4
4
5
5
require (
6
6
github.com/Azure/azure-sdk-for-go v68.0.0+incompatible
7
- github.com/Azure/azure-sdk-for-go/sdk/azcore v1.17 .0
8
- github.com/Azure/azure-sdk-for-go/sdk/azidentity v1.8.2
9
- github.com/BurntSushi/toml v1.4 .0
7
+ github.com/Azure/azure-sdk-for-go/sdk/azcore v1.18 .0
8
+ github.com/Azure/azure-sdk-for-go/sdk/azidentity v1.9.0
9
+ github.com/BurntSushi/toml v1.5 .0
10
10
github.com/CycloneDX/cyclonedx-go v0.9.2
11
11
github.com/GoogleCloudPlatform/docker-credential-gcr v2.0.5+incompatible
12
12
github.com/Masterminds/sprig/v3 v3.3.0
@@ -29,11 +29,11 @@ require (
29
29
github.com/aquasecurity/trivy-java-db v0.0.0-20240109071736-184bd7481d48
30
30
github.com/aquasecurity/trivy-kubernetes v0.8.1
31
31
github.com/aws/aws-sdk-go-v2 v1.36.3
32
- github.com/aws/aws-sdk-go-v2/config v1.29.13
33
- github.com/aws/aws-sdk-go-v2/credentials v1.17.66
34
- github.com/aws/aws-sdk-go-v2/service/ec2 v1.211.2
35
- github.com/aws/aws-sdk-go-v2/service/ecr v1.43.2
36
- github.com/aws/aws-sdk-go-v2/service/s3 v1.79.1
32
+ github.com/aws/aws-sdk-go-v2/config v1.29.14
33
+ github.com/aws/aws-sdk-go-v2/credentials v1.17.67
34
+ github.com/aws/aws-sdk-go-v2/service/ec2 v1.211.3
35
+ github.com/aws/aws-sdk-go-v2/service/ecr v1.43.3
36
+ github.com/aws/aws-sdk-go-v2/service/s3 v1.79.2
37
37
github.com/aws/smithy-go v1.22.3
38
38
github.com/bitnami/go-version v0.0.0-20231130084017-bb00604d650c
39
39
github.com/bmatcuk/doublestar/v4 v4.8.1
@@ -47,12 +47,12 @@ require (
47
47
github.com/docker/go-connections v0.5.0
48
48
github.com/docker/go-units v0.5.0
49
49
github.com/fatih/color v1.18.0
50
- github.com/go-git/go-git/v5 v5.14 .0
50
+ github.com/go-git/go-git/v5 v5.15 .0
51
51
github.com/go-json-experiment/json v0.0.0-20250223041408-d3c622f1b874 // Replace with encoding/json/v2 when proposal is accepted. Track https://github.com/golang/go/issues/71497
52
52
github.com/go-openapi/runtime v0.28.0 // indirect
53
53
github.com/go-openapi/strfmt v0.23.0 // indirect
54
54
github.com/go-redis/redis/v8 v8.11.5
55
- github.com/gocsaf/csaf/v3 v3.1.1
55
+ github.com/gocsaf/csaf/v3 v3.2.0
56
56
github.com/golang-jwt/jwt/v5 v5.2.2
57
57
github.com/google/go-containerregistry v0.20.3
58
58
github.com/google/go-github/v62 v62.0.0
@@ -65,9 +65,9 @@ require (
65
65
github.com/hashicorp/go-uuid v1.0.3
66
66
github.com/hashicorp/go-version v1.7.0
67
67
github.com/hashicorp/golang-lru/v2 v2.0.7
68
- github.com/hashicorp/hc-install v0.9.1
68
+ github.com/hashicorp/hc-install v0.9.2
69
69
github.com/hashicorp/hcl/v2 v2.23.0
70
- github.com/hashicorp/terraform-exec v0.22 .0
70
+ github.com/hashicorp/terraform-exec v0.23 .0
71
71
github.com/in-toto/in-toto-golang v0.9.0
72
72
github.com/knqyf263/go-apk-version v0.0.0-20200609155635-041fdbb8563f
73
73
github.com/knqyf263/go-deb-version v0.0.0-20241115132648-6f4aee6ccd23
@@ -88,7 +88,7 @@ require (
88
88
github.com/mitchellh/hashstructure/v2 v2.0.2
