@@ -7,7 +7,7 @@ require (
77 github.com/Azure/azure-sdk-for-go/sdk/azidentity v1.12.0
88 github.com/Azure/azure-sdk-for-go/sdk/containers/azcontainerregistry v0.2.3
99 github.com/BurntSushi/toml v1.5.0
10- github.com/CycloneDX/cyclonedx-go v0.9.2
10+ github.com/CycloneDX/cyclonedx-go v0.9.3
1111 github.com/GoogleCloudPlatform/docker-credential-gcr v2.0.5+incompatible
1212 github.com/Masterminds/sprig/v3 v3.3.0
1313 github.com/NYTimes/gziphandler v1.1.1
@@ -46,7 +46,7 @@ require (
4646 github.com/docker/go-connections v0.6.0
4747 github.com/docker/go-units v0.5.0
4848 github.com/fatih/color v1.18.0
49- github.com/go-git/go-git/v5 v5.16.2
49+ github.com/go-git/go-git/v5 v5.16.3
5050 github.com/go-redis/redis/v8 v8.11.5
5151 github.com/go-viper/mapstructure/v2 v2.4.0
5252 github.com/gocsaf/csaf/v3 v3.3.0
@@ -83,21 +83,21 @@ require (
8383 github.com/mitchellh/hashstructure/v2 v2.0.2
8484 github.com/moby/buildkit v0.23.2
8585 github.com/moby/docker-image-spec v1.3.1
86- github.com/open-policy-agent/opa v1.8 .0
86+ github.com/open-policy-agent/opa v1.9 .0
8787 github.com/opencontainers/go-digest v1.0.0
8888 github.com/opencontainers/image-spec v1.1.1
8989 github.com/openvex/discovery v0.1.1-0.20240802171711-7c54efc57553
9090 github.com/openvex/go-vex v0.2.7
9191 github.com/owenrumney/go-sarif/v2 v2.3.3
9292 github.com/package-url/packageurl-go v0.1.3
93- github.com/quasilyte/go-ruleguard/dsl v0.3.22
93+ github.com/quasilyte/go-ruleguard/dsl v0.3.23
9494 github.com/rogpeppe/go-internal v1.14.1
9595 github.com/rust-secure-code/go-rustaudit v0.0.0-20250226111315-e20ec32e963c
9696 github.com/samber/lo v1.51.0
9797 github.com/sassoftware/go-rpmutils v0.4.0
9898 github.com/secure-systems-lab/go-securesystemslib v0.9.1
9999 github.com/sigstore/rekor v1.4.2
100- github.com/sirupsen/logrus v1.9.3
100+ github.com/sirupsen/logrus v1.9.4-0.20230606125235-dd1b4c2e81af
101101 github.com/sosedoff/gitkit v0.4.0
102102 github.com/spdx/tools-golang v0.5.5 // v0.5.3 with necessary changes. Can be upgraded to version 0.5.4 after release.
