@@ -5,7 +5,7 @@ go 1.24.6
55require (
66 cuelang.org/go v0.13.2
77 github.com/CycloneDX/cyclonedx-go v0.9.2
8- github.com/MakeNowJust/heredoc v1 .0.0
8+ github.com/MakeNowJust/heredoc/v2 v2 .0.1
99 github.com/Maldris/go-billy-afero v0.0.0-20200815120323-e9d3de59c99a
1010 github.com/conforma/crds/api v0.1.7
1111 github.com/conforma/go-gather v1.0.2
@@ -29,11 +29,11 @@ require (
2929 github.com/open-policy-agent/opa v1.6.0
3030 github.com/package-url/packageurl-go v0.1.3
3131 github.com/qri-io/jsonpointer v0.1.1
32- github.com/santhosh-tekuri/jsonschema/v5 v5.3.1
32+ github.com/santhosh-tekuri/jsonschema/v6 v6.0.2
3333 github.com/secure-systems-lab/go-securesystemslib v0.9.0
3434 github.com/sigstore/cosign/v2 v2.4.1
3535 github.com/sigstore/rekor v1.3.6
36- github.com/sigstore/sigstore v1.8.9
36+ github.com/sigstore/sigstore v1.9.5
3737 github.com/sirupsen/logrus v1.9.3
3838 github.com/smarty/cproxy/v2 v2.1.1
3939 github.com/spdx/tools-golang v0.5.5
@@ -43,13 +43,13 @@ require (
4343 github.com/spf13/viper v1.20.1
4444 github.com/stretchr/testify v1.11.1
4545 github.com/stuart-warren/yamlfmt v0.2.0
46- github.com/tektoncd/pipeline v0.66 .0
46+ github.com/tektoncd/pipeline v1.9 .0
4747 github.com/testcontainers/testcontainers-go v0.34.1-0.20241204123437-72be13940122 // using unreleased version that contains the fix in https://github.com/testcontainers/testcontainers-go/pull/2899
4848 github.com/testcontainers/testcontainers-go/modules/registry v0.34.0
4949 golang.org/x/benchmarks v0.0.0-20241115175113-a2b48b605b42
5050 golang.org/x/exp v0.0.0-20250408133849-7e4ce0ab07d0
51- golang.org/x/net v0.44 .0
52- golang.org/x/sync v0.17 .0
51+ golang.org/x/net v0.47 .0
52+ golang.org/x/sync v0.19 .0
5353 k8s.io/apiextensions-apiserver v0.34.2
5454 k8s.io/apimachinery v0.34.2
5555 k8s.io/client-go v0.34.2
@@ -63,23 +63,25 @@ require (
6363replace github.com/google/go-containerregistry => github.com/conforma/go-containerregistry v0.20.7-0.20250703195040-6f40a3734728
6464
6565require (
66+ github.com/MakeNowJust/heredoc v1.0.0
6667 github.com/cucumber/godog v0.15.1
6768 github.com/go-openapi/runtime v0.28.0
6869 github.com/pmezard/go-difflib v1.0.1-0.20181226105442-5d4384ee4fb2
69- golang.org/x/text v0.29.0
70+ github.com/santhosh-tekuri/jsonschema/v5 v5.3.1
71+ golang.org/x/text v0.31.0
7072 gopkg.in/yaml.v3 v3.0.1
7173 k8s.io/api v0.34.2
7274)
7375
7476require (
75- cel.dev/expr v0.24.0 // indirect
76- cloud.google.com/go v0.116 .0 // indirect
77- cloud.google.com/go/auth v0.13.0 // indirect
78- cloud.google.com/go/auth/oauth2adapt v0.2.6 // indirect
79- cloud.google.com/go/compute/metadata v0.7 .0 // indirect
80- cloud.google.com/go/iam v1.2.2 // indirect
81- cloud.google.com/go/monitoring v1.21.2 // indirect
82- cloud.google.com/go/storage v1.49 .0 // indirect
77+ cel.dev/expr v0.25.1 // indirect
78+ cloud.google.com/go v0.120 .0 // indirect
79+ cloud.google.com/go/auth v0.16.1 // indirect
80+ cloud.google.com/go/auth/oauth2adapt v0.2.8 // indirect
81+ cloud.google.com/go/compute/metadata v0.9 .0 // indirect
82+ cloud.google.com/go/iam v1.5.0 // indirect
83+ cloud.google.com/go/monitoring v1.24.0 // indirect
84+ cloud.google.com/go/storage v1.50 .0 // indirect
8385 contrib.go.opencensus.io/exporter/ocagent v0.7.1-0.20200907061046-05415f1de66d // indirect
8486 contrib.go.opencensus.io/exporter/prometheus v0.4.2 // indirect
8587 dario.cat/mergo v1.0.2 // indirect
@@ -96,9 +98,9 @@ require (
9698 github.com/Azure/go-autorest/logger v0.2.1 // indirect
