@@ -23,7 +23,7 @@ require (
23
23
github.com/aquasecurity/go-pep440-version v0.0.0-20210121094942-22b2f8951d46
24
24
github.com/aquasecurity/go-version v0.0.0-20240603093900-cf8a8d29271d
25
25
github.com/aquasecurity/table v1.8.0
26
- github.com/aquasecurity/testdocker v0.0.0-20240613070307-2c3868d658ac
26
+ github.com/aquasecurity/testdocker v0.0.0-20240730042311-4642e94c7fc8
27
27
github.com/aquasecurity/tml v0.6.1
28
28
github.com/aquasecurity/trivy-checks v0.13.0
29
29
github.com/aquasecurity/trivy-db v0.0.0-20240718084044-d23a6ca8ba04
@@ -75,6 +75,7 @@ require (
75
75
github.com/liamg/iamgo v0.0.9
76
76
github.com/liamg/jfather v0.0.7
77
77
github.com/liamg/memoryfs v1.6.0
78
+ github.com/magefile/mage v1.15.0
78
79
github.com/masahiro331/go-disk v0.0.0-20220919035250-c8da316f91ac
79
80
github.com/masahiro331/go-ebs-file v0.0.0-20240112135404-d5fbb1d46323
80
81
github.com/masahiro331/go-ext4-filesystem v0.0.0-20231208112839-4339555a0cd4
@@ -90,6 +91,7 @@ require (
90
91
github.com/open-policy-agent/opa v0.66.0
91
92
github.com/opencontainers/go-digest v1.0.0
92
93
github.com/opencontainers/image-spec v1.1.0
94
+ github.com/openvex/discovery v0.1.0
93
95
github.com/openvex/go-vex v0.2.5
94
96
github.com/owenrumney/go-sarif/v2 v2.3.3
95
97
github.com/owenrumney/squealer v1.2.3
@@ -133,8 +135,6 @@ require (
133
135
sigs.k8s.io/yaml v1.4.0
134
136
)
135
137
136
- require github.com/magefile/mage v1.15.0
137
-
138
138
require (
139
139
cloud.google.com/go v0.112.1 // indirect
140
140
cloud.google.com/go/compute/metadata v0.3.0 // indirect
@@ -182,6 +182,7 @@ require (
182
182
github.com/aws/aws-sdk-go-v2/service/ssooidc v1.26.4 // indirect
183
183
github.com/beorn7/perks v1.0.1 // indirect
184
184
github.com/bgentry/go-netrc v0.0.0-20140422174119-9fd32a8b3d3d // indirect
185
+ github.com/blang/semver v3.5.1+incompatible // indirect
185
186
github.com/briandowns/spinner v1.23.0 // indirect
186
187
github.com/cespare/xxhash/v2 v2.2.0 // indirect
187
188
github.com/chai2010/gettext-go v1.0.2 // indirect
@@ -198,9 +199,12 @@ require (
198
199
github.com/containerd/typeurl/v2 v2.1.1 // indirect
199
200
github.com/cpuguy83/dockercfg v0.3.1 // indirect
200
201
github.com/cpuguy83/go-md2man/v2 v2.0.4 // indirect
202
+ github.com/cyberphone/json-canonicalization v0.0.0-20231011164504-785e29786b46 // indirect
201
203
github.com/cyphar/filepath-securejoin v0.2.4 // indirect
202
204
github.com/davecgh/go-spew v1.1.2-0.20180830191138-d8f796af33cc // indirect
203
205
github.com/dgryski/go-rendezvous v0.0.0-20200823014737-9f7001d12a5f // indirect
206
+ github.com/digitorus/pkcs7 v0.0.0-20230818184609-3a137a874352 // indirect
207
+ github.com/digitorus/timestamp v0.0.0-20231217203849-220c5c2851b7 // indirect
204
208
github.com/distribution/reference v0.6.0 // indirect
205
209
github.com/dlclark/regexp2 v1.4.0 // indirect
206
210
github.com/docker/cli v27.0.3+incompatible // indirect
@@ -218,6 +222,7 @@ require (
218
222
github.com/exponent-io/jsonpath v0.0.0-20151013193312-d6023ce2651d // indirect
219
223
github.com/felixge/httpsnoop v1.0.4 // indirect
220
224
github.com/fsnotify/fsnotify v1.7.0 // indirect
225
+ github.com/go-chi/chi v4.1.2+incompatible // indirect
221
226
github.com/go-errors/errors v1.4.2 // indirect
222
227
