@@ -71,7 +71,7 @@ require (
7171 github.com/microsoftgraph/msgraph-sdk-go-core v1.4.0
7272 github.com/mikefarah/yq/v4 v4.47.2
7373 github.com/mitchellh/gox v1.0.1
74- github.com/open-policy-agent/opa v1.7.1
74+ github.com/open-policy-agent/opa v1.8.0
7575 github.com/pierrre/gotestcover v0.0.0-20160517101806-924dca7d15f0
7676 github.com/samber/lo v1.51.0
7777 github.com/spf13/viper v1.21.0
@@ -125,18 +125,20 @@ require (
125125 cloud.google.com/go/auth v0.17.0 // indirect
126126 cloud.google.com/go/auth/oauth2adapt v0.2.8 // indirect
127127 cloud.google.com/go/monitoring v1.24.3 // indirect
128+ cloud.google.com/go/spanner v1.86.1 // indirect
128129 dario.cat/mergo v1.0.2 // indirect
129130 github.com/Azure/azure-sdk-for-go/sdk/containers/azcontainerregistry v0.2.3 // indirect
130131 github.com/Azure/azure-sdk-for-go/sdk/resourcemanager/containerservice/armcontainerservice/v4 v4.8.0 // indirect
131132 github.com/Azure/go-ntlmssp v0.0.0-20221128193559-754e69321358 // indirect
132133 github.com/DataDog/zstd v1.5.5 // indirect
134+ github.com/GoogleCloudPlatform/grpc-gcp-go/grpcgcp v1.5.3 // indirect
133135 github.com/Intevation/gval v1.3.0 // indirect
134136 github.com/Intevation/jsonpath v0.2.1 // indirect
135137 github.com/apparentlymart/go-textseg/v15 v15.0.0 // indirect
136138 github.com/aquasecurity/iamgo v0.0.10 // indirect
137139 github.com/aquasecurity/jfather v0.0.8 // indirect
138140 github.com/aquasecurity/trivy-checks v1.11.3-0.20250604022615-9a7efa7c9169 // indirect
139- github.com/aws/aws-sdk-go v1.55.7 // indirect
141+ github.com/aws/aws-sdk-go v1.55.8 // indirect
140142 github.com/aws/aws-sdk-go-v2/service/dynamodb v1.53.3 // indirect
141143 github.com/aws/aws-sdk-go-v2/service/internal/endpoint-discovery v1.11.15 // indirect
142144 github.com/aws/aws-sdk-go-v2/service/signin v1.0.3 // indirect
@@ -156,7 +158,9 @@ require (
156158 github.com/containerd/log v0.1.0 // indirect
157159 github.com/containerd/platforms v1.0.0-rc.1 // indirect
158160 github.com/containerd/plugin v1.0.0 // indirect
161+ github.com/coreos/go-oidc/v3 v3.14.1 // indirect
159162 github.com/cyberphone/json-canonicalization v0.0.0-20241213102144-19d51d7fe467 // indirect
163+ github.com/decred/dcrd/dcrec/secp256k1/v4 v4.4.0 // indirect
160164 github.com/dgraph-io/badger/v4 v4.8.0 // indirect
161165 github.com/dgraph-io/ristretto/v2 v2.2.0 // indirect
162166 github.com/digitorus/pkcs7 v0.0.0-20250730155240-ffadbf3f398c // indirect
@@ -171,7 +175,7 @@ require (
171175 github.com/fvbommel/sortorder v1.1.0 // indirect
172176 github.com/fxamacker/cbor/v2 v2.9.0 // indirect
173177 github.com/go-asn1-ber/asn1-ber v1.5.5 // indirect
174- github.com/go-chi/chi v4.1.2+incompatible // indirect
178+ github.com/go-chi/chi/v5 v5.2.3 // indirect
175179 github.com/go-git/go-git/v5 v5.16.4 // indirect
176180 github.com/go-jose/go-jose/v4 v4.1.3 // indirect
177181 github.com/go-json-experiment/json v0.0.0-20251027170946-4849db3c2f7e // indirect
@@ -190,14 +194,21 @@ require (
190194 github.com/gocsaf/csaf/v3 v3.3.0 // indirect
191195 github.com/gofrs/uuid/v5 v5.4.0 // indirect
192196 github.com/gohugoio/hashstructure v0.6.0 // indirect
193- github.com/google/certificate-transparency-go v1.1.8 // indirect
197+ github.com/google/certificate-transparency-go v1.3.2 // indirect
194198 github.com/google/gnostic-models v0.7.0 // indirect
195199 github.com/google/go-github/v62 v62.0.0 // indirect
196200 github.com/google/go-querystring v1.1.0 // indirect
197201 github.com/grpc-ecosystem/grpc-gateway/v2 v2.27.2 // indirect
198202 github.com/hashicorp/go-retryablehttp v0.7.8 // indirect
203+ github.com/in-toto/attestation v1.1.2 // indirect
199204 github.com/jcmturner/goidentity/v6 v6.0.1 // indirect
200205 github.com/jedisct1/go-minisign v0.0.0-20230811132847-661be99b8267 // indirect
206+ github.com/lestrrat-go/blackmagic v1.0.4 // indirect
