@@ -6,36 +6,36 @@ require (
66 github.com/caarlos0/env/v6 v6.10.1
77 github.com/google/go-cmp v0.5.9
88 github.com/google/go-github/v46 v46.0.0
9- github.com/ossf/scorecard/v4 v4.10.5
10- github.com/sigstore/cosign/v2 v2.0.2
9+ github.com/ossf/scorecard/v4 v4.11.0
10+ github.com/sigstore/cosign/v2 v2.0.3-0.20230517070756-fc61f43262cb
1111 github.com/spf13/cobra v1.7.0
1212 golang.org/x/net v0.11.0
1313)
1414
1515require (
16- cloud.google.com/go v0.110.0 // indirect
17- cloud.google.com/go/compute v1.19 .0 // indirect
16+ cloud.google.com/go v0.110.2 // indirect
17+ cloud.google.com/go/compute v1.20 .0 // indirect
1818 cloud.google.com/go/compute/metadata v0.2.3 // indirect
19- cloud.google.com/go/iam v0.13 .0 // indirect
20- cloud.google.com/go/storage v1.29.0 // indirect
19+ cloud.google.com/go/iam v1.1 .0 // indirect
20+ cloud.google.com/go/storage v1.30.1 // indirect
2121 filippo.io/edwards25519 v1.0.0 // indirect
2222 github.com/AliyunContainerService/ack-ram-tool/pkg/credentials/alibabacloudsdkgo/helper v0.2.0 // indirect
2323 github.com/Azure/azure-sdk-for-go v68.0.0+incompatible // indirect
2424 github.com/Azure/go-autorest v14.2.0+incompatible // indirect
2525 github.com/Azure/go-autorest/autorest v0.11.29 // indirect
26- github.com/Azure/go-autorest/autorest/adal v0.9.22 // indirect
26+ github.com/Azure/go-autorest/autorest/adal v0.9.23 // indirect
2727 github.com/Azure/go-autorest/autorest/azure/auth v0.5.12 // indirect
2828 github.com/Azure/go-autorest/autorest/azure/cli v0.4.6 // indirect
2929 github.com/Azure/go-autorest/autorest/date v0.3.0 // indirect
3030 github.com/Azure/go-autorest/logger v0.2.1 // indirect
3131 github.com/Azure/go-autorest/tracing v0.6.0 // indirect
32- github.com/BurntSushi/toml v1.2.1 // indirect
33- github.com/CycloneDX/cyclonedx-go v0.7.0 // indirect
32+ github.com/BurntSushi/toml v1.3.0 // indirect
33+ github.com/CycloneDX/cyclonedx-go v0.7.1 // indirect
3434 github.com/Masterminds/semver/v3 v3.2.1 // indirect
35- github.com/Microsoft/go-winio v0.6.0 // indirect
36- github.com/ProtonMail/go-crypto v0.0.0-20230217124315-7d5c6f04bbb8 // indirect
35+ github.com/Microsoft/go-winio v0.6.1 // indirect
36+ github.com/ProtonMail/go-crypto v0.0.0-20230518184743-7afd39499903 // indirect
3737 github.com/ThalesIgnite/crypto11 v1.2.5 // indirect
38- github.com/acomagu/bufpipe v1.0.3 // indirect
38+ github.com/acomagu/bufpipe v1.0.4 // indirect
3939 github.com/alibabacloud-go/alibabacloud-gateway-spi v0.0.4 // indirect
4040 github.com/alibabacloud-go/cr-20160607 v1.0.1 // indirect
4141 github.com/alibabacloud-go/cr-20181201 v1.0.10 // indirect
@@ -47,26 +47,27 @@ require (
4747 github.com/alibabacloud-go/tea-utils v1.4.4 // indirect
4848 github.com/alibabacloud-go/tea-xml v1.1.2 // indirect
4949 github.com/aliyun/credentials-go v1.2.3 // indirect
50+ github.com/anchore/go-struct-converter v0.0.0-20221118182256-c68fdcfa2092 // indirect
5051 github.com/asaskevich/govalidator v0.0.0-20230301143203-a9d515a09cc2 // indirect
51- github.com/aws/aws-sdk-go-v2 v1.18.0 // indirect
52- github.com/aws/aws-sdk-go-v2/config v1.18.23 // indirect
53- github.com/aws/aws-sdk-go-v2/credentials v1.13.22 // indirect
54- github.com/aws/aws-sdk-go-v2/feature/ec2/imds v1.13.3 // indirect
55- github.com/aws/aws-sdk-go-v2/internal/configsources v1.1.33 // indirect