github.com/go-git/gcfg v1.5.1-0.20230307220236-3a3c6141e376 // indirect
223
228
github.com/go-git/go-billy/v5 v5.5.0 // indirect
@@ -234,16 +239,17 @@ require (
234
239
github.com/go-openapi/spec v0.21.0 // indirect
235
240
github.com/go-openapi/swag v0.23.0 // indirect
236
241
github.com/go-openapi/validate v0.24.0 // indirect
237
- github.com/go-test/deep v1.1.0 // indirect
238
242
github.com/gobwas/glob v0.2.3 // indirect
239
243
github.com/goccy/go-yaml v1.9.5 // indirect
240
244
github.com/gofrs/uuid v4.3.1+incompatible // indirect
241
245
github.com/gogo/protobuf v1.3.2 // indirect
242
246
github.com/golang-jwt/jwt/v4 v4.5.0 // indirect
243
247
github.com/golang/groupcache v0.0.0-20210331224755-41bb18bfe9da // indirect
244
248
github.com/golang/protobuf v1.5.4 // indirect
249
+ github.com/golang/snappy v0.0.4 // indirect
245
250
github.com/google/btree v1.1.2 // indirect
246
- github.com/google/gnostic-models v0.6.8 // indirect
251
+ github.com/google/certificate-transparency-go v1.1.8 // indirect
252
+ github.com/google/gnostic-models v0.6.9-0.20230804172637-c7be7c783f49 // indirect
247
253
github.com/google/go-cmp v0.6.0 // indirect
248
254
github.com/google/go-querystring v1.1.0 // indirect
249
255
github.com/google/gofuzz v1.2.0 // indirect
@@ -260,12 +266,13 @@ require (
260
266
github.com/hashicorp/go-cleanhttp v0.5.2 // indirect
261
267
github.com/hashicorp/go-safetemp v1.0.0 // indirect
262
268
github.com/hashicorp/golang-lru v0.6.0 // indirect
263
- github.com/hashicorp/hcl v1.0.0 // indirect
269
+ github.com/hashicorp/hcl v1.0.1-vault-5 // indirect
264
270
github.com/hashicorp/terraform-json v0.22.1 // indirect
265
271
github.com/huandu/xstrings v1.4.0 // indirect
266
- github.com/imdario/mergo v0.3.15 // indirect
272
+ github.com/imdario/mergo v0.3.16 // indirect
267
273
github.com/inconshreveable/mousetrap v1.1.0 // indirect
268
274
github.com/jbenet/go-context v0.0.0-20150711004518-d14ea06fba99 // indirect
275
+ github.com/jedisct1/go-minisign v0.0.0-20230811132847-661be99b8267 // indirect
269
276
github.com/jmespath/go-jmespath v0.4.0 // indirect
270
277
github.com/jmoiron/sqlx v1.3.5 // indirect
271
278
github.com/josharian/intern v1.0.0 // indirect
@@ -274,6 +281,7 @@ require (
274
281
github.com/klauspost/compress v1.17.9 // indirect
275
282
github.com/lann/builder v0.0.0-20180802200727-47ae307949d0 // indirect
276
283
github.com/lann/ps v0.0.0-20150810152359-62de8c46ede0 // indirect
284
+ github.com/letsencrypt/boulder v0.0.0-20231026200631-000cd05d5491 // indirect
277
285
github.com/lib/pq v1.10.9 // indirect
278
286
github.com/liggitt/tabwriter v0.0.0-20181228230101-89fcab3d43de // indirect
279
287
github.com/lufia/plan9stats v0.0.0-20240226150601-1dcf7310316a // indirect
@@ -303,6 +311,7 @@ require (
303
311
github.com/munnerz/goautoneg v0.0.0-20191010083416-a7dc8b61c822 // indirect
304
312
github.com/mxk/go-flowrate v0.0.0-20140419014527-cca7078d478f // indirect
305
313
github.com/ncruces/go-strftime v0.1.9 // indirect
314
+ github.com/nozzle/throttler v0.0.0-20180817012639-2ea982251481 // indirect
306
315
github.com/oklog/ulid v1.3.1 // indirect
307
316
github.com/opencontainers/runtime-spec v1.2.0 // indirect
308
317
github.com/opencontainers/selinux v1.11.0 // indirect
@@ -316,30 +325,38 @@ require (
316
325