9799 github.com/Azure/go-autorest/tracing v0.6.0 // indirect
98100 github.com/BurntSushi/toml v1.5.0 // indirect
99- github.com/GoogleCloudPlatform/opentelemetry-operations-go/detectors/gcp v1.29 .0 // indirect
100- github.com/GoogleCloudPlatform/opentelemetry-operations-go/exporter/metric v0.48.1 // indirect
101- github.com/GoogleCloudPlatform/opentelemetry-operations-go/internal/resourcemapping v0.48.1 // indirect
101+ github.com/GoogleCloudPlatform/opentelemetry-operations-go/detectors/gcp v1.30 .0 // indirect
102+ github.com/GoogleCloudPlatform/opentelemetry-operations-go/exporter/metric v0.50.0 // indirect
103+ github.com/GoogleCloudPlatform/opentelemetry-operations-go/internal/resourcemapping v0.50.0 // indirect
102104 github.com/KeisukeYamashita/go-vcl v0.4.0 // indirect
103105 github.com/Microsoft/go-winio v0.6.2 // indirect
104106 github.com/ProtonMail/go-crypto v1.1.5 // indirect
@@ -157,7 +159,7 @@ require (
157159 github.com/chrismellard/docker-credential-acr-env v0.0.0-20230304212654-82a0ddb27589 // indirect
158160 github.com/clbanning/mxj/v2 v2.7.0 // indirect
159161 github.com/cloudflare/circl v1.4.0 // indirect
160- github.com/cncf/xds/go v0.0.0-20250501225837-2ac532fd4443 // indirect
162+ github.com/cncf/xds/go v0.0.0-20251022180443-0feb69152e9f // indirect
161163 github.com/cockroachdb/apd/v3 v3.2.1 // indirect
162164 github.com/common-nighthawk/go-figure v0.0.0-20210622060536-734e95fb86be // indirect
163165 github.com/containerd/containerd/v2 v2.2.0 // indirect
@@ -167,7 +169,7 @@ require (
167169 github.com/containerd/platforms v1.0.0-rc.2 // indirect
168170 github.com/containerd/stargz-snapshotter/estargz v0.16.3 // indirect
169171 github.com/containerd/typeurl/v2 v2.2.3 // indirect
170- github.com/coreos/go-oidc/v3 v3.11.0 // indirect
172+ github.com/coreos/go-oidc/v3 v3.14.1 // indirect
171173 github.com/cpuguy83/dockercfg v0.3.2 // indirect
172174 github.com/cpuguy83/go-md2man/v2 v2.0.7 // indirect
173175 github.com/cucumber/gherkin/go/v26 v26.2.0 // indirect
@@ -189,9 +191,9 @@ require (
189191 github.com/dustin/go-humanize v1.0.1 // indirect
190192 github.com/emicklei/go-restful/v3 v3.13.0 // indirect
191193 github.com/emirpasic/gods v1.18.1 // indirect
192- github.com/envoyproxy/go-control-plane/envoy v1.32.4 // indirect
194+ github.com/envoyproxy/go-control-plane/envoy v1.35.0 // indirect
193195 github.com/envoyproxy/protoc-gen-validate v1.2.1 // indirect
194- github.com/evanphx/json-patch/v5 v5.9.0 // indirect
196+ github.com/evanphx/json-patch/v5 v5.9.11 // indirect
195197 github.com/felixge/httpsnoop v1.0.4 // indirect
196198 github.com/fsnotify/fsnotify v1.9.0 // indirect
197199 github.com/fxamacker/cbor/v2 v2.9.0 // indirect
@@ -203,7 +205,7 @@ require (
203205 github.com/go-git/go-billy/v5 v5.6.2 // indirect
204206 github.com/go-ini/ini v1.67.0 // indirect
205207 github.com/go-jose/go-jose/v3 v3.0.4 // indirect
206- github.com/go-jose/go-jose/v4 v4.1.2 // indirect
208+ github.com/go-jose/go-jose/v4 v4.1.3 // indirect
207209 github.com/go-kit/log v0.2.1 // indirect
208210 github.com/go-logfmt/logfmt v0.6.0 // indirect
209211 github.com/go-logr/stdr v1.2.2 // indirect
@@ -224,18 +226,18 @@ require (
224226 github.com/golang/groupcache v0.0.0-20241129210726-2c02b8208cf8 // indirect
225227 github.com/golang/protobuf v1.5.4 // indirect
226228 github.com/golang/snappy v0.0.4 // indirect
227- github.com/google/cel-go v0.26 .0 // indirect
229+ github.com/google/cel-go v0.27 .0 // indirect
228230 github.com/google/certificate-transparency-go v1.2.1 // indirect
