Lines changed: 11 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -27,6 +27,8 @@ import (
2727
"k8s.io/klog/v2"
2828
"k8s.io/klog/v2/klogr"
2929
ctrl "sigs.k8s.io/controller-runtime"
30+
"sigs.k8s.io/controller-runtime/pkg/metrics/server"
31+
"sigs.k8s.io/controller-runtime/pkg/webhook"
3032

3133
issuersv1beta1 "github.com/jetstack/google-cas-issuer/api/v1beta1"
3234
"github.com/jetstack/google-cas-issuer/pkg/controller/certificaterequest"
@@ -79,11 +81,15 @@ func root() error {
7981

8082
// Create controller-manager
8183
mgr, err := ctrl.NewManager(ctrl.GetConfigOrDie(), ctrl.Options{
82-
Scheme: scheme,
83-
MetricsBindAddress: viper.GetString("metrics-addr"),
84-
Port: 9443,
85-
LeaderElection: viper.GetBool("enable-leader-election"),
86-
LeaderElectionID: viper.GetString("leader-election-id"),
84+
Scheme: scheme,
85+
Metrics: server.Options{
86+
BindAddress: viper.GetString("metrics-addr"),
87+
},
88+
WebhookServer: webhook.NewServer(webhook.Options{
89+
Port: 9443,
90+
}),
91+
LeaderElection: viper.GetBool("enable-leader-election"),
92+
LeaderElectionID: viper.GetString("leader-election-id"),
8793
})
8894
if err != nil {
8995
setupLog.Error(err, "unable to start manager")

go.mod

Lines changed: 95 additions & 76 deletions
Original file line numberDiff line numberDiff line change
@@ -1,115 +1,134 @@
11
module github.com/jetstack/google-cas-issuer
22

3-
go 1.19
3+
go 1.21
44

55
require (
6-
cloud.google.com/go/security v1.10.0
7-
github.com/cert-manager/cert-manager v1.9.2
8-
github.com/go-logr/logr v1.2.3
9-
github.com/golang/protobuf v1.5.2
10-
github.com/google/uuid v1.3.0
6+
cloud.google.com/go/security v1.15.4
7+
github.com/cert-manager/cert-manager v1.13.3
8+
github.com/go-logr/logr v1.3.0
9+
github.com/golang/protobuf v1.5.3
10+
github.com/google/uuid v1.5.0
1111
github.com/olekukonko/tablewriter v0.0.5
12-
github.com/onsi/ginkgo/v2 v2.1.6
13-
github.com/onsi/gomega v1.20.1
14-
github.com/spf13/cobra v1.5.0
15-
github.com/spf13/viper v1.12.0
16-
github.com/stretchr/testify v1.8.1
17-
google.golang.org/api v0.102.0
18-
google.golang.org/genproto v0.0.0-20221118155620-16455021b5e6
19-
google.golang.org/protobuf v1.28.1
20-
k8s.io/api v0.25.4
21-
k8s.io/apimachinery v0.25.4
22-
k8s.io/cli-runtime v0.24.2
23-
k8s.io/client-go v0.25.4
24-
k8s.io/klog/v2 v2.80.1
25-
sigs.k8s.io/controller-runtime v0.12.3
12+
github.com/onsi/ginkgo/v2 v2.13.2
13+
github.com/onsi/gomega v1.30.0
14+
github.com/spf13/cobra v1.8.0
15+
github.com/spf13/viper v1.18.1
16+
github.com/stretchr/testify v1.8.4
17+
google.golang.org/api v0.154.0
18+
google.golang.org/genproto v0.0.0-20231212172506-995d672761c0
19+
google.golang.org/protobuf v1.31.0
20+
k8s.io/api v0.29.0
21+
k8s.io/apimachinery v0.29.0
22+
k8s.io/cli-runtime v0.29.0
23+
k8s.io/client-go v0.29.0
24+
k8s.io/klog/v2 v2.110.1
25+
sigs.k8s.io/controller-runtime v0.16.3
2626
)
2727

