Skip to content

Commit 736f440

Browse files
committed
fix: bump grpc and opentelemetry to resolve dependabot alerts
- google.golang.org/grpc v1.59.0 -> v1.80.0 Closes GHSA-p77j-4mvh-x3m3 / CVE-2026-33186 (authorization bypass via missing leading slash in :path) - go.opentelemetry.io/otel/sdk v1.20.0 -> v1.43.0 (and core siblings) Closes GHSA-hfvc-g4fc-pqhx / CVE-2026-39883 (BSD kenv command not using absolute path -> PATH hijacking) Contrib packages (otelgrpc, otelhttp) pinned at v0.50.0 rather than @latest because k8s.io/apiserver v0.27.2 (pulled transitively) still calls the legacy UnaryClientInterceptor/StreamClientInterceptor and otelhttp.WithPublicEndpoint APIs, which were removed in later contrib releases. Staying on v0.50.0 keeps the k8s.io/* line at v0.27.2. Go directive moves 1.24.1 -> 1.25.0 (required by the otel v1.43.0 dependency graph); Dockerfile base image follows to golang:1.25.0.
1 parent 8757067 commit 736f440

3 files changed

Lines changed: 99 additions & 103 deletions

File tree

Dockerfile

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,4 @@
1-
FROM golang:1.24.1 as builder
1+
FROM golang:1.25.0 as builder
22

33
ARG VERSION=dev
44

go.mod

Lines changed: 30 additions & 29 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
module github.com/civo/civo-cloud-controller-manager
22

