Skip to content

Commit ba5066e

Browse files
authored
Merge pull request #3940 from cpanato/update-cosign
Update cosign image and deps
2 parents dbcd0d0 + 60b1c46 commit ba5066e

File tree

4 files changed

+228
-238
lines changed

4 files changed

+228
-238
lines changed

dependencies.yaml

+1-1
Original file line numberDiff line numberDiff line change
@@ -15,7 +15,7 @@ dependencies:
1515

1616
# cosign
1717
- name: "ghcr.io/sigstore/cosign/cosign"
18-
version: v2.4.2-dev@sha256:b69af124cb744c22eba955ebaf9514b42b1556811211e1cd744331350ccd815a
18+
version: v2.4.3-dev@sha256:ed76c008e733aa64d257f754a02eb07b251525ea8dc08f40974baec317dea8c9
1919
refPaths:
2020
- path: images/build/go-runner/cloudbuild.yaml
2121
match: ghcr.io/sigstore/cosign/cosign:v(0|[1-9]\d*)\.(0|[1-9]\d*)\.(0|[1-9]\d*)(?:-((?:0|[1-9]\d*|\d*[a-zA-Z-][0-9a-zA-Z-]*)(?:\.(?:0|[1-9]\d*|\d*[a-zA-Z-][0-9a-zA-Z-]*))*))?(?:\+([0-9a-zA-Z-]+(?:\.[0-9a-zA-Z-]+)*))?-dev@sha256:[a-f0-9]{64}

go.mod

+60-63
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
module k8s.io/release
22