207+ github.com/lestrrat-go/httpcc v1.0.1 // indirect
208+ github.com/lestrrat-go/httprc/v3 v3.0.0 // indirect
209+ github.com/lestrrat-go/jwx/v3 v3.0.10 // indirect
210+ github.com/lestrrat-go/option v1.0.1 // indirect
211+ github.com/lestrrat-go/option/v2 v2.0.0 // indirect
201212 github.com/letsencrypt/boulder v0.0.0-20240620165639-de9c06129bec // indirect
202213 github.com/mattn/go-shellwords v1.0.12 // indirect
203214 github.com/microsoft/kiota-authentication-azure-go v1.3.1 // indirect
@@ -206,8 +217,10 @@ require (
206217 github.com/microsoft/kiota-serialization-json-go v1.1.2 // indirect
207218 github.com/microsoft/kiota-serialization-multipart-go v1.1.2 // indirect
208219 github.com/microsoft/kiota-serialization-text-go v1.1.2 // indirect
209- github.com/mitchellh/mapstructure v1.5.0 // indirect
220+ github.com/mitchellh/mapstructure v1.5.1-0.20231216201459-8508981c8b6c // indirect
210221 github.com/moby/docker-image-spec v1.3.1 // indirect
222+ github.com/moby/moby/api v1.52.0 // indirect
223+ github.com/moby/moby/client v0.2.1 // indirect
211224 github.com/moby/sys/atomicwriter v0.1.0 // indirect
212225 github.com/moby/sys/user v0.4.0 // indirect
213226 github.com/moby/sys/userns v0.1.0 // indirect
@@ -216,7 +229,7 @@ require (
216229 github.com/ncruces/go-strftime v0.1.9 // indirect
217230 github.com/nozzle/throttler v0.0.0-20180817012639-2ea982251481 // indirect
218231 github.com/oklog/ulid/v2 v2.1.1 // indirect
219- github.com/openvex/discovery v0.1.1-0.20240802171711-7c54efc57553 // indirect
232+ github.com/openvex/discovery v0.1.1-0.20251205165335-709425da9ac4 // indirect
220233 github.com/pkg/errors v0.9.1 // indirect
221234 github.com/planetscale/vtprotobuf v0.6.1-0.20250313105119-ba97887b0a25 // indirect
222235 github.com/rust-secure-code/go-rustaudit v0.0.0-20250226111315-e20ec32e963c // indirect
@@ -225,20 +238,29 @@ require (
225238 github.com/santhosh-tekuri/jsonschema/v6 v6.0.2 // indirect
226239 github.com/sassoftware/go-rpmutils v0.4.0 // indirect
227240 github.com/sassoftware/relic v7.2.1+incompatible // indirect
241+ github.com/segmentio/asm v1.2.0 // indirect
242+ github.com/segmentio/ksuid v1.0.4 // indirect
228243 github.com/shirou/gopsutil/v4 v4.25.11 // indirect
229- github.com/sigstore/cosign/v2 v2.2.4 // indirect
244+ github.com/sigstore/cosign/v2 v2.6.1 // indirect
230245 github.com/sigstore/protobuf-specs v0.5.0 // indirect
231- github.com/sigstore/sigstore v1.9.5 // indirect
232- github.com/sigstore/timestamp-authority v1.2.2 // indirect
246+ github.com/sigstore/rekor-tiles v0.1.11 // indirect
247+ github.com/sigstore/sigstore v1.9.6-0.20250729224751-181c5d3339b3 // indirect
248+ github.com/sigstore/sigstore-go v1.1.3 // indirect
249+ github.com/sigstore/timestamp-authority v1.2.9 // indirect
250+ github.com/skratchdot/open-golang v0.0.0-20200116055534-eef842397966 // indirect
233251 github.com/sourcegraph/conc v0.3.1-0.20240121214520-5f936abd7ae8 // indirect
234252 github.com/spiffe/go-spiffe/v2 v2.6.0 // indirect
235253 github.com/std-uritemplate/std-uritemplate/go/v2 v2.0.5 // indirect
236254 github.com/syndtr/goleveldb v1.0.1-0.20220721030215-126854af5e6d // indirect
237255 github.com/testcontainers/testcontainers-go v0.39.0 // indirect
238256 github.com/theupdateframework/go-tuf v0.7.0 // indirect
257+ github.com/theupdateframework/go-tuf/v2 v2.2.0 // indirect
239258 github.com/titanous/rocacheck v0.0.0-20171023193734-afe73141d399 // indirect
240259 github.com/tonistiigi/go-csvvalue v0.0.0-20240814133006-030d3b2625d0 // indirect
260+ github.com/transparency-dev/formats v0.0.0-20250421220931-bb8ad4d07c26 // indirect
241261 github.com/transparency-dev/merkle v0.0.2 // indirect
262+ github.com/transparency-dev/tessera v1.0.0-rc3 // indirect
263+ github.com/valyala/fastjson v1.6.4 // indirect
242264 github.com/vektah/gqlparser/v2 v2.5.30 // indirect
