@@ -11,15 +11,15 @@ replace github.com/mholt/archiver/v3 => github.com/anchore/archiver/v3 v3.5.2
1111replace modernc.org/sqlite v1.33.0 => modernc.org/sqlite v1.32.0
1212
1313require (
14- chainguard.dev/apko v0.30.26
15- chainguard.dev/melange v0.34 .0
14+ chainguard.dev/apko v0.30.29
15+ chainguard.dev/melange v0.36 .0
1616 cloud.google.com/go/storage v1.56.1
1717 github.com/adrg/xdg v0.5.3
1818 github.com/anchore/grype v0.104.1
1919 github.com/anchore/stereoscope v0.1.13
2020 github.com/anchore/syft v1.38.0
21- github.com/chainguard-dev/clog v1.7 .0
22- github.com/chainguard-dev/yam v0.2.40
21+ github.com/chainguard-dev/clog v1.8 .0
22+ github.com/chainguard-dev/yam v0.2.43
2323 github.com/charmbracelet/bubbles v0.21.0
2424 github.com/charmbracelet/bubbletea v1.3.10
2525 github.com/charmbracelet/lipgloss v1.1.1-0.20250319133953-166f707985bc
@@ -31,15 +31,15 @@ require (
3131 github.com/dprotaso/go-yit v0.0.0-20250513224043-18a80f8f6df4
3232 github.com/dustin/go-humanize v1.0.1
3333 github.com/facebookincubator/nvdtools v0.1.5
34- github.com/github/go-spdx/v2 v2.3.4
34+ github.com/github/go-spdx/v2 v2.3.5
3535 github.com/go-git/go-billy/v5 v5.6.2
36- github.com/go-git/go-git/v5 v5.16.3
36+ github.com/go-git/go-git/v5 v5.16.4
3737 github.com/google/go-cmp v0.7.0
3838 github.com/google/go-github/v58 v58.0.0
3939 github.com/google/osv-scanner v1.9.2
4040 github.com/google/uuid v1.6.0
4141 github.com/hashicorp/go-retryablehttp v0.7.8
42- github.com/hashicorp/go-version v1.7 .0
42+ github.com/hashicorp/go-version v1.8 .0
4343 github.com/knqyf263/go-apk-version v0.0.0-20200609155635-041fdbb8563f
4444 github.com/lucasb-eyer/go-colorful v1.3.0
4545 github.com/muesli/reflow v0.3.0
@@ -49,15 +49,15 @@ require (
4949 github.com/santhosh-tekuri/jsonschema/v5 v5.3.1
5050 github.com/savioxavier/termlink v1.4.3
5151 github.com/skratchdot/open-golang v0.0.0-20200116055534-eef842397966
52- github.com/spf13/cobra v1.10.1
52+ github.com/spf13/cobra v1.10.2
5353 github.com/spf13/pflag v1.0.10
5454 github.com/stretchr/testify v1.11.1
5555 github.com/texttheater/golang-levenshtein/levenshtein v0.0.0-20200805054039-cae8b0eaed6c
5656 github.com/tmc/dot v0.2.0
5757 go.lsp.dev/uri v0.3.0
5858 golang.org/x/exp v0.0.0-20250819193227-8b4c13bb791b
5959 golang.org/x/oauth2 v0.33.0
60- golang.org/x/sync v0.18 .0
60+ golang.org/x/sync v0.19 .0
6161 golang.org/x/term v0.37.0
6262 golang.org/x/text v0.31.0
6363 golang.org/x/time v0.14.0
@@ -67,15 +67,15 @@ require (
6767
6868require (
6969 github.com/anchore/go-logger v0.0.0-20250318195838-07ae343dd722
70- github.com/chainguard-dev/advisory-schema v0.37.28
70+ github.com/chainguard-dev/advisory-schema v0.37.30
7171 github.com/hako/durafmt v0.0.0-20210608085754-5c1018a4e16b
7272 github.com/spf13/afero v1.15.0
7373)
7474
7575require (
7676 cel.dev/expr v0.24.0 // indirect
7777 chainguard.dev/go-grpc-kit v0.17.15 // indirect
