@@ -172,8 +172,8 @@ github.com/go-git/go-billy/v5 v5.6.2 h1:6Q86EsPXMa7c3YZ3aLAQsMA0VlWmy43r6FHqa/UN
172172github.com/go-git/go-billy/v5  v5.6.2 /go.mod  h1:rcFC2rAsp/erv7CMz9GczHcuD0D32fWzH+MJAU+jaUU =
173173github.com/go-git/go-git-fixtures/v4  v4.3.2-0.20231010084843-55a94097c399  h1:eMje31YglSBqCdIqdhKBW8lokaMrL3uTkpGYlE2OOT4 =
174174github.com/go-git/go-git-fixtures/v4  v4.3.2-0.20231010084843-55a94097c399 /go.mod  h1:1OCfN199q1Jm3HZlxleg+Dw/mwps2Wbk9frAWm+4FII =
175- github.com/go-git/go-git/v5  v5.16.2   h1:fT6ZIOjE5iEnkzKyxTHK1W4HGAsPhqEqiSAssSO77hM =
176- github.com/go-git/go-git/v5  v5.16.2  /go.mod  h1:4Ge4alE/5gPs30F2H1esi2gPd69R0C39lolkucHBOp8 =
175+ github.com/go-git/go-git/v5  v5.16.3   h1:Z8BtvxZ09bYm/yYNgPKCzgWtaRqDTgIKRgIRHBfU6Z8 =
176+ github.com/go-git/go-git/v5  v5.16.3  /go.mod  h1:4Ge4alE/5gPs30F2H1esi2gPd69R0C39lolkucHBOp8 =
177177github.com/go-logr/logr  v1.2.2 /go.mod  h1:jdQByPbusPIv2/zmleS9BjJVeZ6kBagPoEUsqbVz/1A =
178178github.com/go-logr/logr  v1.4.3  h1:CjnDlHq8ikf6E492q6eKboGOC0T8CDaOvkHCIg8idEI =
179179github.com/go-logr/logr  v1.4.3 /go.mod  h1:9T104GzyrTigFIr8wt5mBrctHMim0Nb2HLGrmQ40KvY =
@@ -314,8 +314,8 @@ github.com/opencontainers/runtime-spec v1.2.1 h1:S4k4ryNgEpxW1dzyqffOmhI1BHYcjzU
314314github.com/opencontainers/runtime-spec  v1.2.1 /go.mod  h1:jwyrGlmzljRJv/Fgzds9SsS/C5hL+LL3ko9hs6T5lQ0 =
315315github.com/opencontainers/selinux  v1.12.0  h1:6n5JV4Cf+4y0KNXW48TLj5DwfXpvWlxXplUkdTrmPb8 =
316316github.com/opencontainers/selinux  v1.12.0 /go.mod  h1:BTPX+bjVbWGXw7ZZWUbdENt8w0htPSrlgOOysQaU62U =
317- github.com/ossf/osv-schema/bindings/go  v0.0.0-20250926044009-f6ae0b6bae32   h1:QFuqxEaRdRapDSJYMrl/5vAxYl5ZvIqtWszhuy/EeRs =
318- github.com/ossf/osv-schema/bindings/go  v0.0.0-20250926044009-f6ae0b6bae32  /go.mod  h1:/ypmJBpoMvgNp4g93snzyYoyIPmZfLdSiGn/Vq07Dfo =
317+ github.com/ossf/osv-schema/bindings/go  v0.0.0-20251012234424-434020c6442f   h1:0AlxQEA7JATli/nATcQ66fAASlokay8Qpcdjhqxd1gU =
318+ github.com/ossf/osv-schema/bindings/go  v0.0.0-20251012234424-434020c6442f  /go.mod  h1:/ypmJBpoMvgNp4g93snzyYoyIPmZfLdSiGn/Vq07Dfo =
319319github.com/owenrumney/go-sarif/v3  v3.2.3  h1:n6mdX5ugKwCrZInvBsf6WumXmpAe3mbmQXgkXlIq34U =
320320github.com/owenrumney/go-sarif/v3  v3.2.3 /go.mod  h1:1bV7t8SZg7pX41spaDkEUs8/yEjzk9JapztMoX1XNjg =
