11module github.com/Checkmarx/kics/v2
22
3- go 1.23.6
3+ go 1.23.8
44
55require (
6- code.cloudfoundry.org/bytefmt v0.0.0-20240604172014-5a751eb643b0
7- github.com/BurntSushi/toml v1.4 .0
8- github.com/agnivade/levenshtein v1.1 .1
6+ code.cloudfoundry.org/bytefmt v0.35.0
7+ github.com/BurntSushi/toml v1.5 .0
8+ github.com/agnivade/levenshtein v1.2 .1
99 github.com/alexmullins/zip v0.0.0-20180717182244-4affb64b04d0
1010 github.com/antlr4-go/antlr/v4 v4.13.1
11- github.com/aws/aws-sdk-go-v2 v1.30 .3
11+ github.com/aws/aws-sdk-go-v2 v1.36 .3
1212 github.com/bigkevmcd/go-configparser v0.0.0-20230427073640-c6b631f70126
13- github.com/cheggaaa/pb/v3 v3.1.5
14- github.com/emicklei/proto v1.13.2
13+ github.com/cheggaaa/pb/v3 v3.1.7
14+ github.com/emicklei/proto v1.14.0
1515 github.com/getsentry/sentry-go v0.31.2-0.20250102155933-f2d4348b0508
1616 github.com/gocarina/gocsv v0.0.0-20240520201108-78e41c74b4b1
1717 github.com/golang/mock v1.6.0
18- github.com/google/pprof v0.0.0-20241029153458-d1b30febd7db
18+ github.com/google/pprof v0.0.0-20250317173921-a4b03ec1a45e
1919 github.com/google/uuid v1.6.0
2020 github.com/gookit/color v1.5.4
21- github.com/hashicorp/go-getter v1.7.5
21+ github.com/hashicorp/go-getter v1.7.8
2222 github.com/hashicorp/hcl v1.0.0
23- github.com/hashicorp/hcl/v2 v2.20.1
24- github.com/hashicorp/terraform-json v0.22.1
23+ github.com/hashicorp/hcl/v2 v2.23.0
24+ github.com/hashicorp/terraform-json v0.24.0
2525 github.com/johnfercher/maroto v1.0.0
2626 github.com/mackerelio/go-osstat v0.2.5
27- github.com/moby/buildkit v0.19.0
27+ github.com/moby/buildkit v0.20.2
2828 github.com/open-policy-agent/opa v0.68.0
2929 github.com/pkg/errors v0.9.1
3030 github.com/relex/aini v1.6.0
31- github.com/rs/zerolog v1.33 .0
31+ github.com/rs/zerolog v1.34 .0
3232 github.com/sosedoff/ansible-vault-go v0.2.0
33- github.com/spf13/cobra v1.8 .1
34- github.com/spf13/pflag v1.0.5
35- github.com/spf13/viper v1.19.0
33+ github.com/spf13/cobra v1.9 .1
34+ github.com/spf13/pflag v1.0.6
35+ github.com/spf13/viper v1.20.1
3636 github.com/stretchr/testify v1.10.0
37- github.com/tdewolff/minify/v2 v2.20.32
38- github.com/tidwall/gjson v1.17.1
37+ github.com/tdewolff/minify/v2 v2.22.4
38+ github.com/tidwall/gjson v1.18.0
3939 github.com/xeipuuv/gojsonschema v1.2.0
4040 github.com/yargevad/filepathx v1.0.0
41- github.com/zclconf/go-cty v1.14.4
42- golang.org/x/net v0.36 .0
43- golang.org/x/text v0.22 .0
44- golang.org/x/tools v0.26 .0
41+ github.com/zclconf/go-cty v1.15.1
42+ golang.org/x/net v0.38 .0
43+ golang.org/x/text v0.23 .0
44+ golang.org/x/tools v0.31 .0
4545 gopkg.in/yaml.v3 v3.0.1
46- helm.sh/helm/v3 v3.17.1
47- mvdan.cc/sh/v3 v3.8.0
46+ helm.sh/helm/v3 v3.17.2
47+ mvdan.cc/sh/v3 v3.11.0
48+ sigs.k8s.io/controller-runtime v0.14.6
4849)
4950
5051require (
51- cloud.google.com/go v0.112.1 // indirect
52+ cel.dev/expr v0.19.1 // indirect
53+ cloud.google.com/go v0.116.0 // indirect
54+ cloud.google.com/go/auth v0.13.0 // indirect
55+ cloud.google.com/go/auth/oauth2adapt v0.2.6 // indirect
5256 cloud.google.com/go/compute/metadata v0.6.0 // indirect
53- cloud.google.com/go/iam v1.1.6 // indirect
54- cloud.google.com/go/storage v1.38.0 // indirect
57+ cloud.google.com/go/iam v1.2.2 // indirect
58+ cloud.google.com/go/monitoring v1.21.2 // indirect
