Skip to content

Commit d95be2a

Browse files
committed
chore(deps): Migrate to github.com/go-jose/go-jose/v3
Stop using archived gopkg.in/square/go-jose.v2 pkg Bump github.com/go-jose/go-jose/v3 to v3.0.3 Fixes CVE-2024-28180
1 parent 82816c3 commit d95be2a

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

41 files changed

+22
-9799
lines changed

go.mod

Lines changed: 1 addition & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -27,7 +27,6 @@ require (
2727
golang.org/x/exp v0.0.0-20230515195305-f3d0a9c9a5cc
2828
golang.org/x/oauth2 v0.18.0 // indirect
2929
gomodules.xyz/jsonpatch/v2 v2.4.0
30-
gopkg.in/square/go-jose.v2 v2.6.0
3130
k8s.io/api v0.28.5
3231
k8s.io/apimachinery v0.29.0
3332
k8s.io/client-go v0.28.5
@@ -48,6 +47,7 @@ replace (
4847

4948
require (
5049
code.gitea.io/sdk/gitea v0.17.1
50+
github.com/go-jose/go-jose/v3 v3.0.3
5151
github.com/goccy/kpoward v0.1.0
5252
github.com/google/cel-go v0.20.1
5353
github.com/google/go-containerregistry/pkg/authn/k8schain v0.0.0-20240108195214-a0658aa1d0cc
@@ -100,7 +100,6 @@ require (
100100
github.com/emicklei/go-restful/v3 v3.10.2 // indirect
101101
github.com/felixge/httpsnoop v1.0.4 // indirect
102102
github.com/go-fed/httpsig v1.1.0 // indirect
103-
github.com/go-jose/go-jose/v3 v3.0.3 // indirect
104103
github.com/go-jose/go-jose/v4 v4.0.1 // indirect
105104
github.com/go-logr/stdr v1.2.2 // indirect
106105
github.com/golang-jwt/jwt/v5 v5.2.0 // indirect

go.sum

Lines changed: 0 additions & 2 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

pkg/spire/test/ca.go

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -29,6 +29,9 @@ import (
2929
"testing"
3030
"time"
3131

32+
"github.com/go-jose/go-jose/v3"
33+
"github.com/go-jose/go-jose/v3/cryptosigner"
34+
"github.com/go-jose/go-jose/v3/jwt"
3235
"github.com/spiffe/go-spiffe/v2/bundle/jwtbundle"
3336
"github.com/spiffe/go-spiffe/v2/bundle/spiffebundle"
3437
"github.com/spiffe/go-spiffe/v2/bundle/x509bundle"
@@ -37,9 +40,6 @@ import (
3740
"github.com/spiffe/go-spiffe/v2/svid/x509svid"
3841
"github.com/stretchr/testify/require"
3942
"github.com/tektoncd/pipeline/pkg/spire/test/x509util"
40-
"gopkg.in/square/go-jose.v2"
41-
"gopkg.in/square/go-jose.v2/cryptosigner"
42-
"gopkg.in/square/go-jose.v2/jwt"
4343
)
4444

4545
var (

vendor/gopkg.in/square/go-jose.v2/cryptosigner/cryptosigner.go renamed to vendor/github.com/go-jose/go-jose/v3/cryptosigner/cryptosigner.go

Lines changed: 17 additions & 8 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

vendor/gopkg.in/square/go-jose.v2/.gitcookies.sh.enc

Lines changed: 0 additions & 1 deletion
This file was deleted.

vendor/gopkg.in/square/go-jose.v2/.gitignore

Lines changed: 0 additions & 8 deletions
This file was deleted.

vendor/gopkg.in/square/go-jose.v2/.travis.yml

Lines changed: 0 additions & 45 deletions
This file was deleted.

vendor/gopkg.in/square/go-jose.v2/BUG-BOUNTY.md

Lines changed: 0 additions & 10 deletions
This file was deleted.

vendor/gopkg.in/square/go-jose.v2/CONTRIBUTING.md

Lines changed: 0 additions & 14 deletions
This file was deleted.

0 commit comments

Comments
 (0)