Skip to content

Commit 6a1ca83

Browse files
szhGitHub Enterprise
authored andcommitted
Merge pull request #43 from Conjur-Enterprise/CVE-2024-45338
Bump golang.org/x/net to v0.33.0 to address CVE-2024-45338
2 parents b653ab9 + 9f31e4b commit 6a1ca83

File tree

5 files changed

+106
-82
lines changed

5 files changed

+106
-82
lines changed

CHANGELOG.md

Lines changed: 8 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -10,6 +10,11 @@ and this project adheres to [Semantic Versioning](http://semver.org/spec/v2.0.0.
1010
- Nothing should go in this section, please add to the latest unreleased version
1111
(and update the corresponding date), or add a new version.
1212

13+
## [1.7.26] - 2024-12-27
14+
15+
### Security
16+
- Update golang.org/x/net to v0.33.0 to resolve CVE-2024-45338
17+
1318
## [1.7.25] - 2024-12-16
1419

1520
### Security
@@ -742,7 +747,7 @@ and this project adheres to [Semantic Versioning](http://semver.org/spec/v2.0.0.
742747
### Added
743748
- The first tagged version.
744749

745-
[Unreleased]: https://github.com/cyberark/secretless-broker/compare/v1.7.24...HEAD
750+
[Unreleased]: https://github.com/cyberark/secretless-broker/compare/v1.7.26...HEAD
746751
[0.2.0]: https://github.com/cyberark/secretless-broker/compare/v0.1.0...v0.2.0
747752
[0.3.0]: https://github.com/cyberark/secretless-broker/compare/v0.2.0...v0.3.0
748753
[0.4.0]: https://github.com/cyberark/secretless-broker/compare/v0.3.0...v0.4.0
@@ -792,3 +797,5 @@ and this project adheres to [Semantic Versioning](http://semver.org/spec/v2.0.0.
792797
[1.7.22]: https://github.com/cyberark/secretless-broker/compare/v1.7.21...v1.7.22
793798
[1.7.23]: https://github.com/cyberark/secretless-broker/compare/v1.7.22...v1.7.23
794799
[1.7.24]: https://github.com/cyberark/secretless-broker/compare/v1.7.23...v1.7.24
800+
[1.7.25]: https://github.com/cyberark/secretless-broker/compare/v1.7.24...v1.7.25
801+
[1.7.26]: https://github.com/cyberark/secretless-broker/compare/v1.7.25...v1.7.26

docs/Gemfile

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -37,3 +37,7 @@ gem 'jekyll-redirect-from'
3737
gem 'kramdown', '>= 2.3.0'
3838

3939
gem 'webrick', '~> 1.7'
40+
41+
gem 'csv'
42+
gem 'base64'
43+
gem 'bigdecimal'

docs/Gemfile.lock

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -3,8 +3,11 @@ GEM
33
specs:
44
addressable (2.8.6)
55
public_suffix (>= 2.0.2, < 6.0)
6+
base64 (0.2.0)
7+
bigdecimal (3.1.9)
68
colorator (1.1.0)
79
concurrent-ruby (1.2.3)
10+
csv (3.3.2)
811
em-websocket (0.5.3)
912
eventmachine (>= 0.12.9)
1013
http_parser.rb (~> 0)
@@ -76,6 +79,9 @@ PLATFORMS
7679
ruby
7780

7881
DEPENDENCIES
82+
base64
83+
bigdecimal
84+
csv
7985
jekyll (~> 4.3.3)
8086
jekyll-feed (~> 0.17)
8187
jekyll-redirect-from

