Merge pull request #83261 from liggitt/yaml-limits

limit yaml/json decode size

Kubernetes-commit: 4afcba42bed2bb7c36e5209a90d87343f32a0efa
This commit is contained in:
Kubernetes Publisher 2019-10-02 20:28:08 -07:00
parent 8ef9b4517b
commit cc39a16963
3 changed files with 28 additions and 22 deletions

16
Godeps/Godeps.json generated
View File

@ -572,7 +572,7 @@
},
{
"ImportPath": "gopkg.in/yaml.v2",
"Rev": "v2.2.2"
"Rev": "v2.2.4"
},
{
"ImportPath": "gotest.tools",
@ -584,27 +584,27 @@
},
{
"ImportPath": "k8s.io/api",
"Rev": "d58b53da08f5"
"Rev": "10e821c09743"
},
{
"ImportPath": "k8s.io/apimachinery",
"Rev": "62598f38f24e"
"Rev": "c930edf45883"
},
{
"ImportPath": "k8s.io/cli-runtime",
"Rev": "b6110f10831a"
"Rev": "10fd5aad9108"
},
{
"ImportPath": "k8s.io/client-go",
"Rev": "07054768d98d"
"Rev": "a746c2f219b7"
},
{
"ImportPath": "k8s.io/code-generator",
"Rev": "32dfb485ddce"
"Rev": "700b1226c0bd"
},
{
"ImportPath": "k8s.io/component-base",
"Rev": "6dfc4c33e65d"
"Rev": "be468d5d6790"
},
{
"ImportPath": "k8s.io/gengo",
@ -620,7 +620,7 @@
},
{
"ImportPath": "k8s.io/metrics",
"Rev": "4e1cdcf4c305"
"Rev": "c6bb51c85f6a"
},
{
"ImportPath": "k8s.io/utils",

27
go.mod
View File

@ -35,14 +35,14 @@ require (
golang.org/x/sys v0.0.0-20190616124812-15dcb6c0061f
gopkg.in/yaml.v2 v2.2.4
gotest.tools v2.2.0+incompatible // indirect
k8s.io/api v0.0.0
k8s.io/apimachinery v0.0.0
k8s.io/cli-runtime v0.0.0
k8s.io/client-go v0.0.0
k8s.io/component-base v0.0.0
k8s.io/api v0.0.0-20191003035645-10e821c09743
k8s.io/apimachinery v0.0.0-20191003035458-c930edf45883
k8s.io/cli-runtime v0.0.0-20191003041604-10fd5aad9108
k8s.io/client-go v0.0.0-20191003035859-a746c2f219b7
k8s.io/component-base v0.0.0-20191003040350-be468d5d6790
k8s.io/klog v1.0.0
k8s.io/kube-openapi v0.0.0-20190816220812-743ec37842bf
k8s.io/metrics v0.0.0
k8s.io/metrics v0.0.0-20191003041506-c6bb51c85f6a
k8s.io/utils v0.0.0-20190920012459-5008bf6f8cd6
sigs.k8s.io/kustomize v2.0.3+incompatible
sigs.k8s.io/yaml v1.1.0
@ -56,12 +56,11 @@ replace (
golang.org/x/sys => golang.org/x/sys v0.0.0-20190209173611-3b5209105503
golang.org/x/text => golang.org/x/text v0.3.1-0.20181227161524-e6919f6577db
golang.org/x/time => golang.org/x/time v0.0.0-20161028155119-f51c12702a4d
k8s.io/api => ../api
k8s.io/apimachinery => ../apimachinery
k8s.io/cli-runtime => ../cli-runtime
k8s.io/client-go => ../client-go
k8s.io/code-generator => ../code-generator
k8s.io/component-base => ../component-base
k8s.io/kubectl => ../kubectl
k8s.io/metrics => ../metrics
k8s.io/api => k8s.io/api v0.0.0-20191003035645-10e821c09743
k8s.io/apimachinery => k8s.io/apimachinery v0.0.0-20191003035458-c930edf45883
k8s.io/cli-runtime => k8s.io/cli-runtime v0.0.0-20191003041604-10fd5aad9108
k8s.io/client-go => k8s.io/client-go v0.0.0-20191003035859-a746c2f219b7
k8s.io/code-generator => k8s.io/code-generator v0.0.0-20191003035328-700b1226c0bd
k8s.io/component-base => k8s.io/component-base v0.0.0-20191003040350-be468d5d6790
k8s.io/metrics => k8s.io/metrics v0.0.0-20191003041506-c6bb51c85f6a
)