321321github.com/package-url/packageurl-go  v0.1.3  h1:4juMED3hHiz0set3Vq3KeQ75KD1avthoXLtmE3I0PLs =
@@ -462,8 +462,8 @@ golang.org/x/crypto v0.0.0-20191011191535-87dc89f01550/go.mod h1:yigFU9vqHzYiE8U
462462golang.org/x/crypto  v0.0.0-20200622213623-75b288015ac9 /go.mod  h1:LzIPMQfyMNhhGPhUkYOs5KpL4U8rLKemX1yGLhDgUto =
463463golang.org/x/crypto  v0.0.0-20210921155107-089bfa567519 /go.mod  h1:GvvjBRRGRdwPK5ydBHafDWAxML/pGHZbMvKqRZ5+Abc =
464464golang.org/x/crypto  v0.0.0-20220622213112-05595931fe9d /go.mod  h1:IxCIyHEi3zRg3s0A5j5BB6A9Jmi73HwBIUl50j+osU4 =
465- golang.org/x/crypto  v0.42 .0  h1:chiH31gIWm57EkTXpwnqf8qeuMUi0yekh6mT2AvFlqI =
466- golang.org/x/crypto  v0.42 .0 /go.mod  h1:4+rDnOTJhQCx2q7/j6rAN5XDw8kPjeaXEUR2eL94ix8 =
465+ golang.org/x/crypto  v0.43 .0  h1:dduJYIi3A3KOfdGOHX8AVZ/jGiyPa3IbBozJ5kNuE04 =
466+ golang.org/x/crypto  v0.43 .0 /go.mod  h1:BFbav4mRNlXJL4wNeejLpWxB7wMbc79PdRGhWKncxR0 =
467467golang.org/x/exp  v0.0.0-20190121172915-509febef88a4 /go.mod  h1:CJ0aWSM057203Lf6IL+f9T1iT9GByDxfZKAQTCR3kQA =
468468golang.org/x/exp  v0.0.0-20250711185948-6ae5c78190dc  h1:TS73t7x3KarrNd5qAipmspBDS1rkMcgVG/fS1aRb4Rc =
469469golang.org/x/exp  v0.0.0-20250711185948-6ae5c78190dc /go.mod  h1:A+z0yzpGtvnG90cToK5n2tu8UJVP2XUATh+r+sfOOOc =
@@ -473,8 +473,8 @@ golang.org/x/lint v0.0.0-20190313153728-d0100b6bd8b3/go.mod h1:6SW0HCj/g11FgYtHl
473473golang.org/x/mod  v0.2.0 /go.mod  h1:s0Qsj1ACt9ePp/hMypM3fl4fZqREWJwdYDEqhRiZZUA =
474474golang.org/x/mod  v0.3.0 /go.mod  h1:s0Qsj1ACt9ePp/hMypM3fl4fZqREWJwdYDEqhRiZZUA =
475475golang.org/x/mod  v0.6.0-dev.0.20220419223038-86c51ed26bb4 /go.mod  h1:jJ57K6gSWd91VN4djpZkiMVwK6gcyfeH4XE8wZrZaV4 =
476- golang.org/x/mod  v0.27 .0  h1:kb+q2PyFnEADO2IEF935ehFUXlWiNjJWtRNgBLSfbxQ =
477- golang.org/x/mod  v0.27 .0 /go.mod  h1:rWI627Fq0DEoudcK+MBkNkCe0EetEaDSwJJkCcjpazc =
476+ golang.org/x/mod  v0.28 .0  h1:gQBtGhjxykdjY9YhZpSlZIsbnaE2+PgjfLWUQTnoZ1U =
477+ golang.org/x/mod  v0.28 .0 /go.mod  h1:yfB/L0NOf/kmEbXjzCPOx1iK1fRutOydrCMsqRhEBxI =
478478golang.org/x/net  v0.0.0-20180724234803-3673e40ba225 /go.mod  h1:mL1N/T3taQHkDXs73rZJwtUhF3w3ftmwwsq0BUmARs4 =
479479golang.org/x/net  v0.0.0-20180826012351-8a410e7b638d /go.mod  h1:mL1N/T3taQHkDXs73rZJwtUhF3w3ftmwwsq0BUmARs4 =