github.com/power-devops/perfstat v0.0.0-20240221224432-82ca36839d55 // indirect
317
326
github.com/prometheus/client_golang v1.19.1 // indirect
318
327
github.com/prometheus/client_model v0.6.1 // indirect
319
- github.com/prometheus/common v0.48.0 // indirect
328
+ github.com/prometheus/common v0.51.1 // indirect
320
329
github.com/prometheus/procfs v0.15.1 // indirect
321
330
github.com/rcrowley/go-metrics v0.0.0-20201227073835-cf1acfcdf475 // indirect
322
331
github.com/remyoudompheng/bigfft v0.0.0-20230129092748-24d4a6f8daec // indirect
323
- github.com/rivo/uniseg v0.2.0 // indirect
332
+ github.com/rivo/uniseg v0.4.4 // indirect
324
333
github.com/rubenv/sql-migrate v1.5.2 // indirect
325
334
github.com/russross/blackfriday/v2 v2.1.0 // indirect
326
335
github.com/sagikazarmark/locafero v0.4.0 // indirect
327
336
github.com/sagikazarmark/slog-shim v0.1.0 // indirect
328
337
github.com/santhosh-tekuri/jsonschema/v5 v5.3.1 // indirect
338
+ github.com/sassoftware/relic v7.2.1+incompatible // indirect
329
339
github.com/sergi/go-diff v1.3.2-0.20230802210424-5b0b94c5c0d3 // indirect
330
340
github.com/shibumi/go-pathspec v1.3.0 // indirect
331
341
github.com/shirou/gopsutil/v3 v3.24.2 // indirect
332
342
github.com/shoenig/go-m1cpu v0.1.6 // indirect
333
343
github.com/shopspring/decimal v1.3.1 // indirect
344
+ github.com/sigstore/cosign/v2 v2.2.4 // indirect
345
+ github.com/sigstore/sigstore v1.8.3 // indirect
346
+ github.com/sigstore/timestamp-authority v1.2.2 // indirect
334
347
github.com/skeema/knownhosts v1.2.2 // indirect
335
348
github.com/sourcegraph/conc v0.3.0 // indirect
336
349
github.com/spf13/afero v1.11.0 // indirect
337
350
github.com/stretchr/objx v0.5.2 // indirect
338
351
github.com/subosito/gotenv v1.6.0 // indirect
352
+ github.com/syndtr/goleveldb v1.0.1-0.20220721030215-126854af5e6d // indirect
339
353
github.com/tchap/go-patricia/v2 v2.3.1 // indirect
354
+ github.com/theupdateframework/go-tuf v0.7.0 // indirect
355
+ github.com/titanous/rocacheck v0.0.0-20171023193734-afe73141d399 // indirect
340
356
github.com/tklauser/go-sysconf v0.3.13 // indirect
341
357
github.com/tklauser/numcpus v0.7.0 // indirect
342
358
github.com/tonistiigi/go-csvvalue v0.0.0-20240710180619-ddb21b71c0b4 // indirect
359
+ github.com/transparency-dev/merkle v0.0.2 // indirect
343
360
github.com/ulikunitz/xz v0.5.11 // indirect
344
361
github.com/vbatts/tar-split v0.11.5 // indirect
345
362
github.com/xanzy/ssh-agent v0.3.3 // indirect
@@ -371,6 +388,7 @@ require (
371
388
google.golang.org/genproto/googleapis/rpc v0.0.0-20240515191416-fc5f0ca64291 // indirect
372
389
google.golang.org/grpc v1.64.0 // indirect
373
390
gopkg.in/cheggaaa/pb.v1 v1.0.28 // indirect
391
+ gopkg.in/go-jose/go-jose.v2 v2.6.3 // indirect
374
392
gopkg.in/inf.v0 v0.9.1 // indirect
375
393
gopkg.in/ini.v1 v1.67.0 // indirect
376
394
gopkg.in/warnings.v0 v0.1.2 // indirect
@@ -397,3 +415,6 @@ require (
397
415
sigs.k8s.io/kustomize/kyaml v0.14.3-0.20230601165947-6ce0bf390ce3 // indirect
398
416
sigs.k8s.io/structured-merge-diff/v4 v4.4.1 // indirect
399
417
)
418
+
419
+ // cf. https://github.com/openvex/discovery/pull/40
420
+ replace github.com/openvex/discovery => github.com/knqyf263/discovery v0.1.1-0.20240726113521-97873005fd03
0 commit comments