89
89
github.com/mitchellh/mapstructure v1.5.0
90
90
github.com/moby/buildkit v0.18.2
91
- github.com/open-policy-agent/opa v1.2 .0
91
+ github.com/open-policy-agent/opa v1.3 .0
92
92
github.com/opencontainers/go-digest v1.0.0
93
93
github.com/opencontainers/image-spec v1.1.1
94
94
github.com/openvex/discovery v0.1.1-0.20240802171711-7c54efc57553
@@ -101,14 +101,14 @@ require (
101
101
github.com/samber/lo v1.49.1
102
102
github.com/sassoftware/go-rpmutils v0.4.0
103
103
github.com/secure-systems-lab/go-securesystemslib v0.9.0
104
- github.com/sigstore/rekor v1.3.9
104
+ github.com/sigstore/rekor v1.3.10
105
105
github.com/sirupsen/logrus v1.9.3
106
106
github.com/sosedoff/gitkit v0.4.0
107
107
github.com/spdx/tools-golang v0.5.5 // v0.5.3 with necessary changes. Can be upgraded to version 0.5.4 after release.
108
108
github.com/spf13/cast v1.7.1
109
109
github.com/spf13/cobra v1.9.1
110
110
github.com/spf13/pflag v1.0.6
111
- github.com/spf13/viper v1.20.0
111
+ github.com/spf13/viper v1.20.1
112
112
github.com/stretchr/testify v1.10.0
113
113
github.com/testcontainers/testcontainers-go v0.36.0
114
114
github.com/testcontainers/testcontainers-go/modules/localstack v0.36.0
@@ -119,49 +119,49 @@ require (
119
119
github.com/zclconf/go-cty v1.16.2
120
120
github.com/zclconf/go-cty-yaml v1.1.0
121
121
go.etcd.io/bbolt v1.4.0
122
- golang.org/x/crypto v0.36 .0
123
- golang.org/x/exp v0.0.0-20250106191152-7588d65b2ba8 // indirect
122
+ golang.org/x/crypto v0.37 .0
123
+ golang.org/x/exp v0.0.0-20250305212735-054e65f0b394 // indirect
124
124
golang.org/x/mod v0.24.0
125
- golang.org/x/net v0.37 .0
126
- golang.org/x/sync v0.12 .0
127
- golang.org/x/term v0.30 .0
128
- golang.org/x/text v0.23 .0
125
+ golang.org/x/net v0.39 .0
126
+ golang.org/x/sync v0.13 .0
127
+ golang.org/x/term v0.31 .0
128
+ golang.org/x/text v0.24 .0
129
129
golang.org/x/vuln v1.1.4
130
130
golang.org/x/xerrors v0.0.0-20240716161551-93cc26a95ae9
131
- google.golang.org/protobuf v1.36.5
131
+ google.golang.org/protobuf v1.36.6
132
132
gopkg.in/yaml.v3 v3.0.1
133
- helm.sh/helm/v3 v3.17.2
133
+ helm.sh/helm/v3 v3.17.3
134
134
k8s.io/api v0.32.3
135
135
k8s.io/utils v0.0.0-20241104100929-3ea5e8cea738
136
- modernc.org/sqlite v1.36.1
136
+ modernc.org/sqlite v1.37.0
137
137
sigs.k8s.io/yaml v1.4.0 // indirect
138
138
)
139
139
140
140
require (
141
- cel.dev/expr v0.19.0 // indirect
142
- cloud.google.com/go v0.116.0 // indirect
143
- cloud.google.com/go/auth v0.14 .0 // indirect
144
- cloud.google.com/go/auth/oauth2adapt v0.2.7 // indirect
141
+ cel.dev/expr v0.19.1 // indirect
142
+ cloud.google.com/go v0.118.3 // indirect
143
+ cloud.google.com/go/auth v0.15 .0 // indirect
144
+ cloud.google.com/go/auth/oauth2adapt v0.2.8 // indirect
145
145
cloud.google.com/go/compute/metadata v0.6.0 // indirect
146
- cloud.google.com/go/iam v1.2.2 // indirect
147
- cloud.google.com/go/monitoring v1.21.2 // indirect
