@@ -5,8 +5,8 @@ go 1.22.0
5
5
toolchain go1.22.4
6
6
7
7
require (
8
- github.com/aquasecurity/trivy v0.53.0 // Also update .config.yml
9
- github.com/aquasecurity/trivy-db v0.0.0-20231106053131-81d747dba6ac
8
+ github.com/aquasecurity/trivy v0.54.1 // Also update .config.yml
9
+ github.com/aquasecurity/trivy-db v0.0.0-20240718084044-d23a6ca8ba04
10
10
github.com/codacy/codacy-engine-golang-seed/v6 v6.2.1
11
11
github.com/samber/lo v1.47.0
12
12
github.com/stretchr/testify v1.9.0
@@ -23,9 +23,9 @@ require (
23
23
github.com/AdaLogics/go-fuzz-headers v0.0.0-20230811130428-ced1acdcaa24 // indirect
24
24
github.com/AdamKorcz/go-118-fuzz-build v0.0.0-20230306123547-8075edf89bb0 // indirect
25
25
github.com/Azure/azure-sdk-for-go v68.0.0+incompatible // indirect
26
- github.com/Azure/azure-sdk-for-go/sdk/azcore v1.11.1 // indirect
27
- github.com/Azure/azure-sdk-for-go/sdk/azidentity v1.6 .0 // indirect
28
- github.com/Azure/azure-sdk-for-go/sdk/internal v1.8 .0 // indirect
26
+ github.com/Azure/azure-sdk-for-go/sdk/azcore v1.13.0 // indirect
27
+ github.com/Azure/azure-sdk-for-go/sdk/azidentity v1.7 .0 // indirect
28
+ github.com/Azure/azure-sdk-for-go/sdk/internal v1.10 .0 // indirect
29
29
github.com/Azure/go-ansiterm v0.0.0-20230124172434-306776ec8161 // indirect
30
30
github.com/Azure/go-autorest v14.2.0+incompatible // indirect
31
31
github.com/Azure/go-autorest/autorest v0.11.29 // indirect
@@ -65,26 +65,27 @@ require (
65
65
github.com/aquasecurity/trivy-java-db v0.0.0-20240109071736-184bd7481d48 // indirect
66
66
github.com/asaskevich/govalidator v0.0.0-20230301143203-a9d515a09cc2 // indirect
67
67
github.com/aws/aws-sdk-go v1.54.6 // indirect
68
- github.com/aws/aws-sdk-go-v2 v1.27.2 // indirect
69
- github.com/aws/aws-sdk-go-v2/config v1.27.18 // indirect
70
- github.com/aws/aws-sdk-go-v2/credentials v1.17.18 // indirect
71
- github.com/aws/aws-sdk-go-v2/feature/ec2/imds v1.16.5 // indirect
72
- github.com/aws/aws-sdk-go-v2/internal/configsources v1.3.9 // indirect
73
- github.com/aws/aws-sdk-go-v2/internal/endpoints/v2 v2.6.9 // indirect
68
+ github.com/aws/aws-sdk-go-v2 v1.30.3 // indirect
69
+ github.com/aws/aws-sdk-go-v2/config v1.27.27 // indirect
70
+ github.com/aws/aws-sdk-go-v2/credentials v1.17.27 // indirect
71
+ github.com/aws/aws-sdk-go-v2/feature/ec2/imds v1.16.11 // indirect
72
+ github.com/aws/aws-sdk-go-v2/internal/configsources v1.3.15 // indirect
73
+ github.com/aws/aws-sdk-go-v2/internal/endpoints/v2 v2.6.15 // indirect
74
74
github.com/aws/aws-sdk-go-v2/internal/ini v1.8.0 // indirect
75
75
github.com/aws/aws-sdk-go-v2/service/ebs v1.21.7 // indirect
76
- github.com/aws/aws-sdk-go-v2/service/ec2 v1.163.1 // indirect
77
- github.com/aws/aws-sdk-go-v2/service/ecr v1.28.5 // indirect
78
- github.com/aws/aws-sdk-go-v2/service/internal/accept-encoding v1.11.2 // indirect
79
- github.com/aws/aws-sdk-go-v2/service/internal/presigned-url v1.11.11 // indirect
80
- github.com/aws/aws-sdk-go-v2/service/s3 v1.55.1 // indirect
81
