@@ -5,7 +5,7 @@ go 1.24.6
55require (
66 cuelang.org/go v0.13.2
77 github.com/CycloneDX/cyclonedx-go v0.9.3
8- github.com/MakeNowJust/heredoc v1 .0.0
8+ github.com/MakeNowJust/heredoc/v2 v2 .0.1
99 github.com/Maldris/go-billy-afero v0.0.0-20200815120323-e9d3de59c99a
1010 github.com/conforma/go-gather v1.0.2
1111 github.com/docker/docker v28.3.3+incompatible
@@ -29,11 +29,11 @@ require (
2929 github.com/open-policy-agent/opa v1.6.0
3030 github.com/package-url/packageurl-go v0.1.3
3131 github.com/qri-io/jsonpointer v0.1.1
32- github.com/santhosh-tekuri/jsonschema/v5 v5.3.1
32+ github.com/santhosh-tekuri/jsonschema/v6 v6.0.2
3333 github.com/secure-systems-lab/go-securesystemslib v0.9.1
3434 github.com/sigstore/cosign/v2 v2.4.1
3535 github.com/sigstore/rekor v1.3.10
36- github.com/sigstore/sigstore v1.9.1
36+ github.com/sigstore/sigstore v1.9.5
3737 github.com/sirupsen/logrus v1.9.4
3838 github.com/smarty/cproxy/v2 v2.1.1
3939 github.com/spdx/tools-golang v0.5.7
@@ -43,13 +43,13 @@ require (
4343 github.com/spf13/viper v1.20.1
4444 github.com/stretchr/testify v1.11.1
4545 github.com/stuart-warren/yamlfmt v0.2.0
46- github.com/tektoncd/pipeline v0.66 .0
46+ github.com/tektoncd/pipeline v1.9 .0
4747 github.com/testcontainers/testcontainers-go v0.34.1-0.20241204123437-72be13940122 // using unreleased version that contains the fix in https://github.com/testcontainers/testcontainers-go/pull/2899
4848 github.com/testcontainers/testcontainers-go/modules/registry v0.34.0
4949 golang.org/x/benchmarks v0.0.0-20241115175113-a2b48b605b42
5050 golang.org/x/exp v0.0.0-20250408133849-7e4ce0ab07d0
51- golang.org/x/net v0.44 .0
52- golang.org/x/sync v0.17 .0
51+ golang.org/x/net v0.47 .0
52+ golang.org/x/sync v0.19 .0
5353 k8s.io/apiextensions-apiserver v0.34.3
5454 k8s.io/apimachinery v0.34.3
5555 k8s.io/client-go v0.34.3
@@ -63,12 +63,17 @@ require (
6363replace github.com/google/go-containerregistry => github.com/conforma/go-containerregistry v0.20.7-0.20250703195040-6f40a3734728
6464
6565require (
66- cel.dev/expr v0.24.0 // indirect
67- cloud.google.com/go v0.118.3 // indirect
68- cloud.google.com/go/auth v0.15.0 // indirect
66+ github.com/MakeNowJust/heredoc v1.0.0
67+ github.com/santhosh-tekuri/jsonschema/v5 v5.3.1
68+ )
69+
70+ require (
71+ cel.dev/expr v0.25.1 // indirect
72+ cloud.google.com/go v0.120.0 // indirect
73+ cloud.google.com/go/auth v0.16.1 // indirect
6974 cloud.google.com/go/auth/oauth2adapt v0.2.8 // indirect
70- cloud.google.com/go/compute/metadata v0.7 .0 // indirect
71- cloud.google.com/go/iam v1.4.1 // indirect
75+ cloud.google.com/go/compute/metadata v0.9 .0 // indirect
76+ cloud.google.com/go/iam v1.5.0 // indirect
7277 cloud.google.com/go/monitoring v1.24.0 // indirect
7378 cloud.google.com/go/storage v1.50.0 // indirect
7479 contrib.go.opencensus.io/exporter/ocagent v0.7.1-0.20200907061046-05415f1de66d // indirect
@@ -87,9 +92,9 @@ require (
8792 github.com/Azure/go-autorest/logger v0.2.1 // indirect
8893 github.com/Azure/go-autorest/tracing v0.6.0 // indirect
8994 github.com/BurntSushi/toml v1.5.0 // indirect
90- github.com/GoogleCloudPlatform/opentelemetry-operations-go/detectors/gcp v1.29 .0 // indirect
91- github.com/GoogleCloudPlatform/opentelemetry-operations-go/exporter/metric v0.49 .0 // indirect
92- github.com/GoogleCloudPlatform/opentelemetry-operations-go/internal/resourcemapping v0.49 .0 // indirect
95+ github.com/GoogleCloudPlatform/opentelemetry-operations-go/detectors/gcp v1.30 .0 // indirect
