@@ -4,15 +4,15 @@ go 1.20
44
55require (
66 code.cloudfoundry.org/bytefmt v0.0.0-20211005130812-5bb3c17173e5
7- cuelang.org/go v0.4.3
7+ cuelang.org/go v0.5.0
88 entgo.io/ent v0.11.9
99 github.com/CycloneDX/cyclonedx-go v0.7.0
1010 github.com/adrg/xdg v0.4.0
11- github.com/aws/aws-sdk-go-v2 v1.17.5
12- github.com/aws/aws-sdk-go-v2/config v1.18.15
13- github.com/aws/aws-sdk-go-v2/credentials v1.13.15
11+ github.com/aws/aws-sdk-go-v2 v1.17.8
12+ github.com/aws/aws-sdk-go-v2/config v1.18.21
13+ github.com/aws/aws-sdk-go-v2/credentials v1.13.20
1414 github.com/aws/aws-sdk-go-v2/service/secretsmanager v1.18.1
15- github.com/aws/aws-sdk-go-v2/service/sso v1.12.4
15+ github.com/aws/aws-sdk-go-v2/service/sso v1.12.8
1616 github.com/aws/smithy-go v1.13.5
1717 github.com/cenkalti/backoff/v4 v4.2.0
1818 github.com/coreos/go-oidc/v3 v3.5.0
@@ -25,47 +25,46 @@ require (
2525 github.com/go-openapi/errors v0.20.3
2626 github.com/golang-jwt/jwt v3.2.2+incompatible
2727 github.com/golang-jwt/jwt/v4 v4.5.0
28- github.com/google/go-containerregistry v0.13.0
28+ github.com/google/go-containerregistry v0.14.1-0.20230409045903-ed5c185df419
2929 github.com/google/subcommands v1.0.1
3030 github.com/google/uuid v1.3.0
3131 github.com/google/wire v0.5.0
3232 github.com/grpc-ecosystem/go-grpc-middleware v1.3.0
3333 github.com/grpc-ecosystem/go-grpc-prometheus v1.2.0
34- github.com/hashicorp/vault/api v1.9.0
34+ github.com/hashicorp/vault/api v1.9.1
3535 github.com/hedwigz/entviz v0.0.0-20221011080911-9d47f6f1d818
3636 github.com/improbable-eng/grpc-web v0.15.0
37- github.com/in-toto/in-toto-golang v0.6 .0
37+ github.com/in-toto/in-toto-golang v0.8 .0
3838 github.com/jackc/pgx/v4 v4.18.1
3939 github.com/jedib0t/go-pretty/v6 v6.4.6
4040 github.com/lib/pq v1.10.7
4141 github.com/moby/moby v23.0.1+incompatible
4242 github.com/opencontainers/image-spec v1.1.0-rc2
4343 github.com/prometheus/client_golang v1.14.0
4444 github.com/rs/zerolog v1.29.0
45- github.com/secure-systems-lab/go-securesystemslib v0.4 .0
46- github.com/sigstore/cosign v1.13.1
47- github.com/sigstore/sigstore v1.5.2
45+ github.com/secure-systems-lab/go-securesystemslib v0.5 .0
46+ github.com/sigstore/cosign/v2 v2.0.2
47+ github.com/sigstore/sigstore v1.6.3
4848 github.com/spdx/tools-golang v0.3.0
49- github.com/spf13/cobra v1.6.1
49+ github.com/spf13/cobra v1.7.0
5050 github.com/spf13/pflag v1.0.5
5151 github.com/spf13/viper v1.15.0
5252 github.com/stretchr/testify v1.8.2
5353 github.com/testcontainers/testcontainers-go v0.18.0
5454 go.uber.org/automaxprocs v1.5.1
5555 go.uber.org/zap v1.24.0
56- golang.org/x/exp v0.0.0-20230113152452-c42ee1cf562e
57- golang.org/x/oauth2 v0.5 .0
58- golang.org/x/term v0.5 .0
59- google.golang.org/genproto v0.0.0-20230209215440-0dfe4f8abfcc
60- google.golang.org/grpc v1.53 .0
61- google.golang.org/protobuf v1.28.1
56+ golang.org/x/exp v0.0.0-20230124195608-d38c7dcee874
57+ golang.org/x/oauth2 v0.7 .0
58+ golang.org/x/term v0.7 .0
59+ google.golang.org/genproto v0.0.0-20230410155749-daa745c078e1
60+ google.golang.org/grpc v1.54 .0
