diff --git a/.nancy-ignore b/.nancy-ignore index 3f2671c..5b0a3ec 100644 --- a/.nancy-ignore +++ b/.nancy-ignore @@ -1,19 +1,2 @@ -# Non-CVE findings, added with 1 year of exception time. -# If these stay open for more than a year, we might have unmaintained dependencies. -sonatype-2021-1401 until=2024-03-14 -sonatype-2022-6522 until=2024-03-14 - -# hashicorp/consul/sdk and /api are not intended for public use and won't receive future releases. -# Waiting for upstream to move away from it. -CVE-2021-41803 until=2024-03-14 -CVE-2022-29153 until=2024-03-14 -CVE-2022-24687 until=2024-03-14 -# Unresolved as of 2022/06/02 - -sonatype-2022-6522 until=2023-06-06 -CVE-2020-8561 - -CVE-2023-32731 - -# pkg:golang/golang.org/x/net@v0.29.0 -CVE-2024-8421 +# pkg:golang/golang.org/x/net@v0.32.0 +CVE-2024-45338 diff --git a/go.mod b/go.mod index 29bcc32..d5e15da 100644 --- a/go.mod +++ b/go.mod @@ -15,7 +15,7 @@ require ( k8s.io/api v0.32.0 k8s.io/apimachinery v0.32.0 k8s.io/client-go v0.32.0 - sigs.k8s.io/cluster-api v1.9.1 + sigs.k8s.io/cluster-api v1.9.2 sigs.k8s.io/controller-runtime v0.19.3 ) diff --git a/go.sum b/go.sum index 67f5aaa..3e793bd 100644 --- a/go.sum +++ b/go.sum @@ -172,8 +172,8 @@ k8s.io/kube-openapi v0.0.0-20241105132330-32ad38e42d3f h1:GA7//TjRY9yWGy1poLzYYJ k8s.io/kube-openapi v0.0.0-20241105132330-32ad38e42d3f/go.mod h1:R/HEjbvWI0qdfb8viZUeVZm0X6IZnxAydC7YU42CMw4= k8s.io/utils v0.0.0-20241104100929-3ea5e8cea738 h1:M3sRQVHv7vB20Xc2ybTt7ODCeFj6JSWYFzOFnYeS6Ro= k8s.io/utils v0.0.0-20241104100929-3ea5e8cea738/go.mod h1:OLgZIPagt7ERELqWJFomSt595RzquPNLL48iOWgYOg0= -sigs.k8s.io/cluster-api v1.9.1 h1:s2YUB66XceK+EQ3Uq8Mq/N9TgqRU4TQUMsaQYXOIWlU= -sigs.k8s.io/cluster-api v1.9.1/go.mod h1:pkFqVPq0ELlJgyDjgqpb4MU1XnWEi98B2q3DbEjC4ww= +sigs.k8s.io/cluster-api v1.9.2 h1:4nUcIg/nOccn7/O1FF1IJaxQqjOxl+gH4ejQ9D/P+l8= +sigs.k8s.io/cluster-api v1.9.2/go.mod h1:pkFqVPq0ELlJgyDjgqpb4MU1XnWEi98B2q3DbEjC4ww= sigs.k8s.io/controller-runtime v0.19.3 h1:XO2GvC9OPftRst6xWCpTgBZO04S2cbp0Qqkj8bX1sPw= sigs.k8s.io/controller-runtime v0.19.3/go.mod h1:j4j87DqtsThvwTv5/Tc5NFRyyF/RF0ip4+62tbTSIUM= sigs.k8s.io/json v0.0.0-20241010143419-9aa6b5e7a4b3 h1:/Rv+M11QRah1itp8VhT6HoVx1Ray9eB4DBr+K+/sCJ8=