96+ github.com/GoogleCloudPlatform/opentelemetry-operations-go/exporter/metric v0.50 .0 // indirect
97+ github.com/GoogleCloudPlatform/opentelemetry-operations-go/internal/resourcemapping v0.50 .0 // indirect
9398 github.com/KeisukeYamashita/go-vcl v0.4.0 // indirect
9499 github.com/Microsoft/go-winio v0.6.2 // indirect
95100 github.com/ProtonMail/go-crypto v1.1.5 // indirect
@@ -114,8 +119,8 @@ require (
114119 github.com/asaskevich/govalidator v0.0.0-20230301143203-a9d515a09cc2 // indirect
115120 github.com/aws/aws-sdk-go v1.55.6 // indirect
116121 github.com/aws/aws-sdk-go-v2 v1.36.3 // indirect
117- github.com/aws/aws-sdk-go-v2/config v1.29.10 // indirect
118- github.com/aws/aws-sdk-go-v2/credentials v1.17.63 // indirect
122+ github.com/aws/aws-sdk-go-v2/config v1.29.14 // indirect
123+ github.com/aws/aws-sdk-go-v2/credentials v1.17.67 // indirect
119124 github.com/aws/aws-sdk-go-v2/feature/ec2/imds v1.16.30 // indirect
120125 github.com/aws/aws-sdk-go-v2/internal/configsources v1.3.34 // indirect
121126 github.com/aws/aws-sdk-go-v2/internal/endpoints/v2 v2.6.34 // indirect
@@ -124,9 +129,9 @@ require (
124129 github.com/aws/aws-sdk-go-v2/service/ecrpublic v1.25.4 // indirect
125130 github.com/aws/aws-sdk-go-v2/service/internal/accept-encoding v1.12.3 // indirect
126131 github.com/aws/aws-sdk-go-v2/service/internal/presigned-url v1.12.15 // indirect
127- github.com/aws/aws-sdk-go-v2/service/sso v1.25.1 // indirect
128- github.com/aws/aws-sdk-go-v2/service/ssooidc v1.29.2 // indirect
129- github.com/aws/aws-sdk-go-v2/service/sts v1.33.17 // indirect
132+ github.com/aws/aws-sdk-go-v2/service/sso v1.25.3 // indirect
133+ github.com/aws/aws-sdk-go-v2/service/ssooidc v1.30.1 // indirect
134+ github.com/aws/aws-sdk-go-v2/service/sts v1.33.19 // indirect
130135 github.com/aws/smithy-go v1.22.2 // indirect
131136 github.com/awslabs/amazon-ecr-credential-helper/ecr-login v0.0.0-20240826150212-5dc58b6e29f8 // indirect
132137 github.com/basgys/goxml2json v1.1.0 // indirect
@@ -144,7 +149,7 @@ require (
144149 github.com/chrismellard/docker-credential-acr-env v0.0.0-20230304212654-82a0ddb27589 // indirect
145150 github.com/clbanning/mxj/v2 v2.7.0 // indirect
146151 github.com/cloudflare/circl v1.4.0 // indirect
147- github.com/cncf/xds/go v0.0.0-20250501225837-2ac532fd4443 // indirect
152+ github.com/cncf/xds/go v0.0.0-20251022180443-0feb69152e9f // indirect
148153 github.com/cockroachdb/apd/v3 v3.2.1 // indirect
149154 github.com/common-nighthawk/go-figure v0.0.0-20210622060536-734e95fb86be // indirect
150155 github.com/containerd/containerd/v2 v2.2.0 // indirect
@@ -154,7 +159,7 @@ require (
154159 github.com/containerd/platforms v1.0.0-rc.2 // indirect
155160 github.com/containerd/stargz-snapshotter/estargz v0.16.3 // indirect
156161 github.com/containerd/typeurl/v2 v2.2.3 // indirect
157- github.com/coreos/go-oidc/v3 v3.12.0 // indirect
162+ github.com/coreos/go-oidc/v3 v3.14.1 // indirect
158163 github.com/cpuguy83/dockercfg v0.3.2 // indirect
159164 github.com/cpuguy83/go-md2man/v2 v2.0.7 // indirect
160165 github.com/cyberphone/json-canonicalization v0.0.0-20231217050601-ba74d44ecf5f // indirect
@@ -174,9 +179,9 @@ require (
174179 github.com/dustin/go-humanize v1.0.1 // indirect
175180 github.com/emicklei/go-restful/v3 v3.13.0 // indirect
176181 github.com/emirpasic/gods v1.18.1 // indirect
177- github.com/envoyproxy/go-control-plane/envoy v1.32.4 // indirect
182+ github.com/envoyproxy/go-control-plane/envoy v1.35.0 // indirect
