11module github.com/mindersec/minder-rules-and-profiles
22
3- go 1.23.1
4-
5- toolchain go1.23.2
3+ go 1.23.4
64
75require (
8- github.com/mindersec/minder v0.0.68
6+ github.com/mindersec/minder v0.0.80
97 github.com/rs/zerolog v1.33.0
10- github.com/stretchr/testify v1.9 .0
11- google.golang.org/protobuf v1.35.1
8+ github.com/stretchr/testify v1.10 .0
9+ google.golang.org/protobuf v1.35.2
1210 gopkg.in/yaml.v3 v3.0.1
1311)
1412
1513require (
14+ buf.build/gen/go/bufbuild/protovalidate/protocolbuffers/go v1.35.2-20240920164238-5a7b106cbb87.1 // indirect
15+ cel.dev/expr v0.18.0 // indirect
1616 dario.cat/mergo v1.0.1 // indirect
17- github.com/AdaLogics/go-fuzz-headers v0.0.0-20230811130428-ced1acdcaa24 // indirect
18- github.com/AdamKorcz/go-118-fuzz-build v0.0.0-20230306123547-8075edf89bb0 // indirect
17+ github.com/AdaLogics/go-fuzz-headers v0.0.0-20240806141605-e8a1dd7889d6 // indirect
18+ github.com/AdamKorcz/go-118-fuzz-build v0.0.0-20231105174938-2b5cbb29f3e2 // indirect
1919 github.com/BurntSushi/toml v1.4.0 // indirect
20- github.com/CycloneDX/cyclonedx-go v0.9.0 // indirect
20+ github.com/CycloneDX/cyclonedx-go v0.9.1 // indirect
2121 github.com/Microsoft/go-winio v0.6.2 // indirect
22- github.com/Microsoft/hcsshim v0.11.7 // indirect
22+ github.com/Microsoft/hcsshim v0.12.8 // indirect
2323 github.com/OneOfOne/xxhash v1.2.8 // indirect
2424 github.com/ProtonMail/go-crypto v1.0.0 // indirect
25- github.com/ThreeDotsLabs/watermill v1.3.7 // indirect
26- github.com/ThreeDotsLabs/watermill-sql/v3 v3.1.0 // indirect
25+ github.com/ThreeDotsLabs/watermill v1.4.1 // indirect
26+ github.com/a8m/envsubst v1.4.2 // indirect
2727 github.com/agnivade/levenshtein v1.2.0 // indirect
28- github.com/alexdrl/zerowater v0.0.3 // indirect
29- github.com/anchore/go-struct-converter v0.0.0-20230627203149-c72ef8859ca9 // indirect
28+ github.com/alecthomas/participle/v2 v2.1.1 // indirect
29+ github.com/anchore/go-struct-converter v0.0.0-20240925125616-a0883641c664 // indirect
3030 github.com/antlr4-go/antlr/v4 v4.13.1 // indirect
3131 github.com/asaskevich/govalidator v0.0.0-20230301143203-a9d515a09cc2 // indirect
3232 github.com/barkimedes/go-deepcopy v0.0.0-20220514131651-17c30cfc62df // indirect
3333 github.com/beorn7/perks v1.0.1 // indirect
3434 github.com/blang/semver v3.5.1+incompatible // indirect
35- github.com/cenkalti/backoff/v3 v3.2.2 // indirect
3635 github.com/cenkalti/backoff/v4 v4.3.0 // indirect
3736 github.com/cespare/xxhash/v2 v2.3.0 // indirect
38- github.com/cloudevents/sdk-go/protocol/nats_jetstream/v2 v2.15.2 // indirect
39- github.com/cloudevents/sdk-go/v2 v2.15.2 // indirect
40- github.com/cloudflare/circl v1.3.7 // indirect
41- github.com/containerd/cgroups v1.1.0 // indirect
42- github.com/containerd/containerd v1.7.22 // indirect
37+ github.com/cloudflare/circl v1.5.0 // indirect
38+ github.com/containerd/cgroups/v3 v3.0.3 // indirect
39+ github.com/containerd/containerd v1.7.23 // indirect
4340 github.com/containerd/containerd/api v1.7.19 // indirect
4441 github.com/containerd/continuity v0.4.3 // indirect
45- github.com/containerd/errdefs v0.1 .0 // indirect
42+ github.com/containerd/errdefs v0.3 .0 // indirect
4643 github.com/containerd/fifo v1.1.0 // indirect
