Skip to content

Commit 48d3449

Browse files
committed
chore: Update dependencies
1 parent 71bd8f1 commit 48d3449

File tree

4 files changed

+124
-200
lines changed

4 files changed

+124
-200
lines changed

.github/workflows/ci.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -53,7 +53,7 @@ jobs:
5353
# https://github.com/sonatype-nexus-community/nancy-github-action
5454
- name: Scan dependencies
5555
if: ${{ !contains(env.commit_msg, '[skip scan-deps]') }}
56-
uses: sonatype-nexus-community/nancy-github-action@v1.0.2
56+
uses: sonatype-nexus-community/nancy-github-action@v1.0.3
5757

5858
# Scan for leaked secrets
5959
# Can be excluded if the commit message contains: [skip scan-secrets]

Makefile

Lines changed: 6 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -96,16 +96,15 @@ release:
9696
## scan-deps: Look for known vulnerabilities in the project dependencies
9797
# https://github.com/sonatype-nexus-community/nancy
9898
scan-deps:
99-
@go list -mod=readonly -f '{{if not .Indirect}}{{.}}{{end}}' -m all | nancy sleuth --skip-update-check
99+
@go list -json -deps ./... | nancy sleuth --skip-update-check
100100

101101
## scan-secrets: Scan project code for accidentally leaked secrets
102+
# https://github.com/trufflesecurity/trufflehog
102103
scan-secrets:
103-
@docker run --platform linux/amd64 --rm \
104-
-v $(shell pwd):/proj \
105-
dxa4481/trufflehog file:///proj \
106-
-x .exclude-secrets-scan.txt \
107-
--regex \
108-
--entropy false
104+
@docker run -it --rm --platform linux/arm64 \
105+
-v "$PWD:/repo" \
106+
trufflesecurity/trufflehog:latest \
107+
filesystem --directory /repo --only-verified
109108

110109
## test: Run unit tests excluding the vendor dependencies
111110
test:

go.mod

Lines changed: 36 additions & 35 deletions
Original file line numberDiff line numberDiff line change
@@ -3,21 +3,21 @@ module github.com/bryk-io/serve
33
go 1.18
44

55
require (
6-
github.com/spf13/cobra v1.6.1
6+
github.com/spf13/cobra v1.7.0
77
github.com/spf13/viper v1.15.0
8-
go.bryk.io/pkg v0.0.0-20230324162805-f7d468209364
8+
go.bryk.io/pkg v0.0.0-20230517170105-89a1e74b9a96
99
)
1010

