Skip to content

Commit 5e41a86

Browse files
Merge pull request #2632 from 2uasimojo/mce-2.8
[mce-2.8] HIVE-2813: Bump jwt/v4 and v5
2 parents f86cc02 + 0fabe29 commit 5e41a86

File tree

8 files changed

+89
-28
lines changed

8 files changed

+89
-28
lines changed

go.mod

Lines changed: 5 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -105,7 +105,7 @@ require (
105105
github.com/go-openapi/spec v0.21.0 // indirect
106106
github.com/go-openapi/validate v0.24.0 // indirect
107107
github.com/go-test/deep v1.1.0 // indirect
108-
github.com/golang-jwt/jwt/v5 v5.2.1 // indirect
108+
github.com/golang-jwt/jwt/v5 v5.2.2 // indirect
109109
github.com/hashicorp/go-version v1.6.0 // indirect
110110
github.com/hexops/gotextdiff v1.0.3 // indirect
111111
github.com/kkHAIKE/contextcheck v1.1.5 // indirect
@@ -406,7 +406,7 @@ require (
406406
github.com/go-logr/stdr v1.2.2 // indirect
407407
github.com/go-logr/zapr v1.3.0 // indirect
408408
github.com/go-playground/validator/v10 v10.19.0 // indirect
409-
github.com/golang-jwt/jwt/v4 v4.5.1 // indirect
409+
github.com/golang-jwt/jwt/v4 v4.5.2 // indirect
410410
github.com/google/cel-go v0.22.0 // indirect
411411
github.com/google/gnostic-models v0.6.9-0.20230804172637-c7be7c783f49 // indirect
412412
github.com/google/s2a-go v0.1.7 // indirect
@@ -474,3 +474,6 @@ exclude (
474474
go.etcd.io/etcd v0.0.0-20191023171146-3cf2f69b5738
475475
go.etcd.io/etcd v0.5.0-alpha.5.0.20200910180754-dd1b699fc489
476476
)
477+
478+
// CVE-2025-30204: Some transitive deps are still using older v4. Safe to remove once go.sum shows only 4.5.2 or higher.
479+
replace github.com/golang-jwt/jwt/v4 => github.com/golang-jwt/jwt/v4 v4.5.2

