11module github.com/sigstore/policy-controller
22
3- go 1.23.2
3+ go 1.23.4
44
55require (
66 github.com/aws/aws-sdk-go v1.55.6
7- github.com/aws/aws-sdk-go-v2 v1.36.1 // indirect
7+ github.com/aws/aws-sdk-go-v2 v1.36.3 // indirect
88 github.com/golang/protobuf v1.5.4 // indirect
99 github.com/golang/snappy v0.0.4 // indirect
1010 github.com/google/go-cmp v0.7.0
@@ -24,11 +24,11 @@ require (
2424 github.com/kelseyhightower/envconfig v1.4.0
2525 github.com/letsencrypt/boulder v0.0.0-20240620165639-de9c06129bec
2626 github.com/mitchellh/go-homedir v1.1.0
27- github.com/mitchellh/mapstructure v1.5.0
27+ github.com/mitchellh/mapstructure v1.5.1-0.20231216201459-8508981c8b6c
2828 github.com/ryanuber/go-glob v1.0.0
29- github.com/sigstore/cosign/v2 v2.4.1
30- github.com/sigstore/rekor v1.3.7
31- github.com/sigstore/sigstore v1.9.2
29+ github.com/sigstore/cosign/v2 v2.5.0
30+ github.com/sigstore/rekor v1.3.9
31+ github.com/sigstore/sigstore v1.9.3
3232 github.com/stretchr/testify v1.10.0
3333 github.com/theupdateframework/go-tuf v0.7.0
3434 github.com/titanous/rocacheck v0.0.0-20171023193734-afe73141d399
@@ -37,13 +37,13 @@ require (
3737 golang.org/x/net v0.38.0
3838 golang.org/x/sys v0.32.0 // indirect
3939 golang.org/x/time v0.11.0
40- google.golang.org/grpc v1.69.2 // indirect
40+ google.golang.org/grpc v1.71.0 // indirect
4141 google.golang.org/protobuf v1.36.6
4242 gopkg.in/yaml.v3 v3.0.1
4343 k8s.io/api v0.32.3
4444 k8s.io/apimachinery v0.32.3
4545 k8s.io/client-go v0.32.3
46- k8s.io/code-generator v0.32.0
46+ k8s.io/code-generator v0.32.2
4747 k8s.io/kube-openapi v0.0.0-20241105132330-32ad38e42d3f
4848 knative.dev/hack v0.0.0-20240111013919-e89096d74d85
4949 sigs.k8s.io/release-utils v0.11.1
@@ -63,31 +63,31 @@ require (
6363 github.com/docker/go-connections v0.5.0
6464 github.com/go-jose/go-jose/v4 v4.0.5
6565 github.com/sigstore/protobuf-specs v0.4.1
66- github.com/sigstore/scaffolding v0.7.18
67- github.com/sigstore/sigstore/pkg/signature/kms/aws v1.8.12
68- github.com/sigstore/sigstore/pkg/signature/kms/azure v1.8.12
69- github.com/sigstore/sigstore/pkg/signature/kms/gcp v1.8.12
70- github.com/sigstore/sigstore/pkg/signature/kms/hashivault v1.8.12
66+ github.com/sigstore/scaffolding v0.7.22
67+ github.com/sigstore/sigstore/pkg/signature/kms/aws v1.9.1
68+ github.com/sigstore/sigstore/pkg/signature/kms/azure v1.9.1
69+ github.com/sigstore/sigstore/pkg/signature/kms/gcp v1.9.1
70+ github.com/sigstore/sigstore/pkg/signature/kms/hashivault v1.9.1
7171 github.com/spf13/viper v1.20.1
7272 knative.dev/hack/schema v0.0.0-20240607132042-09143140a254
7373 knative.dev/pkg v0.0.0-20230612155445-74c4be5e935e
7474)
7575
7676require (
77- cloud.google.com/go v0.116.0 // indirect
78- cloud.google.com/go/auth v0.13 .0 // indirect
79- cloud.google.com/go/auth/oauth2adapt v0.2.6 // indirect
77+ cloud.google.com/go v0.118.3 // indirect
78+ cloud.google.com/go/auth v0.15 .0 // indirect
79+ cloud.google.com/go/auth/oauth2adapt v0.2.7 // indirect
8080 cloud.google.com/go/compute/metadata v0.6.0 // indirect
81- cloud.google.com/go/iam v1.2.2 // indirect
82- cloud.google.com/go/kms v1.20.4 // indirect
83- cloud.google.com/go/longrunning v0.6.2 // indirect