243265 github.com/vmihailenco/msgpack/v5 v5.4.1 // indirect
244266 github.com/vmihailenco/tagparser/v2 v2.0.0 // indirect
@@ -336,7 +358,7 @@ require (
336358 github.com/containerd/containerd v1.7.29 // indirect
337359 github.com/containerd/continuity v0.4.5 // indirect
338360 github.com/containerd/fifo v1.1.0 // indirect
339- github.com/containerd/stargz-snapshotter/estargz v0.16.3 // indirect
361+ github.com/containerd/stargz-snapshotter/estargz v0.18.1 // indirect
340362 github.com/containerd/ttrpc v1.2.7 // indirect
341363 github.com/containerd/typeurl/v2 v2.2.3 // indirect
342364 github.com/cyphar/filepath-securejoin v0.5.1 // indirect
@@ -345,9 +367,9 @@ require (
345367 github.com/dimchansky/utfbom v1.1.1 // indirect
346368 github.com/dlclark/regexp2 v1.11.0 // indirect
347369 github.com/dnephin/pflag v1.0.7 // indirect
348- github.com/docker/cli v28.3 .3+incompatible // indirect
370+ github.com/docker/cli v29.0 .3+incompatible // indirect
349371 github.com/docker/distribution v2.8.3+incompatible // indirect
350- github.com/docker/docker v28.4.0 +incompatible // indirect
372+ github.com/docker/docker v28.5.2 +incompatible // indirect
351373 github.com/docker/docker-credential-helpers v0.9.3 // indirect
352374 github.com/docker/go-connections v0.6.0 // indirect
353375 github.com/docker/go-units v0.5.0 // indirect
@@ -405,7 +427,7 @@ require (
405427 github.com/google/btree v1.1.3 // indirect
406428 github.com/google/flatbuffers v25.2.10+incompatible // indirect
407429 github.com/google/go-cmp v0.7.0 // indirect
408- github.com/google/go-containerregistry v0.20.6
430+ github.com/google/go-containerregistry v0.20.7
409431 github.com/google/licenseclassifier v0.0.0-20251014224845-584483407d21 // indirect
410432 github.com/google/licenseclassifier/v2 v2.0.0 // indirect
411433 github.com/google/s2a-go v0.1.9 // indirect
@@ -439,7 +461,7 @@ require (
439461 github.com/jinzhu/copier v0.4.0 // indirect
440462 github.com/jmespath/go-jmespath v0.4.1-0.20220621161143-b0104c826a24 // indirect
441463 github.com/jmoiron/sqlx v1.4.0 // indirect
442- github.com/jonboulle/clockwork v0.4 .0 // indirect
464+ github.com/jonboulle/clockwork v0.5 .0 // indirect
443465 github.com/josephspurrier/goversioninfo v1.5.0 // indirect
444466 github.com/json-iterator/go v1.1.12 // indirect
445467 github.com/kevinburke/ssh_config v1.2.0 // indirect
@@ -489,7 +511,7 @@ require (
489511 github.com/opencontainers/image-spec v1.1.1 // indirect
490512 github.com/opencontainers/runtime-spec v1.2.1 // indirect
491513 github.com/opencontainers/selinux v1.13.1 // indirect
492- github.com/openvex/go-vex v0.2.5 // indirect
514+ github.com/openvex/go-vex v0.2.7 // indirect
493515 github.com/owenrumney/go-sarif/v2 v2.3.3 // indirect
494516 github.com/owenrumney/squealer v1.2.11 // indirect
495517 github.com/package-url/packageurl-go v0.1.3 // indirect
@@ -513,7 +535,7 @@ require (
513535 github.com/sergi/go-diff v1.4.0 // indirect
514536 github.com/shibumi/go-pathspec v1.3.0 // indirect
515537 github.com/shopspring/decimal v1.4.0 // indirect
516- github.com/sigstore/rekor v1.4.0 // indirect
538+ github.com/sigstore/rekor v1.4.2 // indirect
517539 github.com/sirupsen/logrus v1.9.3 // indirect
518540 github.com/skeema/knownhosts v1.3.1 // indirect
519541 github.com/spdx/tools-golang v0.5.5 // indirect
@@ -530,7 +552,7 @@ require (
530552 github.com/twitchtv/twirp v8.1.3+incompatible // indirect
531553 github.com/ugorji/go/codec v1.1.8 // indirect
532554 github.com/ulikunitz/xz v0.5.15 // indirect
533- github.com/vbatts/tar-split v0.12.1 // indirect
555+ github.com/vbatts/tar-split v0.12.2 // indirect
534556 github.com/xanzy/ssh-agent v0.3.3 // indirect
535557 github.com/xeipuuv/gojsonpointer v0.0.0-20190905194746-02993c407bfb // indirect
536558 github.com/xeipuuv/gojsonreference v0.0.0-20180127040603-bd5ef7bd5415 // indirect
0 commit comments