78- chainguard.dev/sdk v0.1.43 // indirect
78+ chainguard.dev/sdk v0.1.44 // indirect
7979 cloud.google.com/go v0.121.6 // indirect
8080 cloud.google.com/go/auth v0.17.0 // indirect
8181 cloud.google.com/go/auth/oauth2adapt v0.2.8 // indirect
@@ -91,7 +91,7 @@ require (
9191 github.com/BurntSushi/toml v1.5.0 // indirect
9292 github.com/CycloneDX/cyclonedx-go v0.9.3 // indirect
9393 github.com/DataDog/zstd v1.5.7 // indirect
94- github.com/GoogleCloudPlatform/opentelemetry-operations-go/detectors/gcp v1.29 .0 // indirect
94+ github.com/GoogleCloudPlatform/opentelemetry-operations-go/detectors/gcp v1.30 .0 // indirect
9595 github.com/GoogleCloudPlatform/opentelemetry-operations-go/exporter/metric v0.53.0 // indirect
9696 github.com/GoogleCloudPlatform/opentelemetry-operations-go/internal/resourcemapping v0.53.0 // indirect
9797 github.com/Intevation/gval v1.3.0 // indirect
@@ -122,23 +122,24 @@ require (
122122 github.com/aquasecurity/go-pep440-version v0.0.1 // indirect
123123 github.com/aquasecurity/go-version v0.0.1 // indirect
124124 github.com/atotto/clipboard v0.1.4 // indirect
125- github.com/aws/aws-sdk-go-v2 v1.39.6 // indirect
125+ github.com/aws/aws-sdk-go-v2 v1.40.0 // indirect
126126 github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream v1.6.10 // indirect
127- github.com/aws/aws-sdk-go-v2/config v1.31.17 // indirect
128- github.com/aws/aws-sdk-go-v2/credentials v1.18.21 // indirect
129- github.com/aws/aws-sdk-go-v2/feature/ec2/imds v1.18.13 // indirect
130- github.com/aws/aws-sdk-go-v2/internal/configsources v1.4.13 // indirect
131- github.com/aws/aws-sdk-go-v2/internal/endpoints/v2 v2.7.13 // indirect
127+ github.com/aws/aws-sdk-go-v2/config v1.32.1 // indirect
128+ github.com/aws/aws-sdk-go-v2/credentials v1.19.1 // indirect
129+ github.com/aws/aws-sdk-go-v2/feature/ec2/imds v1.18.14 // indirect
130+ github.com/aws/aws-sdk-go-v2/internal/configsources v1.4.14 // indirect
131+ github.com/aws/aws-sdk-go-v2/internal/endpoints/v2 v2.7.14 // indirect
132132 github.com/aws/aws-sdk-go-v2/internal/ini v1.8.4 // indirect
133133 github.com/aws/aws-sdk-go-v2/internal/v4a v1.3.34 // indirect
134134 github.com/aws/aws-sdk-go-v2/service/internal/accept-encoding v1.13.3 // indirect
135135 github.com/aws/aws-sdk-go-v2/service/internal/checksum v1.7.2 // indirect
136- github.com/aws/aws-sdk-go-v2/service/internal/presigned-url v1.13.13 // indirect
136+ github.com/aws/aws-sdk-go-v2/service/internal/presigned-url v1.13.14 // indirect
137137 github.com/aws/aws-sdk-go-v2/service/internal/s3shared v1.18.15 // indirect
138138 github.com/aws/aws-sdk-go-v2/service/s3 v1.80.1 // indirect
139- github.com/aws/aws-sdk-go-v2/service/sso v1.30.1 // indirect
140- github.com/aws/aws-sdk-go-v2/service/ssooidc v1.35.5 // indirect
141- github.com/aws/aws-sdk-go-v2/service/sts v1.39.1 // indirect
139+ github.com/aws/aws-sdk-go-v2/service/signin v1.0.1 // indirect
