Skip to content

Commit 28d3ef6

Browse files
committed
[YUNIKORN-3238] otel sdk update (cve fix) (#1006)
Update otel and related dependencies to latest releases for CVE fix. Closes: #1006 Signed-off-by: Wilfred Spiegelenburg <wilfreds@apache.org>
1 parent 5c0612c commit 28d3ef6

2 files changed

Lines changed: 105 additions & 95 deletions

File tree

go.mod

Lines changed: 31 additions & 39 deletions
Original file line numberDiff line numberDiff line change
@@ -18,9 +18,7 @@
1818

1919
module github.com/apache/yunikorn-k8shim
2020

21-
go 1.24.0
22-
23-
toolchain go1.24.11
21+
go 1.25.0
2422

2523
require (
2624
github.com/apache/yunikorn-core v0.0.0-20251201043909-11c0a7a644a1
@@ -49,15 +47,15 @@ require (
4947
)
5048

5149
require (
52-
cel.dev/expr v0.24.0 // indirect
50+
cel.dev/expr v0.25.1 // indirect
5351
github.com/Azure/go-ansiterm v0.0.0-20230124172434-306776ec8161 // indirect
5452
github.com/Azure/go-ntlmssp v0.0.0-20221128193559-754e69321358 // indirect
5553
github.com/Masterminds/semver/v3 v3.4.0 // indirect
5654
github.com/NYTimes/gziphandler v1.1.1 // indirect
5755
github.com/antlr4-go/antlr/v4 v4.13.0 // indirect
5856
github.com/beorn7/perks v1.0.1 // indirect
5957
github.com/blang/semver/v4 v4.0.0 // indirect
60-
github.com/cenkalti/backoff/v4 v4.3.0 // indirect
58+
github.com/cenkalti/backoff/v5 v5.0.3 // indirect
6159
github.com/cespare/xxhash/v2 v2.3.0 // indirect
6260
github.com/coreos/go-semver v0.3.1 // indirect
6361
github.com/coreos/go-systemd/v22 v22.5.0 // indirect
@@ -85,7 +83,7 @@ require (
8583
github.com/gorilla/websocket v1.5.4-0.20250319132907-e064f32e3674 // indirect
8684
github.com/gregjones/httpcache v0.0.0-20190611155906-901d90724c79 // indirect
8785
github.com/grpc-ecosystem/go-grpc-prometheus v1.2.0 // indirect
88-
github.com/grpc-ecosystem/grpc-gateway/v2 v2.26.3 // indirect
86+
github.com/grpc-ecosystem/grpc-gateway/v2 v2.28.0 // indirect
8987
github.com/inconshreveable/mousetrap v1.1.0 // indirect
9088
github.com/josharian/intern v1.0.0 // indirect
9189
github.com/json-iterator/go v1.1.12 // indirect
@@ -116,33 +114,33 @@ require (
116114
go.etcd.io/etcd/api/v3 v3.6.4 // indirect
117115
go.etcd.io/etcd/client/pkg/v3 v3.6.4 // indirect
118116
go.etcd.io/etcd/client/v3 v3.6.4 // indirect
119-
go.opentelemetry.io/auto/sdk v1.1.0 // indirect
120-
go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc v0.60.0 // indirect
121-
go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.58.0 // indirect
122-
go.opentelemetry.io/otel v1.35.0 // indirect
123-
go.opentelemetry.io/otel/exporters/otlp/otlptrace v1.34.0 // indirect
124-
go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc v1.34.0 // indirect
125-
go.opentelemetry.io/otel/metric v1.35.0 // indirect
126-
go.opentelemetry.io/otel/sdk v1.34.0 // indirect
127-
go.opentelemetry.io/otel/trace v1.35.0 // indirect
128-
go.opentelemetry.io/proto/otlp v1.5.0 // indirect
117+
go.opentelemetry.io/auto/sdk v1.2.1 // indirect
118+
go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc v0.67.0 // indirect
119+
go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.67.0 // indirect
120+
go.opentelemetry.io/otel v1.42.0 // indirect
121+
go.opentelemetry.io/otel/exporters/otlp/otlptrace v1.42.0 // indirect
122+
go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc v1.42.0 // indirect
123+
go.opentelemetry.io/otel/metric v1.42.0 // indirect
124+
go.opentelemetry.io/otel/sdk v1.42.0 // indirect
125+
go.opentelemetry.io/otel/trace v1.42.0 // indirect
126+
go.opentelemetry.io/proto/otlp v1.9.0 // indirect
129127
go.uber.org/multierr v1.11.0 // indirect
130128
go.yaml.in/yaml/v2 v2.4.2 // indirect
131-
golang.org/x/crypto v0.44.0 // indirect
129+
golang.org/x/crypto v0.49.0 // indirect
132130
golang.org/x/exp v0.0.0-20250228200357-dead58393ab7 // indirect
133-
golang.org/x/mod v0.30.0 // indirect
134-
golang.org/x/net v0.47.0 // indirect
135-
golang.org/x/oauth2 v0.30.0 // indirect
136-
golang.org/x/sync v0.18.0 // indirect
137-
golang.org/x/sys v0.38.0 // indirect
138-
golang.org/x/term v0.37.0 // indirect
139-
golang.org/x/text v0.31.0 // indirect
131+
golang.org/x/mod v0.33.0 // indirect
132+
golang.org/x/net v0.51.0 // indirect
133+
golang.org/x/oauth2 v0.35.0 // indirect
134+
golang.org/x/sync v0.20.0 // indirect
135+
golang.org/x/sys v0.42.0 // indirect
136+
golang.org/x/term v0.41.0 // indirect
137+
golang.org/x/text v0.35.0 // indirect
140138
golang.org/x/time v0.10.0 // indirect
141-
golang.org/x/tools v0.39.0 // indirect
142-
google.golang.org/genproto/googleapis/api v0.0.0-20250303144028-a0af3efb3deb // indirect
143-
google.golang.org/genproto/googleapis/rpc v0.0.0-20250303144028-a0af3efb3deb // indirect
144-
google.golang.org/grpc v1.72.1 // indirect
145-
google.golang.org/protobuf v1.36.8 // indirect
139+
golang.org/x/tools v0.42.0 // indirect
140+
google.golang.org/genproto/googleapis/api v0.0.0-20260209200024-4cfbd4190f57 // indirect
141+
google.golang.org/genproto/googleapis/rpc v0.0.0-20260226221140-a57be14db171 // indirect
142+
google.golang.org/grpc v1.79.2 // indirect
143+
google.golang.org/protobuf v1.36.11 // indirect
146144
gopkg.in/evanphx/json-patch.v4 v4.12.0 // indirect
147145
gopkg.in/inf.v0 v0.9.1 // indirect
148146
gopkg.in/natefinch/lumberjack.v2 v2.2.1 // indirect
@@ -166,16 +164,10 @@ require (
166164
)
167165