148
- cloud.google.com/go/storage v1.49 .0 // indirect
146
+ cloud.google.com/go/iam v1.4.1 // indirect
147
+ cloud.google.com/go/monitoring v1.24.0 // indirect
148
+ cloud.google.com/go/storage v1.50 .0 // indirect
149
149
dario.cat/mergo v1.0.1 // indirect
150
150
github.com/AdaLogics/go-fuzz-headers v0.0.0-20240806141605-e8a1dd7889d6 // indirect
151
151
github.com/AdamKorcz/go-118-fuzz-build v0.0.0-20231105174938-2b5cbb29f3e2 // indirect
152
- github.com/Azure/azure-sdk-for-go/sdk/internal v1.10.0 // indirect
152
+ github.com/Azure/azure-sdk-for-go/sdk/internal v1.11.1 // indirect
153
153
github.com/Azure/go-ansiterm v0.0.0-20230124172434-306776ec8161 // indirect
154
154
github.com/Azure/go-autorest v14.2.0+incompatible // indirect
155
155
github.com/Azure/go-autorest/autorest v0.11.29 // indirect
156
156
github.com/Azure/go-autorest/autorest/adal v0.9.23 // indirect
157
157
github.com/Azure/go-autorest/autorest/date v0.3.0 // indirect
158
158
github.com/Azure/go-autorest/logger v0.2.1 // indirect
159
159
github.com/Azure/go-autorest/tracing v0.6.0 // indirect
160
- github.com/AzureAD/microsoft-authentication-library-for-go v1.3.3 // indirect
160
+ github.com/AzureAD/microsoft-authentication-library-for-go v1.4.2 // indirect
161
161
github.com/DataDog/zstd v1.5.5 // indirect
162
162
github.com/GoogleCloudPlatform/opentelemetry-operations-go/detectors/gcp v1.25.0 // indirect
163
- github.com/GoogleCloudPlatform/opentelemetry-operations-go/exporter/metric v0.48.1 // indirect
164
- github.com/GoogleCloudPlatform/opentelemetry-operations-go/internal/resourcemapping v0.48.1 // indirect
163
+ github.com/GoogleCloudPlatform/opentelemetry-operations-go/exporter/metric v0.49.0 // indirect
164
+ github.com/GoogleCloudPlatform/opentelemetry-operations-go/internal/resourcemapping v0.49.0 // indirect
165
165
github.com/Intevation/gval v1.3.0 // indirect
166
166
github.com/Intevation/jsonpath v0.2.1 // indirect
167
167
github.com/MakeNowJust/heredoc v1.0.0 // indirect
@@ -170,7 +170,7 @@ require (
170
170
github.com/Masterminds/squirrel v1.5.4 // indirect
171
171
github.com/Microsoft/go-winio v0.6.2 // indirect
172
172
github.com/Microsoft/hcsshim v0.12.9 // indirect
173
- github.com/ProtonMail/go-crypto v1.1.5 // indirect
173
+ github.com/ProtonMail/go-crypto v1.1.6 // indirect
174
174
github.com/VividCortex/ewma v1.2.0 // indirect
175
175
github.com/agext/levenshtein v1.2.3 // indirect
176
176
github.com/agnivade/levenshtein v1.2.1 // indirect
@@ -183,11 +183,10 @@ require (
183
183
github.com/blang/semver v3.5.1+incompatible // indirect
184
184
github.com/blang/semver/v4 v4.0.0 // indirect
185
185
github.com/briandowns/spinner v1.23.0 // indirect
186
- github.com/census-instrumentation/opencensus-proto v0.4.1 // indirect
187
186
github.com/cespare/xxhash/v2 v2.3.0 // indirect
188
187
github.com/chai2010/gettext-go v1.0.2 // indirect
189
- github.com/cloudflare/circl v1.6.0 // indirect