140+ github.com/aws/aws-sdk-go-v2/service/sso v1.30.4 // indirect
141+ github.com/aws/aws-sdk-go-v2/service/ssooidc v1.35.9 // indirect
142+ github.com/aws/aws-sdk-go-v2/service/sts v1.41.1 // indirect
142143 github.com/aws/smithy-go v1.23.2 // indirect
143144 github.com/aymanbagabas/go-osc52/v2 v2.0.1 // indirect
144145 github.com/becheran/wildmatch-go v1.0.0 // indirect
@@ -162,7 +163,7 @@ require (
162163 github.com/clipperhouse/stringish v0.1.1 // indirect
163164 github.com/clipperhouse/uax29/v2 v2.2.0 // indirect
164165 github.com/cloudflare/circl v1.6.1 // indirect
165- github.com/cncf/xds/go v0.0.0-20250501225837-2ac532fd4443 // indirect
166+ github.com/cncf/xds/go v0.0.0-20251022180443-0feb69152e9f // indirect
166167 github.com/common-nighthawk/go-figure v0.0.0-20210622060536-734e95fb86be // indirect
167168 github.com/containerd/cgroups/v3 v3.0.5 // indirect
168169 github.com/containerd/containerd v1.7.29 // indirect
@@ -174,15 +175,15 @@ require (
174175 github.com/containerd/fifo v1.1.0 // indirect
175176 github.com/containerd/log v0.1.0 // indirect
176177 github.com/containerd/platforms v1.0.0-rc.1 // indirect
177- github.com/containerd/stargz-snapshotter/estargz v0.17.0 // indirect
178+ github.com/containerd/stargz-snapshotter/estargz v0.18.1 // indirect
178179 github.com/containerd/ttrpc v1.2.7 // indirect
179180 github.com/containerd/typeurl/v2 v2.2.3 // indirect
180181 github.com/cyphar/filepath-securejoin v0.6.0 // indirect
181182 github.com/davecgh/go-spew v1.1.2-0.20180830191138-d8f796af33cc // indirect
182183 github.com/deitch/magic v0.0.0-20240306090643-c67ab88f10cb // indirect
183184 github.com/diskfs/go-diskfs v1.7.0 // indirect
184185 github.com/distribution/reference v0.6.0 // indirect
185- github.com/docker/cli v29.0.1 +incompatible // indirect
186+ github.com/docker/cli v29.1.2 +incompatible // indirect
186187 github.com/docker/distribution v2.8.3+incompatible // indirect
187188 github.com/docker/docker v28.5.2+incompatible // indirect
188189 github.com/docker/docker-credential-helpers v0.9.4 // indirect
@@ -192,7 +193,7 @@ require (
192193 github.com/dsnet/compress v0.0.2-0.20230904184137-39efe44ab707 // indirect
193194 github.com/elliotchance/phpserialize v1.4.0 // indirect
194195 github.com/emirpasic/gods v1.18.1 // indirect
195- github.com/envoyproxy/go-control-plane/envoy v1.32.4 // indirect
196+ github.com/envoyproxy/go-control-plane/envoy v1.35.0 // indirect
196197 github.com/envoyproxy/protoc-gen-validate v1.2.1 // indirect
197198 github.com/erikgeiser/coninput v0.0.0-20211004153227-1c3628e74d0f // indirect
198199 github.com/fatih/color v1.18.0 // indirect
@@ -204,7 +205,7 @@ require (
204205 github.com/glebarez/sqlite v1.11.0 // indirect
205206 github.com/go-git/gcfg v1.5.1-0.20230307220236-3a3c6141e376 // indirect
206207 github.com/go-jose/go-jose/v3 v3.0.4 // indirect
207- github.com/go-jose/go-jose/v4 v4.1.2 // indirect
