Skip to content

Commit 5ca5eb0

Browse files
authored
fix(deps): update module github.com/sigstore/rekor to v1.2.0 [security] (#622)
Signed-off-by: Renovate Bot <[email protected]>
1 parent 9bfbc91 commit 5ca5eb0

File tree

2 files changed

+110
-105
lines changed

2 files changed

+110
-105
lines changed

go.mod

+32-32
Original file line numberDiff line numberDiff line change
@@ -6,11 +6,11 @@ require (
66
github.com/docker/go v1.5.1-1
77
github.com/go-openapi/runtime v0.26.0
88
github.com/google/go-cmp v0.5.9
9-
github.com/google/trillian v1.5.1 // indirect
10-
github.com/in-toto/in-toto-golang v0.8.0
11-
github.com/secure-systems-lab/go-securesystemslib v0.5.0
12-
github.com/sigstore/rekor v1.1.1
13-
github.com/sigstore/sigstore v1.6.3
9+
github.com/google/trillian v1.5.2 // indirect
10+
github.com/in-toto/in-toto-golang v0.9.0
11+
github.com/secure-systems-lab/go-securesystemslib v0.6.0
12+
github.com/sigstore/rekor v1.2.0
13+
github.com/sigstore/sigstore v1.6.4
1414
)
1515

1616
require (
@@ -22,7 +22,7 @@ require (
2222
github.com/slsa-framework/slsa-github-generator v1.4.0
2323
github.com/spf13/cobra v1.7.0
2424
golang.org/x/mod v0.10.0
25-
sigs.k8s.io/release-utils v0.7.3
25+
sigs.k8s.io/release-utils v0.7.4
2626
)
2727

2828
require (
@@ -32,13 +32,13 @@ require (
3232
github.com/digitorus/pkcs7 v0.0.0-20221212123742-001c36b64ec3 // indirect
3333
github.com/digitorus/timestamp v0.0.0-20221019182153-ef3b63b79b31 // indirect
3434
github.com/emicklei/go-restful/v3 v3.8.0 // indirect
35+
github.com/gabriel-vasile/mimetype v1.4.2 // indirect
3536
github.com/google/gnostic v0.5.7-v3refs // indirect
3637
github.com/google/go-github/v50 v50.2.0 // indirect
3738
github.com/munnerz/goautoneg v0.0.0-20191010083416-a7dc8b61c822 // indirect
3839
github.com/sigstore/timestamp-authority v1.0.0 // indirect
39-
github.com/transparency-dev/merkle v0.0.1 // indirect
40-
go.step.sm/crypto v0.29.3 // indirect
41-
golang.org/x/tools v0.8.0 // indirect
40+
github.com/transparency-dev/merkle v0.0.2 // indirect
41+
go.step.sm/crypto v0.30.0 // indirect
4242
)
4343

