4bdfd3b684
vendor: golang.org/x/crypto v0.35.0
...
We have tagged version v0.35.0 of golang.org/x/crypto in order to address
a security issue. Version v0.35.0 of golang.org/x/crypto fixes a vulnerability
in the golang.org/x/crypto/ssh package which could cause a denial of service.
SSH servers which implement file transfer protocols are vulnerable to a denial
of service attack from clients which complete the key exchange slowly, or not
at all, causing pending content to be read into memory, but never transmitted.
Thanks to Yuichi Watanabe for reporting this issue.
This is CVE-2025-22869 and Go issue https://go.dev/issue/71931 .
full diff: https://github.com/golang/crypto/compare/v0.31.0...v0.35.0
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2025-03-10 20:04:11 +01:00
09caaa312d
vendor: golang.org/x/crypto v0.34.0
...
No code-changes, but updates the minimum go version to go1.23:
> all: upgrade go directive to at least 1.23.0 [generated]
>
> By now Go 1.24.0 has been released, and Go 1.22 is no longer supported
> per the Go Release Policy (https://go.dev/doc/devel/release#policy ).
>
> For golang/go#69095 .
full diff: https://github.com/golang/crypto/compare/v0.31.0...v0.34.0
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2025-03-10 20:04:11 +01:00
4dfe7ad85e
vendor: golang.org/x/text v0.22.0
...
no code-changes in vendored files.
full diff: https://github.com/golang/text/compare/v0.21.0...v0.22.0
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2025-03-10 20:04:11 +01:00
3cdc44568d
vendor: golang.org/x/sync v0.11.0
...
no code-changes, only a godoc comment updated
full diff: https://github.com/golang/sync/compare/v0.10.0...v0.11.0
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2025-03-10 20:04:11 +01:00
19ce7f2eaf
vendor: golang.org/x/sys v0.30.0
...
full diff: https://github.com/golang/sys/compare/v0.29.0...v0.30.0
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2025-03-10 20:04:10 +01:00
b2a669fb56
vendor: github.com/docker/docker-credential-helpers v0.9.2
...
full diff: https://github.com/docker/docker-credential-helpers/compare/v0.8.2...v0.9.2
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2025-03-05 22:38:56 +01:00
9e997a57fa
vendor: github.com/docker/docker v28.0.1
...
full diff: https://github.com/docker/docker/compare/af898abe4466...v28.0.1
Signed-off-by: Paweł Gronowski <pawel.gronowski@docker.com >
2025-02-26 15:32:31 +01:00
75595836f2
vendor: github.com/go-jose/go-jose/v4 v4.0.5
...
- Don't allow unbounded amounts of splits.
Fixes GHSA-c6gw-w398-hv78 / CVE-2025-27144
- Various other dependency updates, small fixes, and documentation
updates in the full changelog
full diff: https://github.com/go-jose/go-jose/compare/v4.0.4...v4.0.5
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2025-02-25 11:55:06 +01:00
33f327a98f
vendor: github.com/docker/docker v28.0.0-dev (af898abe4466)
...
full diff: https://github.com/docker/docker/compare/v28.0.0-rc.3...af898abe4466
Signed-off-by: Paweł Gronowski <pawel.gronowski@docker.com >
2025-02-19 22:55:43 +01:00
f53cee5dd1
vendor: github.com/docker/docker v28.0.0-rc.3
...
no diff; same commit, but tagged:
https://github.com/docker/docker/compare/00ab386b5a2e...v28.0.0-rc.3
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2025-02-19 13:48:22 +01:00
fe349e6a6c
vendor: github.com/docker/docker 00ab386b5a2e (master, v28.0.0-rc.3)
...
no code changes, only updated swagger (docs)
full diff: https://github.com/docker/docker/compare/v28.0.0-rc.2...00ab386b5a2e
Signed-off-by: Paweł Gronowski <pawel.gronowski@docker.com >
2025-02-18 23:04:48 +01:00
136901961d
vendor: github.com/docker/docker v28.0.0-rc.2
...
no diff; same commit, but tagged;
https://github.com/docker/docker/compare/57d4d23825f4...v28.0.0-rc.2
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2025-02-18 13:40:15 +01:00
c2ba77de49
vendor: github.com/docker/docker 57d4d23825f4 (master, v28.0.0-rc.2)
...
no changes in vendored code
full diff: 5cc3f1dab8...57d4d23825
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2025-02-17 11:57:23 +01:00
1d3eb6f95b
vendor: github.com/docker/docker 5cc3f1dab895 (master, v28.0.0-rc.2)
...
full diff: b570831cc3...5cc3f1dab8
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2025-02-14 19:22:53 +01:00
591fcb273a
vendor: golang.org/x/sys v0.29.0
...
full diff: https://github.com/golang/sys/compare/v0.28.0...v0.29.0
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2025-02-14 17:29:51 +01:00
c6a7f9a646
vendor: github.com/docker/docker b570831cc3a3 (master, v28.0.0-rc.2)
...
full diff: https://github.com/docker/docker/compare/v28.0.0-rc.1...b570831cc3a3fcfe4edc96af4c249199b019c7dd
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2025-02-11 18:06:55 +01:00
018bf1b237
vendor: google.golang.org/grpc v1.69.4
...
full diff: https://github.com/grpc/grpc-go/compare/v1.68.1...v1.69.4
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2025-02-11 15:55:27 +01:00
558ebd5922
vendor: github.com/spf13/pflag v1.0.6, remove local IPNetSliceVar fork
...