190
- github.com/cncf/xds/go v0.0.0-20240905190251-b4127c9b8d78 // indirect
188
+ github.com/cloudflare/circl v1.6.1 // indirect
189
+ github.com/cncf/xds/go v0.0.0-20241223141626-cff3c89139a3 // indirect
191
190
github.com/containerd/cgroups/v3 v3.0.3 // indirect
192
191
github.com/containerd/containerd v1.7.27 // indirect
193
192
github.com/containerd/containerd/api v1.8.0 // indirect
@@ -217,8 +216,7 @@ require (
217
216
github.com/dustin/go-humanize v1.0.1 // indirect
218
217
github.com/emicklei/go-restful/v3 v3.11.0 // indirect
219
218
github.com/emirpasic/gods v1.18.1 // indirect
220
- github.com/envoyproxy/go-control-plane v0.13.1 // indirect
221
- github.com/envoyproxy/protoc-gen-validate v1.1.0 // indirect
219
+ github.com/envoyproxy/protoc-gen-validate v1.2.1 // indirect
222
220
github.com/evanphx/json-patch v5.9.0+incompatible // indirect
223
221
github.com/exponent-io/jsonpath v0.0.0-20210407135951-1de76d718b3f // indirect
224
222
github.com/felixge/httpsnoop v1.0.4 // indirect
@@ -235,12 +233,12 @@ require (
235
233
github.com/go-logr/stdr v1.2.2 // indirect
236
234
github.com/go-ole/go-ole v1.3.0 // indirect
237
235
github.com/go-openapi/analysis v0.23.0 // indirect
238
- github.com/go-openapi/errors v0.22.0 // indirect
236
+ github.com/go-openapi/errors v0.22.1 // indirect
239
237
github.com/go-openapi/jsonpointer v0.21.0 // indirect
240
238
github.com/go-openapi/jsonreference v0.21.0 // indirect
241
239
github.com/go-openapi/loads v0.22.0 // indirect
242
240
github.com/go-openapi/spec v0.21.0 // indirect
243
- github.com/go-openapi/swag v0.23.0 // indirect
241
+ github.com/go-openapi/swag v0.23.1 // indirect
244
242
github.com/go-openapi/validate v0.24.0 // indirect
245
243
github.com/gobwas/glob v0.2.3 // indirect
246
244
github.com/goccy/go-yaml v1.15.23 // indirect
@@ -258,7 +256,7 @@ require (
258
256
github.com/google/gofuzz v1.2.0 // indirect
259
257
github.com/google/s2a-go v0.1.9 // indirect
260
258
github.com/google/shlex v0.0.0-20191202100458-e7afc7fbc510 // indirect
261
- github.com/googleapis/enterprise-certificate-proxy v0.3.4 // indirect
259
+ github.com/googleapis/enterprise-certificate-proxy v0.3.6 // indirect
262
260
github.com/googleapis/gax-go/v2 v2.14.1 // indirect
263
261
github.com/gorilla/mux v1.8.1 // indirect
264
262
github.com/gorilla/websocket v1.5.0 // indirect
@@ -278,7 +276,7 @@ require (
278
276
github.com/josharian/intern v1.0.0 // indirect
279
277
github.com/json-iterator/go v1.1.12 // indirect
280
278
github.com/kevinburke/ssh_config v1.2.0 // indirect
281
- github.com/klauspost/compress v1.17.11 // indirect
279
+ github.com/klauspost/compress v1.18.0 // indirect
282
280
github.com/lann/builder v0.0.0-20180802200727-47ae307949d0 // indirect
283
281
github.com/lann/ps v0.0.0-20150810152359-62de8c46ede0 // indirect
284
282
github.com/letsencrypt/boulder v0.0.0-20240620165639-de9c06129bec // indirect
