Skip to content
This repository was archived by the owner on Mar 16, 2024. It is now read-only.

Commit 924273a

Browse files
fix(deps): update module github.com/sigstore/cosign/v2 to v2.2.1 [security]
1 parent e46d866 commit 924273a

File tree

2 files changed

+264
-263
lines changed

2 files changed

+264
-263
lines changed

go.mod

+64-60
Original file line numberDiff line numberDiff line change
@@ -15,17 +15,17 @@ require (
1515
github.com/acorn-io/schemer v0.0.0-20240105014212-9739d5485208
1616
github.com/acorn-io/z v0.0.0-20230714155009-a770ecbbdc45
1717
github.com/adrg/xdg v0.4.0
18-
github.com/aws/aws-sdk-go-v2 v1.20.0
19-
github.com/aws/aws-sdk-go-v2/config v1.18.32
18+
github.com/aws/aws-sdk-go-v2 v1.21.2
19+
github.com/aws/aws-sdk-go-v2/config v1.19.1
2020
github.com/aws/aws-sdk-go-v2/service/iam v1.19.10
2121
github.com/charmbracelet/glamour v0.6.0
2222
github.com/containerd/console v1.0.3
2323
github.com/containerd/containerd v1.6.20
2424
github.com/denisbrodbeck/machineid v1.0.1
2525
github.com/depot/depot-go v0.0.0-20230819013533-12cec5cbd2f9
26-
github.com/docker/cli v24.0.0+incompatible
27-
github.com/docker/docker v24.0.0+incompatible
28-
github.com/docker/docker-credential-helpers v0.7.0
26+
github.com/docker/cli v24.0.7+incompatible
27+
github.com/docker/docker v24.0.7+incompatible
28+
github.com/docker/docker-credential-helpers v0.8.0
2929
github.com/docker/go-connections v0.4.0
3030
github.com/go-acme/lego/v4 v4.9.1
3131
github.com/go-git/go-git/v5 v5.9.0
@@ -34,32 +34,32 @@ require (
3434
github.com/google/go-containerregistry v0.16.1
3535
github.com/google/go-containerregistry/pkg/authn/kubernetes v0.0.0-20221213180026-23d895d08035
3636
github.com/google/shlex v0.0.0-20191202100458-e7afc7fbc510
37-
github.com/google/uuid v1.3.0
37+
github.com/google/uuid v1.4.0
3838
github.com/gorilla/websocket v1.5.0
3939
github.com/hexops/autogold/v2 v2.2.1
4040
github.com/hexops/valast v1.4.4
4141
github.com/liggitt/tabwriter v0.0.0-20181228230101-89fcab3d43de
4242
github.com/loft-sh/devspace v1.1.1-0.20231020132550-69e7df31933d
4343
github.com/moby/buildkit v0.11.6
4444
github.com/opencontainers/go-digest v1.0.0
45-
github.com/opencontainers/image-spec v1.1.0-rc4
45+
github.com/opencontainers/image-spec v1.1.0-rc5
4646
github.com/pkg/browser v0.0.0-20210911075715-681adbf594b8
4747
github.com/pkg/errors v0.9.1
4848
github.com/pterm/pterm v0.12.49
4949
github.com/robfig/cron/v3 v3.0.1
5050
github.com/secure-systems-lab/go-securesystemslib v0.7.0
51-
github.com/sigstore/cosign/v2 v2.2.0
52-
github.com/sigstore/sigstore v1.7.3
51+
github.com/sigstore/cosign/v2 v2.2.1
52+
github.com/sigstore/sigstore v1.7.5
5353
github.com/sirupsen/logrus v1.9.3
54-
github.com/spf13/cobra v1.7.0
54+
github.com/spf13/cobra v1.8.0
5555
github.com/spf13/pflag v1.0.5
5656
github.com/stretchr/testify v1.8.4
5757
github.com/tonistiigi/fsutil v0.0.0-20230629203738-36ef4d8c0dbb
5858
github.com/wI2L/jsondiff v0.3.0
5959
