@@ -4,14 +4,14 @@ go 1.24.6
44
55require (
66 cuelang.org/go v0.13.2
7- github.com/CycloneDX/cyclonedx-go v0.9.2
7+ github.com/CycloneDX/cyclonedx-go v0.9.3
88 github.com/MakeNowJust/heredoc v1.0.0
99 github.com/Maldris/go-billy-afero v0.0.0-20200815120323-e9d3de59c99a
1010 github.com/conforma/crds/api v0.1.7
1111 github.com/conforma/go-gather v1.0.2
1212 github.com/docker/docker v28.2.2+incompatible
13- github.com/evanphx/json-patch v5.9.0 +incompatible
14- github.com/gkampitakis/go-snaps v0.5.7
13+ github.com/evanphx/json-patch v5.9.11 +incompatible
14+ github.com/gkampitakis/go-snaps v0.5.19
1515 github.com/go-git/go-git/v5 v5.13.2
1616 github.com/go-logr/logr v1.4.3
1717 github.com/go-openapi/strfmt v0.23.0
@@ -30,16 +30,16 @@ require (
3030 github.com/package-url/packageurl-go v0.1.3
3131 github.com/qri-io/jsonpointer v0.1.1
3232 github.com/santhosh-tekuri/jsonschema/v5 v5.3.1
33- github.com/secure-systems-lab/go-securesystemslib v0.9.0
33+ github.com/secure-systems-lab/go-securesystemslib v0.9.1
3434 github.com/sigstore/cosign/v2 v2.4.1
35- github.com/sigstore/rekor v1.3.6
36- github.com/sigstore/sigstore v1.8.9
37- github.com/sirupsen/logrus v1.9.3
35+ github.com/sigstore/rekor v1.3.10
36+ github.com/sigstore/sigstore v1.9.1
37+ github.com/sirupsen/logrus v1.9.4
3838 github.com/smarty/cproxy/v2 v2.1.1
39- github.com/spdx/tools-golang v0.5.5
39+ github.com/spdx/tools-golang v0.5.7
4040 github.com/spf13/afero v1.14.0
4141 github.com/spf13/cobra v1.9.1
42- github.com/spf13/pflag v1.0.6
42+ github.com/spf13/pflag v1.0.10
4343 github.com/spf13/viper v1.20.1
4444 github.com/stretchr/testify v1.11.1
4545 github.com/stuart-warren/yamlfmt v0.2.0
@@ -50,9 +50,9 @@ require (
5050 golang.org/x/exp v0.0.0-20250408133849-7e4ce0ab07d0
5151 golang.org/x/net v0.44.0
5252 golang.org/x/sync v0.17.0
53- k8s.io/apiextensions-apiserver v0.34.2
54- k8s.io/apimachinery v0.34.2
55- k8s.io/client-go v0.34.2
53+ k8s.io/apiextensions-apiserver v0.34.3
54+ k8s.io/apimachinery v0.34.3
55+ k8s.io/client-go v0.34.3
5656 k8s.io/klog/v2 v2.130.1
5757 k8s.io/kube-openapi v0.0.0-20250710124328-f3f2b991d03b
5858 oras.land/oras-go/v2 v2.6.0
@@ -67,18 +67,18 @@ require (
6767 github.com/pmezard/go-difflib v1.0.1-0.20181226105442-5d4384ee4fb2
6868 golang.org/x/text v0.29.0
6969 gopkg.in/yaml.v3 v3.0.1
70- k8s.io/api v0.34.2
70+ k8s.io/api v0.34.3
7171)
7272
7373require (
7474 cel.dev/expr v0.24.0 // indirect
75- cloud.google.com/go v0.116.0 // indirect
76- cloud.google.com/go/auth v0.13 .0 // indirect
77- cloud.google.com/go/auth/oauth2adapt v0.2.6 // indirect
75+ cloud.google.com/go v0.118.3 // indirect
76+ cloud.google.com/go/auth v0.15 .0 // indirect
77+ cloud.google.com/go/auth/oauth2adapt v0.2.8 // indirect
7878 cloud.google.com/go/compute/metadata v0.7.0 // indirect
79- cloud.google.com/go/iam v1.2.2 // indirect
80- cloud.google.com/go/monitoring v1.21.2 // indirect
81- cloud.google.com/go/storage v1.49 .0 // indirect
79+ cloud.google.com/go/iam v1.4.1 // indirect
80+ cloud.google.com/go/monitoring v1.24.0 // indirect
81+ cloud.google.com/go/storage v1.50 .0 // indirect
8282 contrib.go.opencensus.io/exporter/ocagent v0.7.1-0.20200907061046-05415f1de66d // indirect
8383 contrib.go.opencensus.io/exporter/prometheus v0.4.2 // indirect
8484 dario.cat/mergo v1.0.2 // indirect
@@ -96,8 +96,8 @@ require (
9696 github.com/Azure/go-autorest/tracing v0.6.0 // indirect
9797 github.com/BurntSushi/toml v1.5.0 // indirect
9898 github.com/GoogleCloudPlatform/opentelemetry-operations-go/detectors/gcp v1.29.0 // indirect
99- github.com/GoogleCloudPlatform/opentelemetry-operations-go/exporter/metric v0.48.1 // indirect
100- github.com/GoogleCloudPlatform/opentelemetry-operations-go/internal/resourcemapping v0.48.1 // indirect