go.mod

Lines changed: 68 additions & 62 deletions
Original file line numberDiff line numberDiff line change
@@ -94,7 +94,7 @@ require (
9494
github.com/golang-sql/civil v0.0.0-20190719163853-cb61b32ac6fe // indirect
9595
github.com/golang/protobuf v1.5.3 // indirect
9696
github.com/golang/snappy v0.0.4 // indirect
97-
github.com/google/go-cmp v0.5.9 // indirect
97+
github.com/google/go-cmp v0.6.0 // indirect
9898
github.com/google/gofuzz v1.2.0 // indirect
9999
github.com/hashicorp/errwrap v1.1.0 // indirect
100100
github.com/hashicorp/go-cleanhttp v0.5.2 // indirect
@@ -130,7 +130,7 @@ require (
130130
go.opentelemetry.io/otel/exporters/stdout/stdouttrace v1.7.0 // indirect
131131
go.opentelemetry.io/otel/sdk v1.7.0 // indirect
132132
go.opentelemetry.io/otel/trace v1.7.0 // indirect
133-
golang.org/x/net v0.24.0 // indirect
133+
golang.org/x/net v0.33.0 // indirect
134134
golang.org/x/oauth2 v0.11.0 // indirect
135135
golang.org/x/sys v0.28.0 // indirect
136136
golang.org/x/term v0.27.0 // indirect
@@ -235,125 +235,131 @@ replace golang.org/x/crypto v0.0.0-20211215153901-e495a2d5b3d3 => golang.org/x/c
235235

236236
replace golang.org/x/crypto v0.0.0-20220214200702-86341886e292 => golang.org/x/crypto v0.2.0
237237

238-
replace golang.org/x/net v0.0.0-20180530234432-1e491301e022 => golang.org/x/net v0.24.0
238+
replace golang.org/x/net v0.0.0-20180530234432-1e491301e022 => golang.org/x/net v0.33.0
239239

240-
replace golang.org/x/net v0.0.0-20180724234803-3673e40ba225 => golang.org/x/net v0.24.0
240+
replace golang.org/x/net v0.0.0-20180724234803-3673e40ba225 => golang.org/x/net v0.33.0
241241

242-
replace golang.org/x/net v0.0.0-20180826012351-8a410e7b638d => golang.org/x/net v0.24.0
242+
replace golang.org/x/net v0.0.0-20180826012351-8a410e7b638d => golang.org/x/net v0.33.0
243243

244-
replace golang.org/x/net v0.0.0-20180906233101-161cd47e91fd => golang.org/x/net v0.24.0
244+
replace golang.org/x/net v0.0.0-20180906233101-161cd47e91fd => golang.org/x/net v0.33.0
245245

246-
replace golang.org/x/net v0.0.0-20181023162649-9b4f9f5ad519 => golang.org/x/net v0.24.0
246+
replace golang.org/x/net v0.0.0-20181023162649-9b4f9f5ad519 => golang.org/x/net v0.33.0
247247

248-
replace golang.org/x/net v0.0.0-20181114220301-adae6a3d119a => golang.org/x/net v0.24.0
248+
replace golang.org/x/net v0.0.0-20181114220301-adae6a3d119a => golang.org/x/net v0.33.0
249249

250-
replace golang.org/x/net v0.0.0-20181201002055-351d144fa1fc => golang.org/x/net v0.24.0
250+
replace golang.org/x/net v0.0.0-20181201002055-351d144fa1fc => golang.org/x/net v0.33.0
251251

252-
replace golang.org/x/net v0.0.0-20181220203305-927f97764cc3 => golang.org/x/net v0.24.0
252+
replace golang.org/x/net v0.0.0-20181220203305-927f97764cc3 => golang.org/x/net v0.33.0
253253

254-
replace golang.org/x/net v0.0.0-20190108225652-1e06a53dbb7e => golang.org/x/net v0.24.0
254+
replace golang.org/x/net v0.0.0-20190108225652-1e06a53dbb7e => golang.org/x/net v0.33.0
255255

256-
replace golang.org/x/net v0.0.0-20190213061140-3a22650c66bd => golang.org/x/net v0.24.0
256+
replace golang.org/x/net v0.0.0-20190213061140-3a22650c66bd => golang.org/x/net v0.33.0
257257

258-
replace golang.org/x/net v0.0.0-20190311183353-d8887717615a => golang.org/x/net v0.24.0
258+
replace golang.org/x/net v0.0.0-20190311183353-d8887717615a => golang.org/x/net v0.33.0
259259

260-
replace golang.org/x/net v0.0.0-20190404232315-eb5bcb51f2a3 => golang.org/x/net v0.24.0
260+
replace golang.org/x/net v0.0.0-20190404232315-eb5bcb51f2a3 => golang.org/x/net v0.33.0
261261

