Skip to content

Bump the aws-sdk group with 3 updates - #175

Merged
github-actions[bot] merged 1 commit into
mainfrom
dependabot/go_modules/aws-sdk-6adb5debb0
Aug 5, 2026
Merged

Bump the aws-sdk group with 3 updates#175
github-actions[bot] merged 1 commit into
mainfrom
dependabot/go_modules/aws-sdk-6adb5debb0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 5, 2026

Copy link
Copy Markdown
Contributor

Bumps the aws-sdk group with 3 updates: github.com/aws/aws-sdk-go-v2/config, github.com/aws/aws-sdk-go-v2/service/cloudtrail and github.com/aws/aws-sdk-go-v2/service/ec2.

Updates github.com/aws/aws-sdk-go-v2/config from 1.32.32 to 1.32.34

Commits

Updates github.com/aws/aws-sdk-go-v2/service/cloudtrail from 1.58.1 to 1.58.3

Commits

Updates github.com/aws/aws-sdk-go-v2/service/ec2 from 1.317.1 to 1.318.1

Commits

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Summary by CodeRabbit

  • Chores
    • Updated AWS SDK components and related service-support packages to newer versions.
    • Incorporated dependency updates for configuration, CloudTrail, and EC2 integrations.

Bumps the aws-sdk group with 3 updates: [github.com/aws/aws-sdk-go-v2/config](https://github.com/aws/aws-sdk-go-v2), [github.com/aws/aws-sdk-go-v2/service/cloudtrail](https://github.com/aws/aws-sdk-go-v2) and [github.com/aws/aws-sdk-go-v2/service/ec2](https://github.com/aws/aws-sdk-go-v2).


Updates `github.com/aws/aws-sdk-go-v2/config` from 1.32.32 to 1.32.34
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases)
- [Commits](aws/aws-sdk-go-v2@config/v1.32.32...config/v1.32.34)

Updates `github.com/aws/aws-sdk-go-v2/service/cloudtrail` from 1.58.1 to 1.58.3
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases)
- [Commits](aws/aws-sdk-go-v2@service/s3/v1.58.1...service/s3/v1.58.3)

Updates `github.com/aws/aws-sdk-go-v2/service/ec2` from 1.317.1 to 1.318.1
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases)
- [Commits](aws/aws-sdk-go-v2@service/ec2/v1.317.1...service/ec2/v1.318.1)

---
updated-dependencies:
- dependency-name: github.com/aws/aws-sdk-go-v2/config
  dependency-version: 1.32.34
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: aws-sdk
- dependency-name: github.com/aws/aws-sdk-go-v2/service/cloudtrail
  dependency-version: 1.58.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: aws-sdk
- dependency-name: github.com/aws/aws-sdk-go-v2/service/ec2
  dependency-version: 1.318.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: aws-sdk
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added approved Indicates a PR has been approved by an approver from all required OWNERS files. area/dependency Issues or PRs related to dependency changes ok-to-test Indicates a non-member PR verified by an org member that is safe to test. labels Aug 5, 2026
@openshift-ci

openshift-ci Bot commented Aug 5, 2026

Copy link
Copy Markdown

[APPROVALNOTIFIER] This PR is APPROVED

Approval requirements bypassed by manually added approval.

This pull-request has been approved by: dependabot[bot]

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

2 similar comments
@openshift-ci

openshift-ci Bot commented Aug 5, 2026

Copy link
Copy Markdown

[APPROVALNOTIFIER] This PR is APPROVED

Approval requirements bypassed by manually added approval.

This pull-request has been approved by: dependabot[bot]

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@openshift-ci

openshift-ci Bot commented Aug 5, 2026

Copy link
Copy Markdown

[APPROVALNOTIFIER] This PR is APPROVED

Approval requirements bypassed by manually added approval.

This pull-request has been approved by: dependabot[bot]

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@coderabbitai

coderabbitai Bot commented Aug 5, 2026

Copy link
Copy Markdown

Walkthrough

Updated direct AWS SDK modules for config, CloudTrail, and EC2. Updated related indirect AWS SDK, Smithy, and service-support modules in go.mod.

