sourcegraph/internal/hostmatcher
Keegan Carruthers-Smith 11e13d6583
gomod: update or vendor buildkit, docker, hostmatcher and saml to resolve CVEs (#60130)
We had multiple CVEs reported for these dependencies. I don't think this
affected us in practice, but this is a step towards a clean scan from
trivy. I updated to the minimum version which supports the fix.

  go get github.com/moby/buildkit@v0.12.5
  go get github.com/docker/docker@v24.0.7
  go get -u github.com/crewjam/saml

In the case of code.gitea.io/gitea@v1.18.0/modules/hostmatcher we
couldn't update it due to lots of issues popping up in random
transitive dependencies. However, we don't depend on the whole gitea
project, rather just a tiny self contained package in it. So we vendor
it in.

Test Plan: CI and "trivy fs go.mod" reporting no issues.
2024-02-05 13:14:15 +02:00
..
BUILD.bazel gomod: update or vendor buildkit, docker, hostmatcher and saml to resolve CVEs (#60130) 2024-02-05 13:14:15 +02:00
hostmatcher_test.go gomod: update or vendor buildkit, docker, hostmatcher and saml to resolve CVEs (#60130) 2024-02-05 13:14:15 +02:00
hostmatcher.go gomod: update or vendor buildkit, docker, hostmatcher and saml to resolve CVEs (#60130) 2024-02-05 13:14:15 +02:00
http.go gomod: update or vendor buildkit, docker, hostmatcher and saml to resolve CVEs (#60130) 2024-02-05 13:14:15 +02:00
LICENSE gomod: update or vendor buildkit, docker, hostmatcher and saml to resolve CVEs (#60130) 2024-02-05 13:14:15 +02:00
README.md gomod: update or vendor buildkit, docker, hostmatcher and saml to resolve CVEs (#60130) 2024-02-05 13:14:15 +02:00

This is a vendored copy of the MIT licensed code code.gitea.io/gitea@v1.18.0/modules/hostmatcher

This was done since depending on the full gitea source code created issues in tracking dependencies due to the large number of deps that change in the gitea project. In particular we had trouble updating and resolving a CVE from the dependency.