Skip to content

Commit dfd0b2b

Browse files
authored
CVE-2025-27144: pin go-jose/v4@v4.0.5 (#3550)
1 parent 98b975a commit dfd0b2b

File tree

2 files changed

+2
-0
lines changed

2 files changed

+2
-0
lines changed

Diff for: go.mod

+1
Original file line numberDiff line numberDiff line change
@@ -190,6 +190,7 @@ require (
190190
replace google.golang.org/grpc => google.golang.org/grpc v1.63.2
191191

192192
replace (
193+
github.com/go-jose/go-jose/v4 => github.com/go-jose/go-jose/v4 v4.0.5 // CVE-2025-27144
193194
// controller runtime
194195
github.com/openshift/api => github.com/openshift/api v0.0.0-20221021112143-4226c2167e40 // release-4.12
195196
github.com/openshift/client-go => github.com/openshift/client-go v0.0.0-20221019143426-16aed247da5c // release-4.12

Diff for: vendor/modules.txt

+1
Original file line numberDiff line numberDiff line change
@@ -1886,5 +1886,6 @@ sigs.k8s.io/structured-merge-diff/v4/value
18861886
sigs.k8s.io/yaml
18871887
sigs.k8s.io/yaml/goyaml.v2
18881888
# google.golang.org/grpc => google.golang.org/grpc v1.63.2
1889+
# github.com/go-jose/go-jose/v4 => github.com/go-jose/go-jose/v4 v4.0.5
18891890
# github.com/openshift/api => github.com/openshift/api v0.0.0-20221021112143-4226c2167e40
18901891
# github.com/openshift/client-go => github.com/openshift/client-go v0.0.0-20221019143426-16aed247da5c

0 commit comments

Comments
 (0)