Skip to content

Commit 332f48e

Browse files
Update vulnerable dependencies [SECURITY]
1 parent a047373 commit 332f48e

File tree

4 files changed

+213
-134
lines changed

4 files changed

+213
-134
lines changed

examples/go.mod

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -65,7 +65,7 @@ require (
6565
github.com/felixge/httpsnoop v1.0.4 // indirect
6666
github.com/go-git/gcfg v1.5.1-0.20230307220236-3a3c6141e376 // indirect
6767
github.com/go-git/go-billy/v5 v5.8.0 // indirect
68-
github.com/go-git/go-git/v5 v5.17.1 // indirect
68+
github.com/go-git/go-git/v5 v5.18.0 // indirect
6969
github.com/go-jose/go-jose/v3 v3.0.5 // indirect
7070
github.com/go-logr/logr v1.4.3 // indirect
7171
github.com/go-logr/stdr v1.2.2 // indirect

examples/go.sum

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -162,8 +162,8 @@ github.com/go-git/go-billy/v5 v5.8.0 h1:I8hjc3LbBlXTtVuFNJuwYuMiHvQJDq1AT6u4DwDz
162162
github.com/go-git/go-billy/v5 v5.8.0/go.mod h1:RpvI/rw4Vr5QA+Z60c6d6LXH0rYJo0uD5SqfmrrheCY=
163163
github.com/go-git/go-git-fixtures/v4 v4.3.2-0.20231010084843-55a94097c399 h1:eMje31YglSBqCdIqdhKBW8lokaMrL3uTkpGYlE2OOT4=
164164
github.com/go-git/go-git-fixtures/v4 v4.3.2-0.20231010084843-55a94097c399/go.mod h1:1OCfN199q1Jm3HZlxleg+Dw/mwps2Wbk9frAWm+4FII=
165-
github.com/go-git/go-git/v5 v5.17.1 h1:WnljyxIzSj9BRRUlnmAU35ohDsjRK0EKmL0evDqi5Jk=
166-
github.com/go-git/go-git/v5 v5.17.1/go.mod h1:pW/VmeqkanRFqR6AljLcs7EA7FbZaN5MQqO7oZADXpo=
165+
github.com/go-git/go-git/v5 v5.18.0 h1:O831KI+0PR51hM2kep6T8k+w0/LIAD490gvqMCvL5hM=
166+
github.com/go-git/go-git/v5 v5.18.0/go.mod h1:pW/VmeqkanRFqR6AljLcs7EA7FbZaN5MQqO7oZADXpo=
167167
github.com/go-jose/go-jose/v3 v3.0.5 h1:BLLJWbC4nMZOfuPVxoZIxeYsn6Nl2r1fITaJ78UQlVQ=
168168
github.com/go-jose/go-jose/v3 v3.0.5/go.mod h1:5b+7YgP7ZICgJDBdfjZaIt+H/9L9T/YQrVfLAMboGkQ=
169169
github.com/go-logr/logr v1.2.2/go.mod h1:jdQByPbusPIv2/zmleS9BjJVeZ6kBagPoEUsqbVz/1A=

provider/go.mod

Lines changed: 68 additions & 38 deletions
Original file line numberDiff line numberDiff line change
@@ -1,8 +1,6 @@
11
module github.com/pulumi/pulumi-xyz/provider
22

3-
go 1.24.7
4-
5-
toolchain go1.24.10
3+
go 1.25.8
64

75
replace github.com/hashicorp/terraform-plugin-sdk/v2 => github.com/pulumi/terraform-plugin-sdk/v2 v2.0.0-20250923233607-7f1981c8674a
86