4444
require (
@@ -47,8 +47,8 @@ require (
4747
github.com/AliyunContainerService/ack-ram-tool/pkg/credentials/alibabacloudsdkgo/helper v0.2.0 // indirect
4848
github.com/Azure/azure-sdk-for-go v68.0.0+incompatible // indirect
4949
github.com/Azure/go-autorest v14.2.0+incompatible // indirect
50-
github.com/Azure/go-autorest/autorest v0.11.28 // indirect
51-
github.com/Azure/go-autorest/autorest/adal v0.9.21 // indirect
50+
github.com/Azure/go-autorest/autorest v0.11.29 // indirect
51+
github.com/Azure/go-autorest/autorest/adal v0.9.22 // indirect
5252
github.com/Azure/go-autorest/autorest/azure/auth v0.5.12 // indirect
5353
github.com/Azure/go-autorest/autorest/azure/cli v0.4.6 // indirect
5454
github.com/Azure/go-autorest/autorest/date v0.3.0 // indirect
@@ -67,19 +67,19 @@ require (
6767
github.com/alibabacloud-go/tea-xml v1.1.2 // indirect
6868
github.com/aliyun/credentials-go v1.2.3 // indirect
6969
github.com/asaskevich/govalidator v0.0.0-20230301143203-a9d515a09cc2 // indirect
70-
github.com/aws/aws-sdk-go-v2 v1.17.8 // indirect
71-
github.com/aws/aws-sdk-go-v2/config v1.18.21 // indirect
72-
github.com/aws/aws-sdk-go-v2/credentials v1.13.20 // indirect
73-
github.com/aws/aws-sdk-go-v2/feature/ec2/imds v1.13.2 // indirect
74-
github.com/aws/aws-sdk-go-v2/internal/configsources v1.1.32 // indirect
75-
github.com/aws/aws-sdk-go-v2/internal/endpoints/v2 v2.4.26 // indirect
76-
github.com/aws/aws-sdk-go-v2/internal/ini v1.3.33 // indirect
70+
github.com/aws/aws-sdk-go-v2 v1.18.0 // indirect
71+
github.com/aws/aws-sdk-go-v2/config v1.18.23 // indirect
72+
github.com/aws/aws-sdk-go-v2/credentials v1.13.22 // indirect
73+
github.com/aws/aws-sdk-go-v2/feature/ec2/imds v1.13.3 // indirect
74+
github.com/aws/aws-sdk-go-v2/internal/configsources v1.1.33 // indirect
75+
github.com/aws/aws-sdk-go-v2/internal/endpoints/v2 v2.4.27 // indirect
76+
github.com/aws/aws-sdk-go-v2/internal/ini v1.3.34 // indirect
7777
github.com/aws/aws-sdk-go-v2/service/ecr v1.15.0 // indirect
7878
github.com/aws/aws-sdk-go-v2/service/ecrpublic v1.12.0 // indirect
79-
github.com/aws/aws-sdk-go-v2/service/internal/presigned-url v1.9.26 // indirect
80-
github.com/aws/aws-sdk-go-v2/service/sso v1.12.8 // indirect
81-
github.com/aws/aws-sdk-go-v2/service/ssooidc v1.14.8 // indirect
82-
github.com/aws/aws-sdk-go-v2/service/sts v1.18.9 // indirect
79+
github.com/aws/aws-sdk-go-v2/service/internal/presigned-url v1.9.27 // indirect
80+
github.com/aws/aws-sdk-go-v2/service/sso v1.12.10 // indirect
81+
github.com/aws/aws-sdk-go-v2/service/ssooidc v1.14.10 // indirect
82+
github.com/aws/aws-sdk-go-v2/service/sts v1.18.11 // indirect
8383
github.com/aws/smithy-go v1.13.5 // indirect
8484
github.com/awslabs/amazon-ecr-credential-helper/ecr-login v0.0.0-20220228164355-396b2034c795 // indirect
8585
github.com/blang/semver v3.5.1+incompatible // indirect
@@ -110,7 +110,7 @@ require (
110110
github.com/go-openapi/validate v0.22.1 // indirect
111111
github.com/go-playground/locales v0.14.1 // indirect
112112
github.com/go-playground/universal-translator v0.18.1 // indirect
113-
github.com/go-playground/validator/v10 v10.13.0 // indirect
113+
github.com/go-playground/validator/v10 v10.14.0 // indirect
114114
github.com/gogo/protobuf v1.3.2 // indirect
115115
github.com/golang-jwt/jwt/v4 v4.5.0 // indirect
116116
github.com/golang/protobuf v1.5.3 // indirect
@@ -128,7 +128,7 @@ require (
128128
github.com/josharian/intern v1.0.0 // indirect
129129
github.com/json-iterator/go v1.1.12 // indirect
130130
github.com/klauspost/compress v1.16.0 // indirect
131-
github.com/leodido/go-urn v1.2.3 // indirect
131+
github.com/leodido/go-urn v1.2.4 // indirect
132132
github.com/letsencrypt/boulder v0.0.0-20221109233200-85aa52084eaf // indirect
133133
github.com/magiconair/properties v1.8.7 // indirect
134134
github.com/mailru/easyjson v0.7.7 // indirect
@@ -170,18 +170,18 @@ require (
170170
go.uber.org/atomic v1.10.0 // indirect
171171
go.uber.org/multierr v1.9.0 // indirect
172172
go.uber.org/zap v1.24.0 // indirect
173-
golang.org/x/crypto v0.8.0 // indirect
174-
golang.org/x/exp v0.0.0-20230124195608-d38c7dcee874 // indirect
175-
golang.org/x/net v0.9.0 // indirect
173+
golang.org/x/crypto v0.9.0 // indirect
174+
golang.org/x/exp v0.0.0-20230321023759-10a507213a29 // indirect
175+
golang.org/x/net v0.10.0 // indirect
176176
golang.org/x/oauth2 v0.7.0 // indirect
177-
golang.org/x/sync v0.1.0 // indirect
178-
golang.org/x/sys v0.7.0 // indirect
179-
golang.org/x/term v0.7.0 // indirect
177+
golang.org/x/sync v0.2.0 // indirect
178+
golang.org/x/sys v0.8.0 // indirect
179+
golang.org/x/term v0.8.0 // indirect
180180
golang.org/x/text v0.9.0 // indirect
181181
golang.org/x/time v0.3.0 // indirect
182182
google.golang.org/appengine v1.6.7 // indirect
183183
google.golang.org/genproto v0.0.0-20230410155749-daa745c078e1 // indirect
184-
google.golang.org/grpc v1.54.0 // indirect
184+
google.golang.org/grpc v1.55.0 // indirect
185185
google.golang.org/protobuf v1.30.0
186186
gopkg.in/inf.v0 v0.9.1 // indirect
187187
gopkg.in/ini.v1 v1.67.0 // indirect
@@ -191,7 +191,7 @@ require (
191191
k8s.io/api v0.26.1 // indirect
192192
k8s.io/apimachinery v0.26.1 // indirect
193193
k8s.io/client-go v0.25.4 // indirect
194-
k8s.io/klog/v2 v2.90.0 // indirect
194+
k8s.io/klog/v2 v2.100.1 // indirect
195195
k8s.io/kube-openapi v0.0.0-20221012153701-172d655c2280 // indirect
196196
k8s.io/utils v0.0.0-20230115233650-391b47cb4029 // indirect
197197
sigs.k8s.io/json v0.0.0-20221116044647-bc3834ca7abd // indirect

0 commit comments

Comments
 (0)