Skip to content

Commit 409625f

Browse files
Bump go directive to go 1.25.9 and fix security vulnerabilities (microsoft#728)
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com> Co-authored-by: dlevy-msft-sql <194277063+dlevy-msft-sql@users.noreply.github.com>
1 parent 7155706 commit 409625f

File tree

5 files changed

+114
-202
lines changed

5 files changed

+114
-202
lines changed

.github/workflows/golangci-lint.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -13,7 +13,7 @@ jobs:
1313
# Verify: gh api repos/actions/setup-go/git/ref/tags/v6 --jq '.object.sha'
1414
- uses: actions/setup-go@7a3fe6cf4cb3a834922a1244abfce67bcef6a0c5 # v6.2.0
1515
with:
16-
go-version: '1.25'
16+
go-version: '1.25.9'
1717
- uses: actions/checkout@v6
1818
- name: golangci-lint
1919
# Pinned to commit SHA for supply chain security (CWE-829)

.github/workflows/pr-validation.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -13,7 +13,7 @@ jobs:
1313
- name: Setup go
1414
uses: actions/setup-go@v6
1515
with:
16-
go-version: '1.25'
16+
go-version: '1.25.9'
1717
- name: Run tests against Linux SQL
1818
run: |
1919
go version

go.mod

Lines changed: 21 additions & 28 deletions
Original file line numberDiff line numberDiff line change
@@ -1,17 +1,17 @@
11
module github.com/microsoft/go-sqlcmd
22

