@@ -5,7 +5,7 @@ go 1.24.6
55require (
66 cuelang.org/go v0.13.2
77 github.com/CycloneDX/cyclonedx-go v0.9.2
8- github.com/MakeNowJust/heredoc v1 .0.0
8+ github.com/MakeNowJust/heredoc/v2 v2 .0.1
99 github.com/Maldris/go-billy-afero v0.0.0-20200815120323-e9d3de59c99a
1010 github.com/conforma/crds/api v0.1.7
1111 github.com/conforma/go-gather v1.0.2
@@ -29,11 +29,11 @@ require (
2929 github.com/open-policy-agent/opa v1.6.0
3030 github.com/package-url/packageurl-go v0.1.3
3131 github.com/qri-io/jsonpointer v0.1.1
32- github.com/santhosh-tekuri/jsonschema/v5 v5.3.1
32+ github.com/santhosh-tekuri/jsonschema/v6 v6.0.2
3333 github.com/secure-systems-lab/go-securesystemslib v0.9.0
3434 github.com/sigstore/cosign/v2 v2.4.1
3535 github.com/sigstore/rekor v1.3.6
36- github.com/sigstore/sigstore v1.8.9
36+ github.com/sigstore/sigstore v1.9.5
3737 github.com/sirupsen/logrus v1.9.3
3838 github.com/smarty/cproxy/v2 v2.1.1
3939 github.com/spdx/tools-golang v0.5.5
@@ -43,13 +43,13 @@ require (
4343 github.com/spf13/viper v1.20.1
4444 github.com/stretchr/testify v1.11.1
4545 github.com/stuart-warren/yamlfmt v0.2.0
46- github.com/tektoncd/pipeline v0.66 .0
46+ github.com/tektoncd/pipeline v1.7 .0
4747 github.com/testcontainers/testcontainers-go v0.34.1-0.20241204123437-72be13940122 // using unreleased version that contains the fix in https://github.com/testcontainers/testcontainers-go/pull/2899
4848 github.com/testcontainers/testcontainers-go/modules/registry v0.34.0
4949 golang.org/x/benchmarks v0.0.0-20241115175113-a2b48b605b42
5050 golang.org/x/exp v0.0.0-20250408133849-7e4ce0ab07d0
51- golang.org/x/net v0.44 .0
52- golang.org/x/sync v0.17 .0
51+ golang.org/x/net v0.47 .0
52+ golang.org/x/sync v0.18 .0
5353 k8s.io/apiextensions-apiserver v0.34.2
5454 k8s.io/apimachinery v0.34.2
5555 k8s.io/client-go v0.34.2
@@ -63,22 +63,24 @@ require (
6363replace github.com/google/go-containerregistry => github.com/conforma/go-containerregistry v0.20.7-0.20250703195040-6f40a3734728
6464
6565require (
66+ github.com/MakeNowJust/heredoc v1.0.0
6667 github.com/go-openapi/runtime v0.28.0
6768 github.com/pmezard/go-difflib v1.0.1-0.20181226105442-5d4384ee4fb2
68- golang.org/x/text v0.29.0
69+ github.com/santhosh-tekuri/jsonschema/v5 v5.3.1
70+ golang.org/x/text v0.31.0
6971 gopkg.in/yaml.v3 v3.0.1
7072 k8s.io/api v0.34.2
7173)
7274
7375require (
7476 cel.dev/expr v0.24.0 // indirect
75- cloud.google.com/go v0.116 .0 // indirect
76- cloud.google.com/go/auth v0.13.0 // indirect
77- cloud.google.com/go/auth/oauth2adapt v0.2.6 // indirect
77+ cloud.google.com/go v0.120 .0 // indirect
78+ cloud.google.com/go/auth v0.16.1 // indirect
79+ cloud.google.com/go/auth/oauth2adapt v0.2.8 // indirect
7880 cloud.google.com/go/compute/metadata v0.7.0 // indirect
79- cloud.google.com/go/iam v1.2.2 // indirect
80- cloud.google.com/go/monitoring v1.21.2 // indirect
81- cloud.google.com/go/storage v1.49 .0 // indirect
81+ cloud.google.com/go/iam v1.5.0 // indirect
82+ cloud.google.com/go/monitoring v1.24.0 // indirect
83+ cloud.google.com/go/storage v1.50 .0 // indirect
8284 contrib.go.opencensus.io/exporter/ocagent v0.7.1-0.20200907061046-05415f1de66d // indirect
8385 contrib.go.opencensus.io/exporter/prometheus v0.4.2 // indirect
8486 dario.cat/mergo v1.0.2 // indirect
@@ -96,8 +98,8 @@ require (
9698 github.com/Azure/go-autorest/tracing v0.6.0 // indirect
9799 github.com/BurntSushi/toml v1.5.0 // indirect
