Skip to content

Commit 360fbb9

Browse files
committed
UPSTREAM: <carry>: Update grpc-go to v1.75.1-sec.1 to fix CVE-2026-33186
1 parent 4b3ad17 commit 360fbb9

261 files changed

Lines changed: 43156 additions & 20507 deletions

File tree

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

go.mod

Lines changed: 20 additions & 18 deletions
Original file line numberDiff line numberDiff line change
@@ -9,7 +9,7 @@ require (
99
github.com/containerd/containerd v1.7.27
1010
github.com/containers/image/v5 v5.35.0
1111
github.com/fsnotify/fsnotify v1.9.0
12-
github.com/go-logr/logr v1.4.2
12+
github.com/go-logr/logr v1.4.3
1313
github.com/google/go-cmp v0.7.0
1414
github.com/google/go-containerregistry v0.20.3
1515
github.com/gorilla/handlers v1.5.2
@@ -23,9 +23,9 @@ require (
2323
github.com/spf13/cobra v1.9.1
2424
github.com/stretchr/testify v1.10.0
2525
golang.org/x/exp v0.0.0-20250228200357-dead58393ab7
26-
golang.org/x/mod v0.24.0
27-
golang.org/x/sync v0.13.0
28-
golang.org/x/tools v0.32.0
26+
golang.org/x/mod v0.25.0
27+
golang.org/x/sync v0.15.0
28+
golang.org/x/tools v0.33.0
2929
gopkg.in/yaml.v2 v2.4.0
3030
helm.sh/helm/v3 v3.17.3
3131
k8s.io/api v0.32.3
@@ -48,7 +48,7 @@ require (
4848
)
4949

5050
require (
51-
cel.dev/expr v0.19.1 // indirect
51+
cel.dev/expr v0.24.0 // indirect
5252
dario.cat/mergo v1.0.1 // indirect
5353
github.com/AdaLogics/go-fuzz-headers v0.0.0-20230811130428-ced1acdcaa24 // indirect
5454
github.com/Azure/go-ansiterm v0.0.0-20250102033503-faa5f7b0171c // indirect
@@ -103,7 +103,7 @@ require (
103103
github.com/go-git/go-billy/v5 v5.6.1 // indirect
104104
github.com/go-git/go-git/v5 v5.13.1 // indirect
105105
github.com/go-gorp/gorp/v3 v3.1.0 // indirect
106-
github.com/go-jose/go-jose/v4 v4.0.5 // indirect
106+
github.com/go-jose/go-jose/v4 v4.1.1 // indirect
107107
github.com/go-logr/stdr v1.2.2 // indirect
108108
github.com/go-openapi/analysis v0.23.0 // indirect
109109
github.com/go-openapi/errors v0.22.1 // indirect
@@ -214,24 +214,24 @@ require (
214214
go.opencensus.io v0.24.0 // indirect
215215
go.opentelemetry.io/auto/sdk v1.1.0 // indirect
216216
go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.59.0 // indirect
217-
go.opentelemetry.io/otel v1.34.0 // indirect
217+
go.opentelemetry.io/otel v1.37.0 // indirect
218218
go.opentelemetry.io/otel/exporters/otlp/otlptrace v1.33.0 // indirect
219219
go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc v1.32.0 // indirect
220-
go.opentelemetry.io/otel/metric v1.34.0 // indirect
221-
go.opentelemetry.io/otel/sdk v1.34.0 // indirect
222-
go.opentelemetry.io/otel/trace v1.34.0 // indirect
220+
go.opentelemetry.io/otel/metric v1.37.0 // indirect
221+
go.opentelemetry.io/otel/sdk v1.37.0 // indirect
222+
go.opentelemetry.io/otel/trace v1.37.0 // indirect
223223
go.opentelemetry.io/proto/otlp v1.4.0 // indirect
224-
golang.org/x/crypto v0.37.0 // indirect
225-
golang.org/x/net v0.39.0 // indirect
226-
golang.org/x/oauth2 v0.29.0 // indirect
227-
golang.org/x/sys v0.32.0 // indirect
228-
golang.org/x/term v0.31.0 // indirect
229-
golang.org/x/text v0.24.0 // indirect
224+
golang.org/x/crypto v0.39.0 // indirect
225+
golang.org/x/net v0.41.0 // indirect
226+
golang.org/x/oauth2 v0.30.0 // indirect
227+
golang.org/x/sys v0.33.0 // indirect
228+
golang.org/x/term v0.32.0 // indirect
229+
golang.org/x/text v0.26.0 // indirect
230230
golang.org/x/time v0.11.0 // indirect
231231
gomodules.xyz/jsonpatch/v2 v2.4.0 // indirect
232232
google.golang.org/genproto v0.0.0-20250303144028-a0af3efb3deb // indirect
233-
google.golang.org/genproto/googleapis/api v0.0.0-20250303144028-a0af3efb3deb // indirect
234-
google.golang.org/genproto/googleapis/rpc v0.0.0-20250313205543-e70fdf4c4cb4 // indirect
233+
google.golang.org/genproto/googleapis/api v0.0.0-20250707201910-8d1bb00bc6a7 // indirect
234+
google.golang.org/genproto/googleapis/rpc v0.0.0-20250707201910-8d1bb00bc6a7 // indirect
235235
google.golang.org/grpc v1.71.0 // indirect
236236
google.golang.org/protobuf v1.36.6 // indirect
237237
gopkg.in/evanphx/json-patch.v4 v4.12.0 // indirect
@@ -307,3 +307,5 @@ replace k8s.io/mount-utils => k8s.io/mount-utils v0.32.3
307307
replace k8s.io/pod-security-admission => k8s.io/pod-security-admission v0.32.3
308308

