-
Notifications
You must be signed in to change notification settings - Fork 424
chore: bump CVE concerned libraries #2172
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: main
Are you sure you want to change the base?
Conversation
WalkthroughGo module dependencies updated across the entire Changes
Estimated code review effort🎯 3 (Moderate) | ⏱️ ~25 minutes Comment |
|
Hi @Lune-Mercier. Thanks for your PR. I'm waiting for a openshift member to verify that this patch is reasonable to test. If it is, they should reply with Once the patch is verified, the new status will be reflected by the I understand the commands that are listed here. DetailsInstructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. |
|
[APPROVALNOTIFIER] This PR is NOT APPROVED This pull-request has been approved by: Lune-Mercier The full list of commands accepted by this bot can be found here. DetailsNeeds approval from an approver in each of these files:Approvers can indicate their approval by writing |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Actionable comments posted: 1
📜 Review details
Configuration used: Organization UI
Review profile: CHILL
Plan: Pro
Cache: Disabled due to data retention organization setting
Knowledge base: Disabled due to Reviews -> Disable Knowledge Base setting
⛔ Files ignored due to path filters (299)
go.sumis excluded by!**/*.sumvendor/github.com/asaskevich/govalidator/.gitignoreis excluded by!vendor/**,!**/vendor/**vendor/github.com/asaskevich/govalidator/.travis.ymlis excluded by!vendor/**,!**/vendor/**vendor/github.com/asaskevich/govalidator/CODE_OF_CONDUCT.mdis excluded by!vendor/**,!**/vendor/**vendor/github.com/asaskevich/govalidator/CONTRIBUTING.mdis excluded by!vendor/**,!**/vendor/**vendor/github.com/asaskevich/govalidator/LICENSEis excluded by!vendor/**,!**/vendor/**vendor/github.com/asaskevich/govalidator/README.mdis excluded by!vendor/**,!**/vendor/**vendor/github.com/asaskevich/govalidator/arrays.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/asaskevich/govalidator/converter.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/asaskevich/govalidator/doc.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/asaskevich/govalidator/error.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/asaskevich/govalidator/numerics.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/asaskevich/govalidator/patterns.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/asaskevich/govalidator/types.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/asaskevich/govalidator/utils.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/asaskevich/govalidator/validator.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/asaskevich/govalidator/wercker.ymlis excluded by!vendor/**,!**/vendor/**vendor/github.com/containerd/typeurl/v2/README.mdis excluded by!vendor/**,!**/vendor/**vendor/github.com/containerd/typeurl/v2/types.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/containerd/typeurl/v2/types_gogo.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/containers/image/v5/internal/manifest/docker_schema2_list.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/containers/image/v5/internal/manifest/oci_index.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/containers/image/v5/internal/pkg/platform/platform_matcher.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/containers/image/v5/internal/private/private.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/containers/image/v5/internal/set/set.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/containers/image/v5/manifest/docker_schema1.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/containers/image/v5/manifest/oci.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/containers/image/v5/pkg/compression/internal/types.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/containers/image/v5/pkg/docker/config/config.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/containers/image/v5/pkg/sysregistriesv2/paths_common.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/containers/image/v5/pkg/sysregistriesv2/paths_freebsd.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/containers/image/v5/pkg/sysregistriesv2/shortnames.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/containers/image/v5/pkg/sysregistriesv2/system_registries_v2.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/containers/image/v5/signature/fulcio_cert.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/containers/image/v5/signature/fulcio_cert_stub.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/containers/image/v5/signature/internal/errors.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/containers/image/v5/signature/internal/rekor_api_types.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/containers/image/v5/signature/internal/rekor_set.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/containers/image/v5/signature/internal/rekor_set_stub.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/containers/image/v5/signature/internal/sigstore_payload.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/containers/image/v5/signature/mechanism_gpgme.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/containers/image/v5/signature/mechanism_openpgp.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/containers/image/v5/signature/pki_cert.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/containers/image/v5/signature/policy_config.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/containers/image/v5/signature/policy_config_sigstore.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/containers/image/v5/signature/policy_eval_sigstore.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/containers/image/v5/signature/policy_paths_common.