golang.org/x/crypto v0.16.0
6060
golang.org/x/exp v0.0.0-20240103183307-be819d1f06fc
6161
golang.org/x/sync v0.5.0
62-
google.golang.org/grpc v1.58.3
62+
google.golang.org/grpc v1.59.0
6363
inet.af/tcpproxy v0.0.0-20221017015627-91f861402626
6464
k8s.io/api v0.29.0
6565
k8s.io/apiextensions-apiserver v0.29.0
@@ -80,28 +80,28 @@ require (
8080
atomicgo.dev/cursor v0.1.1 // indirect
8181
atomicgo.dev/keyboard v0.2.8 // indirect
8282
dario.cat/mergo v1.0.0 // indirect
83-
github.com/Azure/go-ansiterm v0.0.0-20210617225240-d185dfc1b5a1 // indirect
83+
github.com/Azure/go-ansiterm v0.0.0-20230124172434-306776ec8161 // indirect
8484
github.com/MakeNowJust/heredoc v1.0.0 // indirect
8585
github.com/Microsoft/go-winio v0.6.1 // indirect
8686
github.com/NYTimes/gziphandler v1.1.1 // indirect
87-
github.com/ProtonMail/go-crypto v0.0.0-20230828082145-3c4c8a2d2371 // indirect
87+
github.com/ProtonMail/go-crypto v0.0.0-20230923063757-afb1ddc0824c // indirect
8888
github.com/ThalesIgnite/crypto11 v1.2.5 // indirect
8989
github.com/acarl005/stripansi v0.0.0-20180116102854-5a71ef0e047d // indirect
9090
github.com/acomagu/bufpipe v1.0.4 // indirect
9191
github.com/acorn-io/cmd v0.0.0-20230929053520-ebe1b9879b38 // indirect
9292
github.com/alecthomas/chroma v0.10.0 // indirect
9393
github.com/antlr/antlr4/runtime/Go/antlr/v4 v4.0.0-20230305170008-8188dc5388df // indirect
9494
github.com/asaskevich/govalidator v0.0.0-20230301143203-a9d515a09cc2 // indirect
95-
github.com/aws/aws-sdk-go-v2/credentials v1.13.31 // indirect
96-
github.com/aws/aws-sdk-go-v2/feature/ec2/imds v1.13.7 // indirect
97-
github.com/aws/aws-sdk-go-v2/internal/configsources v1.1.37 // indirect
98-
github.com/aws/aws-sdk-go-v2/internal/endpoints/v2 v2.4.31 // indirect
99-
github.com/aws/aws-sdk-go-v2/internal/ini v1.3.38 // indirect
100-
github.com/aws/aws-sdk-go-v2/service/internal/presigned-url v1.9.31 // indirect
101-
github.com/aws/aws-sdk-go-v2/service/sso v1.13.1 // indirect
102-
github.com/aws/aws-sdk-go-v2/service/ssooidc v1.15.1 // indirect
103-
github.com/aws/aws-sdk-go-v2/service/sts v1.21.1 // indirect
104-
github.com/aws/smithy-go v1.14.0 // indirect
95+
github.com/aws/aws-sdk-go-v2/credentials v1.13.43 // indirect
96+
github.com/aws/aws-sdk-go-v2/feature/ec2/imds v1.13.13 // indirect
97+
github.com/aws/aws-sdk-go-v2/internal/configsources v1.1.43 // indirect
98+
github.com/aws/aws-sdk-go-v2/internal/endpoints/v2 v2.4.37 // indirect
99+
github.com/aws/aws-sdk-go-v2/internal/ini v1.3.45 // indirect
100+
github.com/aws/aws-sdk-go-v2/service/internal/presigned-url v1.9.37 // indirect
101+
github.com/aws/aws-sdk-go-v2/service/sso v1.15.2 // indirect
102+
github.com/aws/aws-sdk-go-v2/service/ssooidc v1.17.3 // indirect
103+
github.com/aws/aws-sdk-go-v2/service/sts v1.23.2 // indirect
104+
github.com/aws/smithy-go v1.15.0 // indirect
105105
github.com/aymanbagabas/go-osc52 v1.0.3 // indirect
106106
github.com/aymerick/douceur v0.2.0 // indirect
