11module github.com/sigstore/rekor
22
3- go 1.23.6
4-
5- toolchain go1.24.1
3+ go 1.25.0
64
75require (
86 github.com/asaskevich/govalidator v0.0.0-20230301143203-a9d515a09cc2
97 github.com/blang/semver v3.5.1+incompatible
108 github.com/cavaliercoder/go-rpm v0.0.0-20200122174316-8cb9fd9c31a8
119 github.com/go-chi/chi v4.1.2+incompatible
12- github.com/go-openapi/errors v0.22.1
10+ github.com/go-openapi/errors v0.22.2
1311 github.com/go-openapi/loads v0.22.0
1412 github.com/go-openapi/runtime v0.28.0
1513 github.com/go-openapi/spec v0.21.0
1614 github.com/go-openapi/strfmt v0.23.0
17- github.com/go-openapi/swag v0.23 .1
15+ github.com/go-openapi/swag v0.24 .1
1816 github.com/go-openapi/validate v0.24.0
1917 github.com/google/go-cmp v0.7.0
20- github.com/google/rpmpack v0.7.0
18+ github.com/google/rpmpack v0.7.1
2119 github.com/google/trillian v1.7.2
2220 github.com/in-toto/in-toto-golang v0.9.0
2321 github.com/jedisct1/go-minisign v0.0.0-20241212093149-d2f9f49435c7
2422 github.com/mitchellh/go-homedir v1.1.0
2523 github.com/mitchellh/mapstructure v1.5.0
2624 github.com/pkg/errors v0.9.1 // indirect
27- github.com/prometheus/client_golang v1.22.0
25+ github.com/prometheus/client_golang v1.23.2
2826 github.com/rs/cors v1.11.1
2927 github.com/sassoftware/relic v7.2.1+incompatible
30- github.com/secure-systems-lab/go-securesystemslib v0.9.0
28+ github.com/secure-systems-lab/go-securesystemslib v0.9.1
3129 github.com/sigstore/sigstore v1.9.5
32- github.com/spf13/cobra v1.9 .1
33- github.com/spf13/pflag v1.0.6
30+ github.com/spf13/cobra v1.10 .1
31+ github.com/spf13/pflag v1.0.10
3432 github.com/spf13/viper v1.20.1
3533 github.com/theupdateframework/go-tuf v0.7.0
3634 github.com/transparency-dev/merkle v0.0.2
3735 github.com/veraison/go-cose v1.3.0
3836 github.com/zalando/go-keyring v0.2.6 // indirect
3937 go.uber.org/goleak v1.3.0
4038 go.uber.org/zap v1.27.0
41- gocloud.dev v0.40 .0
42- golang.org/x/crypto v0.39 .0
43- golang.org/x/mod v0.25 .0
44- golang.org/x/net v0.41 .0
45- golang.org/x/sync v0.15 .0
46- google.golang.org/genproto v0.0.0-20250528174236-200df99c418a // indirect
47- google.golang.org/grpc v1.73 .0
48- google.golang.org/protobuf v1.36.6
39+ gocloud.dev v0.43 .0
40+ golang.org/x/crypto v0.41 .0
41+ golang.org/x/mod v0.27 .0
42+ golang.org/x/net v0.43 .0
43+ golang.org/x/sync v0.17 .0
44+ google.golang.org/genproto v0.0.0-20250826171959-ef028d996bc1 // indirect
45+ google.golang.org/grpc v1.75 .0
46+ google.golang.org/protobuf v1.36.8
4947 gopkg.in/ini.v1 v1.67.0
50- sigs.k8s.io/release-utils v0.11 .1
51- sigs.k8s.io/yaml v1.5 .0
48+ sigs.k8s.io/release-utils v0.12 .1
49+ sigs.k8s.io/yaml v1.6 .0
5250)
5351
5452require (
5553 cloud.google.com/go/profiler v0.4.3
56- cloud.google.com/go/pubsub v1.49 .0
54+ cloud.google.com/go/pubsub v1.50 .0
5755 github.com/AdamKorcz/go-fuzz-headers-1 v0.0.0-20230919221257-8b5d3ce2d11d
5856 github.com/DATA-DOG/go-sqlmock v1.5.2
5957 github.com/cyberphone/json-canonicalization v0.0.0-20241213102144-19d51d7fe467
6058 github.com/go-redis/redismock/v9 v9.2.0