61+ google.golang.org/protobuf v1.30.0
6262 sigs.k8s.io/yaml v1.3.0
6363)
6464
6565require (
6666 ariga.io/atlas v0.9.1 // indirect
67- bitbucket.org/creachadair/shell v0.0.7 // indirect
68- cloud.google.com/go/compute v1.18.0 // indirect
67+ cloud.google.com/go/compute v1.19.0 // indirect
6968 cloud.google.com/go/compute/metadata v0.2.3 // indirect
7069 github.com/Azure/go-ansiterm v0.0.0-20210617225240-d185dfc1b5a1 // indirect
7170 github.com/Azure/go-autorest v14.2.0+incompatible // indirect
@@ -75,83 +74,70 @@ require (
7574 github.com/Azure/go-autorest/logger v0.2.1 // indirect
7675 github.com/Azure/go-autorest/tracing v0.6.0 // indirect
7776 github.com/Microsoft/go-winio v0.6.0 // indirect
77+ github.com/ProtonMail/go-crypto v0.0.0-20230217124315-7d5c6f04bbb8 // indirect
7878 github.com/ThalesIgnite/crypto11 v1.2.5 // indirect
7979 github.com/agext/levenshtein v1.2.1 // indirect
8080 github.com/apparentlymart/go-textseg/v13 v13.0.0 // indirect
81- github.com/asaskevich/govalidator v0.0.0-20210307081110-f21760c49a8d // indirect
82- github.com/aws/aws-sdk-go-v2/feature/ec2/imds v1.12.23 // indirect
83- github.com/aws/aws-sdk-go-v2/internal/configsources v1.1.29 // indirect
84- github.com/aws/aws-sdk-go-v2/internal/endpoints/v2 v2.4.23 // indirect
85- github.com/aws/aws-sdk-go-v2/internal/ini v1.3.30 // indirect
86- github.com/aws/aws-sdk-go-v2/service/internal/presigned-url v1.9.23 // indirect
87- github.com/aws/aws-sdk-go-v2/service/ssooidc v1.14.4 // indirect
88- github.com/aws/aws-sdk-go-v2/service/sts v1.18.5 // indirect
89- github.com/benbjohnson/clock v1.1.0 // indirect
81+ github.com/asaskevich/govalidator v0.0.0-20230301143203-a9d515a09cc2 // indirect
82+ github.com/aws/aws-sdk-go-v2/feature/ec2/imds v1.13.2 // indirect
83+ github.com/aws/aws-sdk-go-v2/internal/configsources v1.1.32 // indirect
84+ github.com/aws/aws-sdk-go-v2/internal/endpoints/v2 v2.4.26 // indirect
85+ github.com/aws/aws-sdk-go-v2/internal/ini v1.3.33 // indirect
86+ github.com/aws/aws-sdk-go-v2/service/internal/presigned-url v1.9.26 // indirect
87+ github.com/aws/aws-sdk-go-v2/service/ssooidc v1.14.8 // indirect
88+ github.com/aws/aws-sdk-go-v2/service/sts v1.18.9 // indirect
9089 github.com/beorn7/perks v1.0.1 // indirect
91- github.com/bgentry/speakeasy v0.1.0 // indirect
9290 github.com/blang/semver v3.5.1+incompatible // indirect
9391 github.com/cenkalti/backoff/v3 v3.2.2 // indirect
94- github.com/census-instrumentation/opencensus-proto v0.4.1 // indirect
9592 github.com/cespare/xxhash/v2 v2.2.0 // indirect
96- github.com/cncf/udpa/go v0.0.0-20220112060539-c52dc94e7fbe // indirect
97- github.com/cncf/xds/go v0.0.0-20230105202645-06c439db220b // indirect
98- github.com/cockroachdb/apd/v2 v2.0.1 // indirect
93+ github.com/cloudflare/circl v1.1.0 // indirect
94+ github.com/cockroachdb/apd/v2 v2.0.2 // indirect
9995 github.com/containerd/containerd v1.6.18 // indirect
100- github.com/containerd/stargz-snapshotter/estargz v0.12.1 // indirect
101- github.com/coreos/go-semver v0.3.0 // indirect
102- github.com/coreos/go-systemd/v22 v22.3.3-0.20220203105225-a9a7ef127534 // indirect