262-
replace golang.org/x/net v0.0.0-20190501004415-9ce7a6920f09 => golang.org/x/net v0.24.0
262+
replace golang.org/x/net v0.0.0-20190501004415-9ce7a6920f09 => golang.org/x/net v0.33.0
263263

264-
replace golang.org/x/net v0.0.0-20190503192946-f4e77d36d62c => golang.org/x/net v0.24.0
264+
replace golang.org/x/net v0.0.0-20190503192946-f4e77d36d62c => golang.org/x/net v0.33.0
265265

266-
replace golang.org/x/net v0.0.0-20190603091049-60506f45cf65 => golang.org/x/net v0.24.0
266+
replace golang.org/x/net v0.0.0-20190603091049-60506f45cf65 => golang.org/x/net v0.33.0
267267

268-
replace golang.org/x/net v0.0.0-20190613194153-d28f0bde5980 => golang.org/x/net v0.24.0
268+
replace golang.org/x/net v0.0.0-20190613194153-d28f0bde5980 => golang.org/x/net v0.33.0
269269

270-
replace golang.org/x/net v0.0.0-20190620200207-3b0461eec859 => golang.org/x/net v0.24.0
270+
replace golang.org/x/net v0.0.0-20190620200207-3b0461eec859 => golang.org/x/net v0.33.0
271271

272-
replace golang.org/x/net v0.0.0-20190628185345-da137c7871d7 => golang.org/x/net v0.24.0
272+
replace golang.org/x/net v0.0.0-20190628185345-da137c7871d7 => golang.org/x/net v0.33.0
273273

274-
replace golang.org/x/net v0.0.0-20190724013045-ca1201d0de80 => golang.org/x/net v0.24.0
274+
replace golang.org/x/net v0.0.0-20190724013045-ca1201d0de80 => golang.org/x/net v0.33.0
275275

276-
replace golang.org/x/net v0.0.0-20190827160401-ba9fcec4b297 => golang.org/x/net v0.24.0
276+
replace golang.org/x/net v0.0.0-20190827160401-ba9fcec4b297 => golang.org/x/net v0.33.0
277277

278-
replace golang.org/x/net v0.0.0-20191209160850-c0dbc17a3553 => golang.org/x/net v0.24.0
278+
replace golang.org/x/net v0.0.0-20191209160850-c0dbc17a3553 => golang.org/x/net v0.33.0
279279

280-
replace golang.org/x/net v0.0.0-20200114155413-6afb5195e5aa => golang.org/x/net v0.24.0
280+
replace golang.org/x/net v0.0.0-20200114155413-6afb5195e5aa => golang.org/x/net v0.33.0
281281

282-
replace golang.org/x/net v0.0.0-20200202094626-16171245cfb2 => golang.org/x/net v0.24.0
282+
replace golang.org/x/net v0.0.0-20200202094626-16171245cfb2 => golang.org/x/net v0.33.0
283283

284-
replace golang.org/x/net v0.0.0-20200222125558-5a598a2470a0 => golang.org/x/net v0.24.0
284+
replace golang.org/x/net v0.0.0-20200222125558-5a598a2470a0 => golang.org/x/net v0.33.0
285285

286-
replace golang.org/x/net v0.0.0-20200226121028-0de0cce0169b => golang.org/x/net v0.24.0
286+
replace golang.org/x/net v0.0.0-20200226121028-0de0cce0169b => golang.org/x/net v0.33.0
287287

288-
replace golang.org/x/net v0.0.0-20200301022130-244492dfa37a => golang.org/x/net v0.24.0
288+
replace golang.org/x/net v0.0.0-20200301022130-244492dfa37a => golang.org/x/net v0.33.0
289289

290-
replace golang.org/x/net v0.0.0-20200324143707-d3edc9973b7e => golang.org/x/net v0.24.0
290+
replace golang.org/x/net v0.0.0-20200324143707-d3edc9973b7e => golang.org/x/net v0.33.0
291291

292-
replace golang.org/x/net v0.0.0-20200501053045-e0ff5e5a1de5 => golang.org/x/net v0.24.0
292+
replace golang.org/x/net v0.0.0-20200501053045-e0ff5e5a1de5 => golang.org/x/net v0.33.0
293293

