mirror of
https://github.com/distribution/distribution
synced 2024-11-12 05:45:51 +01:00
345be95498
golang.org/x/net contains a fix for CVE-2022-41717, which was addressed in stdlib in go1.19.4 and go1.18.9; > net/http: limit canonical header cache by bytes, not entries > > An attacker can cause excessive memory growth in a Go server accepting > HTTP/2 requests. > > HTTP/2 server connections contain a cache of HTTP header keys sent by > the client. While the total number of entries in this cache is capped, > an attacker sending very large keys can cause the server to allocate > approximately 64 MiB per open connection. > > This issue is also fixed in golang.org/x/net/http2 v0.4.0, > for users manually configuring HTTP/2. full diff: https://github.com/golang/net/compare/v0.2.0...v0.4.0 other dependency updates (due to (circular) dependencies): - golang.org/x/sys v0.3.0: https://github.com/golang/sys/compare/3c1f35247d10...v0.3.0 - golang.org/x/text v0.5.0: https://github.com/golang/text/compare/v0.3.7...v0.5.0 Signed-off-by: Sebastiaan van Stijn <github@gone.nl>
396 lines
14 KiB
Plaintext
396 lines
14 KiB
Plaintext
# cloud.google.com/go v0.65.0
|
|
## explicit; go 1.11
|
|
cloud.google.com/go/compute/metadata
|
|
# github.com/Azure/azure-sdk-for-go v56.3.0+incompatible
|
|
## explicit
|
|
github.com/Azure/azure-sdk-for-go/storage
|
|
github.com/Azure/azure-sdk-for-go/version
|
|
# github.com/Azure/go-autorest v14.2.0+incompatible
|
|
## explicit
|
|
github.com/Azure/go-autorest
|
|
# github.com/Azure/go-autorest/autorest v0.11.24
|
|
## explicit; go 1.15
|
|
github.com/Azure/go-autorest/autorest
|
|
github.com/Azure/go-autorest/autorest/azure
|
|
# github.com/Azure/go-autorest/autorest/adal v0.9.18
|
|
## explicit; go 1.15
|
|
github.com/Azure/go-autorest/autorest/adal
|
|
# github.com/Azure/go-autorest/autorest/date v0.3.0
|
|
## explicit; go 1.12
|
|
github.com/Azure/go-autorest/autorest/date
|
|
# github.com/Azure/go-autorest/autorest/to v0.4.0
|
|
## explicit; go 1.12
|
|
# github.com/Azure/go-autorest/logger v0.2.1
|
|
## explicit; go 1.12
|
|
github.com/Azure/go-autorest/logger
|
|
# github.com/Azure/go-autorest/tracing v0.6.0
|
|
## explicit; go 1.12
|
|
github.com/Azure/go-autorest/tracing
|
|
# github.com/Shopify/logrus-bugsnag v0.0.0-20171204204709-577dee27f20d
|
|
## explicit
|
|
github.com/Shopify/logrus-bugsnag
|
|
# github.com/aws/aws-sdk-go v1.43.16
|
|
## explicit; go 1.11
|
|
github.com/aws/aws-sdk-go/aws
|
|
github.com/aws/aws-sdk-go/aws/arn
|
|
github.com/aws/aws-sdk-go/aws/awserr
|
|
github.com/aws/aws-sdk-go/aws/awsutil
|
|
github.com/aws/aws-sdk-go/aws/client
|
|
github.com/aws/aws-sdk-go/aws/client/metadata
|
|
github.com/aws/aws-sdk-go/aws/corehandlers
|
|
github.com/aws/aws-sdk-go/aws/credentials
|
|
github.com/aws/aws-sdk-go/aws/credentials/ec2rolecreds
|
|
github.com/aws/aws-sdk-go/aws/credentials/endpointcreds
|
|
github.com/aws/aws-sdk-go/aws/credentials/processcreds
|
|
github.com/aws/aws-sdk-go/aws/credentials/ssocreds
|
|
github.com/aws/aws-sdk-go/aws/credentials/stscreds
|
|
github.com/aws/aws-sdk-go/aws/csm
|
|
github.com/aws/aws-sdk-go/aws/defaults
|
|
github.com/aws/aws-sdk-go/aws/ec2metadata
|
|
github.com/aws/aws-sdk-go/aws/endpoints
|
|
github.com/aws/aws-sdk-go/aws/request
|
|
github.com/aws/aws-sdk-go/aws/session
|
|
github.com/aws/aws-sdk-go/aws/signer/v4
|
|
github.com/aws/aws-sdk-go/internal/context