2828
require (
29-
cloud.google.com/go v0.105.0 // indirect
30-
cloud.google.com/go/compute v1.12.1 // indirect
31-
cloud.google.com/go/compute/metadata v0.2.1 // indirect
32-
cloud.google.com/go/longrunning v0.3.0 // indirect
29+
cloud.google.com/go v0.111.0 // indirect
30+
cloud.google.com/go/compute v1.23.3 // indirect
31+
cloud.google.com/go/compute/metadata v0.2.3 // indirect
32+
cloud.google.com/go/iam v1.1.5 // indirect
33+
cloud.google.com/go/longrunning v0.5.4 // indirect
34+
github.com/Azure/go-ansiterm v0.0.0-20210617225240-d185dfc1b5a1 // indirect
3335
github.com/beorn7/perks v1.0.1 // indirect
34-
github.com/cespare/xxhash/v2 v2.1.2 // indirect
35-
github.com/davecgh/go-spew v1.1.1 // indirect
36-
github.com/emicklei/go-restful/v3 v3.9.0 // indirect
36+
github.com/blang/semver/v4 v4.0.0 // indirect
37+
github.com/cespare/xxhash/v2 v2.2.0 // indirect
38+
github.com/davecgh/go-spew v1.1.2-0.20180830191138-d8f796af33cc // indirect
39+
github.com/emicklei/go-restful/v3 v3.11.0 // indirect
3740
github.com/evanphx/json-patch v5.6.0+incompatible // indirect
38-
github.com/fsnotify/fsnotify v1.5.4 // indirect
39-
github.com/go-errors/errors v1.0.1 // indirect
40-
github.com/go-openapi/jsonpointer v0.19.5 // indirect
41-
github.com/go-openapi/jsonreference v0.20.0 // indirect
41+
github.com/evanphx/json-patch/v5 v5.6.0 // indirect
42+
github.com/felixge/httpsnoop v1.0.4 // indirect
43+
github.com/fsnotify/fsnotify v1.7.0 // indirect
44+
github.com/go-errors/errors v1.4.2 // indirect
45+
github.com/go-logr/stdr v1.2.2 // indirect
46+
github.com/go-logr/zapr v1.2.4 // indirect
47+
github.com/go-openapi/jsonpointer v0.19.6 // indirect
48+
github.com/go-openapi/jsonreference v0.20.2 // indirect
4249
github.com/go-openapi/swag v0.22.3 // indirect
50+
github.com/go-task/slim-sprig v0.0.0-20230315185526-52ccab3ef572 // indirect
4351
github.com/gogo/protobuf v1.3.2 // indirect
4452
github.com/golang/groupcache v0.0.0-20210331224755-41bb18bfe9da // indirect
4553
github.com/google/btree v1.0.1 // indirect
46-
github.com/google/gnostic v0.6.9 // indirect
47-
github.com/google/go-cmp v0.5.9 // indirect
54+
github.com/google/gnostic-models v0.6.8 // indirect
55+
github.com/google/go-cmp v0.6.0 // indirect
4856
github.com/google/gofuzz v1.2.0 // indirect
57+
github.com/google/pprof v0.0.0-20210720184732-4bb14d4b1be1 // indirect
58+
github.com/google/s2a-go v0.1.7 // indirect
4959
github.com/google/shlex v0.0.0-20191202100458-e7afc7fbc510 // indirect
50-
github.com/googleapis/enterprise-certificate-proxy v0.2.0 // indirect
51-
github.com/googleapis/gax-go/v2 v2.6.0 // indirect
60+
github.com/googleapis/enterprise-certificate-proxy v0.3.2 // indirect
61+
github.com/googleapis/gax-go/v2 v2.12.0 // indirect
5262
github.com/gregjones/httpcache v0.0.0-20180305231024-9cad4c3443a7 // indirect
53-
github.com/hashicorp/hcl v1.0.0 // indirect
63+
github.com/hashicorp/hcl v1.0.1-vault-5 // indirect
5464
github.com/imdario/mergo v0.3.13 // indirect
55-
github.com/inconshreveable/mousetrap v1.0.1 // indirect
65+