294-
replace golang.org/x/net v0.0.0-20200506145744-7e3656a0809f => golang.org/x/net v0.24.0
294+
replace golang.org/x/net v0.0.0-20200506145744-7e3656a0809f => golang.org/x/net v0.33.0
295295

296-
replace golang.org/x/net v0.0.0-20200513185701-a91f0712d120 => golang.org/x/net v0.24.0
296+
replace golang.org/x/net v0.0.0-20200513185701-a91f0712d120 => golang.org/x/net v0.33.0
297297

298-
replace golang.org/x/net v0.0.0-20200520004742-59133d7f0dd7 => golang.org/x/net v0.24.0
298+
replace golang.org/x/net v0.0.0-20200520004742-59133d7f0dd7 => golang.org/x/net v0.33.0
299299

300-
replace golang.org/x/net v0.0.0-20200520182314-0ba52f642ac2 => golang.org/x/net v0.24.0
300+
replace golang.org/x/net v0.0.0-20200520182314-0ba52f642ac2 => golang.org/x/net v0.33.0
301301

302-
replace golang.org/x/net v0.0.0-20200625001655-4c5254603344 => golang.org/x/net v0.24.0
302+
replace golang.org/x/net v0.0.0-20200625001655-4c5254603344 => golang.org/x/net v0.33.0
303303

304-
replace golang.org/x/net v0.0.0-20200707034311-ab3426394381 => golang.org/x/net v0.24.0
304+
replace golang.org/x/net v0.0.0-20200707034311-ab3426394381 => golang.org/x/net v0.33.0
305305

306-
replace golang.org/x/net v0.0.0-20200822124328-c89045814202 => golang.org/x/net v0.24.0
306+
replace golang.org/x/net v0.0.0-20200822124328-c89045814202 => golang.org/x/net v0.33.0
307307

308-
replace golang.org/x/net v0.0.0-20201006153459-a7d1128ccaa0 => golang.org/x/net v0.24.0
308+
replace golang.org/x/net v0.0.0-20201006153459-a7d1128ccaa0 => golang.org/x/net v0.33.0
309309

310-
replace golang.org/x/net v0.0.0-20201021035429-f5854403a974 => golang.org/x/net v0.24.0
310+
replace golang.org/x/net v0.0.0-20201021035429-f5854403a974 => golang.org/x/net v0.33.0
311311

312-
replace golang.org/x/net v0.0.0-20201031054903-ff519b6c9102 => golang.org/x/net v0.24.0
312+
replace golang.org/x/net v0.0.0-20201031054903-ff519b6c9102 => golang.org/x/net v0.33.0
313313

314-
replace golang.org/x/net v0.0.0-20201110031124-69a78807bb2b => golang.org/x/net v0.24.0
314+
replace golang.org/x/net v0.0.0-20201110031124-69a78807bb2b => golang.org/x/net v0.33.0
315315

316-
replace golang.org/x/net v0.0.0-20201202161906-c7110b5ffcbb => golang.org/x/net v0.24.0
316+
replace golang.org/x/net v0.0.0-20201202161906-c7110b5ffcbb => golang.org/x/net v0.33.0
317317

318-
replace golang.org/x/net v0.0.0-20201209123823-ac852fbbde11 => golang.org/x/net v0.24.0
318+
replace golang.org/x/net v0.0.0-20201209123823-ac852fbbde11 => golang.org/x/net v0.33.0
319319

320-
replace golang.org/x/net v0.0.0-20210119194325-5f4716e94777 => golang.org/x/net v0.24.0
320+
replace golang.org/x/net v0.0.0-20210119194325-5f4716e94777 => golang.org/x/net v0.33.0
321321

322-
replace golang.org/x/net v0.0.0-20210226172049-e18ecbb05110 => golang.org/x/net v0.24.0
322+
replace golang.org/x/net v0.0.0-20210226172049-e18ecbb05110 => golang.org/x/net v0.33.0
323323

324-
replace golang.org/x/net v0.0.0-20210316092652-d523dce5a7f4 => golang.org/x/net v0.24.0
324+
replace golang.org/x/net v0.0.0-20210316092652-d523dce5a7f4 => golang.org/x/net v0.33.0
325325