178183 github.com/envoyproxy/protoc-gen-validate v1.2.1 // indirect
179- github.com/evanphx/json-patch/v5 v5.9.0 // indirect
184+ github.com/evanphx/json-patch/v5 v5.9.11 // indirect
180185 github.com/felixge/httpsnoop v1.0.4 // indirect
181186 github.com/fsnotify/fsnotify v1.9.0 // indirect
182187 github.com/fxamacker/cbor/v2 v2.9.0 // indirect
@@ -188,7 +193,7 @@ require (
188193 github.com/go-git/go-billy/v5 v5.6.2 // indirect
189194 github.com/go-ini/ini v1.67.0 // indirect
190195 github.com/go-jose/go-jose/v3 v3.0.4 // indirect
191- github.com/go-jose/go-jose/v4 v4.1.2 // indirect
196+ github.com/go-jose/go-jose/v4 v4.1.3 // indirect
192197 github.com/go-kit/log v0.2.1 // indirect
193198 github.com/go-logfmt/logfmt v0.6.0 // indirect
194199 github.com/go-logr/stdr v1.2.2 // indirect
@@ -210,7 +215,7 @@ require (
210215 github.com/golang/groupcache v0.0.0-20241129210726-2c02b8208cf8 // indirect
211216 github.com/golang/protobuf v1.5.4 // indirect
212217 github.com/golang/snappy v0.0.4 // indirect
213- github.com/google/cel-go v0.26 .0 // indirect
218+ github.com/google/cel-go v0.27 .0 // indirect
214219 github.com/google/certificate-transparency-go v1.2.1 // indirect
215220 github.com/google/flatbuffers v25.2.10+incompatible // indirect
216221 github.com/google/gnostic-models v0.7.0 // indirect
@@ -221,14 +226,14 @@ require (
221226 github.com/google/uuid v1.6.0 // indirect
222227 github.com/googleapis/enterprise-certificate-proxy v0.3.6 // indirect
223228 github.com/googleapis/gax-go/v2 v2.14.1 // indirect
224- github.com/grpc-ecosystem/grpc-gateway/v2 v2.26.3 // indirect
229+ github.com/grpc-ecosystem/grpc-gateway/v2 v2.27.1 // indirect
225230 github.com/hashicorp/errwrap v1.1.0 // indirect
226231 github.com/hashicorp/go-cleanhttp v0.5.2 // indirect
227232 github.com/hashicorp/go-getter v1.7.9 // indirect
228233 github.com/hashicorp/go-multierror v1.1.1 // indirect
229234 github.com/hashicorp/go-retryablehttp v0.7.7 // indirect
230235 github.com/hashicorp/go-safetemp v1.0.0 // indirect
231- github.com/hashicorp/go-version v1.7 .0 // indirect
236+ github.com/hashicorp/go-version v1.8 .0 // indirect
232237 github.com/hashicorp/hcl v1.0.1-vault-5 // indirect
233238 github.com/hashicorp/hcl/v2 v2.23.0 // indirect
234239 github.com/inconshreveable/mousetrap v1.1.0 // indirect
@@ -305,7 +310,7 @@ require (
305310 github.com/skratchdot/open-golang v0.0.0-20200116055534-eef842397966 // indirect
306311 github.com/sourcegraph/conc v0.3.0 // indirect
307312 github.com/spf13/cast v1.7.1 // indirect
308- github.com/spiffe/go-spiffe/v2 v2.5 .0 // indirect
313+ github.com/spiffe/go-spiffe/v2 v2.6 .0 // indirect
309314 github.com/stoewer/go-strcase v1.3.0 // indirect
310315 github.com/stretchr/objx v0.5.2 // indirect
311316 github.com/subosito/gotenv v1.6.0 // indirect
@@ -338,40 +343,40 @@ require (
338343 github.com/zeebo/errs v1.4.0 // indirect
339344 go.mongodb.org/mongo-driver v1.16.1 // indirect
340345 go.opencensus.io v0.24.0 // indirect
341- go.opentelemetry.io/auto/sdk v1.1.0 // indirect
342- go.opentelemetry.io/contrib/detectors/gcp v1.36 .0 // indirect
346+ go.opentelemetry.io/auto/sdk v1.2.1 // indirect
347+ go.opentelemetry.io/contrib/detectors/gcp v1.38 .0 // indirect
343348 go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc v0.60.0 // indirect
344349 go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.61.0 // indirect
345- go.opentelemetry.io/otel v1.37 .0 // indirect