Changes

AWS SDK dependency updates

Layer / File(s) Summary
AWS SDK module version updates
go.mod
Updated direct AWS SDK versions for config, CloudTrail, and EC2. Updated related indirect AWS SDK, STS, SSO, Smithy, and service-support versions.

Estimated code review effort: 1 (Trivial) | ~2 minutes

Possibly related PRs

Suggested reviewers: bmeng, tiwillia

🚥 Pre-merge checks | ✅ 11
✅ Passed checks (11 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly describes the three AWS SDK dependency updates in the pull request.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
No-Weak-Crypto ✅ Passed The patch changes only AWS dependency versions and checksums; tracked application files contain no flagged algorithms or secret comparisons, and Smithy’s MD5 helper is unchanged from v1.27.5.
Container-Privileges ✅ Passed The PR changes only go.mod and go.sum; it adds no container or Kubernetes manifest settings, and existing privileged-nested parameters default to false.
No-Sensitive-Data-In-Logs ✅ Passed The PR changes only AWS dependency versions and checksums in go.mod/go.sum; it adds no source code, logging calls, or sensitive data.
No-Hardcoded-Secrets ✅ Passed The patch only updates AWS dependency versions and go.sum integrity hashes; it adds no credentials, secret-like literals, credential URLs, or private-key material.
No-Injection-Vectors ✅ Passed The patch changes only go.mod and go.sum. Added content contains AWS module versions and checksums, with no executable source or named injection vectors.
Ai-Attribution ✅ Passed The PR has one Dependabot commit; its message and trailers contain no AI-tool mention, Assisted-by, Generated-by, or Co-Authored-By trailer.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch dependabot/go_modules/aws-sdk-6adb5debb0

Comment @coderabbitai help to get the list of available commands.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@go.mod`:
- Around line 21-33: Upgrade the vulnerable transitive dependencies used by the
E2E binary: set github.com/golang/glog to v1.2.4 or later and golang.org/x/text
to v0.39.0 or later in the module dependency configuration, then refresh the
dependency graph and rerun the vulnerability scan to confirm the resolved
versions.
🪄 Autofix

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository: openshift-online/coderabbit/.coderabbit.yaml

Review profile: CHILL

Plan: Enterprise

Run ID: 2909b6db-ca11-4732-ae98-46a63fd1af3d

📥 Commits

Reviewing files that changed from the base of the PR and between 60b0c91 and 473b20f.

⛔ Files ignored due to path filters (1)
  • go.sum is excluded by !**/*.sum
📒 Files selected for processing (1)
  • go.mod

Comment thread go.mod
Comment on lines +21 to +33
github.com/aws/aws-sdk-go-v2 v1.43.3 // indirect
github.com/aws/aws-sdk-go-v2/credentials v1.19.33 // indirect
github.com/aws/aws-sdk-go-v2/feature/ec2/imds v1.18.34 // indirect
github.com/aws/aws-sdk-go-v2/internal/configsources v1.4.34 // indirect
github.com/aws/aws-sdk-go-v2/internal/endpoints/v2 v2.7.34 // indirect
github.com/aws/aws-sdk-go-v2/internal/v4a v1.4.35 // indirect
github.com/aws/aws-sdk-go-v2/service/internal/accept-encoding v1.13.15 // indirect
github.com/aws/aws-sdk-go-v2/service/internal/presigned-url v1.13.34 // indirect
github.com/aws/aws-sdk-go-v2/service/signin v1.5.3 // indirect
github.com/aws/aws-sdk-go-v2/service/sso v1.33.3 // indirect
github.com/aws/aws-sdk-go-v2/service/ssooidc v1.38.3 // indirect
github.com/aws/aws-sdk-go-v2/service/sts v1.45.3 // indirect
github.com/aws/smithy-go v1.27.6 // indirect

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔒 Security & Privacy | 🟡 Minor | ⚡ Quick win