326-
replace golang.org/x/net v0.0.0-20210405180319-a5a99cb37ef4 => golang.org/x/net v0.24.0
326+
replace golang.org/x/net v0.0.0-20210405180319-a5a99cb37ef4 => golang.org/x/net v0.33.0
327327

328-
replace golang.org/x/net v0.0.0-20210428140749-89ef3d95e781 => golang.org/x/net v0.24.0
328+
replace golang.org/x/net v0.0.0-20210428140749-89ef3d95e781 => golang.org/x/net v0.33.0
329329

330-
replace golang.org/x/net v0.0.0-20210525063256-abc453219eb5 => golang.org/x/net v0.24.0
330+
replace golang.org/x/net v0.0.0-20210525063256-abc453219eb5 => golang.org/x/net v0.33.0
331331

332-
replace golang.org/x/net v0.0.0-20210825183410-e898025ed96a => golang.org/x/net v0.24.0
332+
replace golang.org/x/net v0.0.0-20210825183410-e898025ed96a => golang.org/x/net v0.33.0
333333

334-
replace golang.org/x/net v0.0.0-20211015210444-4f30a5c0130f => golang.org/x/net v0.24.0
334+
replace golang.org/x/net v0.0.0-20211015210444-4f30a5c0130f => golang.org/x/net v0.33.0
335335

336-
replace golang.org/x/net v0.0.0-20211112202133-69e39bad7dc2 => golang.org/x/net v0.24.0
336+
replace golang.org/x/net v0.0.0-20211112202133-69e39bad7dc2 => golang.org/x/net v0.33.0
337337

338-
replace golang.org/x/net v0.0.0-20211216030914-fe4d6282115f => golang.org/x/net v0.24.0
338+
replace golang.org/x/net v0.0.0-20211216030914-fe4d6282115f => golang.org/x/net v0.33.0
339339

340-
replace golang.org/x/net v0.0.0-20220127200216-cd36cc0744dd => golang.org/x/net v0.24.0
340+
replace golang.org/x/net v0.0.0-20220127200216-cd36cc0744dd => golang.org/x/net v0.33.0
341341

342-
replace golang.org/x/net v0.0.0-20220225172249-27dd8689420f => golang.org/x/net v0.24.0
342+
replace golang.org/x/net v0.0.0-20220225172249-27dd8689420f => golang.org/x/net v0.33.0
343343

344-
replace golang.org/x/net v0.0.0-20220722155237-a158d28d115b => golang.org/x/net v0.24.0
344+
replace golang.org/x/net v0.0.0-20220722155237-a158d28d115b => golang.org/x/net v0.33.0
345345

346-
replace golang.org/x/net v0.0.0-20220923203811-8be639271d50 => golang.org/x/net v0.24.0
346+
replace golang.org/x/net v0.0.0-20220923203811-8be639271d50 => golang.org/x/net v0.33.0
347347

348-
replace golang.org/x/net v0.2.0 => golang.org/x/net v0.24.0
348+
replace golang.org/x/net v0.2.0 => golang.org/x/net v0.33.0
349349

350-
replace golang.org/x/net v0.5.0 => golang.org/x/net v0.24.0
350+
replace golang.org/x/net v0.5.0 => golang.org/x/net v0.33.0
351351

352-
replace golang.org/x/net v0.6.0 => golang.org/x/net v0.24.0
352+
replace golang.org/x/net v0.6.0 => golang.org/x/net v0.33.0
353353

354-
replace golang.org/x/net v0.8.0 => golang.org/x/net v0.24.0
354+
replace golang.org/x/net v0.8.0 => golang.org/x/net v0.33.0
355355

356-
replace golang.org/x/net v0.10.0 => golang.org/x/net v0.24.0
356+
replace golang.org/x/net v0.10.0 => golang.org/x/net v0.33.0
357+
358+
replace golang.org/x/net v0.15.0 => golang.org/x/net v0.33.0
359+
360+
replace golang.org/x/net v0.21.0 => golang.org/x/net v0.33.0
361+
362+
replace golang.org/x/net v0.25.0 => golang.org/x/net v0.33.0
357363

358364
replace golang.org/x/text v0.0.0-20170915032832-14c0d48ead0c => golang.org/x/text v0.3.8
359365

0 commit comments

Comments
 (0)