skopeo/vendor
Miloslav Trmač 29835bb7ee Update to github.com/mtrmac/gpgme v0.1.2
This fixes CVE-2020-8945 by incorporating proglottis/gpgme#23 .

Other changes included by the rebase:
- Support for gpgme_off_t (~no-op on Linux)
- Wrapping a few more GPGME functions (irrelevant if we don't call them)

Given how invasive the CVE fix is (affecting basically all binding
code), it seems safer to just update the package (and be verifiably
equivalent with upstream) than to backport and try to back out the few
other changes.

Performed by updating vendor conf,
$ vndr github.com/mtrmac/gpgme
and manually backing out unrelated deletions of files.

Signed-off-by: Miloslav Trmač <mitr@redhat.com>
2020-02-21 14:21:04 +01:00
..
github.com Update to github.com/mtrmac/gpgme v0.1.2 2020-02-21 14:21:04 +01:00
go4.org Vendor after merging containers/image#436 2018-04-05 21:33:04 +02:00
golang.org/x Update vendor for skopeo release 2018-09-21 08:49:55 -04:00
gopkg.in vendor.conf,vendor: vndr update for containers/image 2017-02-27 02:15:36 -08:00
k8s.io/client-go Vendor after merging mtrmac/image:docker-archive-auto-compression 2018-07-18 01:02:26 +02:00