208+ github.com/go-jose/go-jose/v4 v4.1.3 // indirect
208209 github.com/go-logfmt/logfmt v0.6.0 // indirect
209210 github.com/go-logr/logr v1.4.3 // indirect
210211 github.com/go-logr/stdr v1.2.2 // indirect
@@ -215,7 +216,7 @@ require (
215216 github.com/gogo/protobuf v1.3.2 // indirect
216217 github.com/gohugoio/hashstructure v0.6.0 // indirect
217218 github.com/golang/groupcache v0.0.0-20241129210726-2c02b8208cf8 // indirect
218- github.com/google/go-containerregistry v0.20.6 // indirect
219+ github.com/google/go-containerregistry v0.20.7 // indirect
219220 github.com/google/go-licenses/v2 v2.0.1 // indirect
220221 github.com/google/go-querystring v1.1.0 // indirect
221222 github.com/google/licensecheck v0.3.1 // indirect
@@ -228,8 +229,8 @@ require (
228229 github.com/gookit/color v1.6.0 // indirect
229230 github.com/gpustack/gguf-parser-go v0.22.1 // indirect
230231 github.com/grpc-ecosystem/go-grpc-middleware/providers/prometheus v1.1.0 // indirect
231- github.com/grpc-ecosystem/go-grpc-middleware/v2 v2.3.2 // indirect
232- github.com/grpc-ecosystem/grpc-gateway/v2 v2.27.2 // indirect
232+ github.com/grpc-ecosystem/go-grpc-middleware/v2 v2.3.3 // indirect
233+ github.com/grpc-ecosystem/grpc-gateway/v2 v2.27.3 // indirect
233234 github.com/hashicorp/aws-sdk-go-base/v2 v2.0.0-beta.65 // indirect
234235 github.com/hashicorp/errwrap v1.1.0 // indirect
235236 github.com/hashicorp/go-cleanhttp v0.5.2 // indirect
@@ -253,7 +254,7 @@ require (
253254 github.com/kballard/go-shellquote v0.0.0-20180428030007-95032a82bc51 // indirect
254255 github.com/kelseyhightower/envconfig v1.4.0 // indirect
255256 github.com/kevinburke/ssh_config v1.4.0 // indirect
256- github.com/klauspost/compress v1.18.1 // indirect
257+ github.com/klauspost/compress v1.18.2 // indirect
257258 github.com/klauspost/pgzip v1.2.6 // indirect
258259 github.com/knqyf263/go-deb-version v0.0.0-20241115132648-6f4aee6ccd23 // indirect
259260 github.com/masahiro331/go-mvn-version v0.0.0-20250131095131-f4974fa13b8a // indirect
@@ -331,7 +332,7 @@ require (
331332 github.com/spdx/tools-golang v0.5.5 // indirect
332333 github.com/spf13/cast v1.9.2 // indirect
333334 github.com/spf13/viper v1.20.1 // indirect
334- github.com/spiffe/go-spiffe/v2 v2.5 .0 // indirect
335+ github.com/spiffe/go-spiffe/v2 v2.6 .0 // indirect
335336 github.com/subosito/gotenv v1.6.0 // indirect
336337 github.com/sylabs/sif/v2 v2.22.0 // indirect
337338 github.com/sylabs/squashfs v1.0.6 // indirect
@@ -340,7 +341,7 @@ require (
340341 github.com/u-root/uio v0.0.0-20240224005618-d2acac8f3701 // indirect
341342 github.com/ulikunitz/xz v0.5.15 // indirect
342343 github.com/vbatts/go-mtree v0.6.0 // indirect
343- github.com/vbatts/tar-split v0.12.1 // indirect
344+ github.com/vbatts/tar-split v0.12.2 // indirect
344345 github.com/vifraa/gopom v1.0.0 // indirect
345346 github.com/wagoodman/go-partybus v0.0.0-20230516145632-8ccac152c651 // indirect