81+ cloud.google.com/go/iam v1.4.1 // indirect
82+ cloud.google.com/go/kms v1.21.1 // indirect
83+ cloud.google.com/go/longrunning v0.6.5 // indirect
8484 contrib.go.opencensus.io/exporter/ocagent v0.7.1-0.20200907061046-05415f1de66d // indirect
8585 contrib.go.opencensus.io/exporter/prometheus v0.4.2 // indirect
86- cuelang.org/go v0.9.2 // indirect
86+ cuelang.org/go v0.12.1 // indirect
8787 github.com/AliyunContainerService/ack-ram-tool/pkg/credentials/provider v0.14.0 // indirect
8888 github.com/Azure/azure-sdk-for-go/sdk/internal v1.11.0 // indirect
89- github.com/Azure/azure-sdk-for-go/sdk/security/keyvault/azkeys v1.3.0 // indirect
90- github.com/Azure/azure-sdk-for-go/sdk/security/keyvault/internal v1.1.0 // indirect
89+ github.com/Azure/azure-sdk-for-go/sdk/security/keyvault/azkeys v1.3.1 // indirect
90+ github.com/Azure/azure-sdk-for-go/sdk/security/keyvault/internal v1.1.1 // indirect
9191 github.com/Azure/go-autorest v14.2.0+incompatible // indirect
9292 github.com/Azure/go-autorest/autorest v0.11.29 // indirect
9393 github.com/Azure/go-autorest/autorest/adal v0.9.23 // indirect
@@ -101,7 +101,7 @@ require (
101101 github.com/OneOfOne/xxhash v1.2.8 // indirect
102102 github.com/ProtonMail/go-crypto v0.0.0-20230923063757-afb1ddc0824c // indirect
103103 github.com/ThalesIgnite/crypto11 v1.2.5 // indirect
104- github.com/agnivade/levenshtein v1.1.1 // indirect
104+ github.com/agnivade/levenshtein v1.2.0 // indirect
105105 github.com/alibabacloud-go/alibabacloud-gateway-spi v0.0.4 // indirect
106106 github.com/alibabacloud-go/cr-20160607 v1.0.1 // indirect
107107 github.com/alibabacloud-go/cr-20181201 v1.0.10 // indirect
@@ -114,20 +114,20 @@ require (
114114 github.com/alibabacloud-go/tea-xml v1.1.3 // indirect
115115 github.com/aliyun/credentials-go v1.3.2 // indirect
116116 github.com/asaskevich/govalidator v0.0.0-20230301143203-a9d515a09cc2 // indirect
117- github.com/aws/aws-sdk-go-v2/config v1.29.6 // indirect
118- github.com/aws/aws-sdk-go-v2/credentials v1.17.59 // indirect
119- github.com/aws/aws-sdk-go-v2/feature/ec2/imds v1.16.28 // indirect
120- github.com/aws/aws-sdk-go-v2/internal/configsources v1.3.32 // indirect
121- github.com/aws/aws-sdk-go-v2/internal/endpoints/v2 v2.6.32 // indirect
122- github.com/aws/aws-sdk-go-v2/internal/ini v1.8.2 // indirect
117+ github.com/aws/aws-sdk-go-v2/config v1.29.10 // indirect
118+ github.com/aws/aws-sdk-go-v2/credentials v1.17.63 // indirect
119+ github.com/aws/aws-sdk-go-v2/feature/ec2/imds v1.16.30 // indirect
120+ github.com/aws/aws-sdk-go-v2/internal/configsources v1.3.34 // indirect
121+ github.com/aws/aws-sdk-go-v2/internal/endpoints/v2 v2.6.34 // indirect
122+ github.com/aws/aws-sdk-go-v2/internal/ini v1.8.3 // indirect
123123 github.com/aws/aws-sdk-go-v2/service/ecr v1.40.3 // indirect
124124 github.com/aws/aws-sdk-go-v2/service/ecrpublic v1.31.2 // indirect
125- github.com/aws/aws-sdk-go-v2/service/internal/accept-encoding v1.12.2 // indirect
126- github.com/aws/aws-sdk-go-v2/service/internal/presigned-url v1.12.13 // indirect
127- github.com/aws/aws-sdk-go-v2/service/kms v1.37.8 // indirect
128- github.com/aws/aws-sdk-go-v2/service/sso v1.24.15 // indirect