|
|
github.com/aws/aws-sdk-go/internal/ini
|
|
github.com/aws/aws-sdk-go/internal/s3shared
|
|
github.com/aws/aws-sdk-go/internal/s3shared/arn
|
|
github.com/aws/aws-sdk-go/internal/s3shared/s3err
|
|
github.com/aws/aws-sdk-go/internal/sdkio
|
|
github.com/aws/aws-sdk-go/internal/sdkmath
|
|
github.com/aws/aws-sdk-go/internal/sdkrand
|
|
github.com/aws/aws-sdk-go/internal/sdkuri
|
|
github.com/aws/aws-sdk-go/internal/shareddefaults
|
|
github.com/aws/aws-sdk-go/internal/strings
|
|
github.com/aws/aws-sdk-go/internal/sync/singleflight
|
|
github.com/aws/aws-sdk-go/private/checksum
|
|
github.com/aws/aws-sdk-go/private/protocol
|
|
github.com/aws/aws-sdk-go/private/protocol/eventstream
|
|
github.com/aws/aws-sdk-go/private/protocol/eventstream/eventstreamapi
|
|
github.com/aws/aws-sdk-go/private/protocol/json/jsonutil
|
|
github.com/aws/aws-sdk-go/private/protocol/jsonrpc
|
|
github.com/aws/aws-sdk-go/private/protocol/query
|
|
github.com/aws/aws-sdk-go/private/protocol/query/queryutil
|
|
github.com/aws/aws-sdk-go/private/protocol/rest
|
|
github.com/aws/aws-sdk-go/private/protocol/restjson
|
|
github.com/aws/aws-sdk-go/private/protocol/restxml
|
|
github.com/aws/aws-sdk-go/private/protocol/xml/xmlutil
|
|
github.com/aws/aws-sdk-go/service/cloudfront/sign
|
|
github.com/aws/aws-sdk-go/service/s3
|
|
github.com/aws/aws-sdk-go/service/sso
|
|
github.com/aws/aws-sdk-go/service/sso/ssoiface
|
|
github.com/aws/aws-sdk-go/service/sts
|
|
github.com/aws/aws-sdk-go/service/sts/stsiface
|
|
# github.com/beorn7/perks v1.0.1
|
|
## explicit; go 1.11
|
|
github.com/beorn7/perks/quantile
|
|
# github.com/bitly/go-simplejson v0.5.0
|
|
## explicit
|
|
# github.com/bshuster-repo/logrus-logstash-hook v1.0.0
|
|
## explicit
|
|
github.com/bshuster-repo/logrus-logstash-hook
|
|
# github.com/bugsnag/bugsnag-go v0.0.0-20141110184014-b1d153021fcd
|
|
## explicit
|
|
github.com/bugsnag/bugsnag-go
|
|
github.com/bugsnag/bugsnag-go/errors
|
|
# github.com/bugsnag/osext v0.0.0-20130617224835-0dd3f918b21b
|
|
## explicit
|
|
github.com/bugsnag/osext
|
|
# github.com/bugsnag/panicwrap v0.0.0-20151223152923-e2c28503fcd0
|
|
## explicit
|
|
github.com/bugsnag/panicwrap
|
|
# github.com/cespare/xxhash/v2 v2.1.2
|
|
## explicit; go 1.11
|
|
github.com/cespare/xxhash/v2
|
|
# github.com/denverdino/aliyungo v0.0.0-20190125010748-a747050bb1ba
|
|
## explicit
|
|
github.com/denverdino/aliyungo/cdn/auth
|
|
github.com/denverdino/aliyungo/common
|
|
github.com/denverdino/aliyungo/oss
|
|
github.com/denverdino/aliyungo/util
|
|
# github.com/dnaeon/go-vcr v1.0.1
|
|
## explicit
|
|
# github.com/docker/go-events v0.0.0-20190806004212-e31b211e4f1c
|
|
## explicit
|
|
github.com/docker/go-events
|
|
# github.com/docker/go-metrics v0.0.1
|
|
## explicit; go 1.11
|
|
github.com/docker/go-metrics
|
|
# github.com/docker/libtrust v0.0.0-20150114040149-fa567046d9b1
|
|
## explicit
|
|
github.com/docker/libtrust
|
|
# github.com/felixge/httpsnoop v1.0.1
|
|
## explicit; go 1.13
|
|
github.com/felixge/httpsnoop
|
|
# github.com/gofrs/uuid v4.0.0+incompatible
|
|
## explicit
|
|
github.com/gofrs/uuid
|
|
# github.com/golang-jwt/jwt/v4 v4.2.0
|
|
## explicit; go 1.15
|
|
github.com/golang-jwt/jwt/v4
|
|
# github.com/golang/groupcache v0.0.0-20200121045136-8c9f03a8e57e
|
|
## explicit
|
|
github.com/golang/groupcache/lru
|
|
# github.com/golang/protobuf v1.5.2
|