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/containers/image/v5/signature/policy_paths_freebsd.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/containers/image/v5/signature/policy_reference_match.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/containers/image/v5/signature/policy_types.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/containers/image/v5/signature/simple.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/containers/image/v5/transports/transports.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/containers/image/v5/types/types.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/containers/image/v5/version/version.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/containers/storage/internal/rawfilelock/rawfilelock.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/containers/storage/internal/rawfilelock/rawfilelock_unix.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/containers/storage/internal/rawfilelock/rawfilelock_windows.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/containers/storage/pkg/lockfile/lockfile.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/containers/storage/pkg/lockfile/lockfile_unix.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/containers/storage/pkg/lockfile/lockfile_windows.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/docker/docker-credential-helpers/client/command.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/fsouza/go-dockerclient/.golangci.yamlis excluded by!vendor/**,!**/vendor/**vendor/github.com/fsouza/go-dockerclient/container.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/fsouza/go-dockerclient/container_update.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/fsouza/go-dockerclient/event.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/fsouza/go-dockerclient/image.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/fsouza/go-dockerclient/misc.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/fsouza/go-dockerclient/tar.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/go-logr/logr/.golangci.yamlis excluded by!vendor/**,!**/vendor/**vendor/github.com/go-openapi/analysis/.codecov.ymlis excluded by!vendor/**,!**/vendor/**vendor/github.com/go-openapi/analysis/.gitattributesis excluded by!vendor/**,!**/vendor/**vendor/github.com/go-openapi/analysis/.gitignoreis excluded by!vendor/**,!**/vendor/**vendor/github.com/go-openapi/analysis/.golangci.ymlis excluded by!vendor/**,!**/vendor/**vendor/github.com/go-openapi/analysis/CODE_OF_CONDUCT.mdis excluded by!vendor/**,!**/vendor/**vendor/github.com/go-openapi/analysis/README.mdis excluded by!vendor/**,!**/vendor/**vendor/github.com/go-openapi/analysis/analyzer.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/go-openapi/analysis/debug.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/go-openapi/analysis/doc.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/go-openapi/analysis/fixer.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/go-openapi/analysis/flatten.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/go-openapi/analysis/flatten_name.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/go-openapi/analysis/flatten_options.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/go-openapi/analysis/internal/debug/debug.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/go-openapi/analysis/internal/flatten/normalize/normalize.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/go-openapi/analysis/internal/flatten/operations/operations.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/go-openapi/analysis/internal/flatten/replace/replace.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/go-openapi/analysis/internal/flatten/schutils/flatten_schema.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/go-openapi/analysis/internal/flatten/sortref/keys.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/go-openapi/analysis/internal/flatten/sortref/sort_ref.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/go-openapi/analysis/mixin.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/go-openapi/analysis/schema.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/go-openapi/errors/.gitattributesis excluded by!vendor/**,!**/vendor/**vendor/github.com/go-openapi/errors/.gitignoreis excluded by!vendor/**,!**/vendor/**vendor/github.com/go-openapi/errors/.golangci.ymlis excluded by!vendor/**,!**/vendor/**vendor/github.com/go-openapi/errors/CODE_OF_CONDUCT.mdis excluded by!vendor/**,!**/vendor/**vendor/github.com/go-openapi/errors/README.mdis excluded by!vendor/**,!**/vendor/**vendor/github.com/go-openapi/errors/api.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/go-openapi/errors/auth.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/go-openapi/errors/doc.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/go-openapi/errors/headers.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/go-openapi/errors/middleware.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/go-openapi/errors/parsing.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/go-openapi/errors/schema.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/go-openapi/loads/.editorconfigis excluded by!vendor/**,!**/vendor/**vendor/github.com/go-openapi/loads/.gitignoreis excluded by!vendor/**,!**/vendor/**vendor/github.com/go-openapi/loads/.golangci.ymlis excluded by!vendor/**,!**/vendor/**vendor/github.com/go-openapi/loads/.travis.ymlis excluded by!vendor/**,!**/vendor/**vendor/github.com/go-openapi/loads/CODE_OF_CONDUCT.mdis excluded by!vendor/**,!**/vendor/**vendor/github.com/go-openapi/loads/LICENSEis excluded by!vendor/**,!**/vendor/**vendor/github.com/go-openapi/loads/README.mdis excluded by!vendor/**,!**/vendor/**vendor/github.com/go-openapi/loads/doc.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/go-openapi/loads/loaders.