Skip to content

Commit 4ee485c

Browse files
authored
Work around Component Governance false positives (#1623)
1 parent 377de51 commit 4ee485c

File tree

3 files changed

+28
-7
lines changed

3 files changed

+28
-7
lines changed

eng/_util/go.mod

Lines changed: 5 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -4,16 +4,18 @@
44

55
module github.com/microsoft/go/_util
66

7-
go 1.22.0
7+
go 1.23.0
88

99
require (
10+
github.com/golang-jwt/jwt/v5 v5.2.2
1011
github.com/microsoft/go-infra v0.0.7-0.20250217095817-3d02b2f77127
1112
github.com/microsoft/go-infra/goinstallscript v0.0.0-20250210150554-f31015b54477
12-
golang.org/x/sys v0.30.0
13+
golang.org/x/net v0.39.0
14+
golang.org/x/sys v0.32.0
1315
)
1416

1517
require (
1618
github.com/google/uuid v1.6.0 // indirect
1719
github.com/microsoft/azure-devops-go-api/azuredevops v1.0.0-b5 // indirect
18-
golang.org/x/text v0.22.0 // indirect
20+
golang.org/x/text v0.24.0 // indirect
1921
)

eng/_util/go.sum

Lines changed: 8 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,7 @@
11
github.com/go-test/deep v1.1.1 h1:0r/53hagsehfO4bzD2Pgr/+RgHqhmf+k1Bpse2cTu1U=
22
github.com/go-test/deep v1.1.1/go.mod h1:5C2ZWiW0ErCdrYzpqxLbTX7MG14M9iiw8DgHncVwcsE=
3+
github.com/golang-jwt/jwt/v5 v5.2.2 h1:Rl4B7itRWVtYIHFrSNd7vhTiz9UpLdi6gZhZ3wEeDy8=
4+
github.com/golang-jwt/jwt/v5 v5.2.2/go.mod h1:pqrtFR0X4osieyHYxtmOUWsAWrfe1Q5UVIyoH402zdk=
35
github.com/google/uuid v1.1.1/go.mod h1:TIyPZe4MgqvfeYDBFedMoGGpEw/LqOeaOT+nhxU+yHo=
46
github.com/google/uuid v1.6.0 h1:NIvaJDMOsjHA8n1jAhLSgzrAzy1Hgr+hNrb57e+94F0=
57
github.com/google/uuid v1.6.0/go.mod h1:TIyPZe4MgqvfeYDBFedMoGGpEw/LqOeaOT+nhxU+yHo=
@@ -9,9 +11,11 @@ github.com/microsoft/go-infra v0.0.7-0.20250217095817-3d02b2f77127 h1:nb0pU3pHQU
911
github.com/microsoft/go-infra v0.0.7-0.20250217095817-3d02b2f77127/go.mod h1:TYHdrIvfN+aAbpD0KYTK7zUMHu/HjOr3FSjpLtuLA2k=
1012
github.com/microsoft/go-infra/goinstallscript v0.0.0-20250210150554-f31015b54477 h1:wTb+eE4fmHYaHok8MROCDSNBprhBPlj5IAx3KP4MGfU=
1113
github.com/microsoft/go-infra/goinstallscript v0.0.0-20250210150554-f31015b54477/go.mod h1:SFsdKAEHdmGsGoh8FkksVaxoQ3rnnJ/TBqN09Ml/0Cw=
12-
golang.org/x/sys v0.30.0 h1:QjkSwP/36a20jFYWkSue1YwXzLmsV5Gfq7Eiy72C1uc=
13-
golang.org/x/sys v0.30.0/go.mod h1:/VUhepiaJMQUp4+oa/7Zr1D23ma6VTLIYjOOTFZPUcA=
14-
golang.org/x/text v0.22.0 h1:bofq7m3/HAFvbF51jz3Q9wLg3jkvSPuiZu/pD1XwgtM=
15-
golang.org/x/text v0.22.0/go.mod h1:YRoo4H8PVmsu+E3Ou7cqLVH8oXWIHVoX0jqUWALQhfY=
14+
golang.org/x/net v0.39.0 h1:ZCu7HMWDxpXpaiKdhzIfaltL9Lp31x/3fCP11bc6/fY=
15+
golang.org/x/net v0.39.0/go.mod h1:X7NRbYVEA+ewNkCNyJ513WmMdQ3BineSwVtN2zD/d+E=
16+
golang.org/x/sys v0.32.0 h1:s77OFDvIQeibCmezSnk/q6iAfkdiQaJi4VzroCFrN20=
17+
golang.org/x/sys v0.32.0/go.mod h1:BJP2sWEmIv4KK5OTEluFJCKSidICx8ciO85XgH3Ak8k=
18+
golang.org/x/text v0.24.0 h1:dd5Bzh4yt5KYA8f9CJHCP4FB4D51c2c6JvN37xJJkJ0=
19+
golang.org/x/text v0.24.0/go.mod h1:L8rBsPeo2pSS+xqN0d5u2ikmjtmoJbDBT1b7nHvFCdU=
1620
golang.org/x/tools v0.30.0 h1:BgcpHewrV5AUp2G9MebG4XPFI1E2W41zU1SaqVA9vJY=
1721
golang.org/x/tools v0.30.0/go.mod h1:c347cR/OJfw5TI+GfX7RUPNMdDRRbjvYTS0jPyvsVtY=

eng/_util/tools/cg_tools.go

Lines changed: 15 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,15 @@
1+
// Copyright (c) Microsoft Corporation.
2+
// Use of this source code is governed by a BSD-style
3+
// license that can be found in the LICENSE file.
4+
5+
//go:build tools
6+
7+
package tools
8+
9+
// Work around Go detector false positives: import dependencies just so that we can upgrade
10+
// them. See https://github.com/microsoft/component-detection/issues/1333
11+
12+
import (
13+
_ "github.com/golang-jwt/jwt/v5"
14+
_ "golang.org/x/net/http2"
15+
)

0 commit comments

Comments
 (0)