@@ -6,24 +6,24 @@ require (
66 github.com/caarlos0/env/v6 v6.10.1
77 github.com/google/go-cmp v0.5.9
88 github.com/google/go-github/v46 v46.0.0
9- github.com/ossf/scorecard/v4 v4.10.2
9+ github.com/ossf/scorecard/v4 v4.10.5
1010 github.com/sigstore/cosign v1.13.1
1111 github.com/spf13/cobra v1.6.1
1212 golang.org/x/net v0.7.0
1313)
1414
1515require (
1616 bitbucket.org/creachadair/shell v0.0.7 // indirect
17- cloud.google.com/go v0.107 .0 // indirect
18- cloud.google.com/go/compute v1.14 .0 // indirect
17+ cloud.google.com/go v0.109 .0 // indirect
18+ cloud.google.com/go/compute v1.18 .0 // indirect
1919 cloud.google.com/go/compute/metadata v0.2.3 // indirect
20- cloud.google.com/go/iam v0.9 .0 // indirect
21- cloud.google.com/go/storage v1.28.1 // indirect
20+ cloud.google.com/go/iam v0.10 .0 // indirect
21+ cloud.google.com/go/storage v1.29.0 // indirect
2222 github.com/AliyunContainerService/ack-ram-tool/pkg/credentials/alibabacloudsdkgo/helper v0.2.0 // indirect
2323 github.com/Azure/azure-sdk-for-go v66.0.0+incompatible // indirect
2424 github.com/Azure/go-autorest v14.2.0+incompatible // indirect
2525 github.com/Azure/go-autorest/autorest v0.11.28 // indirect
26- github.com/Azure/go-autorest/autorest/adal v0.9.21 // indirect
26+ github.com/Azure/go-autorest/autorest/adal v0.9.22 // indirect
2727 github.com/Azure/go-autorest/autorest/azure/auth v0.5.11 // indirect
2828 github.com/Azure/go-autorest/autorest/azure/cli v0.4.6 // indirect
2929 github.com/Azure/go-autorest/autorest/date v0.3.0 // indirect
@@ -33,7 +33,9 @@ require (
3333 github.com/CycloneDX/cyclonedx-go v0.7.0 // indirect
3434 github.com/Masterminds/semver/v3 v3.2.0 // indirect
3535 github.com/Microsoft/go-winio v0.6.0 // indirect
36+ github.com/ProtonMail/go-crypto v0.0.0-20221026131551-cf6655e29de4 // indirect
3637 github.com/ThalesIgnite/crypto11 v1.2.5 // indirect
38+ github.com/acomagu/bufpipe v1.0.3 // indirect
3739 github.com/alibabacloud-go/alibabacloud-gateway-spi v0.0.4 // indirect
3840 github.com/alibabacloud-go/cr-20160607 v1.0.1 // indirect
3941 github.com/alibabacloud-go/cr-20181201 v1.0.10 // indirect
@@ -46,64 +48,69 @@ require (
4648 github.com/alibabacloud-go/tea-xml v1.1.2 // indirect
4749 github.com/aliyun/credentials-go v1.2.3 // indirect
4850 github.com/asaskevich/govalidator v0.0.0-20210307081110-f21760c49a8d // indirect
49- github.com/aws/aws-sdk-go-v2 v1.16.16 // indirect
50- github.com/aws/aws-sdk-go-v2/config v1.17.8 // indirect
51- github.com/aws/aws-sdk-go-v2/credentials v1.12.21 // indirect
52- github.com/aws/aws-sdk-go-v2/feature/ec2/imds v1.12.17 // indirect
53- github.com/aws/aws-sdk-go-v2/internal/configsources v1.1.23 // indirect
54- github.com/aws/aws-sdk-go-v2/internal/endpoints/v2 v2.4.17 // indirect
55- github.com/aws/aws-sdk-go-v2/internal/ini v1.3.24 // indirect
51+ github.com/aws/aws-sdk-go-v2 v1.17.4 // indirect
52+ github.com/aws/aws-sdk-go-v2/config v1.18.12 // indirect
53+ github.com/aws/aws-sdk-go-v2/credentials v1.13.12 // indirect
54+ github.com/aws/aws-sdk-go-v2/feature/ec2/imds v1.12.22 // indirect
55+ github.com/aws/aws-sdk-go-v2/internal/configsources v1.1.28 // indirect