346347 github.com/wagoodman/go-progress v0.0.0-20230925121702-07e42b3cdba0 // indirect
@@ -350,11 +351,10 @@ require (
350351 github.com/yookoala/realpath v1.0.0 // indirect
351352 github.com/zclconf/go-cty v1.16.3 // indirect
352353 github.com/zealic/xignore v0.3.3 // indirect
353- github.com/zeebo/errs v1.4.0 // indirect
354354 go.etcd.io/bbolt v1.4.2 // indirect
355355 go.opencensus.io v0.24.0 // indirect
356- go.opentelemetry.io/auto/sdk v1.1.0 // indirect
357- go.opentelemetry.io/contrib/detectors/gcp v1.37 .0 // indirect
356+ go.opentelemetry.io/auto/sdk v1.2.1 // indirect
357+ go.opentelemetry.io/contrib/detectors/gcp v1.38 .0 // indirect
358358 go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc v0.63.0 // indirect
359359 go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.63.0 // indirect
360360 go.opentelemetry.io/otel v1.38.0 // indirect
@@ -363,23 +363,23 @@ require (
363363 go.opentelemetry.io/otel/sdk v1.38.0 // indirect
364364 go.opentelemetry.io/otel/sdk/metric v1.38.0 // indirect
365365 go.opentelemetry.io/otel/trace v1.38.0 // indirect
366- go.step.sm/crypto v0.74 .0 // indirect
366+ go.step.sm/crypto v0.75 .0 // indirect
367367 go.uber.org/multierr v1.11.0 // indirect
368368 go.yaml.in/yaml/v2 v2.4.3 // indirect
369369 go.yaml.in/yaml/v3 v3.0.4 // indirect
370370 go4.org v0.0.0-20230225012048-214862532bf5 // indirect
371371 golang.org/x/crypto v0.45.0 // indirect
372372 golang.org/x/mod v0.30.0 // indirect
373373 golang.org/x/net v0.47.0 // indirect
374- golang.org/x/sys v0.38 .0 // indirect
374+ golang.org/x/sys v0.39 .0 // indirect
375375 golang.org/x/tools v0.39.0 // indirect
376376 golang.org/x/xerrors v0.0.0-20240903120638-7835f813f4da // indirect
377377 gonum.org/v1/gonum v0.16.0 // indirect
378- google.golang.org/api v0.256 .0 // indirect
378+ google.golang.org/api v0.257 .0 // indirect
379379 google.golang.org/genproto v0.0.0-20250715232539-7130f93afb79 // indirect
380- google.golang.org/genproto/googleapis/api v0.0.0-20250826171959-ef028d996bc1 // indirect
381- google.golang.org/genproto/googleapis/rpc v0.0.0-20251103181224-f26f9409b101 // indirect
382- google.golang.org/grpc v1.76 .0 // indirect
380+ google.golang.org/genproto/googleapis/api v0.0.0-20251022142026-3a174f9686a8 // indirect
381+ google.golang.org/genproto/googleapis/rpc v0.0.0-20251124214823-79d6a2a48846 // indirect
382+ google.golang.org/grpc v1.77 .0 // indirect
383383 google.golang.org/protobuf v1.36.10 // indirect
384384 gopkg.in/ini.v1 v1.67.0 // indirect
385385 gopkg.in/warnings.v0 v0.1.2 // indirect
@@ -389,6 +389,6 @@ require (
389389 modernc.org/libc v1.66.10 // indirect
390390 modernc.org/mathutil v1.7.1 // indirect
391391 modernc.org/memory v1.11.0 // indirect
392- modernc.org/sqlite v1.40.0 // indirect
392+ modernc.org/sqlite v1.40.1 // indirect
393393 mvdan.cc/sh/v3 v3.12.0 // indirect
394394)
0 commit comments