56- github.com/aws/aws-sdk-go-v2/internal/endpoints/v2 v2.4.27 // indirect
57- github.com/aws/aws-sdk-go-v2/internal/ini v1.3.34 // indirect
52+ github.com/aws/aws-sdk-go-v2 v1.18.1 // indirect
53+ github.com/aws/aws-sdk-go-v2/config v1.18.27 // indirect
54+ github.com/aws/aws-sdk-go-v2/credentials v1.13.26 // indirect
55+ github.com/aws/aws-sdk-go-v2/feature/ec2/imds v1.13.4 // indirect
56+ github.com/aws/aws-sdk-go-v2/internal/configsources v1.1.34 // indirect
57+ github.com/aws/aws-sdk-go-v2/internal/endpoints/v2 v2.4.28 // indirect
58+ github.com/aws/aws-sdk-go-v2/internal/ini v1.3.35 // indirect
5859 github.com/aws/aws-sdk-go-v2/service/ecr v1.15.0 // indirect
5960 github.com/aws/aws-sdk-go-v2/service/ecrpublic v1.12.0 // indirect
60- github.com/aws/aws-sdk-go-v2/service/internal/presigned-url v1.9.27 // indirect
61- github.com/aws/aws-sdk-go-v2/service/sso v1.12.10 // indirect
62- github.com/aws/aws-sdk-go-v2/service/ssooidc v1.14.10 // indirect
63- github.com/aws/aws-sdk-go-v2/service/sts v1.18.11 // indirect
61+ github.com/aws/aws-sdk-go-v2/service/internal/presigned-url v1.9.28 // indirect
62+ github.com/aws/aws-sdk-go-v2/service/sso v1.12.12 // indirect
63+ github.com/aws/aws-sdk-go-v2/service/ssooidc v1.14.12 // indirect
64+ github.com/aws/aws-sdk-go-v2/service/sts v1.19.2 // indirect
6465 github.com/aws/smithy-go v1.13.5 // indirect
6566 github.com/awslabs/amazon-ecr-credential-helper/ecr-login v0.0.0-20220228164355-396b2034c795 // indirect
6667 github.com/blang/semver v3.5.1+incompatible // indirect
6768 github.com/bombsimon/logrusr/v2 v2.0.1 // indirect
68- github.com/bradleyfalzon/ghinstallation/v2 v2.1 .0 // indirect
69- github.com/buildkite/agent/v3 v3.45.0 // indirect
69+ github.com/bradleyfalzon/ghinstallation/v2 v2.5 .0 // indirect
70+ github.com/buildkite/agent/v3 v3.46.1 // indirect
7071 github.com/chrismellard/docker-credential-acr-env v0.0.0-20220119192733-fe33c00cee21 // indirect
7172 github.com/clbanning/mxj/v2 v2.5.6 // indirect
7273 github.com/cloudflare/circl v1.3.3 // indirect
@@ -79,26 +80,26 @@ require (
7980 github.com/digitorus/pkcs7 v0.0.0-20221212123742-001c36b64ec3 // indirect
8081 github.com/digitorus/timestamp v0.0.0-20221019182153-ef3b63b79b31 // indirect
8182 github.com/dimchansky/utfbom v1.1.1 // indirect
82- github.com/docker/cli v23.0.1 +incompatible // indirect
83+ github.com/docker/cli v23.0.5 +incompatible // indirect
8384 github.com/docker/distribution v2.8.2+incompatible // indirect
84- github.com/docker/docker v23.0.3 +incompatible // indirect
85+ github.com/docker/docker v23.0.5 +incompatible // indirect
8586 github.com/docker/docker-credential-helpers v0.7.0 // indirect
86- github.com/emicklei/go-restful/v3 v3.9.0 // indirect
87+ github.com/emicklei/go-restful/v3 v3.10.1 // indirect
8788 github.com/emirpasic/gods v1.18.1 // indirect
88- github.com/fatih/color v1.13.0 // indirect
89+ github.com/fatih/color v1.14.1 // indirect
8990 github.com/fsnotify/fsnotify v1.6.0 // indirect
9091 github.com/gabriel-vasile/mimetype v1.4.2 // indirect
9192 github.com/go-chi/chi v4.1.2+incompatible // indirect
92- github.com/go-git/gcfg v1.5.0 // indirect
93+ github.com/go-git/gcfg v1.5.1-0.20230307220236-3a3c6141e376 // indirect
9394 github.com/go-git/go-billy/v5 v5.4.1 // indirect
94- github.com/go-git/go-git/v5 v5.6 .0 // indirect
95+ github.com/go-git/go-git/v5 v5.7 .0 // indirect