3-
go 1.25.8
3+
go 1.25.9
44

55
require (
66
github.com/alecthomas/chroma/v2 v2.23.1
77
github.com/billgraziano/dpapi v0.5.0
88
github.com/distribution/reference v0.6.0
99
github.com/docker/distribution v2.8.3+incompatible
10-
github.com/docker/docker v28.5.2+incompatible
11-
github.com/docker/go-connections v0.6.0
1210
github.com/golang-sql/sqlexp v0.1.0
1311
github.com/google/uuid v1.6.0
1412
github.com/microsoft/go-mssqldb v1.9.8
13+
github.com/moby/moby/api v1.54.1
14+
github.com/moby/moby/client v0.4.0
1515
github.com/opencontainers/image-spec v1.1.1
1616
github.com/peterh/liner v1.2.2
1717
github.com/pkg/errors v0.9.1
@@ -38,59 +38,52 @@ require (
3838
github.com/cespare/xxhash/v2 v2.3.0 // indirect
3939
github.com/containerd/errdefs v1.0.0 // indirect
4040
github.com/containerd/errdefs/pkg v0.3.0 // indirect
41-
github.com/containerd/log v0.1.0 // indirect
42-
github.com/davecgh/go-spew v1.1.1 // indirect
41+
github.com/davecgh/go-spew v1.1.2-0.20180830191138-d8f796af33cc // indirect
4342
github.com/dlclark/regexp2 v1.11.5 // indirect
43+
github.com/docker/go-connections v0.6.0 // indirect
4444
github.com/docker/go-metrics v0.0.1 // indirect
4545
github.com/docker/go-units v0.5.0 // indirect
4646
github.com/docker/libtrust v0.0.0-20160708172513-aabc10ec26b7 // indirect
4747
github.com/felixge/httpsnoop v1.0.4 // indirect
4848
github.com/fsnotify/fsnotify v1.9.0 // indirect
4949
github.com/go-logr/logr v1.4.3 // indirect
5050
github.com/go-logr/stdr v1.2.2 // indirect
51-
github.com/go-viper/mapstructure/v2 v2.4.0 // indirect
51+
github.com/go-viper/mapstructure/v2 v2.5.0 // indirect
5252
github.com/golang-jwt/jwt/v5 v5.3.1 // indirect
5353
github.com/golang-sql/civil v0.0.0-20220223132316-b832511892a9 // indirect
54-
github.com/golang/protobuf v1.5.4 // indirect
5554
github.com/gorilla/mux v1.8.1 // indirect
5655
github.com/inconshreveable/mousetrap v1.1.0 // indirect
56+
github.com/klauspost/compress v1.18.5 // indirect
5757
github.com/kylelemons/godebug v1.1.0 // indirect
5858
github.com/mattn/go-runewidth v0.0.3 // indirect
59-
github.com/matttproud/golang_protobuf_extensions v1.0.1 // indirect
6059
github.com/moby/docker-image-spec v1.3.1 // indirect
61-
github.com/moby/sys/atomicwriter v0.1.0 // indirect
62-
github.com/moby/term v0.5.2 // indirect
63-
github.com/morikuni/aec v1.0.0 // indirect
60+
github.com/munnerz/goautoneg v0.0.0-20191010083416-a7dc8b61c822 // indirect
6461
github.com/opencontainers/go-digest v1.0.0 // indirect
65-
github.com/pelletier/go-toml/v2 v2.2.4 // indirect
62+
github.com/pelletier/go-toml/v2 v2.3.0 // indirect
6663
github.com/pkg/browser v0.0.0-20240102092130-5ac0b6a4141c // indirect
67-
github.com/pmezard/go-difflib v1.0.0 // indirect
68-
github.com/prometheus/client_golang v1.11.1 // indirect
69-
github.com/prometheus/client_model v0.2.0 // indirect
70-
github.com/prometheus/common v0.26.0 // indirect
71-
github.com/prometheus/procfs v0.6.0 // indirect
64+
github.com/pmezard/go-difflib v1.0.1-0.20181226105442-5d4384ee4fb2 // indirect
65+
github.com/prometheus/client_golang v1.23.2 // indirect
66+
github.com/prometheus/client_model v0.6.2 // indirect
67+
github.com/prometheus/common v0.66.1 // indirect
68+
github.com/prometheus/procfs v0.17.0 // indirect
7269
github.com/sagikazarmark/locafero v0.11.0 // indirect
7370
github.com/shopspring/decimal v1.4.0 // indirect
71+
github.com/sirupsen/logrus v1.9.4 // indirect
7472
github.com/sourcegraph/conc v0.3.1-0.20240121214520-5f936abd7ae8 // indirect
7573
github.com/spf13/afero v1.15.0 // indirect
7674
github.com/spf13/cast v1.10.0 // indirect
7775
github.com/subosito/gotenv v1.6.0 // indirect
7876
go.opentelemetry.io/auto/sdk v1.2.1 // indirect
79-
go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.60.0 // indirect
80-
go.opentelemetry.io/otel v1.40.0 // indirect
81-
go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp v1.35.0 // indirect
82-
go.opentelemetry.io/otel/metric v1.40.0 // indirect
83-
go.opentelemetry.io/otel/sdk v1.40.0 // indirect
84-
go.opentelemetry.io/otel/sdk/metric v1.40.0 // indirect
85-
go.opentelemetry.io/otel/trace v1.40.0 // indirect
77+
go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.67.0 // indirect
78+
go.opentelemetry.io/otel v1.42.0 // indirect
79+
go.opentelemetry.io/otel/metric v1.42.0 // indirect
80+
go.opentelemetry.io/otel/trace v1.42.0 // indirect
81+
go.yaml.in/yaml/v2 v2.4.3 // indirect
8682
go.yaml.in/yaml/v3 v3.0.4 // indirect
8783
golang.org/x/crypto v0.49.0 // indirect
8884
golang.org/x/mod v0.34.0 // indirect
8985
golang.org/x/net v0.52.0 // indirect
9086
golang.org/x/sync v0.20.0 // indirect
91-
golang.org/x/time v0.14.0 // indirect
92-
google.golang.org/grpc v1.79.3 // indirect
93-
google.golang.org/protobuf v1.36.10 // indirect
87+
google.golang.org/protobuf v1.36.11 // indirect
9488
gopkg.in/yaml.v3 v3.0.1 // indirect
95-
gotest.tools/v3 v3.5.2 // indirect
9689
)

0 commit comments

Comments
 (0)