Commit 8860fed
authored
fix(deps): vulnerability fix in connect-rpc validate and ristretto (#3065)
This pull request primarily updates several dependencies in the
`service/go.mod` file, especially for validation and caching libraries,
and makes the necessary code adjustments to support these upgrades. The
most significant changes are grouped below:
**Dependency Upgrades:**
* Upgraded `buf.build/go/protovalidate` from `v0.13.1` to `v1.0.0`, and
`connectrpc.com/validate` from `v0.3.0` to `v0.6.0`, reflecting major
version changes for validation libraries.
* Updated `github.com/dgraph-io/ristretto` to `v2.4.0` (from v0.2.0) and
adjusted all related imports and usages to the new version, which now
uses generics.
[[1]](diffhunk://#diff-d833fd9c30ece95b8f948d87d2a53aa43ac2a725b869fad2e2a9fe8a71924700L8-R22)
[[2]](diffhunk://#diff-86ab8e12a253df7a30da365d95afa01e8149f3ff13ab5727a12c709db8aadec6L9-R9)
[[3]](diffhunk://#diff-86ab8e12a253df7a30da365d95afa01e8149f3ff13ab5727a12c709db8aadec6L25-R25)
[[4]](diffhunk://#diff-86ab8e12a253df7a30da365d95afa01e8149f3ff13ab5727a12c709db8aadec6L47-R47)
[[5]](diffhunk://#diff-86ab8e12a253df7a30da365d95afa01e8149f3ff13ab5727a12c709db8aadec6L155-R155)
* Bumped several other dependencies to newer versions, including
`github.com/google/cel-go`, `github.com/stoewer/go-strcase`,
`go.uber.org/mock`, and `golang.org/x/exp`.
[[1]](diffhunk://#diff-d833fd9c30ece95b8f948d87d2a53aa43ac2a725b869fad2e2a9fe8a71924700L108-R107)
[[2]](diffhunk://#diff-d833fd9c30ece95b8f948d87d2a53aa43ac2a725b869fad2e2a9fe8a71924700L157-R156)
[[3]](diffhunk://#diff-d833fd9c30ece95b8f948d87d2a53aa43ac2a725b869fad2e2a9fe8a71924700L171-R173)
**Code Adjustments for Library Upgrades:**
* Refactored the creation of the validation interceptor
(`validate.NewInterceptor`) to match the updated API, which no longer
returns an error.
[[1]](diffhunk://#diff-afba8000c9b4da491e00de2d21351395f1a4eb444fdb187f8b6ba3040d01441eL522-R522)
[[2]](diffhunk://#diff-afba8000c9b4da491e00de2d21351395f1a4eb444fdb187f8b6ba3040d01441eL545-R542)
* Updated the cache manager implementation to use the new generic types
required by `ristretto/v2`, including changes to the struct field types
and configuration instantiation.
[[1]](diffhunk://#diff-86ab8e12a253df7a30da365d95afa01e8149f3ff13ab5727a12c709db8aadec6L25-R25)
[[2]](diffhunk://#diff-86ab8e12a253df7a30da365d95afa01e8149f3ff13ab5727a12c709db8aadec6L47-R47)
[[3]](diffhunk://#diff-86ab8e12a253df7a30da365d95afa01e8149f3ff13ab5727a12c709db8aadec6L155-R155)
**Indirect Dependency Updates:**
* Updated indirect dependencies such as
`buf.build/gen/go/bufbuild/protovalidate/protocolbuffers/go` and removed
an unused indirect dependency (`github.com/dgryski/go-farm`).