- github.com/aws/aws-sdk-go-v2/service/sso v1.20.11 // indirect
82
- github.com/aws/aws-sdk-go-v2/service/ssooidc v1.24.5 // indirect
83
- github.com/aws/aws-sdk-go-v2/service/sts v1.28.12 // indirect
84
- github.com/aws/smithy-go v1.20.2 // indirect
76
+ github.com/aws/aws-sdk-go-v2/service/ec2 v1.172.0 // indirect
77
+ github.com/aws/aws-sdk-go-v2/service/ecr v1.30.3 // indirect
78
+ github.com/aws/aws-sdk-go-v2/service/internal/accept-encoding v1.11.3 // indirect
79
+ github.com/aws/aws-sdk-go-v2/service/internal/presigned-url v1.11.17 // indirect
80
+ github.com/aws/aws-sdk-go-v2/service/s3 v1.58.2 // indirect
81
+ github.com/aws/aws-sdk-go-v2/service/sso v1.22.4 // indirect
82
+ github.com/aws/aws-sdk-go-v2/service/ssooidc v1.26.4 // indirect
83
+ github.com/aws/aws-sdk-go-v2/service/sts v1.30.3 // indirect
84
+ github.com/aws/smithy-go v1.20.3 // indirect
85
85
github.com/beorn7/perks v1.0.1 // indirect
86
86
github.com/bgentry/go-netrc v0.0.0-20140422174119-9fd32a8b3d3d // indirect
87
87
github.com/bitnami/go-version v0.0.0-20231130084017-bb00604d650c // indirect
88
+ github.com/blang/semver v3.5.1+incompatible // indirect
88
89
github.com/bmatcuk/doublestar/v4 v4.6.1 // indirect
89
90
github.com/briandowns/spinner v1.23.0 // indirect
90
91
github.com/cenkalti/backoff/v4 v4.3.0 // indirect
@@ -93,35 +94,42 @@ require (
93
94
github.com/cheggaaa/pb/v3 v3.1.5 // indirect
94
95
github.com/cloudflare/circl v1.3.7 // indirect
95
96
github.com/containerd/cgroups/v3 v3.0.2 // indirect
96
- github.com/containerd/containerd v1.7.17 // indirect
97
+ github.com/containerd/containerd v1.7.20 // indirect
98
+ github.com/containerd/containerd/api v1.7.19 // indirect
97
99
github.com/containerd/continuity v0.4.3 // indirect
98
100
github.com/containerd/errdefs v0.1.0 // indirect
99
101
github.com/containerd/fifo v1.1.0 // indirect
100
102
github.com/containerd/log v0.1.0 // indirect
103
+ github.com/containerd/platforms v0.2.1 // indirect
101
104
github.com/containerd/stargz-snapshotter/estargz v0.15.1 // indirect
102
- github.com/containerd/ttrpc v1.2.4 // indirect
105
+ github.com/containerd/ttrpc v1.2.5 // indirect
103
106
github.com/containerd/typeurl/v2 v2.1.1 // indirect
104
107
github.com/csaf-poc/csaf_distribution/v3 v3.0.0 // indirect
108
+ github.com/cyberphone/json-canonicalization v0.0.0-20231011164504-785e29786b46 // indirect
105
109
github.com/cyphar/filepath-securejoin v0.2.4 // indirect
106
110
github.com/davecgh/go-spew v1.1.2-0.20180830191138-d8f796af33cc // indirect
107
111
github.com/dgryski/go-rendezvous v0.0.0-20200823014737-9f7001d12a5f // indirect
112
+ github.com/digitorus/pkcs7 v0.0.0-20230818184609-3a137a874352 // indirect
113
+ github.com/digitorus/timestamp v0.0.0-20231217203849-220c5c2851b7 // indirect
108
114
github.com/distribution/reference v0.6.0 // indirect
109
115
github.com/dlclark/regexp2 v1.4.0 // indirect
110
- github.com/docker/cli v25 .0.3+incompatible // indirect
116
+ github.com/docker/cli v27 .0.3+incompatible // indirect