1111
require (
1212
github.com/beorn7/perks v1.0.1 // indirect
1313
github.com/briandowns/spinner v1.23.0 // indirect
14-
github.com/cenkalti/backoff/v4 v4.2.0 // indirect
14+
github.com/cenkalti/backoff/v4 v4.2.1 // indirect
1515
github.com/cespare/xxhash/v2 v2.2.0 // indirect
1616
github.com/fatih/color v1.13.0 // indirect
1717
github.com/felixge/httpsnoop v1.0.3 // indirect
1818
github.com/fsnotify/fsnotify v1.6.0 // indirect
19-
github.com/getsentry/sentry-go v0.19.0 // indirect
20-
github.com/go-logr/logr v1.2.3 // indirect
19+
github.com/getsentry/sentry-go v0.21.0 // indirect
20+
github.com/go-logr/logr v1.2.4 // indirect
2121
github.com/go-logr/stdr v1.2.2 // indirect
2222
github.com/go-ole/go-ole v1.2.6 // indirect
2323
github.com/golang/protobuf v1.5.3 // indirect
@@ -27,7 +27,7 @@ require (
2727
github.com/grpc-ecosystem/go-grpc-prometheus v1.2.0 // indirect
2828
github.com/grpc-ecosystem/grpc-gateway/v2 v2.15.2 // indirect
2929
github.com/hashicorp/hcl v1.0.0 // indirect
30-
github.com/inconshreveable/mousetrap v1.0.1 // indirect
30+
github.com/inconshreveable/mousetrap v1.1.0 // indirect
3131
github.com/lufia/plan9stats v0.0.0-20211012122336-39d0f177ccd0 // indirect
3232
github.com/magiconair/properties v1.8.7 // indirect
3333
github.com/mattn/go-colorable v0.1.13 // indirect
@@ -36,13 +36,14 @@ require (
3636
github.com/mitchellh/mapstructure v1.5.0 // indirect
3737
github.com/pelletier/go-toml/v2 v2.0.6 // indirect
3838
github.com/power-devops/perfstat v0.0.0-20210106213030-5aafc221ea8c // indirect
39-
github.com/prometheus/client_golang v1.14.0 // indirect
40-
github.com/prometheus/client_model v0.3.0 // indirect
41-
github.com/prometheus/common v0.37.0 // indirect
42-
github.com/prometheus/procfs v0.8.0 // indirect
43-
github.com/rs/zerolog v1.29.0 // indirect
44-
github.com/shirou/gopsutil/v3 v3.23.1 // indirect
45-
github.com/sirupsen/logrus v1.9.0 // indirect
39+
github.com/prometheus/client_golang v1.15.1 // indirect
40+
github.com/prometheus/client_model v0.4.0 // indirect
41+
github.com/prometheus/common v0.42.0 // indirect
42+
github.com/prometheus/procfs v0.9.0 // indirect
43+
github.com/rs/zerolog v1.29.1 // indirect
44+
github.com/shirou/gopsutil/v3 v3.23.3 // indirect
45+
github.com/shoenig/go-m1cpu v0.1.4 // indirect
46+
github.com/sirupsen/logrus v1.9.1 // indirect
4647
github.com/soheilhy/cmux v0.1.5 // indirect
4748
github.com/spf13/afero v1.9.3 // indirect
4849
github.com/spf13/cast v1.5.0 // indirect
@@ -52,33 +53,33 @@ require (
5253
github.com/tklauser/go-sysconf v0.3.11 // indirect
5354
github.com/tklauser/numcpus v0.6.0 // indirect
5455
github.com/yusufpapurcu/wmi v1.2.2 // indirect
55-
go.opentelemetry.io/contrib/instrumentation/host v0.40.0 // indirect
56-
go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.40.0 // indirect
57-
go.opentelemetry.io/contrib/instrumentation/runtime v0.40.0 // indirect
58-
go.opentelemetry.io/otel v1.14.0 // indirect
59-
go.opentelemetry.io/otel/exporters/otlp/internal/retry v1.14.0 // indirect
60-
go.opentelemetry.io/otel/exporters/otlp/otlpmetric v0.37.0 // indirect
61-
go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetricgrpc v0.37.0 // indirect
62-
go.opentelemetry.io/otel/exporters/otlp/otlptrace v1.14.0 // indirect
63-
go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc v1.14.0 // indirect
64-
go.opentelemetry.io/otel/exporters/stdout/stdoutmetric v0.37.0 // indirect
65-
go.opentelemetry.io/otel/exporters/stdout/stdouttrace v1.14.0 // indirect
66-
go.opentelemetry.io/otel/metric v0.37.0 // indirect
67-
go.opentelemetry.io/otel/sdk v1.14.0 // indirect
68-
go.opentelemetry.io/otel/sdk/metric v0.37.0 // indirect
69-
go.opentelemetry.io/otel/trace v1.14.0 // indirect
56+
go.opentelemetry.io/contrib/instrumentation/host v0.41.1 // indirect
57+
go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.41.1 // indirect
58+
go.opentelemetry.io/contrib/instrumentation/runtime v0.41.1 // indirect
59+
go.opentelemetry.io/otel v1.15.1 // indirect
60+
go.opentelemetry.io/otel/exporters/otlp/internal/retry v1.15.1 // indirect
61+
go.opentelemetry.io/otel/exporters/otlp/otlpmetric v0.38.1 // indirect
62+
go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetricgrpc v0.38.1 // indirect
63+
go.opentelemetry.io/otel/exporters/otlp/otlptrace v1.15.1 // indirect
64+
go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc v1.15.1 // indirect
65+
go.opentelemetry.io/otel/exporters/stdout/stdoutmetric v0.38.1 // indirect
66+
go.opentelemetry.io/otel/exporters/stdout/stdouttrace v1.15.1 // indirect
67+
go.opentelemetry.io/otel/metric v0.38.1 // indirect
68+
go.opentelemetry.io/otel/sdk v1.15.1 // indirect
69+
go.opentelemetry.io/otel/sdk/metric v0.38.1 // indirect
70+
go.opentelemetry.io/otel/trace v1.15.1 // indirect
7071
go.opentelemetry.io/proto/otlp v0.19.0 // indirect
7172
go.uber.org/atomic v1.9.0 // indirect
7273
go.uber.org/multierr v1.8.0 // indirect
7374
go.uber.org/zap v1.24.0 // indirect
74-
golang.org/x/net v0.8.0 // indirect
75-
golang.org/x/sync v0.1.0 // indirect
76-
golang.org/x/sys v0.6.0 // indirect
77-
golang.org/x/term v0.6.0 // indirect
78-
golang.org/x/text v0.8.0 // indirect
75+
golang.org/x/net v0.10.0 // indirect
76+
golang.org/x/sync v0.2.0 // indirect
77+
golang.org/x/sys v0.8.0 // indirect
78+
golang.org/x/term v0.8.0 // indirect
79+
golang.org/x/text v0.9.0 // indirect
7980
golang.org/x/time v0.3.0 // indirect
80-
google.golang.org/genproto v0.0.0-20230223222841-637eb2293923 // indirect
81-
google.golang.org/grpc v1.54.0 // indirect
81+
google.golang.org/genproto v0.0.0-20230306155012-7f2fa6fef1f4 // indirect
82+
google.golang.org/grpc v1.55.0 // indirect
8283
google.golang.org/protobuf v1.30.0 // indirect
8384
gopkg.in/ini.v1 v1.67.0 // indirect
8485
gopkg.in/yaml.v3 v3.0.1 // indirect

0 commit comments

Comments
 (0)