@@ -3,14 +3,14 @@ module github.com/ossf/scorecard/v5
3
3
go 1.22.10
4
4
5
5
require (
6
- cloud.google.com/go/bigquery v1.66.0
7
- cloud.google.com/go/monitoring v1.21.2 // indirect
8
- cloud.google.com/go/pubsub v1.45.3
9
- cloud.google.com/go/trace v1.11.2 // indirect
6
+ cloud.google.com/go/bigquery v1.66.2
7
+ cloud.google.com/go/monitoring v1.23.0 // indirect
8
+ cloud.google.com/go/pubsub v1.47.0
9
+ cloud.google.com/go/trace v1.11.3 // indirect
10
10
contrib.go.opencensus.io/exporter/stackdriver v0.13.14
11
11
github.com/bombsimon/logrusr/v2 v2.0.1
12
12
github.com/bradleyfalzon/ghinstallation/v2 v2.13.0
13
- github.com/go-git/go-git/v5 v5.13.1
13
+ github.com/go-git/go-git/v5 v5.13.2
14
14
github.com/go-logr/logr v1.4.2
15
15
github.com/golang/mock v1.6.0
16
16
github.com/google/go-cmp v0.6.0
@@ -29,10 +29,10 @@ require (
29
29
github.com/xeipuuv/gojsonschema v1.2.0
30
30
go.opencensus.io v0.24.0
31
31
gocloud.dev v0.40.0
32
- golang.org/x/text v0.21 .0
33
- golang.org/x/tools v0.28 .0 // indirect
34
- google.golang.org/genproto v0.0.0-20241118233622-e639e219e697 // indirect
35
- google.golang.org/protobuf v1.36.3
32
+ golang.org/x/text v0.22 .0
33
+ golang.org/x/tools v0.29 .0 // indirect
34
+ google.golang.org/genproto v0.0.0-20250122153221-138b5a5a4fd4 // indirect
35
+ google.golang.org/protobuf v1.36.4
36
36
gopkg.in/yaml.v2 v2.4.0
37
37
gopkg.in/yaml.v3 v3.0.1
38
38
mvdan.cc/sh/v3 v3.10.0
@@ -46,17 +46,17 @@ require (
46
46
github.com/mcuadros/go-jsonschema-generator v0.0.0-20200330054847-ba7a369d4303
47
47
github.com/onsi/ginkgo/v2 v2.22.2
48
48
github.com/otiai10/copy v1.14.1
49
- gitlab.com/gitlab-org/api/client-go v0.120 .0
49
+ gitlab.com/gitlab-org/api/client-go v0.122 .0
50
50
sigs.k8s.io/release-utils v0.8.4
51
51
)
52
52
53
53
require (
54
- cel.dev/expr v0.16 .2 // indirect
54
+ cel.dev/expr v0.19 .2 // indirect
55
55
cloud.google.com/go/auth v0.14.0 // indirect
56
56
cloud.google.com/go/auth/oauth2adapt v0.2.7 // indirect
57
57
cloud.google.com/go/compute/metadata v0.6.0 // indirect
58
- cloud.google.com/go/containeranalysis v0.13.2 // indirect
59
- cloud.google.com/go/kms v1.20.1 // indirect
58
+ cloud.google.com/go/containeranalysis v0.13.3 // indirect
59
+ cloud.google.com/go/kms v1.20.5 // indirect
60
60
cloud.google.com/go/longrunning v0.6.4 // indirect
61
61
dario.cat/mergo v1.0.0 // indirect
62
62
deps.dev/api/v3 v3.0.0-20241010035105-b3ba03369df1 // indirect
@@ -66,21 +66,21 @@ require (
66
66
github.com/BurntSushi/toml v1.4.0 // indirect
67
67
github.com/CycloneDX/cyclonedx-go v0.9.1 // indirect
68
68
github.com/GoogleCloudPlatform/opentelemetry-operations-go/detectors/gcp v1.25.0 // indirect
69
- github.com/GoogleCloudPlatform/opentelemetry-operations-go/exporter/metric v0.48.1 // indirect
70
- github.com/GoogleCloudPlatform/opentelemetry-operations-go/internal/resourcemapping v0.48.1 // indirect
69
+ github.com/GoogleCloudPlatform/opentelemetry-operations-go/exporter/metric v0.49.0 // indirect
70
+ github.com/GoogleCloudPlatform/opentelemetry-operations-go/internal/resourcemapping v0.49.0 // indirect
71
71
github.com/anchore/go-struct-converter v0.0.0-20230627203149-c72ef8859ca9 // indirect
72
72
github.com/apache/arrow/go/v15 v15.0.2 // indirect
73
73
github.com/bmatcuk/doublestar/v4 v4.8.0 // indirect
74
74
github.com/cespare/xxhash/v2 v2.3.0 // indirect
75
75
github.com/cloudflare/circl v1.3.7 // indirect
76
- github.com/cncf/xds/go v0.0.0-20240905190251-b4127c9b8d78 // indirect
76
+ github.com/cncf/xds/go v0.0.0-20250121191232-2f005788dc42 // indirect
77
77
github.com/containerd/typeurl/v2 v2.2.3 // indirect
78
78
github.com/cyphar/filepath-securejoin v0.3.6 // indirect
79
79
github.com/davecgh/go-spew v1.1.2-0.20180830191138-d8f796af33cc // indirect
80
80
github.com/dghubble/trie v0.1.0 // indirect
81
81
github.com/emicklei/go-restful/v3 v3.11.0 // indirect
82
- github.com/envoyproxy/go-control-plane/envoy v1.32.3 // indirect
83
- github.com/envoyproxy/protoc-gen-validate v1.1.0 // indirect
82
+ github.com/envoyproxy/go-control-plane/envoy v1.32.4 // indirect
83
+ github.com/envoyproxy/protoc-gen-validate v1.2.1 // indirect