4744 github.com/containerd/log v0.1.0 // indirect
4845 github.com/containerd/platforms v0.2.1 // indirect
4946 github.com/containerd/stargz-snapshotter/estargz v0.15.1 // indirect
5047 github.com/containerd/ttrpc v1.2.5 // indirect
5148 github.com/containerd/typeurl/v2 v2.2.0 // indirect
52- github.com/cyberphone/json-canonicalization v0.0.0-20231011164504-785e29786b46 // indirect
53- github.com/cyphar/filepath-securejoin v0.2.5 // indirect
49+ github.com/cyberphone/json-canonicalization v0.0.0-20231217050601-ba74d44ecf5f // indirect
50+ github.com/cyphar/filepath-securejoin v0.3.4 // indirect
5451 github.com/davecgh/go-spew v1.1.2-0.20180830191138-d8f796af33cc // indirect
5552 github.com/deckarep/golang-set/v2 v2.6.0 // indirect
5653 github.com/decred/dcrd/dcrec/secp256k1/v4 v4.3.0 // indirect
5754 github.com/digitorus/pkcs7 v0.0.0-20230818184609-3a137a874352 // indirect
5855 github.com/digitorus/timestamp v0.0.0-20231217203849-220c5c2851b7 // indirect
56+ github.com/dimchansky/utfbom v1.1.1 // indirect
5957 github.com/distribution/reference v0.6.0 // indirect
6058 github.com/docker/cli v27.3.1+incompatible // indirect
6159 github.com/docker/distribution v2.8.3+incompatible // indirect
6260 github.com/docker/docker-credential-helpers v0.8.2 // indirect
63- github.com/docker/go-events v0.0.0-20190806004212-e31b211e4f1c // indirect
61+ github.com/docker/go-events v0.0.0-20241017185736-969db071c880 // indirect
62+ github.com/elliotchance/orderedmap v1.7.0 // indirect
6463 github.com/emirpasic/gods v1.18.1 // indirect
6564 github.com/erikvarga/go-rpmdb v0.0.0-20240208180226-b97e041ef9af // indirect
6665 github.com/evanphx/json-patch/v5 v5.9.0 // indirect
66+ github.com/fatih/color v1.18.0 // indirect
6767 github.com/felixge/httpsnoop v1.0.4 // indirect
68- github.com/fsnotify/fsnotify v1.7 .0 // indirect
69- github.com/gabriel-vasile/mimetype v1.4.3 // indirect
68+ github.com/fsnotify/fsnotify v1.8 .0 // indirect
69+ github.com/gabriel-vasile/mimetype v1.4.6 // indirect
7070 github.com/go-chi/chi v4.1.2+incompatible // indirect
71- github.com/go-chi/chi/v5 v5.1.0 // indirect
7271 github.com/go-git/gcfg v1.5.1-0.20230307220236-3a3c6141e376 // indirect
73- github.com/go-git/go-billy/v5 v5.5.1-0.20240927131424-c1ee0b97d109 // indirect
72+ github.com/go-git/go-billy/v5 v5.6.0 // indirect
7473 github.com/go-git/go-git/v5 v5.12.0 // indirect
7574 github.com/go-ini/ini v1.67.0 // indirect
7675 github.com/go-jose/go-jose/v4 v4.0.4 // indirect
@@ -88,171 +87,168 @@ require (
8887 github.com/go-openapi/validate v0.24.0 // indirect
8988 github.com/go-playground/locales v0.14.1 // indirect
9089 github.com/go-playground/universal-translator v0.18.1 // indirect
91- github.com/go-playground/validator/v10 v10.22.1 // indirect
90+ github.com/go-playground/validator/v10 v10.23.0 // indirect
9291 github.com/go-viper/mapstructure/v2 v2.2.1 // indirect
9392 github.com/gobwas/glob v0.2.3 // indirect
9493 github.com/goccy/go-json v0.10.3 // indirect
94+ github.com/goccy/go-yaml v1.13.0 // indirect
9595 github.com/gogo/protobuf v1.3.2 // indirect
9696 github.com/golang-jwt/jwt/v4 v4.5.1 // indirect
9797 github.com/golang/groupcache v0.0.0-20210331224755-41bb18bfe9da // indirect
