Fix Grype CVEs: update logrus and prometheus/prometheus

- Update github.com/sirupsen/logrus v1.9.0 -> v1.9.3 in test/go.mod
  to fix GHSA-4f99-4q7p-p3gh (High)
- Update github.com/prometheus/prometheus v0.35.0 -> v0.311.3
  to fix GHSA-vffh-x6r8-xx99 (Medium)
- Run go mod tidy and go mod vendor to update vendor directory
This commit is contained in:
Bruno Chauvet
2026-05-04 10:45:24 +03:00
committed by Ciprian Hacman
parent 255c6e602c
commit 97bb2fbb44
279 changed files with 17945 additions and 29165 deletions
@@ -1,9 +1,10 @@
// Copyright 2019 The Prometheus Authors
// Copyright 2026 Google LLC
//
// Licensed under the Apache License, Version 2.0 (the "License");
// you may not use this file except in compliance with the License.
// You may obtain a copy of the License at
//
// http://www.apache.org/licenses/LICENSE-2.0
// http://www.apache.org/licenses/LICENSE-2.0
//
// Unless required by applicable law or agreed to in writing, software
// distributed under the License is distributed on an "AS IS" BASIS,
@@ -11,16 +12,9 @@
// See the License for the specific language governing permissions and
// limitations under the License.
//go:build js
// +build js
// Code generated by gapicgen. DO NOT EDIT.
package prometheus
package internal
func canCollectProcess() bool {
return false
}
func (c *processCollector) processCollect(ch chan<- Metric) {
// noop on this platform
return
}
// Version is the current tagged release of the library.
const Version = "0.18.2"
+1
View File
@@ -43,6 +43,7 @@ const (
// The Content-Type values for the different wire protocols. Do not do direct
// comparisons to these constants, instead use the comparison functions.
//
// Deprecated: Use expfmt.NewFormat(expfmt.TypeUnknown) instead.
FmtUnknown Format = `<unknown>`
// Deprecated: Use expfmt.NewFormat(expfmt.TypeTextPlain) instead.
-1
View File
@@ -13,7 +13,6 @@
// Build only when actually fuzzing
//go:build gofuzz
// +build gofuzz
package expfmt
+5
View File
@@ -101,6 +101,11 @@ https://github.com/microsoft/vscode-codicons
Copyright (c) Microsoft Corporation and other contributors
See https://github.com/microsoft/vscode-codicons/blob/main/LICENSE for license details.
Mantine UI
https://github.com/mantinedev/mantine
Copyright (c) 2021 Vitaly Rtishchev
See https://github.com/mantinedev/mantine/blob/master/LICENSE for license details.
We also use code from a large number of npm packages. For details, see:
- https://github.com/prometheus/prometheus/blob/main/web/ui/react-app/package.json
- https://github.com/prometheus/prometheus/blob/main/web/ui/react-app/package-lock.json
+1 -1
View File
@@ -1,4 +1,4 @@
// Copyright 2016 The Prometheus Authors
// Copyright The Prometheus Authors
// Licensed under the Apache License, Version 2.0 (the "License");
// you may not use this file except in compliance with the License.
// You may obtain a copy of the License at