🧩 Analysis chain

🏁 Script executed:

#!/usr/bin/env bash
set -euo pipefail

test -f go.sum
go mod verify

osv-scanner scan source -r .
osv-scanner --licenses .

retracted_or_prerelease="$(
  go list -m -json all |
    jq -s -r '
      .[]
      | select(
          (.Retracted != null) or
          (((.Version // "") | test("-")))
        )
      | "\(.Path) \(.Version)"
    '
)"

test -z "$retracted_or_prerelease"

Repository: openshift-online/rosa-e2e

Length of output: 2052


🏁 Script executed:

#!/usr/bin/env bash
set -euo pipefail

printf '%s\n' '--- module files ---'
git ls-files 'go.mod' 'go.sum' '.github/**' 'Dockerfile*' '*Containerfile*' | sed -n '1,160p'

printf '%s\n' '--- go.mod context ---'
cat -n go.mod | sed -n '1,90p'

printf '%s\n' '--- vulnerable module declarations and sums ---'
rg -n -C 2 'github.com/golang/glog|golang.org/x/text' go.mod go.sum

printf '%s\n' '--- release controls ---'
rg -n -i -C 2 'sbom|provenance|attest|cosign|sigstore|sign(ing|ed)? artifact|osv|govulncheck' .github go.mod go.sum 2>/dev/null || true

printf '%s\n' '--- resolved module metadata with CGO disabled ---'
CGO_ENABLED=0 go list -m -json all 2>/dev/null |
  jq -r 'select(.Path == "github.com/golang/glog" or .Path == "golang.org/x/text" or .Path == "github.com/aws/aws-sdk-go-v2" or .Path == "github.com/aws/smithy-go") |
    [.Path, (.Version // ""), ((.Retracted // []) | tostring)] | `@tsv`' || true

Repository: openshift-online/rosa-e2e

Length of output: 9794


🏁 Script executed:

#!/usr/bin/env bash
set -euo pipefail

printf '%s\n' '--- dependency paths ---'
CGO_ENABLED=0 go mod why -m github.com/golang/glog
CGO_ENABLED=0 go mod why -m golang.org/x/text

printf '%s\n' '--- tracked container and workflow files ---'
for f in Containerfile .github/workflows/branch-protection-check.yml .github/workflows/dependabot-auto-merge.yml .github/dependabot.yml; do
  if test -f "$f"; then
    printf '\n--- %s ---\n' "$f"
    cat -n "$f"
  fi
done

printf '%s\n' '--- changed module entries ---'
git diff -- go.mod | sed -n '1,180p'

Repository: openshift-online/rosa-e2e

Length of output: 16174


🌐 Web query:

OSV GO-2025-3372 github.com/golang/glog v1.0.0 affected versions fixed version

💡 Result:

The vulnerability identified as GO-2025-3372 (also tracked as CVE-2024-45339 and GHSA-6wxm-mpqj-6jpf) affects the github.com/golang/glog package [1][2][3]. Affected Versions: All versions of github.com/golang/glog prior to v1.2.4 are considered affected [4][2]. Fixed Version: The vulnerability was fixed in version v1.2.4 [5][2][3]. Explanation: The vulnerability concerns insecure temporary file usage. When logs are written to a widely-writable directory—which is the default behavior—an unprivileged attacker could predict a privileged process's log file path and create a symbolic link to a sensitive file. If the privileged process follows this link, it could overwrite the sensitive file [5][2]. The fix introduced in v1.2.4 causes the application to exit with status code 2 if it detects that the configured log file already exists [5][2][3].

Citations:


🌐 Web query:

OSV GO-2026-5970 golang.org/x/text v0.38.0 affected versions fixed version

💡 Result:

GO-2026-5970 is a vulnerability in the golang.org/x/text module characterized by an infinite loop that can be triggered when handling invalid UTF-8 byte sequences [1][2]. Affected Versions: The vulnerability affects versions of golang.org/x/text prior to v0.39.0 [2][3]. Fixed Version: The issue is resolved in version v0.39.0 [1][4]. While v0.39.0 is the minimum fixed version, some users have updated to v0.40.0 to address the vulnerability [5][6]. The vulnerability is also tracked as CVE-2026-56852 [7][8]. It specifically impacts the unicode/norm package, with various functions such as Form.Bytes, Form.IsNormal, Form.NextBoundary, and Iter.Next being identified as vulnerable entry points [1][3].