9596 github.com/go-jose/go-jose/v3 v3.0.0 // indirect
9697 github.com/go-logr/logr v1.2.4 // indirect
9798 github.com/go-logr/stdr v1.2.2 // indirect
9899 github.com/go-openapi/analysis v0.21.4 // indirect
99100 github.com/go-openapi/errors v0.20.3 // indirect
100- github.com/go-openapi/jsonpointer v0.19.5 // indirect
101- github.com/go-openapi/jsonreference v0.20.0 // indirect
101+ github.com/go-openapi/jsonpointer v0.19.6 // indirect
102+ github.com/go-openapi/jsonreference v0.20.2 // indirect
102103 github.com/go-openapi/loads v0.21.2 // indirect
103104 github.com/go-openapi/runtime v0.26.0 // indirect
104105 github.com/go-openapi/spec v0.20.9 // indirect
@@ -115,26 +116,26 @@ require (
115116 github.com/golang/mock v1.6.0 // indirect
116117 github.com/golang/protobuf v1.5.3 // indirect
117118 github.com/golang/snappy v0.0.4 // indirect
118- github.com/google/certificate-transparency-go v1.1.4 // indirect
119- github.com/google/gnostic v0.5.7-v3refs // indirect
120- github.com/google/go-containerregistry v0.14.1-0.20230409045903-ed5c185df419 // indirect
119+ github.com/google/certificate-transparency-go v1.1.6 // indirect
120+ github.com/google/gnostic v0.6.9 // indirect
121+ github.com/google/go-containerregistry v0.15.2 // indirect
121122 github.com/google/go-github/v38 v38.1.0 // indirect
122- github.com/google/go-github/v45 v45.2.0 // indirect
123123 github.com/google/go-github/v50 v50.2.0 // indirect
124+ github.com/google/go-github/v53 v53.0.0 // indirect
124125 github.com/google/go-querystring v1.1.0 // indirect
125126 github.com/google/gofuzz v1.2.0 // indirect
126- github.com/google/osv-scanner v1.2.1-0.20230314051001-c147987006ff // indirect
127- github.com/google/s2a-go v0.1.3 // indirect
127+ github.com/google/osv-scanner v1.3.4 // indirect
128+ github.com/google/s2a-go v0.1.4 // indirect
128129 github.com/google/trillian v1.5.2 // indirect
129130 github.com/google/uuid v1.3.0 // indirect
130131 github.com/google/wire v0.5.0 // indirect
131- github.com/googleapis/enterprise-certificate-proxy v0.2.3 // indirect
132- github.com/googleapis/gax-go/v2 v2.8 .0 // indirect
132+ github.com/googleapis/enterprise-certificate-proxy v0.2.5 // indirect
133+ github.com/googleapis/gax-go/v2 v2.11 .0 // indirect
133134 github.com/h2non/filetype v1.1.3 // indirect
134135 github.com/hashicorp/go-cleanhttp v0.5.2 // indirect
135136 github.com/hashicorp/go-retryablehttp v0.7.2 // indirect
136137 github.com/hashicorp/hcl v1.0.0 // indirect
137- github.com/imdario/mergo v0.3.13 // indirect
138+ github.com/imdario/mergo v0.3.15 // indirect
138139 github.com/in-toto/in-toto-golang v0.9.0 // indirect
139140 github.com/inconshreveable/mousetrap v1.1.0 // indirect
140141 github.com/jbenet/go-context v0.0.0-20150711004518-d14ea06fba99 // indirect
@@ -144,26 +145,26 @@ require (
144145 github.com/josharian/intern v1.0.0 // indirect
145146 github.com/json-iterator/go v1.1.12 // indirect
146147 github.com/kevinburke/ssh_config v1.2.0 // indirect
147- github.com/klauspost/compress v1.16.0 // indirect
148+ github.com/klauspost/compress v1.16.5 // indirect
148149 github.com/leodido/go-urn v1.2.4 // indirect
149150 github.com/letsencrypt/boulder v0.0.0-20221109233200-85aa52084eaf // indirect
150151 github.com/magiconair/properties v1.8.7 // indirect
151152 github.com/mailru/easyjson v0.7.7 // indirect