103- github.com/cpuguy83/go-md2man/v2 v2.0.2 // indirect
96+ github.com/containerd/stargz-snapshotter/estargz v0.14.3 // indirect
10497 github.com/cyberphone/json-canonicalization v0.0.0-20210823021906-dc406ceaf94b // indirect
10598 github.com/davecgh/go-spew v1.1.1 // indirect
10699 github.com/desertbit/timer v0.0.0-20180107155436-c41aec40b27f // indirect
107- github.com/docker/cli v20.10.20+incompatible // indirect
100+ github.com/digitorus/pkcs7 v0.0.0-20221212123742-001c36b64ec3 // indirect
101+ github.com/digitorus/timestamp v0.0.0-20221019182153-ef3b63b79b31 // indirect
102+ github.com/docker/cli v23.0.1+incompatible // indirect
108103 github.com/docker/docker v23.0.3+incompatible // indirect
109104 github.com/docker/docker-credential-helpers v0.7.0 // indirect
110105 github.com/docker/go-units v0.5.0 // indirect
111- github.com/dustin/go-humanize v1.0.1 // indirect
112- github.com/envoyproxy/go-control-plane v0.10.3 // indirect
106+ github.com/emicklei/go-restful/v3 v3.8.0 // indirect
113107 github.com/fsnotify/fsnotify v1.6.0 // indirect
114- github.com/fullstorydev/grpcurl v1.8.7 // indirect
115108 github.com/go-chi/chi v4.1.2+incompatible // indirect
116109 github.com/go-jose/go-jose/v3 v3.0.0 // indirect
117- github.com/go-logr/logr v1.2.3 // indirect
110+ github.com/go-logr/logr v1.2.4 // indirect
118111 github.com/go-logr/stdr v1.2.2 // indirect
119112 github.com/go-openapi/analysis v0.21.4 // indirect
120113 github.com/go-openapi/inflect v0.19.0 // indirect
121114 github.com/go-openapi/jsonpointer v0.19.5 // indirect
122115 github.com/go-openapi/jsonreference v0.20.0 // indirect
123116 github.com/go-openapi/loads v0.21.2 // indirect
124- github.com/go-openapi/runtime v0.24.2 // indirect
125- github.com/go-openapi/spec v0.20.7 // indirect
126- github.com/go-openapi/strfmt v0.21.3 // indirect
117+ github.com/go-openapi/runtime v0.26.0 // indirect
118+ github.com/go-openapi/spec v0.20.8 // indirect
119+ github.com/go-openapi/strfmt v0.21.7 // indirect
127120 github.com/go-openapi/swag v0.22.3 // indirect
128- github.com/go-openapi/validate v0.22.0 // indirect
121+ github.com/go-openapi/validate v0.22.1 // indirect
129122 github.com/go-playground/form/v4 v4.2.0 // indirect
130- github.com/go-playground/locales v0.14.0 // indirect
131- github.com/go-playground/universal-translator v0.18.0 // indirect
132- github.com/go-playground/validator/v10 v10.11.1 // indirect
123+ github.com/go-playground/locales v0.14.1 // indirect
124+ github.com/go-playground/universal-translator v0.18.1 // indirect
125+ github.com/go-playground/validator/v10 v10.12.0 // indirect
133126 github.com/gogo/protobuf v1.3.2 // indirect
134- github.com/golang/glog v1.0.0 // indirect
135- github.com/golang/groupcache v0.0.0-20210331224755-41bb18bfe9da // indirect
136- github.com/golang/mock v1.6.0 // indirect
137- github.com/golang/protobuf v1.5.2 // indirect
127+ github.com/golang/protobuf v1.5.3 // indirect
138128 github.com/golang/snappy v0.0.4 // indirect
139- github.com/google/btree v1.1.2 // indirect