56+ github.com/aws/aws-sdk-go-v2/internal/endpoints/v2 v2.4.22 // indirect
57+ github.com/aws/aws-sdk-go-v2/internal/ini v1.3.29 // indirect
5658 github.com/aws/aws-sdk-go-v2/service/ecr v1.15.0 // indirect
5759 github.com/aws/aws-sdk-go-v2/service/ecrpublic v1.12.0 // indirect
58- github.com/aws/aws-sdk-go-v2/service/internal/presigned-url v1.9.17 // indirect
59- github.com/aws/aws-sdk-go-v2/service/sso v1.11.23 // indirect
60- github.com/aws/aws-sdk-go-v2/service/ssooidc v1.13.6 // indirect
61- github.com/aws/aws-sdk-go-v2/service/sts v1.16.19 // indirect
62- github.com/aws/smithy-go v1.13.3 // indirect
60+ github.com/aws/aws-sdk-go-v2/service/internal/presigned-url v1.9.22 // indirect
61+ github.com/aws/aws-sdk-go-v2/service/sso v1.12.1 // indirect
62+ github.com/aws/aws-sdk-go-v2/service/ssooidc v1.14.1 // indirect
63+ github.com/aws/aws-sdk-go-v2/service/sts v1.18.3 // indirect
64+ github.com/aws/smithy-go v1.13.5 // indirect
6365 github.com/awslabs/amazon-ecr-credential-helper/ecr-login v0.0.0-20220228164355-396b2034c795 // indirect
64- github.com/benbjohnson/clock v1.1 .0 // indirect
66+ github.com/benbjohnson/clock v1.3 .0 // indirect
6567 github.com/beorn7/perks v1.0.1 // indirect
6668 github.com/bgentry/speakeasy v0.1.0 // indirect
6769 github.com/blang/semver v3.5.1+incompatible // indirect
6870 github.com/bombsimon/logrusr/v2 v2.0.1 // indirect
6971 github.com/bradleyfalzon/ghinstallation/v2 v2.1.0 // indirect
70- github.com/cenkalti/backoff/v4 v4.1.3 // indirect
71- github.com/census-instrumentation/opencensus-proto v0.3.0 // indirect
72- github.com/cespare/xxhash/v2 v2.1.2 // indirect
72+ github.com/cenkalti/backoff/v4 v4.2.0 // indirect
73+ github.com/census-instrumentation/opencensus-proto v0.4.1 // indirect
74+ github.com/cespare/xxhash/v2 v2.2.0 // indirect
7375 github.com/chrismellard/docker-credential-acr-env v0.0.0-20220119192733-fe33c00cee21 // indirect
7476 github.com/clbanning/mxj/v2 v2.5.6 // indirect
75- github.com/cncf/udpa/go v0.0.0-20210930031921-04548b0d99d4 // indirect
76- github.com/cncf/xds/go v0.0.0-20220314180256-7f1daf1720fc // indirect
77+ github.com/cloudflare/circl v1.1.0 // indirect
78+ github.com/cncf/udpa/go v0.0.0-20220112060539-c52dc94e7fbe // indirect
79+ github.com/cncf/xds/go v0.0.0-20230105202645-06c439db220b // indirect
7780 github.com/common-nighthawk/go-figure v0.0.0-20210622060536-734e95fb86be // indirect
7881 github.com/containerd/stargz-snapshotter/estargz v0.13.0 // indirect
7982 github.com/containerd/typeurl v1.0.2 // indirect
8083 github.com/coreos/go-oidc/v3 v3.4.0 // indirect
8184 github.com/coreos/go-semver v0.3.0 // indirect
82- github.com/coreos/go-systemd/v22 v22.3.2 // indirect
85+ github.com/coreos/go-systemd/v22 v22.5.0 // indirect
8386 github.com/cpuguy83/go-md2man/v2 v2.0.2 // indirect
8487 github.com/cyberphone/json-canonicalization v0.0.0-20210823021906-dc406ceaf94b // indirect
8588 github.com/davecgh/go-spew v1.1.1 // indirect
8689 github.com/dimchansky/utfbom v1.1.1 // indirect
87- github.com/docker/cli v20.10.22 +incompatible // indirect
90+ github.com/docker/cli v23.0.0-rc.1 +incompatible // indirect