|
## explicit; go 1.9
|
|
github.com/golang/protobuf/proto
|
|
github.com/golang/protobuf/ptypes
|
|
github.com/golang/protobuf/ptypes/any
|
|
github.com/golang/protobuf/ptypes/duration
|
|
github.com/golang/protobuf/ptypes/timestamp
|
|
# github.com/gomodule/redigo v1.8.2
|
|
## explicit; go 1.14
|
|
github.com/gomodule/redigo/redis
|
|
# github.com/googleapis/gax-go/v2 v2.0.5
|
|
## explicit
|
|
github.com/googleapis/gax-go/v2
|
|
# github.com/gorilla/handlers v1.5.1
|
|
## explicit; go 1.14
|
|
github.com/gorilla/handlers
|
|
# github.com/gorilla/mux v1.8.0
|
|
## explicit; go 1.12
|
|
github.com/gorilla/mux
|
|
# github.com/hashicorp/golang-lru v0.5.4
|
|
## explicit; go 1.12
|
|
github.com/hashicorp/golang-lru
|
|
github.com/hashicorp/golang-lru/simplelru
|
|
# github.com/inconshreveable/mousetrap v1.0.1
|
|
## explicit; go 1.18
|
|
github.com/inconshreveable/mousetrap
|
|
# github.com/jmespath/go-jmespath v0.4.0
|
|
## explicit; go 1.14
|
|
github.com/jmespath/go-jmespath
|
|
# github.com/kr/pretty v0.1.0
|
|
## explicit
|
|
github.com/kr/pretty
|
|
# github.com/kr/text v0.1.0
|
|
## explicit
|
|
github.com/kr/text
|
|
# github.com/matttproud/golang_protobuf_extensions v1.0.1
|
|
## explicit
|
|
github.com/matttproud/golang_protobuf_extensions/pbutil
|
|
# github.com/mitchellh/mapstructure v1.1.2
|
|
## explicit
|
|
github.com/mitchellh/mapstructure
|
|
# github.com/mitchellh/osext v0.0.0-20151018003038-5e2d6d41470f
|
|
## explicit
|
|
# github.com/ncw/swift v1.0.47
|
|
## explicit
|
|
github.com/ncw/swift
|
|
github.com/ncw/swift/swifttest
|
|
# github.com/opencontainers/go-digest v1.0.0
|
|
## explicit; go 1.13
|
|
github.com/opencontainers/go-digest
|
|
github.com/opencontainers/go-digest/digestset
|
|
# github.com/opencontainers/image-spec v1.0.2
|
|
## explicit
|
|
github.com/opencontainers/image-spec/specs-go
|
|
github.com/opencontainers/image-spec/specs-go/v1
|
|
# github.com/prometheus/client_golang v1.12.1
|
|
## explicit; go 1.13
|
|
github.com/prometheus/client_golang/prometheus
|
|
github.com/prometheus/client_golang/prometheus/internal
|
|
github.com/prometheus/client_golang/prometheus/promhttp
|
|
# github.com/prometheus/client_model v0.2.0
|
|
## explicit; go 1.9
|
|
github.com/prometheus/client_model/go
|
|
# github.com/prometheus/common v0.32.1
|
|
## explicit; go 1.13
|
|
github.com/prometheus/common/expfmt
|
|
github.com/prometheus/common/internal/bitbucket.org/ww/goautoneg
|
|
github.com/prometheus/common/model
|
|
# github.com/prometheus/procfs v0.7.3
|
|
## explicit; go 1.13
|
|
github.com/prometheus/procfs
|
|
github.com/prometheus/procfs/internal/fs
|
|
github.com/prometheus/procfs/internal/util
|
|
# github.com/sirupsen/logrus v1.8.1
|
|
## explicit; go 1.13
|
|
github.com/sirupsen/logrus
|
|
# github.com/spf13/cobra v1.6.1
|
|
## explicit; go 1.15
|
|
github.com/spf13/cobra
|
|
# github.com/spf13/pflag v1.0.5
|
|
## explicit; go 1.12
|
|
github.com/spf13/pflag
|
|
# github.com/yvasiyarov/go-metrics v0.0.0-20140926110328-57bccd1ccd43
|
|
## explicit
|
|
github.com/yvasiyarov/go-metrics
|
|
# github.com/yvasiyarov/gorelic v0.0.0-20141212073537-a9bba5b9ab50
|
|
## explicit
|
|
github.com/yvasiyarov/gorelic
|
|
# github.com/yvasiyarov/newrelic_platform_go v0.0.0-20140908184405-b21fdbd4370f
|
|
## explicit
|
|
github.com/yvasiyarov/newrelic_platform_go
|
|
# go.opencensus.io v0.22.4
|
|