59+ cloud.google.com/go/storage v1.49.0 // indirect
5560 dario.cat/mergo v1.0.1 // indirect
5661 github.com/AdaLogics/go-fuzz-headers v0.0.0-20240806141605-e8a1dd7889d6 // indirect
62+ github.com/GoogleCloudPlatform/opentelemetry-operations-go/detectors/gcp v1.25.0 // indirect
63+ github.com/GoogleCloudPlatform/opentelemetry-operations-go/exporter/metric v0.48.1 // indirect
64+ github.com/GoogleCloudPlatform/opentelemetry-operations-go/internal/resourcemapping v0.48.1 // indirect
65+ github.com/OneOfOne/xxhash v1.2.8 // indirect
5766 github.com/apparentlymart/go-textseg/v15 v15.0.0 // indirect
5867 github.com/aws/aws-sdk-go v1.44.295 // indirect
59- github.com/aws/smithy-go v1.20.3 // indirect
68+ github.com/aws/smithy-go v1.22.2 // indirect
6069 github.com/blang/semver/v4 v4.0.0 // indirect
70+ github.com/cncf/xds/go v0.0.0-20241223141626-cff3c89139a3 // indirect
6171 github.com/containerd/errdefs v1.0.0 // indirect
6272 github.com/containerd/log v0.1.0 // indirect
6373 github.com/containerd/platforms v1.0.0-rc.1 // indirect
6474 github.com/containerd/typeurl/v2 v2.2.3 // indirect
6575 github.com/distribution/reference v0.6.0 // indirect
66- github.com/evanphx/json-patch/v5 v5.6.0 // indirect
76+ github.com/envoyproxy/go-control-plane/envoy v1.32.4 // indirect
77+ github.com/envoyproxy/protoc-gen-validate v1.2.1 // indirect
78+ github.com/evanphx/json-patch/v5 v5.9.11 // indirect
6779 github.com/felixge/httpsnoop v1.0.4 // indirect
6880 github.com/fxamacker/cbor/v2 v2.7.0 // indirect
6981 github.com/go-ini/ini v1.67.0 // indirect
7082 github.com/go-logr/stdr v1.2.2 // indirect
83+ github.com/go-viper/mapstructure/v2 v2.2.1 // indirect
7184 github.com/golang/groupcache v0.0.0-20210331224755-41bb18bfe9da // indirect
72- github.com/google/flatbuffers v24.3.25+incompatible // indirect
7385 github.com/google/gnostic-models v0.6.8 // indirect
74- github.com/google/s2a-go v0.1.7 // indirect
75- github.com/googleapis/enterprise-certificate-proxy v0.3.2 // indirect
76- github.com/googleapis/gax-go/v2 v2.12.3 // indirect
86+ github.com/google/s2a-go v0.1.8 // indirect
87+ github.com/googleapis/enterprise-certificate-proxy v0.3.4 // indirect
88+ github.com/googleapis/gax-go/v2 v2.14.1 // indirect
7789 github.com/gorilla/websocket v1.5.3 // indirect
7890 github.com/hashicorp/errwrap v1.1.0 // indirect
7991 github.com/hashicorp/go-multierror v1.1.1 // indirect
@@ -82,38 +94,39 @@ require (
8294 github.com/mxk/go-flowrate v0.0.0-20140419014527-cca7078d478f // indirect
8395 github.com/planetscale/vtprotobuf v0.6.1-0.20240319094008-0393e58bdf10 // indirect
8496 github.com/russross/blackfriday/v2 v2.1.0 // indirect
85- github.com/sagikazarmark/locafero v0.6.0 // indirect
86- github.com/sagikazarmark/slog-shim v0.1.0 // indirect
97+ github.com/sagikazarmark/locafero v0.7.0 // indirect
8798 github.com/samber/lo v1.38.1 // indirect
8899 github.com/sourcegraph/conc v0.3.0 // indirect
89- github.com/tchap/go-patricia/v2 v2.3.1 // indirect
100+ github.com/tchap/go-patricia/v2 v2.3.2 // indirect
90101 github.com/x448/float16 v0.8.4 // indirect
91102 go.opencensus.io v0.24.0 // indirect
92103 go.opentelemetry.io/auto/sdk v1.1.0 // indirect
104+ go.opentelemetry.io/contrib/detectors/gcp v1.34.0 // indirect
93105 go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc v0.56.0 // indirect
