Skip to content

Commit 9cfa8cd

Browse files
authored
CVE-2025-30204: bump github.com/golang-jwt/jwt/v4 to v4.5.2 (#218)
* CVE-2025-30204: bump github.com/golang-jwt/jwt/v4 to v4.5.2 * CVE-2025-30204: bump github.com/IBM/secret-utils-lib to v1.1.12
1 parent 08fe882 commit 9cfa8cd

File tree

26 files changed

+42
-1760
lines changed

26 files changed

+42
-1760
lines changed

go.mod

Lines changed: 2 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -6,7 +6,7 @@ require (
66
github.com/IBM/ibm-csi-common v1.1.18
77
github.com/IBM/ibmcloud-volume-interface v1.2.9
88
github.com/IBM/ibmcloud-volume-vpc v1.1.15
9-
github.com/IBM/secret-utils-lib v1.1.11
9+
github.com/IBM/secret-utils-lib v1.1.12
1010
github.com/container-storage-interface/spec v1.9.0
1111
github.com/golang/glog v1.2.4
1212
github.com/google/uuid v1.6.0
@@ -50,8 +50,7 @@ require (
5050
github.com/go-playground/validator/v10 v10.19.0 // indirect
5151
github.com/gofrs/uuid v4.4.0+incompatible // indirect
5252
github.com/gogo/protobuf v1.3.2 // indirect
53-
github.com/golang-jwt/jwt v3.2.2+incompatible // indirect
54-
github.com/golang-jwt/jwt/v4 v4.5.1 // indirect
53+
github.com/golang-jwt/jwt/v4 v4.5.2 // indirect
5554
github.com/golang/groupcache v0.0.0-20210331224755-41bb18bfe9da // indirect
5655
github.com/golang/protobuf v1.5.4 // indirect
5756
github.com/google/gnostic-models v0.6.8 // indirect

go.sum

Lines changed: 4 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -14,8 +14,8 @@ github.com/IBM/ibmcloud-volume-vpc v1.1.15 h1:0TsFcTX8Enbma+gq3Lp9dNqB0NzlzGw+SR
1414
github.com/IBM/ibmcloud-volume-vpc v1.1.15/go.mod h1:CSAsBgEXN6WL8y/EpEj9GA+w+vs3fVLoRadtuCWUAz8=
1515
github.com/IBM/secret-common-lib v1.1.11 h1:EpfEe1gT1bnFQ3bxQPrh6bzTPeGjUo1NReVkCCP+TOc=
1616
github.com/IBM/secret-common-lib v1.1.11/go.mod h1:7YJF0ipT979nHIPkiCpvjFboFoIhrmYnIliE1vjCjZM=
17-
github.com/IBM/secret-utils-lib v1.1.11 h1:w87BzkddoFFlhRuWRteuGj3/561lEUg6Oo0RajVC87A=
18-
github.com/IBM/secret-utils-lib v1.1.11/go.mod h1:3a82l1ZnbKGKq5yvtuU9EKa0ghIrUdyM49t87i59MYc=
17+
github.com/IBM/secret-utils-lib v1.1.12 h1:ASilsVPL6NnyUqPu5v/x3a083lrmXkNU+NIJJAobLOY=
18+
github.com/IBM/secret-utils-lib v1.1.12/go.mod h1:qvQihdfmhHrUjyh4f0rbqMHPMXA2G9W8mx39zyZSizU=
1919
github.com/asaskevich/govalidator v0.0.0-20230301143203-a9d515a09cc2 h1:DklsrG3dyBCFEj5IhUbnKptjxatkF07cF2ak3yi77so=
2020
github.com/asaskevich/govalidator v0.0.0-20230301143203-a9d515a09cc2/go.mod h1:WaHUgvxTVq04UNunO+XhnAqY/wQc+bxr74GqbsZ/Jqw=
2121
github.com/beorn7/perks v1.0.1 h1:VlbKKnNfV8bJzeqoa4cOKqO6bYr3WgKZxO8Z16+hsOM=
@@ -85,10 +85,8 @@ github.com/gofrs/uuid v4.4.0+incompatible h1:3qXRTX8/NbyulANqlc0lchS1gqAVxRgsuW1
8585
github.com/gofrs/uuid v4.4.0+incompatible/go.mod h1:b2aQJv3Z4Fp6yNu3cdSllBxTCLRxnplIgP/c0N/04lM=
8686
github.com/gogo/protobuf v1.3.2 h1:Ov1cvc58UF3b5XjBnZv7+opcTcQFZebYjWzi34vdm4Q=
8787
github.com/gogo/protobuf v1.3.2/go.mod h1:P1XiOD3dCwIKUDQYPy72D8LYyHL2YPYrpS2s69NZV8Q=
88-
github.com/golang-jwt/jwt v3.2.2+incompatible h1:IfV12K8xAKAnZqdXVzCZ+TOjboZ2keLg81eXfW3O+oY=
89-
github.com/golang-jwt/jwt v3.2.2+incompatible/go.mod h1:8pz2t5EyA70fFQQSrl6XZXzqecmYZeUEB8OUGHkxJ+I=
90-
github.com/golang-jwt/jwt/v4 v4.5.1 h1:JdqV9zKUdtaa9gdPlywC3aeoEsR681PlKC+4F5gQgeo=
91-
github.com/golang-jwt/jwt/v4 v4.5.1/go.mod h1:m21LjoU+eqJr34lmDMbreY2eSTRJ1cv77w39/MY0Ch0=
88+
github.com/golang-jwt/jwt/v4 v4.5.2 h1:YtQM7lnr8iZ+j5q71MGKkNw9Mn7AjHM68uc9g5fXeUI=
89+
github.com/golang-jwt/jwt/v4 v4.5.2/go.mod h1:m21LjoU+eqJr34lmDMbreY2eSTRJ1cv77w39/MY0Ch0=
9290
github.com/golang/glog v0.0.0-20160126235308-23def4e6c14b/go.mod h1:SBH7ygxi8pfUlaOkMMuAQtPIUF8ecWP5IEl/CR7VP2Q=
9391
github.com/golang/glog v1.2.4 h1:CNNw5U8lSiiBk7druxtSHHTsRWcxKoac6kZKm2peBBc=
9492
github.com/golang/glog v1.2.4/go.mod h1:6AhwSGph0fcJtXVM/PEHPqZlFeoLxhs7/t5UDAwmO+w=

vendor/github.com/IBM/secret-utils-lib/pkg/token/token.go

Lines changed: 1 addition & 1 deletion
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

vendor/github.com/golang-jwt/jwt/.gitignore

Lines changed: 0 additions & 4 deletions
This file was deleted.

vendor/github.com/golang-jwt/jwt/LICENSE

Lines changed: 0 additions & 9 deletions
This file was deleted.

vendor/github.com/golang-jwt/jwt/MIGRATION_GUIDE.md

Lines changed: 0 additions & 22 deletions
This file was deleted.

vendor/github.com/golang-jwt/jwt/README.md

Lines changed: 0 additions & 113 deletions
This file was deleted.

0 commit comments

Comments
 (0)