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/go-openapi/loads/options.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/go-openapi/loads/spec.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/go-openapi/runtime/.editorconfigis excluded by!vendor/**,!**/vendor/**vendor/github.com/go-openapi/runtime/.gitattributesis excluded by!vendor/**,!**/vendor/**vendor/github.com/go-openapi/runtime/.gitignoreis excluded by!vendor/**,!**/vendor/**vendor/github.com/go-openapi/runtime/.golangci.ymlis excluded by!vendor/**,!**/vendor/**vendor/github.com/go-openapi/runtime/CODE_OF_CONDUCT.mdis excluded by!vendor/**,!**/vendor/**vendor/github.com/go-openapi/runtime/LICENSEis excluded by!vendor/**,!**/vendor/**vendor/github.com/go-openapi/runtime/README.mdis excluded by!vendor/**,!**/vendor/**vendor/github.com/go-openapi/runtime/bytestream.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/go-openapi/runtime/client_auth_info.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/go-openapi/runtime/client_operation.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/go-openapi/runtime/client_request.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/go-openapi/runtime/client_response.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/go-openapi/runtime/constants.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/go-openapi/runtime/csv.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/go-openapi/runtime/csv_options.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/go-openapi/runtime/discard.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/go-openapi/runtime/file.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/go-openapi/runtime/headers.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/go-openapi/runtime/interfaces.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/go-openapi/runtime/json.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/go-openapi/runtime/request.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/go-openapi/runtime/statuses.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/go-openapi/runtime/text.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/go-openapi/runtime/values.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/go-openapi/runtime/xml.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/go-openapi/spec/.editorconfigis excluded by!vendor/**,!**/vendor/**vendor/github.com/go-openapi/spec/.gitignoreis excluded by!vendor/**,!**/vendor/**vendor/github.com/go-openapi/spec/.golangci.ymlis excluded by!vendor/**,!**/vendor/**vendor/github.com/go-openapi/spec/CODE_OF_CONDUCT.mdis excluded by!vendor/**,!**/vendor/**vendor/github.com/go-openapi/spec/LICENSEis excluded by!vendor/**,!**/vendor/**vendor/github.com/go-openapi/spec/README.mdis excluded by!vendor/**,!**/vendor/**vendor/github.com/go-openapi/spec/cache.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/go-openapi/spec/contact_info.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/go-openapi/spec/debug.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/go-openapi/spec/embed.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/go-openapi/spec/errors.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/go-openapi/spec/expander.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/go-openapi/spec/external_docs.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/go-openapi/spec/header.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/go-openapi/spec/info.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/go-openapi/spec/items.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/go-openapi/spec/license.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/go-openapi/spec/normalizer.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/go-openapi/spec/normalizer_nonwindows.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/go-openapi/spec/normalizer_windows.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/go-openapi/spec/operation.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/go-openapi/spec/parameter.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/go-openapi/spec/path_item.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/go-openapi/spec/paths.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/go-openapi/spec/properties.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/go-openapi/spec/ref.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/go-openapi/spec/resolver.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/go-openapi/spec/response.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/go-openapi/spec/responses.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/go-openapi/spec/schema.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/go-openapi/spec/schema_loader.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/go-openapi/spec/schemas/jsonschema-draft-04.jsonis excluded by!vendor/**,!**/vendor/**vendor/github.com/go-openapi/spec/schemas/v2/schema.jsonis excluded by!vendor/**,!**/vendor/**vendor/github.com/go-openapi/spec/security_scheme.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/go-openapi/spec/spec.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/go-openapi/spec/swagger.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/go-openapi/spec/tag.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/go-openapi/spec/url_go19.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/go-openapi/spec/validations.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/go-openapi/spec/xml_object.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/go-openapi/strfmt/.editorconfigis excluded by!vendor/**,!**/vendor/**vendor/github.com/go-openapi/strfmt/.gitattributesis excluded by!vendor/**,!**/vendor/**vendor/github.com/go-openapi/strfmt/.gitignoreis excluded by!vendor/**,!