These changes ensure compatibility with the latest versions of the
libraries and take advantage of improvements such as generics support
and simplified APIs.1 parent 65eb7c3 commit 8860fed
4 files changed
+35
-44
lines changed| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
5 | 5 | | |
6 | 6 | | |
7 | 7 | | |
8 | | - | |
| 8 | + | |
9 | 9 | | |
10 | 10 | | |
11 | 11 | | |
12 | | - | |
| 12 | + | |
13 | 13 | | |
14 | 14 | | |
15 | 15 | | |
16 | 16 | | |
17 | 17 | | |
18 | | - | |
| 18 | + | |
19 | 19 | | |
20 | 20 | | |
21 | 21 | | |
22 | | - | |
| 22 | + | |
23 | 23 | | |
24 | 24 | | |
25 | 25 | | |
| |||
59 | 59 | | |
60 | 60 | | |
61 | 61 | | |
62 | | - | |
| 62 | + | |
63 | 63 | | |
64 | 64 | | |
65 | 65 | | |
66 | 66 | | |
67 | 67 | | |
68 | | - | |
69 | 68 | | |
70 | 69 | | |
71 | 70 | | |
| |||
105 | 104 | | |
106 | 105 | | |
107 | 106 | | |
108 | | - | |
| 107 | + | |
109 | 108 | | |
110 | 109 | | |
111 | 110 | | |
| |||
154 | 153 | | |
155 | 154 | | |
156 | 155 | | |
157 | | - | |
| 156 | + | |
158 | 157 | | |
159 | 158 | | |
160 | 159 | | |
| |||
168 | 167 | | |
169 | 168 | | |
170 | 169 | | |
171 | | - | |
| 170 | + | |
172 | 171 | | |
173 | 172 | | |
174 | | - | |
| 173 | + | |
175 | 174 | | |
176 | 175 | | |
177 | 176 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
1 | | - | |
2 | | - | |
3 | | - | |
4 | | - | |
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
5 | 5 | | |
6 | 6 | | |
7 | 7 | | |
| |||
10 | 10 | | |
11 | 11 | | |
12 | 12 | | |
13 | | - | |
14 | | - | |
| 13 | + | |
| 14 | + | |
15 | 15 | | |
16 | 16 | | |
17 | 17 | | |
| |||
75 | 75 | | |
76 | 76 | | |
77 | 77 | | |
78 | | - | |
79 | | - | |
80 | | - | |
81 | | - | |
| 78 | + | |
| 79 | + | |
82 | 80 | | |
83 | 81 | | |
84 | 82 | | |
| |||
97 | 95 | | |
98 | 96 | | |
99 | 97 | | |
100 | | - | |
101 | | - | |
| 98 | + | |
| 99 | + | |
102 | 100 | | |
103 | 101 | | |
104 | 102 | | |
| |||
146 | 144 | | |
147 | 145 | | |
148 | 146 | | |
149 | | - | |
150 | | - | |
| 147 | + | |
| 148 | + | |
151 | 149 | | |
152 | 150 | | |
153 | 151 | | |
| |||
309 | 307 | | |
310 | 308 | | |
311 | 309 | | |
312 | | - | |
313 | | - | |
| 310 | + | |
| 311 | + | |
314 | 312 | | |
315 | 313 | | |
316 | 314 | | |
| |||
375 | 373 | | |
376 | 374 | | |
377 | 375 | | |
378 | | - | |
379 | | - | |
| 376 | + | |
| 377 | + | |
380 | 378 | | |
381 | 379 | | |
382 | 380 | | |
383 | 381 | | |
384 | 382 | | |
385 | 383 | | |
386 | | - | |
387 | | - | |
| 384 | + | |
| 385 | + | |
388 | 386 | | |
389 | 387 | | |
390 | 388 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
519 | 519 | | |
520 | 520 | | |
521 | 521 | | |
522 | | - | |
523 | | - | |
524 | | - | |
525 | | - | |
| 522 | + | |
526 | 523 | | |
527 | | - | |
| 524 | + | |
528 | 525 | | |
529 | 526 | | |
530 | 527 | | |
| |||
542 | 539 | | |
543 | 540 | | |
544 | 541 | | |
545 | | - | |
546 | | - | |
547 | | - | |
548 | | - | |
| 542 | + | |
549 | 543 | | |
550 | | - | |
| 544 | + | |
551 | 545 | | |
552 | 546 | | |
553 | 547 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
6 | 6 | | |
7 | 7 | | |
8 | 8 | | |
9 | | - | |
| 9 | + | |
10 | 10 | | |
11 | 11 | | |
12 | 12 | | |
| |||
22 | 22 | | |
23 | 23 | | |
24 | 24 | | |
25 | | - | |
| 25 | + | |
26 | 26 | | |
27 | 27 | | |
28 | 28 | | |
| |||
44 | 44 | | |
45 | 45 | | |
46 | 46 | | |
47 | | - | |
| 47 | + | |
48 | 48 | | |
49 | 49 | | |
50 | 50 | | |
| |||
152 | 152 | | |
153 | 153 | | |
154 | 154 | | |
155 | | - | |
| 155 | + | |
156 | 156 | | |
157 | 157 | | |
158 | 158 | | |
| |||
0 commit comments