168166
replace (
169-
golang.org/x/crypto => golang.org/x/crypto v0.45.0
170-
golang.org/x/lint => golang.org/x/lint v0.0.0-20210508222113-6edffad5e616
171-
golang.org/x/net => golang.org/x/net v0.47.0
172-
golang.org/x/oauth2 => golang.org/x/oauth2 v0.33.0
173-
golang.org/x/sync => golang.org/x/sync v0.18.0
174-
golang.org/x/sys => golang.org/x/sys v0.39.0
175-
golang.org/x/term => golang.org/x/term v0.37.0
176-
golang.org/x/text => golang.org/x/text v0.31.0
177-
golang.org/x/time => golang.org/x/time v0.14.0
178-
golang.org/x/tools => golang.org/x/tools v0.39.0
167+
golang.org/x/mod => golang.org/x/mod v0.34.0
168+
golang.org/x/net => golang.org/x/net v0.52.0
169+
golang.org/x/oauth2 => golang.org/x/oauth2 v0.36.0
170+
golang.org/x/time => golang.org/x/time v0.15.0
179171
k8s.io/api => k8s.io/api v0.34.2
180172
k8s.io/apiextensions-apiserver => k8s.io/apiextensions-apiserver v0.34.2
181173
k8s.io/apimachinery => k8s.io/apimachinery v0.34.2

0 commit comments

Comments
 (0)