98- github.com/google/cel-go v0.21.0 // indirect
98+ github.com/google/cel-go v0.22.1 // indirect
9999 github.com/google/certificate-transparency-go v1.2.1 // indirect
100100 github.com/google/go-cmp v0.6.0 // indirect
101101 github.com/google/go-containerregistry v0.20.2 // indirect
102102 github.com/google/go-github/v61 v61.0.0 // indirect
103103 github.com/google/go-github/v63 v63.0.0 // indirect
104104 github.com/google/go-querystring v1.1.0 // indirect
105- github.com/google/osv-scalibr v0.1.4-0.20241008174812-047e6a2b425d // indirect
106- github.com/google/osv-scanner v1.7.1 // indirect
105+ github.com/google/osv-scalibr v0.1.5 // indirect
106+ github.com/google/osv-scanner v1.9.0 // indirect
107107 github.com/google/uuid v1.6.0 // indirect
108108 github.com/gorilla/mux v1.8.1 // indirect
109- github.com/grpc-ecosystem/grpc-gateway/v2 v2.22.0 // indirect
110- github.com/hashicorp/errwrap v1.1 .0 // indirect
109+ github.com/groob/plist v0.1.1 // indirect
110+ github.com/grpc-ecosystem/grpc-gateway/v2 v2.24 .0 // indirect
111111 github.com/hashicorp/go-cleanhttp v0.5.2 // indirect
112- github.com/hashicorp/go-multierror v1.1.1 // indirect
113112 github.com/hashicorp/go-retryablehttp v0.7.7 // indirect
114113 github.com/hashicorp/go-version v1.7.0 // indirect
115114 github.com/hashicorp/hcl v1.0.1-vault-5 // indirect
116115 github.com/in-toto/attestation v1.1.0 // indirect
117116 github.com/in-toto/in-toto-golang v0.9.0 // indirect
118117 github.com/inconshreveable/mousetrap v1.1.0 // indirect
119- github.com/itchyny/gojq v0.12.16 // indirect
118+ github.com/itchyny/gojq v0.12.17 // indirect
120119 github.com/itchyny/timefmt-go v0.1.6 // indirect
121120 github.com/jbenet/go-context v0.0.0-20150711004518-d14ea06fba99 // indirect
122121 github.com/jedisct1/go-minisign v0.0.0-20230811132847-661be99b8267 // indirect
122+ github.com/jinzhu/copier v0.4.0 // indirect
123123 github.com/josharian/intern v1.0.0 // indirect
124- github.com/json-iterator/go v1.1.12 // indirect
125124 github.com/kevinburke/ssh_config v1.2.0 // indirect
126- github.com/klauspost/compress v1.17.9 // indirect
125+ github.com/klauspost/compress v1.17.11 // indirect
127126 github.com/leodido/go-urn v1.4.0 // indirect
128127 github.com/lestrrat-go/blackmagic v1.0.2 // indirect
129128 github.com/lestrrat-go/httpcc v1.0.1 // indirect
130129 github.com/lestrrat-go/httprc v1.0.6 // indirect
131130 github.com/lestrrat-go/iter v1.0.2 // indirect
132- github.com/lestrrat-go/jwx/v2 v2.1.1 // indirect
131+ github.com/lestrrat-go/jwx/v2 v2.1.3 // indirect
133132 github.com/lestrrat-go/option v1.0.1 // indirect
134- github.com/letsencrypt/boulder v0.0.0-20240620165639-de9c06129bec // indirect
133+ github.com/letsencrypt/boulder v0.0.0-20241021211548-844334e04aef // indirect
135134 github.com/lib/pq v1.10.9 // indirect
136135 github.com/lithammer/shortuuid/v3 v3.0.7 // indirect
137136 github.com/magiconair/properties v1.8.7 // indirect
138137 github.com/mailru/easyjson v0.7.7 // indirect
139138 github.com/mattn/go-colorable v0.1.13 // indirect
140139 github.com/mattn/go-isatty v0.0.20 // indirect
141- github.com/mattn/go-sqlite3 v1.14.22 // indirect
140+ github.com/mattn/go-sqlite3 v1.14.24 // indirect
141+ github.com/mikefarah/yq/v4 v4.44.6 // indirect