@@ -13,12 +11,19 @@ require (
1311
)
1412

1513
require (
16-
cloud.google.com/go v0.112.1 // indirect
14+
cel.dev/expr v0.25.1 // indirect
15+
cloud.google.com/go v0.123.0 // indirect
16+
cloud.google.com/go/auth v0.18.2 // indirect
17+
cloud.google.com/go/auth/oauth2adapt v0.2.8 // indirect
1718
cloud.google.com/go/compute/metadata v0.9.0 // indirect
18-
cloud.google.com/go/iam v1.1.6 // indirect
19-
cloud.google.com/go/storage v1.39.1 // indirect
19+
cloud.google.com/go/iam v1.5.3 // indirect
20+
cloud.google.com/go/monitoring v1.24.3 // indirect
21+
cloud.google.com/go/storage v1.61.3 // indirect
2022
dario.cat/mergo v1.0.0 // indirect
2123
github.com/BurntSushi/toml v1.2.1 // indirect
24+
github.com/GoogleCloudPlatform/opentelemetry-operations-go/detectors/gcp v1.30.0 // indirect
25+
github.com/GoogleCloudPlatform/opentelemetry-operations-go/exporter/metric v0.55.0 // indirect
26+
github.com/GoogleCloudPlatform/opentelemetry-operations-go/internal/resourcemapping v0.55.0 // indirect
2227
github.com/Masterminds/goutils v1.1.1 // indirect
2328
github.com/Masterminds/semver v1.5.0 // indirect
2429
github.com/Masterminds/semver/v3 v3.2.0 // indirect
@@ -31,7 +36,25 @@ require (
3136
github.com/apparentlymart/go-textseg/v15 v15.0.0 // indirect
3237
github.com/armon/go-radix v1.0.0 // indirect
3338
github.com/atotto/clipboard v0.1.4 // indirect
34-
github.com/aws/aws-sdk-go v1.50.36 // indirect
39+
github.com/aws/aws-sdk-go-v2 v1.41.4 // indirect
40+
github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream v1.7.7 // indirect
41+
github.com/aws/aws-sdk-go-v2/config v1.32.12 // indirect
42+
github.com/aws/aws-sdk-go-v2/credentials v1.19.12 // indirect
43+
github.com/aws/aws-sdk-go-v2/feature/ec2/imds v1.18.20 // indirect
44+
github.com/aws/aws-sdk-go-v2/internal/configsources v1.4.20 // indirect
45+
github.com/aws/aws-sdk-go-v2/internal/endpoints/v2 v2.7.20 // indirect
46+
github.com/aws/aws-sdk-go-v2/internal/ini v1.8.6 // indirect
47+
github.com/aws/aws-sdk-go-v2/internal/v4a v1.4.21 // indirect
48+
github.com/aws/aws-sdk-go-v2/service/internal/accept-encoding v1.13.7 // indirect
49+
github.com/aws/aws-sdk-go-v2/service/internal/checksum v1.9.12 // indirect
50+
github.com/aws/aws-sdk-go-v2/service/internal/presigned-url v1.13.20 // indirect
51+
github.com/aws/aws-sdk-go-v2/service/internal/s3shared v1.19.20 // indirect
52+
github.com/aws/aws-sdk-go-v2/service/s3 v1.97.1 // indirect
53+
github.com/aws/aws-sdk-go-v2/service/signin v1.0.8 // indirect
54+
github.com/aws/aws-sdk-go-v2/service/sso v1.30.13 // indirect
55+
github.com/aws/aws-sdk-go-v2/service/ssooidc v1.35.17 // indirect
56+
github.com/aws/aws-sdk-go-v2/service/sts v1.41.9 // indirect
57+
github.com/aws/smithy-go v1.24.2 // indirect
3558
github.com/aymanbagabas/go-osc52/v2 v2.0.1 // indirect
3659
github.com/bgentry/go-netrc v0.0.0-20140422174119-9fd32a8b3d3d // indirect
3760
github.com/bgentry/speakeasy v0.1.0 // indirect
@@ -46,40 +69,44 @@ require (
4669
github.com/charmbracelet/x/windows v0.1.0 // indirect
4770
github.com/cheggaaa/pb v1.0.29 // indirect
4871
github.com/cloudflare/circl v1.6.3 // indirect
72+
github.com/cncf/xds/go v0.0.0-20251210132809-ee656c7534f5 // indirect
4973
github.com/cyphar/filepath-securejoin v0.4.1 // indirect
5074
github.com/deckarep/golang-set/v2 v2.5.0 // indirect
5175
github.com/djherbis/times v1.6.0 // indirect
5276
github.com/edsrzf/mmap-go v1.1.0 // indirect
5377
github.com/emirpasic/gods v1.18.1 // indirect
78+
github.com/envoyproxy/go-control-plane/envoy v1.36.0 // indirect
79+
