Skip to content

Commit 2e9112d

Browse files
authored
fix(deps): lock file maintenance vulnfeeds (google#3606)
This PR contains the following updates: | Package | Type | Update | Change | Age | Adoption | Passing | Confidence | |---|---|---|---|---|---|---|---| | | | lockFileMaintenance | All locks refreshed | | | | | | [cloud.google.com/go/secretmanager](https://redirect.github.com/googleapis/google-cloud-go) | require | minor | `v1.14.7` -> `v1.15.0` | [![age](https://developer.mend.io/api/mc/badges/age/go/cloud.google.com%2fgo%2fsecretmanager/v1.15.0?slim=true)](https://docs.renovatebot.com/merge-confidence/) | [![adoption](https://developer.mend.io/api/mc/badges/adoption/go/cloud.google.com%2fgo%2fsecretmanager/v1.15.0?slim=true)](https://docs.renovatebot.com/merge-confidence/) | [![passing](https://developer.mend.io/api/mc/badges/compatibility/go/cloud.google.com%2fgo%2fsecretmanager/v1.14.7/v1.15.0?slim=true)](https://docs.renovatebot.com/merge-confidence/) | [![confidence](https://developer.mend.io/api/mc/badges/confidence/go/cloud.google.com%2fgo%2fsecretmanager/v1.14.7/v1.15.0?slim=true)](https://docs.renovatebot.com/merge-confidence/) | | gcr.io/google.com/cloudsdktool/google-cloud-cli | final | digest | `ca70dd0` -> `0820bec` | | | | | | golang.org/x/exp | require | digest | `dcc06ee` -> `b7579e2` | [![age](https://developer.mend.io/api/mc/badges/age/go/golang.org%2fx%2fexp/v0.0.0-20250620022241-b7579e27df2b?slim=true)](https://docs.renovatebot.com/merge-confidence/) | [![adoption](https://developer.mend.io/api/mc/badges/adoption/go/golang.org%2fx%2fexp/v0.0.0-20250620022241-b7579e27df2b?slim=true)](https://docs.renovatebot.com/merge-confidence/) | [![passing](https://developer.mend.io/api/mc/badges/compatibility/go/golang.org%2fx%2fexp/v0.0.0-20250606033433-dcc06ee1d476/v0.0.0-20250620022241-b7579e27df2b?slim=true)](https://docs.renovatebot.com/merge-confidence/) | [![confidence](https://developer.mend.io/api/mc/badges/confidence/go/golang.org%2fx%2fexp/v0.0.0-20250606033433-dcc06ee1d476/v0.0.0-20250620022241-b7579e27df2b?slim=true)](https://docs.renovatebot.com/merge-confidence/) | 🔧 This Pull Request updates lock files to use the latest dependency versions. --- ### Configuration 📅 **Schedule**: Branch creation - "before 6am on wednesday" in timezone Australia/Sydney, Automerge - At any time (no schedule defined). 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 👻 **Immortal**: This PR will be recreated if closed unmerged. Get [config help](https://redirect.github.com/renovatebot/renovate/discussions) if that's undesired. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/google/osv.dev). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0MC42Mi4xIiwidXBkYXRlZEluVmVyIjoiNDAuNjIuMSIsInRhcmdldEJyYW5jaCI6Im1hc3RlciIsImxhYmVscyI6WyJkZXBlbmRlbmNpZXMiXX0=-->
1 parent 63663bd commit 2e9112d

File tree

11 files changed

+135
-135
lines changed

11 files changed

+135
-135
lines changed

vulnfeeds/cmd/alpine/Dockerfile

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -25,7 +25,7 @@ COPY ./ /src/
2525
RUN go build -o alpine-osv ./cmd/alpine/
2626

2727

28-
FROM gcr.io/google.com/cloudsdktool/google-cloud-cli:alpine@sha256:ca70dd0fcf3924c9b05527b55fe0cc08eff55bc970941101fcf28041a3a08e69
28+
FROM gcr.io/google.com/cloudsdktool/google-cloud-cli:alpine@sha256:0820becf1b7e9ed9ee4d7ee8694428d72430138ec44a83b7e9552827b702ef25
2929

3030
WORKDIR /root/
3131
COPY --from=GO_BUILD /src/alpine-osv ./

vulnfeeds/cmd/combine-to-osv/Dockerfile

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -26,7 +26,7 @@ RUN go build -o combine-to-osv ./cmd/combine-to-osv/
2626
RUN go build -o download-cves ./cmd/download-cves/
2727

2828

29-
FROM gcr.io/google.com/cloudsdktool/google-cloud-cli:alpine@sha256:ca70dd0fcf3924c9b05527b55fe0cc08eff55bc970941101fcf28041a3a08e69
29+
FROM gcr.io/google.com/cloudsdktool/google-cloud-cli:alpine@sha256:0820becf1b7e9ed9ee4d7ee8694428d72430138ec44a83b7e9552827b702ef25
3030
RUN apk --no-cache add jq
3131