99+ github.com/GoogleCloudPlatform/opentelemetry-operations-go/exporter/metric v0.49.0 // indirect
100+ github.com/GoogleCloudPlatform/opentelemetry-operations-go/internal/resourcemapping v0.49.0 // indirect
101101 github.com/KeisukeYamashita/go-vcl v0.4.0 // indirect
102102 github.com/Microsoft/go-winio v0.6.2 // indirect
103103 github.com/ProtonMail/go-crypto v1.1.5 // indirect
@@ -116,7 +116,7 @@ require (
116116 github.com/alibabacloud-go/tea-utils/v2 v2.0.6 // indirect
117117 github.com/alibabacloud-go/tea-xml v1.1.3 // indirect
118118 github.com/aliyun/credentials-go v1.3.9 // indirect
119- github.com/anchore/go-struct-converter v0.0.0-20230627203149-c72ef8859ca9 // indirect
119+ github.com/anchore/go-struct-converter v0.1.0 // indirect
120120 github.com/antlr4-go/antlr/v4 v4.13.1 // indirect
121121 github.com/apparentlymart/go-textseg/v15 v15.0.0 // indirect
122122 github.com/asaskevich/govalidator v0.0.0-20230301143203-a9d515a09cc2 // indirect
@@ -166,7 +166,7 @@ require (
166166 github.com/containerd/platforms v1.0.0-rc.2 // indirect
167167 github.com/containerd/stargz-snapshotter/estargz v0.16.3 // indirect
168168 github.com/containerd/typeurl/v2 v2.2.3 // indirect
169- github.com/coreos/go-oidc/v3 v3.11 .0 // indirect
169+ github.com/coreos/go-oidc/v3 v3.12 .0 // indirect
170170 github.com/cpuguy83/dockercfg v0.3.2 // indirect
171171 github.com/cpuguy83/go-md2man/v2 v2.0.7 // indirect
172172 github.com/cyberphone/json-canonicalization v0.0.0-20231217050601-ba74d44ecf5f // indirect
@@ -192,7 +192,7 @@ require (
192192 github.com/felixge/httpsnoop v1.0.4 // indirect
193193 github.com/fsnotify/fsnotify v1.9.0 // indirect
194194 github.com/fxamacker/cbor/v2 v2.9.0 // indirect
195- github.com/gkampitakis/ciinfo v0.3.0 // indirect
195+ github.com/gkampitakis/ciinfo v0.3.2 // indirect
196196 github.com/gkampitakis/go-diff v1.3.2 // indirect
197197 github.com/go-akka/configuration v0.0.0-20200606091224-a002c0330665 // indirect
198198 github.com/go-chi/chi v4.1.2+incompatible // indirect
@@ -206,15 +206,16 @@ require (
206206 github.com/go-logr/stdr v1.2.2 // indirect
207207 github.com/go-ole/go-ole v1.2.6 // indirect
208208 github.com/go-openapi/analysis v0.23.0 // indirect
209- github.com/go-openapi/errors v0.22.0 // indirect
209+ github.com/go-openapi/errors v0.22.1 // indirect
210210 github.com/go-openapi/jsonpointer v0.21.0 // indirect
211211 github.com/go-openapi/jsonreference v0.21.0 // indirect
212212 github.com/go-openapi/loads v0.22.0 // indirect
213213 github.com/go-openapi/spec v0.21.0 // indirect
214- github.com/go-openapi/swag v0.23.0 // indirect
214+ github.com/go-openapi/swag v0.23.1 // indirect
215215 github.com/go-openapi/validate v0.24.0 // indirect
216216 github.com/go-viper/mapstructure/v2 v2.3.0 // indirect
217217 github.com/gobwas/glob v0.2.3 // indirect
218+ github.com/goccy/go-yaml v1.18.0 // indirect
218219 github.com/gogo/protobuf v1.3.2 // indirect
219220 github.com/golang-jwt/jwt/v4 v4.5.2 // indirect
220221 github.com/golang/groupcache v0.0.0-20241129210726-2c02b8208cf8 // indirect
@@ -227,9 +228,9 @@ require (
227228 github.com/google/go-github/v55 v55.0.0 // indirect
228229 github.com/google/go-jsonnet v0.21.0 // indirect
229230 github.com/google/go-querystring v1.1.0 // indirect
230- github.com/google/s2a-go v0.1.8 // indirect
231+ github.com/google/s2a-go v0.1.9 // indirect
231232 github.com/google/uuid v1.6.0 // indirect
232- github.com/googleapis/enterprise-certificate-proxy v0.3.4 // indirect
233+ github.com/googleapis/enterprise-certificate-proxy v0.3.6 // indirect
233234 github.com/googleapis/gax-go/v2 v2.14.1 // indirect
234235 github.com/grpc-ecosystem/grpc-gateway/v2 v2.26.3 // indirect
