Skip to content

Commit 5b7cedb

Browse files
🌱 Bump github.com/sigstore/cosign/v2 from 2.4.3 to 2.5.0 (#1537)
1 parent 0869247 commit 5b7cedb

File tree

2 files changed

+188
-192
lines changed

2 files changed

+188
-192
lines changed

go.mod

Lines changed: 52 additions & 54 deletions
Original file line numberDiff line numberDiff line change
@@ -7,18 +7,18 @@ require (
77
github.com/google/go-cmp v0.7.0
88
github.com/google/go-github/v46 v46.0.0
99
github.com/ossf/scorecard/v5 v5.1.1
10-
github.com/sigstore/cosign/v2 v2.4.3
10+
github.com/sigstore/cosign/v2 v2.5.0
1111
github.com/spf13/cobra v1.9.1
1212
golang.org/x/net v0.38.0
1313
)
1414

1515
require (
1616
cel.dev/expr v0.20.0 // indirect
17-
cloud.google.com/go v0.118.2 // indirect
18-
cloud.google.com/go/auth v0.14.1 // indirect
17+
cloud.google.com/go v0.118.3 // indirect
18+
cloud.google.com/go/auth v0.15.0 // indirect
1919
cloud.google.com/go/auth/oauth2adapt v0.2.7 // indirect
2020
cloud.google.com/go/compute/metadata v0.6.0 // indirect
21-
cloud.google.com/go/iam v1.4.0 // indirect
21+
cloud.google.com/go/iam v1.4.1 // indirect
2222
cloud.google.com/go/monitoring v1.24.0 // indirect
2323
cloud.google.com/go/storage v1.50.0 // indirect
2424
dario.cat/mergo v1.0.1 // indirect
@@ -57,27 +57,27 @@ require (
5757
github.com/aliyun/credentials-go v1.3.2 // indirect
5858
github.com/anchore/go-struct-converter v0.0.0-20250211213226-cce56d595160 // indirect
5959
github.com/asaskevich/govalidator v0.0.0-20230301143203-a9d515a09cc2 // indirect
60-
github.com/aws/aws-sdk-go-v2 v1.36.1 // indirect
61-
github.com/aws/aws-sdk-go-v2/config v1.29.6 // indirect
62-
github.com/aws/aws-sdk-go-v2/credentials v1.17.59 // indirect
63-
github.com/aws/aws-sdk-go-v2/feature/ec2/imds v1.16.28 // indirect
64-
github.com/aws/aws-sdk-go-v2/internal/configsources v1.3.32 // indirect
65-
github.com/aws/aws-sdk-go-v2/internal/endpoints/v2 v2.6.32 // indirect
66-
github.com/aws/aws-sdk-go-v2/internal/ini v1.8.2 // indirect
60+
github.com/aws/aws-sdk-go-v2 v1.36.3 // indirect
61+
github.com/aws/aws-sdk-go-v2/config v1.29.10 // indirect
62+
github.com/aws/aws-sdk-go-v2/credentials v1.17.63 // indirect
63+
github.com/aws/aws-sdk-go-v2/feature/ec2/imds v1.16.30 // indirect
64+
github.com/aws/aws-sdk-go-v2/internal/configsources v1.3.34 // indirect
65+
github.com/aws/aws-sdk-go-v2/internal/endpoints/v2 v2.6.34 // indirect
66+
github.com/aws/aws-sdk-go-v2/internal/ini v1.8.3 // indirect
6767
github.com/aws/aws-sdk-go-v2/service/ecr v1.40.3 // indirect
6868
github.com/aws/aws-sdk-go-v2/service/ecrpublic v1.31.2 // indirect
69-
github.com/aws/aws-sdk-go-v2/service/internal/accept-encoding v1.12.2 // indirect
70-
github.com/aws/aws-sdk-go-v2/service/internal/presigned-url v1.12.13 // indirect
71-
github.com/aws/aws-sdk-go-v2/service/sso v1.24.15 // indirect
72-
github.com/aws/aws-sdk-go-v2/service/ssooidc v1.28.14 // indirect
73-
github.com/aws/aws-sdk-go-v2/service/sts v1.33.14 // indirect
69+
github.com/aws/aws-sdk-go-v2/service/internal/accept-encoding v1.12.3 // indirect
70+
github.com/aws/aws-sdk-go-v2/service/internal/presigned-url v1.12.15 // indirect
71+
github.com/aws/aws-sdk-go-v2/service/sso v1.25.1 // indirect
72+