61- github.com/go-sql-driver/mysql v1.9.2
59+ github.com/go-sql-driver/mysql v1.9.3
6260 github.com/golang/mock v1.7.0-rc.1
6361 github.com/hashicorp/go-cleanhttp v0.5.2
6462 github.com/hashicorp/go-retryablehttp v0.7.8
6563 github.com/jmoiron/sqlx v1.4.0
66- github.com/redis/go-redis/v9 v9.9 .0
64+ github.com/redis/go-redis/v9 v9.10 .0
6765 github.com/sassoftware/relic/v7 v7.6.2
68- github.com/sigstore/protobuf-specs v0.4.2
69- github.com/sigstore/sigstore/pkg/signature/kms/aws v1.9.4
70- github.com/sigstore/sigstore/pkg/signature/kms/azure v1.9.4
71- github.com/sigstore/sigstore/pkg/signature/kms/gcp v1.9.4
72- github.com/sigstore/sigstore/pkg/signature/kms/hashivault v1.9.4
73- github.com/stretchr/testify v1.10.0
66+ github.com/sigstore/protobuf-specs v0.5.0
67+ github.com/sigstore/sigstore/pkg/signature/kms/aws v1.9.5
68+ github.com/sigstore/sigstore/pkg/signature/kms/azure v1.9.5
69+ github.com/sigstore/sigstore/pkg/signature/kms/gcp v1.9.5
70+ github.com/sigstore/sigstore/pkg/signature/kms/hashivault v1.9.5
71+ github.com/stretchr/testify v1.11.1
7472 github.com/tink-crypto/tink-go-awskms/v2 v2.1.0
7573 github.com/tink-crypto/tink-go-gcpkms/v2 v2.2.0
7674 github.com/tink-crypto/tink-go/v2 v2.4.0
77- golang.org/x/exp v0.0.0-20250531010427-b6e5de432a8b
78- google.golang.org/genproto/googleapis/rpc v0.0.0-20250603155806-513f23925822
75+ golang.org/x/exp v0.0.0-20250819193227-8b4c13bb791b
76+ google.golang.org/genproto/googleapis/rpc v0.0.0-20250826171959-ef028d996bc1
7977)
8078
8179require (
8280 cel.dev/expr v0.24.0 // indirect
83- cloud.google.com/go/auth v0.16.2 // indirect
81+ cloud.google.com/go/auth v0.16.5 // indirect
8482)
8583
8684require (
8785 al.essio.dev/pkg/shellescape v1.6.0 // indirect
8886 cloud.google.com/go/auth/oauth2adapt v0.2.8 // indirect
89- cloud.google.com/go/compute/metadata v0.7 .0 // indirect
87+ cloud.google.com/go/compute/metadata v0.8 .0 // indirect
9088 cloud.google.com/go/longrunning v0.6.7 // indirect
9189 cloud.google.com/go/monitoring v1.24.2 // indirect
90+ cloud.google.com/go/pubsub/v2 v2.0.0 // indirect
9291 filippo.io/edwards25519 v1.1.0 // indirect
93- github.com/Azure/azure-sdk-for-go/sdk/azcore v1.18 .0 // indirect
94- github.com/Azure/azure-sdk-for-go/sdk/azidentity v1.10.1 // indirect
95- github.com/Azure/azure-sdk-for-go/sdk/internal v1.11.1 // indirect
92+ github.com/Azure/azure-sdk-for-go/sdk/azcore v1.19 .0 // indirect
93+ github.com/Azure/azure-sdk-for-go/sdk/azidentity v1.11.0 // indirect
94+ github.com/Azure/azure-sdk-for-go/sdk/internal v1.11.2 // indirect
9695 github.com/Azure/azure-sdk-for-go/sdk/security/keyvault/azkeys v1.4.0 // indirect
9796 github.com/Azure/azure-sdk-for-go/sdk/security/keyvault/internal v1.2.0 // indirect
98- github.com/AzureAD/microsoft-authentication-library-for-go v1.4.2 // indirect
99- github.com/GoogleCloudPlatform/opentelemetry-operations-go/detectors/gcp v1.27 .0 // indirect
100- github.com/GoogleCloudPlatform/opentelemetry-operations-go/exporter/metric v0.51 .0 // indirect