111
117
github.com/docker/distribution v2.8.3+incompatible // indirect
112
- github.com/docker/docker v26 .1.5 +incompatible // indirect
113
- github.com/docker/docker-credential-helpers v0.8.0 // indirect
118
+ github.com/docker/docker v27 .1.1 +incompatible // indirect
119
+ github.com/docker/docker-credential-helpers v0.8.2 // indirect
114
120
github.com/docker/go-connections v0.5.0 // indirect
115
121
github.com/docker/go-events v0.0.0-20190806004212-e31b211e4f1c // indirect
116
122
github.com/docker/go-metrics v0.0.1 // indirect
117
123
github.com/docker/go-units v0.5.0 // indirect
124
+ github.com/dustin/go-humanize v1.0.1 // indirect
118
125
github.com/emicklei/go-restful/v3 v3.11.0 // indirect
119
126
github.com/emirpasic/gods v1.18.1 // indirect
120
127
github.com/evanphx/json-patch v5.7.0+incompatible // indirect
121
128
github.com/exponent-io/jsonpath v0.0.0-20151013193312-d6023ce2651d // indirect
122
129
github.com/fatih/color v1.17.0 // indirect
123
130
github.com/felixge/httpsnoop v1.0.4 // indirect
124
131
github.com/fsnotify/fsnotify v1.7.0 // indirect
132
+ github.com/go-chi/chi v4.1.2+incompatible // indirect
125
133
github.com/go-errors/errors v1.4.2 // indirect
126
134
github.com/go-git/gcfg v1.5.1-0.20230307220236-3a3c6141e376 // indirect
127
135
github.com/go-git/go-billy/v5 v5.5.0 // indirect
@@ -147,10 +155,14 @@ require (
147
155
github.com/golang-jwt/jwt/v5 v5.2.1 // indirect
148
156
github.com/golang/groupcache v0.0.0-20210331224755-41bb18bfe9da // indirect
149
157
github.com/golang/protobuf v1.5.4 // indirect
158
+ github.com/golang/snappy v0.0.4 // indirect
150
159
github.com/google/btree v1.1.2 // indirect
151
- github.com/google/gnostic-models v0.6.8 // indirect
160
+ github.com/google/certificate-transparency-go v1.1.8 // indirect
161
+ github.com/google/gnostic-models v0.6.9-0.20230804172637-c7be7c783f49 // indirect
152
162
github.com/google/go-cmp v0.6.0 // indirect
153
- github.com/google/go-containerregistry v0.19.2 // indirect
163
+ github.com/google/go-containerregistry v0.20.1 // indirect
164
+ github.com/google/go-github/v62 v62.0.0 // indirect
165
+ github.com/google/go-querystring v1.1.0 // indirect
154
166
github.com/google/gofuzz v1.2.0 // indirect
155
167
github.com/google/licenseclassifier/v2 v2.0.0 // indirect
156
168
github.com/google/s2a-go v0.1.7 // indirect
@@ -171,19 +183,20 @@ require (
171
183
github.com/hashicorp/go-uuid v1.0.3 // indirect
172
184
github.com/hashicorp/go-version v1.7.0 // indirect
173
185
github.com/hashicorp/golang-lru/v2 v2.0.7 // indirect
174
- github.com/hashicorp/hcl v1.0.0 // indirect
175
- github.com/hashicorp/hcl/v2 v2.20.1 // indirect
186
+ github.com/hashicorp/hcl v1.0.1-vault-5 // indirect
187
+ github.com/hashicorp/hcl/v2 v2.21.0 // indirect
176
188
github.com/huandu/xstrings v1.4.0 // indirect
177
- github.com/imdario/mergo v0.3.15 // indirect
189
+ github.com/imdario/mergo v0.3.16 // indirect
178
190
github.com/in-toto/in-toto-golang v0.9.0 // indirect
179
191