103103 github.com/spf13/cast v1.10.0
@@ -122,10 +122,10 @@ require (
122122 golang.org/x/text v0.29.0
123123 golang.org/x/vuln v1.1.4
124124 golang.org/x/xerrors v0.0.0-20240716161551-93cc26a95ae9
125- google.golang.org/protobuf v1.36.9
125+ google.golang.org/protobuf v1.36.10
126126 gopkg.in/yaml.v3 v3.0.1
127127 helm.sh/helm/v3 v3.19.0
128- k8s.io/api v0.34.0
128+ k8s.io/api v0.34.1
129129 k8s.io/utils v0.0.0-20250604170112-4c0f3b243397
130130 modernc.org/sqlite v1.39.0
131131)
@@ -201,7 +201,7 @@ require (
201201 github.com/bufbuild/buf v1.55.1 // indirect
202202 github.com/bufbuild/protocompile v0.14.1 // indirect
203203 github.com/bufbuild/protoplugin v0.0.0-20250218205857-750e09ce93e1 // indirect
204- github.com/cenkalti/backoff/v5 v5.0.2 // indirect
204+ github.com/cenkalti/backoff/v5 v5.0.3 // indirect
205205 github.com/cespare/xxhash/v2 v2.3.0 // indirect
206206 github.com/chai2010/gettext-go v1.0.2 // indirect
207207 github.com/cloudflare/circl v1.6.1 // indirect
@@ -277,7 +277,7 @@ require (
277277 github.com/go-openapi/validate v0.24.0 // indirect
278278 github.com/go-task/slim-sprig/v3 v3.0.0 // indirect
279279 github.com/gobwas/glob v0.2.3 // indirect
280- github.com/goccy/go-json v0.10.3 // indirect
280+ github.com/goccy/go-json v0.10.5 // indirect
281281 github.com/goccy/go-yaml v1.15.23 // indirect
282282 github.com/gofrs/flock v0.12.1 // indirect
283283 github.com/gofrs/uuid v4.3.1+incompatible // indirect
@@ -301,7 +301,7 @@ require (
301301 github.com/gorilla/websocket v1.5.4-0.20250319132907-e064f32e3674 // indirect
302302 github.com/gosuri/uitable v0.0.4 // indirect
303303 github.com/gregjones/httpcache v0.0.0-20190611155906-901d90724c79 // indirect
304- github.com/grpc-ecosystem/grpc-gateway/v2 v2.27.1 // indirect
304+ github.com/grpc-ecosystem/grpc-gateway/v2 v2.27.2 // indirect
305305 github.com/hashicorp/aws-sdk-go-base/v2 v2.0.0-beta.65 // indirect
306306 github.com/hashicorp/errwrap v1.1.0 // indirect
307307 github.com/hashicorp/go-cleanhttp v0.5.2 // indirect
@@ -322,9 +322,11 @@ require (
322322 github.com/lann/builder v0.0.0-20180802200727-47ae307949d0 // indirect
323323 github.com/lann/ps v0.0.0-20150810152359-62de8c46ede0 // indirect
324324 github.com/lestrrat-go/blackmagic v1.0.4 // indirect
325+ github.com/lestrrat-go/dsig v1.0.0 // indirect
326+ github.com/lestrrat-go/dsig-secp256k1 v1.0.0 // indirect
325327 github.com/lestrrat-go/httpcc v1.0.1 // indirect
326- github.com/lestrrat-go/httprc/v3 v3.0.0 // indirect
327- github.com/lestrrat-go/jwx/v3 v3.0.10 // indirect
328+ github.com/lestrrat-go/httprc/v3 v3.0.1 // indirect
329+ github.com/lestrrat-go/jwx/v3 v3.0.11 // indirect
328330 github.com/lestrrat-go/option v1.0.1 // indirect
329331 github.com/lestrrat-go/option/v2 v2.0.0 // indirect
330332 github.com/letsencrypt/boulder v0.0.0-20240620165639-de9c06129bec // indirect
@@ -377,13 +379,13 @@ require (
377379 github.com/planetscale/vtprotobuf v0.6.1-0.20240319094008-0393e58bdf10 // indirect
378380 github.com/pmezard/go-difflib v1.0.1-0.20181226105442-5d4384ee4fb2 // indirect
379381 github.com/power-devops/perfstat v0.0.0-20240221224432-82ca36839d55 // indirect
380- github.com/prometheus/client_golang v1.23.0 // indirect
382+ github.com/prometheus/client_golang v1.23.2 // indirect
381383 github.com/prometheus/client_model v0.6.2 // indirect
382- github.com/prometheus/common v0.65.0 // indirect
383- github.com/prometheus/procfs v0.16.1 // indirect
384+ github.com/prometheus/common v0.66.1 // indirect
385+ github.com/prometheus/procfs v0.17.0 // indirect
384386 github.com/quic-go/qpack v0.5.1 // indirect