8891 github.com/docker/distribution v2.8.1+incompatible // indirect
89- github.com/docker/docker v20.10.22 +incompatible // indirect
92+ github.com/docker/docker v23.0.0-rc.1 +incompatible // indirect
9093 github.com/docker/docker-credential-helpers v0.7.0 // indirect
9194 github.com/dustin/go-humanize v1.0.0 // indirect
92- github.com/emicklei/go-restful v2.16.0+incompatible // indirect
95+ github.com/emicklei/go-restful/v3 v3.9.0 // indirect
96+ github.com/emirpasic/gods v1.18.1 // indirect
9397 github.com/envoyproxy/go-control-plane v0.10.3 // indirect
94- github.com/envoyproxy/protoc-gen-validate v0.6.7 // indirect
98+ github.com/envoyproxy/protoc-gen-validate v0.9.1 // indirect
9599 github.com/fatih/color v1.13.0 // indirect
96- github.com/fsnotify/fsnotify v1.5.4 // indirect
100+ github.com/fsnotify/fsnotify v1.6.0 // indirect
97101 github.com/fullstorydev/grpcurl v1.8.7 // indirect
98102 github.com/go-chi/chi v4.1.2+incompatible // indirect
103+ github.com/go-git/gcfg v1.5.0 // indirect
104+ github.com/go-git/go-billy/v5 v5.4.1 // indirect
105+ github.com/go-git/go-git/v5 v5.6.0 // indirect
99106 github.com/go-logr/logr v1.2.3 // indirect
100107 github.com/go-logr/stdr v1.2.2 // indirect
101108 github.com/go-openapi/analysis v0.21.4 // indirect
102109 github.com/go-openapi/errors v0.20.3 // indirect
103110 github.com/go-openapi/jsonpointer v0.19.5 // indirect
104111 github.com/go-openapi/jsonreference v0.20.0 // indirect
105112 github.com/go-openapi/loads v0.21.2 // indirect
106- github.com/go-openapi/runtime v0.24.2 // indirect
113+ github.com/go-openapi/runtime v0.25.0 // indirect
107114 github.com/go-openapi/spec v0.20.7 // indirect
108115 github.com/go-openapi/strfmt v0.21.3 // indirect
109116 github.com/go-openapi/swag v0.22.3 // indirect
@@ -128,13 +135,13 @@ require (
128135 github.com/google/go-github/v45 v45.2.0 // indirect
129136 github.com/google/go-querystring v1.1.0 // indirect
130137 github.com/google/gofuzz v1.2.0 // indirect
131- github.com/google/osv-scanner v1.0.1 // indirect
138+ github.com/google/osv-scanner v1.2.1-0.20230314051001-c147987006ff // indirect
132139 github.com/google/trillian v1.5.0 // indirect
133140 github.com/google/uuid v1.3.0 // indirect
134141 github.com/google/wire v0.5.0 // indirect
135- github.com/googleapis/enterprise-certificate-proxy v0.2.1 // indirect
142+ github.com/googleapis/enterprise-certificate-proxy v0.2.3 // indirect
136143 github.com/googleapis/gax-go/v2 v2.7.0 // indirect
137- github.com/gorilla/websocket v1.4.2 // indirect
144+ github.com/gorilla/websocket v1.5.0 // indirect
138145 github.com/grpc-ecosystem/go-grpc-middleware v1.3.0 // indirect
139146 github.com/grpc-ecosystem/go-grpc-prometheus v1.2.0 // indirect
140147 github.com/grpc-ecosystem/grpc-gateway v1.16.0 // indirect
@@ -143,16 +150,18 @@ require (
143150 github.com/hashicorp/go-cleanhttp v0.5.2 // indirect
144151 github.com/hashicorp/go-retryablehttp v0.7.1 // indirect
145152 github.com/hashicorp/hcl v1.0.0 // indirect
146- github.com/imdario/mergo v0.3.12 // indirect
147- github.com/in-toto/in-toto-golang v0.3.4-0.20220709202702-fa494aaa0add // indirect