3-
go 1.23.3
3+
go 1.23.4
44

55
require (
66
cloud.google.com/go/storage v1.45.0
@@ -17,7 +17,7 @@ require (
1717
github.com/in-toto/in-toto-golang v0.9.0
1818
github.com/mattn/go-isatty v0.0.20
1919
github.com/maxbrunsfeld/counterfeiter/v6 v6.11.2
20-
github.com/mitchellh/mapstructure v1.5.0
20+
github.com/mitchellh/mapstructure v1.5.1-0.20231216201459-8508981c8b6c
2121
github.com/nozzle/throttler v0.0.0-20180817012639-2ea982251481
2222
github.com/olekukonko/tablewriter v0.0.5
2323
github.com/psampaz/go-mod-outdated v0.9.0
@@ -35,7 +35,7 @@ require (
3535
golang.org/x/net v0.35.0
3636
golang.org/x/oauth2 v0.27.0
3737
golang.org/x/text v0.22.0
38-
google.golang.org/api v0.218.0
38+
google.golang.org/api v0.221.0
3939
gopkg.in/yaml.v2 v2.4.0
4040
k8s.io/apimachinery v0.32.2
4141
k8s.io/utils v0.0.0-20241104100929-3ea5e8cea738
@@ -50,15 +50,14 @@ require (
5050
require (
5151
cel.dev/expr v0.19.0 // indirect
5252
cloud.google.com/go v0.116.0 // indirect
53-
cloud.google.com/go/auth v0.14.0 // indirect
53+
cloud.google.com/go/auth v0.14.1 // indirect
5454
cloud.google.com/go/auth/oauth2adapt v0.2.7 // indirect
5555
cloud.google.com/go/compute/metadata v0.6.0 // indirect
5656
cloud.google.com/go/iam v1.2.2 // indirect
5757
cloud.google.com/go/monitoring v1.21.2 // indirect
58-
cuelabs.dev/go/oci/ociregistry v0.0.0-20240404174027-a39bec0462d2 // indirect
59-
cuelang.org/go v0.9.2 // indirect
58+
cuelabs.dev/go/oci/ociregistry v0.0.0-20241125120445-2c00c104c6e1 // indirect
59+
cuelang.org/go v0.12.0 // indirect
6060
dario.cat/mergo v1.0.1 // indirect
61-
filippo.io/edwards25519 v1.1.0 // indirect
6261
github.com/AliyunContainerService/ack-ram-tool/pkg/credentials/provider v0.14.0 // indirect
6362
github.com/Azure/azure-sdk-for-go v68.0.0+incompatible // indirect
6463
github.com/Azure/go-ansiterm v0.0.0-20250102033503-faa5f7b0171c // indirect
@@ -80,7 +79,7 @@ require (
8079
github.com/ProtonMail/go-crypto v1.1.5 // indirect
8180
github.com/ThalesIgnite/crypto11 v1.2.5 // indirect
8281
github.com/VividCortex/ewma v1.2.0 // indirect
83-
github.com/agnivade/levenshtein v1.1.1 // indirect
82+
github.com/agnivade/levenshtein v1.2.0 // indirect
8483
github.com/alibabacloud-go/alibabacloud-gateway-spi v0.0.4 // indirect
8584
github.com/alibabacloud-go/cr-20160607 v1.0.1 // indirect
8685
github.com/alibabacloud-go/cr-20181201 v1.0.10 // indirect
@@ -94,28 +93,28 @@ require (
9493
github.com/aliyun/credentials-go v1.3.2 // indirect
9594
github.com/asaskevich/govalidator v0.0.0-20230301143203-a9d515a09cc2 // indirect
9695
github.com/avast/retry-go/v4 v4.6.0 // indirect
97-
github.com/aws/aws-sdk-go-v2 v1.32.8 // indirect
98-
github.com/aws/aws-sdk-go-v2/config v1.28.10 // indirect
99-
github.com/aws/aws-sdk-go-v2/credentials v1.17.51 // indirect
100-
github.com/aws/aws-sdk-go-v2/feature/ec2/imds v1.16.23 // indirect
101-
github.com/aws/aws-sdk-go-v2/internal/configsources v1.3.27 // indirect
102-
github.com/aws/aws-sdk-go-v2/internal/endpoints/v2 v2.6.27 // indirect
103-
github.com/aws/aws-sdk-go-v2/internal/ini v1.8.1 // indirect
104-
github.com/aws/aws-sdk-go-v2/service/ecr v1.20.2 // indirect
105-
github.com/aws/aws-sdk-go-v2/service/ecrpublic v1.18.2 // indirect
106-
github.com/aws/aws-sdk-go-v2/service/internal/accept-encoding v1.12.1 // indirect