Citations:


🏁 Script executed:

#!/usr/bin/env bash
set -euo pipefail

printf '%s\n' '--- repository imports and logging configuration ---'
rg -n -C 3 'ocm-sdk-go|logging|glog|idna|unicode/norm|LoadDefaultConfig|NewClient' --glob '*.go' .

printf '%s\n' '--- module cache locations ---'
go env GOMODCACHE GOPATH

printf '%s\n' '--- vulnerable package references in cached modules ---'
modcache="$(go env GOMODCACHE)"
rg -n -C 3 'package logging|glog\.|package idna|unicode/norm|norm\.' \
  "$modcache/github.com/openshift-online/ocm-sdk-go"* \
  "$modcache/golang.org/x/net"* \
  "$modcache/golang.org/x/text"* 2>/dev/null | sed -n '1,240p' || true

printf '%s\n' '--- E2E dependency inclusion ---'
CGO_ENABLED=0 go list -tags E2Etests -deps ./test/e2e/... 2>/dev/null |
  rg 'github.com/golang/glog|golang.org/x/text/(secure/bidirule|unicode/norm)|golang.org/x/net/idna' || true

Repository: openshift-online/rosa-e2e

Length of output: 28537


🏁 Script executed:

#!/usr/bin/env bash
set -euo pipefail

printf '%s\n' '--- OCM client construction ---'
rg -n -C 6 'New.*Connection|ConnectionBuilder|Logger|GlogLogger|WithLogger|NewGlogLogger' \
  --glob '*.go' test pkg

printf '%s\n' '--- glog logger implementation and defaults ---'
sed -n '20,180p' /home/jailuser/go/pkg/mod/github.com/openshift-online/ocm-sdk-go@v0.1.507/logging/glog_logger.go
rg -n -C 4 'log_dir|logtostderr|alsologtostderr|stderrthreshold|log_file|Create|OpenFile|Mkdir' \
  /home/jailuser/go/pkg/mod/github.com/golang/glog@v1.0.0 2>/dev/null | sed -n '1,220p'

printf '%s\n' '--- application-controlled host and URL inputs ---'
rg -n -C 4 'AWSRegion|ClusterID|OCM|URL|endpoint|kubeconfig|clientcmd|rest.Config|Host|Server' \
  --glob '*.go' test pkg | sed -n '1,280p'

Repository: openshift-online/rosa-e2e

Length of output: 38137


Known Vulnerable Transitive Dependencies (CWE-1104)

Reachability: Internal · Exploitability: Difficult

Upgrade vulnerable transitive dependencies.

The E2E binary includes github.com/golang/glog v1.0.0 and golang.org/x/text v0.38.0. Upgrade them to v1.2.4 and v0.39.0 or later, then rerun the vulnerability scan. go mod verify checks integrity but does not detect vulnerabilities.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@go.mod` around lines 21 - 33, Upgrade the vulnerable transitive dependencies
used by the E2E binary: set github.com/golang/glog to v1.2.4 or later and
golang.org/x/text to v0.39.0 or later in the module dependency configuration,
then refresh the dependency graph and rerun the vulnerability scan to confirm
the resolved versions.

Source: Path instructions

@github-actions
github-actions Bot merged commit dd0adc5 into main Aug 5, 2026
11 of 12 checks passed
@dependabot
dependabot Bot deleted the dependabot/go_modules/aws-sdk-6adb5debb0 branch August 5, 2026 06:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

approved Indicates a PR has been approved by an approver from all required OWNERS files. area/dependency Issues or PRs related to dependency changes ok-to-test Indicates a non-member PR verified by an org member that is safe to test.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants