Skip to content

Commit 1e59138

Browse files
committed
feat: update runc 1.1.12, containerd 1.6.28, Linux 6.1.74
Major updates to address CVEs. Signed-off-by: Andrey Smirnov <andrey.smirnov@siderolabs.com>
1 parent ad7361c commit 1e59138

File tree

6 files changed

+81
-83
lines changed

6 files changed

+81
-83
lines changed

Makefile

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -13,8 +13,8 @@ DOCKER_LOGIN_ENABLED ?= true
1313
NAME = Talos
1414

1515
ARTIFACTS := _out
16-
TOOLS ?= ghcr.io/siderolabs/tools:v1.5.0-3-gc95372c
17-
PKGS ?= v1.5.0-15-gab5b0e5
16+
TOOLS ?= ghcr.io/siderolabs/tools:v1.5.0-4-g02895ed
17+
PKGS ?= v1.5.0-17-ga550ab9
1818
EXTRAS ?= v1.5.0-3-gb43c4e4
1919
# renovate: datasource=github-tags depName=golang/go
2020
GO_VERSION ?= 1.20

go.mod

Lines changed: 23 additions & 22 deletions
Original file line numberDiff line numberDiff line change
@@ -33,7 +33,7 @@ require (
3333
github.com/benbjohnson/clock v1.3.5 // project archived on 2023-05-18
3434
github.com/cenkalti/backoff/v4 v4.2.1
3535
github.com/containerd/cgroups v1.1.0
36-
github.com/containerd/containerd v1.6.23
36+
github.com/containerd/containerd v1.6.28
3737
github.com/containerd/typeurl/v2 v2.1.1
3838
github.com/containernetworking/cni v1.1.2
3939
github.com/containernetworking/plugins v1.3.0
@@ -55,11 +55,11 @@ require (
5555
github.com/gizak/termui/v3 v3.1.0
5656
github.com/godbus/dbus/v5 v5.1.0
5757
github.com/golang/mock v1.6.0
58-
github.com/google/go-cmp v0.5.9
58+
github.com/google/go-cmp v0.6.0
5959
github.com/google/go-containerregistry v0.15.2
6060
github.com/google/go-tpm v0.9.0
6161
github.com/google/nftables v0.1.0
62-
github.com/google/uuid v1.3.0
62+
github.com/google/uuid v1.3.1
6363
github.com/gopacket/gopacket v1.1.1
6464
github.com/gosuri/uiprogress v0.0.1
6565
github.com/grpc-ecosystem/go-grpc-middleware v1.4.0
@@ -131,14 +131,14 @@ require (
131131
go.etcd.io/etcd/etcdutl/v3 v3.5.10
132132
go.uber.org/zap v1.25.0
133133
go4.org/netipx v0.0.0-20230728184502-ec4c8b891b28
134-
golang.org/x/net v0.17.0
134+
golang.org/x/net v0.18.0
135135
golang.org/x/sync v0.3.0
136-
golang.org/x/sys v0.13.0
137-
golang.org/x/term v0.13.0
138-
golang.org/x/text v0.13.0
136+
golang.org/x/sys v0.16.0
137+
golang.org/x/term v0.16.0
138+
golang.org/x/text v0.14.0
139139
golang.org/x/time v0.3.0
140140
golang.zx2c4.com/wireguard/wgctrl v0.0.0-20230429144221-925a1e7659e6
141-
google.golang.org/grpc v1.58.3
141+
google.golang.org/grpc v1.59.0
142142
google.golang.org/protobuf v1.31.0
143143
gopkg.in/yaml.v3 v3.0.1
144144
k8s.io/klog/v2 v2.100.1
@@ -147,7 +147,7 @@ require (
147147
)
148148