@@ -287,7 +285,7 @@ require (
287
285
github.com/lufia/plan9stats v0.0.0-20240226150601-1dcf7310316a // indirect
288
286
github.com/lunixbochs/struc v0.0.0-20200707160740-784aaebc1d40 // indirect
289
287
github.com/magiconair/properties v1.8.9 // indirect
290
- github.com/mailru/easyjson v0.7.7 // indirect
288
+ github.com/mailru/easyjson v0.9.0 // indirect
291
289
github.com/mattn/go-colorable v0.1.14 // indirect
292
290
github.com/mattn/go-isatty v0.0.20 // indirect
293
291
github.com/mattn/go-runewidth v0.0.16 // indirect
@@ -325,7 +323,7 @@ require (
325
323
github.com/planetscale/vtprotobuf v0.6.1-0.20240319094008-0393e58bdf10 // indirect
326
324
github.com/pmezard/go-difflib v1.0.1-0.20181226105442-5d4384ee4fb2 // indirect
327
325
github.com/power-devops/perfstat v0.0.0-20240221224432-82ca36839d55 // indirect
328
- github.com/prometheus/client_golang v1.21.0 // indirect
326
+ github.com/prometheus/client_golang v1.21.1 // indirect
329
327
github.com/prometheus/client_model v0.6.1 // indirect
330
328
github.com/prometheus/common v0.62.0 // indirect
331
329
github.com/prometheus/procfs v0.15.1 // indirect
@@ -341,7 +339,7 @@ require (
341
339
github.com/shibumi/go-pathspec v1.3.0 // indirect
342
340
github.com/shopspring/decimal v1.4.0 // indirect
343
341
github.com/sigstore/cosign/v2 v2.2.4 // indirect
344
- github.com/sigstore/sigstore v1.8.12 // indirect
342
+ github.com/sigstore/sigstore v1.9.1 // indirect
345
343
github.com/sigstore/timestamp-authority v1.2.2 // indirect
346
344
github.com/skeema/knownhosts v1.3.1 // indirect
347
345
github.com/sourcegraph/conc v0.3.0 // indirect
@@ -371,26 +369,26 @@ require (
371
369
go.mongodb.org/mongo-driver v1.14.0 // indirect
372
370
go.opencensus.io v0.24.0 // indirect
373
371
go.opentelemetry.io/auto/sdk v1.1.0 // indirect
374
- go.opentelemetry.io/contrib/detectors/gcp v1.32 .0 // indirect
375
- go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc v0.56 .0 // indirect
376
- go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.59 .0 // indirect
372
+ go.opentelemetry.io/contrib/detectors/gcp v1.34 .0 // indirect
373
+ go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc v0.59 .0 // indirect
374
+ go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.60 .0 // indirect
377
375
go.opentelemetry.io/otel v1.35.0 // indirect
378
376
go.opentelemetry.io/otel/metric v1.35.0 // indirect
379
- go.opentelemetry.io/otel/sdk v1.34 .0 // indirect
380
- go.opentelemetry.io/otel/sdk/metric v1.32 .0 // indirect
377
+ go.opentelemetry.io/otel/sdk v1.35 .0 // indirect
378
+ go.opentelemetry.io/otel/sdk/metric v1.35 .0 // indirect
381
379
go.opentelemetry.io/otel/trace v1.35.0 // indirect
382
380
go.uber.org/multierr v1.11.0 // indirect
383
381
go.uber.org/zap v1.27.0 // indirect
384
- golang.org/x/oauth2 v0.26 .0 // indirect
385
- golang.org/x/sys v0.31 .0 // indirect
382
+ golang.org/x/oauth2 v0.28 .0 // indirect
383
