Skip to content

Commit 5e41a86

Browse files
Merge pull request #2632 from 2uasimojo/mce-2.8
[mce-2.8] HIVE-2813: Bump jwt/v4 and v5
2 parents f86cc02 + 0fabe29 commit 5e41a86

File tree

8 files changed

+89
-28
lines changed

8 files changed

+89
-28
lines changed

go.mod

+5-2
Original file line numberDiff line numberDiff line change
@@ -105,7 +105,7 @@ require (
105105
github.com/go-openapi/spec v0.21.0 // indirect
106106
github.com/go-openapi/validate v0.24.0 // indirect
107107
github.com/go-test/deep v1.1.0 // indirect
108-
github.com/golang-jwt/jwt/v5 v5.2.1 // indirect
108+
github.com/golang-jwt/jwt/v5 v5.2.2 // indirect
109109
github.com/hashicorp/go-version v1.6.0 // indirect
110110
github.com/hexops/gotextdiff v1.0.3 // indirect
111111
github.com/kkHAIKE/contextcheck v1.1.5 // indirect
@@ -406,7 +406,7 @@ require (
406406
github.com/go-logr/stdr v1.2.2 // indirect
407407
github.com/go-logr/zapr v1.3.0 // indirect
408408
github.com/go-playground/validator/v10 v10.19.0 // indirect
409-
github.com/golang-jwt/jwt/v4 v4.5.1 // indirect
409+
github.com/golang-jwt/jwt/v4 v4.5.2 // indirect
410410
github.com/google/cel-go v0.22.0 // indirect
411411
github.com/google/gnostic-models v0.6.9-0.20230804172637-c7be7c783f49 // indirect
412412
github.com/google/s2a-go v0.1.7 // indirect
@@ -474,3 +474,6 @@ exclude (
474474
go.etcd.io/etcd v0.0.0-20191023171146-3cf2f69b5738
475475
go.etcd.io/etcd v0.5.0-alpha.5.0.20200910180754-dd1b699fc489
476476
)
477+
478+
// CVE-2025-30204: Some transitive deps are still using older v4. Safe to remove once go.sum shows only 4.5.2 or higher.
479+
replace github.com/golang-jwt/jwt/v4 => github.com/golang-jwt/jwt/v4 v4.5.2

