Skip to content

Commit 9cc18cf

Browse files
authored
Merge pull request #1132 from fluxcd/cosign-2.1
Update Cosign to v2.1.0
2 parents 5cd936d + 9b78bc6 commit 9cc18cf

File tree

4 files changed

+86
-89
lines changed

4 files changed

+86
-89
lines changed

go.mod

Lines changed: 25 additions & 31 deletions
Original file line numberDiff line numberDiff line change
@@ -14,13 +14,6 @@ replace github.com/opencontainers/go-digest => github.com/opencontainers/go-dige
1414
// Check again when oras.land/oras-go is updated, which is a dependency of Helm.
1515
replace github.com/docker/docker => github.com/docker/docker v23.0.6+incompatible
1616

17-
// Required to keep github.com/sigstore/cosign/v2 happy, as it will otherwise fail with
18-
// "cannot use remote.Referrers(d, rOpt...) (value of type ".../go-containerregistry/pkg/v1".ImageIndex)"
19-
//
20-
// Check again when github.com/sigstore/cosign/v2 is updated to a version that
21-
// is compatible with github.com/google/go-containerregistry v0.15.x.
22-
replace github.com/google/go-containerregistry => github.com/google/go-containerregistry v0.14.1-0.20230409045903-ed5c185df419
23-
2417
require (
2518
cloud.google.com/go/storage v1.30.1
2619
github.com/AdaLogics/go-fuzz-headers v0.0.0-20230106234847-43070de90fa1
@@ -52,7 +45,7 @@ require (
5245
github.com/go-git/go-git/v5 v5.7.0
5346
github.com/go-logr/logr v1.2.4
5447
github.com/google/go-containerregistry v0.15.2
55-
github.com/google/go-containerregistry/pkg/authn/k8schain v0.0.0-20230622215552-fe268b7c97b3
48+
github.com/google/go-containerregistry/pkg/authn/k8schain v0.0.0-20230625233257-b8504803389b
5649
github.com/google/uuid v1.3.0
5750
github.com/minio/minio-go/v7 v7.0.58
5851
github.com/onsi/gomega v1.27.8
@@ -62,7 +55,7 @@ require (
6255
github.com/otiai10/copy v1.12.0
6356
github.com/phayes/freeport v0.0.0-20220201140144-74d24b5ae9f5
6457
github.com/prometheus/client_golang v1.16.0
65-
github.com/sigstore/cosign/v2 v2.0.2
58+
github.com/sigstore/cosign/v2 v2.1.0
6659
github.com/sigstore/sigstore v1.7.1
6760
github.com/sirupsen/logrus v1.9.3
6861
github.com/spf13/pflag v1.0.5
@@ -143,8 +136,8 @@ require (
143136
github.com/bugsnag/bugsnag-go v0.0.0-20141110184014-b1d153021fcd // indirect
144137
github.com/bugsnag/osext v0.0.0-20130617224835-0dd3f918b21b // indirect
145138
github.com/bugsnag/panicwrap v0.0.0-20151223152923-e2c28503fcd0 // indirect
146-
github.com/buildkite/agent/v3 v3.45.0 // indirect
147-
github.com/cenkalti/backoff/v4 v4.2.0 // indirect
139+
github.com/buildkite/agent/v3 v3.49.0 // indirect
140+
github.com/cenkalti/backoff/v4 v4.2.1 // indirect
148141
github.com/cespare/xxhash/v2 v2.2.0 // indirect
149142
github.com/chai2010/gettext-go v1.0.2 // indirect
150143
github.com/chrismellard/docker-credential-acr-env v0.0.0-20230304212654-82a0ddb27589 // indirect
@@ -194,7 +187,7 @@ require (
194187
github.com/go-openapi/runtime v0.26.0 // indirect
195188
github.com/go-openapi/spec v0.20.9 // indirect
196189
github.com/go-openapi/strfmt v0.21.7 // indirect
197-
github.com/go-openapi/swag v0.22.3 // indirect
190+
github.com/go-openapi/swag v0.22.4 // indirect
198191
github.com/go-openapi/validate v0.22.1 // indirect
199192
github.com/go-piv/piv-go v1.11.0 // indirect