480480golang.org/x/net  v0.0.0-20190213061140-3a22650c66bd /go.mod  h1:mL1N/T3taQHkDXs73rZJwtUhF3w3ftmwwsq0BUmARs4 =
@@ -487,8 +487,8 @@ golang.org/x/net v0.0.0-20201110031124-69a78807bb2b/go.mod h1:sp8m0HH+o8qH0wwXwY
487487golang.org/x/net  v0.0.0-20210226172049-e18ecbb05110 /go.mod  h1:m0MpNAwzfU5UDzcl9v0D8zg8gWTRqZa9RBIspLL5mdg =
488488golang.org/x/net  v0.0.0-20211112202133-69e39bad7dc2 /go.mod  h1:9nx3DQGgdP8bBQD5qxJ1jj9UTztislL4KSBs9R2vV5Y =
489489golang.org/x/net  v0.0.0-20220722155237-a158d28d115b /go.mod  h1:XRhObCWvk6IyKnWLug+ECip1KBveYUHfp+8e9klMJ9c =
490- golang.org/x/net  v0.44 .0  h1:evd8IRDyfNBMBTTY5XRF1vaZlD+EmWx6x8PkhR04H/I =
491- golang.org/x/net  v0.44 .0 /go.mod  h1:ECOoLqd5U3Lhyeyo/QDCEVQ4sNgYsqvCZ722XogGieY =
490+ golang.org/x/net  v0.46 .0  h1:giFlY12I07fugqwPuWJi68oOnpfqFnJIJzaIIm2JVV4 =
491+ golang.org/x/net  v0.46 .0 /go.mod  h1:Q9BGdFy1y4nkUwiLvT5qtyhAnEHgnQ/zd8PfU6nc210 =
492492golang.org/x/oauth2  v0.0.0-20180821212333-d2e6202438be /go.mod  h1:N/0e6XlmueqKjAGxoOufVs8QHGRruUQn6yWY3a++T0U =
493493golang.org/x/oauth2  v0.30.0  h1:dnDm7JmhM45NNpd8FDDeLhK6FwqbOf4MLCM9zb1BOHI =
494494golang.org/x/oauth2  v0.30.0 /go.mod  h1:B++QgG3ZKulg6sRPGD/mqlHQs5rB3Ml9erfeDY7xKlU =
@@ -516,21 +516,21 @@ golang.org/x/sys v0.0.0-20220520151302-bc2c85ada10a/go.mod h1:oPkhp1MJrh7nUepCBc
516516golang.org/x/sys  v0.0.0-20220715151400-c0bba94af5f8 /go.mod  h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg =
517517golang.org/x/sys  v0.0.0-20220722155257-8c9f86f7a55f /go.mod  h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg =
518518golang.org/x/sys  v0.6.0 /go.mod  h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg =
519- golang.org/x/sys  v0.36 .0  h1:KVRy2GtZBrk1cBYA7MKu5bEZFxQk4NIDV6RLVcC8o0k =
520- golang.org/x/sys  v0.36 .0 /go.mod  h1:OgkHotnGiDImocRcuBABYBEXf8A9a87e/uXjp9XT3ks =
521- golang.org/x/telemetry  v0.0.0-20250807160809-1a19826ec488   h1:3doPGa+Gg4snce233aCWnbZVFsyFMo/dR40KK/6skyE =
522- golang.org/x/telemetry  v0.0.0-20250807160809-1a19826ec488  /go.mod  h1:fGb/2+tgXXjhjHsTNdVEEMZNWA0quBnfrO+AfoDSAKw =
519+ golang.org/x/sys  v0.37 .0  h1:fdNQudmxPjkdUTPnLn5mdQv7Zwvbvpaxqs831goi9kQ =
520+ golang.org/x/sys  v0.37 .0 /go.mod  h1:OgkHotnGiDImocRcuBABYBEXf8A9a87e/uXjp9XT3ks =
521+ golang.org/x/telemetry  v0.0.0-20250908211612-aef8a434d053   h1:dHQOQddU4YHS5gY33/6klKjq7Gp3WwMyOXGNp5nzRj8 =