309309
replace k8s.io/sample-apiserver => k8s.io/sample-apiserver v0.32.3
310+
311+
replace google.golang.org/grpc => github.com/openshift-sustaining/grpc-go v1.75.1-sec.1

go.sum

Lines changed: 2028 additions & 56 deletions
Large diffs are not rendered by default.

openshift/default-catalog-consistency/go.mod

Lines changed: 14 additions & 12 deletions
Original file line numberDiff line numberDiff line change
@@ -43,8 +43,8 @@ require (
4343
github.com/go-git/gcfg v1.5.1-0.20230307220236-3a3c6141e376 // indirect
4444
github.com/go-git/go-billy/v5 v5.6.2 // indirect
4545
github.com/go-git/go-git/v5 v5.16.0 // indirect
46-
github.com/go-jose/go-jose/v4 v4.0.5 // indirect
47-
github.com/go-logr/logr v1.4.2 // indirect
46+
github.com/go-jose/go-jose/v4 v4.1.1 // indirect
47+
github.com/go-logr/logr v1.4.3 // indirect
4848
github.com/go-openapi/analysis v0.23.0 // indirect
4949
github.com/go-openapi/errors v0.22.1 // indirect
5050
github.com/go-openapi/jsonpointer v0.21.1 // indirect
@@ -110,18 +110,18 @@ require (
110110
github.com/x448/float16 v0.8.4 // indirect
111111
go.mongodb.org/mongo-driver v1.14.0 // indirect
112112
go.opencensus.io v0.24.0 // indirect
113-
golang.org/x/crypto v0.37.0 // indirect
113+
golang.org/x/crypto v0.39.0 // indirect
114114
golang.org/x/exp v0.0.0-20250408133849-7e4ce0ab07d0 // indirect
115-
golang.org/x/net v0.39.0 // indirect
116-
golang.org/x/oauth2 v0.29.0 // indirect
117-
golang.org/x/sync v0.13.0 // indirect
118-
golang.org/x/sys v0.32.0 // indirect
119-
golang.org/x/term v0.31.0 // indirect
120-
golang.org/x/text v0.24.0 // indirect
115+
golang.org/x/net v0.41.0 // indirect
116+
golang.org/x/oauth2 v0.30.0 // indirect
117+
golang.org/x/sync v0.15.0 // indirect
118+
golang.org/x/sys v0.33.0 // indirect
119+
golang.org/x/term v0.32.0 // indirect
120+
golang.org/x/text v0.26.0 // indirect
121121
golang.org/x/time v0.11.0 // indirect
122-
golang.org/x/tools v0.32.0 // indirect
123-
google.golang.org/genproto/googleapis/api v0.0.0-20250303144028-a0af3efb3deb // indirect
124-
google.golang.org/genproto/googleapis/rpc v0.0.0-20250313205543-e70fdf4c4cb4 // indirect
122+
golang.org/x/tools v0.33.0 // indirect
123+
google.golang.org/genproto/googleapis/api v0.0.0-20250707201910-8d1bb00bc6a7 // indirect
124+
google.golang.org/genproto/googleapis/rpc v0.0.0-20250707201910-8d1bb00bc6a7 // indirect
125125
google.golang.org/grpc v1.71.0 // indirect
126126
google.golang.org/protobuf v1.36.6 // indirect
127127
gopkg.in/inf.v0 v0.9.1 // indirect
@@ -137,3 +137,5 @@ require (
137137
sigs.k8s.io/json v0.0.0-20241014173422-cfa47c3a1cc8 // indirect
138138
sigs.k8s.io/structured-merge-diff/v4 v4.7.0 // indirect
139139
)
140+
141+
replace google.golang.org/grpc => github.com/openshift-sustaining/grpc-go v1.75.1-sec.1

0 commit comments

Comments
 (0)