101- github.com/GoogleCloudPlatform/opentelemetry-operations-go/internal/resourcemapping v0.51 .0 // indirect
102- github.com/aws/aws-sdk-go v1.55.6 // indirect
103- github.com/aws/aws-sdk-go-v2 v1.36.4 // indirect
104- github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream v1.6.10 // indirect
105- github.com/aws/aws-sdk-go-v2/config v1.29.16 // indirect
106- github.com/aws/aws-sdk-go-v2/credentials v1.17.69 // indirect
107- github.com/aws/aws-sdk-go-v2/feature/ec2/imds v1.16.31 // indirect
108- github.com/aws/aws-sdk-go-v2/feature/s3/manager v1.17.77 // indirect
109- github.com/aws/aws-sdk-go-v2/internal/configsources v1.3.35 // indirect
110- github.com/aws/aws-sdk-go-v2/internal/endpoints/v2 v2.6.35 // indirect
97+ github.com/AzureAD/microsoft-authentication-library-for-go v1.5.0 // indirect
98+ github.com/GoogleCloudPlatform/opentelemetry-operations-go/detectors/gcp v1.29 .0 // indirect
99+ github.com/GoogleCloudPlatform/opentelemetry-operations-go/exporter/metric v0.53 .0 // indirect
100+ github.com/GoogleCloudPlatform/opentelemetry-operations-go/internal/resourcemapping v0.53 .0 // indirect
101+ github.com/aws/aws-sdk-go v1.55.7 // indirect
102+ github.com/aws/aws-sdk-go-v2 v1.38.3 // indirect
103+ github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream v1.7.1 // indirect
104+ github.com/aws/aws-sdk-go-v2/config v1.31.6 // indirect
105+ github.com/aws/aws-sdk-go-v2/credentials v1.18.10 // indirect
106+ github.com/aws/aws-sdk-go-v2/feature/ec2/imds v1.18.6 // indirect
107+ github.com/aws/aws-sdk-go-v2/feature/s3/manager v1.19.4 // indirect
108+ github.com/aws/aws-sdk-go-v2/internal/configsources v1.4.6 // indirect
109+ github.com/aws/aws-sdk-go-v2/internal/endpoints/v2 v2.7.6 // indirect
111110 github.com/aws/aws-sdk-go-v2/internal/ini v1.8.3 // indirect
112- github.com/aws/aws-sdk-go-v2/internal/v4a v1.3.34 // indirect
113- github.com/aws/aws-sdk-go-v2/service/internal/accept-encoding v1.12.3 // indirect
114- github.com/aws/aws-sdk-go-v2/service/internal/checksum v1.7.2 // indirect
115- github.com/aws/aws-sdk-go-v2/service/internal/presigned-url v1.12.16 // indirect
116- github.com/aws/aws-sdk-go-v2/service/internal/s3shared v1.18.15 // indirect
117- github.com/aws/aws-sdk-go-v2/service/kms v1.41 .0 // indirect
118- github.com/aws/aws-sdk-go-v2/service/s3 v1.80.0 // indirect
119- github.com/aws/aws-sdk-go-v2/service/sso v1.25.4 // indirect
120- github.com/aws/aws-sdk-go-v2/service/ssooidc v1.30 .2 // indirect
121- github.com/aws/aws-sdk-go-v2/service/sts v1.33.21 // indirect
122- github.com/aws/smithy-go v1.22.3 // indirect
111+ github.com/aws/aws-sdk-go-v2/internal/v4a v1.4.6 // indirect
112+ github.com/aws/aws-sdk-go-v2/service/internal/accept-encoding v1.13.1 // indirect
113+ github.com/aws/aws-sdk-go-v2/service/internal/checksum v1.8.6 // indirect
114+ github.com/aws/aws-sdk-go-v2/service/internal/presigned-url v1.13.6 // indirect
115+ github.com/aws/aws-sdk-go-v2/service/internal/s3shared v1.19.6 // indirect
116+ github.com/aws/aws-sdk-go-v2/service/kms v1.44 .0 // indirect