go.sum

Lines changed: 4 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -629,13 +629,10 @@ github.com/gogo/protobuf v1.3.2 h1:Ov1cvc58UF3b5XjBnZv7+opcTcQFZebYjWzi34vdm4Q=
629629
github.com/gogo/protobuf v1.3.2/go.mod h1:P1XiOD3dCwIKUDQYPy72D8LYyHL2YPYrpS2s69NZV8Q=
630630
github.com/golang-jwt/jwt v3.2.1+incompatible/go.mod h1:8pz2t5EyA70fFQQSrl6XZXzqecmYZeUEB8OUGHkxJ+I=
631631
github.com/golang-jwt/jwt v3.2.2+incompatible/go.mod h1:8pz2t5EyA70fFQQSrl6XZXzqecmYZeUEB8OUGHkxJ+I=
632-
github.com/golang-jwt/jwt/v4 v4.0.0/go.mod h1:/xlHOz8bRuivTWchD4jCa+NbatV+wEUSzwAxVc6locg=
633-
github.com/golang-jwt/jwt/v4 v4.2.0/go.mod h1:/xlHOz8bRuivTWchD4jCa+NbatV+wEUSzwAxVc6locg=
634-
github.com/golang-jwt/jwt/v4 v4.5.0/go.mod h1:m21LjoU+eqJr34lmDMbreY2eSTRJ1cv77w39/MY0Ch0=
635-
github.com/golang-jwt/jwt/v4 v4.5.1 h1:JdqV9zKUdtaa9gdPlywC3aeoEsR681PlKC+4F5gQgeo=
636-
github.com/golang-jwt/jwt/v4 v4.5.1/go.mod h1:m21LjoU+eqJr34lmDMbreY2eSTRJ1cv77w39/MY0Ch0=
637-
github.com/golang-jwt/jwt/v5 v5.2.1 h1:OuVbFODueb089Lh128TAcimifWaLhJwVflnrgM17wHk=
638-
github.com/golang-jwt/jwt/v5 v5.2.1/go.mod h1:pqrtFR0X4osieyHYxtmOUWsAWrfe1Q5UVIyoH402zdk=
632+
github.com/golang-jwt/jwt/v4 v4.5.2 h1:YtQM7lnr8iZ+j5q71MGKkNw9Mn7AjHM68uc9g5fXeUI=
633+
github.com/golang-jwt/jwt/v4 v4.5.2/go.mod h1:m21LjoU+eqJr34lmDMbreY2eSTRJ1cv77w39/MY0Ch0=
634+
github.com/golang-jwt/jwt/v5 v5.2.2 h1:Rl4B7itRWVtYIHFrSNd7vhTiz9UpLdi6gZhZ3wEeDy8=
635+
github.com/golang-jwt/jwt/v5 v5.2.2/go.mod h1:pqrtFR0X4osieyHYxtmOUWsAWrfe1Q5UVIyoH402zdk=
639636
github.com/golang/glog v0.0.0-20160126235308-23def4e6c14b/go.mod h1:SBH7ygxi8pfUlaOkMMuAQtPIUF8ecWP5IEl/CR7VP2Q=
640637
github.com/golang/groupcache v0.0.0-20190129154638-5b532d6fd5ef/go.mod h1:cIg4eruTrX1D+g88fzRXU5OdNfaM+9IcxsU14FzY7Hc=
641638
github.com/golang/groupcache v0.0.0-20190702054246-869f871628b6/go.mod h1:cIg4eruTrX1D+g88fzRXU5OdNfaM+9IcxsU14FzY7Hc=

vendor/github.com/golang-jwt/jwt/v4/parser.go

Lines changed: 33 additions & 3 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

vendor/github.com/golang-jwt/jwt/v5/README.md

Lines changed: 8 additions & 8 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

vendor/github.com/golang-jwt/jwt/v5/SECURITY.md

Lines changed: 2 additions & 2 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

vendor/github.com/golang-jwt/jwt/v5/parser.go

Lines changed: 33 additions & 3 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

vendor/github.com/golang-jwt/jwt/v5/token.go

Lines changed: 1 addition & 1 deletion
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

vendor/modules.txt

Lines changed: 3 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -716,10 +716,10 @@ github.com/gogo/protobuf/gogoproto
716716
github.com/gogo/protobuf/proto
717717
github.com/gogo/protobuf/protoc-gen-gogo/descriptor
718718
github.com/gogo/protobuf/sortkeys
719-
# github.com/golang-jwt/jwt/v4 v4.5.1
719+
# github.com/golang-jwt/jwt/v4 v4.5.2 => github.com/golang-jwt/jwt/v4 v4.5.2
720720
## explicit; go 1.16
721721
github.com/golang-jwt/jwt/v4
722-
# github.com/golang-jwt/jwt/v5 v5.2.1
722+
# github.com/golang-jwt/jwt/v5 v5.2.2
723723
## explicit; go 1.18
724724
github.com/golang-jwt/jwt/v5
725725
# github.com/golang/groupcache v0.0.0-20210331224755-41bb18bfe9da
@@ -3617,3 +3617,4 @@ sigs.k8s.io/yaml/goyaml.v3
36173617
# k8s.io/apimachinery => k8s.io/apimachinery v0.32.0
36183618
# github.com/dgrijalva/jwt-go v3.2.0+incompatible => github.com/golang-jwt/jwt v3.2.1+incompatible
36193619
# github.com/emicklei/go-restful v2.15.0+incompatible => github.com/emicklei/go-restful v2.16.0+incompatible
3620+
# github.com/golang-jwt/jwt/v4 => github.com/golang-jwt/jwt/v4 v4.5.2

0 commit comments

Comments
 (0)