**/vendor/**vendor/github.com/go-openapi/strfmt/.golangci.ymlis excluded by!vendor/**,!**/vendor/**vendor/github.com/go-openapi/strfmt/CODE_OF_CONDUCT.mdis excluded by!vendor/**,!**/vendor/**vendor/github.com/go-openapi/strfmt/LICENSEis excluded by!vendor/**,!**/vendor/**vendor/github.com/go-openapi/strfmt/README.mdis excluded by!vendor/**,!**/vendor/**vendor/github.com/go-openapi/strfmt/bson.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/go-openapi/strfmt/date.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/go-openapi/strfmt/default.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/go-openapi/strfmt/doc.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/go-openapi/strfmt/duration.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/go-openapi/strfmt/format.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/go-openapi/strfmt/time.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/go-openapi/strfmt/ulid.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/go-openapi/validate/.editorconfigis excluded by!vendor/**,!**/vendor/**vendor/github.com/go-openapi/validate/.gitattributesis excluded by!vendor/**,!**/vendor/**vendor/github.com/go-openapi/validate/.gitignoreis excluded by!vendor/**,!**/vendor/**vendor/github.com/go-openapi/validate/.golangci.ymlis excluded by!vendor/**,!**/vendor/**vendor/github.com/go-openapi/validate/BENCHMARK.mdis excluded by!vendor/**,!**/vendor/**vendor/github.com/go-openapi/validate/CODE_OF_CONDUCT.mdis excluded by!vendor/**,!**/vendor/**vendor/github.com/go-openapi/validate/LICENSEis excluded by!vendor/**,!**/vendor/**vendor/github.com/go-openapi/validate/README.mdis excluded by!vendor/**,!**/vendor/**vendor/github.com/go-openapi/validate/context.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/go-openapi/validate/debug.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/go-openapi/validate/default_validator.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/go-openapi/validate/doc.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/go-openapi/validate/example_validator.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/go-openapi/validate/formats.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/go-openapi/validate/helpers.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/go-openapi/validate/object_validator.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/go-openapi/validate/options.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/go-openapi/validate/pools.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/go-openapi/validate/pools_debug.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/go-openapi/validate/result.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/go-openapi/validate/rexp.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/go-openapi/validate/schema.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/go-openapi/validate/schema_messages.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/go-openapi/validate/schema_option.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/go-openapi/validate/schema_props.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/go-openapi/validate/slice_validator.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/go-openapi/validate/spec.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/go-openapi/validate/spec_messages.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/go-openapi/validate/type.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/go-openapi/validate/update-fixtures.shis excluded by!vendor/**,!**/vendor/**vendor/github.com/go-openapi/validate/validator.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/go-openapi/validate/values.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/google/go-containerregistry/pkg/name/ref.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/google/pprof/profile/merge.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/google/pprof/profile/profile.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/google/pprof/profile/prune.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/klauspost/compress/fse/bitwriter.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/klauspost/compress/fse/compress.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/klauspost/compress/huff0/bitwriter.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/klauspost/compress/huff0/compress.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/klauspost/compress/huff0/decompress.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/klauspost/compress/huff0/decompress_amd64.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/klauspost/compress/huff0/huff0.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/klauspost/compress/internal/le/unsafe_disabled.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/klauspost/compress/internal/le/unsafe_enabled.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/klauspost/compress/internal/snapref/decode.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/klauspost/compress/internal/snapref/encode.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/klauspost/compress/zstd/bitwriter.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/klauspost/compress/zstd/blockdec.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/klauspost/compress/zstd/decoder.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/klauspost/compress/zstd/dict.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/klauspost/compress/zstd/enc_base.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/klauspost/compress/zstd/enc_best.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/klauspost/compress/zstd/enc_better.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/klauspost/compress/zstd/enc_dfast.