346- go.opentelemetry.io/otel/exporters/otlp/otlptrace v1.36 .0 // indirect
350+ go.opentelemetry.io/otel v1.39 .0 // indirect
351+ go.opentelemetry.io/otel/exporters/otlp/otlptrace v1.37 .0 // indirect
347352 go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc v1.36.0 // indirect
348- go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp v1.36 .0 // indirect
349- go.opentelemetry.io/otel/metric v1.37 .0 // indirect
350- go.opentelemetry.io/otel/sdk v1.37 .0 // indirect
351- go.opentelemetry.io/otel/sdk/metric v1.37 .0 // indirect
352- go.opentelemetry.io/otel/trace v1.37 .0 // indirect
353- go.opentelemetry.io/proto/otlp v1.6 .0 // indirect
353+ go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp v1.37 .0 // indirect
354+ go.opentelemetry.io/otel/metric v1.39 .0 // indirect
355+ go.opentelemetry.io/otel/sdk v1.39 .0 // indirect
356+ go.opentelemetry.io/otel/sdk/metric v1.39 .0 // indirect
357+ go.opentelemetry.io/otel/trace v1.39 .0 // indirect
358+ go.opentelemetry.io/proto/otlp v1.7 .0 // indirect
354359 go.step.sm/crypto v0.60.0 // indirect
355360 go.uber.org/automaxprocs v1.6.0 // indirect
356361 go.uber.org/multierr v1.11.0 // indirect
357- go.uber.org/zap v1.27.0 // indirect
362+ go.uber.org/zap v1.27.1 // indirect
358363 go.yaml.in/yaml/v2 v2.4.2 // indirect
359364 go.yaml.in/yaml/v3 v3.0.4 // indirect
360- golang.org/x/crypto v0.42 .0 // indirect
365+ golang.org/x/crypto v0.45 .0 // indirect
361366 golang.org/x/mod v0.29.0 // indirect
362- golang.org/x/oauth2 v0.30 .0 // indirect
363- golang.org/x/sys v0.37 .0 // indirect
364- golang.org/x/term v0.35 .0 // indirect
365- golang.org/x/text v0.29 .0 // indirect
367+ golang.org/x/oauth2 v0.32 .0 // indirect
368+ golang.org/x/sys v0.39 .0 // indirect
369+ golang.org/x/term v0.37 .0 // indirect
370+ golang.org/x/text v0.31 .0 // indirect
366371 golang.org/x/time v0.14.0 // indirect
367- golang.org/x/tools v0.37 .0 // indirect
368- gomodules.xyz/jsonpatch/v2 v2.4 .0 // indirect
369- google.golang.org/api v0.228 .0 // indirect
372+ golang.org/x/tools v0.38 .0 // indirect
373+ gomodules.xyz/jsonpatch/v2 v2.5 .0 // indirect
374+ google.golang.org/api v0.233 .0 // indirect
370375 google.golang.org/genproto v0.0.0-20250303144028-a0af3efb3deb // indirect
371- google.golang.org/genproto/googleapis/api v0.0.0-20250804133106-a7a43d27e69b // indirect
372- google.golang.org/genproto/googleapis/rpc v0.0.0-20250804133106-a7a43d27e69b // indirect
373- google.golang.org/grpc v1.76 .0 // indirect
374- google.golang.org/protobuf v1.36.10 // indirect
376+ google.golang.org/genproto/googleapis/api v0.0.0-20251022142026-3a174f9686a8 // indirect
377+ google.golang.org/genproto/googleapis/rpc v0.0.0-20251022142026-3a174f9686a8 // indirect
378+ google.golang.org/grpc v1.77 .0 // indirect
379+ google.golang.org/protobuf v1.36.11 // indirect
375380 gopkg.in/evanphx/json-patch.v4 v4.12.0 // indirect
376381 gopkg.in/inf.v0 v0.9.1 // indirect
377382 gopkg.in/ini.v1 v1.67.0 // indirect
@@ -380,7 +385,7 @@ require (
380385 gopkg.in/yaml.v3 v3.0.1 // indirect
381386 k8s.io/api v0.34.3 // indirect
382387 k8s.io/utils v0.0.0-20250604170112-4c0f3b243397 // indirect
383- knative.dev/pkg v0.0.0-20240815051656-89743d9bbf7c // indirect
388+ knative.dev/pkg v0.0.0-20250415155312-ed3e2158b883 // indirect
384389 olympos.io/encoding/edn v0.0.0-20201019073823-d3554ca0b0a3 // indirect
385390 sigs.k8s.io/controller-runtime v0.19.0 // indirect
386391 sigs.k8s.io/json v0.0.0-20241014173422-cfa47c3a1cc8 // indirect
0 commit comments