github.com/inconshreveable/mousetrap v1.1.0 // indirect
5666
github.com/josharian/intern v1.0.0 // indirect
5767
github.com/json-iterator/go v1.1.12 // indirect
5868
github.com/liggitt/tabwriter v0.0.0-20181228230101-89fcab3d43de // indirect
59-
github.com/magiconair/properties v1.8.6 // indirect
69+
github.com/magiconair/properties v1.8.7 // indirect
6070
github.com/mailru/easyjson v0.7.7 // indirect
6171
github.com/mattn/go-runewidth v0.0.9 // indirect
6272
github.com/matttproud/golang_protobuf_extensions v1.0.4 // indirect
6373
github.com/mitchellh/mapstructure v1.5.0 // indirect
74+
github.com/moby/term v0.0.0-20221205130635-1aeaba878587 // indirect
6475
github.com/modern-go/concurrent v0.0.0-20180306012644-bacd9c7ef1dd // indirect
6576
github.com/modern-go/reflect2 v1.0.2 // indirect
6677
github.com/monochromegane/go-gitignore v0.0.0-20200626010858-205db1a8cc00 // indirect
6778
github.com/munnerz/goautoneg v0.0.0-20191010083416-a7dc8b61c822 // indirect
68-
github.com/pelletier/go-toml v1.9.5 // indirect
69-
github.com/pelletier/go-toml/v2 v2.0.6 // indirect
79+
github.com/pelletier/go-toml/v2 v2.1.0 // indirect
7080
github.com/peterbourgon/diskv v2.0.1+incompatible // indirect
7181
github.com/pkg/errors v0.9.1 // indirect
72-
github.com/pmezard/go-difflib v1.0.0 // indirect
73-
github.com/prometheus/client_golang v1.13.1 // indirect
74-
github.com/prometheus/client_model v0.2.0 // indirect
75-
github.com/prometheus/common v0.37.0 // indirect
76-
github.com/prometheus/procfs v0.8.0 // indirect
77-
github.com/spf13/afero v1.9.3 // indirect
78-
github.com/spf13/cast v1.5.0 // indirect
79-
github.com/spf13/jwalterweatherman v1.1.0 // indirect
82+
github.com/pmezard/go-difflib v1.0.1-0.20181226105442-5d4384ee4fb2 // indirect
83+
github.com/prometheus/client_golang v1.16.0 // indirect
84+
github.com/prometheus/client_model v0.4.0 // indirect
85+
github.com/prometheus/common v0.44.0 // indirect
86+
github.com/prometheus/procfs v0.10.1 // indirect
87+
github.com/sagikazarmark/locafero v0.4.0 // indirect
88+
github.com/sagikazarmark/slog-shim v0.1.0 // indirect
89+
github.com/sourcegraph/conc v0.3.0 // indirect
90+
github.com/spf13/afero v1.11.0 // indirect
91+
github.com/spf13/cast v1.6.0 // indirect
8092
github.com/spf13/pflag v1.0.5 // indirect
81-
github.com/subosito/gotenv v1.4.1 // indirect
82-
github.com/xlab/treeprint v0.0.0-20181112141820-a009c3971eca // indirect
83-
go.opencensus.io v0.23.0 // indirect
84-
go.starlark.net v0.0.0-20200306205701-8dd3e2ee1dd5 // indirect
85-
go.uber.org/atomic v1.10.0 // indirect
86-
go.uber.org/multierr v1.8.0 // indirect
87-
go.uber.org/zap v1.22.0 // indirect
88-
golang.org/x/net v0.0.0-20221014081412-f15817d10f9b // indirect
89-
golang.org/x/oauth2 v0.0.0-20221014153046-6fdb5e3db783 // indirect
90-
golang.org/x/sys v0.0.0-20220823224334-20c2bfdbfe24 // indirect
91-
golang.org/x/term v0.0.0-20220722155259-a9ba230a4035 // indirect
92-
golang.org/x/text v0.4.0 // indirect
93-
golang.org/x/time v0.0.0-20220722155302-e5dcc9cfc0b9 // indirect
94-
gomodules.xyz/jsonpatch/v2 v2.2.0 // indirect
