diff --git a/CHANGELOG.md b/CHANGELOG.md index 806c96b7704..fd350853a0d 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -65,7 +65,7 @@ To learn more about active deprecations, we recommend checking [GitHub Discussio ### Other -- TODO ([#XXX](https://github.com/kedacore/keda/issue/XXX)) +- **General**: Drop a transitive dependency on bou.ke/monkey ([#4364](https://github.com/kedacore/keda/issues/4364)) ## v2.10.0 diff --git a/go.mod b/go.mod index f2e7aa23a59..b105a6dd135 100644 --- a/go.mod +++ b/go.mod @@ -36,6 +36,7 @@ require ( github.com/gocql/gocql v1.3.1 github.com/golang/mock v1.6.0 github.com/google/go-cmp v0.5.9 + github.com/google/go-github/v50 v50.1.0 github.com/google/uuid v1.3.0 github.com/gophercloud/gophercloud v1.2.0 github.com/hashicorp/vault/api v1.9.0 @@ -98,6 +99,9 @@ replace ( // https://nvd.nist.gov/vuln/detail/CVE-2022-1996 github.com/emicklei/go-restful => github.com/emicklei/go-restful v2.16.0+incompatible + // we need to drop a transitive dependency on bou.ke/monkey -> https://github.com/kedacore/keda/issues/4364 + github.com/otiai10/mint => github.com/otiai10/mint v1.4.1 + // https://avd.aquasec.com/nvd/2022/cve-2022-27191/ golang.org/x/crypto => golang.org/x/crypto v0.0.0-20220829220503-c86fa9a7ed90 @@ -176,7 +180,6 @@ require ( github.com/golang/snappy v0.0.4 // indirect github.com/google/cel-go v0.13.0 // indirect github.com/google/gnostic v0.6.9 // indirect - github.com/google/go-github/v50 v50.1.0 // indirect github.com/google/go-querystring v1.1.0 // indirect github.com/google/gofuzz v1.2.0 // indirect github.com/google/pprof v0.0.0-20230228050547-1710fef4ab10 // indirect diff --git a/go.sum b/go.sum index b74733895a3..2ac26aedcf9 100644 --- a/go.sum +++ b/go.sum @@ -1,4 +1,3 @@ -bou.ke/monkey v1.0.1/go.mod h1:FgHuK96Rv2Nlf+0u1OOVDpCMdsWyOFmeeketDHE7LIg= cloud.google.com/go v0.26.0/go.mod h1:aQUYkXzVsufM+DwF1aE+0xfcU+56JwCaLick0ClmMTw= cloud.google.com/go v0.34.0/go.mod h1:aQUYkXzVsufM+DwF1aE+0xfcU+56JwCaLick0ClmMTw= cloud.google.com/go v0.38.0/go.mod h1:990N+gfupTy94rShfmMCWGDn0LpTmnzTp2qbd1dvSRU= @@ -628,12 +627,9 @@ github.com/opentracing/opentracing-go v1.1.0/go.mod h1:UkNAQd3GIcIGf0SeVgPpRdFSt github.com/otiai10/copy v1.0.2/go.mod h1:c7RpqBkwMom4bYTSkLSym4VSJz/XtncWRAj/J4PEIMY= github.com/otiai10/copy v1.7.0 h1:hVoPiN+t+7d2nzzwMiDHPSOogsWAStewq3TwU05+clE= github.com/otiai10/copy v1.7.0/go.mod h1:rmRl6QPdJj6EiUqXQ/4Nn2lLXoNQjFCQbbNrxgc/t3U= -github.com/otiai10/curr v0.0.0-20150429015615-9b4961190c95/go.mod h1:9qAhocn7zKJG+0mI8eUu6xqkFDYS2kb2saOteoSB3cE= github.com/otiai10/curr v0.0.0-20190513014714-f5a3d24e5776/go.mod h1:3HNVkVOU7vZeFXocWuvtcS0XSFLcf2XUSDHkq9t1jU4= github.com/otiai10/curr v1.0.0/go.mod h1:LskTG5wDwr8Rs+nNQ+1LlxRjAtTZZjtJW4rMXl6j4vs= -github.com/otiai10/mint v1.2.4/go.mod h1:d+b7n/0R3tdyUYYylALXpWQ/kTN+QobSq/4SRGBkR3M= -github.com/otiai10/mint v1.3.0/go.mod h1:F5AjcsTsWUqX+Na9fpHb52P8pcRX2CI6A3ctIT91xUo= -github.com/otiai10/mint v1.3.3/go.mod h1:/yxELlJQ0ufhjUwhshSj+wFjZ78CnZ48/1wtmBH1OTc= +github.com/otiai10/mint v1.4.1/go.mod h1:gifjb2MYOoULtKLqUAEILUG/9KONW6f7YsJ6vQLTlFI= github.com/phayes/freeport v0.0.0-20220201140144-74d24b5ae9f5 h1:Ii+DKncOVM8Cu1Hc+ETb5K+23HdAMvESYE3ZJ5b5cMI= github.com/phayes/freeport v0.0.0-20220201140144-74d24b5ae9f5/go.mod h1:iIss55rKnNBTvrwdmkUpLnDpZoAHvWaiq5+iMmen4AE= github.com/pierrec/lz4/v4 v4.1.17 h1:kV4Ip+/hUBC+8T6+2EgburRtkE9ef4nbY3f4dFhGjMc= diff --git a/vendor/modules.txt b/vendor/modules.txt index 12d6fcff23a..5b5e474138a 100644 --- a/vendor/modules.txt +++ b/vendor/modules.txt @@ -1193,7 +1193,6 @@ go.uber.org/zap/zapcore go.uber.org/zap/zapgrpc # golang.org/x/crypto v0.6.0 => golang.org/x/crypto v0.0.0-20220829220503-c86fa9a7ed90 ## explicit; go 1.17 -golang.org/x/crypto/blake2b golang.org/x/crypto/cast5 golang.org/x/crypto/cryptobyte golang.org/x/crypto/cryptobyte/asn1 @@ -2402,6 +2401,7 @@ sigs.k8s.io/yaml # github.com/chzyer/logex => github.com/chzyer/logex v1.2.1 # github.com/dgrijalva/jwt-go => github.com/golang-jwt/jwt/v4 v4.1.0 # github.com/emicklei/go-restful => github.com/emicklei/go-restful v2.16.0+incompatible +# github.com/otiai10/mint => github.com/otiai10/mint v1.4.1 # golang.org/x/crypto => golang.org/x/crypto v0.0.0-20220829220503-c86fa9a7ed90 # golang.org/x/net => golang.org/x/net v0.7.0 # golang.org/x/text => golang.org/x/text v0.7.0