94- go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.56.0 // indirect
95- go.opentelemetry.io/otel v1.34.0 // indirect
96- go.opentelemetry.io/otel/metric v1.34.0 // indirect
97- go.opentelemetry.io/otel/sdk v1.34.0 // indirect
98- go.opentelemetry.io/otel/trace v1.34.0 // indirect
106+ go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.60.0 // indirect
107+ go.opentelemetry.io/otel v1.35.0 // indirect
108+ go.opentelemetry.io/otel/metric v1.35.0 // indirect
109+ go.opentelemetry.io/otel/sdk v1.35.0 // indirect
110+ go.opentelemetry.io/otel/sdk/metric v1.35.0 // indirect
111+ go.opentelemetry.io/otel/trace v1.35.0 // indirect
99112 go.uber.org/multierr v1.11.0 // indirect
100- golang.org/x/exp v0.0.0-20240909161429-701f63a606c0 // indirect
101- golang.org/x/mod v0.21 .0 // indirect
102- google.golang.org/api v0.171 .0 // indirect
103- google.golang.org/genproto v0.0.0-20240213162025-012b6fc9bca9 // indirect
104- google.golang.org/genproto/googleapis/api v0.0.0-20250106144421-5f5ef82da422 // indirect
105- google.golang.org/genproto/googleapis/rpc v0.0.0-20250115164207-1a7da9e5054f // indirect
113+ golang.org/x/exp v0.0.0-20241108190413-2d47ceb2692f // indirect
114+ golang.org/x/mod v0.24 .0 // indirect
115+ google.golang.org/api v0.215 .0 // indirect
116+ google.golang.org/genproto v0.0.0-20241118233622-e639e219e697 // indirect
117+ google.golang.org/genproto/googleapis/api v0.0.0-20250218202821-56aae31c358a // indirect
118+ google.golang.org/genproto/googleapis/rpc v0.0.0-20250218202821-56aae31c358a // indirect
106119 gopkg.in/evanphx/json-patch.v4 v4.12.0 // indirect
120+ gopkg.in/yaml.v2 v2.4.0 // indirect
107121)
108122
109123require (
110- github.com/Azure/go-ansiterm v0.0.0-20230124172434-306776ec8161 // indirect
124+ github.com/Azure/go-ansiterm v0.0.0-20250102033503-faa5f7b0171c // indirect
111125 github.com/MakeNowJust/heredoc v1.0.0 // indirect
112126 github.com/Masterminds/goutils v1.1.1 // indirect
113127 github.com/Masterminds/semver/v3 v3.3.0 // indirect
114128 github.com/Masterminds/sprig/v3 v3.3.0 // indirect
115129 github.com/Masterminds/squirrel v1.5.4 // indirect
116- github.com/OneOfOne/xxhash v1.2.8 // indirect
117130 github.com/VividCortex/ewma v1.2.0 // indirect
118131 github.com/agext/levenshtein v1.2.3 // indirect
119132 github.com/asaskevich/govalidator v0.0.0-20230301143203-a9d515a09cc2 // indirect
@@ -125,17 +138,17 @@ require (
125138 github.com/containerd/containerd v1.7.27 // indirect
126139 github.com/cyphar/filepath-securejoin v0.3.6 // indirect
127140 github.com/davecgh/go-spew v1.1.2-0.20180830191138-d8f796af33cc // indirect
128- github.com/docker/cli v27.5.0 +incompatible // indirect
141+ github.com/docker/cli v27.5.1 +incompatible // indirect
129142 github.com/docker/distribution v2.8.3+incompatible // indirect
130- github.com/docker/docker v27.5.0 +incompatible // indirect
143+ github.com/docker/docker v27.5.1 +incompatible // indirect
131144 github.com/docker/docker-credential-helpers v0.8.2 // indirect
132145 github.com/docker/go-connections v0.5.0 // indirect
133146 github.com/docker/go-metrics v0.0.1 // indirect
134147 github.com/emicklei/go-restful/v3 v3.11.0 // indirect
135148 github.com/evanphx/json-patch v5.9.0+incompatible // indirect