107107
github.com/beorn7/perks v1.0.1 // indirect
@@ -113,20 +113,21 @@ require (
113113
github.com/cenkalti/backoff/v4 v4.2.1 // indirect
114114
github.com/cespare/xxhash/v2 v2.2.0 // indirect
115115
github.com/chai2010/gettext-go v1.0.2 // indirect
116-
github.com/cloudflare/circl v1.3.3 // indirect
116+
github.com/cloudflare/circl v1.3.5 // indirect
117117
github.com/containerd/continuity v0.4.1 // indirect
118118
github.com/containerd/stargz-snapshotter/estargz v0.14.3 // indirect
119119
github.com/containerd/typeurl v1.0.3-0.20220422153119-7f6e6d160d67 // indirect
120120
github.com/coreos/go-semver v0.3.1 // indirect
121121
github.com/coreos/go-systemd/v22 v22.5.0 // indirect
122-
github.com/cpuguy83/go-md2man/v2 v2.0.2 // indirect
123-
github.com/cyberphone/json-canonicalization v0.0.0-20220623050100-57a0ce2678a7 // indirect
122+
github.com/cpuguy83/go-md2man/v2 v2.0.3 // indirect
123+
github.com/cyberphone/json-canonicalization v0.0.0-20231011164504-785e29786b46 // indirect
124124
github.com/cyphar/filepath-securejoin v0.2.4 // indirect
125-
github.com/davecgh/go-spew v1.1.1 // indirect
125+
github.com/davecgh/go-spew v1.1.2-0.20180830191138-d8f796af33cc // indirect
126126
github.com/digitorus/pkcs7 v0.0.0-20230818184609-3a137a874352 // indirect
127-
github.com/digitorus/timestamp v0.0.0-20230821155606-d1ad5ca9624c // indirect
127+
github.com/digitorus/timestamp v0.0.0-20230902153158-687734543647 // indirect
128+
github.com/distribution/reference v0.5.0 // indirect
128129
github.com/dlclark/regexp2 v1.4.0 // indirect
129-
github.com/docker/distribution v2.8.2+incompatible // indirect
130+
github.com/docker/distribution v2.8.3+incompatible // indirect
130131
github.com/docker/go v1.5.1-1.0.20160303222718-d30aec9fd63c // indirect
131132
github.com/docker/go-metrics v0.0.1 // indirect
132133
github.com/docker/go-units v0.5.0 // indirect
@@ -140,7 +141,7 @@ require (
140141
github.com/fsnotify/fsnotify v1.7.0 // indirect
141142
github.com/fujiwara/shapeio v1.0.0 // indirect
142143
github.com/fvbommel/sortorder v1.1.0 // indirect
143-
github.com/gabriel-vasile/mimetype v1.4.2 // indirect
144+
github.com/gabriel-vasile/mimetype v1.4.3 // indirect
144145
github.com/go-chi/chi v4.1.2+incompatible // indirect
145146
github.com/go-errors/errors v1.4.2 // indirect
146147
github.com/go-git/gcfg v1.5.1-0.20230307220236-3a3c6141e376 // indirect
@@ -149,7 +150,7 @@ require (
149150
github.com/go-logr/stdr v1.2.2 // indirect
150151
github.com/go-openapi/analysis v0.21.4 // indirect
151152
github.com/go-openapi/errors v0.20.4 // indirect
152-
github.com/go-openapi/jsonpointer v0.19.6 // indirect
153+
github.com/go-openapi/jsonpointer v0.20.0 // indirect
153154
github.com/go-openapi/jsonreference v0.20.2 // indirect
154155
github.com/go-openapi/loads v0.21.2 // indirect
155156
github.com/go-openapi/runtime v0.26.0 // indirect
@@ -159,7 +160,7 @@ require (
159160
github.com/go-openapi/validate v0.22.1 // indirect