153+ github.com/imdario/mergo v0.3.13 // indirect
154+ github.com/in-toto/in-toto-golang v0.5.0 // indirect
148155 github.com/inconshreveable/mousetrap v1.1.0 // indirect
149- github.com/jedib0t/go-pretty/v6 v6.4.3 // indirect
156+ github.com/jbenet/go-context v0.0.0-20150711004518-d14ea06fba99 // indirect
157+ github.com/jedib0t/go-pretty/v6 v6.4.6 // indirect
150158 github.com/jedisct1/go-minisign v0.0.0-20211028175153-1c139d1cc84b // indirect
151159 github.com/jhump/protoreflect v1.13.0 // indirect
152160 github.com/jmespath/go-jmespath v0.4.0 // indirect
153161 github.com/jonboulle/clockwork v0.3.0 // indirect
154162 github.com/josharian/intern v1.0.0 // indirect
155163 github.com/json-iterator/go v1.1.12 // indirect
164+ github.com/kevinburke/ssh_config v1.2.0 // indirect
156165 github.com/klauspost/compress v1.15.13 // indirect
157166 github.com/leodido/go-urn v1.2.1 // indirect
158167 github.com/letsencrypt/boulder v0.0.0-20220929215747-76583552c2be // indirect
@@ -161,11 +170,11 @@ require (
161170 github.com/mattn/go-colorable v0.1.13 // indirect
162171 github.com/mattn/go-isatty v0.0.16 // indirect
163172 github.com/mattn/go-runewidth v0.0.14 // indirect
164- github.com/matttproud/golang_protobuf_extensions v1.0.2-0.20181231171920-c182affec369 // indirect
173+ github.com/matttproud/golang_protobuf_extensions v1.0.4 // indirect
165174 github.com/miekg/pkcs11 v1.1.1 // indirect
166175 github.com/mitchellh/go-homedir v1.1.0 // indirect
167176 github.com/mitchellh/mapstructure v1.5.0 // indirect
168- github.com/moby/buildkit v0.10.6 // indirect
177+ github.com/moby/buildkit v0.11.4 // indirect
169178 github.com/modern-go/concurrent v0.0.0-20180306012644-bacd9c7ef1dd // indirect
170179 github.com/modern-go/reflect2 v1.0.2 // indirect
171180 github.com/mozillazg/docker-credential-acr-helper v0.3.0 // indirect
@@ -175,14 +184,15 @@ require (
175184 github.com/opencontainers/go-digest v1.0.0 // indirect
176185 github.com/opencontainers/image-spec v1.1.0-rc2 // indirect
177186 github.com/opentracing/opentracing-go v1.2.0 // indirect
178- github.com/package-url/packageurl-go v0.1.0 // indirect
187+ github.com/package-url/packageurl-go v0.1.1-0.20220428063043-89078438f170 // indirect
179188 github.com/pelletier/go-toml v1.9.5 // indirect
180189 github.com/pelletier/go-toml/v2 v2.0.5 // indirect
190+ github.com/pjbgf/sha1cd v0.3.0 // indirect
181191 github.com/pkg/errors v0.9.1 // indirect
182192 github.com/pmezard/go-difflib v1.0.0 // indirect
183- github.com/prometheus/client_golang v1.13 .0 // indirect
184- github.com/prometheus/client_model v0.2 .0 // indirect
185- github.com/prometheus/common v0.37 .0 // indirect
193+ github.com/prometheus/client_golang v1.14 .0 // indirect
194+ github.com/prometheus/client_model v0.3 .0 // indirect
195+ github.com/prometheus/common v0.39 .0 // indirect
186196 github.com/prometheus/procfs v0.8.0 // indirect
187197 github.com/rhysd/actionlint v1.6.22 // indirect
188198 github.com/rivo/uniseg v0.4.3 // indirect
@@ -191,18 +201,20 @@ require (
191201 github.com/sassoftware/relic v0.0.0-20210427151427-dfb082b79b74 // indirect
192202 github.com/secure-systems-lab/go-securesystemslib v0.4.0 // indirect