129- github.com/aws/aws-sdk-go-v2/service/ssooidc v1.28.14 // indirect
130- github.com/aws/aws-sdk-go-v2/service/sts v1.33.14 // indirect
125+ github.com/aws/aws-sdk-go-v2/service/internal/accept-encoding v1.12.3 // indirect
126+ github.com/aws/aws-sdk-go-v2/service/internal/presigned-url v1.12.15 // indirect
127+ github.com/aws/aws-sdk-go-v2/service/kms v1.38.1 // indirect
128+ github.com/aws/aws-sdk-go-v2/service/sso v1.25.1 // indirect
129+ github.com/aws/aws-sdk-go-v2/service/ssooidc v1.29.2 // indirect
130+ github.com/aws/aws-sdk-go-v2/service/sts v1.33.17 // indirect
131131 github.com/aws/smithy-go v1.22.2 // indirect
132132 github.com/beorn7/perks v1.0.1 // indirect
133133 github.com/blang/semver v3.5.1+incompatible // indirect
@@ -159,20 +159,19 @@ require (
159159 github.com/fxamacker/cbor/v2 v2.7.0 // indirect
160160 github.com/go-chi/chi v4.1.2+incompatible // indirect
161161 github.com/go-ini/ini v1.67.0 // indirect
162- github.com/go-jose/go-jose/v3 v3.0.4 // indirect
163162 github.com/go-kit/log v0.2.1 // indirect
164163 github.com/go-logfmt/logfmt v0.5.1 // indirect
165164 github.com/go-logr/logr v1.4.2 // indirect
166165 github.com/go-logr/stdr v1.2.2 // indirect
167166 github.com/go-openapi/analysis v0.23.0 // indirect
168- github.com/go-openapi/errors v0.22.0 // indirect
167+ github.com/go-openapi/errors v0.22.1 // indirect
169168 github.com/go-openapi/jsonpointer v0.21.0 // indirect
170169 github.com/go-openapi/jsonreference v0.21.0 // indirect
171170 github.com/go-openapi/loads v0.22.0 // indirect
172171 github.com/go-openapi/runtime v0.28.0 // indirect
173172 github.com/go-openapi/spec v0.21.0 // indirect
174173 github.com/go-openapi/strfmt v0.23.0 // indirect
175- github.com/go-openapi/swag v0.23.0 // indirect
174+ github.com/go-openapi/swag v0.23.1 // indirect
176175 github.com/go-openapi/validate v0.24.0 // indirect
177176 github.com/go-viper/mapstructure/v2 v2.2.1 // indirect
178177 github.com/gobuffalo/flect v1.0.2 // indirect
@@ -181,18 +180,19 @@ require (
181180 github.com/golang-jwt/jwt/v4 v4.5.2 // indirect
182181 github.com/golang-jwt/jwt/v5 v5.2.2 // indirect
183182 github.com/golang/groupcache v0.0.0-20210331224755-41bb18bfe9da // indirect
184- github.com/google/certificate-transparency-go v1.3.0 // indirect
183+ github.com/google/certificate-transparency-go v1.3.1 // indirect
185184 github.com/google/gnostic-models v0.6.9-0.20230804172637-c7be7c783f49 // indirect
186185 github.com/google/go-github/v55 v55.0.0 // indirect
187186 github.com/google/go-querystring v1.1.0 // indirect
188187 github.com/google/gofuzz v1.2.0 // indirect
189- github.com/google/s2a-go v0.1.8 // indirect
188+ github.com/google/s2a-go v0.1.9 // indirect
190189 github.com/google/uuid v1.6.0 // indirect
191- github.com/googleapis/enterprise-certificate-proxy v0.3.4 // indirect
190+ github.com/googleapis/enterprise-certificate-proxy v0.3.6 // indirect
192191 github.com/googleapis/gax-go/v2 v2.14.1 // indirect
193192 github.com/gorilla/mux v1.8.1 // indirect
194- github.com/grpc-ecosystem/grpc-gateway/v2 v2.24.0 // indirect
195- github.com/hashicorp/vault/api v1.15.0 // indirect
193+ github.com/grpc-ecosystem/grpc-gateway/v2 v2.25.1 // indirect
