Skip to content

Commit 21ef1f4

Browse files
authored
INS-1562: Fix polaris vulnerabilities (#1156)
1 parent ec1ba2f commit 21ef1f4

File tree

3 files changed

+141
-115
lines changed

3 files changed

+141
-115
lines changed

.circleci/config.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -120,7 +120,7 @@ jobs:
120120

121121
test:
122122
docker:
123-
- image: cimg/go:1.24.6
123+
- image: cimg/go:1.24.9
124124
steps:
125125
- checkout
126126
- *set_environment_variables
@@ -136,7 +136,7 @@ jobs:
136136
# The goreleaser image tag determins the version of Go.
137137
# Manually check goreleaser images for their version of Go.
138138
# Ref: https://hub.docker.com/r/goreleaser/goreleaser/tags
139-
- image: goreleaser/goreleaser:v2.12.0-nightly
139+
- image: goreleaser/goreleaser:v2.12.7
140140
steps:
141141
- checkout
142142
- setup_remote_docker

go.mod

Lines changed: 44 additions & 35 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
module github.com/fairwindsops/polaris
22

3-
go 1.24.6
3+
go 1.24.9
44

55
require (
66
github.com/fairwindsops/controller-utils v0.3.4
@@ -10,68 +10,77 @@ require (
1010
github.com/qri-io/jsonpointer v0.1.1
1111
github.com/qri-io/jsonschema v0.2.1
1212
github.com/sirupsen/logrus v1.9.3
13-
github.com/spf13/cobra v1.9.1
14-
github.com/stretchr/testify v1.10.0
13+
github.com/spf13/cobra v1.10.1
14+
github.com/stretchr/testify v1.11.1
1515
github.com/thoas/go-funk v0.9.3
1616
gomodules.xyz/jsonpatch/v2 v2.5.0
1717
gopkg.in/yaml.v3 v3.0.1
18-
k8s.io/api v0.33.3
19-
k8s.io/apimachinery v0.33.3
20-
k8s.io/client-go v0.33.1
21-
sigs.k8s.io/controller-runtime v0.21.0
18+
k8s.io/api v0.34.1
19+
k8s.io/apimachinery v0.34.1
20+
k8s.io/client-go v0.34.1
21+
sigs.k8s.io/controller-runtime v0.22.3
2222
sigs.k8s.io/yaml v1.6.0
2323
)
2424

