@@ -19,7 +19,7 @@ require (
1919 github.com/coreos/go-oidc/v3 v3.7.0
2020 github.com/doublerebel/bellows v0.0.0-20160303004610-f177d92a03d3
2121 github.com/evanphx/json-patch v5.8.0+incompatible
22- github.com/expr-lang/expr v1.16.9
22+ github.com/expr-lang/expr v1.17.5
2323 github.com/gavv/httpexpect/v2 v2.16.0
2424 github.com/go-git/go-git/v5 v5.13.1
2525 github.com/go-jose/go-jose/v3 v3.0.3
@@ -55,10 +55,10 @@ require (
5555 github.com/upper/db/v4 v4.7.0
5656 github.com/valyala/fasttemplate v1.2.2
5757 github.com/xeipuuv/gojsonschema v1.2.0
58- golang.org/x/crypto v0.31 .0
58+ golang.org/x/crypto v0.35 .0
5959 golang.org/x/exp v0.0.0-20240719175910-8a7402abbf56
60- golang.org/x/oauth2 v0.21 .0
61- golang.org/x/sync v0.10 .0
60+ golang.org/x/oauth2 v0.27 .0
61+ golang.org/x/sync v0.11 .0
6262 golang.org/x/time v0.5.0
6363 google.golang.org/api v0.163.0
6464 google.golang.org/genproto/googleapis/api v0.0.0-20240513163218-0867130af1f8
@@ -88,7 +88,7 @@ require (
8888 github.com/fatih/color v1.15.0 // indirect
8989 github.com/go-logr/stdr v1.2.2 // indirect
9090 github.com/gobwas/glob v0.2.4-0.20181002190808-e7a84e9525fe // indirect
91- github.com/golang-jwt/jwt/v5 v5.2.1 // indirect
91+ github.com/golang-jwt/jwt/v5 v5.2.2 // indirect
9292 github.com/google/s2a-go v0.1.7 // indirect
9393 github.com/jackc/chunkreader/v2 v2.0.1 // indirect
9494 github.com/jackc/pgconn v1.14.3 // indirect
@@ -198,7 +198,7 @@ require (
198198 github.com/go-logr/logr v1.4.2 // indirect
199199 github.com/go-openapi/jsonpointer v0.19.6 // indirect
200200 github.com/go-openapi/swag v0.22.3 // indirect
201- github.com/golang-jwt/jwt/v4 v4.5.0 // indirect
201+ github.com/golang-jwt/jwt/v4 v4.5.2 // indirect
202202 github.com/golang/groupcache v0.0.0-20210331224755-41bb18bfe9da // indirect
203203 github.com/golang/mock v1.6.0
204204 github.com/google/btree v1.0.1 // indirect
@@ -281,9 +281,9 @@ require (
281281 go.opencensus.io v0.24.0 // indirect
282282 go.starlark.net v0.0.0-20230525235612-a134d8f9ddca // indirect
283283 golang.org/x/net v0.33.0 // indirect
284- golang.org/x/sys v0.28 .0
285- golang.org/x/term v0.27 .0
286- golang.org/x/text v0.21 .0 // indirect
284+ golang.org/x/sys v0.30 .0
285+ golang.org/x/term v0.29 .0
286+ golang.org/x/text v0.22 .0 // indirect
287287 google.golang.org/protobuf v1.34.2 // indirect
288288 gopkg.in/inf.v0 v0.9.1 // indirect
289289 gopkg.in/ini.v1 v1.67.0 // indirect
@@ -300,6 +300,3 @@ require (
300300 sigs.k8s.io/kustomize/kyaml v0.13.9 // indirect
301301 sigs.k8s.io/structured-merge-diff/v4 v4.2.3 // indirect
302302)
303-
304- // Avoid CVE-2023-45288
305- replace golang.org/x/net => golang.org/x/net v0.23.0
0 commit comments