107-
github.com/aws/aws-sdk-go-v2/service/internal/presigned-url v1.12.8 // indirect
108-
github.com/aws/aws-sdk-go-v2/service/sso v1.24.9 // indirect
109-
github.com/aws/aws-sdk-go-v2/service/ssooidc v1.28.8 // indirect
110-
github.com/aws/aws-sdk-go-v2/service/sts v1.33.6 // indirect
111-
github.com/aws/smithy-go v1.22.1 // indirect
112-
github.com/awslabs/amazon-ecr-credential-helper/ecr-login v0.0.0-20231024185945-8841054dbdb8 // indirect
96+
github.com/aws/aws-sdk-go-v2 v1.36.1 // indirect
97+
github.com/aws/aws-sdk-go-v2/config v1.29.6 // indirect
98+
github.com/aws/aws-sdk-go-v2/credentials v1.17.59 // indirect
99+
github.com/aws/aws-sdk-go-v2/feature/ec2/imds v1.16.28 // indirect
100+
github.com/aws/aws-sdk-go-v2/internal/configsources v1.3.32 // indirect
101+
github.com/aws/aws-sdk-go-v2/internal/endpoints/v2 v2.6.32 // indirect
102+
github.com/aws/aws-sdk-go-v2/internal/ini v1.8.2 // indirect
103+
github.com/aws/aws-sdk-go-v2/service/ecr v1.40.3 // indirect
104+
github.com/aws/aws-sdk-go-v2/service/ecrpublic v1.31.2 // indirect
105+
github.com/aws/aws-sdk-go-v2/service/internal/accept-encoding v1.12.2 // indirect
106+
github.com/aws/aws-sdk-go-v2/service/internal/presigned-url v1.12.13 // indirect
107+
github.com/aws/aws-sdk-go-v2/service/sso v1.24.15 // indirect
108+
github.com/aws/aws-sdk-go-v2/service/ssooidc v1.28.14 // indirect
109+
github.com/aws/aws-sdk-go-v2/service/sts v1.33.14 // indirect
110+
github.com/aws/smithy-go v1.22.2 // indirect
111+
github.com/awslabs/amazon-ecr-credential-helper/ecr-login v0.9.1 // indirect
113112
github.com/beorn7/perks v1.0.1 // indirect
114113
github.com/blang/semver v3.5.1+incompatible // indirect
115-
github.com/buildkite/agent/v3 v3.81.0 // indirect
116-
github.com/buildkite/go-pipeline v0.13.1 // indirect
117-
github.com/buildkite/interpolate v0.1.3 // indirect
118-
github.com/buildkite/roko v1.2.0 // indirect
114+
github.com/buildkite/agent/v3 v3.92.1 // indirect
115+
github.com/buildkite/go-pipeline v0.13.3 // indirect
116+
github.com/buildkite/interpolate v0.1.5 // indirect
117+
github.com/buildkite/roko v1.3.1 // indirect
119118
github.com/census-instrumentation/opencensus-proto v0.4.1 // indirect
120119
github.com/cespare/xxhash/v2 v2.3.0 // indirect
121120
github.com/chrismellard/docker-credential-acr-env v0.0.0-20230304212654-82a0ddb27589 // indirect
@@ -137,13 +136,13 @@ require (
137136
github.com/docker/docker-credential-helpers v0.8.2 // indirect
138137
github.com/dustin/go-humanize v1.0.1 // indirect
139138
github.com/emicklei/go-restful/v3 v3.11.0 // indirect
140-
github.com/emicklei/proto v1.12.1 // indirect
139+
github.com/emicklei/proto v1.13.4 // indirect
141140
github.com/emirpasic/gods v1.18.1 // indirect
142141
github.com/envoyproxy/go-control-plane v0.13.1 // indirect
143142
github.com/envoyproxy/protoc-gen-validate v1.1.0 // indirect
144143
github.com/fatih/color v1.18.0 // indirect
145144
github.com/felixge/httpsnoop v1.0.4 // indirect
146-
github.com/fsnotify/fsnotify v1.7.0 // indirect
145+
github.com/fsnotify/fsnotify v1.8.0 // indirect
147146
github.com/fvbommel/sortorder v1.0.1 // indirect
148147
github.com/fxamacker/cbor/v2 v2.7.0 // indirect
149148
github.com/glebarez/go-sqlite v1.22.0 // indirect