522+ golang.org/x/telemetry  v0.0.0-20250908211612-aef8a434d053  /go.mod  h1:+nZKN+XVh4LCiA9DV3ywrzN4gumyCnKjau3NGb9SGoE =
523523golang.org/x/term  v0.0.0-20201126162022-7de9c90e9dd1 /go.mod  h1:bj7SfCRtBDWHUb9snDiAeCFNEtKQo2Wmx5Cou7ajbmo =
524524golang.org/x/term  v0.0.0-20210927222741-03fcf44c2211 /go.mod  h1:jbD1KX2456YbFQfuXm/mYQcufACuNUgVhRMnK/tPxf8 =
525- golang.org/x/term  v0.35 .0  h1:bZBVKBudEyhRcajGcNc3jIfWPqV4y/Kt2XcoigOWtDQ =
526- golang.org/x/term  v0.35 .0 /go.mod  h1:TPGtkTLesOwf2DE8CgVYiZinHAOuy5AYUYT1lENIZnA =
525+ golang.org/x/term  v0.36 .0  h1:zMPR+aF8gfksFprF/Nc/rd1wRS1EI6nDBGyWAvDzx2Q =
526+ golang.org/x/term  v0.36 .0 /go.mod  h1:Qu394IJq6V6dCBRgwqshf3mPF85AqzYEzofzRdZkWss =
527527golang.org/x/text  v0.3.0 /go.mod  h1:NqM8EUOU14njkJ3fqMW+pc6Ldnwhi/IjpwHt7yyuwOQ =
528528golang.org/x/text  v0.3.3 /go.mod  h1:5Zoc/QRtKVWzQhOtBMvqHzDpF6irO9z98xDceosuGiQ =
529529golang.org/x/text  v0.3.6 /go.mod  h1:5Zoc/QRtKVWzQhOtBMvqHzDpF6irO9z98xDceosuGiQ =
530530golang.org/x/text  v0.3.7 /go.mod  h1:u+2+/6zg+i71rQMx5EYifcz6MCKuco9NR6JIITiCfzQ =
531531golang.org/x/text  v0.7.0 /go.mod  h1:mrYo+phRRbMaCq/xk9113O4dZlRixOauAjOtrjsXDZ8 =
532- golang.org/x/text  v0.29 .0  h1:1neNs90w9YzJ9BocxfsQNHKuAT4pkghyXc4nhZ6sJvk =
533- golang.org/x/text  v0.29 .0 /go.mod  h1:7MhJOA9CD2qZyOKYazxdYMF85OwPdEr9jTtBpO7ydH4 =
532+ golang.org/x/text  v0.30 .0  h1:yznKA/E9zq54KzlzBEAWn1NXSQ8DIp/NYMy88xJjl4k =
533+ golang.org/x/text  v0.30 .0 /go.mod  h1:yDdHFIX9t+tORqspjENWgzaCVXgk0yYnYuSZ8UzzBVM =
534534golang.org/x/time  v0.11.0  h1:/bpjEDfN9tkoN/ryeYHnv5hcMlc8ncjMcM4XBk5NWV0 =
535535golang.org/x/time  v0.11.0 /go.mod  h1:CDIdPxbZBQxdj6cxyCIdrNogrJKMJ7pr37NYpMcMDSg =
536536golang.org/x/tools  v0.0.0-20180917221912-90fa682c2a6e /go.mod  h1:n7NCudcB/nEzxVGmLbDWY5pfWTLqBcC2KZ6jyYvM4mQ =
@@ -542,8 +542,8 @@ golang.org/x/tools v0.0.0-20191119224855-298f0cb1881e/go.mod h1:b+2E5dAYhXwXZwtn
542542golang.org/x/tools  v0.0.0-20200619180055-7c47624df98f /go.mod  h1:EkVYQZoAsY45+roYkvgYkIh4xh/qjgUK9TdY2XT94GE =
543543golang.org/x/tools  v0.0.0-20210106214847-113979e3529a /go.mod  h1:emZCQorbCU4vsT4fOWvOPXz4eW1wZW4PmDk9uLelYpA =
544544golang.org/x/tools  v0.1.12 /go.mod  h1:hNGJHUnrk76NpqgfD5Aqm5Crs+Hm0VOH/i9J2+nxYbc =