github.com/inconshreveable/mousetrap v1.1.0 // indirect
180
192
github.com/jbenet/go-context v0.0.0-20150711004518-d14ea06fba99 // indirect
193
+ github.com/jedisct1/go-minisign v0.0.0-20230811132847-661be99b8267 // indirect
181
194
github.com/jmespath/go-jmespath v0.4.0 // indirect
182
195
github.com/jmoiron/sqlx v1.3.5 // indirect
183
196
github.com/josharian/intern v1.0.0 // indirect
184
197
github.com/json-iterator/go v1.1.12 // indirect
185
198
github.com/kevinburke/ssh_config v1.2.0 // indirect
186
- github.com/klauspost/compress v1.17.7 // indirect
199
+ github.com/klauspost/compress v1.17.9 // indirect
187
200
github.com/knqyf263/go-apk-version v0.0.0-20200609155635-041fdbb8563f // indirect
188
201
github.com/knqyf263/go-deb-version v0.0.0-20230223133812-3ed183d23422 // indirect
189
202
github.com/knqyf263/go-rpm-version v0.0.0-20220614171824-631e686d1075 // indirect
@@ -192,6 +205,7 @@ require (
192
205
github.com/kylelemons/godebug v1.1.0 // indirect
193
206
github.com/lann/builder v0.0.0-20180802200727-47ae307949d0 // indirect
194
207
github.com/lann/ps v0.0.0-20150810152359-62de8c46ede0 // indirect
208
+ github.com/letsencrypt/boulder v0.0.0-20231026200631-000cd05d5491 // indirect
195
209
github.com/liamg/iamgo v0.0.9 // indirect
196
210
github.com/liamg/jfather v0.0.7 // indirect
197
211
github.com/liamg/memoryfs v1.6.0 // indirect
@@ -218,7 +232,7 @@ require (
218
232
github.com/mitchellh/hashstructure/v2 v2.0.2 // indirect
219
233
github.com/mitchellh/mapstructure v1.5.0 // indirect
220
234
github.com/mitchellh/reflectwalk v1.0.2 // indirect
221
- github.com/moby/buildkit v0.13.2 // indirect
235
+ github.com/moby/buildkit v0.15.1 // indirect
222
236
github.com/moby/docker-image-spec v1.3.1 // indirect
223
237
github.com/moby/locker v1.0.1 // indirect
224
238
github.com/moby/spdystream v0.2.0 // indirect
@@ -232,16 +246,18 @@ require (
232
246
github.com/monochromegane/go-gitignore v0.0.0-20200626010858-205db1a8cc00 // indirect
233
247
github.com/munnerz/goautoneg v0.0.0-20191010083416-a7dc8b61c822 // indirect
234
248
github.com/mxk/go-flowrate v0.0.0-20140419014527-cca7078d478f // indirect
249
+ github.com/nozzle/throttler v0.0.0-20180817012639-2ea982251481 // indirect
235
250
github.com/oklog/ulid v1.3.1 // indirect
236
- github.com/open-policy-agent/opa v0.65 .0 // indirect
251
+ github.com/open-policy-agent/opa v0.66 .0 // indirect
237
252
github.com/opencontainers/go-digest v1.0.0 // indirect
238
253
github.com/opencontainers/image-spec v1.1.0 // indirect
239
- github.com/opencontainers/runtime-spec v1.1 .0 // indirect
254
+ github.com/opencontainers/runtime-spec v1.2 .0 // indirect
240
255
github.com/opencontainers/selinux v1.11.0 // indirect
241
256
github.com/opentracing/opentracing-go v1.2.0 // indirect
257
+ github.com/openvex/discovery v0.1.0 // indirect
242
258
github.com/openvex/go-vex v0.2.5 // indirect
243
- github.com/owenrumney/go-sarif/v2 v2.3.1 // indirect
244
- github.com/owenrumney/squealer v1.2.2 // indirect
259