7
go.sum
View File

@ -290,6 +290,12 @@ gotest.tools v2.2.0+incompatible h1:VsBPFP1AI068pPrMxtb/S8Zkgf9xEmTLJjfM+P5UIEo=
gotest.tools v2.2.0+incompatible/go.mod h1:DsYFclhRJ6vuDpmuTbkuFWG+y2sxOXAzmJt81HFBacw=
honnef.co/go/tools v0.0.0-20190102054323-c2f93a96b099/go.mod h1:rf3lG4BRIbNafJWhAfAdb/ePZxsR/4RtNHQocxwk9r4=
honnef.co/go/tools v0.0.0-20190106161140-3f1c8253044a/go.mod h1:rf3lG4BRIbNafJWhAfAdb/ePZxsR/4RtNHQocxwk9r4=
k8s.io/api v0.0.0-20191003035645-10e821c09743/go.mod h1:uO3sqSrudYAYLDvkW5ph6lZtwlcN7mUlfE80fNPY8EE=
k8s.io/apimachinery v0.0.0-20191003035458-c930edf45883/go.mod h1:3rOMKKJmoWw7dJkRxGjW26hYSWvYV5nrieoTsmWq1jw=
k8s.io/cli-runtime v0.0.0-20191003041604-10fd5aad9108/go.mod h1:OSUtt+ONh4/GRMqj5NIVS5pF+NB9M493k8d1qjcllK8=
k8s.io/client-go v0.0.0-20191003035859-a746c2f219b7/go.mod h1:6LOleLJHIuJ9sIFNLPjRLTsWNYHk6MyS9VawVsBRe4g=
k8s.io/code-generator v0.0.0-20191003035328-700b1226c0bd/go.mod h1:HC9p4y3SBN+txSs8x57qmNPXFZ/CxdCHiDTNnocCSEw=
k8s.io/component-base v0.0.0-20191003040350-be468d5d6790/go.mod h1:9mA4uQCNQ0qIetCGWbprquCMokZ5N5FDKDtftfE8bXU=
k8s.io/gengo v0.0.0-20190128074634-0689ccc1d7d6/go.mod h1:ezvh/TsK7cY6rbqRK0oQQ8IAqLxYwwyPxAX1Pzy0ii0=
k8s.io/gengo v0.0.0-20190822140433-26a664648505/go.mod h1:ezvh/TsK7cY6rbqRK0oQQ8IAqLxYwwyPxAX1Pzy0ii0=
k8s.io/klog v0.0.0-20181102134211-b9b56d5dfc92/go.mod h1:Gq+BEi5rUBO/HRz0bTSXDUcqjScdoY3a9IHpCEIOOfk=
@ -298,6 +304,7 @@ k8s.io/klog v1.0.0 h1:Pt+yjF5aB1xDSVbau4VsWe+dQNzA0qv1LlXdC2dF6Q8=
k8s.io/klog v1.0.0/go.mod h1:4Bi6QPql/J/LkTDqv7R/cd3hPo4k2DG6Ptcz060Ez5I=
k8s.io/kube-openapi v0.0.0-20190816220812-743ec37842bf h1:EYm5AW/UUDbnmnI+gK0TJDVK9qPLhM+sRHYanNKw0EQ=
k8s.io/kube-openapi v0.0.0-20190816220812-743ec37842bf/go.mod h1:1TqjTSzOxsLGIKfj0lK8EeCP7K1iUG65v09OM0/WG5E=
k8s.io/metrics v0.0.0-20191003041506-c6bb51c85f6a/go.mod h1:Sx9P91jBh/PwrWOVpIuV82hIXUY4Pw30BzMefJ3XbRc=
k8s.io/utils v0.0.0-20190920012459-5008bf6f8cd6 h1:rfepARh/ECp66dk9TTmT//1PBkHffjnxhdOrgH4m+eA=
k8s.io/utils v0.0.0-20190920012459-5008bf6f8cd6/go.mod h1:sZAwmy6armz5eXlNoLmJcl4F1QuKu7sr+mFQ0byX7Ew=
modernc.org/cc v1.0.0/go.mod h1:1Sk4//wdnYJiUIxnW8ddKpaOJCF37yAdqYnkxUpaYxw=