## explicit; go 1.13
|
|
go.opencensus.io
|
|
go.opencensus.io/internal
|
|
go.opencensus.io/internal/tagencoding
|
|
go.opencensus.io/metric/metricdata
|
|
go.opencensus.io/metric/metricproducer
|
|
go.opencensus.io/plugin/ochttp
|
|
go.opencensus.io/plugin/ochttp/propagation/b3
|
|
go.opencensus.io/resource
|
|
go.opencensus.io/stats
|
|
go.opencensus.io/stats/internal
|
|
go.opencensus.io/stats/view
|
|
go.opencensus.io/tag
|
|
go.opencensus.io/trace
|
|
go.opencensus.io/trace/internal
|
|
go.opencensus.io/trace/propagation
|
|
go.opencensus.io/trace/tracestate
|
|
# golang.org/x/crypto v0.0.0-20211215153901-e495a2d5b3d3
|
|
## explicit; go 1.17
|
|
golang.org/x/crypto/acme
|
|
golang.org/x/crypto/acme/autocert
|
|
golang.org/x/crypto/bcrypt
|
|
golang.org/x/crypto/blowfish
|
|
golang.org/x/crypto/pkcs12
|
|
golang.org/x/crypto/pkcs12/internal/rc2
|
|
# golang.org/x/net v0.4.0
|
|
## explicit; go 1.17
|
|
golang.org/x/net/context
|
|
golang.org/x/net/context/ctxhttp
|
|
golang.org/x/net/http/httpguts
|
|
golang.org/x/net/http2
|
|
golang.org/x/net/http2/hpack
|
|
golang.org/x/net/idna
|
|
golang.org/x/net/internal/timeseries
|
|
golang.org/x/net/trace
|
|
# golang.org/x/oauth2 v0.0.0-20210514164344-f6687ab2804c
|
|
## explicit; go 1.11
|
|
golang.org/x/oauth2
|
|
golang.org/x/oauth2/authhandler
|
|
golang.org/x/oauth2/google
|
|
golang.org/x/oauth2/google/internal/externalaccount
|
|
golang.org/x/oauth2/internal
|
|
golang.org/x/oauth2/jws
|
|
golang.org/x/oauth2/jwt
|
|
# golang.org/x/sys v0.3.0
|
|
## explicit; go 1.17
|
|
golang.org/x/sys/internal/unsafeheader
|
|
golang.org/x/sys/unix
|
|
golang.org/x/sys/windows
|
|
# golang.org/x/text v0.5.0
|
|
## explicit; go 1.17
|
|
golang.org/x/text/secure/bidirule
|
|
golang.org/x/text/transform
|
|
golang.org/x/text/unicode/bidi
|
|
golang.org/x/text/unicode/norm
|
|
# google.golang.org/api v0.30.0
|
|
## explicit; go 1.11
|
|
google.golang.org/api/googleapi
|
|
google.golang.org/api/googleapi/transport
|
|
google.golang.org/api/internal
|
|
google.golang.org/api/internal/gensupport
|
|
google.golang.org/api/internal/third_party/uritemplates
|
|
google.golang.org/api/option
|
|
google.golang.org/api/option/internaloption
|
|
google.golang.org/api/storage/v1
|
|
google.golang.org/api/transport/cert
|
|
google.golang.org/api/transport/http
|
|
google.golang.org/api/transport/http/internal/propagation
|
|
# google.golang.org/appengine v1.6.6
|
|
## explicit; go 1.11
|
|
google.golang.org/appengine
|
|
google.golang.org/appengine/internal
|
|
google.golang.org/appengine/internal/app_identity
|
|
google.golang.org/appengine/internal/base
|
|
google.golang.org/appengine/internal/datastore
|
|
google.golang.org/appengine/internal/log
|
|
google.golang.org/appengine/internal/modules
|
|
google.golang.org/appengine/internal/remote_api
|
|
google.golang.org/appengine/internal/urlfetch
|
|
google.golang.org/appengine/urlfetch
|
|
# google.golang.org/cloud v0.0.0-20151119220103-975617b05ea8
|
|
## explicit
|
|
google.golang.org/cloud
|
|
google.golang.org/cloud/internal
|
|
google.golang.org/cloud/internal/opts
|
|
google.golang.org/cloud/storage
|
|
# google.golang.org/genproto v0.0.0-20200825200019-8632dd797987
|
|
## explicit; go 1.11
|
|
google.golang.org/genproto/googleapis/rpc/status
|
|
# google.golang.org/grpc v1.31.0
|
|
## explicit; go 1.11
|
|
google.golang.org/grpc
|
|