@@ -166,15 +165,15 @@ require (
166165
github.com/go-openapi/strfmt v0.23.0 // indirect
167166
github.com/go-openapi/swag v0.23.0 // indirect
168167
github.com/go-openapi/validate v0.24.0 // indirect
169-
github.com/go-piv/piv-go v1.11.0 // indirect
168+
github.com/go-piv/piv-go/v2 v2.3.0 // indirect
170169
github.com/goark/errs v1.3.2 // indirect
171170
github.com/gobwas/glob v0.2.3 // indirect
172171
github.com/gogo/protobuf v1.3.2 // indirect
173172
github.com/golang-jwt/jwt/v4 v4.5.1 // indirect
174173
github.com/golang/groupcache v0.0.0-20210331224755-41bb18bfe9da // indirect
175174
github.com/golang/snappy v0.0.4 // indirect
176175
github.com/gomarkdown/markdown v0.0.0-20240328165702-4d01890c35c0 // indirect
177-
github.com/google/certificate-transparency-go v1.2.1 // indirect
176+
github.com/google/certificate-transparency-go v1.3.1 // indirect
178177
github.com/google/gnostic-models v0.6.9-0.20230804172637-c7be7c783f49 // indirect
179178
github.com/google/go-cmp v0.6.0 // indirect
180179
github.com/google/go-github/v55 v55.0.0 // indirect
@@ -196,14 +195,13 @@ require (
196195
github.com/jbenet/go-context v0.0.0-20150711004518-d14ea06fba99 // indirect
197196
github.com/jedisct1/go-minisign v0.0.0-20230811132847-661be99b8267 // indirect
198197
github.com/jellydator/ttlcache/v3 v3.3.0 // indirect
199-
github.com/jmespath/go-jmespath v0.4.1-0.20220621161143-b0104c826a24 // indirect
200198
github.com/josharian/intern v1.0.0 // indirect
201199
github.com/json-iterator/go v1.1.12 // indirect
202200
github.com/kevinburke/ssh_config v1.2.0 // indirect
203201
github.com/klauspost/compress v1.17.11 // indirect
204202
github.com/knqyf263/go-rpmdb v0.0.0-20230723082926-067d98befa60 // indirect
205203
github.com/letsencrypt/boulder v0.0.0-20240620165639-de9c06129bec // indirect
206-
github.com/magiconair/properties v1.8.7 // indirect
204+
github.com/magiconair/properties v1.8.9 // indirect
207205
github.com/mailru/easyjson v0.7.7 // indirect
208206
github.com/mattn/go-colorable v0.1.14 // indirect
209207
github.com/mattn/go-runewidth v0.0.16 // indirect
@@ -218,97 +216,96 @@ require (
218216
github.com/munnerz/goautoneg v0.0.0-20191010083416-a7dc8b61c822 // indirect
219217
github.com/oklog/ulid v1.3.1 // indirect
220218
github.com/oleiade/reflections v1.1.0 // indirect
221-
github.com/open-policy-agent/opa v0.68.0 // indirect
219+
github.com/open-policy-agent/opa v1.1.0 // indirect
222220
github.com/opencontainers/go-digest v1.0.0 // indirect
223221
github.com/opencontainers/image-spec v1.1.0 // indirect
224222
github.com/opentracing/opentracing-go v1.2.0 // indirect
225223
github.com/package-url/packageurl-go v0.1.2 // indirect
226224
github.com/pborman/uuid v1.2.1 // indirect
227-
github.com/pelletier/go-toml/v2 v2.2.2 // indirect
225+
github.com/pelletier/go-toml/v2 v2.2.3 // indirect
228226
github.com/pjbgf/sha1cd v0.3.2 // indirect
229227
github.com/pkg/errors v0.9.1 // indirect
230228
github.com/planetscale/vtprotobuf v0.6.1-0.20240319094008-0393e58bdf10 // indirect
231229
github.com/pmezard/go-difflib v1.0.1-0.20181226105442-5d4384ee4fb2 // indirect
232-
github.com/power-devops/perfstat v0.0.0-20210106213030-5aafc221ea8c // indirect
230+
github.com/power-devops/perfstat v0.0.0-20220216144756-c35f1ee13d7c // indirect