160161
github.com/go-playground/locales v0.14.1 // indirect
161162
github.com/go-playground/universal-translator v0.18.1 // indirect
162-
github.com/go-playground/validator/v10 v10.15.1 // indirect
163+
github.com/go-playground/validator/v10 v10.15.5 // indirect
163164
github.com/gofrs/flock v0.8.1 // indirect
164165
github.com/gogo/googleapis v1.4.1 // indirect
165166
github.com/gogo/protobuf v1.3.2 // indirect
@@ -168,9 +169,9 @@ require (
168169
github.com/golang/snappy v0.0.4 // indirect
169170
github.com/google/btree v1.1.2 // indirect
170171
github.com/google/cel-go v0.17.7 // indirect
171-
github.com/google/certificate-transparency-go v1.1.6 // indirect
172-
github.com/google/gnostic-models v0.6.8 // indirect
173-
github.com/google/go-github/v53 v53.2.0 // indirect
172+
github.com/google/certificate-transparency-go v1.1.7 // indirect
173+
github.com/google/gnostic-models v0.6.9-0.20230804172637-c7be7c783f49 // indirect
174+
github.com/google/go-github/v55 v55.0.0 // indirect
174175
github.com/google/go-querystring v1.1.0 // indirect
175176
github.com/google/gofuzz v1.2.0 // indirect
176177
github.com/gookit/color v1.5.2 // indirect
@@ -179,25 +180,25 @@ require (
179180
github.com/gregjones/httpcache v0.0.0-20180305231024-9cad4c3443a7 // indirect
180181
github.com/grpc-ecosystem/go-grpc-middleware v1.4.0 // indirect
181182
github.com/grpc-ecosystem/go-grpc-prometheus v1.2.1-0.20210315223345-82c243799c99 // indirect
182-
github.com/grpc-ecosystem/grpc-gateway/v2 v2.16.0 // indirect
183+
github.com/grpc-ecosystem/grpc-gateway/v2 v2.18.0 // indirect
183184
github.com/hashicorp/go-cleanhttp v0.5.2 // indirect
184185
github.com/hashicorp/go-retryablehttp v0.7.4 // indirect
185-
github.com/hashicorp/hcl v1.0.0 // indirect
186+
github.com/hashicorp/hcl v1.0.1-vault-5 // indirect
186187
github.com/hexops/gotextdiff v1.0.3 // indirect
187-
github.com/imdario/mergo v0.3.15 // indirect
188+
github.com/imdario/mergo v0.3.16 // indirect
188189
github.com/in-toto/in-toto-golang v0.9.0 // indirect
189190
github.com/inconshreveable/mousetrap v1.1.0 // indirect
190191
github.com/jbenet/go-context v0.0.0-20150711004518-d14ea06fba99 // indirect
191-
github.com/jedisct1/go-minisign v0.0.0-20211028175153-1c139d1cc84b // indirect
192+
github.com/jedisct1/go-minisign v0.0.0-20230811132847-661be99b8267 // indirect
192193
github.com/jessevdk/go-flags v1.5.0 // indirect
193194
github.com/josharian/intern v1.0.0 // indirect
194195
github.com/json-iterator/go v1.1.12 // indirect
195196
github.com/k0kubun/go-ansi v0.0.0-20180517002512-3bf9e2903213 // indirect
196197
github.com/kballard/go-shellquote v0.0.0-20180428030007-95032a82bc51 // indirect
197198
github.com/kevinburke/ssh_config v1.2.0 // indirect
198-
github.com/klauspost/compress v1.16.5 // indirect
199+
github.com/klauspost/compress v1.17.2 // indirect
199200
github.com/leodido/go-urn v1.2.4 // indirect
200-
github.com/letsencrypt/boulder v0.0.0-20221109233200-85aa52084eaf // indirect