117+ github.com/aws/aws-sdk-go-v2/service/s3 v1.87.3 // indirect
118+ github.com/aws/aws-sdk-go-v2/service/sso v1.29.1 // indirect
119+ github.com/aws/aws-sdk-go-v2/service/ssooidc v1.34 .2 // indirect
120+ github.com/aws/aws-sdk-go-v2/service/sts v1.38.2 // indirect
121+ github.com/aws/smithy-go v1.23.0 // indirect
123122 github.com/cavaliergopher/cpio v1.0.1 // indirect
124123 github.com/cenkalti/backoff/v4 v4.3.0 // indirect
125124 github.com/cncf/xds/go v0.0.0-20250501225837-2ac532fd4443 // indirect
@@ -128,57 +127,68 @@ require (
128127 github.com/envoyproxy/go-control-plane/envoy v1.32.4 // indirect
129128 github.com/envoyproxy/protoc-gen-validate v1.2.1 // indirect
130129 github.com/felixge/httpsnoop v1.0.4 // indirect
131- github.com/go-jose/go-jose/v4 v4.0.5 // indirect
130+ github.com/go-jose/go-jose/v4 v4.1.2 // indirect
132131 github.com/go-logr/logr v1.4.3 // indirect
133132 github.com/go-logr/stdr v1.2.2 // indirect
133+ github.com/go-openapi/swag/cmdutils v0.24.0 // indirect
134+ github.com/go-openapi/swag/conv v0.24.0 // indirect
135+ github.com/go-openapi/swag/fileutils v0.24.0 // indirect
136+ github.com/go-openapi/swag/jsonname v0.24.0 // indirect
137+ github.com/go-openapi/swag/jsonutils v0.24.0 // indirect
138+ github.com/go-openapi/swag/loading v0.24.0 // indirect
139+ github.com/go-openapi/swag/mangling v0.24.0 // indirect
140+ github.com/go-openapi/swag/netutils v0.24.0 // indirect
141+ github.com/go-openapi/swag/stringutils v0.24.0 // indirect
142+ github.com/go-openapi/swag/typeutils v0.24.0 // indirect
143+ github.com/go-openapi/swag/yamlutils v0.24.0 // indirect
134144 github.com/go-viper/mapstructure/v2 v2.2.1 // indirect
135- github.com/golang-jwt/jwt/v5 v5.2.2 // indirect
136- github.com/google/pprof v0.0.0-20250602020802-c6617b811d0e // indirect
145+ github.com/golang-jwt/jwt/v5 v5.3.0 // indirect
146+ github.com/google/pprof v0.0.0-20250903194437-c28834ac2320 // indirect
137147 github.com/google/s2a-go v0.1.9 // indirect
138148 github.com/hashicorp/errwrap v1.1.0 // indirect
139149 github.com/hashicorp/go-multierror v1.1.1 // indirect
140150 github.com/hashicorp/go-rootcerts v1.0.2 // indirect
141151 github.com/hashicorp/go-secure-stdlib/parseutil v0.2.0 // indirect
142152 github.com/hashicorp/go-secure-stdlib/strutil v0.1.2 // indirect
143153 github.com/hashicorp/go-sockaddr v1.0.7 // indirect
144- github.com/hashicorp/vault/api v1.16 .0 // indirect
154+ github.com/hashicorp/vault/api v1.20 .0 // indirect
145155 github.com/jellydator/ttlcache/v3 v3.3.0 // indirect
146156 github.com/jmespath/go-jmespath v0.4.1-0.20220621161143-b0104c826a24 // indirect
147157 github.com/klauspost/compress v1.18.0 // indirect
148158 github.com/klauspost/pgzip v1.2.6 // indirect
149159 github.com/kylelemons/godebug v1.1.0 // indirect
150- github.com/mattn/go-sqlite3 v1.14.28 // indirect
160+ github.com/mattn/go-sqlite3 v1.14.32 // indirect
151161 github.com/munnerz/goautoneg v0.0.0-20191010083416-a7dc8b61c822 // indirect
152162 github.com/pkg/browser v0.0.0-20240102092130-5ac0b6a4141c // indirect