84
84
github.com/felixge/httpsnoop v1.0.4 // indirect
85
85
github.com/go-logr/stdr v1.2.2 // indirect
86
86
github.com/go-openapi/jsonpointer v0.20.2 // indirect
@@ -112,7 +112,7 @@ require (
112
112
github.com/package-url/packageurl-go v0.1.3 // indirect
113
113
github.com/pandatix/go-cvss v0.6.2 // indirect
114
114
github.com/pierrec/lz4/v4 v4.1.21 // indirect
115
- github.com/pjbgf/sha1cd v0.3.0 // indirect
115
+ github.com/pjbgf/sha1cd v0.3.2 // indirect
116
116
github.com/planetscale/vtprotobuf v0.6.1-0.20240319094008-0393e58bdf10 // indirect
117
117
github.com/prometheus/prometheus v0.54.0 // indirect
118
118
github.com/robfig/cron/v3 v3.0.1 // indirect
@@ -123,20 +123,21 @@ require (
123
123
github.com/tidwall/match v1.1.1 // indirect
124
124
github.com/tidwall/pretty v1.2.1 // indirect
125
125
github.com/zeebo/xxh3 v1.0.2 // indirect
126
- go.opentelemetry.io/contrib/detectors/gcp v1.31.0 // indirect
127
- go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc v0.56.0 // indirect
128
- go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.56.0 // indirect
129
- go.opentelemetry.io/otel v1.31.0 // indirect
130
- go.opentelemetry.io/otel/metric v1.31.0 // indirect
131
- go.opentelemetry.io/otel/sdk v1.31.0 // indirect
132
- go.opentelemetry.io/otel/sdk/metric v1.31.0 // indirect
133
- go.opentelemetry.io/otel/trace v1.31.0 // indirect
126
+ go.opentelemetry.io/auto/sdk v1.1.0 // indirect
127
+ go.opentelemetry.io/contrib/detectors/gcp v1.33.0 // indirect
128
+ go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc v0.58.0 // indirect
129
+ go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.58.0 // indirect
130
+ go.opentelemetry.io/otel v1.34.0 // indirect
131
+ go.opentelemetry.io/otel/metric v1.34.0 // indirect
132
+ go.opentelemetry.io/otel/sdk v1.34.0 // indirect
133
+ go.opentelemetry.io/otel/sdk/metric v1.32.0 // indirect
134
+ go.opentelemetry.io/otel/trace v1.34.0 // indirect
134
135
golang.org/x/mod v0.22.0 // indirect
135
136
golang.org/x/term v0.28.0 // indirect
136
137
golang.org/x/time v0.9.0 // indirect
137
138
golang.org/x/vuln v1.0.4 // indirect
138
- google.golang.org/genproto/googleapis/api v0.0.0-20250115164207-1a7da9e5054f // indirect
139
- google.golang.org/genproto/googleapis/rpc v0.0.0-20250115164207-1a7da9e5054f // indirect
139
+ google.golang.org/genproto/googleapis/api v0.0.0-20250127172529-29210b9bc287 // indirect
140
+ google.golang.org/genproto/googleapis/rpc v0.0.0-20250127172529-29210b9bc287 // indirect
140
141
gopkg.in/inf.v0 v0.9.1 // indirect
141
142
gopkg.in/ini.v1 v1.67.0 // indirect
142
143
k8s.io/api v0.29.3 // indirect
@@ -151,11 +152,11 @@ require (
151
152
)
152
153
153
154
require (
154
- cloud.google.com/go v0.118.0 // indirect
155
+ cloud.google.com/go v0.118.1 // indirect
155
156
cloud.google.com/go/iam v1.3.1 // indirect
156
157
cloud.google.com/go/storage v1.50.0 // indirect
157
158
github.com/Microsoft/go-winio v0.6.2 // indirect
158
- github.com/ProtonMail/go-crypto v1.1.3 // indirect
159
+ github.com/ProtonMail/go-crypto v1.1.5 // indirect
159
160
github.com/aws/aws-sdk-go v1.55.5 // indirect
160
161
github.com/census-instrumentation/opencensus-proto v0.4.1 // indirect
161
162
github.com/common-nighthawk/go-figure v0.0.0-20210622060536-734e95fb86be // indirect
@@ -200,11 +201,11 @@ require (
200
201
golang.org/x/crypto v0.32.0 // indirect
201
202
golang.org/x/exp v0.0.0-20241108190413-2d47ceb2692f // indirect
202
203
golang.org/x/net v0.34.0 // indirect
203
- golang.org/x/oauth2 v0.25 .0
204
- golang.org/x/sync v0.10 .0 // indirect
205
- golang.org/x/sys v0.29 .0 // indirect
204
+ golang.org/x/oauth2 v0.26 .0
205
+ golang.org/x/sync v0.11 .0 // indirect
206
+ golang.org/x/sys v0.30 .0 // indirect
206
207
golang.org/x/xerrors v0.0.0-20240903120638-7835f813f4da // indirect
207
- google.golang.org/api v0.217 .0 // indirect
208
- google.golang.org/grpc v1.69.4 // indirect
208
+ google.golang.org/api v0.218 .0 // indirect
209
+ google.golang.org/grpc v1.70.0 // indirect
209
210
gopkg.in/warnings.v0 v0.1.2 // indirect
210
211
)
0 commit comments