- Add exported functions to preserve pkg/flag compatibility
- Add IPNetSlice and unit tests
- Revert the local fork added in 80a2256478 ,
which was pending the upstream feature to be shipped in a release.
full diff: https://github.com/spf13/pflag/compare/v1.0.5...v1.0.6
Revert "Swarm init: use local IPNetSliceValue"
This reverts commit 80a2256478 .
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2025-02-11 12:19:51 +01:00
661d079b1e
Merge pull request #5805 from thaJeztah/vendor_28.0.0-rc.1
...
vendor: github.com/docker/docker/v28.0.0-rc.1
2025-02-10 10:32:17 +00:00
df8c19d8fd
vendor: gotest.tools/v3 v3.5.2
...
- un-deprecates `assert.ErrorType`, `cmp.ErrorType`
- assert: ensure message is always displayed and fix under bazel
- poll: Continue(): use format.Message for formatting
- fix TestFromDirSymlink on Windows due to missing drive-letter
- fix various linting issues and minor bugs
full diff: https://github.com/gotestyourself/gotest.tools/compare/v3.5.1...v3.5.2
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2025-02-09 13:39:45 +01:00
3c0d703acd
vendor: github.com/docker/docker/v28.0.0-rc.1
...
no diff; same code but tagged
full diff: https://github.com/docker/docker/compare/6c3797923dcb...v28.0.0-rc.1
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2025-02-07 01:38:33 +01:00
01da8a582f
vendor: github.com/docker/docker 6c3797923dcb (master, v28.0-dev)
...
full diff: 6968719093...6c3797923d
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2025-02-06 19:16:50 +01:00
88755df233
Merge pull request #5741 from thaJeztah/vendor_cli_docs_tool
...
update cli-docs-tool to v0.9.0, go-md2man v2.0.6
2025-01-14 19:36:26 +01:00
2f42b32722
vendor: otel v0.56.0 / v1.31.0
...
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2025-01-14 19:09:03 +01:00
3d9b861165
vendor: github.com/mattn/go-runewidth v0.0.16
...
adds support for Unicode 15.1.0
full diff: https://github.com/mattn/go-runewidth/compare/v0.0.15...v0.0.16
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2025-01-14 15:18:35 +01:00
25bdd5ced6
Merge pull request #5747 from thaJeztah/vendor_containerd_platforms
...
vendor: github.com/containerd/platforms v1.0.0-rc.1
2025-01-14 15:13:42 +01:00
5896278838
Merge pull request #5745 from thaJeztah/vendor_grpc_v1.68.1
...
vendor: google.golang.org/grpc v1.68.1, google.golang.org/genproto 324edc3d5d38
2025-01-14 15:07:58 +01:00
aa540679e4
vendor: github.com/containerd/platforms v1.0.0-rc.1
...
full diff: https://github.com/containerd/platforms/compare/v0.2.1...v1.0.0-rc.1
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2025-01-14 14:28:53 +01:00
d3ca995857
vendor: github.com/creack/pty v1.1.24
...
full diff: https://github.com/creack/pty/compare/v1.1.21...v1.1.24
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2025-01-14 13:41:12 +01:00
b412f7199a
vendor: google.golang.org/grpc v1.68.1, google.golang.org/genproto 324edc3d5d38
...
full diff: https://github.com/grpc/grpc-go/compare/v1.66.3...v1.68.1
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2025-01-14 13:31:06 +01:00
6f3ba987b1
vendor: github.com/docker/cli-docs-tool v0.9.0
...
full diff: https://github.com/docker/cli-docs-tool/compare/v0.8.0...v0.9.0
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2025-01-13 18:58:31 +01:00
0df55307c8
vendor: github.com/docker/docker 69687190936d (master, v28.0-dev)
...
full diff: 50212d215b...6968719093
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2025-01-11 01:17:36 +01:00
216674c3e3
vendor: github.com/docker/docker 50212d215ba7 (master, v28.0-dev)
...
full diff: 6f6c3b9211...50212d215b
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2025-01-08 18:11:19 +01:00
a289f11ac8
vendor: github.com/moby/swarmkit/v2 v2.0.0-20250103191802-8c1959736554
...
no changes in vendored code
full diff: e8ecf83ee0...8c19597365
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2025-01-06 10:28:35 +01:00
2fc32c707b
vendor: github.com/moby/term v0.5.2
...