98100 github.com/GoogleCloudPlatform/opentelemetry-operations-go/detectors/gcp v1.29.0 // indirect
99- github.com/GoogleCloudPlatform/opentelemetry-operations-go/exporter/metric v0.48.1 // indirect
100- github.com/GoogleCloudPlatform/opentelemetry-operations-go/internal/resourcemapping v0.48.1 // indirect
101+ github.com/GoogleCloudPlatform/opentelemetry-operations-go/exporter/metric v0.50.0 // indirect
102+ github.com/GoogleCloudPlatform/opentelemetry-operations-go/internal/resourcemapping v0.50.0 // indirect
101103 github.com/KeisukeYamashita/go-vcl v0.4.0 // indirect
102104 github.com/Microsoft/go-winio v0.6.2 // indirect
103105 github.com/ProtonMail/go-crypto v1.1.5 // indirect
@@ -166,7 +168,7 @@ require (
166168 github.com/containerd/platforms v1.0.0-rc.2 // indirect
167169 github.com/containerd/stargz-snapshotter/estargz v0.16.3 // indirect
168170 github.com/containerd/typeurl/v2 v2.2.3 // indirect
169- github.com/coreos/go-oidc/v3 v3.11.0 // indirect
171+ github.com/coreos/go-oidc/v3 v3.14.1 // indirect
170172 github.com/cpuguy83/dockercfg v0.3.2 // indirect
171173 github.com/cpuguy83/go-md2man/v2 v2.0.7 // indirect
172174 github.com/cyberphone/json-canonicalization v0.0.0-20231217050601-ba74d44ecf5f // indirect
@@ -188,7 +190,7 @@ require (
188190 github.com/emirpasic/gods v1.18.1 // indirect
189191 github.com/envoyproxy/go-control-plane/envoy v1.32.4 // indirect
190192 github.com/envoyproxy/protoc-gen-validate v1.2.1 // indirect
191- github.com/evanphx/json-patch/v5 v5.9.0 // indirect
193+ github.com/evanphx/json-patch/v5 v5.9.11 // indirect
192194 github.com/felixge/httpsnoop v1.0.4 // indirect
193195 github.com/fsnotify/fsnotify v1.9.0 // indirect
194196 github.com/fxamacker/cbor/v2 v2.9.0 // indirect
@@ -227,11 +229,11 @@ require (
227229 github.com/google/go-github/v55 v55.0.0 // indirect
228230 github.com/google/go-jsonnet v0.21.0 // indirect
229231 github.com/google/go-querystring v1.1.0 // indirect
230- github.com/google/s2a-go v0.1.8 // indirect
232+ github.com/google/s2a-go v0.1.9 // indirect
231233 github.com/google/uuid v1.6.0 // indirect
232- github.com/googleapis/enterprise-certificate-proxy v0.3.4 // indirect
234+ github.com/googleapis/enterprise-certificate-proxy v0.3.6 // indirect
233235 github.com/googleapis/gax-go/v2 v2.14.1 // indirect
234- github.com/grpc-ecosystem/grpc-gateway/v2 v2.26.3 // indirect
236+ github.com/grpc-ecosystem/grpc-gateway/v2 v2.27.1 // indirect
235237 github.com/hashicorp/aws-sdk-go-base/v2 v2.0.0-beta.65 // indirect
236238 github.com/hashicorp/errwrap v1.1.0 // indirect
237239 github.com/hashicorp/go-cleanhttp v0.5.2 // indirect
@@ -257,7 +259,7 @@ require (
257259 github.com/logrusorgru/aurora v2.0.3+incompatible // indirect
258260 github.com/lufia/plan9stats v0.0.0-20211012122336-39d0f177ccd0 // indirect
259261 github.com/magiconair/properties v1.8.10 // indirect
260- github.com/mailru/easyjson v0.7.7 // indirect
262+ github.com/mailru/easyjson v0.9.0 // indirect
261263 github.com/maruel/natural v1.1.1 // indirect
262264 github.com/mattn/go-runewidth v0.0.16 // indirect
263265 github.com/miekg/pkcs11 v1.1.1 // indirect
@@ -309,13 +311,13 @@ require (
309311 github.com/shoenig/go-m1cpu v0.1.6 // indirect
310312 github.com/shteou/go-ignore v0.3.1 // indirect
311313 github.com/sigstore/fulcio v1.6.3 // indirect
312- github.com/sigstore/protobuf-specs v0.3.2 // indirect
314+ github.com/sigstore/protobuf-specs v0.4.1 // indirect
313315 github.com/sigstore/timestamp-authority v1.2.2 // indirect