140- github.com/google/certificate-transparency-go v1.1.3 // indirect
129+ github.com/google/certificate-transparency-go v1.1.4 // indirect
130+ github.com/google/gnostic v0.5.7-v3refs // indirect
141131 github.com/google/go-cmp v0.5.9 // indirect
142- github.com/google/go-github/v45 v45 .2.0 // indirect
132+ github.com/google/go-github/v50 v50 .2.0 // indirect
143133 github.com/google/go-querystring v1.1.0 // indirect
144134 github.com/google/gofuzz v1.2.0 // indirect
145- github.com/google/trillian v1.5.0 // indirect
146- github.com/googleapis/gnostic v0.5.5 // indirect
135+ github.com/google/trillian v1.5.1 // indirect
147136 github.com/gorilla/mux v1.8.0 // indirect
148- github.com/gorilla/websocket v1.5.0 // indirect
149- github.com/grpc-ecosystem/grpc-gateway v1.16.0 // indirect
150- github.com/grpc-ecosystem/grpc-gateway/v2 v2.11.3 // indirect
151137 github.com/hashicorp/errwrap v1.1.0 // indirect
152138 github.com/hashicorp/go-cleanhttp v0.5.2 // indirect
153139 github.com/hashicorp/go-multierror v1.1.1 // indirect
154- github.com/hashicorp/go-retryablehttp v0.7.1 // indirect
140+ github.com/hashicorp/go-retryablehttp v0.7.2 // indirect
155141 github.com/hashicorp/go-rootcerts v1.0.2 // indirect
156142 github.com/hashicorp/go-secure-stdlib/parseutil v0.1.7 // indirect
157143 github.com/hashicorp/go-secure-stdlib/strutil v0.1.2 // indirect
@@ -168,12 +154,10 @@ require (
168154 github.com/jackc/pgservicefile v0.0.0-20221227161230-091c0ba34f0a // indirect
169155 github.com/jackc/pgtype v1.14.0 // indirect
170156 github.com/jedisct1/go-minisign v0.0.0-20211028175153-1c139d1cc84b // indirect
171- github.com/jhump/protoreflect v1.14.0 // indirect
172- github.com/jonboulle/clockwork v0.3.0 // indirect
173157 github.com/josharian/intern v1.0.0 // indirect
174158 github.com/json-iterator/go v1.1.12 // indirect
175- github.com/klauspost/compress v1.15.11 // indirect
176- github.com/leodido/go-urn v1.2.1 // indirect
159+ github.com/klauspost/compress v1.16.0 // indirect
160+ github.com/leodido/go-urn v1.2.2 // indirect
177161 github.com/letsencrypt/boulder v0.0.0-20221109233200-85aa52084eaf // indirect
178162 github.com/magiconair/properties v1.8.7 // indirect
179163 github.com/mailru/easyjson v0.7.7 // indirect
@@ -183,35 +167,34 @@ require (
183167 github.com/matttproud/golang_protobuf_extensions v1.0.4 // indirect
184168 github.com/miekg/pkcs11 v1.1.1 // indirect
185169 github.com/mitchellh/go-homedir v1.1.0 // indirect
186- github.com/mitchellh/go-wordwrap v1.0.0 // indirect
170+ github.com/mitchellh/go-wordwrap v1.0.1 // indirect
187171 github.com/mitchellh/mapstructure v1.5.0 // indirect
188172 github.com/moby/patternmatcher v0.5.0 // indirect
189173 github.com/moby/sys/sequential v0.5.0 // indirect
190- github.com/moby/term v0.0.0-20221128092401-c43b287e0e0f // indirect
174+ github.com/moby/term v0.0.0-20221205130635-1aeaba878587 // indirect
191175 github.com/modern-go/concurrent v0.0.0-20180306012644-bacd9c7ef1dd // indirect
192176 github.com/modern-go/reflect2 v1.0.2 // indirect
193177 github.com/morikuni/aec v1.0.0 // indirect