193203 github.com/segmentio/ksuid v1.0.4 // indirect
204+ github.com/sergi/go-diff v1.2.0 // indirect
194205 github.com/shibumi/go-pathspec v1.3.0 // indirect
195206 github.com/shurcooL/githubv4 v0.0.0-20221203213311-70889c5dac07 // indirect
196207 github.com/shurcooL/graphql v0.0.0-20220606043923-3cf50f8a0a29 // indirect
197208 github.com/sigstore/fulcio v0.6.0 // indirect
198209 github.com/sigstore/rekor v0.12.1-0.20220915152154-4bb6f441c1b2 // indirect
199210 github.com/sigstore/sigstore v1.4.4 // indirect
200211 github.com/sirupsen/logrus v1.9.0 // indirect
212+ github.com/skeema/knownhosts v1.1.0 // indirect
201213 github.com/skratchdot/open-golang v0.0.0-20200116055534-eef842397966 // indirect
202214 github.com/soheilhy/cmux v0.1.5 // indirect
203- github.com/spdx/gordf v0.0.0-20201111095634-7098f93598fb // indirect
204- github.com/spdx/tools-golang v0.3 .0 // indirect
205- github.com/spf13/afero v1.8 .2 // indirect
215+ github.com/spdx/gordf v0.0.0-20221230105357-b735bd5aac89 // indirect
216+ github.com/spdx/tools-golang v0.4 .0 // indirect
217+ github.com/spf13/afero v1.9 .2 // indirect
206218 github.com/spf13/cast v1.5.0 // indirect
207219 github.com/spf13/jwalterweatherman v1.1.0 // indirect
208220 github.com/spf13/pflag v1.0.5 // indirect
@@ -220,7 +232,8 @@ require (
220232 github.com/transparency-dev/merkle v0.0.1 // indirect
221233 github.com/urfave/cli v1.22.7 // indirect
222234 github.com/vbatts/tar-split v0.11.2 // indirect
223- github.com/xanzy/go-gitlab v0.76.0 // indirect
235+ github.com/xanzy/go-gitlab v0.78.0 // indirect
236+ github.com/xanzy/ssh-agent v0.3.3 // indirect
224237 github.com/xiang90/probing v0.0.0-20190116061207-43a291ad63a2 // indirect
225238 github.com/zeebo/errs v1.2.2 // indirect
226239 go.etcd.io/bbolt v1.3.6 // indirect
@@ -235,52 +248,54 @@ require (
235248 go.etcd.io/etcd/server/v3 v3.6.0-alpha.0 // indirect
236249 go.etcd.io/etcd/tests/v3 v3.6.0-alpha.0 // indirect
237250 go.etcd.io/etcd/v3 v3.6.0-alpha.0 // indirect
238- go.mongodb.org/mongo-driver v1.10 .0 // indirect
251+ go.mongodb.org/mongo-driver v1.11 .0 // indirect
239252 go.opencensus.io v0.24.0 // indirect
240253 go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc v0.29.0 // indirect
241- go.opentelemetry.io/otel v1.7.0 // indirect
242- go.opentelemetry.io/otel/exporters/otlp/internal/retry v1.7.0 // indirect
243- go.opentelemetry.io/otel/exporters/otlp/otlptrace v1.7.0 // indirect
244- go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc v1.7.0 // indirect
245- go.opentelemetry.io/otel/sdk v1.7.0 // indirect
246- go.opentelemetry.io/otel/trace v1.7.0 // indirect
247- go.opentelemetry.io/proto/otlp v0.16 .0 // indirect
254+ go.opentelemetry.io/otel v1.11.2 // indirect
255+ go.opentelemetry.io/otel/exporters/otlp/internal/retry v1.11.2 // indirect
256+ go.opentelemetry.io/otel/exporters/otlp/otlptrace v1.11.2 // indirect
257+ go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc v1.11.2 // indirect
258+ go.opentelemetry.io/otel/sdk v1.11.2 // indirect
259+ go.opentelemetry.io/otel/trace v1.11.2 // indirect
260+ go.opentelemetry.io/proto/otlp v0.19 .0 // indirect