+ github.com/owenrumney/go-sarif/v2 v2.3.3 // indirect
260
+ github.com/owenrumney/squealer v1.2.3 // indirect
245
261
github.com/package-url/packageurl-go v0.1.3 // indirect
246
262
github.com/pelletier/go-toml/v2 v2.2.2 // indirect
247
263
github.com/peterbourgon/diskv v2.0.1+incompatible // indirect
@@ -251,33 +267,42 @@ require (
251
267
github.com/pmezard/go-difflib v1.0.1-0.20181226105442-5d4384ee4fb2 // indirect
252
268
github.com/prometheus/client_golang v1.19.1 // indirect
253
269
github.com/prometheus/client_model v0.6.1 // indirect
254
- github.com/prometheus/common v0.48.0 // indirect
255
- github.com/prometheus/procfs v0.12.0 // indirect
270
+ github.com/prometheus/common v0.51.1 // indirect
271
+ github.com/prometheus/procfs v0.15.1 // indirect
256
272
github.com/rcrowley/go-metrics v0.0.0-20201227073835-cf1acfcdf475 // indirect
257
- github.com/rivo/uniseg v0.2.0 // indirect
273
+ github.com/rivo/uniseg v0.4.4 // indirect
258
274
github.com/rubenv/sql-migrate v1.5.2 // indirect
259
275
github.com/russross/blackfriday/v2 v2.1.0 // indirect
260
276
github.com/sagikazarmark/locafero v0.4.0 // indirect
261
277
github.com/sagikazarmark/slog-shim v0.1.0 // indirect
262
278
github.com/santhosh-tekuri/jsonschema/v5 v5.3.1 // indirect
279
+ github.com/sassoftware/relic v7.2.1+incompatible // indirect
263
280
github.com/secure-systems-lab/go-securesystemslib v0.8.0 // indirect
264
281
github.com/sergi/go-diff v1.3.2-0.20230802210424-5b0b94c5c0d3 // indirect
265
282
github.com/shibumi/go-pathspec v1.3.0 // indirect
266
283
github.com/shopspring/decimal v1.3.1 // indirect
284
+ github.com/sigstore/cosign/v2 v2.2.4 // indirect
267
285
github.com/sigstore/rekor v1.3.6 // indirect
286
+ github.com/sigstore/sigstore v1.8.3 // indirect
287
+ github.com/sigstore/timestamp-authority v1.2.2 // indirect
268
288
github.com/sirupsen/logrus v1.9.3 // indirect
269
289
github.com/skeema/knownhosts v1.2.2 // indirect
270
290
github.com/sourcegraph/conc v0.3.0 // indirect
271
- github.com/spdx/tools-golang v0.5.4 // indirect
291
+ github.com/spdx/tools-golang v0.5.5 // indirect
272
292
github.com/spf13/afero v1.11.0 // indirect
273
293
github.com/spf13/cast v1.6.0 // indirect
274
- github.com/spf13/cobra v1.8.0 // indirect
294
+ github.com/spf13/cobra v1.8.1 // indirect
275
295
github.com/spf13/pflag v1.0.5 // indirect
276
296
github.com/spf13/viper v1.19.0 // indirect
277
297
github.com/stretchr/objx v0.5.2 // indirect
278
298
github.com/subosito/gotenv v1.6.0 // indirect
299
+ github.com/syndtr/goleveldb v1.0.1-0.20220721030215-126854af5e6d // indirect
279
300
github.com/tchap/go-patricia/v2 v2.3.1 // indirect
280
- github.com/tetratelabs/wazero v1.7.2 // indirect
301
+ github.com/tetratelabs/wazero v1.7.3 // indirect
302
+ github.com/theupdateframework/go-tuf v0.7.0 // indirect
303
+ github.com/titanous/rocacheck v0.0.0-20171023193734-afe73141d399 // indirect
304
+ github.com/tonistiigi/go-csvvalue v0.0.0-20240710180619-ddb21b71c0b4 // indirect
305