314316 github.com/skeema/knownhosts v1.3.0 // indirect
315317 github.com/skratchdot/open-golang v0.0.0-20200116055534-eef842397966 // indirect
316318 github.com/sourcegraph/conc v0.3.0 // indirect
317319 github.com/spf13/cast v1.7.1 // indirect
318- github.com/spiffe/go-spiffe/v2 v2.5 .0 // indirect
320+ github.com/spiffe/go-spiffe/v2 v2.6 .0 // indirect
319321 github.com/stoewer/go-strcase v1.3.0 // indirect
320322 github.com/stretchr/objx v0.5.2 // indirect
321323 github.com/subosito/gotenv v1.6.0 // indirect
@@ -353,30 +355,30 @@ require (
353355 go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc v0.60.0 // indirect
354356 go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.61.0 // indirect
355357 go.opentelemetry.io/otel v1.37.0 // indirect
356- go.opentelemetry.io/otel/exporters/otlp/otlptrace v1.36 .0 // indirect
358+ go.opentelemetry.io/otel/exporters/otlp/otlptrace v1.37 .0 // indirect
357359 go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc v1.36.0 // indirect
358- go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp v1.36 .0 // indirect
360+ go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp v1.37 .0 // indirect
359361 go.opentelemetry.io/otel/metric v1.37.0 // indirect
360362 go.opentelemetry.io/otel/sdk v1.37.0 // indirect
361363 go.opentelemetry.io/otel/sdk/metric v1.37.0 // indirect
362364 go.opentelemetry.io/otel/trace v1.37.0 // indirect
363- go.opentelemetry.io/proto/otlp v1.6 .0 // indirect
365+ go.opentelemetry.io/proto/otlp v1.7 .0 // indirect
364366 go.step.sm/crypto v0.51.2 // indirect
365367 go.uber.org/automaxprocs v1.6.0 // indirect
366368 go.uber.org/multierr v1.11.0 // indirect
367369 go.uber.org/zap v1.27.0 // indirect
368370 go.yaml.in/yaml/v2 v2.4.2 // indirect
369371 go.yaml.in/yaml/v3 v3.0.4 // indirect
370- golang.org/x/crypto v0.42 .0 // indirect
372+ golang.org/x/crypto v0.45 .0 // indirect
371373 golang.org/x/mod v0.29.0 // indirect
372374 golang.org/x/oauth2 v0.30.0 // indirect
373- golang.org/x/sys v0.37 .0 // indirect
374- golang.org/x/term v0.35 .0 // indirect
375+ golang.org/x/sys v0.38 .0 // indirect
376+ golang.org/x/term v0.37 .0 // indirect
375377 golang.org/x/time v0.14.0 // indirect
376- golang.org/x/tools v0.37 .0 // indirect
377- gomodules.xyz/jsonpatch/v2 v2.4 .0 // indirect
378- google.golang.org/api v0.215 .0 // indirect
379- google.golang.org/genproto v0.0.0-20241118233622-e639e219e697 // indirect
378+ golang.org/x/tools v0.38 .0 // indirect
379+ gomodules.xyz/jsonpatch/v2 v2.5 .0 // indirect
380+ google.golang.org/api v0.233 .0 // indirect
381+ google.golang.org/genproto v0.0.0-20250303144028-a0af3efb3deb // indirect
380382 google.golang.org/genproto/googleapis/api v0.0.0-20250804133106-a7a43d27e69b // indirect
381383 google.golang.org/genproto/googleapis/rpc v0.0.0-20250804133106-a7a43d27e69b // indirect
382384 google.golang.org/grpc v1.76.0 // indirect
@@ -387,7 +389,7 @@ require (
387389 gopkg.in/warnings.v0 v0.1.2 // indirect
388390 gopkg.in/yaml.v2 v2.4.0 // indirect
389391 k8s.io/utils v0.0.0-20250604170112-4c0f3b243397 // indirect
390- knative.dev/pkg v0.0.0-20240815051656-89743d9bbf7c // indirect
392+ knative.dev/pkg v0.0.0-20250415155312-ed3e2158b883 // indirect
391393 olympos.io/encoding/edn v0.0.0-20201019073823-d3554ca0b0a3 // indirect
392394 sigs.k8s.io/controller-runtime v0.19.0 // indirect
393395 sigs.k8s.io/json v0.0.0-20241014173422-cfa47c3a1cc8 // indirect
0 commit comments