github.com/aws/aws-sdk-go-v2/service/ssooidc v1.29.2 // indirect
73+
github.com/aws/aws-sdk-go-v2/service/sts v1.33.17 // indirect
7474
github.com/aws/smithy-go v1.22.2 // indirect
7575
github.com/awslabs/amazon-ecr-credential-helper/ecr-login v0.9.1 // indirect
7676
github.com/blang/semver v3.5.1+incompatible // indirect
7777
github.com/bmatcuk/doublestar/v4 v4.8.1 // indirect
7878
github.com/bombsimon/logrusr/v2 v2.0.1 // indirect
7979
github.com/bradleyfalzon/ghinstallation/v2 v2.13.0 // indirect
80-
github.com/buildkite/agent/v3 v3.92.1 // indirect
80+
github.com/buildkite/agent/v3 v3.95.1 // indirect
8181
github.com/buildkite/go-pipeline v0.13.3 // indirect
8282
github.com/buildkite/interpolate v0.1.5 // indirect
8383
github.com/buildkite/roko v1.3.1 // indirect
@@ -117,16 +117,17 @@ require (
117117
github.com/go-logr/logr v1.4.2 // indirect
118118
github.com/go-logr/stdr v1.2.2 // indirect
119119
github.com/go-openapi/analysis v0.23.0 // indirect
120-
github.com/go-openapi/errors v0.22.0 // indirect
120+
github.com/go-openapi/errors v0.22.1 // indirect
121121
github.com/go-openapi/jsonpointer v0.21.0 // indirect
122122
github.com/go-openapi/jsonreference v0.21.0 // indirect
123123
github.com/go-openapi/loads v0.22.0 // indirect
124124
github.com/go-openapi/runtime v0.28.0 // indirect
125125
github.com/go-openapi/spec v0.21.0 // indirect
126126
github.com/go-openapi/strfmt v0.23.0 // indirect
127-
github.com/go-openapi/swag v0.23.0 // indirect
127+
github.com/go-openapi/swag v0.23.1 // indirect
128128
github.com/go-openapi/validate v0.24.0 // indirect
129129
github.com/go-piv/piv-go/v2 v2.3.0 // indirect
130+
github.com/go-viper/mapstructure/v2 v2.2.1 // indirect
130131
github.com/gogo/protobuf v1.3.2 // indirect
131132
github.com/golang-jwt/jwt/v4 v4.5.2 // indirect
132133
github.com/golang/groupcache v0.0.0-20241129210726-2c02b8208cf8 // indirect
@@ -144,15 +145,14 @@ require (
144145
github.com/google/s2a-go v0.1.9 // indirect
145146
github.com/google/uuid v1.6.0 // indirect
146147
github.com/google/wire v0.6.0 // indirect
147-
github.com/googleapis/enterprise-certificate-proxy v0.3.4 // indirect
148+
github.com/googleapis/enterprise-certificate-proxy v0.3.6 // indirect
148149
github.com/googleapis/gax-go/v2 v2.14.1 // indirect
149150
github.com/h2non/filetype v1.1.3 // indirect
150151
github.com/hashicorp/go-cleanhttp v0.5.2 // indirect
151152
github.com/hashicorp/go-retryablehttp v0.7.7 // indirect
152-
github.com/hashicorp/hcl v1.0.1-vault-5 // indirect
153153
github.com/ianlancetaylor/demangle v0.0.0-20240912202439-0a2b6291aafd // indirect
154154
github.com/imdario/mergo v0.3.16 // indirect
155-
github.com/in-toto/attestation v1.1.0 // indirect
155+
github.com/in-toto/attestation v1.1.1 // indirect
156156
github.com/in-toto/in-toto-golang v0.9.0 // indirect
157157
github.com/inconshreveable/mousetrap v1.1.0 // indirect
158158
github.com/jbenet/go-context v0.0.0-20150711004518-d14ea06fba99 // indirect
@@ -163,8 +163,7 @@ require (
163163
github.com/kevinburke/ssh_config v1.2.0 // indirect
164164
github.com/klauspost/compress v1.17.11 // indirect
165165
github.com/letsencrypt/boulder v0.0.0-20240620165639-de9c06129bec // indirect
166-
github.com/magiconair/properties v1.8.9 // indirect
167-