153163 github.com/planetscale/vtprotobuf v0.6.1-0.20250313105119-ba97887b0a25 // indirect
154164 github.com/pmezard/go-difflib v1.0.1-0.20181226105442-5d4384ee4fb2 // indirect
155165 github.com/ryanuber/go-glob v1.0.0 // indirect
156- github.com/sagikazarmark/locafero v0.9 .0 // indirect
157- github.com/sourcegraph/conc v0.3.0 // indirect
166+ github.com/sagikazarmark/locafero v0.10 .0 // indirect
167+ github.com/sourcegraph/conc v0.3.1-0.20240121214520-5f936abd7ae8 // indirect
158168 github.com/spiffe/go-spiffe/v2 v2.5.0 // indirect
159169 github.com/zeebo/errs v1.4.0 // indirect
160170 go.opentelemetry.io/auto/sdk v1.1.0 // indirect
161- go.opentelemetry.io/contrib/detectors/gcp v1.36 .0 // indirect
162- go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc v0.61 .0 // indirect
163- go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.61 .0 // indirect
164- go.opentelemetry.io/otel v1.36 .0 // indirect
165- go.opentelemetry.io/otel/metric v1.36 .0 // indirect
166- go.opentelemetry.io/otel/sdk v1.36 .0 // indirect
167- go.opentelemetry.io/otel/sdk/metric v1.36 .0 // indirect
168- go.opentelemetry.io/otel/trace v1.36 .0 // indirect
171+ go.opentelemetry.io/contrib/detectors/gcp v1.37 .0 // indirect
172+ go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc v0.63 .0 // indirect
173+ go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.63 .0 // indirect
174+ go.opentelemetry.io/otel v1.38 .0 // indirect
175+ go.opentelemetry.io/otel/metric v1.38 .0 // indirect
176+ go.opentelemetry.io/otel/sdk v1.38 .0 // indirect
177+ go.opentelemetry.io/otel/sdk/metric v1.38 .0 // indirect
178+ go.opentelemetry.io/otel/trace v1.38 .0 // indirect
169179 go.yaml.in/yaml/v2 v2.4.2 // indirect
170- golang.org/x/text v0.26 .0 // indirect
171- golang.org/x/time v0.12 .0 // indirect
172- google.golang.org/genproto/googleapis/api v0.0.0-20250528174236-200df99c418a // indirect
180+ golang.org/x/text v0.28 .0 // indirect
181+ golang.org/x/time v0.13 .0 // indirect
182+ google.golang.org/genproto/googleapis/api v0.0.0-20250826171959-ef028d996bc1 // indirect
173183 k8s.io/klog/v2 v2.130.1 // indirect
174- software.sslmate.com/src/go-pkcs12 v0.5 .0 // indirect
184+ software.sslmate.com/src/go-pkcs12 v0.6 .0 // indirect
175185)
176186
177187require (
178- cloud.google.com/go v0.121.2 // indirect
188+ cloud.google.com/go v0.122.0 // indirect
179189 cloud.google.com/go/iam v1.5.2 // indirect
180190 cloud.google.com/go/kms v1.22.0 // indirect
181- cloud.google.com/go/storage v1.55 .0 // indirect
191+ cloud.google.com/go/storage v1.56 .0 // indirect
182192 github.com/beorn7/perks v1.0.1 // indirect
183193 github.com/cavaliercoder/badio v0.0.0-20160213150051-ce5280129e9e // indirect
184194 github.com/cespare/xxhash/v2 v2.3.0 // indirect
@@ -188,44 +198,43 @@ require (
188198 github.com/fsnotify/fsnotify v1.9.0 // indirect
189199 github.com/fxamacker/cbor/v2 v2.7.0 // indirect
190200 github.com/go-openapi/analysis v0.23.0 // indirect
191- github.com/go-openapi/jsonpointer v0.21.1 // indirect