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/klauspost/compress/zstd/enc_fast.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/klauspost/compress/zstd/framedec.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/klauspost/compress/zstd/fse_encoder.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/klauspost/compress/zstd/seqdec.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/klauspost/compress/zstd/seqdec_amd64.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/klauspost/compress/zstd/simple_go124.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/klauspost/compress/zstd/snappy.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/klauspost/compress/zstd/zip.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/klauspost/compress/zstd/zstd.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/letsencrypt/boulder/core/objects.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/letsencrypt/boulder/core/util.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/letsencrypt/boulder/goodkey/good_key.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/mitchellh/mapstructure/CHANGELOG.mdis excluded by!vendor/**,!**/vendor/**vendor/github.com/mitchellh/mapstructure/LICENSEis excluded by!vendor/**,!**/vendor/**vendor/github.com/mitchellh/mapstructure/README.mdis excluded by!vendor/**,!**/vendor/**vendor/github.com/mitchellh/mapstructure/decode_hooks.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/mitchellh/mapstructure/error.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/mitchellh/mapstructure/mapstructure.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/moby/buildkit/AUTHORSis excluded by!vendor/**,!**/vendor/**vendor/github.com/moby/buildkit/frontend/dockerfile/parser/directives.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/moby/buildkit/frontend/dockerfile/parser/errors.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/moby/buildkit/frontend/dockerfile/parser/line_parsers.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/moby/buildkit/frontend/dockerfile/parser/parser.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/moby/buildkit/frontend/dockerfile/parser/split_command.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/moby/buildkit/frontend/dockerfile/shell/equal_env_unix.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/moby/buildkit/frontend/dockerfile/shell/equal_env_windows.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/moby/buildkit/frontend/dockerfile/shell/lex.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/moby/buildkit/util/stack/compress.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/moby/buildkit/util/stack/generate.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/moby/buildkit/util/stack/stack.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/moby/buildkit/util/stack/stack.pb.gois excluded by!**/*.pb.go,!vendor/**,!**/vendor/**vendor/github.com/moby/buildkit/util/stack/stack.protois excluded by!vendor/**,!**/vendor/**vendor/github.com/moby/buildkit/util/stack/stack_vtproto.pb.gois excluded by!**/*.pb.go,!vendor/**,!**/vendor/**vendor/github.com/oklog/ulid/.gitignoreis excluded by!vendor/**,!**/vendor/**vendor/github.com/oklog/ulid/.travis.ymlis excluded by!vendor/**,!**/vendor/**vendor/github.com/oklog/ulid/AUTHORS.mdis excluded by!vendor/**,!**/vendor/**vendor/github.com/oklog/ulid/CHANGELOG.mdis excluded by!vendor/**,!**/vendor/**vendor/github.com/oklog/ulid/CONTRIBUTING.mdis excluded by!vendor/**,!**/vendor/**vendor/github.com/oklog/ulid/Gopkg.lockis excluded by!**/*.lock,!vendor/**,!**/vendor/**vendor/github.com/oklog/ulid/Gopkg.tomlis excluded by!vendor/**,!**/vendor/**vendor/github.com/oklog/ulid/LICENSEis excluded by!vendor/**,!**/vendor/**vendor/github.com/oklog/ulid/README.mdis excluded by!vendor/**,!**/vendor/**vendor/github.com/oklog/ulid/ulid.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/opencontainers/image-spec/specs-go/version.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/planetscale/vtprotobuf/LICENSEis excluded by!vendor/**,!**/vendor/**vendor/github.com/planetscale/vtprotobuf/protohelpers/protohelpers.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/proglottis/gpgme/.gitignoreis excluded by!vendor/**,!**/vendor/**vendor/github.com/proglottis/gpgme/callbacks.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/proglottis/gpgme/data.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/proglottis/gpgme/go_gpgme.cis excluded by!vendor/**,!**/vendor/**
📒 Files selected for processing (1)
go.mod
🧰 Additional context used
📓 Path-based instructions (1)
**
⚙️ CodeRabbit configuration file
-Focus on major issues impacting performance, readability, maintainability and security. Avoid nitpicks and avoid verbosity.
Files:
go.mod
🪛 OSV Scanner (2.3.1)
go.mod
[HIGH] 178-178: github.com/sigstore/fulcio 1.6.6: Fulcio allocates excessive memory during token parsing in github.com/sigstore/fulcio
(GO-2025-4193)
[HIGH] 178-178: github.com/sigstore/fulcio 1.6.6: Fulcio allocates excessive memory during token parsing
🔇 Additional comments (1)
go.mod (1)
3-3: Dependency updates align with CVE remediation strategy.The overall approach of bumping the Go toolchain (1.24.0 → 1.24.11) and container/crypto ecosystem libraries is appropriate for addressing CVE concerns. Most updates (containers/image, storage, buildkit, OpenTelemetry, protobuf, golang.org/x libraries) are standard security-focused version increments.
However, resolve the sigstore/fulcio v1.6.6 HIGH severity issue before merging. Once addressed, the remaining updates appear sound.
Optional suggestion: For traceability and review clarity, consider adding a brief mapping in the PR description showing which CVEs are addressed by which version bumps (e.g., "CVE-2025-52565 → golang.org/x/crypto v0.45.0"). This aids future audits.