github.com/mailru/easyjson v0.7.7 // indirect
166+
github.com/mailru/easyjson v0.9.0 // indirect
168167
github.com/mattn/go-colorable v0.1.14 // indirect
169168
github.com/mattn/go-isatty v0.0.20 // indirect
170169
github.com/mattn/go-runewidth v0.0.16 // indirect
@@ -196,8 +195,7 @@ require (
196195
github.com/rhysd/actionlint v1.7.7 // indirect
197196
github.com/rivo/uniseg v0.4.7 // indirect
198197
github.com/robfig/cron/v3 v3.0.1 // indirect
199-
github.com/sagikazarmark/locafero v0.4.0 // indirect
200-
github.com/sagikazarmark/slog-shim v0.1.0 // indirect
198+
github.com/sagikazarmark/locafero v0.7.0 // indirect
201199
github.com/sassoftware/relic v7.2.1+incompatible // indirect
202200
github.com/secure-systems-lab/go-securesystemslib v0.9.0 // indirect
203201
github.com/segmentio/ksuid v1.0.4 // indirect
@@ -206,21 +204,21 @@ require (
206204
github.com/shurcooL/githubv4 v0.0.0-20240727222349-48295856cce7 // indirect
207205
github.com/shurcooL/graphql v0.0.0-20230722043721-ed46e5a46466 // indirect
208206
github.com/sigstore/fulcio v1.6.6 // indirect
209-
github.com/sigstore/protobuf-specs v0.4.0 // indirect
207+
github.com/sigstore/protobuf-specs v0.4.1 // indirect
210208
github.com/sigstore/rekor v1.3.9 // indirect
211-
github.com/sigstore/sigstore v1.8.15 // indirect
212-
github.com/sigstore/sigstore-go v0.7.0 // indirect
213-
github.com/sigstore/timestamp-authority v1.2.4 // indirect
209+
github.com/sigstore/sigstore v1.9.1 // indirect
210+
github.com/sigstore/sigstore-go v0.7.1 // indirect
211+
github.com/sigstore/timestamp-authority v1.2.5 // indirect
214212
github.com/sirupsen/logrus v1.9.3 // indirect
215213
github.com/skeema/knownhosts v1.3.1 // indirect
216214
github.com/skratchdot/open-golang v0.0.0-20200116055534-eef842397966 // indirect
217215
github.com/sourcegraph/conc v0.3.0 // indirect
218216
github.com/spdx/gordf v0.0.0-20250128162952-000978ccd6fb // indirect
219217
github.com/spdx/tools-golang v0.5.5 // indirect
220-
github.com/spf13/afero v1.11.0 // indirect
221-
github.com/spf13/cast v1.7.0 // indirect
218+
github.com/spf13/afero v1.12.0 // indirect
219+
github.com/spf13/cast v1.7.1 // indirect
222220
github.com/spf13/pflag v1.0.6 // indirect
223-
github.com/spf13/viper v1.19.0 // indirect
221+
github.com/spf13/viper v1.20.1 // indirect
224222
github.com/spiffe/go-spiffe/v2 v2.5.0 // indirect
225223
github.com/subosito/gotenv v1.6.0 // indirect
226224
github.com/syndtr/goleveldb v1.0.1-0.20220721030215-126854af5e6d // indirect
@@ -236,40 +234,40 @@ require (
236234
github.com/vbatts/tar-split v0.12.1 // indirect
237235
github.com/xanzy/ssh-agent v0.3.3 // indirect
238236
github.com/zeebo/errs v1.4.0 // indirect
239-
gitlab.com/gitlab-org/api/client-go v0.123.0 // indirect
237+
gitlab.com/gitlab-org/api/client-go v0.127.0 // indirect
240238
go.mongodb.org/mongo-driver v1.14.0 // indirect
241239
go.opencensus.io v0.24.0 // indirect
242240
go.opentelemetry.io/auto/sdk v1.1.0 // indirect
243241
go.opentelemetry.io/contrib/detectors/gcp v1.34.0 // indirect
244242
go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc v0.59.0 // indirect
245243
go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.59.0 // indirect
246-
go.opentelemetry.io/otel v1.34.0 // indirect
