1
1
module github.com/slsa-framework/slsa-verifier/v2
2
2
3
- go 1.23.1
3
+ go 1.23.2
4
+
5
+ toolchain go1.23.4
4
6
5
7
require (
6
8
github.com/docker/go v1.5.1-1
7
9
github.com/go-openapi/runtime v0.28.0
8
10
github.com/google/go-cmp v0.6.0
9
- github.com/google/trillian v1.6.0 // indirect
11
+ github.com/google/trillian v1.6.1 // indirect
10
12
github.com/in-toto/in-toto-golang v0.9.0
11
- github.com/secure-systems-lab/go-securesystemslib v0.8 .0
12
- github.com/sigstore/rekor v1.3.6
13
- github.com/sigstore/sigstore v1.8.9
13
+ github.com/secure-systems-lab/go-securesystemslib v0.9 .0
14
+ github.com/sigstore/rekor v1.3.7
15
+ github.com/sigstore/sigstore v1.8.12
14
16
)
15
17
16
18
require (
17
- github.com/google/go-containerregistry v0.20.2
19
+ github.com/google/go-containerregistry v0.20.3
18
20
github.com/gorilla/mux v1.8.1
19
21
github.com/in-toto/attestation v1.1.0
20
- github.com/sigstore/cosign/v2 v2.2.4
22
+ github.com/sigstore/cosign/v2 v2.4.1
21
23
github.com/sigstore/sigstore-go v0.6.2
22
- github.com/slsa-framework/slsa-github-generator v1.9 .0
24
+ github.com/slsa-framework/slsa-github-generator v1.10 .0
23
25
github.com/spf13/cobra v1.8.1
24
- golang.org/x/mod v0.21 .0
25
- sigs.k8s.io/release-utils v0.8.4
26
+ golang.org/x/mod v0.22 .0
27
+ sigs.k8s.io/release-utils v0.9.0
26
28
)
27
29
28
30
require (
29
31
github.com/digitorus/pkcs7 v0.0.0-20230818184609-3a137a874352 // indirect
30
32
github.com/digitorus/timestamp v0.0.0-20231217203849-220c5c2851b7 // indirect
31
33
github.com/dustin/go-humanize v1.0.1 // indirect
32
- github.com/go-jose/go-jose/v4 v4.0.2 // indirect
34
+ github.com/go-jose/go-jose/v4 v4.0.4 // indirect
33
35
github.com/go-openapi/strfmt v0.23.0 // indirect
34
36
github.com/go-openapi/swag v0.23.0 // indirect
35
37
github.com/google/uuid v1.6.0 // indirect
@@ -40,23 +42,24 @@ require (
40
42
github.com/sourcegraph/conc v0.3.0 // indirect
41
43
github.com/theupdateframework/go-tuf/v2 v2.0.1 // indirect
42
44
github.com/transparency-dev/merkle v0.0.2 // indirect
43
- go.opentelemetry.io/otel/metric v1.27.0 // indirect
44
- google.golang.org/genproto/googleapis/api v0.0.0-20240520151616-dc85e6b867a5 // indirect
45
- google.golang.org/genproto/googleapis/rpc v0.0.0-20240520151616-dc85e6b867a5 // indirect
45
+ go.opentelemetry.io/auto/sdk v1.1.0 // indirect
46
+ go.opentelemetry.io/otel/metric v1.33.0 // indirect
47
+ google.golang.org/genproto/googleapis/api v0.0.0-20241104194629-dd2ea8efbc28 // indirect
48
+ google.golang.org/genproto/googleapis/rpc v0.0.0-20241104194629-dd2ea8efbc28 // indirect
46
49
)
47
50
48
51
require (
49
52
github.com/asaskevich/govalidator v0.0.0-20230301143203-a9d515a09cc2 // indirect
50
53
github.com/blang/semver v3.5.1+incompatible // indirect
51
54
github.com/common-nighthawk/go-figure v0.0.0-20210622060536-734e95fb86be // indirect
52
- github.com/containerd/stargz-snapshotter/estargz v0.14 .3 // indirect
55
+ github.com/containerd/stargz-snapshotter/estargz v0.16 .3 // indirect
53
56
github.com/cyberphone/json-canonicalization v0.0.0-20231011164504-785e29786b46 // indirect
54
- github.com/docker/cli v27.1.1 +incompatible // indirect
57
+ github.com/docker/cli v27.5.0 +incompatible // indirect
55
58
github.com/docker/distribution v2.8.3+incompatible // indirect
56
- github.com/docker/docker-credential-helpers v0.8.0 // indirect
59
+ github.com/docker/docker-credential-helpers v0.8.2 // indirect
57
60
github.com/fsnotify/fsnotify v1.7.0 // indirect
58
61
github.com/go-chi/chi v4.1.2+incompatible // indirect