+ github.com/transparency-dev/merkle v0.0.2 // indirect
281
306
github.com/twitchtv/twirp v8.1.3+incompatible // indirect
282
307
github.com/ulikunitz/xz v0.5.11 // indirect
283
308
github.com/vbatts/tar-split v0.11.5 // indirect
@@ -287,7 +312,7 @@ require (
287
312
github.com/xeipuuv/gojsonschema v1.2.0 // indirect
288
313
github.com/xlab/treeprint v1.2.0 // indirect
289
314
github.com/yashtewari/glob-intersection v0.2.0 // indirect
290
- github.com/zclconf/go-cty v1.14.4 // indirect
315
+ github.com/zclconf/go-cty v1.15.0 // indirect
291
316
github.com/zclconf/go-cty-yaml v1.0.3 // indirect
292
317
go.etcd.io/bbolt v1.3.10 // indirect
293
318
go.mongodb.org/mongo-driver v1.14.0 // indirect
@@ -301,34 +326,35 @@ require (
301
326
go.starlark.net v0.0.0-20230525235612-a134d8f9ddca // indirect
302
327
go.uber.org/multierr v1.11.0 // indirect
303
328
go.uber.org/zap v1.27.0 // indirect
304
- golang.org/x/crypto v0.24 .0 // indirect
329
+ golang.org/x/crypto v0.25 .0 // indirect
305
330
golang.org/x/exp v0.0.0-20231110203233-9a3e6036ecaa // indirect
306
- golang.org/x/net v0.26 .0 // indirect
331
+ golang.org/x/net v0.27 .0 // indirect
307
332
golang.org/x/oauth2 v0.20.0 // indirect
308
333
golang.org/x/sync v0.7.0 // indirect
309
- golang.org/x/sys v0.21 .0 // indirect
310
- golang.org/x/term v0.21 .0 // indirect
334
+ golang.org/x/sys v0.22 .0 // indirect
335
+ golang.org/x/term v0.22 .0 // indirect
311
336
golang.org/x/text v0.16.0 // indirect
312
337
golang.org/x/time v0.5.0 // indirect
313
- golang.org/x/tools v0.21.1-0.20240508182429-e35e4ccd0d2d // indirect
338
+ golang.org/x/tools v0.23.0 // indirect
314
339
golang.org/x/xerrors v0.0.0-20231012003039-104605ab7028 // indirect
315
340
google.golang.org/api v0.172.0 // indirect
316
341
google.golang.org/genproto v0.0.0-20240311173647-c811ad7063a7 // indirect
317
342
google.golang.org/genproto/googleapis/api v0.0.0-20240520151616-dc85e6b867a5 // indirect
318
343
google.golang.org/genproto/googleapis/rpc v0.0.0-20240515191416-fc5f0ca64291 // indirect
319
344
google.golang.org/grpc v1.64.1 // indirect
320
- google.golang.org/protobuf v1.34.1 // indirect
345
+ google.golang.org/protobuf v1.34.2 // indirect
321
346
gopkg.in/cheggaaa/pb.v1 v1.0.28 // indirect
347
+ gopkg.in/go-jose/go-jose.v2 v2.6.3 // indirect
322
348
gopkg.in/inf.v0 v0.9.1 // indirect
323
349
gopkg.in/ini.v1 v1.67.0 // indirect
324
350
gopkg.in/warnings.v0 v0.1.2 // indirect
325
351
gopkg.in/yaml.v2 v2.4.0 // indirect
326
352
gopkg.in/yaml.v3 v3.0.1 // indirect
327
353
gotest.tools/v3 v3.5.0 // indirect
328
- helm.sh/helm/v3 v3.15.1 // indirect
329
- k8s.io/api v0.30.2 // indirect
354
+ helm.sh/helm/v3 v3.15.3 // indirect
355
+ k8s.io/api v0.30.3 // indirect
330
356
k8s.io/apiextensions-apiserver v0.30.0 // indirect
331
- k8s.io/apimachinery v0.30.2 // indirect
357
+ k8s.io/apimachinery v0.30.3 // indirect
332
358
k8s.io/apiserver v0.30.0 // indirect
333
359
k8s.io/cli-runtime v0.30.2 // indirect
334
360
k8s.io/client-go v0.30.2 // indirect
0 commit comments