3232
WORKDIR /root/

vulnfeeds/cmd/cpe-repo-gen/Dockerfile

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -24,7 +24,7 @@ RUN go mod download
2424
COPY ./ /src/
2525
RUN CGO_ENABLED=0 go build -o cpe-repo-gen ./cmd/cpe-repo-gen
2626

27-
FROM gcr.io/google.com/cloudsdktool/google-cloud-cli:alpine@sha256:ca70dd0fcf3924c9b05527b55fe0cc08eff55bc970941101fcf28041a3a08e69
27+
FROM gcr.io/google.com/cloudsdktool/google-cloud-cli:alpine@sha256:0820becf1b7e9ed9ee4d7ee8694428d72430138ec44a83b7e9552827b702ef25
2828

2929
COPY --from=GO_BUILD /src/cpe-repo-gen ./
3030
COPY ./cmd/cpe-repo-gen/cpe-repo-gen_map.sh ./

vulnfeeds/cmd/debian-copyright-mirror/Dockerfile

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -12,7 +12,7 @@
1212
# See the License for the specific language governing permissions and
1313
# limitations under the License.
1414

15-
FROM gcr.io/google.com/cloudsdktool/google-cloud-cli:alpine@sha256:ca70dd0fcf3924c9b05527b55fe0cc08eff55bc970941101fcf28041a3a08e69
15+
FROM gcr.io/google.com/cloudsdktool/google-cloud-cli:alpine@sha256:0820becf1b7e9ed9ee4d7ee8694428d72430138ec44a83b7e9552827b702ef25
1616

1717
RUN apk add py3-yaml
1818

vulnfeeds/cmd/debian/Dockerfile

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -25,7 +25,7 @@ COPY ./ /src/
2525
RUN go build -o debian-osv ./cmd/debian/
2626

2727

28-
FROM gcr.io/google.com/cloudsdktool/google-cloud-cli:alpine@sha256:ca70dd0fcf3924c9b05527b55fe0cc08eff55bc970941101fcf28041a3a08e69
28+
FROM gcr.io/google.com/cloudsdktool/google-cloud-cli:alpine@sha256:0820becf1b7e9ed9ee4d7ee8694428d72430138ec44a83b7e9552827b702ef25
2929

3030
WORKDIR /root/
3131
COPY --from=GO_BUILD /src/debian-osv ./

vulnfeeds/cmd/download-cves/Dockerfile

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -24,7 +24,7 @@ RUN go mod download
2424
COPY ./ /src/
2525
RUN go build -o download-cves ./cmd/download-cves/
2626

27-
FROM gcr.io/google.com/cloudsdktool/google-cloud-cli:alpine@sha256:ca70dd0fcf3924c9b05527b55fe0cc08eff55bc970941101fcf28041a3a08e69
27+
FROM gcr.io/google.com/cloudsdktool/google-cloud-cli:alpine@sha256:0820becf1b7e9ed9ee4d7ee8694428d72430138ec44a83b7e9552827b702ef25
2828
RUN apk --no-cache add jq
2929

3030
WORKDIR /usr/local/bin

vulnfeeds/cmd/nvd-cve-osv/Dockerfile

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -22,7 +22,7 @@ RUN go mod download && go mod verify
2222
COPY . .
2323
RUN CGO_ENABLED=0 go build -v -o /usr/local/bin ./cmd/nvd-cve-osv ./cmd/download-cves
2424

25-
FROM gcr.io/google.com/cloudsdktool/google-cloud-cli:alpine@sha256:ca70dd0fcf3924c9b05527b55fe0cc08eff55bc970941101fcf28041a3a08e69
25+
FROM gcr.io/google.com/cloudsdktool/google-cloud-cli:alpine@sha256:0820becf1b7e9ed9ee4d7ee8694428d72430138ec44a83b7e9552827b702ef25
2626
RUN apk --no-cache add jq
2727

2828
COPY --from=GO_BUILD /usr/local/bin/ ./usr/local/bin/

vulnfeeds/go.mod

Lines changed: 23 additions & 23 deletions
Original file line numberDiff line numberDiff line change
@@ -4,26 +4,26 @@ go 1.23.6
44

55
require (
66
cloud.google.com/go/logging v1.13.0
7-
cloud.google.com/go/secretmanager v1.14.7
7+
cloud.google.com/go/secretmanager v1.15.0
88
github.com/aquasecurity/go-pep440-version v0.0.1
99
github.com/atombender/go-jsonschema v0.20.0
1010
github.com/go-git/go-git/v5 v5.16.2
1111
github.com/google/go-cmp v0.7.0
1212
github.com/google/osv-scanner v1.9.2
1313
github.com/knqyf263/go-cpe v0.0.0-20230627041855-cb0794d06872
1414
github.com/sethvargo/go-retry v0.3.0
15-
golang.org/x/exp v0.0.0-20250606033433-dcc06ee1d476
15+
golang.org/x/exp v0.0.0-20250620022241-b7579e27df2b
1616
gopkg.in/dnaeon/go-vcr.v4 v4.0.3
1717
gopkg.in/yaml.v2 v2.4.0
1818
)
1919