149149
require (
150-
cloud.google.com/go/compute v1.21.0 // indirect
150+
cloud.google.com/go/compute v1.23.0 // indirect
151151
github.com/0x5a17ed/itkit v0.6.0 // indirect
152152
github.com/Azure/go-ansiterm v0.0.0-20210617225240-d185dfc1b5a1 // indirect
153153
github.com/MakeNowJust/heredoc v1.0.0 // indirect
@@ -178,6 +178,7 @@ require (
178178
github.com/containerd/continuity v0.3.0 // indirect
179179
github.com/containerd/fifo v1.0.0 // indirect
180180
github.com/containerd/go-cni v1.1.9 // indirect
181+
github.com/containerd/log v0.1.0 // indirect
181182
github.com/containerd/stargz-snapshotter/estargz v0.14.3 // indirect
182183
github.com/containerd/ttrpc v1.1.2 // indirect
183184
github.com/containerd/typeurl v1.0.2 // indirect
@@ -194,7 +195,7 @@ require (
194195
github.com/gdamore/encoding v1.0.0 // indirect
195196
github.com/ghodss/yaml v1.0.0 // indirect
196197
github.com/go-errors/errors v1.4.2 // indirect
197-
github.com/go-logr/logr v1.2.4 // indirect
198+
github.com/go-logr/logr v1.3.0 // indirect
198199
github.com/go-logr/stdr v1.2.2 // indirect
199200
github.com/go-openapi/jsonpointer v0.19.6 // indirect
200201
github.com/go-openapi/jsonreference v0.20.2 // indirect
@@ -245,17 +246,18 @@ require (
245246
github.com/moby/spdystream v0.2.0 // indirect
246247
github.com/moby/sys/mountinfo v0.6.2 // indirect
247248
github.com/moby/sys/signal v0.6.0 // indirect
249+
github.com/moby/sys/user v0.1.0 // indirect
248250
github.com/moby/term v0.0.0-20221205130635-1aeaba878587 // indirect
249251
github.com/modern-go/concurrent v0.0.0-20180306012644-bacd9c7ef1dd // indirect
250252
github.com/modern-go/reflect2 v1.0.2 // indirect
251253
github.com/monochromegane/go-gitignore v0.0.0-20200626010858-205db1a8cc00 // indirect
252254
github.com/munnerz/goautoneg v0.0.0-20191010083416-a7dc8b61c822 // indirect
253255
github.com/nsf/termbox-go v0.0.0-20190121233118-02980233997d // indirect
254-
github.com/opencontainers/runc v1.1.5 // indirect
255256
github.com/opencontainers/selinux v1.11.0 // indirect
256257
github.com/pelletier/go-toml/v2 v2.0.6 // indirect
257258
github.com/peterbourgon/diskv v2.0.1+incompatible // indirect
258259
github.com/pierrec/lz4/v4 v4.1.14 // indirect
260+
github.com/pkg/browser v0.0.0-20210911075715-681adbf594b8 // indirect
259261
github.com/pkg/errors v0.9.1 // indirect
260262
github.com/pmezard/go-difflib v1.0.0 // indirect
261263
github.com/prometheus/client_golang v1.16.0 // indirect
@@ -269,7 +271,7 @@ require (
269271
github.com/siderolabs/go-api-signature v0.3.1 // indirect
270272
github.com/siderolabs/protoenc v0.2.0 // indirect
271273
github.com/siderolabs/tcpproxy v0.1.0 // indirect
272-
github.com/sirupsen/logrus v1.9.0 // indirect
274+
github.com/sirupsen/logrus v1.9.3 // indirect
273275
github.com/spf13/afero v1.9.3 // indirect
274276
github.com/spf13/cast v1.5.0 // indirect
275277
github.com/spf13/jwalterweatherman v1.1.0 // indirect
@@ -286,21 +288,22 @@ require (
286288
go.etcd.io/etcd/raft/v3 v3.5.10 // indirect
287289
go.etcd.io/etcd/server/v3 v3.5.10 // indirect
288290
go.opencensus.io v0.24.0 // indirect
289-
go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc v0.35.0 // indirect
290-
go.opentelemetry.io/otel v1.10.0 // indirect
291-
go.opentelemetry.io/otel/trace v1.10.0 // indirect
291+
go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc v0.46.0 // indirect
292+
go.opentelemetry.io/otel v1.21.0 // indirect
293+
go.opentelemetry.io/otel/metric v1.21.0 // indirect
294+
go.opentelemetry.io/otel/trace v1.21.0 // indirect
292295
go.starlark.net v0.0.0-20230525235612-a134d8f9ddca // indirect
293296
go.uber.org/multierr v1.11.0 // indirect
294-
golang.org/x/crypto v0.14.0 // indirect
297+
golang.org/x/crypto v0.18.0 // indirect
295298
golang.org/x/mod v0.12.0 // indirect
296-
golang.org/x/oauth2 v0.10.0 // indirect
299+
golang.org/x/oauth2 v0.11.0 // indirect
297300
golang.org/x/tools v0.11.0 // indirect
298301
golang.zx2c4.com/wintun v0.0.0-20230126152724-0fa3db229ce2 // indirect
299302
golang.zx2c4.com/wireguard v0.0.0-20230325221338-052af4a8072b // indirect
300303
google.golang.org/appengine v1.6.7 // indirect
301-
google.golang.org/genproto v0.0.0-20230711160842-782d3b101e98 // indirect
302-
google.golang.org/genproto/googleapis/api v0.0.0-20230726155614-23370e0ffb3e // indirect
303-
google.golang.org/genproto/googleapis/rpc v0.0.0-20230726155614-23370e0ffb3e // indirect
304+
google.golang.org/genproto v0.0.0-20230822172742-b8732ec3820d // indirect
305+
google.golang.org/genproto/googleapis/api v0.0.0-20230822172742-b8732ec3820d // indirect
306+
google.golang.org/genproto/googleapis/rpc v0.0.0-20230822172742-b8732ec3820d // indirect
304307
gopkg.in/inf.v0 v0.9.1 // indirect
305308
gopkg.in/ini.v1 v1.67.0 // indirect
306309
gopkg.in/yaml.v2 v2.4.0 // indirect
@@ -314,5 +317,3 @@ require (
314317
sigs.k8s.io/kustomize/kyaml v0.14.3-0.20230601165947-6ce0bf390ce3 // indirect
315318
sigs.k8s.io/structured-merge-diff/v4 v4.2.3 // indirect
316319
)
317-
318-
require github.com/pkg/browser v0.0.0-20210911075715-681adbf594b8 // indirect

0 commit comments

Comments
 (0)