235236 github.com/hashicorp/aws-sdk-go-base/v2 v2.0.0-beta.65 // indirect
@@ -245,7 +246,7 @@ require (
245246 github.com/inconshreveable/mousetrap v1.1.0 // indirect
246247 github.com/jbenet/go-context v0.0.0-20150711004518-d14ea06fba99 // indirect
247248 github.com/jedisct1/go-minisign v0.0.0-20230811132847-661be99b8267 // indirect
248- github.com/jmespath/go-jmespath v0.4.0 // indirect
249+ github.com/jmespath/go-jmespath v0.4.1-0.20220621161143-b0104c826a24 // indirect
249250 github.com/josharian/intern v1.0.0 // indirect
250251 github.com/json-iterator/go v1.1.12 // indirect
251252 github.com/jstemmer/go-junit-report v1.0.0 // indirect
@@ -257,7 +258,7 @@ require (
257258 github.com/logrusorgru/aurora v2.0.3+incompatible // indirect
258259 github.com/lufia/plan9stats v0.0.0-20211012122336-39d0f177ccd0 // indirect
259260 github.com/magiconair/properties v1.8.10 // indirect
260- github.com/mailru/easyjson v0.7.7 // indirect
261+ github.com/mailru/easyjson v0.9.0 // indirect
261262 github.com/maruel/natural v1.1.1 // indirect
262263 github.com/mattn/go-runewidth v0.0.16 // indirect
263264 github.com/miekg/pkcs11 v1.1.1 // indirect
@@ -303,13 +304,13 @@ require (
303304 github.com/sagikazarmark/locafero v0.7.0 // indirect
304305 github.com/sassoftware/relic v7.2.1+incompatible // indirect
305306 github.com/segmentio/ksuid v1.0.4 // indirect
306- github.com/sergi/go-diff v1.3.2-0.20230802210424-5b0b94c5c0d3 // indirect
307+ github.com/sergi/go-diff v1.4.0 // indirect
307308 github.com/shibumi/go-pathspec v1.3.0 // indirect
308309 github.com/shirou/gopsutil/v3 v3.23.12 // indirect
309310 github.com/shoenig/go-m1cpu v0.1.6 // indirect
310311 github.com/shteou/go-ignore v0.3.1 // indirect
311312 github.com/sigstore/fulcio v1.6.3 // indirect
312- github.com/sigstore/protobuf-specs v0.3.2 // indirect
313+ github.com/sigstore/protobuf-specs v0.4.1 // indirect
313314 github.com/sigstore/timestamp-authority v1.2.2 // indirect
314315 github.com/skeema/knownhosts v1.3.0 // indirect
315316 github.com/skratchdot/open-golang v0.0.0-20200116055534-eef842397966 // indirect
@@ -323,7 +324,7 @@ require (
323324 github.com/tchap/go-patricia/v2 v2.3.3 // indirect
324325 github.com/thales-e-security/pool v0.0.2 // indirect
325326 github.com/theupdateframework/go-tuf v0.7.0 // indirect
326- github.com/tidwall/gjson v1.17 .0 // indirect
327+ github.com/tidwall/gjson v1.18 .0 // indirect
327328 github.com/tidwall/match v1.1.1 // indirect
328329 github.com/tidwall/pretty v1.2.1 // indirect
329330 github.com/tidwall/sjson v1.2.5 // indirect
@@ -361,7 +362,7 @@ require (
361362 go.opentelemetry.io/otel/sdk/metric v1.37.0 // indirect
362363 go.opentelemetry.io/otel/trace v1.37.0 // indirect
363364 go.opentelemetry.io/proto/otlp v1.6.0 // indirect
364- go.step.sm/crypto v0.51.2 // indirect
365+ go.step.sm/crypto v0.60.0 // indirect
365366 go.uber.org/automaxprocs v1.6.0 // indirect
366367 go.uber.org/multierr v1.11.0 // indirect
367368 go.uber.org/zap v1.27.0 // indirect
@@ -375,8 +376,8 @@ require (
375376 golang.org/x/time v0.14.0 // indirect
376377 golang.org/x/tools v0.37.0 // indirect
377378 gomodules.xyz/jsonpatch/v2 v2.4.0 // indirect
378- google.golang.org/api v0.215 .0 // indirect
379- google.golang.org/genproto v0.0.0-20241118233622-e639e219e697 // indirect
379+ google.golang.org/api v0.228 .0 // indirect
380+ google.golang.org/genproto v0.0.0-20250303144028-a0af3efb3deb // indirect
380381 google.golang.org/genproto/googleapis/api v0.0.0-20250804133106-a7a43d27e69b // indirect
381382 google.golang.org/genproto/googleapis/rpc v0.0.0-20250804133106-a7a43d27e69b // indirect
382383 google.golang.org/grpc v1.76.0 // indirect
0 commit comments