192- github.com/go-openapi/jsonreference v0.21.0 // indirect
201+ github.com/go-openapi/jsonpointer v0.22.0 // indirect
202+ github.com/go-openapi/jsonreference v0.21.1 // indirect
193203 github.com/godbus/dbus/v5 v5.1.0 // indirect
194- github.com/golang/groupcache v0.0.0-20241129210726-2c02b8208cf8 // indirect
195- github.com/google/go-containerregistry v0.20.3 // indirect
204+ github.com/google/go-containerregistry v0.20.6 // indirect
196205 github.com/google/uuid v1.6.0 // indirect
197- github.com/google/wire v0.6 .0 // indirect
206+ github.com/google/wire v0.7 .0 // indirect
198207 github.com/googleapis/enterprise-certificate-proxy v0.3.6 // indirect
199- github.com/googleapis/gax-go/v2 v2.14.2 // indirect
200- github.com/hashicorp/hcl v1.0.0 // indirect
208+ github.com/googleapis/gax-go/v2 v2.15.0 // indirect
209+ github.com/hashicorp/hcl v1.0.1-vault-7 // indirect
201210 github.com/howeyc/gopass v0.0.0-20210920133722-c8aef6fb66ef // indirect
202211 github.com/inconshreveable/mousetrap v1.1.0 // indirect
203212 github.com/josharian/intern v1.0.0 // indirect
204- github.com/letsencrypt/boulder v0.0.0-20240620165639-de9c06129bec // indirect
213+ github.com/letsencrypt/boulder v0.20250902.0 // indirect
205214 github.com/mailru/easyjson v0.9.0 // indirect
206215 github.com/oklog/ulid v1.3.1 // indirect
207216 github.com/opencontainers/go-digest v1.0.0 // indirect
208217 github.com/opentracing/opentracing-go v1.2.0 // indirect
209218 github.com/pelletier/go-toml/v2 v2.2.3 // indirect
210219 github.com/prometheus/client_model v0.6.2 // indirect
211- github.com/prometheus/common v0.64.0 // indirect
212- github.com/prometheus/procfs v0.16.1 // indirect
220+ github.com/prometheus/common v0.66.1 // indirect
221+ github.com/prometheus/procfs v0.17.0 // indirect
213222 github.com/shibumi/go-pathspec v1.3.0 // indirect
214223 github.com/spf13/afero v1.14.0 // indirect
215- github.com/spf13/cast v1.9.0 // indirect
224+ github.com/spf13/cast v1.9.2 // indirect
216225 github.com/subosito/gotenv v1.6.0 // indirect
217226 github.com/titanous/rocacheck v0.0.0-20171023193734-afe73141d399 // indirect
218- github.com/ulikunitz/xz v0.5.12 // indirect
227+ github.com/ulikunitz/xz v0.5.15 // indirect
219228 github.com/x448/float16 v0.8.4 // indirect
220- go.mongodb.org/mongo-driver v1.17.3 // indirect
229+ go.mongodb.org/mongo-driver v1.17.4 // indirect
221230 go.opencensus.io v0.24.0 // indirect
222- go.step.sm/crypto v0.67 .0
231+ go.step.sm/crypto v0.70 .0
223232 go.uber.org/multierr v1.11.0 // indirect
224- golang.org/x/oauth2 v0.30 .0 // indirect
225- golang.org/x/sys v0.33 .0 // indirect
226- golang.org/x/term v0.32 .0 // indirect
233+ golang.org/x/oauth2 v0.31 .0 // indirect
234+ golang.org/x/sys v0.36 .0 // indirect
235+ golang.org/x/term v0.34 .0 // indirect
227236 golang.org/x/xerrors v0.0.0-20240903120638-7835f813f4da // indirect
228- google.golang.org/api v0.237 .0
237+ google.golang.org/api v0.248 .0
229238 gopkg.in/yaml.v2 v2.4.0
230239 gopkg.in/yaml.v3 v3.0.1 // indirect
231240)
0 commit comments