Skip to content

Commit 37d8ea7

Browse files
authored
Merge pull request #2451 from kubernetes-sigs/CVE-2025-30204-1.31
[release-1.31] fix: CVE-2025-30204
2 parents 05f9b73 + 1d392e7 commit 37d8ea7

File tree

9 files changed

+86
-25
lines changed

9 files changed

+86
-25
lines changed

.trivyignore

+1
Original file line numberDiff line numberDiff line change
@@ -2,3 +2,4 @@ CVE-2024-45336
22
CVE-2024-45341
33
CVE-2025-22866
44
CVE-2025-22870
5+
CVE-2025-30204

go.mod

+2-2
Original file line numberDiff line numberDiff line change
@@ -98,8 +98,8 @@ require (
9898
github.com/go-openapi/swag v0.23.0 // indirect
9999
github.com/go-task/slim-sprig/v3 v3.0.0 // indirect
100100
github.com/gogo/protobuf v1.3.2 // indirect
101-
github.com/golang-jwt/jwt/v4 v4.5.1 // indirect
102-
github.com/golang-jwt/jwt/v5 v5.2.1 // indirect
101+
github.com/golang-jwt/jwt/v4 v4.5.2 // indirect
102+
github.com/golang-jwt/jwt/v5 v5.2.2 // indirect
103103
github.com/golang/groupcache v0.0.0-20210331224755-41bb18bfe9da // indirect
104104
github.com/google/cel-go v0.20.1 // indirect
105105
github.com/google/gnostic-models v0.6.8 // indirect

go.sum

+4-4
Original file line numberDiff line numberDiff line change
@@ -852,10 +852,10 @@ github.com/gogo/protobuf v1.3.2 h1:Ov1cvc58UF3b5XjBnZv7+opcTcQFZebYjWzi34vdm4Q=
852852
github.com/gogo/protobuf v1.3.2/go.mod h1:P1XiOD3dCwIKUDQYPy72D8LYyHL2YPYrpS2s69NZV8Q=
853853
github.com/golang-jwt/jwt/v4 v4.0.0/go.mod h1:/xlHOz8bRuivTWchD4jCa+NbatV+wEUSzwAxVc6locg=
854854
github.com/golang-jwt/jwt/v4 v4.5.0/go.mod h1:m21LjoU+eqJr34lmDMbreY2eSTRJ1cv77w39/MY0Ch0=
855-
github.com/golang-jwt/jwt/v4 v4.5.1 h1:JdqV9zKUdtaa9gdPlywC3aeoEsR681PlKC+4F5gQgeo=
856-
github.com/golang-jwt/jwt/v4 v4.5.1/go.mod h1:m21LjoU+eqJr34lmDMbreY2eSTRJ1cv77w39/MY0Ch0=
857-
github.com/golang-jwt/jwt/v5 v5.2.1 h1:OuVbFODueb089Lh128TAcimifWaLhJwVflnrgM17wHk=
858-
github.com/golang-jwt/jwt/v5 v5.2.1/go.mod h1:pqrtFR0X4osieyHYxtmOUWsAWrfe1Q5UVIyoH402zdk=
855+
github.com/golang-jwt/jwt/v4 v4.5.2 h1:YtQM7lnr8iZ+j5q71MGKkNw9Mn7AjHM68uc9g5fXeUI=
856+
github.com/golang-jwt/jwt/v4 v4.5.2/go.mod h1:m21LjoU+eqJr34lmDMbreY2eSTRJ1cv77w39/MY0Ch0=
857+
github.com/golang-jwt/jwt/v5 v5.2.2 h1:Rl4B7itRWVtYIHFrSNd7vhTiz9UpLdi6gZhZ3wEeDy8=
858+
github.com/golang-jwt/jwt/v5 v5.2.2/go.mod h1:pqrtFR0X4osieyHYxtmOUWsAWrfe1Q5UVIyoH402zdk=
859859
github.com/golang/freetype v0.0.0-20170609003504-e2365dfdc4a0/go.mod h1:E/TSTwGwJL78qG/PmXZO1EjYhfJinVAhrmmHX6Z8B9k=
860860
github.com/golang/glog v0.0.0-20160126235308-23def4e6c14b/go.mod h1:SBH7ygxi8pfUlaOkMMuAQtPIUF8ecWP5IEl/CR7VP2Q=
861861
github.com/golang/glog v1.0.0/go.mod h1:EWib/APOK0SL3dFbYqvxE3UYd8E6s1ouQ7iEp/0LWV4=

vendor/github.com/golang-jwt/jwt/v4/parser.go

+33-3
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

vendor/github.com/golang-jwt/jwt/v5/README.md

+8-8
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

vendor/github.com/golang-jwt/jwt/v5/SECURITY.md

+2-2
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

vendor/github.com/golang-jwt/jwt/v5/parser.go

+33-3
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

vendor/github.com/golang-jwt/jwt/v5/token.go

+1-1
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

vendor/modules.txt

+2-2
Original file line numberDiff line numberDiff line change
@@ -237,10 +237,10 @@ github.com/gogo/protobuf/gogoproto
237237
github.com/gogo/protobuf/proto
238238
github.com/gogo/protobuf/protoc-gen-gogo/descriptor
239239
github.com/gogo/protobuf/sortkeys
240-
# github.com/golang-jwt/jwt/v4 v4.5.1
240+
# github.com/golang-jwt/jwt/v4 v4.5.2
241241
## explicit; go 1.16
242242
github.com/golang-jwt/jwt/v4
243-
# github.com/golang-jwt/jwt/v5 v5.2.1
243+
# github.com/golang-jwt/jwt/v5 v5.2.2
244244
## explicit; go 1.18
245245
github.com/golang-jwt/jwt/v5
246246
# github.com/golang/groupcache v0.0.0-20210331224755-41bb18bfe9da

0 commit comments

Comments
 (0)