fleet/ee/fleetctl
Lucas Manuel Rodriguez 832b29f8c7
Update go-tuf to v0.5.0 (bis) (#8112)
* Update go-tuf to v0.5.0

This was triggered by the security advisory
[GHSA-3633-5h82-39pq](https://github.com/theupdateframework/go-tuf/security/advisories/GHSA-3633-5h82-39pq).
Fleet's use of go-tuf is not vulnerable to this issue due to not using
key thresholds greater than 1.

There were some API changes that necessitate changing the initialization
code for the TUF client. See
https://github.com/theupdateframework/go-tuf/issues/379 for further
discussion.

* Add changes file

* Update default root metadata

* Add review changes to update-go-tuf branch

* Update tests

* Add more checks to roots output

Co-authored-by: Zach Wasserman <zach@fleetdm.com>
2022-10-07 17:03:39 -03:00
..
updates_test.go Update go-tuf to v0.5.0 (bis) (#8112) 2022-10-07 17:03:39 -03:00
updates_windows.go Fix missing import on Windows (#3035) 2021-11-18 18:37:29 -08:00
updates.go Update go-tuf to v0.5.0 (bis) (#8112) 2022-10-07 17:03:39 -03:00