194178 github.com/mpvl/unique v0.0.0-20150818121801-cbe035fff7de // indirect
179+ github.com/munnerz/goautoneg v0.0.0-20191010083416-a7dc8b61c822 // indirect
195180 github.com/oklog/ulid v1.3.1 // indirect
196- github.com/olekukonko/tablewriter v0.0.5 // indirect
197181 github.com/opencontainers/go-digest v1.0.0 // indirect
198182 github.com/opencontainers/runc v1.1.5 // indirect
199183 github.com/opentracing/opentracing-go v1.2.0 // indirect
200184 github.com/pelletier/go-toml/v2 v2.0.6 // indirect
201185 github.com/pkg/errors v0.9.1 // indirect
202186 github.com/pmezard/go-difflib v1.0.0 // indirect
203187 github.com/prometheus/client_model v0.3.0 // indirect
204- github.com/prometheus/common v0.37 .0 // indirect
205- github.com/prometheus/procfs v0.8 .0 // indirect
188+ github.com/prometheus/common v0.42 .0 // indirect
189+ github.com/prometheus/procfs v0.9 .0 // indirect
206190 github.com/rivo/uniseg v0.2.0 // indirect
207- github.com/rs/cors v1.8.2 // indirect
208- github.com/russross/blackfriday/v2 v2.1.0 // indirect
191+ github.com/rs/cors v1.8.3 // indirect
209192 github.com/ryanuber/go-glob v1.0.0 // indirect
210- github.com/sassoftware/relic v0.0.0-20210427151427-dfb082b79b74 // indirect
193+ github.com/sassoftware/relic v7.2.1+incompatible // indirect
211194 github.com/shibumi/go-pathspec v1.3.0 // indirect
212- github.com/sigstore/rekor v0.12.1-0.20220915152154-4bb6f441c1b2 // indirect
195+ github.com/sigstore/rekor v1.1.0 // indirect
196+ github.com/sigstore/timestamp-authority v1.0.0 // indirect
213197 github.com/sirupsen/logrus v1.9.0 // indirect
214- github.com/soheilhy/cmux v0.1.5 // indirect
215198 github.com/spf13/afero v1.9.3 // indirect
216199 github.com/spf13/cast v1.5.0 // indirect
217200 github.com/spf13/jwalterweatherman v1.1.0 // indirect
@@ -222,59 +205,37 @@ require (
222205 github.com/thales-e-security/pool v0.0.2 // indirect
223206 github.com/theupdateframework/go-tuf v0.5.2 // indirect
224207 github.com/titanous/rocacheck v0.0.0-20171023193734-afe73141d399 // indirect
225- github.com/tmc/grpc-websocket-proxy v0.0.0-20201229170055-e5319fda7802 // indirect
226208 github.com/transparency-dev/merkle v0.0.1 // indirect
227- github.com/urfave/cli v1.22.7 // indirect
228209 github.com/vbatts/tar-split v0.11.2 // indirect
229- github.com/xanzy/go-gitlab v0.73.1 // indirect
230- github.com/xiang90/probing v0.0.0-20190116061207-43a291ad63a2 // indirect
210+ github.com/xanzy/go-gitlab v0.83.0 // indirect
231211 github.com/zclconf/go-cty v1.8.0 // indirect
232- go.etcd.io/bbolt v1.3.6 // indirect
233- go.etcd.io/etcd/api/v3 v3.6.0-alpha.0 // indirect
234- go.etcd.io/etcd/client/pkg/v3 v3.6.0-alpha.0 // indirect
235- go.etcd.io/etcd/client/v2 v2.306.0-alpha.0 // indirect
236- go.etcd.io/etcd/client/v3 v3.6.0-alpha.0 // indirect
237- go.etcd.io/etcd/etcdctl/v3 v3.6.0-alpha.0 // indirect
238- go.etcd.io/etcd/etcdutl/v3 v3.6.0-alpha.0 // indirect
239- go.etcd.io/etcd/pkg/v3 v3.6.0-alpha.0 // indirect
240- go.etcd.io/etcd/raft/v3 v3.6.0-alpha.0 // indirect
241- go.etcd.io/etcd/server/v3 v3.6.0-alpha.0 // indirect
