@@ -9,7 +9,7 @@ require (
99 github.com/owenrumney/go-sarif v1.1.1
1010 github.com/secure-systems-lab/go-securesystemslib v0.9.1
1111 github.com/sigstore/cosign/v2 v2.6.1
12- github.com/sigstore/rekor v1.4.2
12+ github.com/sigstore/rekor v1.4.3
1313 github.com/sigstore/sigstore v1.9.6-0.20250729224751-181c5d3339b3
1414 github.com/sirupsen/logrus v1.9.3
1515 github.com/spf13/cobra v1.10.1
@@ -19,10 +19,10 @@ require (
1919require (
2020 cel.dev/expr v0.24.0 // indirect
2121 cloud.google.com/go v0.121.6 // indirect
22- cloud.google.com/go/auth v0.16.5 // indirect
22+ cloud.google.com/go/auth v0.17.0 // indirect
2323 cloud.google.com/go/auth/oauth2adapt v0.2.8 // indirect
24- cloud.google.com/go/compute/metadata v0.8 .0 // indirect
25- cloud.google.com/go/iam v1.5.2 // indirect
24+ cloud.google.com/go/compute/metadata v0.9 .0 // indirect
25+ cloud.google.com/go/iam v1.5.3 // indirect
2626 cloud.google.com/go/longrunning v0.6.7 // indirect
2727 cloud.google.com/go/monitoring v1.24.2 // indirect
2828 cloud.google.com/go/spanner v1.84.1 // indirect
@@ -56,21 +56,21 @@ require (
5656 github.com/alibabacloud-go/tea-xml v1.1.3 // indirect
5757 github.com/aliyun/credentials-go v1.3.2 // indirect
5858 github.com/asaskevich/govalidator v0.0.0-20230301143203-a9d515a09cc2 // indirect
59- github.com/aws/aws-sdk-go-v2 v1.38.1 // indirect
60- github.com/aws/aws-sdk-go-v2/config v1.31.3 // indirect
61- github.com/aws/aws-sdk-go-v2/credentials v1.18.7 // indirect
62- github.com/aws/aws-sdk-go-v2/feature/ec2/imds v1.18.4 // indirect
63- github.com/aws/aws-sdk-go-v2/internal/configsources v1.4.4 // indirect
64- github.com/aws/aws-sdk-go-v2/internal/endpoints/v2 v2.7.4 // indirect
65- github.com/aws/aws-sdk-go-v2/internal/ini v1.8.3 // indirect
59+ github.com/aws/aws-sdk-go-v2 v1.39.5 // indirect
60+ github.com/aws/aws-sdk-go-v2/config v1.31.16 // indirect
61+ github.com/aws/aws-sdk-go-v2/credentials v1.18.20 // indirect
62+ github.com/aws/aws-sdk-go-v2/feature/ec2/imds v1.18.12 // indirect
63+ github.com/aws/aws-sdk-go-v2/internal/configsources v1.4.12 // indirect
64+ github.com/aws/aws-sdk-go-v2/internal/endpoints/v2 v2.7.12 // indirect
65+ github.com/aws/aws-sdk-go-v2/internal/ini v1.8.4 // indirect
6666 github.com/aws/aws-sdk-go-v2/service/ecr v1.45.1 // indirect
6767 github.com/aws/aws-sdk-go-v2/service/ecrpublic v1.33.2 // indirect
68- github.com/aws/aws-sdk-go-v2/service/internal/accept-encoding v1.13.0 // indirect
69- github.com/aws/aws-sdk-go-v2/service/internal/presigned-url v1.13.4 // indirect
70- github.com/aws/aws-sdk-go-v2/service/sso v1.28.2 // indirect
71- github.com/aws/aws-sdk-go-v2/service/ssooidc v1.34.0 // indirect
72- github.com/aws/aws-sdk-go-v2/service/sts v1.38 .0 // indirect
73- github.com/aws/smithy-go v1.22.5 // indirect
68+ github.com/aws/aws-sdk-go-v2/service/internal/accept-encoding v1.13.2 // indirect
69+ github.com/aws/aws-sdk-go-v2/service/internal/presigned-url v1.13.12 // indirect
70+ github.com/aws/aws-sdk-go-v2/service/sso v1.30.0 // indirect
71+ github.com/aws/aws-sdk-go-v2/service/ssooidc v1.35.4 // indirect
72+ github.com/aws/aws-sdk-go-v2/service/sts v1.39 .0 // indirect
73+ github.com/aws/smithy-go v1.23.1 // indirect
7474 github.com/awslabs/amazon-ecr-credential-helper/ecr-login v0.10.1 // indirect
7575 github.com/blang/semver v3.5.1+incompatible // indirect
7676 github.com/blang/semver/v4 v4.0.0 // indirect
@@ -106,27 +106,27 @@ require (
106106 github.com/go-jose/go-jose/v4 v4.1.2 // indirect
107107 github.com/go-logr/logr v1.4.3 // indirect
108108 github.com/go-logr/stdr v1.2.2 // indirect
109- github.com/go-openapi/analysis v0.23.0 // indirect
110- github.com/go-openapi/errors v0.22.2 // indirect
111- github.com/go-openapi/jsonpointer v0.21.0 // indirect
112- github.com/go-openapi/jsonreference v0.21.0 // indirect
113- github.com/go-openapi/loads v0.22.0 // indirect
114- github.com/go-openapi/runtime v0.28.0 // indirect
115- github.com/go-openapi/spec v0.21.0 // indirect
116- github.com/go-openapi/strfmt v0.23 .0 // indirect
117- github.com/go-openapi/swag v0.24 .1 // indirect
118- github.com/go-openapi/swag/cmdutils v0.24.0 // indirect
119- github.com/go-openapi/swag/conv v0.24.0 // indirect
120- github.com/go-openapi/swag/fileutils v0.24.0 // indirect
121- github.com/go-openapi/swag/jsonname v0.24.0 // indirect
122- github.com/go-openapi/swag/jsonutils v0.24.0 // indirect
123- github.com/go-openapi/swag/loading v0.24.0 // indirect
124- github.com/go-openapi/swag/mangling v0.24.0 // indirect
125- github.com/go-openapi/swag/netutils v0.24.0 // indirect
126- github.com/go-openapi/swag/stringutils v0.24.0 // indirect
127- github.com/go-openapi/swag/typeutils v0.24.0 // indirect
128- github.com/go-openapi/swag/yamlutils v0.24.0 // indirect
129- github.com/go-openapi/validate v0.24.0 // indirect
109+ github.com/go-openapi/analysis v0.24.1 // indirect
110+ github.com/go-openapi/errors v0.22.4 // indirect
111+ github.com/go-openapi/jsonpointer v0.22.1 // indirect
112+ github.com/go-openapi/jsonreference v0.21.3 // indirect
113+ github.com/go-openapi/loads v0.23.2 // indirect
114+ github.com/go-openapi/runtime v0.29.2 // indirect
115+ github.com/go-openapi/spec v0.22.1 // indirect
116+ github.com/go-openapi/strfmt v0.25 .0 // indirect
117+ github.com/go-openapi/swag v0.25 .1 // indirect
118+ github.com/go-openapi/swag/cmdutils v0.25.1 // indirect
119+ github.com/go-openapi/swag/conv v0.25.1 // indirect
120+ github.com/go-openapi/swag/fileutils v0.25.1 // indirect
121+ github.com/go-openapi/swag/jsonname v0.25.1 // indirect
122+ github.com/go-openapi/swag/jsonutils v0.25.1 // indirect
123+ github.com/go-openapi/swag/loading v0.25.1 // indirect
124+ github.com/go-openapi/swag/mangling v0.25.1 // indirect
125+ github.com/go-openapi/swag/netutils v0.25.1 // indirect
126+ github.com/go-openapi/swag/stringutils v0.25.1 // indirect
127+ github.com/go-openapi/swag/typeutils v0.25.1 // indirect
128+ github.com/go-openapi/swag/yamlutils v0.25.1 // indirect
129+ github.com/go-openapi/validate v0.25.1 // indirect
130130 github.com/go-piv/piv-go/v2 v2.4.0 // indirect
131131 github.com/go-viper/mapstructure/v2 v2.4.0 // indirect
132132 github.com/gogo/protobuf v1.3.2 // indirect
@@ -148,17 +148,14 @@ require (
148148 github.com/hashicorp/golang-lru/v2 v2.0.7 // indirect
149149 github.com/in-toto/attestation v1.1.2 // indirect
150150 github.com/jedisct1/go-minisign v0.0.0-20230811132847-661be99b8267 // indirect
151- github.com/josharian/intern v1.0.0 // indirect
152151 github.com/json-iterator/go v1.1.12 // indirect
153152 github.com/klauspost/compress v1.18.0 // indirect
154153 github.com/letsencrypt/boulder v0.0.0-20240620165639-de9c06129bec // indirect
155- github.com/mailru/easyjson v0.9.0 // indirect
156154 github.com/mattn/go-colorable v0.1.14 // indirect
157155 github.com/mattn/go-isatty v0.0.20 // indirect
158156 github.com/mattn/go-runewidth v0.0.16 // indirect
159157 github.com/miekg/pkcs11 v1.1.1 // indirect
160158 github.com/mitchellh/go-homedir v1.1.0 // indirect
161- github.com/mitchellh/mapstructure v1.5.1-0.20231216201459-8508981c8b6c // indirect
162159 github.com/moby/term v0.5.2 // indirect
163160 github.com/modern-go/concurrent v0.0.0-20180306012644-bacd9c7ef1dd // indirect
164161 github.com/modern-go/reflect2 v1.0.3-0.20250322232337-35a7c28c31ee // indirect
@@ -172,14 +169,13 @@ require (
172169 github.com/olekukonko/tablewriter v1.1.0 // indirect
173170 github.com/opencontainers/go-digest v1.0.0 // indirect
174171 github.com/opencontainers/image-spec v1.1.1 // indirect
175- github.com/opentracing/opentracing-go v1.2.0 // indirect
176172 github.com/pborman/uuid v1.2.1 // indirect
177173 github.com/pelletier/go-toml/v2 v2.2.4 // indirect
178174 github.com/pkg/errors v0.9.1 // indirect
179175 github.com/planetscale/vtprotobuf v0.6.1-0.20240319094008-0393e58bdf10 // indirect
180176 github.com/pmezard/go-difflib v1.0.1-0.20181226105442-5d4384ee4fb2 // indirect
181177 github.com/rivo/uniseg v0.4.7 // indirect
182- github.com/sagikazarmark/locafero v0.7 .0 // indirect
178+ github.com/sagikazarmark/locafero v0.11 .0 // indirect
183179 github.com/sassoftware/relic v7.2.1+incompatible // indirect
184180 github.com/segmentio/ksuid v1.0.4 // indirect
185181 github.com/sigstore/fulcio v1.7.1 // indirect
@@ -188,10 +184,10 @@ require (
188184 github.com/sigstore/sigstore-go v1.1.3 // indirect
189185 github.com/sigstore/timestamp-authority v1.2.9 // indirect
190186 github.com/skratchdot/open-golang v0.0.0-20200116055534-eef842397966 // indirect
191- github.com/sourcegraph/conc v0.3.0 // indirect
192- github.com/spf13/afero v1.12 .0 // indirect
193- github.com/spf13/cast v1.7.1 // indirect
194- github.com/spf13/viper v1.20.1 // indirect
187+ github.com/sourcegraph/conc v0.3.1-0.20240121214520-5f936abd7ae8 // indirect
188+ github.com/spf13/afero v1.15 .0 // indirect
189+ github.com/spf13/cast v1.10.0 // indirect
190+ github.com/spf13/viper v1.21.0 // indirect
195191 github.com/spiffe/go-spiffe/v2 v2.6.0 // indirect
196192 github.com/subosito/gotenv v1.6.0 // indirect
197193 github.com/syndtr/goleveldb v1.0.1-0.20220721030215-126854af5e6d // indirect
@@ -207,9 +203,9 @@ require (
207203 github.com/x448/float16 v0.8.4 // indirect
208204 github.com/zclconf/go-cty v1.10.0 // indirect
209205 gitlab.com/gitlab-org/api/client-go v0.143.3 // indirect
210- go.mongodb.org/mongo-driver v1.14.0 // indirect
206+ go.mongodb.org/mongo-driver v1.17.6 // indirect
211207 go.opencensus.io v0.24.0 // indirect
212- go.opentelemetry.io/auto/sdk v1.1.0 // indirect
208+ go.opentelemetry.io/auto/sdk v1.2.1 // indirect
213209 go.opentelemetry.io/contrib/detectors/gcp v1.38.0 // indirect
214210 go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc v0.61.0 // indirect
215211 go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.62.0 // indirect
@@ -222,21 +218,21 @@ require (
222218 go.uber.org/zap v1.27.0 // indirect
223219 go.yaml.in/yaml/v2 v2.4.2 // indirect
224220 go.yaml.in/yaml/v3 v3.0.4 // indirect
225- golang.org/x/crypto v0.42 .0 // indirect
221+ golang.org/x/crypto v0.43 .0 // indirect
226222 golang.org/x/exp v0.0.0-20250620022241-b7579e27df2b // indirect
227- golang.org/x/mod v0.28 .0 // indirect
228- golang.org/x/net v0.43 .0 // indirect
229- golang.org/x/oauth2 v0.31 .0 // indirect
230- golang.org/x/sync v0.17 .0 // indirect
231- golang.org/x/term v0.35 .0 // indirect
232- golang.org/x/text v0.29 .0 // indirect
233- golang.org/x/time v0.12 .0 // indirect
234- google.golang.org/api v0.248 .0 // indirect
223+ golang.org/x/mod v0.30 .0 // indirect
224+ golang.org/x/net v0.46 .0 // indirect
225+ golang.org/x/oauth2 v0.32 .0 // indirect
226+ golang.org/x/sync v0.18 .0 // indirect
227+ golang.org/x/term v0.36 .0 // indirect
228+ golang.org/x/text v0.30 .0 // indirect
229+ golang.org/x/time v0.14 .0 // indirect
230+ google.golang.org/api v0.254 .0 // indirect
235231 google.golang.org/genproto v0.0.0-20250603155806-513f23925822 // indirect
236232 google.golang.org/genproto/googleapis/api v0.0.0-20250818200422-3122310a409c // indirect
237- google.golang.org/genproto/googleapis/rpc v0.0.0-20250818200422-3122310a409c // indirect
238- google.golang.org/grpc v1.75 .0 // indirect
239- google.golang.org/protobuf v1.36.9 // indirect
233+ google.golang.org/genproto/googleapis/rpc v0.0.0-20251022142026-3a174f9686a8 // indirect
234+ google.golang.org/grpc v1.76 .0 // indirect
235+ google.golang.org/protobuf v1.36.10 // indirect
240236 gopkg.in/evanphx/json-patch.v4 v4.12.0 // indirect
241237 gopkg.in/inf.v0 v0.9.1 // indirect
242238 gopkg.in/ini.v1 v1.67.0 // indirect
@@ -259,5 +255,5 @@ require (
259255 github.com/shibumi/go-pathspec v1.3.0 // indirect
260256 github.com/spf13/pflag v1.0.10 // indirect
261257 github.com/stretchr/testify v1.11.1
262- golang.org/x/sys v0.36 .0 // indirect
258+ golang.org/x/sys v0.37 .0 // indirect
263259)
0 commit comments