Skip to content

Commit 450f6b9

Browse files
committed
vendor: golang.org/x/crypto v0.31.0
update to the latest version of this dependency, which has a fix for a authorization bypass in the ssh package. We don't use this functionality, so there's no need to backport this change (other than de-noising false positives). This is CVE-2024-45337 and Go issue https://go.dev/issue/70779. full diff: golang/crypto@v0.29.0...v0.31.0 Signed-off-by: Sebastiaan van Stijn <github@gone.nl>
1 parent b74302e commit 450f6b9

3 files changed

Lines changed: 8 additions & 8 deletions

File tree

vendor.mod

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -50,7 +50,7 @@ require (
5050
go.opentelemetry.io/otel/trace v1.28.0
5151
golang.org/x/sync v0.10.0
5252
golang.org/x/sys v0.28.0
53-
golang.org/x/term v0.26.0
53+
golang.org/x/term v0.27.0
5454
golang.org/x/text v0.21.0
5555
gopkg.in/yaml.v2 v2.4.0
5656
gotest.tools/v3 v3.5.1
@@ -95,7 +95,7 @@ require (
9595
go.opentelemetry.io/otel/exporters/otlp/otlptrace v1.28.0 // indirect
9696
go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp v1.28.0 // indirect
9797
go.opentelemetry.io/proto/otlp v1.3.1 // indirect
98-
golang.org/x/crypto v0.29.0 // indirect
98+
golang.org/x/crypto v0.31.0 // indirect
9999
golang.org/x/net v0.31.0 // indirect
100100
golang.org/x/time v0.6.0 // indirect
101101
google.golang.org/genproto/googleapis/api v0.0.0-20241007155032-5fefd90f89a9 // indirect

vendor.sum

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -316,8 +316,8 @@ golang.org/x/crypto v0.0.0-20191011191535-87dc89f01550/go.mod h1:yigFU9vqHzYiE8U
316316
golang.org/x/crypto v0.0.0-20200302210943-78000ba7a073/go.mod h1:LzIPMQfyMNhhGPhUkYOs5KpL4U8rLKemX1yGLhDgUto=
317317
golang.org/x/crypto v0.0.0-20200622213623-75b288015ac9/go.mod h1:LzIPMQfyMNhhGPhUkYOs5KpL4U8rLKemX1yGLhDgUto=
318318
golang.org/x/crypto v0.0.0-20201117144127-c1f2f97bffc9/go.mod h1:jdWPYTVW3xRLrWPugEBEK3UY2ZEsg3UU495nc5E+M+I=
319-
golang.org/x/crypto v0.29.0 h1:L5SG1JTTXupVV3n6sUqMTeWbjAyfPwoda2DLX8J8FrQ=
320-
golang.org/x/crypto v0.29.0/go.mod h1:+F4F4N5hv6v38hfeYwTdx20oUvLLc+QfrE9Ax9HtgRg=
319+
golang.org/x/crypto v0.31.0 h1:ihbySMvVjLAeSH1IbfcRTkD/iNscyz8rGzjF/E5hV6U=
320+
golang.org/x/crypto v0.31.0/go.mod h1:kDsLvtWBEx7MV9tJOj9bnXsPbxwJQ6csT/x4KIN4Ssk=
321321
golang.org/x/mod v0.2.0/go.mod h1:s0Qsj1ACt9ePp/hMypM3fl4fZqREWJwdYDEqhRiZZUA=
322322
golang.org/x/mod v0.3.0/go.mod h1:s0Qsj1ACt9ePp/hMypM3fl4fZqREWJwdYDEqhRiZZUA=
323323
golang.org/x/net v0.0.0-20180906233101-161cd47e91fd/go.mod h1:mL1N/T3taQHkDXs73rZJwtUhF3w3ftmwwsq0BUmARs4=
@@ -352,8 +352,8 @@ golang.org/x/sys v0.1.0/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg=
352352
golang.org/x/sys v0.28.0 h1:Fksou7UEQUWlKvIdsqzJmUmCX3cZuD2+P3XyyzwMhlA=
353353
golang.org/x/sys v0.28.0/go.mod h1:/VUhepiaJMQUp4+oa/7Zr1D23ma6VTLIYjOOTFZPUcA=
354354
golang.org/x/term v0.0.0-20201117132131-f5c789dd3221/go.mod h1:Nr5EML6q2oocZ2LXRh80K7BxOlk5/8JxuGnuhpl+muw=
355-
golang.org/x/term v0.26.0 h1:WEQa6V3Gja/BhNxg540hBip/kkaYtRg3cxg4oXSw4AU=
356-
golang.org/x/term v0.26.0/go.mod h1:Si5m1o57C5nBNQo5z1iq+XDijt21BDBDp2bK0QI8e3E=
355+
golang.org/x/term v0.27.0 h1:WP60Sv1nlK1T6SupCHbXzSaN0b9wUmsPoRS9b61A23Q=
356+
golang.org/x/term v0.27.0/go.mod h1:iMsnZpn0cago0GOrHO2+Y7u7JPn5AylBrcoWkElMTSM=
357357
golang.org/x/text v0.3.0/go.mod h1:NqM8EUOU14njkJ3fqMW+pc6Ldnwhi/IjpwHt7yyuwOQ=
358358
golang.org/x/text v0.3.3/go.mod h1:5Zoc/QRtKVWzQhOtBMvqHzDpF6irO9z98xDceosuGiQ=
359359
golang.org/x/text v0.21.0 h1:zyQAAkrwaneQ066sspRyJaG9VNi/YJ1NfzcGB3hZ/qo=

vendor/modules.txt

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -383,7 +383,7 @@ go.opentelemetry.io/proto/otlp/common/v1
383383
go.opentelemetry.io/proto/otlp/metrics/v1
384384
go.opentelemetry.io/proto/otlp/resource/v1
385385
go.opentelemetry.io/proto/otlp/trace/v1
386-
# golang.org/x/crypto v0.29.0
386+
# golang.org/x/crypto v0.31.0
387387
## explicit; go 1.20
388388
golang.org/x/crypto/ed25519
389389
golang.org/x/crypto/pbkdf2
@@ -404,7 +404,7 @@ golang.org/x/sys/plan9
404404
golang.org/x/sys/unix
405405
golang.org/x/sys/windows
406406
golang.org/x/sys/windows/registry
407-
# golang.org/x/term v0.26.0
407+
# golang.org/x/term v0.27.0
408408
## explicit; go 1.18
409409
golang.org/x/term
410410
# golang.org/x/text v0.21.0

0 commit comments

Comments
 (0)