vault/physical
Vault Automation a7c8fece0e
Backport [VAULT-45173] go: bump several dependencies to resolve GHSA-j88v-2chj-qfwx into release/2.x.x+ent into ce/release/2.x.x
* [VAULT-45173] go: bump several dependencies to resolve GHSA-j88v-2chj-qfwx

This PR has a set of fairly complex dependency bumps to resolve GHSA-j88v-2chj-qfwx. For the third time in about six weeks, we've had to deal with CVEs in old and unsupported versions of `jackc/pgx`. These changes are for us to rid ourselves of those transitive dependencies completely.

First, we get rid `jackc/pgx/v4` by bumping `cloud.google.com/go/cloudsqlconn` to `v1.21.0`, which pulls in `v5`.

Next, we have to get rid of `jackc/pgx v3`, which was brought in via chain of `hashicorp/go-discover` -> `joyent/triton-go` -> `jackc/pgx/v3`. First, we updated `go-discover` to pull in the v2 module of `triton-go` from the modern upstream ([0], [1]) and pin to it. Then we update our own manta support to pull in the v2 module. Finally, we replace the `TritonDataCenter/triton-go` module with a fork that removes an unnecessary dep on `pgx/v3`.[2]

[0]: https://github.com/hashicorp/go-discover/pull/326
[1]: https://github.com/hashicorp/go-discover/pull/332
[2]: https://github.com/TritonDataCenter/triton-go/pull/207

Signed-off-by: Ryan Cragun <me@ryan.ec>
Co-authored-by: Ryan Cragun <me@ryan.ec>
2026-05-18 09:42:41 -06:00
..
aerospike Backport [VAULT-43618] sdk: migrate from github.com/docker/docker to github.com/moby/moby into release/2.x.x+ent into ce/release/2.x.x (#13577) 2026-04-02 11:49:45 -06:00
alicloudoss license: update headers to IBM Corp. (#10229) (#10233) 2025-10-21 15:20:20 -06:00
azure license: update headers to IBM Corp. (#10229) (#10233) 2025-10-21 15:20:20 -06:00
cassandra license: update headers to IBM Corp. (#10229) (#10233) 2025-10-21 15:20:20 -06:00
cockroachdb Backport [VAULT-43618] sdk: migrate from github.com/docker/docker to github.com/moby/moby into release/2.x.x+ent into ce/release/2.x.x (#13577) 2026-04-02 11:49:45 -06:00
consul license: update headers to IBM Corp. (#10229) (#10233) 2025-10-21 15:20:20 -06:00
couchdb license: update headers to IBM Corp. (#10229) (#10233) 2025-10-21 15:20:20 -06:00
dynamodb license: update headers to IBM Corp. (#10229) (#10233) 2025-10-21 15:20:20 -06:00
etcd license: update headers to IBM Corp. (#10229) (#10233) 2025-10-21 15:20:20 -06:00
foundationdb license: update headers to IBM Corp. (#10229) (#10233) 2025-10-21 15:20:20 -06:00
gcs license: update headers to IBM Corp. (#10229) (#10233) 2025-10-21 15:20:20 -06:00
manta Backport [VAULT-45173] go: bump several dependencies to resolve GHSA-j88v-2chj-qfwx into release/2.x.x+ent into ce/release/2.x.x 2026-05-18 09:42:41 -06:00
mssql license: update headers to IBM Corp. (#10229) (#10233) 2025-10-21 15:20:20 -06:00
mysql license: update headers to IBM Corp. (#10229) (#10233) 2025-10-21 15:20:20 -06:00
oci physical: use permitpool from go-secure-stdlib (#29331) 2025-01-24 12:33:44 -05:00
postgresql Backport [VAULT-43618] sdk: migrate from github.com/docker/docker to github.com/moby/moby into release/2.x.x+ent into ce/release/2.x.x (#13577) 2026-04-02 11:49:45 -06:00
raft Backport update go version 1.26.1 into ce/main (#13099) 2026-03-17 17:02:43 -07:00
s3 license: update headers to IBM Corp. (#10229) (#10233) 2025-10-21 15:20:20 -06:00
spanner license: update headers to IBM Corp. (#10229) (#10233) 2025-10-21 15:20:20 -06:00
swift license: update headers to IBM Corp. (#10229) (#10233) 2025-10-21 15:20:20 -06:00
zookeeper license: update headers to IBM Corp. (#10229) (#10233) 2025-10-21 15:20:20 -06:00