194+ github.com/hashicorp/vault/api v1.16.0 // indirect
195+ github.com/in-toto/attestation v1.1.1 // indirect
196196 github.com/in-toto/in-toto-golang v0.9.0 // indirect
197197 github.com/inconshreveable/mousetrap v1.1.0 // indirect
198198 github.com/jedisct1/go-minisign v0.0.0-20230811132847-661be99b8267 // indirect
@@ -201,7 +201,7 @@ require (
201201 github.com/json-iterator/go v1.1.12 // indirect
202202 github.com/klauspost/compress v1.17.11 // indirect
203203 github.com/kylelemons/godebug v1.1.0 // indirect
204- github.com/mailru/easyjson v0.7.7 // indirect
204+ github.com/mailru/easyjson v0.9.0 // indirect
205205 github.com/miekg/pkcs11 v1.1.1 // indirect
206206 github.com/moby/docker-image-spec v1.3.1 // indirect
207207 github.com/modern-go/concurrent v0.0.0-20180306012644-bacd9c7ef1dd // indirect
@@ -210,69 +210,68 @@ require (
210210 github.com/munnerz/goautoneg v0.0.0-20191010083416-a7dc8b61c822 // indirect
211211 github.com/nozzle/throttler v0.0.0-20180817012639-2ea982251481 // indirect
212212 github.com/oklog/ulid v1.3.1 // indirect
213- github.com/open-policy-agent/opa v0.68 .0 // indirect
213+ github.com/open-policy-agent/opa v1.1 .0 // indirect
214214 github.com/opencontainers/go-digest v1.0.0 // indirect
215215 github.com/opencontainers/image-spec v1.1.0 // indirect
216216 github.com/opentracing/opentracing-go v1.2.0 // indirect
217217 github.com/pelletier/go-toml/v2 v2.2.3 // indirect
218218 github.com/pkg/browser v0.0.0-20240102092130-5ac0b6a4141c // indirect
219219 github.com/pkg/errors v0.9.1 // indirect
220220 github.com/pmezard/go-difflib v1.0.1-0.20181226105442-5d4384ee4fb2 // indirect
221- github.com/prometheus/client_golang v1.20.5 // indirect
221+ github.com/prometheus/client_golang v1.21.1 // indirect
222222 github.com/prometheus/client_model v0.6.1 // indirect
223- github.com/prometheus/common v0.60 .0 // indirect
223+ github.com/prometheus/common v0.62 .0 // indirect
224224 github.com/prometheus/procfs v0.15.1 // indirect
225225 github.com/prometheus/statsd_exporter v0.22.8 // indirect
226226 github.com/rcrowley/go-metrics v0.0.0-20201227073835-cf1acfcdf475 // indirect
227227 github.com/sagikazarmark/locafero v0.7.0 // indirect
228228 github.com/sassoftware/relic v7.2.1+incompatible // indirect
229229 github.com/secure-systems-lab/go-securesystemslib v0.9.0 // indirect
230230 github.com/shibumi/go-pathspec v1.3.0 // indirect
231- github.com/sigstore/sigstore-go v0.6.2 // indirect
232- github.com/sigstore/timestamp-authority v1.2.3 // indirect
231+ github.com/sigstore/sigstore-go v0.7.1 // indirect
232+ github.com/sigstore/timestamp-authority v1.2.5 // indirect
233233 github.com/sirupsen/logrus v1.9.3 // indirect
234234 github.com/sourcegraph/conc v0.3.0 // indirect
235235 github.com/spf13/afero v1.12.0 // indirect
236236 github.com/spf13/cast v1.7.1 // indirect
237237 github.com/spf13/pflag v1.0.6 // indirect
238238 github.com/subosito/gotenv v1.6.0 // indirect
239239 github.com/syndtr/goleveldb v1.0.1-0.20220721030215-126854af5e6d // indirect
240- github.com/tchap/go-patricia/v2 v2.3.1 // indirect
240+ github.com/tchap/go-patricia/v2 v2.3.2 // indirect
241241 github.com/thales-e-security/pool v0.0.2 // indirect