242- go.etcd.io/etcd/tests/v3 v3.6.0-alpha.0 // indirect
243- go.etcd.io/etcd/v3 v3.6.0-alpha.0 // indirect
244- go.mongodb.org/mongo-driver v1.10.0 // indirect
245- go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc v0.28.0 // indirect
246- go.opentelemetry.io/otel v1.7.0 // indirect
247- go.opentelemetry.io/otel/exporters/otlp/internal/retry v1.7.0 // indirect
248- go.opentelemetry.io/otel/exporters/otlp/otlptrace v1.7.0 // indirect
249- go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc v1.7.0 // indirect
250- go.opentelemetry.io/otel/sdk v1.7.0 // indirect
251- go.opentelemetry.io/otel/trace v1.7.0 // indirect
252- go.opentelemetry.io/proto/otlp v0.16.0 // indirect
212+ go.mongodb.org/mongo-driver v1.11.3 // indirect
213+ go.opentelemetry.io/otel v1.14.0 // indirect
214+ go.opentelemetry.io/otel/trace v1.14.0 // indirect
253215 go.uber.org/atomic v1.10.0 // indirect
254- go.uber.org/multierr v1.8 .0 // indirect
255- golang.org/x/crypto v0.6 .0 // indirect
256- golang.org/x/mod v0.8 .0 // indirect
257- golang.org/x/net v0.7 .0 // indirect
216+ go.uber.org/multierr v1.9 .0 // indirect
217+ golang.org/x/crypto v0.8 .0 // indirect
218+ golang.org/x/mod v0.9 .0 // indirect
219+ golang.org/x/net v0.9 .0 // indirect
258220 golang.org/x/sync v0.1.0 // indirect
259- golang.org/x/sys v0.5 .0 // indirect
260- golang.org/x/text v0.7 .0 // indirect
261- golang.org/x/time v0.2 .0 // indirect
262- golang.org/x/tools v0.6.1-0.20230222164832-25d2519c8696 // indirect
221+ golang.org/x/sys v0.7 .0 // indirect
222+ golang.org/x/text v0.9 .0 // indirect
223+ golang.org/x/time v0.3 .0 // indirect
224+ golang.org/x/tools v0.7.0 // indirect
263225 google.golang.org/appengine v1.6.7 // indirect
264- gopkg.in/cheggaaa/pb.v1 v1.0.28 // indirect
265226 gopkg.in/inf.v0 v0.9.1 // indirect
266227 gopkg.in/ini.v1 v1.67.0 // indirect
267- gopkg.in/natefinch/lumberjack.v2 v2.0.0 // indirect
268228 gopkg.in/square/go-jose.v2 v2.6.0 // indirect
269229 gopkg.in/yaml.v2 v2.4.0 // indirect
270230 gopkg.in/yaml.v3 v3.0.1 // indirect
271- k8s.io/api v0.23.5 // indirect
272- k8s.io/apimachinery v0.23.5 // indirect
273- k8s.io/client-go v0.23.5 // indirect
274- k8s.io/klog/v2 v2.60.1-0.20220317184644-43cc75f9ae89 // indirect
275- k8s.io/kube-openapi v0.0.0-20220124234850-424119656bbf // indirect
276- k8s.io/utils v0.0.0-20220210201930-3a6ce19ff2f9 // indirect
231+ gotest.tools/v3 v3.1.0 // indirect
232+ k8s.io/api v0.26.1 // indirect
233+ k8s.io/apimachinery v0.26.1 // indirect
234+ k8s.io/client-go v0.25.4 // indirect
235+ k8s.io/klog/v2 v2.90.0 // indirect
236+ k8s.io/kube-openapi v0.0.0-20221012153701-172d655c2280 // indirect
237+ k8s.io/utils v0.0.0-20230115233650-391b47cb4029 // indirect
277238 nhooyr.io/websocket v1.8.6 // indirect
278- sigs.k8s.io/json v0.0.0-20211208200746-9f7c6b3444d2 // indirect
279- sigs.k8s.io/structured-merge-diff/v4 v4.2.1 // indirect
239+ sigs.k8s.io/json v0.0.0-20221116044647-bc3834ca7abd // indirect
240+ sigs.k8s.io/structured-merge-diff/v4 v4.2.3 // indirect
280241)
0 commit comments