Skip to content

Commit 822efeb

Browse files
authored
chore: fix vulnerabilities (#374)
Fixes: - CVE-2025-64718 - CVE-2025-54798 - CVE-2025-5889 Also: - Updates grafana plugin sdk (#366) - Updates @changesets/cli (#354) - Pins dependencies (https://github.com/grafana/google-sheets-datasource/pull/353/files)
1 parent f14587b commit 822efeb

File tree

9 files changed

+313
-295
lines changed

9 files changed

+313
-295
lines changed

.config/Dockerfile

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,4 @@
1-
ARG grafana_version=latest
1+
ARG grafana_version=latest@sha256:96a793a92c9a77cf543d6e5c55100cd296ed9e22487dc3d069331364c456247b
22
ARG grafana_image=grafana-enterprise
33

44
FROM grafana/${grafana_image}:${grafana_version}

.github/workflows/add-to-project.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -24,7 +24,7 @@ jobs:
2424
GITHUB_APP_PRIVATE_KEY=grafana-oss-big-tent:private-key
2525
- name: Generate a token
2626
id: generate-token
27-
uses: actions/create-github-app-token@v1
27+
uses: actions/create-github-app-token@d72941d797fd3113feb6b93fd0dec494b13a2547 #v1
2828
with:
2929
app-id: ${{ env.GITHUB_APP_ID }}
3030
private-key: ${{ env.GITHUB_APP_PRIVATE_KEY }}

.github/workflows/update-make-docs.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -15,4 +15,4 @@ jobs:
1515
- uses: actions/checkout@692973e3d937129bcbf40652eb9f2f61becf3332 # v4.1.7
1616
with:
1717
persist-credentials: false
18-
- uses: grafana/writers-toolkit/update-make-docs@update-make-docs/v1 # zizmor: ignore[unpinned-uses]
18+
- uses: grafana/writers-toolkit/update-make-docs@f65819d6a412b752c0e0263375215f049507b0e6 # update-make-docs/v1 # zizmor: ignore[unpinned-uses]

go.mod

Lines changed: 29 additions & 28 deletions
Original file line numberDiff line numberDiff line change
@@ -5,18 +5,20 @@ go 1.24.6
55
require (
66
github.com/araddon/dateparse v0.0.0-20210429162001-6b43995a97de
77
github.com/davecgh/go-spew v1.1.2-0.20180830191138-d8f796af33cc
8-
github.com/grafana/grafana-plugin-sdk-go v0.283.0
8+
github.com/grafana/grafana-plugin-sdk-go v0.284.0
99
github.com/patrickmn/go-cache v2.1.0+incompatible
1010
github.com/stretchr/testify v1.11.1
1111
golang.org/x/oauth2 v0.33.0
12-
google.golang.org/api v0.233.0
12+
google.golang.org/api v0.256.0
1313
)
1414

1515
require (
16-
cloud.google.com/go/auth v0.16.1 // indirect
16+
cloud.google.com/go/auth v0.17.0 // indirect
1717
cloud.google.com/go/auth/oauth2adapt v0.2.8 // indirect
1818
github.com/apache/arrow-go/v18 v18.4.1 // indirect
1919
github.com/cenkalti/backoff/v5 v5.0.3 // indirect
20+
github.com/clipperhouse/stringish v0.1.1 // indirect
21+
github.com/clipperhouse/uax29/v2 v2.3.0 // indirect
2022
github.com/felixge/httpsnoop v1.0.4 // indirect
2123
github.com/go-logr/logr v1.4.3 // indirect
2224
github.com/go-logr/stdr v1.2.2 // indirect
@@ -28,14 +30,15 @@ require (
2830
github.com/grafana/pyroscope-go/godeltaprof v0.1.9 // indirect
2931
github.com/grpc-ecosystem/go-grpc-middleware/providers/prometheus v1.1.0 // indirect
3032
github.com/grpc-ecosystem/go-grpc-middleware/v2 v2.3.3 // indirect
31-
github.com/grpc-ecosystem/grpc-gateway/v2 v2.27.2 // indirect
32-
github.com/jaegertracing/jaeger-idl v0.5.0 // indirect
33+
github.com/grpc-ecosystem/grpc-gateway/v2 v2.27.3 // indirect
34+
github.com/jaegertracing/jaeger-idl v0.6.0 // indirect
3335
github.com/klauspost/cpuid/v2 v2.3.0 // indirect
3436
github.com/munnerz/goautoneg v0.0.0-20191010083416-a7dc8b61c822 // indirect
37+
github.com/olekukonko/tablewriter v0.0.5 // indirect
3538
github.com/prometheus/client_golang v1.23.2 // indirect
36-
github.com/stretchr/objx v0.5.2 // indirect
39+
github.com/stretchr/objx v0.5.3 // indirect
3740
github.com/zeebo/xxh3 v1.0.2 // indirect
38-
go.opentelemetry.io/auto/sdk v1.1.0 // indirect
41+
go.opentelemetry.io/auto/sdk v1.2.1 // indirect
3942
go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc v0.63.0 // indirect
4043
go.opentelemetry.io/contrib/instrumentation/net/http/httptrace/otelhttptrace v0.63.0 // indirect
4144
go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.63.0 // indirect
@@ -47,54 +50,52 @@ require (
4750
go.opentelemetry.io/otel/metric v1.38.0 // indirect
4851
go.opentelemetry.io/otel/sdk v1.38.0 // indirect
4952
go.opentelemetry.io/otel/trace v1.38.0 // indirect
50-
go.opentelemetry.io/proto/otlp v1.7.1 // indirect
53+
go.opentelemetry.io/proto/otlp v1.9.0 // indirect
5154
go.yaml.in/yaml/v2 v2.4.3 // indirect
5255
golang.org/x/crypto v0.45.0 // indirect
53-
golang.org/x/exp v0.0.0-20251002181428-27f1f14c8bb9 // indirect
54-
golang.org/x/mod v0.29.0 // indirect
56+
golang.org/x/exp v0.0.0-20251125195548-87e1e737ad39 // indirect
57+
golang.org/x/mod v0.30.0 // indirect
5558
golang.org/x/sync v0.18.0 // indirect
56-
golang.org/x/telemetry v0.0.0-20251008203120-078029d740a8 // indirect
57-
golang.org/x/tools v0.38.0 // indirect
58-
google.golang.org/genproto/googleapis/api v0.0.0-20250825161204-c5933d9347a5 // indirect
59-
google.golang.org/genproto/googleapis/rpc v0.0.0-20251002232023-7c0ddcbb5797 // indirect
59+
golang.org/x/telemetry v0.0.0-20251128220624-abf20d0e57ec // indirect
60+
golang.org/x/tools v0.39.0 // indirect
61+
google.golang.org/genproto/googleapis/api v0.0.0-20251124214823-79d6a2a48846 // indirect
62+
google.golang.org/genproto/googleapis/rpc v0.0.0-20251124214823-79d6a2a48846 // indirect
6063
)
6164