201+
github.com/letsencrypt/boulder v0.0.0-20231026200631-000cd05d5491 // indirect
201202
github.com/lithammer/fuzzysearch v1.1.5 // indirect
202203
github.com/loft-sh/notify v0.0.0-20210827094439-0720dcc7feee // indirect
203204
github.com/loft-sh/utils v0.0.16 // indirect
@@ -210,7 +211,7 @@ require (
210211
github.com/matttproud/golang_protobuf_extensions/v2 v2.0.0 // indirect
211212
github.com/mgutz/ansi v0.0.0-20170206155736-9520e82c474b // indirect
212213
github.com/microcosm-cc/bluemonday v1.0.26 // indirect
213-
github.com/miekg/dns v1.1.50 // indirect
214+
github.com/miekg/dns v1.1.55 // indirect
214215
github.com/miekg/pkcs11 v1.1.1 // indirect
215216
github.com/mitchellh/go-homedir v1.1.0 // indirect
216217
github.com/mitchellh/go-wordwrap v1.0.1 // indirect
@@ -236,29 +237,31 @@ require (
236237
github.com/olekukonko/tablewriter v0.0.5 // indirect
237238
github.com/opentracing/opentracing-go v1.2.0 // indirect
238239
github.com/otiai10/copy v1.7.0 // indirect
239-
github.com/pelletier/go-toml/v2 v2.0.8 // indirect
240+
github.com/pelletier/go-toml/v2 v2.1.0 // indirect
240241
github.com/peterbourgon/diskv v2.0.1+incompatible // indirect
241242
github.com/pjbgf/sha1cd v0.3.0 // indirect
242-
github.com/pmezard/go-difflib v1.0.0 // indirect
243+
github.com/pmezard/go-difflib v1.0.1-0.20181226105442-5d4384ee4fb2 // indirect
243244
github.com/prometheus/client_golang v1.18.0 // indirect
244245
github.com/prometheus/client_model v0.5.0 // indirect
245246
github.com/prometheus/common v0.45.0 // indirect
246247
github.com/prometheus/procfs v0.12.0 // indirect
247-
github.com/rivo/uniseg v0.2.0 // indirect
248+
github.com/rivo/uniseg v0.4.4 // indirect
248249
github.com/russross/blackfriday/v2 v2.1.0 // indirect
249250
github.com/sabhiram/go-gitignore v0.0.0-20180611051255-d3107576ba94 // indirect
251+
github.com/sagikazarmark/locafero v0.3.0 // indirect
252+
github.com/sagikazarmark/slog-shim v0.1.0 // indirect
250253
github.com/sassoftware/relic v7.2.1+incompatible // indirect
251254
github.com/sergi/go-diff v1.3.1 // indirect
252255
github.com/shibumi/go-pathspec v1.3.0 // indirect
253-
github.com/sigstore/rekor v1.2.2 // indirect
254-
github.com/sigstore/timestamp-authority v1.1.2 // indirect
256+
github.com/sigstore/rekor v1.3.3 // indirect
257+
github.com/sigstore/timestamp-authority v1.2.0 // indirect
255258
github.com/skeema/knownhosts v1.2.0 // indirect
256-
github.com/spf13/afero v1.9.5 // indirect
259+
github.com/sourcegraph/conc v0.3.0 // indirect
260+
github.com/spf13/afero v1.10.0 // indirect
257261
github.com/spf13/cast v1.5.1 // indirect
258-
github.com/spf13/jwalterweatherman v1.1.0 // indirect
259-
github.com/spf13/viper v1.16.0 // indirect
262+
github.com/spf13/viper v1.17.0 // indirect
260263
github.com/stoewer/go-strcase v1.2.0 // indirect
261-
github.com/subosito/gotenv v1.4.2 // indirect
264+
github.com/subosito/gotenv v1.6.0 // indirect
262265
