Skip to content

build(deps): bump deps specifically CVE-2024-45338#1128

Merged
thozza merged 1 commit intoosbuild:mainfrom
lzap:gobump1
Jan 8, 2025
Merged

build(deps): bump deps specifically CVE-2024-45338#1128
thozza merged 1 commit intoosbuild:mainfrom
lzap:gobump1

Conversation

@lzap
Copy link
Copy Markdown
Contributor

@lzap lzap commented Jan 6, 2025

SSIA

@lzap
Copy link
Copy Markdown
Contributor Author

lzap commented Jan 6, 2025

Excluded images from the update, incompatible change.

@lzap
Copy link
Copy Markdown
Contributor Author

lzap commented Jan 6, 2025

The same issue as in osbuild/osbuild-composer#4545 trying to solve it.

@lzap
Copy link
Copy Markdown
Contributor Author

lzap commented Jan 7, 2025

For the record, this is how I solved it:

lzap@dev:~/images$ tools/prepare-source.sh
+ GO_VERSION=1.21.13
++ go env GOPATH
+ GO_BINARY=/home/lzap/go/bin/go1.21.13
+ go install golang.org/dl/go1.21.13@latest
+ /home/lzap/go/bin/go1.21.13 download
go1.21.13: already downloaded in /home/lzap/sdk/go1.21.13
+ /home/lzap/go/bin/go1.21.13 mod tidy
go: github.com/osbuild/images/pkg/cloud/gcp imports
        cloud.google.com/go/storage imports
        google.golang.org/grpc/stats/opentelemetry: ambiguous import: found package google.golang.org/grpc/stats/opentelemetry in multiple modules:
        google.golang.org/grpc v1.67.3 (/home/lzap/go/pkg/mod/google.golang.org/grpc@v1.67.3/stats/opentelemetry)
        google.golang.org/grpc/stats/opentelemetry v0.0.0-20240907200651-3ffb98b2c93a (/home/lzap/go/pkg/mod/google.golang.org/grpc/stats/opentelemetry@v0.0.0-20240907200651-3ffb98b2c93a)

lzap@dev:~/images$ go get google.golang.org/grpc/stats/opentelemetry@none
go: downgraded cloud.google.com/go/storage v1.44.0 => v1.43.0
go: removed google.golang.org/grpc/stats/opentelemetry v0.0.0-20240907200651-3ffb98b2c93a

lzap@dev:~/images$ tools/prepare-source.sh
+ GO_VERSION=1.21.13
++ go env GOPATH
+ GO_BINARY=/home/lzap/go/bin/go1.21.13
+ go install golang.org/dl/go1.21.13@latest
+ /home/lzap/go/bin/go1.21.13 download
go1.21.13: already downloaded in /home/lzap/sdk/go1.21.13
+ /home/lzap/go/bin/go1.21.13 mod tidy
+ /home/lzap/go/bin/go1.21.13 fmt ./...
+ ./test/scripts/generate-gitlab-ci ./.gitlab-ci.yml

Copy link
Copy Markdown
Member

@thozza thozza left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@thozza thozza added this pull request to the merge queue Jan 8, 2025
Merged via the queue into osbuild:main with commit 7b2802d Jan 8, 2025
@lzap lzap deleted the gobump1 branch January 8, 2025 12:49
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants