@@ -22,20 +22,20 @@ require (
2222 github.com/pkg/errors v0.9.1
2323 github.com/sabhiram/go-gitignore v0.0.0-20210923224102-525f6e181f06
2424 github.com/sclevine/spec v1.4.0
25- github.com/secure-systems-lab/go-securesystemslib v0.7 .0
26- github.com/sigstore/cosign/v2 v2.2.2
27- github.com/sigstore/sigstore v1.7.6
25+ github.com/secure-systems-lab/go-securesystemslib v0.8 .0
26+ github.com/sigstore/cosign/v2 v2.2.4
27+ github.com/sigstore/sigstore v1.8.3
2828 github.com/sirupsen/logrus v1.9.3
2929 github.com/spf13/pflag v1.0.5
30- github.com/stretchr/testify v1.8.4
30+ github.com/stretchr/testify v1.9.0
3131 github.com/theupdateframework/notary v0.7.0
3232 github.com/vdemeester/k8s-pkg-credentialprovider v1.22.4
3333 github.com/whilp/git-urls v1.0.0
34- go.uber.org/zap v1.26 .0
34+ go.uber.org/zap v1.27 .0
3535 golang.org/x/crypto v0.23.0
3636 golang.org/x/net v0.25.0
37- golang.org/x/oauth2 v0.15 .0
38- golang.org/x/sync v0.6 .0
37+ golang.org/x/oauth2 v0.19 .0
38+ golang.org/x/sync v0.7 .0
3939 k8s.io/api v0.29.0
4040 k8s.io/apimachinery v0.29.0
4141 k8s.io/client-go v0.29.0
@@ -46,13 +46,14 @@ require (
4646)
4747
4848require (
49- cloud.google.com/go/compute v1.23.3 // indirect
49+ cloud.google.com/go/compute v1.25.0 // indirect
5050 cloud.google.com/go/compute/metadata v0.2.3 // indirect
5151 contrib.go.opencensus.io/exporter/ocagent v0.7.1-0.20200907061046-05415f1de66d // indirect
5252 contrib.go.opencensus.io/exporter/prometheus v0.4.2 // indirect
53- cuelang.org/go v0.6.0 // indirect
53+ cuelabs.dev/go/oci/ociregistry v0.0.0-20240314152124-224736b49f2e // indirect
54+ cuelang.org/go v0.8.1 // indirect
5455 dario.cat/mergo v1.0.0 // indirect
55- filippo.io/edwards25519 v1.0 .0 // indirect
56+ filippo.io/edwards25519 v1.1 .0 // indirect
5657 github.com/AliyunContainerService/ack-ram-tool/pkg/credentials/alibabacloudsdkgo/helper v0.2.0 // indirect
5758 github.com/Azure/azure-sdk-for-go v68.0.0+incompatible // indirect
5859 github.com/Azure/azure-sdk-for-go/sdk/internal v1.5.2 // indirect
@@ -87,28 +88,28 @@ require (
8788 github.com/aliyun/credentials-go v1.3.1 // indirect
8889 github.com/apex/log v1.9.0 // indirect
8990 github.com/asaskevich/govalidator v0.0.0-20230301143203-a9d515a09cc2 // indirect
90- github.com/aws/aws-sdk-go-v2 v1.24.1 // indirect
91- github.com/aws/aws-sdk-go-v2/config v1.26.6 // indirect
92- github.com/aws/aws-sdk-go-v2/credentials v1.16.16 // indirect
93- github.com/aws/aws-sdk-go-v2/feature/ec2/imds v1.14.11 // indirect
94- github.com/aws/aws-sdk-go-v2/internal/configsources v1.2.10 // indirect
95- github.com/aws/aws-sdk-go-v2/internal/endpoints/v2 v2.5.10 // indirect
96- github.com/aws/aws-sdk-go-v2/internal/ini v1.7.3 // indirect
91+ github.com/aws/aws-sdk-go-v2 v1.26.0 // indirect
92+ github.com/aws/aws-sdk-go-v2/config v1.27.9 // indirect
93+ github.com/aws/aws-sdk-go-v2/credentials v1.17.9 // indirect
94+ github.com/aws/aws-sdk-go-v2/feature/ec2/imds v1.16.0 // indirect
95+ github.com/aws/aws-sdk-go-v2/internal/configsources v1.3.4 // indirect
96+ github.com/aws/aws-sdk-go-v2/internal/endpoints/v2 v2.6.4 // indirect
97+ github.com/aws/aws-sdk-go-v2/internal/ini v1.8.0 // indirect
9798 github.com/aws/aws-sdk-go-v2/service/ecr v1.24.7 // indirect
9899 github.com/aws/aws-sdk-go-v2/service/ecrpublic v1.21.6 // indirect
99- github.com/aws/aws-sdk-go-v2/service/internal/accept-encoding v1.10.4 // indirect
100- github.com/aws/aws-sdk-go-v2/service/internal/presigned-url v1.10.10 // indirect
101- github.com/aws/aws-sdk-go-v2/service/sso v1.18.7 // indirect
102- github.com/aws/aws-sdk-go-v2/service/ssooidc v1.21.7 // indirect
103- github.com/aws/aws-sdk-go-v2/service/sts v1.26.7 // indirect
104- github.com/aws/smithy-go v1.19.0 // indirect
100+ github.com/aws/aws-sdk-go-v2/service/internal/accept-encoding v1.11.1 // indirect
101+ github.com/aws/aws-sdk-go-v2/service/internal/presigned-url v1.11.6 // indirect
102+ github.com/aws/aws-sdk-go-v2/service/sso v1.20.3 // indirect
103+ github.com/aws/aws-sdk-go-v2/service/ssooidc v1.23.3 // indirect
104+ github.com/aws/aws-sdk-go-v2/service/sts v1.28.5 // indirect
105+ github.com/aws/smithy-go v1.20.1 // indirect
105106 github.com/awslabs/amazon-ecr-credential-helper/ecr-login v0.0.0-20231024185945-8841054dbdb8 // indirect
106107 github.com/beorn7/perks v1.0.1 // indirect
107108 github.com/blang/semver v3.5.1+incompatible // indirect
108109 github.com/blang/semver/v4 v4.0.0 // indirect
109110 github.com/blendle/zapdriver v1.3.1 // indirect
110- github.com/buildkite/agent/v3 v3.59 .0 // indirect
111- github.com/buildkite/go-pipeline v0.2.0 // indirect
111+ github.com/buildkite/agent/v3 v3.62 .0 // indirect
112+ github.com/buildkite/go-pipeline v0.3.2 // indirect
112113 github.com/buildkite/interpolate v0.0.0-20200526001904-07f35b4ae251 // indirect
113114 github.com/census-instrumentation/opencensus-proto v0.4.1 // indirect
114115 github.com/cespare/xxhash/v2 v2.2.0 // indirect
@@ -119,12 +120,12 @@ require (
119120 github.com/common-nighthawk/go-figure v0.0.0-20210622060536-734e95fb86be // indirect
120121 github.com/containerd/stargz-snapshotter/estargz v0.14.3 // indirect
121122 github.com/containerd/typeurl/v2 v2.1.1 // indirect
122- github.com/coreos/go-oidc/v3 v3.7 .0 // indirect
123+ github.com/coreos/go-oidc/v3 v3.10 .0 // indirect
123124 github.com/cyberphone/json-canonicalization v0.0.0-20231011164504-785e29786b46 // indirect
124125 github.com/cyphar/filepath-securejoin v0.2.4 // indirect
125126 github.com/davecgh/go-spew v1.1.2-0.20180830191138-d8f796af33cc // indirect
126127 github.com/digitorus/pkcs7 v0.0.0-20230818184609-3a137a874352 // indirect
127- github.com/digitorus/timestamp v0.0.0-20230902153158-687734543647 // indirect
128+ github.com/digitorus/timestamp v0.0.0-20231217203849-220c5c2851b7 // indirect
128129 github.com/dimchansky/utfbom v1.1.1 // indirect
129130 github.com/distribution/reference v0.5.0 // indirect
130131 github.com/docker/cli v24.0.7+incompatible // indirect
@@ -134,6 +135,7 @@ require (
134135 github.com/docker/go v1.5.1-1.0.20160303222718-d30aec9fd63c // indirect
135136 github.com/docker/go-connections v0.4.0 // indirect
136137 github.com/docker/go-units v0.5.0 // indirect
138+ github.com/dustin/go-humanize v1.0.1 // indirect
137139 github.com/emicklei/go-restful/v3 v3.11.0 // indirect
138140 github.com/emicklei/proto v1.12.1 // indirect
139141 github.com/emirpasic/gods v1.18.1 // indirect
@@ -146,30 +148,31 @@ require (
146148 github.com/go-git/go-billy/v5 v5.5.0 // indirect
147149 github.com/go-ini/ini v1.67.0 // indirect
148150 github.com/go-jose/go-jose/v3 v3.0.3 // indirect
151+ github.com/go-jose/go-jose/v4 v4.0.1 // indirect
149152 github.com/go-kit/log v0.2.1 // indirect
150153 github.com/go-logfmt/logfmt v0.5.1 // indirect
151- github.com/go-logr/logr v1.3.0 // indirect
154+ github.com/go-logr/logr v1.4.1 // indirect
152155 github.com/go-logr/stdr v1.2.2 // indirect
153- github.com/go-openapi/analysis v0.21.4 // indirect
154- github.com/go-openapi/errors v0.20.4 // indirect
155- github.com/go-openapi/jsonpointer v0.20 .0 // indirect
156- github.com/go-openapi/jsonreference v0.20.2 // indirect
157- github.com/go-openapi/loads v0.21.2 // indirect
158- github.com/go-openapi/runtime v0.26 .0 // indirect
159- github.com/go-openapi/spec v0.20.11 // indirect
160- github.com/go-openapi/strfmt v0.21.8 // indirect
161- github.com/go-openapi/swag v0.22.4 // indirect
162- github.com/go-openapi/validate v0.22.3 // indirect
156+ github.com/go-openapi/analysis v0.23.0 // indirect
157+ github.com/go-openapi/errors v0.22.0 // indirect
158+ github.com/go-openapi/jsonpointer v0.21 .0 // indirect
159+ github.com/go-openapi/jsonreference v0.21.0 // indirect
160+ github.com/go-openapi/loads v0.22.0 // indirect
161+ github.com/go-openapi/runtime v0.28 .0 // indirect
162+ github.com/go-openapi/spec v0.21.0 // indirect
163+ github.com/go-openapi/strfmt v0.23.0 // indirect
164+ github.com/go-openapi/swag v0.23.0 // indirect
165+ github.com/go-openapi/validate v0.24.0 // indirect
163166 github.com/go-piv/piv-go v1.11.0 // indirect
164167 github.com/gobuffalo/flect v1.0.2 // indirect
165168 github.com/gobwas/glob v0.2.3 // indirect
166169 github.com/gogo/protobuf v1.3.2 // indirect
167170 github.com/golang-jwt/jwt/v4 v4.5.0 // indirect
168171 github.com/golang-jwt/jwt/v5 v5.2.1 // indirect
169172 github.com/golang/groupcache v0.0.0-20210331224755-41bb18bfe9da // indirect
170- github.com/golang/protobuf v1.5.3 // indirect
173+ github.com/golang/protobuf v1.5.4 // indirect
171174 github.com/golang/snappy v0.0.4 // indirect
172- github.com/google/certificate-transparency-go v1.1.7 // indirect
175+ github.com/google/certificate-transparency-go v1.1.8 // indirect
173176 github.com/google/gnostic-models v0.6.9-0.20230804172637-c7be7c783f49 // indirect
174177 github.com/google/go-containerregistry/pkg/authn/kubernetes v0.0.0-20230516205744-dbecb1de8cfa // indirect
175178 github.com/google/go-github/v55 v55.0.0 // indirect
@@ -179,7 +182,7 @@ require (
179182 github.com/google/uuid v1.6.0 // indirect
180183 github.com/googleapis/enterprise-certificate-proxy v0.3.2 // indirect
181184 github.com/gorilla/mux v1.8.1 // indirect
182- github.com/grpc-ecosystem/grpc-gateway/v2 v2.18.0 // indirect
185+ github.com/grpc-ecosystem/grpc-gateway/v2 v2.19.1 // indirect
183186 github.com/hashicorp/go-cleanhttp v0.5.2 // indirect
184187 github.com/hashicorp/go-retryablehttp v0.7.5 // indirect
185188 github.com/hashicorp/golang-lru v1.0.2 // indirect
@@ -195,14 +198,13 @@ require (
195198 github.com/json-iterator/go v1.1.12 // indirect
196199 github.com/kelseyhightower/envconfig v1.4.0 // indirect
197200 github.com/kevinburke/ssh_config v1.2.0 // indirect
198- github.com/klauspost/compress v1.17.2 // indirect
201+ github.com/klauspost/compress v1.17.4 // indirect
199202 github.com/kylelemons/godebug v1.1.0 // indirect
200203 github.com/letsencrypt/boulder v0.0.0-20231026200631-000cd05d5491 // indirect
201204 github.com/magiconair/properties v1.8.7 // indirect
202205 github.com/mailru/easyjson v0.7.7 // indirect
203206 github.com/mattn/go-colorable v0.1.13 // indirect
204207 github.com/mattn/go-isatty v0.0.20 // indirect
205- github.com/matttproud/golang_protobuf_extensions/v2 v2.0.0 // indirect
206208 github.com/miekg/pkcs11 v1.1.1 // indirect
207209 github.com/mitchellh/go-homedir v1.1.0 // indirect
208210 github.com/mitchellh/go-wordwrap v1.0.1 // indirect
@@ -213,44 +215,44 @@ require (
213215 github.com/modern-go/reflect2 v1.0.2 // indirect
214216 github.com/morikuni/aec v1.0.0 // indirect
215217 github.com/mozillazg/docker-credential-acr-helper v0.3.0 // indirect
216- github.com/mpvl/unique v0.0.0-20150818121801-cbe035fff7de // indirect
217218 github.com/munnerz/goautoneg v0.0.0-20191010083416-a7dc8b61c822 // indirect
218219 github.com/nozzle/throttler v0.0.0-20180817012639-2ea982251481 // indirect
219220 github.com/oklog/ulid v1.3.1 // indirect
220221 github.com/oleiade/reflections v1.0.1 // indirect
221- github.com/open-policy-agent/opa v0.59 .0 // indirect
222+ github.com/open-policy-agent/opa v0.63 .0 // indirect
222223 github.com/opencontainers/go-digest v1.0.0 // indirect
223- github.com/opencontainers/image-spec v1.1.0-rc5 // indirect
224+ github.com/opencontainers/image-spec v1.1.0 // indirect
224225 github.com/opentracing/opentracing-go v1.2.0 // indirect
225226 github.com/pborman/uuid v1.2.1 // indirect
226227 github.com/pelletier/go-toml/v2 v2.1.0 // indirect
227228 github.com/pjbgf/sha1cd v0.3.0 // indirect
228229 github.com/pkg/browser v0.0.0-20240102092130-5ac0b6a4141c // indirect
229230 github.com/pmezard/go-difflib v1.0.1-0.20181226105442-5d4384ee4fb2 // indirect
230- github.com/prometheus/client_golang v1.17 .0 // indirect
231- github.com/prometheus/client_model v0.5 .0 // indirect
232- github.com/prometheus/common v0.45.0 // indirect
231+ github.com/prometheus/client_golang v1.19 .0 // indirect
232+ github.com/prometheus/client_model v0.6 .0 // indirect
233+ github.com/prometheus/common v0.51.1 // indirect
233234 github.com/prometheus/procfs v0.12.0 // indirect
234235 github.com/prometheus/statsd_exporter v0.22.7 // indirect
235236 github.com/protocolbuffers/txtpbfmt v0.0.0-20231025115547-084445ff1adf // indirect
236237 github.com/rcrowley/go-metrics v0.0.0-20201227073835-cf1acfcdf475 // indirect
237- github.com/sagikazarmark/locafero v0.3.0 // indirect
238+ github.com/rogpeppe/go-internal v1.12.0 // indirect
239+ github.com/sagikazarmark/locafero v0.4.0 // indirect
238240 github.com/sagikazarmark/slog-shim v0.1.0 // indirect
239241 github.com/sassoftware/relic v7.2.1+incompatible // indirect
240242 github.com/segmentio/ksuid v1.0.4 // indirect
241243 github.com/sergi/go-diff v1.3.1 // indirect
242244 github.com/shibumi/go-pathspec v1.3.0 // indirect
243- github.com/sigstore/fulcio v1.4.3 // indirect
244- github.com/sigstore/rekor v1.3.4 // indirect
245- github.com/sigstore/timestamp-authority v1.2.0 // indirect
245+ github.com/sigstore/fulcio v1.4.5 // indirect
246+ github.com/sigstore/rekor v1.3.6 // indirect
247+ github.com/sigstore/timestamp-authority v1.2.2 // indirect
246248 github.com/skeema/knownhosts v1.2.1 // indirect
247249 github.com/skratchdot/open-golang v0.0.0-20200116055534-eef842397966 // indirect
248250 github.com/sourcegraph/conc v0.3.0 // indirect
249- github.com/spf13/afero v1.10 .0 // indirect
250- github.com/spf13/cast v1.5.1 // indirect
251+ github.com/spf13/afero v1.11 .0 // indirect
252+ github.com/spf13/cast v1.6.0 // indirect
251253 github.com/spf13/cobra v1.8.0 // indirect
252- github.com/spf13/viper v1.17.0 // indirect
253- github.com/spiffe/go-spiffe/v2 v2.1.6 // indirect
254+ github.com/spf13/viper v1.18.2 // indirect
255+ github.com/spiffe/go-spiffe/v2 v2.2.0 // indirect
254256 github.com/subosito/gotenv v1.6.0 // indirect
255257 github.com/syndtr/goleveldb v1.0.1-0.20220721030215-126854af5e6d // indirect
256258 github.com/tchap/go-patricia/v2 v2.3.1 // indirect
@@ -260,47 +262,45 @@ require (
260262 github.com/tjfoc/gmsm v1.4.1 // indirect
261263 github.com/transparency-dev/merkle v0.0.2 // indirect
262264 github.com/vbatts/tar-split v0.11.5 // indirect
263- github.com/xanzy/go-gitlab v0.94 .0 // indirect
265+ github.com/xanzy/go-gitlab v0.102 .0 // indirect
264266 github.com/xanzy/ssh-agent v0.3.3 // indirect
265267 github.com/xeipuuv/gojsonpointer v0.0.0-20190905194746-02993c407bfb // indirect
266268 github.com/xeipuuv/gojsonreference v0.0.0-20180127040603-bd5ef7bd5415 // indirect
267269 github.com/yashtewari/glob-intersection v0.2.0 // indirect
268270 github.com/zeebo/errs v1.3.0 // indirect
269- go.mongodb.org/mongo-driver v1.12.1 // indirect
271+ go.mongodb.org/mongo-driver v1.14.0 // indirect
270272 go.opencensus.io v0.24.0 // indirect
271- go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.46.1 // indirect
272- go.opentelemetry.io/otel v1.21 .0 // indirect
273+ go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.49.0 // indirect
274+ go.opentelemetry.io/otel v1.24 .0 // indirect
273275 go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp v1.21.0 // indirect
274- go.opentelemetry.io/otel/metric v1.21 .0 // indirect
275- go.opentelemetry.io/otel/sdk v1.21 .0 // indirect
276- go.opentelemetry.io/otel/trace v1.21 .0 // indirect
277- go.step.sm/crypto v0.38.0 // indirect
276+ go.opentelemetry.io/otel/metric v1.24 .0 // indirect
277+ go.opentelemetry.io/otel/sdk v1.24 .0 // indirect
278+ go.opentelemetry.io/otel/trace v1.24 .0 // indirect
279+ go.step.sm/crypto v0.44.2 // indirect
278280 go.uber.org/automaxprocs v1.5.3 // indirect
279281 go.uber.org/multierr v1.11.0 // indirect
280282 golang.org/x/exp v0.0.0-20231108232855-2478ac86f678 // indirect
281- golang.org/x/mod v0.14 .0 // indirect
283+ golang.org/x/mod v0.16 .0 // indirect
282284 golang.org/x/sys v0.20.0 // indirect
283285 golang.org/x/term v0.20.0 // indirect
284286 golang.org/x/text v0.15.0 // indirect
285287 golang.org/x/time v0.5.0 // indirect
286- golang.org/x/tools v0.15 .0 // indirect
288+ golang.org/x/tools v0.19 .0 // indirect
287289 gomodules.xyz/jsonpatch/v2 v2.3.0 // indirect
288- google.golang.org/api v0.152.0 // indirect
289- google.golang.org/appengine v1.6.8 // indirect
290- google.golang.org/genproto/googleapis/api v0.0.0-20231106174013-bbf56f31fb17 // indirect
291- google.golang.org/genproto/googleapis/rpc v0.0.0-20231120223509-83a465c0220f // indirect
292- google.golang.org/grpc v1.59.0 // indirect
290+ google.golang.org/api v0.172.0 // indirect
291+ google.golang.org/genproto/googleapis/api v0.0.0-20240311173647-c811ad7063a7 // indirect
292+ google.golang.org/genproto/googleapis/rpc v0.0.0-20240318140521-94a12d6c2237 // indirect
293+ google.golang.org/grpc v1.62.1 // indirect
293294 google.golang.org/protobuf v1.33.0 // indirect
294- gopkg.in/go-jose/go-jose.v2 v2.6.1 // indirect
295+ gopkg.in/go-jose/go-jose.v2 v2.6.3 // indirect
295296 gopkg.in/inf.v0 v0.9.1 // indirect
296297 gopkg.in/ini.v1 v1.67.0 // indirect
297- gopkg.in/square/go-jose.v2 v2.6.0 // indirect
298298 gopkg.in/warnings.v0 v0.1.2 // indirect
299299 gopkg.in/yaml.v2 v2.4.0 // indirect
300300 gopkg.in/yaml.v3 v3.0.1 // indirect
301301 k8s.io/apiextensions-apiserver v0.26.5 // indirect
302302 k8s.io/gengo v0.0.0-20230829151522-9cce18d56c01 // indirect
303- k8s.io/klog/v2 v2.110 .1 // indirect
303+ k8s.io/klog/v2 v2.120 .1 // indirect
304304 k8s.io/legacy-cloud-providers v0.23.9 // indirect
305305 k8s.io/utils v0.0.0-20230726121419-3b25d923346b // indirect
306306 sigs.k8s.io/json v0.0.0-20221116044647-bc3834ca7abd // indirect
0 commit comments