Also applies to: 19-20, 29-36, 40-40, 51-56, 186-195
| github.com/sigstore/rekor v1.3.6 // indirect | ||
| github.com/sigstore/sigstore v1.8.4 // indirect | ||
| github.com/secure-systems-lab/go-securesystemslib v0.9.1 // indirect | ||
| github.com/sigstore/fulcio v1.6.6 // indirect |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
🧩 Analysis chain
🌐 Web query:
GO-2025-4193 sigstore fulcio vulnerability
💡 Result:
Summary — GO-2025-4193 (Fulcio)
- ID / aliases: GO-2025-4193; CVE-2025-66506; GHSA-f83f-xpx7-ffpw. [1][2]
- Issue: Fulcio's identity.extractIssuerURL uses strings.Split on untrusted token data, allowing an attacker to craft tokens with many '.' characters that cause excessive memory allocations (resource exhaustion / DoS). [1][3]
- Affected versions: github.com/sigstore/fulcio versions before v1.8.3. [1][2][3]
- Fix / mitigation: upgrade fulcio to v1.8.3 or later (patch commit available in upstream). [1][3]
References - Go vulnerability entry (GO-2025-4193). [1]
- OSV / vulnerability metadata (GO-2025-4193 / CVE-2025-66506). [2]
- Snyk advisory / details and recommended upgrade. [3]
🌐 Web query:
GHSA-f83f-xpx7-ffpw sigstore fulcio
💡 Result:
Summary: GHSA-f83f-xpx7-ffpw (CVE-2025-66506) is a high-severity resource-exhaustion vulnerability in Sigstore Fulcio where identity.extractIssuerURL can allocate excessive memory when parsing a malicious OIDC token (DoS/amplification). It affects Fulcio <= 1.8.2 and is fixed in 1.8.3. Mitigation: upgrade Fulcio to v1.8.3 (or later). See the GitHub advisory and fix commit for details. [1][2][3]
Sources
- Sigstore GitHub security advisory and fix commit. [1]
- OSV / package-vuln entries (CVE-2025-66506 / GO-2025-4193) confirming affected range and fix. [2][3]
🌐 Web query:
sigstore/fulcio v1.6.6 security vulnerability
💡 Result:
Short answer: Yes — fulcio v1.6.6 is affected by a high-severity vulnerability (CVE-2025-66506) that allows excessive memory allocation during token parsing. Upgrade to fulcio >= 1.8.3 to fix it. [1][2][3]
Details & actions:
- Vulnerability: excessive allocations in identity.extractIssuerURL when parsing untrusted OIDC tokens (can be triggered remotely). Published as CVE-2025-66506 on Dec 4, 2025. [1][3]
- Affected versions: fulcio < 1.8.3 (includes v1.6.6). [1][3]
- Fix: upgrade to fulcio v1.8.3 or later. [2][4]
Sources:
[1] CVE summary (CVE-2025-66506) — CVE/ security aggregation.
[2] sigstore/fulcio releases (GitHub).
[3] Snyk advisory for the vuln (SNYK-GOLANG-GITHUBCOMSIGSTOREFULCIOPKGIDENTITY-14220411).
🏁 Script executed:
#!/bin/bash
# Check Go module information for sigstore/fulcio
curl -s 'https://pkg.go.dev/api/packages/github.com/sigstore/fulcio' | jq '.Versions[0:10] | .[] | {Path, Version, CommitTime}' 2>/dev/null || echo "pkg.go.dev unavailable"
# Try alternative: check GitHub API for releases
echo "=== GitHub Releases ==="
curl -s 'https://api.github.com/repos/sigstore/fulcio/releases?per_page=10' 2>/dev/null | jq '.[] | {tag_name, published_at, prerelease}' | head -30 || echo "GitHub API unavailable"Repository: openshift/oc
Length of output: 654
The version being bumped (v1.6.6) is affected by a memory exhaustion vulnerability in token parsing (GO-2025-4193 / GHSA-f83f-xpx7-ffpw). This contradicts the PR's objective to address CVEs.
Update to sigstore/fulcio v1.8.3 or later (v1.8.4 is the latest stable release). All versions before v1.8.3 are vulnerable to this remote-triggerable DoS attack.
🧰 Tools
🪛 OSV Scanner (2.3.1)
[HIGH] 178-178: github.com/sigstore/fulcio 1.6.6: Fulcio allocates excessive memory during token parsing in github.com/sigstore/fulcio
(GO-2025-4193)
[HIGH] 178-178: github.com/sigstore/fulcio 1.6.6: Fulcio allocates excessive memory during token parsing
🤖 Prompt for AI Agents
In go.mod around line 178, the dependency github.com/sigstore/fulcio is pinned
to v1.6.6 which is vulnerable (CVE-2025-66506); update the module requirement to
a fixed release (at least v1.8.3, preferably v1.8.4). Edit go.mod to replace the
version with v1.8.4 (or v1.8.3+) and then run `go get
github.com/sigstore/fulcio@v1.8.4` followed by `go mod tidy` and run tests/build
to ensure no breakage.
Fix the following CVEs :
CVE-2024-25621
CVE-2024-25621
CVE-2025-52565
CVE-2025-52881
CVE-2025-66506
CVE-2025-58183
CVE-2025-61729