Skip to content

Commit 5fd3fad

Browse files
committed
Migrate to golang-jwt v3.2.1
Fix for GHSA-w73w-5m7g-f7qc Signed-off-by: Hasan Turken <[email protected]>
1 parent e9a7329 commit 5fd3fad

File tree

7 files changed

+8
-6
lines changed

7 files changed

+8
-6
lines changed

cmd/upbound-agent/main.go

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -24,7 +24,7 @@ import (
2424
"strings"
2525

2626
"github.com/alecthomas/kong"
27-
"github.com/dgrijalva/jwt-go"
27+
"github.com/golang-jwt/jwt"
2828
"github.com/google/uuid"
2929
"github.com/pkg/errors"
3030
corev1 "k8s.io/api/core/v1"

go.mod

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -8,8 +8,8 @@ require (
88
github.com/aws/aws-sdk-go-v2/config v1.1.4
99
github.com/aws/aws-sdk-go-v2/service/marketplacemetering v1.2.1
1010
github.com/crossplane/crossplane-runtime v0.13.1-0.20210504165942-53874539b310
11-
github.com/dgrijalva/jwt-go v3.2.0+incompatible
1211
github.com/go-resty/resty/v2 v2.5.0
12+
github.com/golang-jwt/jwt v3.2.1+incompatible
1313
github.com/golang/mock v1.5.0
1414
github.com/google/addlicense v0.0.0-20210428195630-6d92264d7170
1515
github.com/google/go-cmp v0.5.5

go.sum

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -218,6 +218,8 @@ github.com/gogo/protobuf v1.2.1/go.mod h1:hp+jE20tsWTFYpLwKvXlhS1hjn+gTNwPg2I6zV
218218
github.com/gogo/protobuf v1.2.2-0.20190723190241-65acae22fc9d/go.mod h1:SlYgWuQ5SjCEi6WLHjHCa1yvBfUnHcTbrrZtXPKa29o=
219219
github.com/gogo/protobuf v1.3.1 h1:DqDEcV5aeaTmdFBePNpYsp3FlcVH/2ISVVM9Qf8PSls=
220220
github.com/gogo/protobuf v1.3.1/go.mod h1:SlYgWuQ5SjCEi6WLHjHCa1yvBfUnHcTbrrZtXPKa29o=
221+
github.com/golang-jwt/jwt v3.2.1+incompatible h1:73Z+4BJcrTC+KczS6WvTPvRGOp1WmfEP4Q1lOd9Z/+c=
222+
github.com/golang-jwt/jwt v3.2.1+incompatible/go.mod h1:8pz2t5EyA70fFQQSrl6XZXzqecmYZeUEB8OUGHkxJ+I=
221223
github.com/golang/glog v0.0.0-20160126235308-23def4e6c14b/go.mod h1:SBH7ygxi8pfUlaOkMMuAQtPIUF8ecWP5IEl/CR7VP2Q=
222224
github.com/golang/groupcache v0.0.0-20160516000752-02826c3e7903/go.mod h1:cIg4eruTrX1D+g88fzRXU5OdNfaM+9IcxsU14FzY7Hc=
223225
github.com/golang/groupcache v0.0.0-20190129154638-5b532d6fd5ef/go.mod h1:cIg4eruTrX1D+g88fzRXU5OdNfaM+9IcxsU14FzY7Hc=

internal/controllers/billing/aws/aws.go

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -21,7 +21,7 @@ import (
2121

2222
"github.com/aws/aws-sdk-go-v2/aws"
2323
"github.com/aws/aws-sdk-go-v2/service/marketplacemetering"
24-
"github.com/dgrijalva/jwt-go"
24+
"github.com/golang-jwt/jwt"
2525
"github.com/pkg/errors"
2626
v1 "k8s.io/api/core/v1"
2727
"sigs.k8s.io/controller-runtime/pkg/client"

internal/upboundagent/internal/upboundapi.go

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -14,7 +14,7 @@
1414

1515
package internal
1616

17-
import "github.com/dgrijalva/jwt-go"
17+
import "github.com/golang-jwt/jwt"
1818

1919
// CrossplaneAccessor is the struct holding accessor info in JWT custom claims
2020
type CrossplaneAccessor struct {

internal/upboundagent/proxy.go

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -28,7 +28,7 @@ import (
2828
"syscall"
2929
"time"
3030

31-
"github.com/dgrijalva/jwt-go"
31+
"github.com/golang-jwt/jwt"
3232
"github.com/google/uuid"
3333
"github.com/labstack/echo-contrib/jaegertracing"
3434
"github.com/labstack/echo-contrib/prometheus"

internal/upboundagent/proxy_test.go

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -25,7 +25,7 @@ import (
2525

2626
"github.com/crossplane/crossplane-runtime/pkg/logging"
2727

28-
"github.com/dgrijalva/jwt-go"
28+
"github.com/golang-jwt/jwt"
2929
"github.com/google/go-cmp/cmp"
3030
"github.com/labstack/echo/v4"
3131
"github.com/pkg/errors"

0 commit comments

Comments
 (0)