github.com/envoyproxy/protoc-gen-validate v1.3.0 // indirect
5480
github.com/erikgeiser/coninput v0.0.0-20211004153227-1c3628e74d0f // indirect
5581
github.com/ettle/strcase v0.1.1 // indirect
56-
github.com/fatih/color v1.17.0 // indirect
82+
github.com/fatih/color v1.18.0 // indirect
5783
github.com/felixge/httpsnoop v1.0.4 // indirect
5884
github.com/go-git/gcfg v1.5.1-0.20230307220236-3a3c6141e376 // indirect
5985
github.com/go-git/go-billy/v5 v5.8.0 // indirect
60-
github.com/go-git/go-git/v5 v5.17.1 // indirect
86+
github.com/go-git/go-git/v5 v5.18.0 // indirect
87+
github.com/go-jose/go-jose/v4 v4.1.3 // indirect
6188
github.com/go-logr/logr v1.4.3 // indirect
6289
github.com/go-logr/stdr v1.2.2 // indirect
6390
github.com/gogo/protobuf v1.3.2 // indirect
6491
github.com/golang/glog v1.2.5 // indirect
6592
github.com/golang/groupcache v0.0.0-20241129210726-2c02b8208cf8 // indirect
6693
github.com/golang/protobuf v1.5.4 // indirect
6794
github.com/google/go-cmp v0.7.0 // indirect
68-
github.com/google/s2a-go v0.1.7 // indirect
95+
github.com/google/s2a-go v0.1.9 // indirect
6996
github.com/google/shlex v0.0.0-20191202100458-e7afc7fbc510 // indirect
7097
github.com/google/uuid v1.6.0 // indirect
71-
github.com/googleapis/enterprise-certificate-proxy v0.3.2 // indirect
72-
github.com/googleapis/gax-go/v2 v2.12.2 // indirect
98+
github.com/googleapis/enterprise-certificate-proxy v0.3.14 // indirect
99+
github.com/googleapis/gax-go/v2 v2.17.0 // indirect
73100
github.com/grpc-ecosystem/grpc-opentracing v0.0.0-20180507213350-8e809c8a8645 // indirect
101+
github.com/hashicorp/aws-sdk-go-base/v2 v2.0.0-beta.72 // indirect
74102
github.com/hashicorp/errwrap v1.1.0 // indirect
75103
github.com/hashicorp/go-cleanhttp v0.5.2 // indirect
76104
github.com/hashicorp/go-cty v1.5.0 // indirect
77-
github.com/hashicorp/go-getter v1.7.9 // indirect
105+
github.com/hashicorp/go-getter v1.8.6 // indirect
78106
github.com/hashicorp/go-hclog v1.6.3 // indirect
79107
github.com/hashicorp/go-multierror v1.1.1 // indirect
80-
github.com/hashicorp/go-safetemp v1.0.0 // indirect
81108
github.com/hashicorp/go-uuid v1.0.3 // indirect
82-
github.com/hashicorp/go-version v1.7.0 // indirect
109+
github.com/hashicorp/go-version v1.8.0 // indirect
83110
github.com/hashicorp/hcl v1.0.0 // indirect
84111
github.com/hashicorp/hcl/v2 v2.24.0 // indirect
85112
github.com/hashicorp/hil v0.0.0-20190212132231-97b3a9cdfa93 // indirect
@@ -93,12 +120,11 @@ require (
93120
github.com/imdario/mergo v0.3.15 // indirect
94121
github.com/inconshreveable/mousetrap v1.1.0 // indirect
95122
github.com/jbenet/go-context v0.0.0-20150711004518-d14ea06fba99 // indirect
96-
github.com/jmespath/go-jmespath v0.4.0 // indirect
97123
github.com/json-iterator/go v1.1.12 // indirect
98124
github.com/kevinburke/ssh_config v1.2.0 // indirect
99-
github.com/klauspost/compress v1.18.0 // indirect
125+
github.com/klauspost/compress v1.18.5 // indirect
100126
github.com/lucasb-eyer/go-colorful v1.2.0 // indirect
101-
github.com/mattn/go-colorable v0.1.13 // indirect
127+
github.com/mattn/go-colorable v0.1.14 // indirect
102128
github.com/mattn/go-isatty v0.0.20 // indirect
103129
github.com/mattn/go-localereader v0.0.1 // indirect
104130
github.com/mattn/go-runewidth v0.0.15 // indirect
@@ -126,6 +152,7 @@ require (
126152
github.com/pjbgf/sha1cd v0.3.2 // indirect
127153
github.com/pkg/errors v0.9.1 // indirect
128154
github.com/pkg/term v1.1.0 // indirect
155+
github.com/planetscale/vtprotobuf v0.6.1-0.20240319094008-0393e58bdf10 // indirect
129156
github.com/posener/complete v1.2.3 // indirect