247-
go.opentelemetry.io/otel/metric v1.34.0 // indirect
248-
go.opentelemetry.io/otel/sdk v1.34.0 // indirect
244+
go.opentelemetry.io/otel v1.35.0 // indirect
245+
go.opentelemetry.io/otel/metric v1.35.0 // indirect
246+
go.opentelemetry.io/otel/sdk v1.35.0 // indirect
249247
go.opentelemetry.io/otel/sdk/metric v1.34.0 // indirect
250-
go.opentelemetry.io/otel/trace v1.34.0 // indirect
248+
go.opentelemetry.io/otel/trace v1.35.0 // indirect
251249
go.uber.org/multierr v1.11.0 // indirect
252250
go.uber.org/zap v1.27.0 // indirect
253251
gocloud.dev v0.40.0 // indirect
254-
golang.org/x/crypto v0.36.0 // indirect
252+
golang.org/x/crypto v0.37.0 // indirect
255253
golang.org/x/exp v0.0.0-20250210185358-939b2ce775ac // indirect
256-
golang.org/x/mod v0.23.0 // indirect
257-
golang.org/x/oauth2 v0.26.0 // indirect
258-
golang.org/x/sync v0.12.0 // indirect
259-
golang.org/x/sys v0.31.0 // indirect
254+
golang.org/x/mod v0.24.0 // indirect
255+
golang.org/x/oauth2 v0.29.0 // indirect
256+
golang.org/x/sync v0.13.0 // indirect
257+
golang.org/x/sys v0.32.0 // indirect
260258
golang.org/x/telemetry v0.0.0-20250212145848-75305293b65a // indirect
261-
golang.org/x/term v0.30.0 // indirect
262-
golang.org/x/text v0.23.0 // indirect
263-
golang.org/x/time v0.10.0 // indirect
259+
golang.org/x/term v0.31.0 // indirect
260+
golang.org/x/text v0.24.0 // indirect
261+
golang.org/x/time v0.11.0 // indirect
264262
golang.org/x/tools v0.30.0 // indirect
265263
golang.org/x/vuln v1.1.4 // indirect
266264
golang.org/x/xerrors v0.0.0-20240903120638-7835f813f4da // indirect
267-
google.golang.org/api v0.221.0 // indirect
268-
google.golang.org/genproto v0.0.0-20250212204824-5a70512c5d8b // indirect
269-
google.golang.org/genproto/googleapis/api v0.0.0-20250212204824-5a70512c5d8b // indirect
270-
google.golang.org/genproto/googleapis/rpc v0.0.0-20250212204824-5a70512c5d8b // indirect
271-
google.golang.org/grpc v1.70.0 // indirect
272-
google.golang.org/protobuf v1.36.5 // indirect
265+
google.golang.org/api v0.227.0 // indirect
266+
google.golang.org/genproto v0.0.0-20250303144028-a0af3efb3deb // indirect
267+
google.golang.org/genproto/googleapis/api v0.0.0-20250303144028-a0af3efb3deb // indirect
268+
google.golang.org/genproto/googleapis/rpc v0.0.0-20250313205543-e70fdf4c4cb4 // indirect
269+
google.golang.org/grpc v1.71.0 // indirect
270+
google.golang.org/protobuf v1.36.6 // indirect
273271
gopkg.in/inf.v0 v0.9.1 // indirect
274272
gopkg.in/ini.v1 v1.67.0 // indirect
275273
gopkg.in/warnings.v0 v0.1.2 // indirect
@@ -280,10 +278,10 @@ require (
280278
k8s.io/client-go v0.29.3 // indirect
281279
k8s.io/klog/v2 v2.130.1 // indirect
282280
k8s.io/kube-openapi v0.0.0-20240228011516-70dd3763d340 // indirect
283-
k8s.io/utils v0.0.0-20240502163921-fe8a2dddb1d0 // indirect
281+
k8s.io/utils v0.0.0-20241210054802-24370beab758 // indirect
284282
mvdan.cc/sh/v3 v3.10.0 // indirect
285283
sigs.k8s.io/json v0.0.0-20221116044647-bc3834ca7abd // indirect
286-
sigs.k8s.io/release-utils v0.11.0 // indirect
284+
sigs.k8s.io/release-utils v0.11.1 // indirect
287285
sigs.k8s.io/structured-merge-diff/v4 v4.4.1 // indirect
288286
sigs.k8s.io/yaml v1.4.0 // indirect
289287
)

0 commit comments

Comments
 (0)