142142 github.com/mitchellh/go-homedir v1.1.0 // indirect
143143 github.com/mitchellh/mapstructure v1.5.0 // indirect
144144 github.com/moby/buildkit v0.16.0 // indirect
145145 github.com/moby/locker v1.0.1 // indirect
146146 github.com/moby/sys/mountinfo v0.7.2 // indirect
147- github.com/moby/sys/sequential v0.5 .0 // indirect
147+ github.com/moby/sys/sequential v0.6 .0 // indirect
148148 github.com/moby/sys/signal v0.7.1 // indirect
149149 github.com/moby/sys/user v0.3.0 // indirect
150150 github.com/moby/sys/userns v0.1.0 // indirect
151- github.com/modern-go/concurrent v0.0.0-20180306012644-bacd9c7ef1dd // indirect
152- github.com/modern-go/reflect2 v1.0.2 // indirect
153151 github.com/motemen/go-loghttp v0.0.0-20231107055348-29ae44b293f4 // indirect
154152 github.com/motemen/go-nuts v0.0.0-20220604134737-2658d0104f31 // indirect
155153 github.com/munnerz/goautoneg v0.0.0-20191010083416-a7dc8b61c822 // indirect
156- github.com/nats-io/nats.go v1.37.0 // indirect
157- github.com/nats-io/nkeys v0.4.7 // indirect
158- github.com/nats-io/nuid v1.0.1 // indirect
159154 github.com/nikunjy/rules v1.5.0 // indirect
160155 github.com/nozzle/throttler v0.0.0-20180817012639-2ea982251481 // indirect
161156 github.com/oklog/ulid v1.3.1 // indirect
162- github.com/open-feature/go-sdk v1.13.0 // indirect
157+ github.com/open-feature/go-sdk v1.13.1 // indirect
163158 github.com/open-feature/go-sdk-contrib/providers/go-feature-flag-in-process v0.1.0 // indirect
164- github.com/open-policy-agent/opa v0.68 .0 // indirect
159+ github.com/open-policy-agent/opa v0.70 .0 // indirect
165160 github.com/opencontainers/go-digest v1.0.0 // indirect
166161 github.com/opencontainers/image-spec v1.1.0 // indirect
167162 github.com/opencontainers/runtime-spec v1.2.0 // indirect
168- github.com/opencontainers/selinux v1.11.0 // indirect
163+ github.com/opencontainers/selinux v1.11.1 // indirect
169164 github.com/opentracing/opentracing-go v1.2.0 // indirect
170165 github.com/package-url/packageurl-go v0.1.3 // indirect
171- github.com/pelletier/go-toml/v2 v2.2.2 // indirect
166+ github.com/pelletier/go-toml/v2 v2.2.3 // indirect
172167 github.com/pjbgf/sha1cd v0.3.0 // indirect
173168 github.com/pkg/errors v0.9.1 // indirect
174169 github.com/pmezard/go-difflib v1.0.1-0.20181226105442-5d4384ee4fb2 // indirect
175170 github.com/prometheus/client_golang v1.20.5 // indirect
176171 github.com/prometheus/client_model v0.6.1 // indirect
177- github.com/prometheus/common v0.60.0 // indirect
172+ github.com/prometheus/common v0.60.1 // indirect
178173 github.com/prometheus/procfs v0.15.1 // indirect
174+ github.com/protobom/protobom v0.5.0 // indirect
179175 github.com/puzpuzpuz/xsync v1.5.2 // indirect
180176 github.com/puzpuzpuz/xsync/v3 v3.4.0 // indirect
181177 github.com/rcrowley/go-metrics v0.0.0-20201227073835-cf1acfcdf475 // indirect
182178 github.com/rogpeppe/go-internal v1.13.1 // indirect
183- github.com/sagikazarmark/locafero v0.4 .0 // indirect
179+ github.com/sagikazarmark/locafero v0.6 .0 // indirect
184180 github.com/sagikazarmark/slog-shim v0.1.0 // indirect
181+ github.com/santhosh-tekuri/jsonschema/v6 v6.0.1 // indirect
185182 github.com/sassoftware/relic v7.2.1+incompatible // indirect