130157
github.com/pulumi/appdash v0.0.0-20231130102222-75f619a67231 // indirect
131158
github.com/pulumi/esc v0.22.0 // indirect
@@ -149,6 +176,7 @@ require (
149176
github.com/spf13/cast v1.5.0 // indirect
150177
github.com/spf13/cobra v1.10.1 // indirect
151178
github.com/spf13/pflag v1.0.10 // indirect
179+
github.com/spiffe/go-spiffe/v2 v2.6.0 // indirect
152180
github.com/teekennedy/goldmark-markdown v0.3.0 // indirect
153181
github.com/texttheater/golang-levenshtein v1.0.1 // indirect
154182
github.com/uber/jaeger-client-go v2.30.0+incompatible // indirect
@@ -161,30 +189,32 @@ require (
161189
github.com/xo/terminfo v0.0.0-20220910002029-abceb7e1c41e // indirect
162190
github.com/yuin/goldmark v1.7.13 // indirect
163191
github.com/zclconf/go-cty v1.17.0 // indirect
164-
go.opencensus.io v0.24.0 // indirect
165192
go.opentelemetry.io/auto/sdk v1.2.1 // indirect
166-
go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc v0.49.0 // indirect
167-
go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.49.0 // indirect
168-
go.opentelemetry.io/otel v1.40.0 // indirect
169-
go.opentelemetry.io/otel/metric v1.40.0 // indirect
170-
go.opentelemetry.io/otel/trace v1.40.0 // indirect
193+
go.opentelemetry.io/contrib/detectors/gcp v1.39.0 // indirect
194+
go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc v0.63.0 // indirect
195+
go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.61.0 // indirect
196+
go.opentelemetry.io/otel v1.42.0 // indirect
197+
go.opentelemetry.io/otel/metric v1.42.0 // indirect
198+
go.opentelemetry.io/otel/sdk v1.42.0 // indirect
199+
go.opentelemetry.io/otel/sdk/metric v1.42.0 // indirect
200+
go.opentelemetry.io/otel/trace v1.42.0 // indirect
171201
go.uber.org/atomic v1.11.0 // indirect
172-
golang.org/x/crypto v0.47.0 // indirect
202+
golang.org/x/crypto v0.49.0 // indirect
173203
golang.org/x/exp v0.0.0-20250718183923-645b1fa84792 // indirect
174-
golang.org/x/mod v0.31.0 // indirect
175-
golang.org/x/net v0.49.0 // indirect
176-
golang.org/x/oauth2 v0.34.0 // indirect
177-
golang.org/x/sync v0.19.0 // indirect
178-
golang.org/x/sys v0.40.0 // indirect
179-
golang.org/x/term v0.39.0 // indirect
180-
golang.org/x/text v0.33.0 // indirect
181-
golang.org/x/time v0.12.0 // indirect
182-
golang.org/x/tools v0.40.0 // indirect
183-
google.golang.org/api v0.169.0 // indirect
204+
golang.org/x/mod v0.33.0 // indirect
205+
golang.org/x/net v0.52.0 // indirect
206+
golang.org/x/oauth2 v0.36.0 // indirect
207+
golang.org/x/sync v0.20.0 // indirect
208+
golang.org/x/sys v0.42.0 // indirect
209+
golang.org/x/term v0.41.0 // indirect
210+
golang.org/x/text v0.35.0 // indirect
211+
golang.org/x/time v0.15.0 // indirect
212+
golang.org/x/tools v0.42.0 // indirect
213+
google.golang.org/api v0.271.0 // indirect
184214
google.golang.org/appengine v1.6.8 // indirect
185-
google.golang.org/genproto v0.0.0-20240311173647-c811ad7063a7 // indirect
186-
google.golang.org/genproto/googleapis/api v0.0.0-20260128011058-8636f8732409 // indirect
187-
google.golang.org/genproto/googleapis/rpc v0.0.0-20260128011058-8636f8732409 // indirect
215+
google.golang.org/genproto v0.0.0-20260128011058-8636f8732409 // indirect
216+
google.golang.org/genproto/googleapis/api v0.0.0-20260203192932-546029d2fa20 // indirect
217+
google.golang.org/genproto/googleapis/rpc v0.0.0-20260226221140-a57be14db171 // indirect
188218
google.golang.org/grpc v1.79.3 // indirect
189219
google.golang.org/protobuf v1.36.11 // indirect
190220
gopkg.in/warnings.v0 v0.1.2 // indirect

0 commit comments

Comments
 (0)