95-
google.golang.org/appengine v1.6.7 // indirect
96-
google.golang.org/grpc v1.50.1 // indirect
93+
github.com/subosito/gotenv v1.6.0 // indirect
94+
github.com/xlab/treeprint v1.2.0 // indirect
95+
go.opencensus.io v0.24.0 // indirect
96+
go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc v0.46.1 // indirect
97+
go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.46.1 // indirect
98+
go.opentelemetry.io/otel v1.21.0 // indirect
99+
go.opentelemetry.io/otel/metric v1.21.0 // indirect
100+
go.opentelemetry.io/otel/trace v1.21.0 // indirect
101+
go.starlark.net v0.0.0-20230525235612-a134d8f9ddca // indirect
102+
go.uber.org/multierr v1.11.0 // indirect
103+
go.uber.org/zap v1.25.0 // indirect
104+
golang.org/x/crypto v0.16.0 // indirect
105+
golang.org/x/exp v0.0.0-20230905200255-921286631fa9 // indirect
106+
golang.org/x/net v0.19.0 // indirect
107+
golang.org/x/oauth2 v0.15.0 // indirect
108+
golang.org/x/sync v0.5.0 // indirect
109+
golang.org/x/sys v0.15.0 // indirect
110+
golang.org/x/term v0.15.0 // indirect
111+
golang.org/x/text v0.14.0 // indirect
112+
golang.org/x/time v0.5.0 // indirect
113+
golang.org/x/tools v0.14.0 // indirect
114+
gomodules.xyz/jsonpatch/v2 v2.4.0 // indirect
115+
google.golang.org/appengine v1.6.8 // indirect
116+
google.golang.org/genproto/googleapis/api v0.0.0-20231211222908-989df2bf70f3 // indirect
117+
google.golang.org/genproto/googleapis/rpc v0.0.0-20231211222908-989df2bf70f3 // indirect
118+
google.golang.org/grpc v1.60.0 // indirect
97119
gopkg.in/inf.v0 v0.9.1 // indirect
98120
gopkg.in/ini.v1 v1.67.0 // indirect
99121
gopkg.in/yaml.v2 v2.4.0 // indirect
100122
gopkg.in/yaml.v3 v3.0.1 // indirect
101-
k8s.io/apiextensions-apiserver v0.25.4 // indirect
102-
k8s.io/component-base v0.25.4 // indirect
103-
k8s.io/kube-aggregator v0.25.4 // indirect
104-
k8s.io/kube-openapi v0.0.0-20221123214604-86e75ddd809a // indirect
105-
k8s.io/utils v0.0.0-20221128185143-99ec85e7a448 // indirect
106-
sigs.k8s.io/gateway-api v0.5.1 // indirect
123+
k8s.io/apiextensions-apiserver v0.28.3 // indirect
124+
k8s.io/component-base v0.28.3 // indirect
125+
k8s.io/kube-aggregator v0.28.1 // indirect
126+
k8s.io/kube-openapi v0.0.0-20231010175941-2dd684a91f00 // indirect
127+
k8s.io/utils v0.0.0-20230726121419-3b25d923346b // indirect
128+
sigs.k8s.io/gateway-api v0.8.0 // indirect
107129
sigs.k8s.io/json v0.0.0-20221116044647-bc3834ca7abd // indirect
108-
sigs.k8s.io/kustomize/api v0.11.4 // indirect
109-
sigs.k8s.io/kustomize/kyaml v0.13.6 // indirect
110-
sigs.k8s.io/structured-merge-diff/v4 v4.2.3 // indirect
130+
sigs.k8s.io/kustomize/api v0.13.5-0.20230601165947-6ce0bf390ce3 // indirect
131+
sigs.k8s.io/kustomize/kyaml v0.14.3-0.20230601165947-6ce0bf390ce3 // indirect
132+
sigs.k8s.io/structured-merge-diff/v4 v4.4.1 // indirect
111133
sigs.k8s.io/yaml v1.3.0 // indirect
112134
)
113-
114-
// Required because of cert-manager's outdated gateway API import.
115-
replace sigs.k8s.io/gateway-api => sigs.k8s.io/gateway-api v0.4.3

0 commit comments

Comments
 (0)