Skip to content

Commit 9c1b1d1

Browse files
committed
CVE-2025-27144: pin go-jose/[email protected] (#3550)
Upstream-repository: operator-lifecycle-manager Upstream-commit: dfd0b2bea85038d3c0d65348bc812d297f16b8d2
1 parent cc44b48 commit 9c1b1d1

File tree

9 files changed

+14
-25
lines changed

9 files changed

+14
-25
lines changed

go.mod

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -87,7 +87,7 @@ require (
8787
github.com/go-git/gcfg v1.5.1-0.20230307220236-3a3c6141e376 // indirect
8888
github.com/go-git/go-billy/v5 v5.6.1 // indirect
8989
github.com/go-git/go-git/v5 v5.13.1 // indirect
90-
github.com/go-jose/go-jose/v4 v4.0.4 // indirect
90+
github.com/go-jose/go-jose/v4 v4.0.5 // indirect
9191
github.com/go-logr/stdr v1.2.2 // indirect
9292
github.com/go-logr/zapr v1.3.0 // indirect
9393
github.com/go-openapi/jsonpointer v0.21.0 // indirect

go.sum

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1544,8 +1544,8 @@ github.com/go-git/go-git/v5 v5.13.1/go.mod h1:qryJB4cSBoq3FRoBRf5A77joojuBcmPJ0q
15441544
github.com/go-gl/glfw v0.0.0-20190409004039-e6da0acd62b1/go.mod h1:vR7hzQXu2zJy9AVAgeJqvqgH9Q5CA+iKCZ2gyEVpxRU=
15451545
github.com/go-gl/glfw/v3.3/glfw v0.0.0-20191125211704-12ad95a8df72/go.mod h1:tQ2UAYgL5IevRw8kRxooKSPJfGvJ9fJQFa0TUsXzTg8=
15461546
github.com/go-gl/glfw/v3.3/glfw v0.0.0-20200222043503-6f7a984d4dc4/go.mod h1:tQ2UAYgL5IevRw8kRxooKSPJfGvJ9fJQFa0TUsXzTg8=
1547-
github.com/go-jose/go-jose/v4 v4.0.4 h1:VsjPI33J0SB9vQM6PLmNjoHqMQNGPiZ0rHL7Ni7Q6/E=
1548-
github.com/go-jose/go-jose/v4 v4.0.4/go.mod h1:NKb5HO1EZccyMpiZNbdUw/14tiXNyUJh188dfnMCAfc=
1547+
github.com/go-jose/go-jose/v4 v4.0.5 h1:M6T8+mKZl/+fNNuFHvGIzDz7BTLQPIounk/b9dw3AaE=
1548+
github.com/go-jose/go-jose/v4 v4.0.5/go.mod h1:s3P1lRrkT8igV8D9OjyL4WRyHvjB6a4JSllnOrmmBOA=
15491549
github.com/go-kit/kit v0.8.0/go.mod h1:xBxKIO96dXMWWy0MnWVtmwkA9/13aqxPnvrjFYMA2as=
15501550
github.com/go-latex/latex v0.0.0-20210118124228-b3d85cf34e07/go.mod h1:CO1AlKB2CSIqUrmQPqA0gdRIlnLEY0gK5JGjh37zN5U=
15511551
github.com/go-latex/latex v0.0.0-20210823091927-c0d11ff05a81/go.mod h1:SX0U8uGpxhq9o2S/CELCSUxEWWAuoCUcVCQWv7G2OCk=

staging/operator-lifecycle-manager/go.mod

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -185,6 +185,7 @@ require (
185185
replace google.golang.org/grpc => google.golang.org/grpc v1.63.2
186186

187187
replace (
188+
github.com/go-jose/go-jose/v4 => github.com/go-jose/go-jose/v4 v4.0.5 // CVE-2025-27144
188189
// controller runtime
189190
github.com/openshift/api => github.com/openshift/api v0.0.0-20221021112143-4226c2167e40 // release-4.12
190191
github.com/openshift/client-go => github.com/openshift/client-go v0.0.0-20221019143426-16aed247da5c // release-4.12

vendor/github.com/go-jose/go-jose/v4/CONTRIBUTING.md

Lines changed: 0 additions & 6 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

vendor/github.com/go-jose/go-jose/v4/README.md

Lines changed: 1 addition & 9 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

vendor/github.com/go-jose/go-jose/v4/jwe.go

Lines changed: 3 additions & 2 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

vendor/github.com/go-jose/go-jose/v4/jwk.go

Lines changed: 2 additions & 2 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

vendor/github.com/go-jose/go-jose/v4/jws.go

Lines changed: 3 additions & 2 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

vendor/modules.txt

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -291,7 +291,7 @@ github.com/go-git/go-git/v5/internal/path_util
291291
github.com/go-git/go-git/v5/plumbing/format/config
292292
github.com/go-git/go-git/v5/plumbing/format/gitignore
293293
github.com/go-git/go-git/v5/utils/ioutil
294-
# github.com/go-jose/go-jose/v4 v4.0.4
294+
# github.com/go-jose/go-jose/v4 v4.0.5
295295
## explicit; go 1.21
296296
github.com/go-jose/go-jose/v4
297297
github.com/go-jose/go-jose/v4/cipher

0 commit comments

Comments
 (0)