6265
require (
63-
cloud.google.com/go/compute/metadata v0.7.0 // indirect
66+
cloud.google.com/go/compute/metadata v0.9.0 // indirect
6467
github.com/BurntSushi/toml v1.5.0 // indirect
6568
github.com/beorn7/perks v1.0.1 // indirect
6669
github.com/cespare/xxhash/v2 v2.3.0 // indirect
6770
github.com/cheekybits/genny v1.0.0 // indirect
6871
github.com/cpuguy83/go-md2man/v2 v2.0.7 // indirect
69-
github.com/fatih/color v1.15.0 // indirect
72+
github.com/fatih/color v1.18.0 // indirect
7073
github.com/golang/protobuf v1.5.4 // indirect
71-
github.com/google/flatbuffers v25.2.10+incompatible // indirect
74+
github.com/google/flatbuffers v25.9.23+incompatible // indirect
7275
github.com/google/go-cmp v0.7.0 // indirect
7376
github.com/google/uuid v1.6.0 // indirect
74-
github.com/googleapis/enterprise-certificate-proxy v0.3.6 // indirect
75-
github.com/googleapis/gax-go/v2 v2.14.1 // indirect
77+
github.com/googleapis/enterprise-certificate-proxy v0.3.7 // indirect
78+
github.com/googleapis/gax-go/v2 v2.15.0 // indirect
7679
github.com/grafana/grafana-google-sdk-go v0.4.2
7780
github.com/hashicorp/go-hclog v1.6.3 // indirect
7881
github.com/hashicorp/go-plugin v1.7.0 // indirect
7982
github.com/hashicorp/yamux v0.1.2 // indirect
8083
github.com/json-iterator/go v1.1.12 // indirect
81-
github.com/klauspost/compress v1.18.0 // indirect
84+
github.com/klauspost/compress v1.18.2 // indirect
8285
github.com/magefile/mage v1.15.0 // indirect
8386
github.com/mattetti/filebuffer v1.0.1 // indirect
84-
github.com/mattn/go-colorable v0.1.13 // indirect
87+
github.com/mattn/go-colorable v0.1.14 // indirect
8588
github.com/mattn/go-isatty v0.0.20 // indirect
86-
github.com/mattn/go-runewidth v0.0.16 // indirect
89+
github.com/mattn/go-runewidth v0.0.19 // indirect
8790
github.com/modern-go/concurrent v0.0.0-20180306012644-bacd9c7ef1dd // indirect
8891
github.com/modern-go/reflect2 v1.0.2 // indirect
89-
github.com/oklog/run v1.1.0 // indirect
90-
github.com/olekukonko/tablewriter v0.0.5 // indirect
92+
github.com/oklog/run v1.2.0 // indirect
9193
github.com/pierrec/lz4/v4 v4.1.22 // indirect
9294
github.com/pkg/errors v0.9.1
9395
github.com/pmezard/go-difflib v1.0.1-0.20181226105442-5d4384ee4fb2 // indirect
9496
github.com/prometheus/client_model v0.6.2 // indirect
95-
github.com/prometheus/common v0.67.2 // indirect
96-
github.com/prometheus/procfs v0.16.1 // indirect
97-
github.com/rivo/uniseg v0.4.7 // indirect
97+
github.com/prometheus/common v0.67.4 // indirect
98+
github.com/prometheus/procfs v0.19.2 // indirect
9899
github.com/russross/blackfriday/v2 v2.1.0 // indirect
99100
github.com/unknwon/bra v0.0.0-20200517080246-1e3013ecaff8 // indirect
100101
github.com/unknwon/com v1.0.1 // indirect
@@ -104,7 +105,7 @@ require (
104105
golang.org/x/sys v0.38.0 // indirect
105106
golang.org/x/text v0.31.0 // indirect
106107
golang.org/x/xerrors v0.0.0-20240903120638-7835f813f4da // indirect
107-
google.golang.org/grpc v1.76.0
108+
google.golang.org/grpc v1.77.0
108109
google.golang.org/protobuf v1.36.10 // indirect
109110
gopkg.in/fsnotify/fsnotify.v1 v1.4.7 // indirect
110111
gopkg.in/yaml.v3 v3.0.1 // indirect

0 commit comments

Comments
 (0)