Skip to content

Commit 955021e

Browse files
authored
Merge pull request #1908 from k8s-infra-cherrypick-robot/cherry-pick-1907-to-release-1.24
[release-1.24] fix: CVE-2025-30204
2 parents 8d36876 + 2a93903 commit 955021e

File tree

9 files changed

+86
-25
lines changed

9 files changed

+86
-25
lines changed

.trivyignore

+1
Original file line numberDiff line numberDiff line change
@@ -2,3 +2,4 @@ CVE-2024-45336
22
CVE-2024-45341
33
CVE-2025-22866
44
CVE-2025-22870
5+
CVE-2025-30204

go.mod

+2-2
Original file line numberDiff line numberDiff line change
@@ -75,8 +75,8 @@ require (
7575
github.com/go-openapi/jsonreference v0.20.2 // indirect
7676
github.com/go-openapi/swag v0.22.4 // indirect
7777
github.com/gogo/protobuf v1.3.2 // indirect
78-
github.com/golang-jwt/jwt/v4 v4.5.1 // indirect
79-
github.com/golang-jwt/jwt/v5 v5.2.1 // indirect
78+
github.com/golang-jwt/jwt/v4 v4.5.2 // indirect
79+
github.com/golang-jwt/jwt/v5 v5.2.2 // indirect
8080
github.com/golang/groupcache v0.0.0-20210331224755-41bb18bfe9da // indirect
8181
github.com/google/cel-go v0.17.8 // indirect
8282
github.com/google/gnostic-models v0.6.8 // indirect

go.sum

+4-4
Original file line numberDiff line numberDiff line change
@@ -130,10 +130,10 @@ github.com/gogo/protobuf v1.3.2 h1:Ov1cvc58UF3b5XjBnZv7+opcTcQFZebYjWzi34vdm4Q=
130130
github.com/gogo/protobuf v1.3.2/go.mod h1:P1XiOD3dCwIKUDQYPy72D8LYyHL2YPYrpS2s69NZV8Q=
131131
github.com/golang-jwt/jwt/v4 v4.0.0/go.mod h1:/xlHOz8bRuivTWchD4jCa+NbatV+wEUSzwAxVc6locg=
132132
github.com/golang-jwt/jwt/v4 v4.5.0/go.mod h1:m21LjoU+eqJr34lmDMbreY2eSTRJ1cv77w39/MY0Ch0=
133-
github.com/golang-jwt/jwt/v4 v4.5.1 h1:JdqV9zKUdtaa9gdPlywC3aeoEsR681PlKC+4F5gQgeo=
134-
github.com/golang-jwt/jwt/v4 v4.5.1/go.mod h1:m21LjoU+eqJr34lmDMbreY2eSTRJ1cv77w39/MY0Ch0=
135-
github.com/golang-jwt/jwt/v5 v5.2.1 h1:OuVbFODueb089Lh128TAcimifWaLhJwVflnrgM17wHk=
136-
github.com/golang-jwt/jwt/v5 v5.2.1/go.mod h1:pqrtFR0X4osieyHYxtmOUWsAWrfe1Q5UVIyoH402zdk=
133+
github.com/golang-jwt/jwt/v4 v4.5.2 h1:YtQM7lnr8iZ+j5q71MGKkNw9Mn7AjHM68uc9g5fXeUI=
134+
github.com/golang-jwt/jwt/v4 v4.5.2/go.mod h1:m21LjoU+eqJr34lmDMbreY2eSTRJ1cv77w39/MY0Ch0=
135+
github.com/golang-jwt/jwt/v5 v5.2.2 h1:Rl4B7itRWVtYIHFrSNd7vhTiz9UpLdi6gZhZ3wEeDy8=
136+
github.com/golang-jwt/jwt/v5 v5.2.2/go.mod h1:pqrtFR0X4osieyHYxtmOUWsAWrfe1Q5UVIyoH402zdk=
137137
github.com/golang/groupcache v0.0.0-20210331224755-41bb18bfe9da h1:oI5xCqsCo564l8iNU+DwB5epxmsaqB+rhGL0m5jtYqE=
138138
github.com/golang/groupcache v0.0.0-20210331224755-41bb18bfe9da/go.mod h1:cIg4eruTrX1D+g88fzRXU5OdNfaM+9IcxsU14FzY7Hc=
139139
github.com/golang/protobuf v1.2.0/go.mod h1:6lQm79b+lXiMfvg/cZm0SGofjICqVBUtrP5yJMmIC1U=

vendor/github.com/golang-jwt/jwt/v4/parser.go

+33-3
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

vendor/github.com/golang-jwt/jwt/v5/README.md

+8-8
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

vendor/github.com/golang-jwt/jwt/v5/SECURITY.md

+2-2
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

vendor/github.com/golang-jwt/jwt/v5/parser.go

+33-3
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

vendor/github.com/golang-jwt/jwt/v5/token.go

+1-1
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

vendor/modules.txt

+2-2
Original file line numberDiff line numberDiff line change
@@ -225,10 +225,10 @@ github.com/gogo/protobuf/gogoproto
225225
github.com/gogo/protobuf/proto
226226
github.com/gogo/protobuf/protoc-gen-gogo/descriptor
227227
github.com/gogo/protobuf/sortkeys
228-
# github.com/golang-jwt/jwt/v4 v4.5.1
228+
# github.com/golang-jwt/jwt/v4 v4.5.2
229229
## explicit; go 1.16
230230
github.com/golang-jwt/jwt/v4
231-
# github.com/golang-jwt/jwt/v5 v5.2.1
231+
# github.com/golang-jwt/jwt/v5 v5.2.2
232232
## explicit; go 1.18
233233
github.com/golang-jwt/jwt/v5
234234
# github.com/golang/groupcache v0.0.0-20210331224755-41bb18bfe9da

0 commit comments

Comments
 (0)