229231 github.com/google/flatbuffers v25.2.10+incompatible // indirect
230232 github.com/google/gnostic-models v0.7.0 // indirect
231233 github.com/google/go-github/v55 v55.0.0 // indirect
232234 github.com/google/go-jsonnet v0.21.0 // indirect
233235 github.com/google/go-querystring v1.1.0 // indirect
234- github.com/google/s2a-go v0.1.8 // indirect
236+ github.com/google/s2a-go v0.1.9 // indirect
235237 github.com/google/uuid v1.6.0 // indirect
236- github.com/googleapis/enterprise-certificate-proxy v0.3.4 // indirect
238+ github.com/googleapis/enterprise-certificate-proxy v0.3.6 // indirect
237239 github.com/googleapis/gax-go/v2 v2.14.1 // indirect
238- github.com/grpc-ecosystem/grpc-gateway/v2 v2.26.3 // indirect
240+ github.com/grpc-ecosystem/grpc-gateway/v2 v2.27.1 // indirect
239241 github.com/hashicorp/aws-sdk-go-base/v2 v2.0.0-beta.65 // indirect
240242 github.com/hashicorp/errwrap v1.1.0 // indirect
241243 github.com/hashicorp/go-cleanhttp v0.5.2 // indirect
@@ -245,7 +247,7 @@ require (
245247 github.com/hashicorp/go-multierror v1.1.1 // indirect
246248 github.com/hashicorp/go-retryablehttp v0.7.7 // indirect
247249 github.com/hashicorp/go-safetemp v1.0.0 // indirect
248- github.com/hashicorp/go-version v1.7 .0 // indirect
250+ github.com/hashicorp/go-version v1.8 .0 // indirect
249251 github.com/hashicorp/golang-lru v1.0.2 // indirect
250252 github.com/hashicorp/hcl v1.0.1-vault-5 // indirect
251253 github.com/hashicorp/hcl/v2 v2.23.0 // indirect
@@ -264,7 +266,7 @@ require (
264266 github.com/logrusorgru/aurora v2.0.3+incompatible // indirect
265267 github.com/lufia/plan9stats v0.0.0-20211012122336-39d0f177ccd0 // indirect
266268 github.com/magiconair/properties v1.8.10 // indirect
267- github.com/mailru/easyjson v0.7.7 // indirect
269+ github.com/mailru/easyjson v0.9.0 // indirect
268270 github.com/maruel/natural v1.1.1 // indirect
269271 github.com/mattn/go-runewidth v0.0.16 // indirect
270272 github.com/miekg/pkcs11 v1.1.1 // indirect
@@ -316,13 +318,13 @@ require (
316318 github.com/shoenig/go-m1cpu v0.1.6 // indirect
317319 github.com/shteou/go-ignore v0.3.1 // indirect
318320 github.com/sigstore/fulcio v1.6.3 // indirect
319- github.com/sigstore/protobuf-specs v0.3.2 // indirect
321+ github.com/sigstore/protobuf-specs v0.4.1 // indirect
320322 github.com/sigstore/timestamp-authority v1.2.2 // indirect
321323 github.com/skeema/knownhosts v1.3.0 // indirect
322324 github.com/skratchdot/open-golang v0.0.0-20200116055534-eef842397966 // indirect
323325 github.com/sourcegraph/conc v0.3.0 // indirect
324326 github.com/spf13/cast v1.7.1 // indirect
325- github.com/spiffe/go-spiffe/v2 v2.5 .0 // indirect
327+ github.com/spiffe/go-spiffe/v2 v2.6 .0 // indirect
326328 github.com/stoewer/go-strcase v1.3.0 // indirect
327329 github.com/stretchr/objx v0.5.2 // indirect
328330 github.com/subosito/gotenv v1.6.0 // indirect
@@ -355,46 +357,46 @@ require (
355357 github.com/zeebo/errs v1.4.0 // indirect
356358 go.mongodb.org/mongo-driver v1.16.1 // indirect
357359 go.opencensus.io v0.24.0 // indirect
358- go.opentelemetry.io/auto/sdk v1.1.0 // indirect
359- go.opentelemetry.io/contrib/detectors/gcp v1.36 .0 // indirect
360+ go.opentelemetry.io/auto/sdk v1.2.1 // indirect
361+ go.opentelemetry.io/contrib/detectors/gcp v1.38 .0 // indirect
360362 go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc v0.60.0 // indirect
361363 go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.61.0 // indirect