2525
require (
2626
github.com/beorn7/perks v1.0.1 // indirect
2727
github.com/cespare/xxhash/v2 v2.3.0 // indirect
2828
github.com/davecgh/go-spew v1.1.2-0.20180830191138-d8f796af33cc // indirect
29-
github.com/emicklei/go-restful/v3 v3.12.2 // indirect
29+
github.com/emicklei/go-restful/v3 v3.13.0 // indirect
3030
github.com/evanphx/json-patch v5.9.0+incompatible // indirect
3131
github.com/evanphx/json-patch/v5 v5.9.11 // indirect
3232
github.com/fsnotify/fsnotify v1.9.0 // indirect
33-
github.com/fxamacker/cbor/v2 v2.8.0 // indirect
33+
github.com/fxamacker/cbor/v2 v2.9.0 // indirect
3434
github.com/go-logr/logr v1.4.3 // indirect
3535
github.com/go-logr/stdr v1.2.2 // indirect
36-
github.com/go-openapi/jsonpointer v0.21.1 // indirect
37-
github.com/go-openapi/jsonreference v0.21.0 // indirect
38-
github.com/go-openapi/swag v0.23.1 // indirect
36+
github.com/go-openapi/jsonpointer v0.22.1 // indirect
37+
github.com/go-openapi/jsonreference v0.21.2 // indirect
38+
github.com/go-openapi/swag v0.25.1 // indirect
39+
github.com/go-openapi/swag/cmdutils v0.25.1 // indirect
40+
github.com/go-openapi/swag/conv v0.25.1 // indirect
41+
github.com/go-openapi/swag/fileutils v0.25.1 // indirect
42+
github.com/go-openapi/swag/jsonname v0.25.1 // indirect
43+
github.com/go-openapi/swag/jsonutils v0.25.1 // indirect
44+
github.com/go-openapi/swag/loading v0.25.1 // indirect
45+
github.com/go-openapi/swag/mangling v0.25.1 // indirect
46+
github.com/go-openapi/swag/netutils v0.25.1 // indirect
47+
github.com/go-openapi/swag/stringutils v0.25.1 // indirect
48+
github.com/go-openapi/swag/typeutils v0.25.1 // indirect
49+
github.com/go-openapi/swag/yamlutils v0.25.1 // indirect
3950
github.com/gogo/protobuf v1.3.2 // indirect
40-
github.com/google/gnostic-models v0.6.9 // indirect
51+
github.com/google/gnostic-models v0.7.0 // indirect
4152
github.com/google/go-cmp v0.7.0 // indirect
4253
github.com/google/uuid v1.6.0 // indirect
4354
github.com/inconshreveable/mousetrap v1.1.0 // indirect
44-
github.com/josharian/intern v1.0.0 // indirect
4555
github.com/json-iterator/go v1.1.12 // indirect
46-
github.com/mailru/easyjson v0.9.0 // indirect
4756
github.com/mattn/go-colorable v0.1.14 // indirect
4857
github.com/mattn/go-isatty v0.0.20 // indirect
4958
github.com/modern-go/concurrent v0.0.0-20180306012644-bacd9c7ef1dd // indirect
50-
github.com/modern-go/reflect2 v1.0.2 // indirect
59+
github.com/modern-go/reflect2 v1.0.3-0.20250322232337-35a7c28c31ee // indirect
5160
github.com/munnerz/goautoneg v0.0.0-20191010083416-a7dc8b61c822 // indirect
5261
github.com/pmezard/go-difflib v1.0.1-0.20181226105442-5d4384ee4fb2 // indirect
53-
github.com/prometheus/client_golang v1.22.0 // indirect
62+
github.com/prometheus/client_golang v1.23.2 // indirect
5463
github.com/prometheus/client_model v0.6.2 // indirect
55-
github.com/prometheus/common v0.64.0 // indirect
56-
github.com/prometheus/procfs v0.16.1 // indirect
57-
github.com/samber/lo v1.51.0 // indirect
58-
github.com/spf13/pflag v1.0.6 // indirect
64+
github.com/prometheus/common v0.67.2 // indirect
65+
github.com/prometheus/procfs v0.19.2 // indirect
66+
github.com/samber/lo v1.52.0 // indirect
67+
github.com/spf13/pflag v1.0.10 // indirect
5968
github.com/x448/float16 v0.8.4 // indirect
60-
go.yaml.in/yaml/v2 v2.4.2 // indirect
61-
golang.org/x/net v0.41.0 // indirect
62-
golang.org/x/oauth2 v0.30.0 // indirect
63-
golang.org/x/sys v0.34.0 // indirect
64-
golang.org/x/term v0.33.0 // indirect
65-
golang.org/x/text v0.26.0 // indirect
66-
golang.org/x/time v0.12.0 // indirect
67-
google.golang.org/protobuf v1.36.6 // indirect
68-
gopkg.in/evanphx/json-patch.v4 v4.12.0 // indirect
69+
go.yaml.in/yaml/v2 v2.4.3 // indirect
70+
go.yaml.in/yaml/v3 v3.0.4 // indirect
71+
golang.org/x/net v0.46.0 // indirect
72+
golang.org/x/oauth2 v0.32.0 // indirect
73+
golang.org/x/sys v0.37.0 // indirect
74+
golang.org/x/term v0.36.0 // indirect
75+
golang.org/x/text v0.30.0 // indirect
76+
golang.org/x/time v0.14.0 // indirect
77+
google.golang.org/protobuf v1.36.10 // indirect
78+
gopkg.in/evanphx/json-patch.v4 v4.13.0 // indirect
6979
gopkg.in/inf.v0 v0.9.1 // indirect
70-
k8s.io/apiextensions-apiserver v0.33.1 // indirect
7180
k8s.io/klog/v2 v2.130.1 // indirect
72-
k8s.io/kube-openapi v0.0.0-20250610211856-8b98d1ed966a // indirect
73-
k8s.io/utils v0.0.0-20250604170112-4c0f3b243397 // indirect
74-
sigs.k8s.io/json v0.0.0-20241014173422-cfa47c3a1cc8 // indirect
81+
k8s.io/kube-openapi v0.0.0-20250910181357-589584f1c912 // indirect
82+
k8s.io/utils v0.0.0-20251002143259-bc988d571ff4 // indirect
83+
sigs.k8s.io/json v0.0.0-20250730193827-2d320260d730 // indirect
7584
sigs.k8s.io/randfill v1.0.0 // indirect
76-
sigs.k8s.io/structured-merge-diff/v4 v4.7.0 // indirect
85+
sigs.k8s.io/structured-merge-diff/v6 v6.3.0 // indirect
7786
)

0 commit comments

Comments
 (0)