136149 github.com/exponent-io/jsonpath v0.0.0-20210407135951-1de76d718b3f // indirect
137- github.com/fatih/color v1.17 .0 // indirect
138- github.com/fsnotify/fsnotify v1.7 .0 // indirect
150+ github.com/fatih/color v1.18 .0 // indirect
151+ github.com/fsnotify/fsnotify v1.8 .0 // indirect
139152 github.com/go-errors/errors v1.4.2 // indirect
140153 github.com/go-gorp/gorp/v3 v3.1.0 // indirect
141154 github.com/go-logr/logr v1.4.2 // indirect
@@ -145,8 +158,8 @@ require (
145158 github.com/gobwas/glob v0.2.3 // indirect
146159 github.com/gogo/protobuf v1.3.2 // indirect
147160 github.com/golang/protobuf v1.5.4 // indirect
148- github.com/google/btree v1.0.1 // indirect
149- github.com/google/go-cmp v0.6 .0 // indirect
161+ github.com/google/btree v1.1.3 // indirect
162+ github.com/google/go-cmp v0.7 .0 // indirect
150163 github.com/google/gofuzz v1.2.0 // indirect
151164 github.com/google/shlex v0.0.0-20191202100458-e7afc7fbc510 // indirect
152165 github.com/gorilla/mux v1.8.1 // indirect
@@ -161,36 +174,34 @@ require (
161174 github.com/josharian/intern v1.0.0 // indirect
162175 github.com/json-iterator/go v1.1.12 // indirect
163176 github.com/jung-kurt/gofpdf v1.16.3-0.20210918000319-0c885ad36193 // indirect
164- github.com/klauspost/compress v1.17.11 // indirect
177+ github.com/klauspost/compress v1.18.0 // indirect
165178 github.com/lann/builder v0.0.0-20180802200727-47ae307949d0 // indirect
166179 github.com/lann/ps v0.0.0-20150810152359-62de8c46ede0 // indirect
167180 github.com/lib/pq v1.10.9 // indirect
168181 github.com/liggitt/tabwriter v0.0.0-20181228230101-89fcab3d43de // indirect
169- github.com/magiconair/properties v1.8.7 // indirect
170- github.com/mattn/go-colorable v0.1.13 // indirect
182+ github.com/mattn/go-colorable v0.1.14 // indirect
171183 github.com/mattn/go-isatty v0.0.20 // indirect
172- github.com/mattn/go-runewidth v0.0.15 // indirect
184+ github.com/mattn/go-runewidth v0.0.16 // indirect
173185 github.com/mitchellh/copystructure v1.2.0 // indirect
174186 github.com/mitchellh/go-homedir v1.1.0 // indirect
175187 github.com/mitchellh/go-testing-interface v1.14.1 // indirect
176188 github.com/mitchellh/go-wordwrap v1.0.1 // indirect
177- github.com/mitchellh/mapstructure v1.5.0 // indirect
178189 github.com/mitchellh/reflectwalk v1.0.2 // indirect
179190 github.com/moby/locker v1.0.1 // indirect
180191 github.com/moby/spdystream v0.5.0 // indirect
181- github.com/moby/term v0.5.0 // indirect
192+ github.com/moby/term v0.5.2 // indirect
182193 github.com/modern-go/concurrent v0.0.0-20180306012644-bacd9c7ef1dd // indirect
183194 github.com/modern-go/reflect2 v1.0.2 // indirect
184195 github.com/monochromegane/go-gitignore v0.0.0-20200626010858-205db1a8cc00 // indirect
185196 github.com/munnerz/goautoneg v0.0.0-20191010083416-a7dc8b61c822 // indirect
186197 github.com/opencontainers/go-digest v1.0.0 // indirect
187- github.com/opencontainers/image-spec v1.1.0 // indirect
188- github.com/pelletier/go-toml/v2 v2.2.2 // indirect
198+ github.com/opencontainers/image-spec v1.1.1 // indirect
199+ github.com/pelletier/go-toml/v2 v2.2.3 // indirect
189200 github.com/peterbourgon/diskv v2.0.1+incompatible // indirect
190201 github.com/pmezard/go-difflib v1.0.1-0.20181226105442-5d4384ee4fb2 // indirect