200193
github.com/go-playground/locales v0.14.1 // indirect
@@ -209,16 +202,16 @@ require (
209202
github.com/golang/snappy v0.0.4 // indirect
210203
github.com/gomodule/redigo v1.8.2 // indirect
211204
github.com/google/btree v1.1.2 // indirect
212-
github.com/google/certificate-transparency-go v1.1.4 // indirect
205+
github.com/google/certificate-transparency-go v1.1.6 // indirect
213206
github.com/google/gnostic v0.6.9 // indirect
214207
github.com/google/go-cmp v0.5.9 // indirect
215208
github.com/google/go-containerregistry/pkg/authn/kubernetes v0.0.0-20230516205744-dbecb1de8cfa // indirect
216209
github.com/google/go-github/v50 v50.2.0 // indirect
217210
github.com/google/go-querystring v1.1.0 // indirect
218211
github.com/google/gofuzz v1.2.0 // indirect
212+
github.com/google/pprof v0.0.0-20221103000818-d260c55eee4c // indirect
219213
github.com/google/s2a-go v0.1.4 // indirect
220214
github.com/google/shlex v0.0.0-20191202100458-e7afc7fbc510 // indirect
221-
github.com/google/trillian v1.5.2 // indirect
222215
github.com/googleapis/enterprise-certificate-proxy v0.2.4 // indirect
223216
github.com/googleapis/gax-go/v2 v2.11.0 // indirect
224217
github.com/gorilla/handlers v1.5.1 // indirect
@@ -274,12 +267,13 @@ require (
274267
github.com/morikuni/aec v1.0.0 // indirect
275268
github.com/mozillazg/docker-credential-acr-helper v0.3.0 // indirect
276269
github.com/munnerz/goautoneg v0.0.0-20191010083416-a7dc8b61c822 // indirect
270+
github.com/nozzle/throttler v0.0.0-20180817012639-2ea982251481 // indirect
277271
github.com/oklog/ulid v1.3.1 // indirect
278272
github.com/opencontainers/image-spec v1.1.0-rc3 // indirect
279273
github.com/opencontainers/runc v1.1.5 // indirect
280274
github.com/opentracing/opentracing-go v1.2.0 // indirect
281275
github.com/pborman/uuid v1.2.1 // indirect
282-
github.com/pelletier/go-toml/v2 v2.0.6 // indirect
276+
github.com/pelletier/go-toml/v2 v2.0.8 // indirect
283277
github.com/peterbourgon/diskv v2.0.1+incompatible // indirect
284278
github.com/pjbgf/sha1cd v0.3.0 // indirect
285279
github.com/pkg/browser v0.0.0-20210911075715-681adbf594b8 // indirect
@@ -297,22 +291,21 @@ require (
297291
github.com/sergi/go-diff v1.3.1 // indirect
298292
github.com/shibumi/go-pathspec v1.3.0 // indirect
299293
github.com/shopspring/decimal v1.3.1 // indirect
300-
github.com/sigstore/fulcio v1.2.0 // indirect
301-
github.com/sigstore/protobuf-specs v0.1.0 // indirect
302-
github.com/sigstore/rekor v1.2.0 // indirect
294+
github.com/sigstore/fulcio v1.3.1 // indirect
295+
github.com/sigstore/rekor v1.2.2-0.20230530122220-67cc9e58bd23 // indirect
303296
github.com/sigstore/sigstore/pkg/signature/kms/aws v1.7.1 // indirect
304297
github.com/sigstore/sigstore/pkg/signature/kms/azure v1.7.1 // indirect
305298
github.com/sigstore/sigstore/pkg/signature/kms/gcp v1.7.1 // indirect
306299
github.com/sigstore/sigstore/pkg/signature/kms/hashivault v1.7.1 // indirect
307-
github.com/sigstore/timestamp-authority v1.0.0 // indirect
300+
github.com/sigstore/timestamp-authority v1.1.1 // indirect
308301
github.com/skeema/knownhosts v1.1.1 // indirect
309302
github.com/skratchdot/open-golang v0.0.0-20200116055534-eef842397966 // indirect
310-