152153 github.com/mattn/go-colorable v0.1.13 // indirect
153- github.com/mattn/go-isatty v0.0.16 // indirect
154+ github.com/mattn/go-isatty v0.0.17 // indirect
154155 github.com/mattn/go-runewidth v0.0.14 // indirect
155156 github.com/miekg/pkcs11 v1.1.1 // indirect
156157 github.com/mitchellh/go-homedir v1.1.0 // indirect
157158 github.com/mitchellh/mapstructure v1.5.0 // indirect
158- github.com/moby/buildkit v0.11.4 // indirect
159+ github.com/moby/buildkit v0.11.6 // indirect
159160 github.com/modern-go/concurrent v0.0.0-20180306012644-bacd9c7ef1dd // indirect
160161 github.com/modern-go/reflect2 v1.0.2 // indirect
161162 github.com/mozillazg/docker-credential-acr-helper v0.3.0 // indirect
162163 github.com/munnerz/goautoneg v0.0.0-20191010083416-a7dc8b61c822 // indirect
163164 github.com/oklog/ulid v1.3.1 // indirect
164165 github.com/olekukonko/tablewriter v0.0.5 // indirect
165166 github.com/opencontainers/go-digest v1.0.0 // indirect
166- github.com/opencontainers/image-spec v1.1.0-rc2 // indirect
167+ github.com/opencontainers/image-spec v1.1.0-rc3 // indirect
167168 github.com/opentracing/opentracing-go v1.2.0 // indirect
168169 github.com/package-url/packageurl-go v0.1.1-0.20220428063043-89078438f170 // indirect
169170 github.com/pborman/uuid v1.2.1 // indirect
@@ -176,20 +177,20 @@ require (
176177 github.com/sassoftware/relic v7.2.1+incompatible // indirect
177178 github.com/secure-systems-lab/go-securesystemslib v0.6.0 // indirect
178179 github.com/segmentio/ksuid v1.0.4 // indirect
179- github.com/sergi/go-diff v1.2.0 // indirect
180+ github.com/sergi/go-diff v1.3.1 // indirect
180181 github.com/shibumi/go-pathspec v1.3.0 // indirect
181182 github.com/shurcooL/githubv4 v0.0.0-20221203213311-70889c5dac07 // indirect
182183 github.com/shurcooL/graphql v0.0.0-20220606043923-3cf50f8a0a29 // indirect
183- github.com/sigstore/fulcio v1.2.0 // indirect
184+ github.com/sigstore/fulcio v1.3.1 // indirect
184185 github.com/sigstore/protobuf-specs v0.1.0 // indirect
185186 github.com/sigstore/rekor v1.2.0 // indirect
186187 github.com/sigstore/sigstore v1.6.4 // indirect
187- github.com/sigstore/timestamp-authority v1.0.0 // indirect
188- github.com/sirupsen/logrus v1.9.0 // indirect
189- github.com/skeema/knownhosts v1.1.0 // indirect
188+ github.com/sigstore/timestamp-authority v1.1.1 // indirect
189+ github.com/sirupsen/logrus v1.9.3 // indirect
190+ github.com/skeema/knownhosts v1.1.1 // indirect
190191 github.com/skratchdot/open-golang v0.0.0-20200116055534-eef842397966 // indirect
191192 github.com/spdx/gordf v0.0.0-20221230105357-b735bd5aac89 // indirect
192- github.com/spdx/tools-golang v0.4.0 // indirect
193+ github.com/spdx/tools-golang v0.5.1 // indirect
193194 github.com/spf13/afero v1.9.3 // indirect
194195 github.com/spf13/cast v1.5.0 // indirect
195196 github.com/spf13/jwalterweatherman v1.1.0 // indirect
@@ -203,35 +204,37 @@ require (
203204 github.com/titanous/rocacheck v0.0.0-20171023193734-afe73141d399 // indirect
204205 github.com/tjfoc/gmsm v1.3.2 // indirect
205206 github.com/transparency-dev/merkle v0.0.2 // indirect
206- github.com/vbatts/tar-split v0.11.2 // indirect
207- github.com/xanzy/go-gitlab v0.83 .0 // indirect
207+ github.com/vbatts/tar-split v0.11.3 // indirect
208+ github.com/xanzy/go-gitlab v0.86 .0 // indirect