google.golang.org/grpc/attributes
|
|
google.golang.org/grpc/backoff
|
|
google.golang.org/grpc/balancer
|
|
google.golang.org/grpc/balancer/base
|
|
google.golang.org/grpc/balancer/grpclb/state
|
|
google.golang.org/grpc/balancer/roundrobin
|
|
google.golang.org/grpc/binarylog/grpc_binarylog_v1
|
|
google.golang.org/grpc/codes
|
|
google.golang.org/grpc/connectivity
|
|
google.golang.org/grpc/credentials
|
|
google.golang.org/grpc/credentials/internal
|
|
google.golang.org/grpc/encoding
|
|
google.golang.org/grpc/encoding/proto
|
|
google.golang.org/grpc/grpclog
|
|
google.golang.org/grpc/internal
|
|
google.golang.org/grpc/internal/backoff
|
|
google.golang.org/grpc/internal/balancerload
|
|
google.golang.org/grpc/internal/binarylog
|
|
google.golang.org/grpc/internal/buffer
|
|
google.golang.org/grpc/internal/channelz
|
|
google.golang.org/grpc/internal/credentials
|
|
google.golang.org/grpc/internal/envconfig
|
|
google.golang.org/grpc/internal/grpclog
|
|
google.golang.org/grpc/internal/grpcrand
|
|
google.golang.org/grpc/internal/grpcsync
|
|
google.golang.org/grpc/internal/grpcutil
|
|
google.golang.org/grpc/internal/resolver/dns
|
|
google.golang.org/grpc/internal/resolver/passthrough
|
|
google.golang.org/grpc/internal/serviceconfig
|
|
google.golang.org/grpc/internal/status
|
|
google.golang.org/grpc/internal/syscall
|
|
google.golang.org/grpc/internal/transport
|
|
google.golang.org/grpc/keepalive
|
|
google.golang.org/grpc/metadata
|
|
google.golang.org/grpc/peer
|
|
google.golang.org/grpc/resolver
|
|
google.golang.org/grpc/serviceconfig
|
|
google.golang.org/grpc/stats
|
|
google.golang.org/grpc/status
|
|
google.golang.org/grpc/tap
|
|
# google.golang.org/protobuf v1.26.0
|
|
## explicit; go 1.9
|
|
google.golang.org/protobuf/encoding/prototext
|
|
google.golang.org/protobuf/encoding/protowire
|
|
google.golang.org/protobuf/internal/descfmt
|
|
google.golang.org/protobuf/internal/descopts
|
|
google.golang.org/protobuf/internal/detrand
|
|
google.golang.org/protobuf/internal/encoding/defval
|
|
google.golang.org/protobuf/internal/encoding/messageset
|
|
google.golang.org/protobuf/internal/encoding/tag
|
|
google.golang.org/protobuf/internal/encoding/text
|
|
google.golang.org/protobuf/internal/errors
|
|
google.golang.org/protobuf/internal/filedesc
|
|
google.golang.org/protobuf/internal/filetype
|
|
google.golang.org/protobuf/internal/flags
|
|
google.golang.org/protobuf/internal/genid
|
|
google.golang.org/protobuf/internal/impl
|
|
google.golang.org/protobuf/internal/order
|
|
google.golang.org/protobuf/internal/pragma
|
|
google.golang.org/protobuf/internal/set
|
|
google.golang.org/protobuf/internal/strs
|
|
google.golang.org/protobuf/internal/version
|
|
google.golang.org/protobuf/proto
|
|
google.golang.org/protobuf/reflect/protodesc
|
|
google.golang.org/protobuf/reflect/protoreflect
|
|
google.golang.org/protobuf/reflect/protoregistry
|
|
google.golang.org/protobuf/runtime/protoiface
|
|
google.golang.org/protobuf/runtime/protoimpl
|
|
google.golang.org/protobuf/types/descriptorpb
|
|
google.golang.org/protobuf/types/known/anypb
|
|
google.golang.org/protobuf/types/known/durationpb
|
|
google.golang.org/protobuf/types/known/timestamppb
|
|
# gopkg.in/check.v1 v1.0.0-20190902080502-41f04d3bba15
|
|
## explicit
|
|
gopkg.in/check.v1
|
|
# gopkg.in/yaml.v2 v2.4.0
|
|
## explicit; go 1.15
|
|
gopkg.in/yaml.v2
|