233231
github.com/prometheus/client_golang v1.20.5 // indirect
234232
github.com/prometheus/client_model v0.6.1 // indirect
235-
github.com/prometheus/common v0.55.0 // indirect
233+
github.com/prometheus/common v0.62.0 // indirect
236234
github.com/prometheus/procfs v0.15.1 // indirect
237-
github.com/protocolbuffers/txtpbfmt v0.0.0-20231025115547-084445ff1adf // indirect
235+
github.com/protocolbuffers/txtpbfmt v0.0.0-20241112170944-20d2c9ebc01d // indirect
238236
github.com/rcrowley/go-metrics v0.0.0-20201227073835-cf1acfcdf475 // indirect
239237
github.com/remyoudompheng/bigfft v0.0.0-20230129092748-24d4a6f8daec // indirect
240238
github.com/rivo/uniseg v0.4.4 // indirect
241-
github.com/rogpeppe/go-internal v1.13.1 // indirect
239+
github.com/rogpeppe/go-internal v1.13.2-0.20241226121412-a5dc8ff20d0a // indirect
242240
github.com/sagikazarmark/locafero v0.4.0 // indirect
243241
github.com/sagikazarmark/slog-shim v0.1.0 // indirect
244242
github.com/sassoftware/relic v7.2.1+incompatible // indirect
245243
github.com/secure-systems-lab/go-securesystemslib v0.9.0 // indirect
246244
github.com/segmentio/ksuid v1.0.4 // indirect
247245
github.com/shibumi/go-pathspec v1.3.0 // indirect
248246
github.com/shurcooL/graphql v0.0.0-20230722043721-ed46e5a46466 // indirect
249-
github.com/sigstore/cosign/v2 v2.4.1 // indirect
250-
github.com/sigstore/fulcio v1.6.3 // indirect
251-
github.com/sigstore/protobuf-specs v0.3.3 // indirect
247+
github.com/sigstore/cosign/v2 v2.4.3 // indirect
248+
github.com/sigstore/fulcio v1.6.6 // indirect
249+
github.com/sigstore/protobuf-specs v0.4.0 // indirect
252250
github.com/sigstore/rekor v1.3.9 // indirect
253-
github.com/sigstore/sigstore v1.8.12 // indirect
254-
github.com/sigstore/sigstore-go v0.6.1 // indirect
255-
github.com/sigstore/timestamp-authority v1.2.2 // indirect
251+
github.com/sigstore/sigstore v1.8.15 // indirect
252+
github.com/sigstore/sigstore-go v0.7.0 // indirect
253+
github.com/sigstore/timestamp-authority v1.2.4 // indirect
256254
github.com/skeema/knownhosts v1.3.0 // indirect
257255
github.com/skratchdot/open-golang v0.0.0-20200116055534-eef842397966 // indirect
258256
github.com/sourcegraph/conc v0.3.0 // indirect
259257
github.com/spf13/afero v1.11.0 // indirect
260258
github.com/spf13/cast v1.7.0 // indirect
261259
github.com/spf13/pflag v1.0.6 // indirect
262260
github.com/spf13/viper v1.19.0 // indirect
263-
github.com/spiffe/go-spiffe/v2 v2.3.0 // indirect
261+
github.com/spiffe/go-spiffe/v2 v2.5.0 // indirect
264262
github.com/subosito/gotenv v1.6.0 // indirect
265263
github.com/syndtr/goleveldb v1.0.1-0.20220721030215-126854af5e6d // indirect
266-
github.com/tchap/go-patricia/v2 v2.3.1 // indirect
264+
github.com/tchap/go-patricia/v2 v2.3.2 // indirect
267265
github.com/thales-e-security/pool v0.0.2 // indirect
268266
github.com/theupdateframework/go-tuf v0.7.0 // indirect
269-
github.com/theupdateframework/go-tuf/v2 v2.0.1 // indirect
267+
github.com/theupdateframework/go-tuf/v2 v2.0.2 // indirect
270268
github.com/titanous/rocacheck v0.0.0-20171023193734-afe73141d399 // indirect
271269
github.com/tjfoc/gmsm v1.4.1 // indirect
272270
github.com/transparency-dev/merkle v0.0.2 // indirect
273271
github.com/vbatts/tar-split v0.11.6 // indirect