385387 github.com/quic-go/quic-go v0.52.0 // indirect
386- github.com/rcrowley/go-metrics v0.0.0-20201227073835-cf1acfcdf475 // indirect
388+ github.com/rcrowley/go-metrics v0.0.0-20250401214520-65e299d6c5c9 // indirect
387389 github.com/remyoudompheng/bigfft v0.0.0-20230129092748-24d4a6f8daec // indirect
388390 github.com/rivo/uniseg v0.4.7 // indirect
389391 github.com/rs/cors v1.11.1 // indirect
@@ -444,16 +446,16 @@ require (
444446 go.opentelemetry.io/auto/sdk v1.1.0 // indirect
445447 go.opentelemetry.io/contrib/detectors/gcp v1.36.0 // indirect
446448 go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc v0.61.0 // indirect
447- go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.62 .0 // indirect
448- go.opentelemetry.io/otel v1.37 .0 // indirect
449+ go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.63 .0 // indirect
450+ go.opentelemetry.io/otel v1.38 .0 // indirect
449451 go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetricgrpc v1.32.0 // indirect
450- go.opentelemetry.io/otel/exporters/otlp/otlptrace v1.37 .0 // indirect
451- go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc v1.37 .0 // indirect
452- go.opentelemetry.io/otel/metric v1.37 .0 // indirect
453- go.opentelemetry.io/otel/sdk v1.37 .0 // indirect
454- go.opentelemetry.io/otel/sdk/metric v1.37 .0 // indirect
455- go.opentelemetry.io/otel/trace v1.37 .0 // indirect
456- go.opentelemetry.io/proto/otlp v1.7.0 // indirect
452+ go.opentelemetry.io/otel/exporters/otlp/otlptrace v1.38 .0 // indirect
453+ go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc v1.38 .0 // indirect
454+ go.opentelemetry.io/otel/metric v1.38 .0 // indirect
455+ go.opentelemetry.io/otel/sdk v1.38 .0 // indirect
456+ go.opentelemetry.io/otel/sdk/metric v1.38 .0 // indirect
457+ go.opentelemetry.io/otel/trace v1.38 .0 // indirect
458+ go.opentelemetry.io/proto/otlp v1.7.1 // indirect
457459 go.uber.org/automaxprocs v1.6.0 // indirect
458460 go.uber.org/mock v0.5.2 // indirect
459461 go.uber.org/multierr v1.11.0 // indirect
@@ -464,22 +466,22 @@ require (
464466 golang.org/x/oauth2 v0.30.0 // indirect
465467 golang.org/x/sys v0.36.0 // indirect
466468 golang.org/x/telemetry v0.0.0-20250807160809-1a19826ec488 // indirect
467- golang.org/x/time v0.12 .0 // indirect
469+ golang.org/x/time v0.13 .0 // indirect
468470 golang.org/x/tools v0.36.0 // indirect
469471 golang.org/x/tools/go/packages/packagestest v0.1.1-deprecated // indirect
470472 golang.org/x/tools/gopls v0.19.1 // indirect
471473 google.golang.org/api v0.248.0 // indirect
472474 google.golang.org/genproto v0.0.0-20250603155806-513f23925822 // indirect
473- google.golang.org/genproto/googleapis/api v0.0.0-20250721164621-a45f3dfb1074 // indirect
474- google.golang.org/genproto/googleapis/rpc v0.0.0-20250818200422-3122310a409c // indirect
475- google.golang.org/grpc v1.75.0 // indirect
475+ google.golang.org/genproto/googleapis/api v0.0.0-20250825161204-c5933d9347a5 // indirect
476+ google.golang.org/genproto/googleapis/rpc v0.0.0-20250825161204-c5933d9347a5 // indirect
477+ google.golang.org/grpc v1.75.1 // indirect
476478 gopkg.in/cheggaaa/pb.v1 v1.0.28 // indirect
477479 gopkg.in/evanphx/json-patch.v4 v4.12.0 // indirect
478480 gopkg.in/inf.v0 v0.9.1 // indirect
479481 gopkg.in/warnings.v0 v0.1.2 // indirect
480482 gopkg.in/yaml.v2 v2.4.0 // indirect
481483 k8s.io/apiextensions-apiserver v0.34.0 // indirect
482- k8s.io/apimachinery v0.34.0 // indirect
484+ k8s.io/apimachinery v0.34.1 // indirect
483485 k8s.io/apiserver v0.34.0 // indirect
484486 k8s.io/cli-runtime v0.34.0 // indirect
485487 k8s.io/client-go v0.34.0 // indirect
0 commit comments