186183 github.com/secure-systems-lab/go-securesystemslib v0.8.0 // indirect
187184 github.com/segmentio/asm v1.2.0 // indirect
188185 github.com/sergi/go-diff v1.3.2-0.20230802210424-5b0b94c5c0d3 // indirect
189186 github.com/shibumi/go-pathspec v1.3.0 // indirect
190- github.com/signalfx/splunk-otel-go/instrumentation/database/sql/splunksql v1.20 .0 // indirect
191- github.com/signalfx/splunk-otel-go/instrumentation/github.com/lib/pq/splunkpq v1.20 .0 // indirect
192- github.com/signalfx/splunk-otel-go/instrumentation/internal v1.20 .0 // indirect
187+ github.com/signalfx/splunk-otel-go/instrumentation/database/sql/splunksql v1.22 .0 // indirect
188+ github.com/signalfx/splunk-otel-go/instrumentation/github.com/lib/pq/splunkpq v1.22 .0 // indirect
189+ github.com/signalfx/splunk-otel-go/instrumentation/internal v1.22 .0 // indirect
193190 github.com/sigstore/protobuf-specs v0.3.2 // indirect
194191 github.com/sigstore/rekor v1.3.6 // indirect
195- github.com/sigstore/sigstore v1.8.9 // indirect
192+ github.com/sigstore/sigstore v1.8.10 // indirect
196193 github.com/sigstore/sigstore-go v0.6.2 // indirect
197- github.com/sigstore/timestamp-authority v1.2.2 // indirect
194+ github.com/sigstore/timestamp-authority v1.2.3 // indirect
198195 github.com/sirupsen/logrus v1.9.4-0.20230606125235-dd1b4c2e81af // indirect
199- github.com/skeema/knownhosts v1.2.2 // indirect
200- github.com/sony/gobreaker v1.0.0 // indirect
196+ github.com/skeema/knownhosts v1.3.0 // indirect
201197 github.com/sourcegraph/conc v0.3.0 // indirect
202198 github.com/spdx/gordf v0.0.0-20221230105357-b735bd5aac89 // indirect
203- github.com/spdx/tools-golang v0.5.3 // indirect
199+ github.com/spdx/tools-golang v0.5.5 // indirect
204200 github.com/spf13/afero v1.11.0 // indirect
205- github.com/spf13/cast v1.6 .0 // indirect
201+ github.com/spf13/cast v1.7 .0 // indirect
206202 github.com/spf13/cobra v1.8.1 // indirect
207203 github.com/spf13/pflag v1.0.5 // indirect
208204 github.com/spf13/viper v1.19.0 // indirect
209205 github.com/sqlc-dev/pqtype v0.3.0 // indirect
210- github.com/stacklok/frizbee v0.1.3 // indirect
211- github.com/stacklok/trusty-sdk-go v0.2.1 // indirect
206+ github.com/stacklok/frizbee v0.1.4 // indirect
207+ github.com/stacklok/trusty-sdk-go v0.2.3-0.20241121160719-089f44e88687 // indirect
212208 github.com/stoewer/go-strcase v1.3.0 // indirect
213209 github.com/subosito/gotenv v1.6.0 // indirect
214210 github.com/tchap/go-patricia/v2 v2.3.1 // indirect
215211 github.com/theupdateframework/go-tuf v0.7.0 // indirect
216- github.com/theupdateframework/go-tuf/v2 v2.0.1 // indirect
217- github.com/thomaspoignant/go-feature-flag v1.34.0 // indirect
212+ github.com/theupdateframework/go-tuf/v2 v2.0.2 // indirect
213+ github.com/thomaspoignant/go-feature-flag v1.39.1 // indirect
218214 github.com/titanous/rocacheck v0.0.0-20171023193734-afe73141d399 // indirect
219215 github.com/transparency-dev/merkle v0.0.2 // indirect
220- github.com/vbatts/tar-split v0.11.5 // indirect
221- github.com/xanzy/go-gitlab v0.112.0 // indirect
216+ github.com/vbatts/tar-split v0.11.6 // indirect
222217 github.com/xanzy/ssh-agent v0.3.3 // indirect
223218 github.com/xeipuuv/gojsonpointer v0.0.0-20190905194746-02993c407bfb // indirect