208209 github.com/xanzy/ssh-agent v0.3.3 // indirect
209210 github.com/zeebo/errs v1.3.0 // indirect
210211 go.mongodb.org/mongo-driver v1.11.3 // indirect
211212 go.opencensus.io v0.24.0 // indirect
212- go.opentelemetry.io/otel v1.14 .0 // indirect
213- go.opentelemetry.io/otel/trace v1.14 .0 // indirect
213+ go.opentelemetry.io/otel v1.15 .0 // indirect
214+ go.opentelemetry.io/otel/trace v1.15 .0 // indirect
214215 go.step.sm/crypto v0.30.0 // indirect
215- go.uber.org/atomic v1.10 .0 // indirect
216- go.uber.org/multierr v1.9 .0 // indirect
216+ go.uber.org/atomic v1.11 .0 // indirect
217+ go.uber.org/multierr v1.11 .0 // indirect
217218 go.uber.org/zap v1.24.0 // indirect
218- gocloud.dev v0.29 .0 // indirect
219+ gocloud.dev v0.30 .0 // indirect
219220 golang.org/x/crypto v0.10.0 // indirect
220- golang.org/x/exp v0.0.0-20230321023759-10a507213a29 // indirect
221- golang.org/x/mod v0.10 .0 // indirect
222- golang.org/x/oauth2 v0.7 .0 // indirect
223- golang.org/x/sync v0.2 .0 // indirect
221+ golang.org/x/exp v0.0.0-20230522175609-2e198f4a06a1 // indirect
222+ golang.org/x/mod v0.11 .0 // indirect
223+ golang.org/x/oauth2 v0.9 .0 // indirect
224+ golang.org/x/sync v0.3 .0 // indirect
224225 golang.org/x/sys v0.9.0 // indirect
225226 golang.org/x/term v0.9.0 // indirect
226227 golang.org/x/text v0.10.0 // indirect
227228 golang.org/x/time v0.3.0 // indirect
228- golang.org/x/tools v0.8 .0 // indirect
229+ golang.org/x/tools v0.10 .0 // indirect
229230 golang.org/x/vuln v0.0.0-20230303230808-d3042fecc4e3 // indirect
230231 golang.org/x/xerrors v0.0.0-20220907171357-04be3eba64a2 // indirect
231- google.golang.org/api v0.121 .0 // indirect
232+ google.golang.org/api v0.128 .0 // indirect
232233 google.golang.org/appengine v1.6.7 // indirect
233- google.golang.org/genproto v0.0.0-20230410155749-daa745c078e1 // indirect
234- google.golang.org/grpc v1.55.0 // indirect
234+ google.golang.org/genproto v0.0.0-20230530153820-e85fd2cbaebc // indirect
235+ google.golang.org/genproto/googleapis/api v0.0.0-20230530153820-e85fd2cbaebc // indirect
236+ google.golang.org/genproto/googleapis/rpc v0.0.0-20230530153820-e85fd2cbaebc // indirect
237+ google.golang.org/grpc v1.56.0 // indirect
235238 google.golang.org/protobuf v1.30.0 // indirect
236239 gopkg.in/inf.v0 v0.9.1 // indirect
237240 gopkg.in/ini.v1 v1.67.0 // indirect
@@ -240,13 +243,13 @@ require (
240243 gopkg.in/yaml.v2 v2.4.0 // indirect
241244 gopkg.in/yaml.v3 v3.0.1 // indirect
242245 gotest.tools/v3 v3.1.0 // indirect
243- k8s.io/api v0.26.1 // indirect
244- k8s.io/apimachinery v0.26.1 // indirect
245- k8s.io/client-go v0.26.1 // indirect
246+ k8s.io/api v0.26.3 // indirect
247+ k8s.io/apimachinery v0.26.3 // indirect
248+ k8s.io/client-go v0.26.2 // indirect
246249 k8s.io/klog/v2 v2.100.1 // indirect
247- k8s.io/kube-openapi v0.0.0-20221207184640-f3cff1453715 // indirect
248- k8s.io/utils v0.0.0-20230115233650-391b47cb4029 // indirect
249- mvdan.cc/sh/v3 v3.6 .0 // indirect
250+ k8s.io/kube-openapi v0.0.0-20230303024457-afdc3dddf62d // indirect
251+ k8s.io/utils v0.0.0-20230406110748-d93618cff8a2 // indirect
252+ mvdan.cc/sh/v3 v3.7 .0 // indirect
250253 sigs.k8s.io/json v0.0.0-20221116044647-bc3834ca7abd // indirect
251254 sigs.k8s.io/release-utils v0.7.4 // indirect
252255 sigs.k8s.io/structured-merge-diff/v4 v4.2.3 // indirect
0 commit comments