chore(deps): update module gopkg.in/go-jose/go-jose.v2 to v4 - #499
Conversation
4b9315c to
498b09d
Compare
|
313ce29 to
fced98d
Compare
Automated review summaryPR type: Go dependency major version bump ( Checklist
Root cause of CI failureThe PR only modified Additional problem: v2 is still a required transitive dependencyEven if the vendor directory were updated, this upgrade cannot simply replace v2 with v4. The
These packages use different import paths ( Note: the repository already vendors RecommendationThis PR cannot be merged as-is and should be closed. To properly address this:
|
721d700 to
2a585b8
Compare
2259fbe to
85a0807
Compare
a882303 to
11c8852
Compare
Signed-off-by: red-hat-konflux-kflux-prd-rh02 <190377777+red-hat-konflux-kflux-prd-rh02[bot]@users.noreply.github.com>
11c8852 to
c999908
Compare
This PR contains the following updates:
v2.6.3→v4.1.4Warning
Some dependencies could not be looked up. Check the warning logs for more information.
Release Notes
go-jose/go-jose (gopkg.in/go-jose/go-jose.v2)
v4.1.4Compare Source
What's Changed
Fixes Panic in JWE decryption. See GHSA-78h2-9frx-2jm8
Full Changelog: go-jose/go-jose@v4.1.3...v4.1.4
v4.1.3Compare Source
This release drops Go 1.23 support as that Go release is no longer supported. With that, we can drop
x/cryptoand no longer have any external dependencies in go-jose outside of the standard library!This release fixes a bug where a critical b64 header was ignored if in an unprotected header. It is now rejected instead of ignored.
What's Changed
Full Changelog: go-jose/go-jose@v4.1.2...v4.1.3
v4.1.2Compare Source
What's Changed
go-jose v4.1.2 improves some documentation, errors, and removes the only 3rd-party dependency.
New Contributors
Full Changelog: go-jose/go-jose@v4.1.1...v4.1.2
v4.1.1Compare Source
What's Changed
New Contributors
Full Changelog: go-jose/go-jose@v4.1.0...v4.1.1
v4.1.0Compare Source
What's Changed
signatureAlgorithmsargument by @tgeoghegan in #163New Contributors
Full Changelog: go-jose/go-jose@v4.0.5...v4.1.0
v4.0.5Compare Source
What's Changed
Fixes GHSA-c6gw-w398-hv78
Various other dependency updates, small fixes, and documentation updates in the full changelog
New Contributors
Full Changelog: go-jose/go-jose@v4.0.4...v4.0.5
v4.0.4: Version 4.0.4Compare Source
Fixed
v4.0.3: Version 4.0.3Compare Source
Changed
v4.0.2: Version 4.0.2Compare Source
What's Changed
New Contributors
Full Changelog: go-jose/go-jose@v4.0.1...v4.0.2
v4.0.1: Version 4.0.1Compare Source
Fixed
amounts of memory and CPU when decompressed by
DecryptorDecryptMulti.Those functions now return an error if the decompressed data would exceed
250kB or 10x the compressed size (whichever is larger). Thanks to
Enze Wang@Alioth and Jianjun Chen@Zhongguancun Lab (@zer0yu and @chenjj)
for reporting.
v4.0.0: Version 4.0.0Compare Source
This release makes some breaking changes in order to more thoroughly address the vulnerabilities discussed in Three New Attacks Against JSON Web Tokens, "Sign/encrypt confusion", "Billion hash attack", and "Polyglot token".
Changed
ParseSigned, ParseDetached, jwt.ParseEncrypted, jwt.ParseSigned,
jwt.ParseSignedAndEncrypted (#69, #74)
Added
v3.0.5Compare Source
What's Changed
Fixes GHSA-78h2-9frx-2jm8
We recommend migrating from v3 to v4, and we will stop support v3 in the near future.
Full Changelog: go-jose/go-jose@v3.0.4...v3.0.5
v3.0.4Compare Source
What's Changed
Backport fix for GHSA-c6gw-w398-hv78 CVE-2025-27144
#174
Full Changelog: go-jose/go-jose@v3.0.3...v3.0.4
v3.0.3: Version 3.0.3Compare Source
Fixed
v3.0.2: Version 3.0.2Compare Source
Fixed
Changed
Added
v3.0.1: Version 3.0.1Compare Source
Fixed
Security issue: an attacker specifying a large "p2c" value can cause JSONWebEncryption.Decrypt and JSONWebEncryption.DecryptMulti to consume large amounts of CPU, causing a DoS. Thanks to Matt Schwager (@mschwager) for the disclosure and to Tom Tervoort for originally publishing the category of attack. https://i.blackhat.com/BH-US-23/Presentations/US-23-Tervoort-Three-New-Attacks-Against-JSON-Web-Tokens.pdf
The release is tagged off the release-v3.0.1 branch to avoid mixing in some as-yet unreleased changes on the v3 branch.
v3.0.0: Version 3.0.0Compare Source
First release after moving from square/go-jose to the new go-jose/go-jose repository.
Fixes & Improvements
a10ff54- Fix for EC thumbprint template so we compute EC thumbprints correctly30f4a6a- Treat zero Expected.Time as now in Claims.Validate when verifying JWTs4ac8eda- Fix handling of the x5u header (X.509 certificate URL) in JWKsd7b900b- Strip padding off base64 strings, to match spec per RFC7515 Appendix C7f81482- Extract key from JWKs to ensure you can use it when verifying a detached signaturee225b2d- Support non-pointer JWKs to match behavior for other key types94cbec2- Useed25519from the stdlib instead of the golang.org/x/crypto versioneae0da4- Export jose-util helpers as they might be useful for others4bac79d- Fix issue square#182 that caused panic on claims with invalid JWT payload60a6e9d- Use string.Builder to remove whitespace, instead of a regexp to improve performance2009556- Better error handling to avoid panic that can be caused by invalid headersThis release also cleans up a number of module references for the new repo migration, fixed some typos in comments, and more.
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
To execute skipped test pipelines write comment
/ok-to-test.Documentation
Find out how to configure dependency updates in MintMaker documentation or see all available configuration options in Renovate documentation.