Skip to content

Commit

Permalink
Upgrade Go to 1.20, other libraries to remove vulnerabilities (#41)
Browse files Browse the repository at this point in the history
  • Loading branch information
dmcwhorter-ddl authored Oct 27, 2023
1 parent 4671b69 commit 440b0c1
Show file tree
Hide file tree
Showing 13 changed files with 798 additions and 357 deletions.
2 changes: 1 addition & 1 deletion .circleci/config.yml
Original file line number Diff line number Diff line change
Expand Up @@ -16,7 +16,7 @@ jobs:
resource_class: medium
steps:
- go/install:
version: "1.17"
version: "1.20"
- run:
name: "Install kustomize"
command: |
Expand Down
4 changes: 2 additions & 2 deletions core-builder/Dockerfile
Original file line number Diff line number Diff line change
Expand Up @@ -91,8 +91,8 @@ RUN apt-get remove -y --auto-remove \

# INSTALL GO
ENV PATH /usr/local/go/bin:$PATH
RUN wget https://dl.google.com/go/go1.17.7.linux-amd64.tar.gz && \
tar -zxvf go1.17.7.linux-amd64.tar.gz && \
RUN wget https://dl.google.com/go/go1.20.10.linux-amd64.tar.gz && \
tar -zxvf go1.20.10.linux-amd64.tar.gz && \
mv go/ /usr/local/go

# Install kubebuilder (using github link)
Expand Down
4 changes: 2 additions & 2 deletions executor/Dockerfile.executor
Original file line number Diff line number Diff line change
@@ -1,5 +1,5 @@
# Build the manager binary
FROM golang:1.17.13-buster as builder
FROM golang:1.20.10-bookworm as builder

WORKDIR /workspace
# Copy the Go Modules manifests
Expand Down Expand Up @@ -56,7 +56,7 @@ RUN chmod -R 666 /openapi/ \

# Use distroless as minimal base image to package the manager binary
# Refer to https://github.com/GoogleContainerTools/distroless for more details
FROM gcr.io/distroless/base-debian11:nonroot
FROM gcr.io/distroless/base-debian12:nonroot
WORKDIR /
COPY --from=builder /workspace/executor .
COPY licenses/license.txt licenses/license.txt
Expand Down
2 changes: 1 addition & 1 deletion executor/Dockerfile.executor.redhat
Original file line number Diff line number Diff line change
@@ -1,5 +1,5 @@
# Build the manager binary
FROM golang:1.17.13-buster as builder
FROM golang:1.20.10-bookworm as builder

WORKDIR /workspace
# Copy the Go Modules manifests
Expand Down
41 changes: 20 additions & 21 deletions executor/go.mod
Original file line number Diff line number Diff line change
@@ -1,13 +1,13 @@
module github.com/seldonio/seldon-core/executor

go 1.17
go 1.20

require (
github.com/cloudevents/sdk-go v1.2.0
github.com/confluentinc/confluent-kafka-go v1.8.2
github.com/ghodss/yaml v1.0.0
github.com/go-logr/logr v1.2.3
github.com/golang/protobuf v1.5.2
github.com/golang/protobuf v1.5.3
github.com/google/uuid v1.3.0
github.com/gorilla/mux v1.8.0
github.com/grpc-ecosystem/go-grpc-middleware v1.3.0
Expand All @@ -24,21 +24,22 @@ require (
go.uber.org/automaxprocs v1.4.0
go.uber.org/zap v1.19.1
golang.org/x/xerrors v0.0.0-20220411194840-2f41105eb62f
google.golang.org/grpc v1.47.0
google.golang.org/protobuf v1.28.0
google.golang.org/grpc v1.56.3
google.golang.org/protobuf v1.30.0
gotest.tools v2.2.0+incompatible
k8s.io/api v0.24.2
k8s.io/api v0.25.0
sigs.k8s.io/controller-runtime v0.12.2
)

require (
github.com/PuerkitoBio/purell v1.1.1 // indirect
github.com/PuerkitoBio/urlesc v0.0.0-20170810143723-de5bf2ad4578 // indirect
github.com/beorn7/perks v1.0.1 // indirect
github.com/cespare/xxhash/v2 v2.1.2 // indirect
github.com/cespare/xxhash/v2 v2.2.0 // indirect
github.com/codahale/hdrhistogram v0.0.0-00010101000000-000000000000 // indirect
github.com/davecgh/go-spew v1.1.1 // indirect
github.com/emicklei/go-restful v2.15.0+incompatible // indirect
github.com/emicklei/go-restful/v3 v3.10.0 // indirect
github.com/evanphx/json-patch v5.6.0+incompatible // indirect
github.com/evanphx/json-patch/v5 v5.6.0 // indirect
github.com/fsnotify/fsnotify v1.5.1 // indirect
Expand All @@ -49,7 +50,7 @@ require (
github.com/gogo/protobuf v1.3.2 // indirect
github.com/golang/groupcache v0.0.0-20210331224755-41bb18bfe9da // indirect
github.com/google/gnostic v0.5.7-v3refs // indirect
github.com/google/go-cmp v0.5.8 // indirect
github.com/google/go-cmp v0.5.9 // indirect
github.com/google/gofuzz v1.2.0 // indirect
github.com/imdario/mergo v0.3.12 // indirect
github.com/josharian/intern v1.0.1-0.20211109044230-42b52b674af5 // indirect
Expand All @@ -70,37 +71,35 @@ require (
go.opencensus.io v0.23.0 // indirect
go.uber.org/atomic v1.9.0 // indirect
go.uber.org/multierr v1.6.0 // indirect
golang.org/x/net v0.15.0 // indirect
golang.org/x/oauth2 v0.0.0-20220411215720-9780585627b5 // indirect
golang.org/x/sys v0.12.0 // indirect
golang.org/x/term v0.12.0 // indirect
golang.org/x/net v0.17.0 // indirect
golang.org/x/oauth2 v0.7.0 // indirect
golang.org/x/sys v0.13.0 // indirect
golang.org/x/term v0.13.0 // indirect
golang.org/x/text v0.13.0 // indirect
golang.org/x/time v0.0.0-20220210224613-90d013bbcef8 // indirect
gomodules.xyz/jsonpatch/v2 v2.2.0 // indirect
google.golang.org/appengine v1.6.7 // indirect
google.golang.org/genproto v0.0.0-20220628213854-d9e0b6570c03 // indirect
google.golang.org/genproto v0.0.0-20230410155749-daa745c078e1 // indirect
gopkg.in/inf.v0 v0.9.1 // indirect
gopkg.in/yaml.v2 v2.4.0 // indirect
gopkg.in/yaml.v3 v3.0.1 // indirect
k8s.io/apiextensions-apiserver v0.24.2 // indirect
k8s.io/apimachinery v0.24.2 // indirect
k8s.io/client-go v12.0.0+incompatible // indirect
k8s.io/apimachinery v0.25.0 // indirect
k8s.io/client-go v0.25.0 // indirect
k8s.io/component-base v0.24.2 // indirect
k8s.io/klog/v2 v2.60.1 // indirect
k8s.io/kube-openapi v0.0.0-20220328201542-3ee0da9b0b42 // indirect
k8s.io/utils v0.0.0-20220210201930-3a6ce19ff2f9 // indirect
k8s.io/klog/v2 v2.70.1 // indirect
k8s.io/kube-openapi v0.0.0-20220803162953-67bda5d908f1 // indirect
k8s.io/utils v0.0.0-20220728103510-ee6ede2d64ed // indirect
knative.dev/pkg v0.0.0-20220502225657-4fced0164c9a // indirect
sigs.k8s.io/json v0.0.0-20211208200746-9f7c6b3444d2 // indirect
sigs.k8s.io/structured-merge-diff/v4 v4.2.1 // indirect
sigs.k8s.io/json v0.0.0-20220713155537-f223a00ba0e2 // indirect
sigs.k8s.io/structured-merge-diff/v4 v4.2.3 // indirect
sigs.k8s.io/yaml v1.3.0 // indirect
)

replace github.com/tensorflow/tensorflow/tensorflow/go/core => ./proto/tensorflow/core

replace github.com/seldonio/seldon-core/operator => ./_operator

replace k8s.io/client-go => k8s.io/client-go v0.24.2

replace github.com/codahale/hdrhistogram => github.com/HdrHistogram/hdrhistogram-go v1.1.2

exclude github.com/go-logr/logr v1.0.0
Loading

0 comments on commit 440b0c1

Please sign in to comment.