545- golang.org/x/tools  v0.36 .0  h1:kWS0uv/zsvHEle1LbV5LE8QujrxB3wfQyxHfhOk0Qkg =
546- golang.org/x/tools  v0.36 .0 /go.mod  h1:WBDiHKJK8YgLHlcQPYQzNCkUxUypCaa5ZegCVutKm+s =
545+ golang.org/x/tools  v0.37 .0  h1:DVSRzp7FwePZW356yEAChSdNcQo6Nsp+fex1SUW09lE =
546+ golang.org/x/tools  v0.37 .0 /go.mod  h1:MBN5QPQtLMHVdvsbtarmTNukZDdgwdwlO5qGacAzF0w =
547547golang.org/x/tools/go/expect  v0.1.0-deprecated  h1:jY2C5HGYR5lqex3gEniOQL0r7Dq5+VGVgY1nudX5lXY =
548548golang.org/x/tools/go/expect  v0.1.0-deprecated /go.mod  h1:eihoPOH+FgIqa3FpoTwguz/bVUSGBlGQU67vpBeOrBY =
549549golang.org/x/tools/go/packages/packagestest  v0.1.1-deprecated  h1:1h2MnaIAIXISqTFKdENegdpAgUXz6NrPEsbIeWaBRvM =
@@ -565,17 +565,17 @@ google.golang.org/genproto v0.0.0-20190819201941-24fa4b261c55/go.mod h1:DMBHOl98
565565google.golang.org/genproto  v0.0.0-20200526211855-cb27e3aa2013 /go.mod  h1:NbSheEEYHJ7i3ixzK3sjbqSGDJWnxyFXZblF3eUsNvo =
566566google.golang.org/genproto  v0.0.0-20250707201910-8d1bb00bc6a7  h1:FGOcxvKlJgRBVbXeugjljCfCgfKWhC42FBoYmTCWVBs =
567567google.golang.org/genproto  v0.0.0-20250707201910-8d1bb00bc6a7 /go.mod  h1:249YoW4b1INqFTEop2T4aJgiO7UBYJrpejsaLvjWfI8 =
568- google.golang.org/genproto/googleapis/api  v0.0.0-20250707201910-8d1bb00bc6a7   h1:FiusG7LWj+4byqhbvmB+Q93B/mOxJLN2DTozDuZm4EU =
569- google.golang.org/genproto/googleapis/api  v0.0.0-20250707201910-8d1bb00bc6a7  /go.mod  h1:kXqgZtrWaf6qS3jZOCnCH7WYfrvFjkC51bM8fz3RsCA =
570- google.golang.org/genproto/googleapis/rpc  v0.0.0-20250707201910-8d1bb00bc6a7   h1:pFyd6EwwL2TqFf8emdthzeX+gZE1ElRq3iM8pui4KBY =
571- google.golang.org/genproto/googleapis/rpc  v0.0.0-20250707201910-8d1bb00bc6a7  /go.mod  h1:qQ0YXyHHx3XkvlzUtpXDkS29lDSafHMZBAZDc03LQ3A =
568+ google.golang.org/genproto/googleapis/api  v0.0.0-20250804133106-a7a43d27e69b   h1:ULiyYQ0FdsJhwwZUwbaXpZF5yUE3h+RA+gxvBu37ucc =
569+ google.golang.org/genproto/googleapis/api  v0.0.0-20250804133106-a7a43d27e69b  /go.mod  h1:oDOGiMSXHL4sDTJvFvIB9nRQCGdLP1o/iVaqQK8zB+M =
570+ google.golang.org/genproto/googleapis/rpc  v0.0.0-20250804133106-a7a43d27e69b   h1:zPKJod4w6F1+nRGDI9ubnXYhU9NSWoFAijkHkUXeTK8 =
571+ google.golang.org/genproto/googleapis/rpc  v0.0.0-20250804133106-a7a43d27e69b  /go.mod  h1:qQ0YXyHHx3XkvlzUtpXDkS29lDSafHMZBAZDc03LQ3A =
