Skip to content

Commit

Permalink
chore(deps): Migrate to github.com/go-jose/go-jose/v3
Browse files Browse the repository at this point in the history
Stop using archived gopkg.in/square/go-jose.v2 pkg
Switch to github.com/go-jose/go-jose/v3 instead

Fixes CVE-2024-28180

(cherry picked from commit c19b6e6)
Signed-off-by: Vincent Demeester <vdemeest@redhat.com>
  • Loading branch information
isibeni authored and tekton-robot committed Apr 8, 2024
1 parent b29a5b9 commit 0ca072b
Show file tree
Hide file tree
Showing 31 changed files with 421 additions and 964 deletions.
6 changes: 3 additions & 3 deletions go.mod
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
module github.com/tektoncd/pipeline

go 1.19
go 1.21

require (
github.com/Microsoft/go-winio v0.6.1 // indirect
Expand All @@ -27,7 +27,6 @@ require (
golang.org/x/exp v0.0.0-20230307190834-24139beb5833
golang.org/x/oauth2 v0.9.0 // indirect
gomodules.xyz/jsonpatch/v2 v2.2.0
gopkg.in/square/go-jose.v2 v2.6.0
k8s.io/api v0.27.1
k8s.io/apimachinery v0.27.1
k8s.io/client-go v0.27.1
Expand All @@ -50,6 +49,7 @@ require github.com/benbjohnson/clock v1.1.0 // indirect

require (
code.gitea.io/sdk/gitea v0.15.1
github.com/go-jose/go-jose/v3 v3.0.3
github.com/goccy/kpoward v0.1.0
github.com/google/go-containerregistry/pkg/authn/k8schain v0.0.0-20230625233257-b8504803389b
github.com/sigstore/sigstore/pkg/signature/kms/aws v1.7.1
Expand Down Expand Up @@ -93,7 +93,6 @@ require (
github.com/cyphar/filepath-securejoin v0.2.4 // indirect
github.com/emicklei/go-restful/v3 v3.10.2 // indirect
github.com/fatih/color v1.13.0 // indirect
github.com/go-jose/go-jose/v3 v3.0.0 // indirect
github.com/go-logr/stdr v1.2.2 // indirect
github.com/google/gnostic v0.6.9 // indirect
github.com/google/go-containerregistry/pkg/authn/kubernetes v0.0.0-20230516205744-dbecb1de8cfa // indirect
Expand Down Expand Up @@ -126,6 +125,7 @@ require (
go.opentelemetry.io/otel/metric v1.16.0 // indirect
google.golang.org/genproto/googleapis/api v0.0.0-20230530153820-e85fd2cbaebc // indirect
google.golang.org/genproto/googleapis/rpc v0.0.0-20230530153820-e85fd2cbaebc // indirect
gopkg.in/square/go-jose.v2 v2.6.0 // indirect
)

require (
Expand Down
40 changes: 37 additions & 3 deletions go.sum

Large diffs are not rendered by default.

6 changes: 3 additions & 3 deletions pkg/spire/test/ca.go
Original file line number Diff line number Diff line change
Expand Up @@ -29,6 +29,9 @@ import (
"testing"
"time"

"github.com/go-jose/go-jose/v3"
"github.com/go-jose/go-jose/v3/cryptosigner"
"github.com/go-jose/go-jose/v3/jwt"
"github.com/spiffe/go-spiffe/v2/bundle/jwtbundle"
"github.com/spiffe/go-spiffe/v2/bundle/spiffebundle"
"github.com/spiffe/go-spiffe/v2/bundle/x509bundle"
Expand All @@ -37,9 +40,6 @@ import (
"github.com/spiffe/go-spiffe/v2/svid/x509svid"
"github.com/stretchr/testify/require"
"github.com/tektoncd/pipeline/pkg/spire/test/x509util"
"gopkg.in/square/go-jose.v2"
"gopkg.in/square/go-jose.v2/cryptosigner"
"gopkg.in/square/go-jose.v2/jwt"
)

var (
Expand Down
10 changes: 0 additions & 10 deletions vendor/github.com/go-jose/go-jose/v3/BUG-BOUNTY.md

This file was deleted.

78 changes: 78 additions & 0 deletions vendor/github.com/go-jose/go-jose/v3/CHANGELOG.md

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

60 changes: 23 additions & 37 deletions vendor/github.com/go-jose/go-jose/v3/README.md

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

13 changes: 13 additions & 0 deletions vendor/github.com/go-jose/go-jose/v3/SECURITY.md

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

3 changes: 3 additions & 0 deletions vendor/github.com/go-jose/go-jose/v3/asymmetric.go

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

Loading

0 comments on commit 0ca072b

Please sign in to comment.