3-
go 1.24.1
3+
go 1.25.0
44

55
require (
66
github.com/civo/civogo v0.3.96
@@ -22,8 +22,8 @@ require (
2222
github.com/asaskevich/govalidator v0.0.0-20190424111038-f61b66f89f4a // indirect
2323
github.com/beorn7/perks v1.0.1 // indirect
2424
github.com/blang/semver/v4 v4.0.0 // indirect
25-
github.com/cenkalti/backoff/v4 v4.2.1 // indirect
26-
github.com/cespare/xxhash/v2 v2.2.0 // indirect
25+
github.com/cenkalti/backoff/v5 v5.0.3 // indirect
26+
github.com/cespare/xxhash/v2 v2.3.0 // indirect
2727
github.com/coreos/go-semver v0.3.0 // indirect
2828
github.com/coreos/go-systemd/v22 v22.4.0 // indirect
2929
github.com/davecgh/go-spew v1.1.1 // indirect
@@ -32,22 +32,22 @@ require (
3232
github.com/evanphx/json-patch/v5 v5.6.0 // indirect
3333
github.com/felixge/httpsnoop v1.0.4 // indirect
3434
github.com/fsnotify/fsnotify v1.6.0 // indirect
35-
github.com/go-logr/logr v1.4.1 // indirect
35+
github.com/go-logr/logr v1.4.3 // indirect
3636
github.com/go-logr/stdr v1.2.2 // indirect
3737
github.com/go-openapi/jsonpointer v0.19.6 // indirect
3838
github.com/go-openapi/jsonreference v0.20.1 // indirect
3939
github.com/go-openapi/swag v0.22.3 // indirect
4040
github.com/gogo/protobuf v1.3.2 // indirect
4141
github.com/golang/groupcache v0.0.0-20210331224755-41bb18bfe9da // indirect
42-
github.com/golang/protobuf v1.5.3 // indirect
42+
github.com/golang/protobuf v1.5.4 // indirect
4343
github.com/google/cel-go v0.12.6 // indirect
4444
github.com/google/gnostic v0.5.7-v3refs // indirect
45-
github.com/google/go-cmp v0.6.0 // indirect
45+
github.com/google/go-cmp v0.7.0 // indirect
4646
github.com/google/go-querystring v1.1.0 // indirect
4747
github.com/google/gofuzz v1.1.0 // indirect
48-
github.com/google/uuid v1.3.1 // indirect
48+
github.com/google/uuid v1.6.0 // indirect
4949
github.com/grpc-ecosystem/go-grpc-prometheus v1.2.0 // indirect
50-
github.com/grpc-ecosystem/grpc-gateway/v2 v2.16.0 // indirect
50+
github.com/grpc-ecosystem/grpc-gateway/v2 v2.28.0 // indirect
5151
github.com/imdario/mergo v0.3.6 // indirect
5252
github.com/inconshreveable/mousetrap v1.0.1 // indirect
5353
github.com/josharian/intern v1.0.0 // indirect
@@ -70,32 +70,33 @@ require (
7070
go.etcd.io/etcd/api/v3 v3.5.7 // indirect
7171
go.etcd.io/etcd/client/pkg/v3 v3.5.7 // indirect
7272
go.etcd.io/etcd/client/v3 v3.5.7 // indirect
73-
go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc v0.46.0 // indirect
74-
go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.45.0 // indirect
75-
go.opentelemetry.io/otel v1.20.0 // indirect
76-
go.opentelemetry.io/otel/exporters/otlp/otlptrace v1.20.0 // indirect
77-
go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc v1.20.0 // indirect
78-
go.opentelemetry.io/otel/metric v1.20.0 // indirect
79-
go.opentelemetry.io/otel/sdk v1.20.0 // indirect
80-
go.opentelemetry.io/otel/trace v1.20.0 // indirect
81-
go.opentelemetry.io/proto/otlp v1.0.0 // indirect
73+
go.opentelemetry.io/auto/sdk v1.2.1 // indirect
74+
go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc v0.50.0 // indirect
75+
go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.50.0 // indirect
76+
go.opentelemetry.io/otel v1.43.0 // indirect
77+
go.opentelemetry.io/otel/exporters/otlp/otlptrace v1.43.0 // indirect
78+
go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc v1.43.0 // indirect
79+
go.opentelemetry.io/otel/metric v1.43.0 // indirect
80+
go.opentelemetry.io/otel/sdk v1.43.0 // indirect
81+
go.opentelemetry.io/otel/trace v1.43.0 // indirect
82+
go.opentelemetry.io/proto/otlp v1.10.0 // indirect
8283
go.uber.org/atomic v1.7.0 // indirect
8384
go.uber.org/multierr v1.6.0 // indirect
8485
go.uber.org/zap v1.24.0 // indirect
85-
golang.org/x/crypto v0.45.0 // indirect
86-
golang.org/x/mod v0.29.0 // indirect
87-
golang.org/x/net v0.47.0 // indirect
88-
golang.org/x/oauth2 v0.27.0 // indirect
89-
golang.org/x/sync v0.18.0 // indirect
90-
golang.org/x/sys v0.38.0 // indirect
91-
golang.org/x/term v0.37.0 // indirect
92-
golang.org/x/text v0.31.0 // indirect
86+
golang.org/x/crypto v0.49.0 // indirect
87+
golang.org/x/mod v0.33.0 // indirect
88+
golang.org/x/net v0.52.0 // indirect
89+
golang.org/x/oauth2 v0.35.0 // indirect
90+
golang.org/x/sync v0.20.0 // indirect
91+
golang.org/x/sys v0.42.0 // indirect
92+
golang.org/x/term v0.41.0 // indirect
93+
golang.org/x/text v0.35.0 // indirect
9394
golang.org/x/time v0.3.0 // indirect
9495
google.golang.org/genproto v0.0.0-20230822172742-b8732ec3820d // indirect
95-
google.golang.org/genproto/googleapis/api v0.0.0-20230822172742-b8732ec3820d // indirect
96-
google.golang.org/genproto/googleapis/rpc v0.0.0-20230822172742-b8732ec3820d // indirect
97-
google.golang.org/grpc v1.59.0 // indirect
98-
google.golang.org/protobuf v1.33.0 // indirect
96+
google.golang.org/genproto/googleapis/api v0.0.0-20260401024825-9d38bb4040a9 // indirect
97+
google.golang.org/genproto/googleapis/rpc v0.0.0-20260406210006-6f92a3bedf2d // indirect
98+
google.golang.org/grpc v1.80.0 // indirect
99+
google.golang.org/protobuf v1.36.11 // indirect
99100
gopkg.in/inf.v0 v0.9.1 // indirect
100101
gopkg.in/natefinch/lumberjack.v2 v2.0.0 // indirect
101102
gopkg.in/yaml.v2 v2.4.0 // indirect

0 commit comments

Comments
 (0)