2020
require (
2121
cloud.google.com/go v0.120.0 // indirect
22-
cloud.google.com/go/auth v0.16.0 // indirect
22+
cloud.google.com/go/auth v0.16.2 // indirect
2323
cloud.google.com/go/auth/oauth2adapt v0.2.8 // indirect
24-
cloud.google.com/go/compute/metadata v0.6.0 // indirect
25-
cloud.google.com/go/iam v1.5.0 // indirect
26-
cloud.google.com/go/longrunning v0.6.6 // indirect
24+
cloud.google.com/go/compute/metadata v0.7.0 // indirect
25+
cloud.google.com/go/iam v1.5.2 // indirect
26+
cloud.google.com/go/longrunning v0.6.7 // indirect
2727
dario.cat/mergo v1.0.2 // indirect
2828
github.com/Microsoft/go-winio v0.6.2 // indirect
2929
github.com/ProtonMail/go-crypto v1.1.6 // indirect
@@ -39,7 +39,7 @@ require (
3939
github.com/golang/groupcache v0.0.0-20241129210726-2c02b8208cf8 // indirect
4040
github.com/google/s2a-go v0.1.9 // indirect
4141
github.com/googleapis/enterprise-certificate-proxy v0.3.6 // indirect
42-
github.com/googleapis/gax-go/v2 v2.14.1 // indirect
42+
github.com/googleapis/gax-go/v2 v2.14.2 // indirect
4343
github.com/jbenet/go-context v0.0.0-20150711004518-d14ea06fba99 // indirect
4444
github.com/kevinburke/ssh_config v1.2.0 // indirect
4545
github.com/package-url/packageurl-go v0.1.3 // indirect
@@ -49,24 +49,24 @@ require (
4949
github.com/skeema/knownhosts v1.3.1 // indirect
5050
github.com/xanzy/ssh-agent v0.3.3 // indirect
5151
go.opentelemetry.io/auto/sdk v1.1.0 // indirect
52-
go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc v0.60.0 // indirect
53-
go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.60.0 // indirect
54-
go.opentelemetry.io/otel v1.35.0 // indirect
55-
go.opentelemetry.io/otel/metric v1.35.0 // indirect
56-
go.opentelemetry.io/otel/trace v1.35.0 // indirect
57-
golang.org/x/crypto v0.37.0 // indirect
58-
golang.org/x/net v0.39.0 // indirect
59-
golang.org/x/oauth2 v0.29.0 // indirect
52+
go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc v0.61.0 // indirect
53+
go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.61.0 // indirect
54+
go.opentelemetry.io/otel v1.36.0 // indirect
55+
go.opentelemetry.io/otel/metric v1.36.0 // indirect
56+
go.opentelemetry.io/otel/trace v1.36.0 // indirect
57+
golang.org/x/crypto v0.39.0 // indirect
58+
golang.org/x/net v0.41.0 // indirect
59+
golang.org/x/oauth2 v0.30.0 // indirect
6060
golang.org/x/sync v0.15.0 // indirect
61-
golang.org/x/sys v0.32.0 // indirect
62-
golang.org/x/text v0.24.0 // indirect
63-
golang.org/x/time v0.11.0 // indirect
61+
golang.org/x/sys v0.33.0 // indirect
62+
golang.org/x/text v0.26.0 // indirect
63+
golang.org/x/time v0.12.0 // indirect
6464
golang.org/x/xerrors v0.0.0-20240903120638-7835f813f4da // indirect
65-
google.golang.org/api v0.229.0 // indirect
66-
google.golang.org/genproto v0.0.0-20250303144028-a0af3efb3deb // indirect
67-
google.golang.org/genproto/googleapis/api v0.0.0-20250414145226-207652e42e2e // indirect
68-
google.golang.org/genproto/googleapis/rpc v0.0.0-20250414145226-207652e42e2e // indirect
69-
google.golang.org/grpc v1.71.1 // indirect
65+
google.golang.org/api v0.237.0 // indirect
66+
google.golang.org/genproto v0.0.0-20250505200425-f936aa4a68b2 // indirect
67+
google.golang.org/genproto/googleapis/api v0.0.0-20250603155806-513f23925822 // indirect
68+
google.golang.org/genproto/googleapis/rpc v0.0.0-20250603155806-513f23925822 // indirect
69+
google.golang.org/grpc v1.73.0 // indirect
7070
google.golang.org/protobuf v1.36.6 // indirect
7171
gopkg.in/warnings.v0 v0.1.2 // indirect
7272
gopkg.in/yaml.v3 v3.0.1 // indirect

0 commit comments

Comments
 (0)