Skip to content

Commit 5b88a5e

Browse files
Merge pull request #6526 from pmtk/grpc-cve-4.19
[release-4.19] OCPBUGS-80370: Replace google.golang.org/grpc with openshift-sustaining fork
2 parents 7696d74 + c482d66 commit 5b88a5e

476 files changed

Lines changed: 61793 additions & 24716 deletions

File tree

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

etcd/go.mod

Lines changed: 18 additions & 16 deletions
Original file line numberDiff line numberDiff line change
@@ -28,7 +28,7 @@ require (
2828
github.com/fxamacker/cbor/v2 v2.7.0 // indirect
2929
github.com/go-logr/stdr v1.2.2 // indirect
3030
github.com/google/gnostic-models v0.6.9 // indirect
31-
github.com/google/go-cmp v0.6.0 // indirect
31+
github.com/google/go-cmp v0.7.0 // indirect
3232
github.com/grpc-ecosystem/grpc-gateway/v2 v2.25.1 // indirect
3333
github.com/klauspost/compress v1.17.11 // indirect
3434
github.com/mxk/go-flowrate v0.0.0-20140419014527-cca7078d478f // indirect
@@ -38,12 +38,12 @@ require (
3838
github.com/vishvananda/netns v0.0.4 // indirect
3939
github.com/x448/float16 v0.8.4 // indirect
4040
go.opentelemetry.io/auto/sdk v1.1.0 // indirect
41-
go.opentelemetry.io/otel/metric v1.34.0 // indirect
41+
go.opentelemetry.io/otel/metric v1.37.0 // indirect
4242
go.yaml.in/yaml/v2 v2.4.2 // indirect
4343
go.yaml.in/yaml/v3 v3.0.3 // indirect
44-
golang.org/x/sync v0.12.0 // indirect
45-
google.golang.org/genproto/googleapis/api v0.0.0-20250115164207-1a7da9e5054f // indirect
46-
google.golang.org/genproto/googleapis/rpc v0.0.0-20250115164207-1a7da9e5054f // indirect
44+
golang.org/x/sync v0.15.0 // indirect
45+
google.golang.org/genproto/googleapis/api v0.0.0-20250707201910-8d1bb00bc6a7 // indirect
46+
google.golang.org/genproto/googleapis/rpc v0.0.0-20250707201910-8d1bb00bc6a7 // indirect
4747
gopkg.in/evanphx/json-patch.v4 v4.12.0 // indirect
4848
k8s.io/apiserver v1.32.13 // indirect
4949
)
@@ -64,7 +64,7 @@ require (
6464
github.com/evanphx/json-patch v4.12.0+incompatible // indirect
6565
github.com/exponent-io/jsonpath v0.0.0-20210407135951-1de76d718b3f // indirect
6666
github.com/go-errors/errors v1.4.2 // indirect
67-
github.com/go-logr/logr v1.4.2 // indirect
67+
github.com/go-logr/logr v1.4.3 // indirect
6868
github.com/go-openapi/jsonpointer v0.21.0 // indirect
6969
github.com/go-openapi/jsonreference v0.21.0 // indirect
7070
github.com/go-openapi/swag v0.23.0 // indirect
@@ -112,24 +112,24 @@ require (
112112
go.etcd.io/etcd/pkg/v3 v3.5.26 // indirect
113113
go.etcd.io/etcd/raft/v3 v3.5.26 // indirect
114114
go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc v0.53.0 // indirect
115-
go.opentelemetry.io/otel v1.34.0 // indirect
115+
go.opentelemetry.io/otel v1.37.0 // indirect
116116
go.opentelemetry.io/otel/exporters/otlp/otlptrace v1.34.0 // indirect
117117
go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc v1.34.0 // indirect
118-
go.opentelemetry.io/otel/sdk v1.34.0 // indirect
119-
go.opentelemetry.io/otel/trace v1.34.0 // indirect
118+
go.opentelemetry.io/otel/sdk v1.37.0 // indirect
119+
go.opentelemetry.io/otel/trace v1.37.0 // indirect
120120
go.opentelemetry.io/proto/otlp v1.5.0 // indirect
121121
go.uber.org/multierr v1.11.0 // indirect
122122
go.uber.org/zap v1.27.0 // indirect
123-
golang.org/x/crypto v0.36.0 // indirect
124-
golang.org/x/net v0.38.0 // indirect
125-
golang.org/x/oauth2 v0.25.0 // indirect
126-
golang.org/x/sys v0.31.0 // indirect
127-
golang.org/x/term v0.30.0 // indirect
128-
golang.org/x/text v0.23.0 // indirect
123+
golang.org/x/crypto v0.39.0 // indirect
124+
golang.org/x/net v0.41.0 // indirect
125+
golang.org/x/oauth2 v0.30.0 // indirect
126+
golang.org/x/sys v0.33.0 // indirect
127+
golang.org/x/term v0.32.0 // indirect
128+
golang.org/x/text v0.26.0 // indirect
129129
golang.org/x/time v0.9.0 // indirect
130130
google.golang.org/genproto v0.0.0-20240123012728-ef4313101c80 // indirect
131131
google.golang.org/grpc v1.71.1 // indirect
132-
google.golang.org/protobuf v1.36.4 // indirect
132+
google.golang.org/protobuf v1.36.6 // indirect
133133
gopkg.in/inf.v0 v0.9.1 // indirect
134134
gopkg.in/natefinch/lumberjack.v2 v2.2.1 // indirect
135135
gopkg.in/yaml.v3 v3.0.1 // indirect
@@ -188,3 +188,5 @@ replace (
188188
k8s.io/sample-cli-plugin => ../deps/github.com/openshift/kubernetes/staging/src/k8s.io/sample-cli-plugin
189189
k8s.io/sample-controller => ../deps/github.com/openshift/kubernetes/staging/src/k8s.io/sample-controller
190190
)
191+
192+
replace google.golang.org/grpc => github.com/openshift-sustaining/grpc-go v1.75.1-sec.1

etcd/go.sum

Lines changed: 2110 additions & 48 deletions
Large diffs are not rendered by default.

etcd/vendor/github.com/go-logr/logr/.golangci.yaml

Lines changed: 9 additions & 7 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

etcd/vendor/github.com/go-logr/logr/funcr/funcr.go

Lines changed: 4 additions & 4 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

etcd/vendor/github.com/google/go-cmp/cmp/internal/function/func.go

Lines changed: 7 additions & 0 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

etcd/vendor/github.com/google/go-cmp/cmp/options.go

Lines changed: 9 additions & 1 deletion
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

etcd/vendor/go.opentelemetry.io/otel/.clomonitor.yml

Lines changed: 3 additions & 0 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

etcd/vendor/go.opentelemetry.io/otel/.gitignore

Lines changed: 1 addition & 0 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

0 commit comments

Comments
 (0)