191- github.com/prometheus/client_golang v1.20.5 // indirect
202+ github.com/prometheus/client_golang v1.21.1 // indirect
192203 github.com/prometheus/client_model v0.6.1 // indirect
193- github.com/prometheus/common v0.55 .0 // indirect
204+ github.com/prometheus/common v0.62 .0 // indirect
194205 github.com/prometheus/procfs v0.15.1 // indirect
195206 github.com/rcrowley/go-metrics v0.0.0-20201227073835-cf1acfcdf475 // indirect
196207 github.com/rivo/uniseg v0.4.7 // indirect
@@ -199,10 +210,10 @@ require (
199210 github.com/sabhiram/go-gitignore v0.0.0-20210923224102-525f6e181f06
200211 github.com/shopspring/decimal v1.4.0 // indirect
201212 github.com/sirupsen/logrus v1.9.3 // indirect
202- github.com/spf13/afero v1.11 .0 // indirect
203- github.com/spf13/cast v1.7.0 // indirect
213+ github.com/spf13/afero v1.12 .0 // indirect
214+ github.com/spf13/cast v1.7.1 // indirect
204215 github.com/subosito/gotenv v1.6.0 // indirect
205- github.com/tdewolff/parse/v2 v2.7.14 // indirect
216+ github.com/tdewolff/parse/v2 v2.7.21 // indirect
206217 github.com/tidwall/match v1.1.1 // indirect
207218 github.com/tidwall/pretty v1.2.1 // indirect
208219 github.com/ulikunitz/xz v0.5.11 // indirect
@@ -211,30 +222,27 @@ require (
211222 github.com/xlab/treeprint v1.2.0 // indirect
212223 github.com/xo/terminfo v0.0.0-20210125001918-ca9a967f8778 // indirect
213224 github.com/yashtewari/glob-intersection v0.2.0 // indirect
214- golang.org/x/crypto v0.35 .0 // indirect
225+ golang.org/x/crypto v0.36 .0 // indirect
215226 golang.org/x/oauth2 v0.27.0 // indirect
216- golang.org/x/sync v0.11 .0 // indirect
217- golang.org/x/sys v0.30 .0 // indirect
218- golang.org/x/term v0.29 .0 // indirect
219- golang.org/x/time v0.7 .0 // indirect
227+ golang.org/x/sync v0.12 .0 // indirect
228+ golang.org/x/sys v0.31 .0 // indirect
229+ golang.org/x/term v0.30 .0 // indirect
230+ golang.org/x/time v0.11 .0 // indirect
220231 google.golang.org/grpc v1.71.0 // indirect
221- google.golang.org/protobuf v1.36.4 // indirect
232+ google.golang.org/protobuf v1.36.5 // indirect
222233 gopkg.in/inf.v0 v0.9.1 // indirect
223- gopkg.in/ini.v1 v1.67.0 // indirect
224- gopkg.in/yaml.v2 v2.4.0 // indirect
225- k8s.io/api v0.32.1
226- k8s.io/apiextensions-apiserver v0.32.1 // indirect
227- k8s.io/apimachinery v0.32.1
228- k8s.io/apiserver v0.32.1 // indirect
229- k8s.io/cli-runtime v0.32.1 // indirect
230- k8s.io/client-go v0.32.1
231- k8s.io/component-base v0.32.1 // indirect
234+ k8s.io/api v0.32.2
235+ k8s.io/apiextensions-apiserver v0.32.2 // indirect
236+ k8s.io/apimachinery v0.32.2
237+ k8s.io/apiserver v0.32.2 // indirect
238+ k8s.io/cli-runtime v0.32.2 // indirect
239+ k8s.io/client-go v0.32.2
240+ k8s.io/component-base v0.32.2 // indirect
232241 k8s.io/klog/v2 v2.130.1 // indirect
233242 k8s.io/kube-openapi v0.0.0-20241105132330-32ad38e42d3f // indirect
234- k8s.io/kubectl v0.32.1 // indirect
243+ k8s.io/kubectl v0.32.2 // indirect
235244 k8s.io/utils v0.0.0-20241104100929-3ea5e8cea738 // indirect
236245 oras.land/oras-go v1.2.5 // indirect
237- sigs.k8s.io/controller-runtime v0.14.6
238246 sigs.k8s.io/json v0.0.0-20241010143419-9aa6b5e7a4b3 // indirect
239247 sigs.k8s.io/kustomize/api v0.18.0 // indirect
240248 sigs.k8s.io/kustomize/kyaml v0.18.1 // indirect
0 commit comments