274272
github.com/x448/float16 v0.8.4 // indirect
275-
github.com/xanzy/go-gitlab v0.109.0 // indirect
276273
github.com/xanzy/ssh-agent v0.3.3 // indirect
277274
github.com/xeipuuv/gojsonpointer v0.0.0-20190905194746-02993c407bfb // indirect
278275
github.com/xeipuuv/gojsonreference v0.0.0-20180127040603-bd5ef7bd5415 // indirect
279276
github.com/yashtewari/glob-intersection v0.2.0 // indirect
280277
github.com/yusufpapurcu/wmi v1.2.4 // indirect
281-
github.com/zeebo/errs v1.3.0 // indirect
278+
github.com/zeebo/errs v1.4.0 // indirect
282279
gitlab.alpinelinux.org/alpine/go v0.8.0 // indirect
280+
gitlab.com/gitlab-org/api/client-go v0.123.0 // indirect
283281
go.mongodb.org/mongo-driver v1.14.0 // indirect
284282
go.opencensus.io v0.24.0 // indirect
285283
go.opentelemetry.io/auto/sdk v1.1.0 // indirect
286284
go.opentelemetry.io/contrib/detectors/gcp v1.32.0 // indirect
287-
go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc v0.54.0 // indirect
288-
go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.58.0 // indirect
289-
go.opentelemetry.io/otel v1.33.0 // indirect
290-
go.opentelemetry.io/otel/metric v1.33.0 // indirect
291-
go.opentelemetry.io/otel/sdk v1.33.0 // indirect
285+
go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc v0.58.0 // indirect
286+
go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.59.0 // indirect
287+
go.opentelemetry.io/otel v1.34.0 // indirect
288+
go.opentelemetry.io/otel/metric v1.34.0 // indirect
289+
go.opentelemetry.io/otel/sdk v1.34.0 // indirect
292290
go.opentelemetry.io/otel/sdk/metric v1.32.0 // indirect
293-
go.opentelemetry.io/otel/trace v1.33.0 // indirect
294-
go.step.sm/crypto v0.57.0 // indirect
291+
go.opentelemetry.io/otel/trace v1.34.0 // indirect
295292
go.uber.org/multierr v1.11.0 // indirect
296293
go.uber.org/zap v1.27.0 // indirect
297294
golang.org/x/crypto v0.33.0 // indirect
298-
golang.org/x/exp v0.0.0-20240719175910-8a7402abbf56 // indirect
295+
golang.org/x/exp v0.0.0-20241108190413-2d47ceb2692f // indirect
299296
golang.org/x/mod v0.22.0 // indirect
300297
golang.org/x/sync v0.11.0 // indirect
301298
golang.org/x/sys v0.30.0 // indirect
302299
golang.org/x/term v0.29.0 // indirect
303-
golang.org/x/time v0.9.0 // indirect
300+
golang.org/x/time v0.10.0 // indirect
304301
golang.org/x/tools v0.29.0 // indirect
305302
golang.org/x/tools/go/vcs v0.1.0-deprecated // indirect
306303
golang.org/x/xerrors v0.0.0-20240716161551-93cc26a95ae9 // indirect
307304
google.golang.org/genproto v0.0.0-20241118233622-e639e219e697 // indirect
308-
google.golang.org/genproto/googleapis/api v0.0.0-20241209162323-e6fa225c2576 // indirect
309-
google.golang.org/genproto/googleapis/rpc v0.0.0-20250115164207-1a7da9e5054f // indirect
305+
google.golang.org/genproto/googleapis/api v0.0.0-20250115164207-1a7da9e5054f // indirect
306+
google.golang.org/genproto/googleapis/rpc v0.0.0-20250207221924-e9438ea467c6 // indirect
310307
google.golang.org/grpc v1.70.0 // indirect
311-
google.golang.org/protobuf v1.36.4 // indirect
308+
google.golang.org/protobuf v1.36.5 // indirect
312309
gopkg.in/inf.v0 v0.9.1 // indirect
313310
gopkg.in/ini.v1 v1.67.0 // indirect
314311
gopkg.in/warnings.v0 v0.1.2 // indirect

0 commit comments

Comments
 (0)