diff --git a/go.mod b/go.mod index a817fd6..d8852b9 100644 --- a/go.mod +++ b/go.mod @@ -6,7 +6,7 @@ require ( github.com/google/go-cmp v0.5.9 github.com/grpc-ecosystem/grpc-gateway/v2 v2.15.0 google.golang.org/grpc v1.56.3 - google.golang.org/protobuf v1.32.0 + google.golang.org/protobuf v1.33.0 sigs.k8s.io/controller-runtime v0.14.1 ) @@ -41,7 +41,7 @@ replace ( // Fixes CVE-2023-48795 - golang.org/x/crypto Authentication Bypass by Capture-replay golang.org/x/crypto => golang.org/x/crypto v0.17.0 golang.org/x/net => golang.org/x/net v0.17.0 - + // Fixes github.com/elazarl/goproxy Denial of Service (DoS), the dependency was removed in v0.27.0 // Remove below when upgrading to controller-runtime 0.15.x or apimachinery to 0.27.x k8s.io/apimachinery => k8s.io/apimachinery v0.27.0 diff --git a/go.sum b/go.sum index 86a6850..9d25a3f 100644 --- a/go.sum +++ b/go.sum @@ -112,6 +112,8 @@ google.golang.org/protobuf v1.26.0-rc.1/go.mod h1:jlhhOSvTdKEhbULTjvd4ARK9grFBp0 google.golang.org/protobuf v1.26.0/go.mod h1:9q0QmTI4eRPtz6boOQmLYwt+qCgq0jsYwAQnmE0givc= google.golang.org/protobuf v1.32.0 h1:pPC6BG5ex8PDFnkbrGU3EixyhKcQ2aDuBS36lqK/C7I= google.golang.org/protobuf v1.32.0/go.mod h1:c6P6GXX6sHbq/GpV6MGZEdwhWPcYBgnhAHhKbcUYpos= +google.golang.org/protobuf v1.33.0 h1:uNO2rsAINq/JlFpSdYEKIZ0uKD/R9cpdv0T+yoGwGmI= +google.golang.org/protobuf v1.33.0/go.mod h1:c6P6GXX6sHbq/GpV6MGZEdwhWPcYBgnhAHhKbcUYpos= gopkg.in/check.v1 v0.0.0-20161208181325-20d25e280405/go.mod h1:Co6ibVJAznAaIkqp8huTwlJQCZ016jof/cbN4VW5Yz0= gopkg.in/check.v1 v1.0.0-20180628173108-788fd7840127 h1:qIbj1fsPNlZgppZ+VLlY7N33q108Sa+fhmuc+sWQYwY= gopkg.in/check.v1 v1.0.0-20180628173108-788fd7840127/go.mod h1:Co6ibVJAznAaIkqp8huTwlJQCZ016jof/cbN4VW5Yz0=