github.com/spf13/afero v1.9.3 // indirect
311-
github.com/spf13/cast v1.5.0 // indirect
303+
github.com/spf13/afero v1.9.5 // indirect
304+
github.com/spf13/cast v1.5.1 // indirect
312305
github.com/spf13/cobra v1.7.0 // indirect
313306
github.com/spf13/jwalterweatherman v1.1.0 // indirect
314-
github.com/spf13/viper v1.15.0 // indirect
315-
github.com/spiffe/go-spiffe/v2 v2.1.4 // indirect
307+
github.com/spf13/viper v1.16.0 // indirect
308+
github.com/spiffe/go-spiffe/v2 v2.1.6 // indirect
316309
github.com/subosito/gotenv v1.4.2 // indirect
317310
github.com/syndtr/goleveldb v1.0.1-0.20220721030215-126854af5e6d // indirect
318311
github.com/thales-e-security/pool v0.0.2 // indirect
@@ -321,7 +314,7 @@ require (
321314
github.com/tjfoc/gmsm v1.3.2 // indirect
322315
github.com/transparency-dev/merkle v0.0.2 // indirect
323316
github.com/vbatts/tar-split v0.11.3 // indirect
324-
github.com/xanzy/go-gitlab v0.83.0 // indirect
317+
github.com/xanzy/go-gitlab v0.86.0 // indirect
325318
github.com/xanzy/ssh-agent v0.3.3 // indirect
326319
github.com/xeipuuv/gojsonpointer v0.0.0-20190905194746-02993c407bfb // indirect
327320
github.com/xeipuuv/gojsonreference v0.0.0-20180127040603-bd5ef7bd5415 // indirect
@@ -334,29 +327,30 @@ require (
334327
github.com/zeebo/errs v1.3.0 // indirect
335328
go.mongodb.org/mongo-driver v1.11.3 // indirect
336329
go.opencensus.io v0.24.0 // indirect
337-
go.opentelemetry.io/otel v1.14.0 // indirect
338-
go.opentelemetry.io/otel/trace v1.14.0 // indirect
330+
go.opentelemetry.io/otel v1.16.0 // indirect
331+
go.opentelemetry.io/otel/metric v1.16.0 // indirect
332+
go.opentelemetry.io/otel/trace v1.16.0 // indirect
339333
go.starlark.net v0.0.0-20221028183056-acb66ad56dd2 // indirect
340-
go.step.sm/crypto v0.30.0 // indirect
334+
go.step.sm/crypto v0.32.1 // indirect
341335
go.uber.org/atomic v1.10.0 // indirect
342-
go.uber.org/multierr v1.9.0 // indirect
336+
go.uber.org/multierr v1.11.0 // indirect
343337
go.uber.org/zap v1.24.0 // indirect
344338
golang.org/x/exp v0.0.0-20230321023759-10a507213a29 // indirect
345-
golang.org/x/mod v0.10.0 // indirect
339+
golang.org/x/mod v0.11.0 // indirect
346340
golang.org/x/net v0.11.0 // indirect
347341
golang.org/x/oauth2 v0.9.0 // indirect
348342
golang.org/x/sys v0.9.0 // indirect
349343
golang.org/x/term v0.9.0 // indirect
350344
golang.org/x/text v0.10.0 // indirect
351345
golang.org/x/time v0.3.0 // indirect
352-
golang.org/x/tools v0.9.1 // indirect
346+
golang.org/x/tools v0.9.3 // indirect
353347
golang.org/x/xerrors v0.0.0-20220907171357-04be3eba64a2 // indirect
354348
gomodules.xyz/jsonpatch/v2 v2.3.0 // indirect
355349
google.golang.org/appengine v1.6.7 // indirect
356350
google.golang.org/genproto v0.0.0-20230530153820-e85fd2cbaebc // indirect
357351
google.golang.org/genproto/googleapis/api v0.0.0-20230530153820-e85fd2cbaebc // indirect
358352
google.golang.org/genproto/googleapis/rpc v0.0.0-20230530153820-e85fd2cbaebc // indirect
359-
google.golang.org/grpc v1.55.0 // indirect
353+
google.golang.org/grpc v1.56.0 // indirect
360354
google.golang.org/protobuf v1.30.0 // indirect
361355
gopkg.in/inf.v0 v0.9.1 // indirect
362356
gopkg.in/ini.v1 v1.67.0 // indirect

0 commit comments

Comments
 (0)