224219 github.com/xeipuuv/gojsonreference v0.0.0-20180127040603-bd5ef7bd5415 // indirect
225- github.com/xeipuuv/gojsonschema v1.2.0 // indirect
226220 github.com/yashtewari/glob-intersection v0.2.0 // indirect
227- go.etcd.io/bbolt v1.3.10 // indirect
228- go.mongodb.org/mongo-driver v1.16.1 // indirect
221+ github.com/yuin/gopher-lua v1.1.1 // indirect
222+ gitlab.com/gitlab-org/api/client-go v0.116.0 // indirect
223+ go.etcd.io/bbolt v1.3.11 // indirect
224+ go.mongodb.org/mongo-driver v1.17.1 // indirect
229225 go.opencensus.io v0.24.0 // indirect
230- go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.56 .0 // indirect
231- go.opentelemetry.io/otel v1.31 .0 // indirect
232- go.opentelemetry.io/otel/metric v1.31 .0 // indirect
233- go.opentelemetry.io/otel/sdk v1.31 .0 // indirect
234- go.opentelemetry.io/otel/trace v1.31 .0 // indirect
226+ go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.57 .0 // indirect
227+ go.opentelemetry.io/otel v1.32 .0 // indirect
228+ go.opentelemetry.io/otel/metric v1.32 .0 // indirect
229+ go.opentelemetry.io/otel/sdk v1.32 .0 // indirect
230+ go.opentelemetry.io/otel/trace v1.32 .0 // indirect
235231 go.uber.org/multierr v1.11.0 // indirect
236232 go.uber.org/zap v1.27.0 // indirect
237233 golang.org/x/crypto v0.31.0 // indirect
238- golang.org/x/exp v0.0.0-20240904232852-e7e105dedf7e // indirect
239- golang.org/x/mod v0.21 .0 // indirect
240- golang.org/x/net v0.30 .0 // indirect
241- golang.org/x/oauth2 v0.23 .0 // indirect
234+ golang.org/x/exp v0.0.0-20241009180824-f66d83c29e7c // indirect
235+ golang.org/x/mod v0.22 .0 // indirect
236+ golang.org/x/net v0.32 .0 // indirect
237+ golang.org/x/oauth2 v0.24 .0 // indirect
242238 golang.org/x/sync v0.10.0 // indirect
243239 golang.org/x/sys v0.28.0 // indirect
244240 golang.org/x/term v0.27.0 // indirect
245241 golang.org/x/text v0.21.0 // indirect
246- golang.org/x/time v0.6 .0 // indirect
247- golang.org/x/xerrors v0.0.0-20231012003039-104605ab7028 // indirect
248- google.golang.org/genproto v0.0.0-20240903143218-8af14fe29dc1 // indirect
249- google.golang.org/genproto/googleapis/api v0.0.0-20240903143218-8af14fe29dc1 // indirect
250- google.golang.org/genproto/googleapis/rpc v0.0.0-20241007155032-5fefd90f89a9 // indirect
251- google.golang.org/grpc v1.67 .1 // indirect
242+ golang.org/x/time v0.8 .0 // indirect
243+ golang.org/x/xerrors v0.0.0-20240903120638-7835f813f4da // indirect
244+ google.golang.org/genproto v0.0.0-20241113202542-65e8d215514f // indirect
245+ google.golang.org/genproto/googleapis/api v0.0.0-20241118233622-e639e219e697 // indirect
246+ google.golang.org/genproto/googleapis/rpc v0.0.0-20241118233622-e639e219e697 // indirect
247+ google.golang.org/grpc v1.68 .1 // indirect
252248 gopkg.in/ini.v1 v1.67.0 // indirect
249+ gopkg.in/op/go-logging.v1 v1.0.0-20160211212156-b2cb9fa56473 // indirect
253250 gopkg.in/warnings.v0 v0.1.2 // indirect
254- gopkg.in/yaml.v2 v2.4.0 // indirect
255- k8s.io/apimachinery v0.31.1 // indirect
251+ k8s.io/apimachinery v0.31.4 // indirect
256252 k8s.io/klog/v2 v2.130.1 // indirect
257253 sigs.k8s.io/release-utils v0.8.5 // indirect
258254 sigs.k8s.io/yaml v1.4.0 // indirect
0 commit comments