+ golang.org/x/sys v0.32 .0 // indirect
386
384
golang.org/x/telemetry v0.0.0-20240522233618-39ace7a40ae7 // indirect
387
- golang.org/x/time v0.10 .0 // indirect
388
- golang.org/x/tools v0.29 .0 // indirect
389
- google.golang.org/api v0.218 .0 // indirect
390
- google.golang.org/genproto v0.0.0-20241118233622-e639e219e697 // indirect
391
- google.golang.org/genproto/googleapis/api v0.0.0-20250115164207-1a7da9e5054f // indirect
392
- google.golang.org/genproto/googleapis/rpc v0.0.0-20250115164207-1a7da9e5054f // indirect
393
- google.golang.org/grpc v1.70 .0 // indirect
385
+ golang.org/x/time v0.11 .0 // indirect
386
+ golang.org/x/tools v0.31 .0 // indirect
387
+ google.golang.org/api v0.228 .0 // indirect
388
+ google.golang.org/genproto v0.0.0-20250303144028-a0af3efb3deb // indirect
389
+ google.golang.org/genproto/googleapis/api v0.0.0-20250303144028-a0af3efb3deb // indirect
390
+ google.golang.org/genproto/googleapis/rpc v0.0.0-20250313205543-e70fdf4c4cb4 // indirect
391
+ google.golang.org/grpc v1.71 .0 // indirect
394
392
gopkg.in/cheggaaa/pb.v1 v1.0.28 // indirect
395
393
gopkg.in/evanphx/json-patch.v4 v4.12.0 // indirect
396
394
gopkg.in/inf.v0 v0.9.1 // indirect
@@ -404,9 +402,9 @@ require (
404
402
k8s.io/klog/v2 v2.130.1 // indirect
405
403
k8s.io/kube-openapi v0.0.0-20241105132330-32ad38e42d3f // indirect
406
404
k8s.io/kubectl v0.32.3 // indirect
407
- modernc.org/libc v1.61.13 // indirect
405
+ modernc.org/libc v1.62.1 // indirect
408
406
modernc.org/mathutil v1.7.1 // indirect
409
- modernc.org/memory v1.8.2 // indirect
407
+ modernc.org/memory v1.9.1 // indirect
410
408
mvdan.cc/sh/v3 v3.11.0 // indirect
411
409
oras.land/oras-go v1.2.5 // indirect
412
410
sigs.k8s.io/json v0.0.0-20241010143419-9aa6b5e7a4b3 // indirect
@@ -427,8 +425,9 @@ require (
427
425
github.com/aws/aws-sdk-go-v2/service/internal/presigned-url v1.12.15 // indirect
428
426
github.com/aws/aws-sdk-go-v2/service/sso v1.25.3 // indirect
429
427
github.com/aws/aws-sdk-go-v2/service/ssooidc v1.30.1 // indirect
430
- github.com/aws/aws-sdk-go-v2/service/sts v1.33.18 // indirect
428
+ github.com/aws/aws-sdk-go-v2/service/sts v1.33.19 // indirect
431
429
github.com/ebitengine/purego v0.8.2 // indirect
430
+ github.com/envoyproxy/go-control-plane/envoy v1.32.4 // indirect
432
431
github.com/evanphx/json-patch/v5 v5.6.0 // indirect
433
432
github.com/go-viper/mapstructure/v2 v2.2.1 // indirect
434
433
github.com/google/go-github/v31 v31.0.0 // indirect
@@ -439,6 +438,7 @@ require (
439
438
github.com/pelletier/go-toml v1.9.5 // indirect
440
439
github.com/samber/oops v1.15.0 // indirect
441
440
github.com/shirou/gopsutil/v4 v4.25.1 // indirect
441
+ github.com/sigstore/protobuf-specs v0.4.1 // indirect
442
442
github.com/tonglil/versioning v0.0.0-20170205083536-8b2a4334bd1d // indirect
443
443
gopkg.in/yaml.v2 v2.4.0 // indirect
444
444
sigs.k8s.io/kind v0.19.0 // indirect
0 commit comments