github.com/syndtr/goleveldb v1.0.1-0.20220721030215-126854af5e6d // indirect
263266
github.com/thales-e-security/pool v0.0.2 // indirect
264267
github.com/theupdateframework/go-tuf v0.6.1 // indirect
@@ -270,8 +273,8 @@ require (
270273
github.com/tonistiigi/units v0.0.0-20180711220420-6950e57a87ea // indirect
271274
github.com/tonistiigi/vt100 v0.0.0-20210615222946-8066bb97264f // indirect
272275
github.com/transparency-dev/merkle v0.0.2 // indirect
273-
github.com/vbatts/tar-split v0.11.3 // indirect
274-
github.com/xanzy/go-gitlab v0.90.0 // indirect
276+
github.com/vbatts/tar-split v0.11.5 // indirect
277+
github.com/xanzy/go-gitlab v0.93.2 // indirect
275278
github.com/xanzy/ssh-agent v0.3.3 // indirect
276279
github.com/xlab/treeprint v1.2.0 // indirect
277280
github.com/xo/terminfo v0.0.0-20210125001918-ca9a967f8778 // indirect
@@ -280,8 +283,8 @@ require (
280283
go.etcd.io/etcd/api/v3 v3.5.10 // indirect
281284
go.etcd.io/etcd/client/pkg/v3 v3.5.10 // indirect
282285
go.etcd.io/etcd/client/v3 v3.5.10 // indirect
283-
go.mongodb.org/mongo-driver v1.11.3 // indirect
284-
go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc v0.42.0 // indirect
286+
go.mongodb.org/mongo-driver v1.12.1 // indirect
287+
go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc v0.45.0 // indirect
285288
go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.44.0 // indirect
286289
go.opentelemetry.io/otel v1.19.0 // indirect
287290
go.opentelemetry.io/otel/exporters/otlp/otlptrace v1.19.0 // indirect
@@ -295,18 +298,19 @@ require (
295298
go.uber.org/zap v1.26.0 // indirect
296299
golang.org/x/mod v0.14.0 // indirect
297300
golang.org/x/net v0.19.0 // indirect
298-
golang.org/x/oauth2 v0.12.0 // indirect
301+
golang.org/x/oauth2 v0.13.0 // indirect
299302
golang.org/x/sys v0.15.0 // indirect
300303
golang.org/x/term v0.15.0 // indirect
301304
golang.org/x/text v0.14.0 // indirect
302305
golang.org/x/time v0.3.0 // indirect
303306
golang.org/x/tools v0.16.0 // indirect
304307
gomodules.xyz/jsonpatch/v2 v2.4.0 // indirect
305-
google.golang.org/appengine v1.6.7 // indirect
306-
google.golang.org/genproto v0.0.0-20230803162519-f966b187b2e5 // indirect
307-
google.golang.org/genproto/googleapis/api v0.0.0-20230803162519-f966b187b2e5 // indirect
308-
google.golang.org/genproto/googleapis/rpc v0.0.0-20230822172742-b8732ec3820d // indirect
308+
google.golang.org/appengine v1.6.8 // indirect
309+
google.golang.org/genproto v0.0.0-20231016165738-49dd2c1f3d0b // indirect
310+
google.golang.org/genproto/googleapis/api v0.0.0-20231016165738-49dd2c1f3d0b // indirect
311+
google.golang.org/genproto/googleapis/rpc v0.0.0-20231016165738-49dd2c1f3d0b // indirect
309312
google.golang.org/protobuf v1.31.0 // indirect
313+
gopkg.in/go-jose/go-jose.v2 v2.6.1 // indirect
310314
gopkg.in/inf.v0 v0.9.1 // indirect
311315
gopkg.in/ini.v1 v1.67.0 // indirect
312316
gopkg.in/natefinch/lumberjack.v2 v2.2.1 // indirect

0 commit comments

Comments
 (0)