Skip to content

Commit ff5b628

Browse files
committed
chore(deps): update grpc to v1.79.3
Upgrade google.golang.org/grpc to v1.79.3 to fix CVE-2026-33186 (GHSA-p77j-4mvh-x3m3), a critical HTTP/2 :path validation flaw that allows bypassing authorization rules in gRPC interceptors. Signed-off-by: Akshay Pant <akpant@redhat.com>
1 parent 8b79f2d commit ff5b628

File tree

158 files changed

+5636
-9792
lines changed

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

158 files changed

+5636
-9792
lines changed

go.mod

Lines changed: 13 additions & 13 deletions
Original file line numberDiff line numberDiff line change
@@ -35,9 +35,9 @@ require (
3535
go.opencensus.io v0.24.0
3636
go.uber.org/zap v1.27.0
3737
golang.org/x/exp v0.0.0-20250911091902-df9299821621
38-
golang.org/x/oauth2 v0.31.0
39-
golang.org/x/sync v0.17.0
40-
golang.org/x/text v0.29.0
38+
golang.org/x/oauth2 v0.34.0
39+
golang.org/x/sync v0.19.0
40+
golang.org/x/text v0.32.0
4141
gopkg.in/yaml.v2 v2.4.0
4242
gotest.tools/v3 v3.5.2
4343
k8s.io/api v0.34.1
@@ -50,15 +50,15 @@ require (
5050
)
5151

5252
require (
53-
cel.dev/expr v0.24.0 // indirect
53+
cel.dev/expr v0.25.1 // indirect
5454
github.com/42wim/httpsig v1.2.3 // indirect
5555
github.com/antlr/antlr4/runtime/Go/antlr v1.4.10 // indirect
5656
github.com/cert-manager/cert-manager v1.18.2 // indirect
5757
github.com/cloudevents/sdk-go/sql/v2 v2.16.1 // indirect
5858
github.com/coreos/go-oidc/v3 v3.15.0 // indirect
5959
github.com/fxamacker/cbor/v2 v2.9.0 // indirect
6060
github.com/go-jose/go-jose/v3 v3.0.4 // indirect
61-
github.com/go-jose/go-jose/v4 v4.1.2 // indirect
61+
github.com/go-jose/go-jose/v4 v4.1.3 // indirect
6262
github.com/go-openapi/swag/cmdutils v0.24.0 // indirect
6363
github.com/go-openapi/swag/conv v0.24.0 // indirect
6464
github.com/go-openapi/swag/fileutils v0.24.0 // indirect
@@ -139,17 +139,17 @@ require (
139139
github.com/xlzd/gotp v0.1.0 // indirect
140140
go.uber.org/automaxprocs v1.6.0 // indirect
141141
go.uber.org/multierr v1.11.0 // indirect
142-
golang.org/x/crypto v0.42.0 // indirect
143-
golang.org/x/net v0.44.0 // indirect
144-
golang.org/x/sys v0.36.0 // indirect
145-
golang.org/x/term v0.35.0
142+
golang.org/x/crypto v0.46.0 // indirect
143+
golang.org/x/net v0.48.0 // indirect
144+
golang.org/x/sys v0.39.0 // indirect
145+
golang.org/x/term v0.38.0
146146
golang.org/x/time v0.13.0 // indirect
147147
gomodules.xyz/jsonpatch/v2 v2.5.0 // indirect
148148
google.golang.org/api v0.249.0 // indirect
149-
google.golang.org/genproto/googleapis/api v0.0.0-20250908214217-97024824d090 // indirect
150-
google.golang.org/genproto/googleapis/rpc v0.0.0-20250908214217-97024824d090 // indirect
151-
google.golang.org/grpc v1.75.1 // indirect
152-
google.golang.org/protobuf v1.36.9
149+
google.golang.org/genproto/googleapis/api v0.0.0-20251202230838-ff82c1b0f217 // indirect
150+
google.golang.org/genproto/googleapis/rpc v0.0.0-20251202230838-ff82c1b0f217 // indirect
151+
google.golang.org/grpc v1.79.3 // indirect
152+
google.golang.org/protobuf v1.36.10
153153
gopkg.in/inf.v0 v0.9.1 // indirect
154154
gopkg.in/yaml.v3 v3.0.1 // indirect
155155
k8s.io/apiextensions-apiserver v0.34.1 // indirect

go.sum

Lines changed: 40 additions & 40 deletions
Large diffs are not rendered by default.

vendor/cel.dev/expr/BUILD.bazel

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -16,7 +16,6 @@ go_library(
1616
importpath = "cel.dev/expr",
1717
visibility = ["//visibility:public"],
1818
deps = [
19-
"@org_golang_google_genproto_googleapis_rpc//status:go_default_library",
2019
"@org_golang_google_protobuf//reflect/protoreflect",
2120
"@org_golang_google_protobuf//runtime/protoimpl",
2221
"@org_golang_google_protobuf//types/known/anypb",

vendor/cel.dev/expr/MODULE.bazel

Lines changed: 2 additions & 20 deletions
Original file line numberDiff line numberDiff line change
@@ -11,26 +11,9 @@ bazel_dep(
1111
version = "0.39.1",
1212
repo_name = "bazel_gazelle",
1313
)
14-
bazel_dep(
15-
name = "googleapis",
16-
version = "0.0.0-20241220-5e258e33.bcr.1",
17-
repo_name = "com_google_googleapis",
18-
)
19-
bazel_dep(
20-
name = "googleapis-cc",
21-
version = "1.0.0",
22-
)
23-
bazel_dep(
24-
name = "googleapis-java",
25-
version = "1.0.0",
26-
)
27-
bazel_dep(
28-
name = "googleapis-go",
29-
version = "1.0.0",
30-
)
3114
bazel_dep(
3215
name = "protobuf",
33-
version = "27.0",
16+
version = "27.1",
3417
repo_name = "com_google_protobuf",
3518
)
3619
bazel_dep(
@@ -63,12 +46,11 @@ python.toolchain(
6346
)
6447

6548
go_sdk = use_extension("@io_bazel_rules_go//go:extensions.bzl", "go_sdk")
66-
go_sdk.download(version = "1.22.0")
49+
go_sdk.download(version = "1.23.0")
6750

6851
go_deps = use_extension("@bazel_gazelle//:extensions.bzl", "go_deps")
6952
go_deps.from_file(go_mod = "//:go.mod")
7053
use_repo(
7154
go_deps,
72-
"org_golang_google_genproto_googleapis_rpc",
7355
"org_golang_google_protobuf",
7456
)

0 commit comments

Comments
 (0)