242- github.com/theupdateframework/go-tuf/v2 v2.0.1 // indirect
242+ github.com/theupdateframework/go-tuf/v2 v2.0.2 // indirect
243243 github.com/tjfoc/gmsm v1.4.1 // indirect
244244 github.com/transparency-dev/merkle v0.0.2 // indirect
245245 github.com/vbatts/tar-split v0.11.6 // indirect
246246 github.com/x448/float16 v0.8.4 // indirect
247- github.com/xanzy/go-gitlab v0.109.0 // indirect
248247 github.com/xeipuuv/gojsonpointer v0.0.0-20190905194746-02993c407bfb // indirect
249248 github.com/xeipuuv/gojsonreference v0.0.0-20180127040603-bd5ef7bd5415 // indirect
250249 github.com/yashtewari/glob-intersection v0.2.0 // indirect
250+ gitlab.com/gitlab-org/api/client-go v0.127.0 // indirect
251251 go.mongodb.org/mongo-driver v1.14.0 // indirect
252252 go.opencensus.io v0.24.0 // indirect
253253 go.opentelemetry.io/auto/sdk v1.1.0 // indirect
254- go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc v0.55.0 // indirect
255- go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.58.0 // indirect
256- go.opentelemetry.io/otel v1.33.0 // indirect
257- go.opentelemetry.io/otel/exporters/otlp/otlptrace v1.33.0 // indirect
258- go.opentelemetry.io/otel/metric v1.33.0 // indirect
259- go.opentelemetry.io/otel/sdk v1.33.0 // indirect
260- go.opentelemetry.io/otel/trace v1.33.0 // indirect
254+ go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc v0.59.0 // indirect
255+ go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.59.0 // indirect
256+ go.opentelemetry.io/otel v1.35.0 // indirect
257+ go.opentelemetry.io/otel/metric v1.35.0 // indirect
258+ go.opentelemetry.io/otel/sdk v1.35.0 // indirect
259+ go.opentelemetry.io/otel/trace v1.35.0 // indirect
261260 go.uber.org/atomic v1.9.0 // indirect
262- go.uber.org/automaxprocs v1.5.3 // indirect
261+ go.uber.org/automaxprocs v1.6.0 // indirect
263262 go.uber.org/multierr v1.11.0 // indirect
264- golang.org/x/exp v0.0.0-20240909161429-701f63a606c0 // indirect
265- golang.org/x/mod v0.23 .0 // indirect
266- golang.org/x/oauth2 v0.28 .0 // indirect
263+ golang.org/x/exp v0.0.0-20241108190413-2d47ceb2692f // indirect
264+ golang.org/x/mod v0.24 .0 // indirect
265+ golang.org/x/oauth2 v0.29 .0 // indirect
267266 golang.org/x/sync v0.13.0 // indirect
268267 golang.org/x/term v0.31.0 // indirect
269268 golang.org/x/text v0.24.0 // indirect
270269 golang.org/x/tools v0.30.0 // indirect
271270 gomodules.xyz/jsonpatch/v2 v2.4.0 // indirect
272- google.golang.org/api v0.215 .0 // indirect
273- google.golang.org/genproto v0.0.0-20241118233622-e639e219e697 // indirect
274- google.golang.org/genproto/googleapis/api v0.0.0-20241209162323-e6fa225c2576 // indirect
275- google.golang.org/genproto/googleapis/rpc v0.0.0-20241223144023-3abc09e42ca8 // indirect
271+ google.golang.org/api v0.227 .0 // indirect
272+ google.golang.org/genproto v0.0.0-20250303144028-a0af3efb3deb // indirect
273+ google.golang.org/genproto/googleapis/api v0.0.0-20250303144028-a0af3efb3deb // indirect
274+ google.golang.org/genproto/googleapis/rpc v0.0.0-20250313205543-e70fdf4c4cb4 // indirect
276275 gopkg.in/evanphx/json-patch.v4 v4.12.0 // indirect
277276 gopkg.in/inf.v0 v0.9.1 // indirect
278277 gopkg.in/ini.v1 v1.67.0 // indirect
0 commit comments