go.sum

+4-7
Original file line numberDiff line numberDiff line change
@@ -629,13 +629,10 @@ github.com/gogo/protobuf v1.3.2 h1:Ov1cvc58UF3b5XjBnZv7+opcTcQFZebYjWzi34vdm4Q=
629629
github.com/gogo/protobuf v1.3.2/go.mod h1:P1XiOD3dCwIKUDQYPy72D8LYyHL2YPYrpS2s69NZV8Q=
630630
github.com/golang-jwt/jwt v3.2.1+incompatible/go.mod h1:8pz2t5EyA70fFQQSrl6XZXzqecmYZeUEB8OUGHkxJ+I=
631631
github.com/golang-jwt/jwt v3.2.2+incompatible/go.mod h1:8pz2t5EyA70fFQQSrl6XZXzqecmYZeUEB8OUGHkxJ+I=
632-
github.com/golang-jwt/jwt/v4 v4.0.0/go.mod h1:/xlHOz8bRuivTWchD4jCa+NbatV+wEUSzwAxVc6locg=
633-
github.com/golang-jwt/jwt/v4 v4.2.0/go.mod h1:/xlHOz8bRuivTWchD4jCa+NbatV+wEUSzwAxVc6locg=
634-
github.com/golang-jwt/jwt/v4 v4.5.0/go.mod h1:m21LjoU+eqJr34lmDMbreY2eSTRJ1cv77w39/MY0Ch0=
635-
github.com/golang-jwt/jwt/v4 v4.5.1 h1:JdqV9zKUdtaa9gdPlywC3aeoEsR681PlKC+4F5gQgeo=
636-
github.com/golang-jwt/jwt/v4 v4.5.1/go.mod h1:m21LjoU+eqJr34lmDMbreY2eSTRJ1cv77w39/MY0Ch0=
637-
github.com/golang-jwt/jwt/v5 v5.2.1 h1:OuVbFODueb089Lh128TAcimifWaLhJwVflnrgM17wHk=
638-
github.com/golang-jwt/jwt/v5 v5.2.1/go.mod h1:pqrtFR0X4osieyHYxtmOUWsAWrfe1Q5UVIyoH402zdk=
632+
github.com/golang-jwt/jwt/v4 v4.5.2 h1:YtQM7lnr8iZ+j5q71MGKkNw9Mn7AjHM68uc9g5fXeUI=
633+
github.com/golang-jwt/jwt/v4 v4.5.2/go.mod h1:m21LjoU+eqJr34lmDMbreY2eSTRJ1cv77w39/MY0Ch0=
634+
github.com/golang-jwt/jwt/v5 v5.2.2 h1:Rl4B7itRWVtYIHFrSNd7vhTiz9UpLdi6gZhZ3wEeDy8=
635+
github.com/golang-jwt/jwt/v5 v5.2.2/go.mod h1:pqrtFR0X4osieyHYxtmOUWsAWrfe1Q5UVIyoH402zdk=
639636
github.com/golang/glog v0.0.0-20160126235308-23def4e6c14b/go.mod h1:SBH7ygxi8pfUlaOkMMuAQtPIUF8ecWP5IEl/CR7VP2Q=
640637
github.com/golang/groupcache v0.0.0-20190129154638-5b532d6fd5ef/go.mod h1:cIg4eruTrX1D+g88fzRXU5OdNfaM+9IcxsU14FzY7Hc=
641638
github.com/golang/groupcache v0.0.0-20190702054246-869f871628b6/go.mod h1:cIg4eruTrX1D+g88fzRXU5OdNfaM+9IcxsU14FzY7Hc=

vendor/github.com/golang-jwt/jwt/v4/parser.go

+33-3
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

vendor/github.com/golang-jwt/jwt/v5/README.md

+8-8
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

vendor/github.com/golang-jwt/jwt/v5/SECURITY.md

+2-2
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

vendor/github.com/golang-jwt/jwt/v5/parser.go

+33-3
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

vendor/github.com/golang-jwt/jwt/v5/token.go

+1-1
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

vendor/modules.txt

+3-2
Original file line numberDiff line numberDiff line change
@@ -716,10 +716,10 @@ github.com/gogo/protobuf/gogoproto
716716
github.com/gogo/protobuf/proto
717717
github.com/gogo/protobuf/protoc-gen-gogo/descriptor
718718
github.com/gogo/protobuf/sortkeys
719-
# github.com/golang-jwt/jwt/v4 v4.5.1
719+
# github.com/golang-jwt/jwt/v4 v4.5.2 => github.com/golang-jwt/jwt/v4 v4.5.2
720720
## explicit; go 1.16
721721
github.com/golang-jwt/jwt/v4
722-
# github.com/golang-jwt/jwt/v5 v5.2.1
722+
# github.com/golang-jwt/jwt/v5 v5.2.2
723723
## explicit; go 1.18
724724
github.com/golang-jwt/jwt/v5
725725
# github.com/golang/groupcache v0.0.0-20210331224755-41bb18bfe9da
@@ -3617,3 +3617,4 @@ sigs.k8s.io/yaml/goyaml.v3
36173617
# k8s.io/apimachinery => k8s.io/apimachinery v0.32.0
36183618
# github.com/dgrijalva/jwt-go v3.2.0+incompatible => github.com/golang-jwt/jwt v3.2.1+incompatible
36193619
# github.com/emicklei/go-restful v2.15.0+incompatible => github.com/emicklei/go-restful v2.16.0+incompatible
3620+
# github.com/golang-jwt/jwt/v4 => github.com/golang-jwt/jwt/v4 v4.5.2

0 commit comments

Comments
 (0)