572572google.golang.org/grpc  v1.19.0 /go.mod  h1:mqu4LbDTu4XGKhr4mRzUsmM4RtVoemTSY81AxZiDr8c =
573573google.golang.org/grpc  v1.23.0 /go.mod  h1:Y5yQAOtifL1yxbo5wqy6BxZv8vAUGQwXBOALyacEbxg =
574574google.golang.org/grpc  v1.25.1 /go.mod  h1:c3i+UQWmh7LiEpx4sFZnkU36qjEYZ0imhYfXVyQciAY =
575575google.golang.org/grpc  v1.27.0 /go.mod  h1:qbnxyOmOxrQa7FizSgH+ReBfzJrCY1pSN7KXBS8abTk =
576576google.golang.org/grpc  v1.33.2 /go.mod  h1:JMHMWHQWaTccqQQlmk3MJZS+GWXOdAesneDmEnv2fbc =
577- google.golang.org/grpc  v1.75.1   h1:/ODCNEuf9VghjgO3rqLcfg8fiOP0nSluljWFlDxELLI =
578- google.golang.org/grpc  v1.75.1  /go.mod  h1:JtPAzKiq4v1xcAB2hydNlWI2RnF85XXcV0mhKXr2ecQ =
577+ google.golang.org/grpc  v1.76.0   h1:UnVkv1+uMLYXoIz6o7chp59WfQUYA2ex/BXQ9rHZu7A =
578+ google.golang.org/grpc  v1.76.0  /go.mod  h1:Ju12QI8M6iQJtbcsV+awF5a4hfJMLi4X0JLo94ULZ6c =
579579google.golang.org/protobuf  v0.0.0-20200109180630-ec00e32a8dfd /go.mod  h1:DFci5gLYBciE7Vtevhsrf46CRTquxDuWsQurQQe4oz8 =
580580google.golang.org/protobuf  v0.0.0-20200221191635-4d8936d0db64 /go.mod  h1:kwYJMbMJ01Woi6D6+Kah6886xMZcty6N08ah7+eCXa0 =
581581google.golang.org/protobuf  v0.0.0-20200228230310-ab0ca4ff8a60 /go.mod  h1:cfTl7dwQJ+fmap5saPgwCLgHXTUD7jkjRqWcaiX5VyM =
@@ -630,8 +630,8 @@ modernc.org/strutil v1.2.1 h1:UneZBkQA+DX2Rp35KcM69cSsNES9ly8mQWD71HKlOA0=
630630modernc.org/strutil  v1.2.1 /go.mod  h1:EHkiggD70koQxjVdSBM3JKM7k6L0FbGE5eymy9i3B9A =
631631modernc.org/token  v1.1.0  h1:Xl7Ap9dKaEs5kLoOQeQmPWevfnk/DM5qcLcYlA8ys6Y =
632632modernc.org/token  v1.1.0 /go.mod  h1:UGzOrNV1mAFSEB63lOFHIpNRUVMvYTc6yu1SMY/XTDM =
633- osv.dev/bindings/go  v0.0.0-20251003064252-c81c39e62149   h1:0LuEmpVUqDS7tOZmcyZmQny6KvfzwnFEfEGG8MXJXZQ =
634- osv.dev/bindings/go  v0.0.0-20251003064252-c81c39e62149  /go.mod  h1:PCzVrLpwZc69NCvBLJR5ZKv5nrCvwA6HbaamsgmgEZc =
633+ osv.dev/bindings/go  v0.0.0-20251013010847-b847e93bd9b0   h1:Ifkkko1GPrSnkoexWdoJXpQDta+JCq/KLfyHpTHEmcE =
634+ osv.dev/bindings/go  v0.0.0-20251013010847-b847e93bd9b0  /go.mod  h1:rdPwQuPQTR0mCfqasd9g0UYFuHWD/iXmj1E+YXuGYeg =
635635sigs.k8s.io/yaml  v1.4.0 /go.mod  h1:Ejl7/uTz7PSA4eKMyQCUTnhZYNmLIl+5c2lQPGR2BPY =
636636sigs.k8s.io/yaml  v1.5.0  h1:M10b2U7aEUY6hRtU870n2VTPgR5RZiL/I6Lcc2F4NUQ =
637637sigs.k8s.io/yaml  v1.5.0 /go.mod  h1:wZs27Rbxoai4C0f8/9urLZtZtF3avA3gKvGyPdDqTO4 =
0 commit comments