362- go.opentelemetry.io/otel v1.37 .0 // indirect
363- go.opentelemetry.io/otel/exporters/otlp/otlptrace v1.36 .0 // indirect
364+ go.opentelemetry.io/otel v1.39 .0 // indirect
365+ go.opentelemetry.io/otel/exporters/otlp/otlptrace v1.37 .0 // indirect
364366 go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc v1.36.0 // indirect
365- go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp v1.36 .0 // indirect
366- go.opentelemetry.io/otel/metric v1.37 .0 // indirect
367- go.opentelemetry.io/otel/sdk v1.37 .0 // indirect
368- go.opentelemetry.io/otel/sdk/metric v1.37 .0 // indirect
369- go.opentelemetry.io/otel/trace v1.37 .0 // indirect
370- go.opentelemetry.io/proto/otlp v1.6 .0 // indirect
367+ go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp v1.37 .0 // indirect
368+ go.opentelemetry.io/otel/metric v1.39 .0 // indirect
369+ go.opentelemetry.io/otel/sdk v1.39 .0 // indirect
370+ go.opentelemetry.io/otel/sdk/metric v1.39 .0 // indirect
371+ go.opentelemetry.io/otel/trace v1.39 .0 // indirect
372+ go.opentelemetry.io/proto/otlp v1.7 .0 // indirect
371373 go.step.sm/crypto v0.51.2 // indirect
372374 go.uber.org/automaxprocs v1.6.0 // indirect
373375 go.uber.org/multierr v1.11.0 // indirect
374- go.uber.org/zap v1.27.0 // indirect
376+ go.uber.org/zap v1.27.1 // indirect
375377 go.yaml.in/yaml/v2 v2.4.2 // indirect
376378 go.yaml.in/yaml/v3 v3.0.4 // indirect
377- golang.org/x/crypto v0.42 .0 // indirect
379+ golang.org/x/crypto v0.45 .0 // indirect
378380 golang.org/x/mod v0.29.0 // indirect
379- golang.org/x/oauth2 v0.30 .0 // indirect
380- golang.org/x/sys v0.37 .0 // indirect
381- golang.org/x/term v0.35 .0 // indirect
381+ golang.org/x/oauth2 v0.32 .0 // indirect
382+ golang.org/x/sys v0.39 .0 // indirect
383+ golang.org/x/term v0.37 .0 // indirect
382384 golang.org/x/time v0.14.0 // indirect
383- golang.org/x/tools v0.37 .0 // indirect
384- gomodules.xyz/jsonpatch/v2 v2.4 .0 // indirect
385- google.golang.org/api v0.215 .0 // indirect
386- google.golang.org/genproto v0.0.0-20241118233622-e639e219e697 // indirect
387- google.golang.org/genproto/googleapis/api v0.0.0-20250804133106-a7a43d27e69b // indirect
388- google.golang.org/genproto/googleapis/rpc v0.0.0-20250804133106-a7a43d27e69b // indirect
389- google.golang.org/grpc v1.76 .0 // indirect
390- google.golang.org/protobuf v1.36.10 // indirect
385+ golang.org/x/tools v0.38 .0 // indirect
386+ gomodules.xyz/jsonpatch/v2 v2.5 .0 // indirect
387+ google.golang.org/api v0.233 .0 // indirect
388+ google.golang.org/genproto v0.0.0-20250303144028-a0af3efb3deb // indirect
389+ google.golang.org/genproto/googleapis/api v0.0.0-20251022142026-3a174f9686a8 // indirect
390+ google.golang.org/genproto/googleapis/rpc v0.0.0-20251022142026-3a174f9686a8 // indirect
391+ google.golang.org/grpc v1.77 .0 // indirect
392+ google.golang.org/protobuf v1.36.11 // indirect
391393 gopkg.in/evanphx/json-patch.v4 v4.12.0 // indirect
392394 gopkg.in/inf.v0 v0.9.1 // indirect
393395 gopkg.in/ini.v1 v1.67.0 // indirect
394396 gopkg.in/warnings.v0 v0.1.2 // indirect
395397 gopkg.in/yaml.v2 v2.4.0 // indirect
396398 k8s.io/utils v0.0.0-20250604170112-4c0f3b243397 // indirect
397- knative.dev/pkg v0.0.0-20240815051656-89743d9bbf7c // indirect
399+ knative.dev/pkg v0.0.0-20250415155312-ed3e2158b883 // indirect
398400 olympos.io/encoding/edn v0.0.0-20201019073823-d3554ca0b0a3 // indirect
399401 sigs.k8s.io/controller-runtime v0.19.0 // indirect
400402 sigs.k8s.io/json v0.0.0-20241014173422-cfa47c3a1cc8 // indirect
0 commit comments