@@ -5,54 +5,37 @@ go 1.16
5
5
replace github.com/fluxcd/helm-controller/api => ./api
6
6
7
7
require (
8
- github.com/bshuster-repo/logrus-logstash-hook v1.0.2 // indirect
9
- github.com/bugsnag/bugsnag-go v2.1.2+incompatible // indirect
10
- github.com/bugsnag/panicwrap v1.3.4 // indirect
11
- github.com/docker/go-metrics v0.0.1 // indirect
12
- github.com/docker/libtrust v0.0.0-20160708172513-aabc10ec26b7 // indirect
13
8
github.com/fluxcd/helm-controller/api v0.14.1
14
9
github.com/fluxcd/pkg/apis/kustomize v0.3.0
15
10
github.com/fluxcd/pkg/apis/meta v0.10.1
16
11
github.com/fluxcd/pkg/runtime v0.12.2
17
12
github.com/fluxcd/source-controller/api v0.19.2
18
13
github.com/garyburd/redigo v1.6.3 // indirect
19
14
github.com/go-logr/logr v0.4.0
20
- github.com/gofrs/uuid v4.1.0+incompatible // indirect
21
- github.com/gorilla/handlers v1.5.1 // indirect
22
15
github.com/hashicorp/go-retryablehttp v0.6.8
23
- github.com/kardianos/osext v0.0.0-20190222173326-2bc1f35cddc0 // indirect
24
16
github.com/onsi/ginkgo v1.16.4
25
17
github.com/onsi/gomega v1.15.0
26
18
github.com/spf13/pflag v1.0.5
27
- github.com/yvasiyarov/go-metrics v0.0.0-20150112132944-c25f46c4b940 // indirect
28
- github.com/yvasiyarov/gorelic v0.0.7 // indirect
29
- github.com/yvasiyarov/newrelic_platform_go v0.0.0-20160601141957-9c099fbc30e9 // indirect
30
- helm.sh/helm/v3 v3.7.1
31
- k8s.io/api v0.22.2
32
- k8s.io/apiextensions-apiserver v0.22.2
33
- k8s.io/apimachinery v0.22.2
34
- k8s.io/cli-runtime v0.22.2
35
- k8s.io/client-go v0.22.2
36
- rsc.io/letsencrypt v0.0.3 // indirect
19
+ helm.sh/helm/v3 v3.7.2
20
+ k8s.io/api v0.22.4
21
+ k8s.io/apiextensions-apiserver v0.22.4
22
+ k8s.io/apimachinery v0.22.4
23
+ k8s.io/cli-runtime v0.22.4
24
+ k8s.io/client-go v0.22.4
37
25
sigs.k8s.io/controller-runtime v0.10.2
38
26
sigs.k8s.io/kustomize/api v0.10.1
39
27
sigs.k8s.io/yaml v1.2.0
40
28
)
41
29
42
- // pin kustomize to v4.4.1
30
+ // Pin kustomize to v4.4.1
43
31
replace (
44
32
sigs.k8s.io/kustomize/api => sigs.k8s.io/kustomize/api v0.10.1
45
33
sigs.k8s.io/kustomize/kyaml => sigs.k8s.io/kustomize/kyaml v0.13.0
46
34
)
47
35
48
- // Freeze Helm due to OOM issues https://github.com/fluxcd/helm-controller/issues/345
49
- replace helm.sh/helm/v3 => helm.sh/helm/v3 v3.6.3
50
-
51
- // Required by https://github.com/helm/helm/blob/v3.6.3/go.mod,
52
- // but overwritten with a newer version due to CVE-2017-11468.
53
- replace github.com/docker/distribution => github.com/docker/distribution v2.7.0-rc.0+incompatible
54
-
55
36
// Fix CVE-2021-41092
37
+ // Due to https://github.com/oras-project/oras-go/blob/v0.4.0/go.mod#L14
38
+ // pulled in by Helm.
56
39
replace github.com/docker/cli => github.com/docker/cli v20.10.9+incompatible
57
40
58
41
// Fix CVE-2021-30465
@@ -64,7 +47,11 @@ replace github.com/opencontainers/runc => github.com/opencontainers/runc v1.0.3
64
47
// Fix CVE-2021-32760
65
48
// Fix CVE-2021-41103
66
49
// Fix CVE-2021-41190
67
- replace github.com/containerd/containerd => github.com/containerd/containerd v1.4.12
50
+ // Due to https://github.com/oras-project/oras-go/blob/v0.4.0/go.mod#L13,
51
+ // pulled in by Helm.
52
+ replace github.com/containerd/containerd => github.com/containerd/containerd v1.5.8
68
53
69
54
// Fix CVE-2021-41190
55
+ // Due to https://github.com/oras-project/oras-go/blob/v0.4.0/go.mod#L21,
56
+ // pulled in by Helm.
70
57
replace github.com/opencontainers/image-spec => github.com/opencontainers/image-spec v1.0.2
0 commit comments