59
- github.com/go-logr/logr v1.4.1 // indirect
62
+ github.com/go-logr/logr v1.4.2 // indirect
60
63
github.com/go-logr/stdr v1.2.2 // indirect
61
64
github.com/go-openapi/analysis v0.23.0 // indirect
62
65
github.com/go-openapi/errors v0.22.0 // indirect
@@ -73,7 +76,7 @@ require (
73
76
github.com/inconshreveable/mousetrap v1.1.0 // indirect
74
77
github.com/jedisct1/go-minisign v0.0.0-20230811132847-661be99b8267 // indirect
75
78
github.com/josharian/intern v1.0.0 // indirect
76
- github.com/klauspost/compress v1.17.8 // indirect
79
+ github.com/klauspost/compress v1.17.11 // indirect
77
80
github.com/letsencrypt/boulder v0.0.0-20240620165639-de9c06129bec // indirect
78
81
github.com/magiconair/properties v1.8.7 // indirect
79
82
github.com/mailru/easyjson v0.7.7 // indirect
@@ -83,38 +86,38 @@ require (
83
86
github.com/opencontainers/go-digest v1.0.0 // indirect
84
87
github.com/opencontainers/image-spec v1.1.0 // indirect
85
88
github.com/opentracing/opentracing-go v1.2.0 // indirect
86
- github.com/pelletier/go-toml/v2 v2.1.0 // indirect
89
+ github.com/pelletier/go-toml/v2 v2.2.2 // indirect
87
90
github.com/pkg/errors v0.9.1 // indirect
88
91
github.com/sassoftware/relic v7.2.1+incompatible // indirect
89
92
github.com/shibumi/go-pathspec v1.3.0 // indirect
90
- github.com/sigstore/fulcio v1.4 .5
91
- github.com/sigstore/protobuf-specs v0.3.2
93
+ github.com/sigstore/fulcio v1.6 .5
94
+ github.com/sigstore/protobuf-specs v0.3.3
92
95
github.com/sirupsen/logrus v1.9.3 // indirect
93
96
github.com/spf13/afero v1.11.0 // indirect
94
- github.com/spf13/cast v1.6 .0 // indirect
97
+ github.com/spf13/cast v1.7 .0 // indirect
95
98
github.com/spf13/pflag v1.0.5 // indirect
96
- github.com/spf13/viper v1.18.2 // indirect
99
+ github.com/spf13/viper v1.19.0 // indirect
97
100
github.com/subosito/gotenv v1.6.0 // indirect
98
101
github.com/syndtr/goleveldb v1.0.1-0.20220721030215-126854af5e6d // indirect
99
102
github.com/theupdateframework/go-tuf v0.7.0 // indirect
100
103
github.com/titanous/rocacheck v0.0.0-20171023193734-afe73141d399 // indirect
101
- github.com/vbatts/tar-split v0.11.5 // indirect
104
+ github.com/vbatts/tar-split v0.11.6 // indirect
102
105
go.mongodb.org/mongo-driver v1.14.0 // indirect
103
- go.opentelemetry.io/otel v1.27 .0 // indirect
104
- go.opentelemetry.io/otel/trace v1.27 .0 // indirect
106
+ go.opentelemetry.io/otel v1.33 .0 // indirect
107
+ go.opentelemetry.io/otel/trace v1.33 .0 // indirect
105
108
go.uber.org/multierr v1.11.0 // indirect
106
109
go.uber.org/zap v1.27.0 // indirect
107
- golang.org/x/crypto v0.31 .0 // indirect
110
+ golang.org/x/crypto v0.32 .0 // indirect
108
111
golang.org/x/exp v0.0.0-20241004190924-225e2abe05e6
109
- golang.org/x/net v0.27 .0 // indirect
112
+ golang.org/x/net v0.31 .0 // indirect
110
113
golang.org/x/sync v0.10.0 // indirect
111
- golang.org/x/sys v0.28 .0 // indirect
112
- golang.org/x/term v0.27 .0 // indirect
114
+ golang.org/x/sys v0.29 .0 // indirect
115
+ golang.org/x/term v0.28 .0 // indirect
113
116
golang.org/x/text v0.21.0 // indirect
114
- google.golang.org/grpc v1.64.1 // indirect
115
- google.golang.org/protobuf v1.34.2
117
+ google.golang.org/grpc v1.68.0 // indirect
118
+ google.golang.org/protobuf v1.36.3
116
119
gopkg.in/ini.v1 v1.67.0 // indirect
117
120
gopkg.in/yaml.v3 v3.0.1 // indirect
118
- k8s.io/klog/v2 v2.120 .1 // indirect
121
+ k8s.io/klog/v2 v2.130 .1 // indirect
119
122
sigs.k8s.io/yaml v1.4.0 // indirect
120
123
)
0 commit comments