248261 go.uber.org/atomic v1.10.0 // indirect
249- go.uber.org/multierr v1.8 .0 // indirect
250- go.uber.org/zap v1.23 .0 // indirect
251- gocloud.dev v0.27 .0 // indirect
252- golang.org/x/crypto v0.4 .0 // indirect
253- golang.org/x/exp v0.0.0-20221217163422-3c43f8badb15 // indirect
254- golang.org/x/mod v0.7 .0 // indirect
255- golang.org/x/oauth2 v0.3 .0 // indirect
262+ go.uber.org/multierr v1.9 .0 // indirect
263+ go.uber.org/zap v1.24 .0 // indirect
264+ gocloud.dev v0.29 .0 // indirect
265+ golang.org/x/crypto v0.6 .0 // indirect
266+ golang.org/x/exp v0.0.0-20230304125523-9ff063c70017 // indirect
267+ golang.org/x/mod v0.9 .0 // indirect
268+ golang.org/x/oauth2 v0.5 .0 // indirect
256269 golang.org/x/sync v0.1.0 // indirect
257- golang.org/x/sys v0.5 .0 // indirect
258- golang.org/x/term v0.5 .0 // indirect
270+ golang.org/x/sys v0.6 .0 // indirect
271+ golang.org/x/term v0.6 .0 // indirect
259272 golang.org/x/text v0.7.0 // indirect
260- golang.org/x/time v0.1.0 // indirect
261- golang.org/x/tools v0.3.0 // indirect
273+ golang.org/x/time v0.3.0 // indirect
274+ golang.org/x/tools v0.6.1-0.20230217175706-3102dad5faf9 // indirect
275+ golang.org/x/vuln v0.0.0-20230303230808-d3042fecc4e3 // indirect
262276 golang.org/x/xerrors v0.0.0-20220907171357-04be3eba64a2 // indirect
263- google.golang.org/api v0.105 .0 // indirect
277+ google.golang.org/api v0.110 .0 // indirect
264278 google.golang.org/appengine v1.6.7 // indirect
265- google.golang.org/genproto v0.0.0-20221207170731-23e4bf6bdc37 // indirect
266- google.golang.org/grpc v1.51 .0 // indirect
279+ google.golang.org/genproto v0.0.0-20230209215440-0dfe4f8abfcc // indirect
280+ google.golang.org/grpc v1.53 .0 // indirect
267281 google.golang.org/protobuf v1.28.1 // indirect
268282 gopkg.in/cheggaaa/pb.v1 v1.0.28 // indirect
269283 gopkg.in/inf.v0 v0.9.1 // indirect
270284 gopkg.in/ini.v1 v1.67.0 // indirect
271285 gopkg.in/natefinch/lumberjack.v2 v2.0.0 // indirect
272286 gopkg.in/square/go-jose.v2 v2.6.0 // indirect
287+ gopkg.in/warnings.v0 v0.1.2 // indirect
273288 gopkg.in/yaml.v2 v2.4.0 // indirect
274289 gopkg.in/yaml.v3 v3.0.1 // indirect
275- k8s.io/api v0.24.2 // indirect
276- k8s.io/apimachinery v0.24.3 // indirect
277- k8s.io/client-go v0.24.2 // indirect
290+ k8s.io/api v0.26.1 // indirect
291+ k8s.io/apimachinery v0.26.1 // indirect
292+ k8s.io/client-go v0.26.1 // indirect
278293 k8s.io/klog/v2 v2.80.1 // indirect
279- k8s.io/kube-openapi v0.0.0-20220328201542-3ee0da9b0b42 // indirect
280- k8s.io/utils v0.0.0-20220210201930-3a6ce19ff2f9 // indirect
294+ k8s.io/kube-openapi v0.0.0-20221207184640-f3cff1453715 // indirect
295+ k8s.io/utils v0.0.0-20221128185143-99ec85e7a448 // indirect
281296 mvdan.cc/sh/v3 v3.6.0 // indirect
282- sigs.k8s.io/json v0.0.0-20211208200746-9f7c6b3444d2 // indirect
297+ sigs.k8s.io/json v0.0.0-20221116044647-bc3834ca7abd // indirect
283298 sigs.k8s.io/release-utils v0.7.3 // indirect
284- sigs.k8s.io/structured-merge-diff/v4 v4.2.1 // indirect
299+ sigs.k8s.io/structured-merge-diff/v4 v4.2.3 // indirect
285300 sigs.k8s.io/yaml v1.3.0 // indirect
286301)
0 commit comments