containerd/vendor/golang.org/x/net/http2
Sebastiaan van Stijn 662d8a085e
vendor: golang.org/x/net v0.4.0
golang.org/x/net contains a fix for CVE-2022-41717, which was addressed
in stdlib in go1.19.4 and go1.18.9;

> net/http: limit canonical header cache by bytes, not entries
>
> An attacker can cause excessive memory growth in a Go server accepting
> HTTP/2 requests.
>
> HTTP/2 server connections contain a cache of HTTP header keys sent by
> the client. While the total number of entries in this cache is capped,
> an attacker sending very large keys can cause the server to allocate
> approximately 64 MiB per open connection.
>
> This issue is also fixed in golang.org/x/net/http2 v0.4.0,
> for users manually configuring HTTP/2.

full diff: https://github.com/golang/net/compare/c63010009c80...v0.4.0

other dependency updates (due to (circular) dependencies between them):

- golang.org/x/sys v0.3.0: https://github.com/golang/sys/compare/v0.2.0...v0.3.0
- golang.org/x/term v0.3.0: https://github.com/golang/term/compare/v0.1.0...v0.3.0
- golang.org/x/text v0.5.0: https://github.com/golang/text/compare/v0.4.0...v0.5.0

Signed-off-by: Sebastiaan van Stijn <github@gone.nl>
2022-12-07 22:20:44 +01:00
..
hpack vendor: golang.org/x/net v0.4.0 2022-12-07 22:20:44 +01:00
.gitignore Go mod vendor 2020-12-01 01:41:25 +08:00
ascii.go vendor: Bump hcsshim to 0.9.0 2021-10-07 21:00:35 -07:00
ciphers.go Update x/sys, x/net and bbolt modules to support Risc-V 2019-06-07 17:54:32 -03:00
client_conn_pool.go bump cri-api 2022-08-25 21:03:55 +08:00
databuffer.go vendor: update grpc dependencies 2017-05-25 17:20:23 -07:00
Dockerfile go.mod: update kubernetes to v1.22.0 2021-08-09 16:16:54 -04:00
errors.go Upgrade google.golang.org/grpc and google.golang.org/protobuf 2022-04-27 17:25:02 +00:00
flow.go vendor: golang.org/x/net v0.0.0-20200707034311-ab3426394381 2020-08-11 09:57:41 +02:00
frame.go vendor: golang.org/x/net v0.0.0-20220906165146-f3363e06e74c 2022-09-06 22:46:21 +02:00
go111.go go.mod: github.com/containerd/imgcrypt v1.1.1-0.20210412181126-0bed51b9522c 2021-04-13 01:06:38 +02:00
go115.go go.mod: update kubernetes to v1.22.0 2021-08-09 16:16:54 -04:00
go118.go Upgrade google.golang.org/grpc and google.golang.org/protobuf 2022-04-27 17:25:02 +00:00
gotrack.go Add vendoring to containerd master 2017-01-11 16:59:06 -05:00
headermap.go vendor: golang.org/x/net v0.4.0 2022-12-07 22:20:44 +01:00
http2.go vendor: golang.org/x/net v0.0.0-20220906165146-f3363e06e74c 2022-09-06 22:46:21 +02:00
Makefile Go mod vendor 2020-12-01 01:41:25 +08:00
not_go111.go go.mod: github.com/containerd/imgcrypt v1.1.1-0.20210412181126-0bed51b9522c 2021-04-13 01:06:38 +02:00
not_go115.go go.mod: update kubernetes to v1.22.0 2021-08-09 16:16:54 -04:00
not_go118.go Upgrade google.golang.org/grpc and google.golang.org/protobuf 2022-04-27 17:25:02 +00:00
pipe.go Upgrade OpenTelemetry dependencies 2021-12-16 22:35:57 +00:00
server.go vendor: golang.org/x/net v0.4.0 2022-12-07 22:20:44 +01:00
transport.go vendor: golang.org/x/net v0.4.0 2022-12-07 22:20:44 +01:00
write.go go.mod: update kubernetes to v1.22.0 2021-08-09 16:16:54 -04:00
writesched_priority.go bump cri-api 2022-08-25 21:03:55 +08:00
writesched_random.go Upgrade OpenTelemetry dependencies 2021-12-16 22:35:57 +00:00
writesched.go Upgrade OpenTelemetry dependencies 2021-12-16 22:35:57 +00:00