- update github.com/Azure/go-ansiterm to v0.0.0-20250102033503-faa5f7b0171c
to fix OSC string terminator parsing.
- add security policy
- update github actions and test against go1.22, go1.23
full diff: https://github.com/moby/term/compare/v0.5.0...v0.5.2
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2025-01-03 22:33:30 +01:00
e1a0c377b7
vendor: github.com/Azure/go-ansiterm faa5f7b0171c
...
- fix OSC string terminator parsing
diff: d185dfc1b5...faa5f7b017
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2025-01-03 22:32:37 +01:00
25f02bc044
vendor: github.com/docker/docker 6f6c3b921180 (master, v28.0.0-dev)
...
full diff: a72026acbb...6f6c3b9211
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2025-01-01 16:24:28 +01:00
76ec0ea2eb
vendor: github.com/docker/docker a72026acbbdf (master, v28.0.0-dev)
...
removes uses of pkg/system
full diff: ad6929339a...a72026acbb
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2024-12-23 13:50:59 +01:00
cc65127cb0
vendor: github.com/docker/docker ad6929339acd (master, v28.0.0-dev)
...
full diff: b249c5ebd2...ad6929339a
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2024-12-20 17:58:34 +01:00
6f47bce41c
vendor: golang.org/x/net v0.33.0
...
contains a fix for CVE-2024-45338 / https://go.dev/issue/70906 ,
but it doesn't affect our codebase:
govulncheck -show=verbose ./...
Scanning your code and 1260 packages across 211 dependent modules for known vulnerabilities...
...
Vulnerability #1 : GO-2024-3333
Non-linear parsing of case-insensitive content in golang.org/x/net/html
More info: https://pkg.go.dev/vuln/GO-2024-3333
Module: golang.org/x/net
Found in: golang.org/x/net@v0.32 .0
Fixed in: golang.org/x/net@v0.33 .0
Your code is affected by 0 vulnerabilities.
This scan also found 0 vulnerabilities in packages you import and 1
vulnerability in modules you require, but your code doesn't appear to call these
vulnerabilities.
full diff: https://github.com/golang/net/compare/v0.32.0...v0.33.0
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2024-12-20 17:12:38 +01:00
83156e6627
vendor: golang.org/x/net v0.32.0
...
go maintainers annnounced a security release for this module; this patch
already brings it up to the current version in case the security issue
affects us.
full diff: https://github.com/golang/net/compare/v0.31.0...v0.32.0
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2024-12-16 23:01:20 +01:00
450f6b9955
vendor: golang.org/x/crypto v0.31.0
...
update to the latest version of this dependency, which has a fix for a
authorization bypass in the ssh package. We don't use this functionality,
so there's no need to backport this change (other than de-noising false positives).
This is CVE-2024-45337 and Go issue https://go.dev/issue/70779 .
full diff: https://github.com/golang/crypto/compare/v0.29.0...v0.31.0
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2024-12-16 22:59:33 +01:00
b74302eb50
vendor: golang.org/x/text v0.21.0
...
no changes in vendored code
full diff: https://github.com/golang/text/compare/v0.20.0...v0.21.0
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2024-12-16 22:58:24 +01:00
cb2e35286c
vendor: golang.org/x/sync v0.10.0
...
no changes in vendored code
full diff: https://github.com/golang/sync/compare/v0.9.0...v0.10.0
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2024-12-16 22:57:35 +01:00
e56b665d81
vendor: golang.org/x/sys v0.28.0
...
full diff: https://github.com/golang/sys/compare/v0.27.0...v0.28.0
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2024-12-16 22:56:51 +01:00
2a5ac8f5ab
vendor: github.com/docker/docker b249c5ebd214 (master, v28.0.0-dev)
...
full diff: 5d72419486...b249c5ebd2
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2024-12-09 21:56:05 +01:00
2eb77f4ede
vendor: github.com/docker/docker 5d72419486fe (master, v28.0.0-dev)
...
full diff: 87fbd9cd3b...5d72419486
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2024-12-09 12:41:45 +01:00
9dfdffa015
Merge pull request #5672 from thaJeztah/bump_protobuf
...
vendor: google.golang.org/protobuf v1.35.2
2024-12-09 12:11:31 +01:00
f50dea6c40
vendor: google.golang.org/protobuf v1.35.2
...
full diff: https://github.com/protocolbuffers/protobuf-go/compare/v1.35.1...v1.35.2
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2024-12-06 22:45:30 +01:00
9399483f7a
vendor: golang.org/x/net v0.31.0
...
full diff: https://github.com/golang/net/compare/v0.30.0...v0.31.0
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2024-12-06 22:40:39 +01:00