11module github.com/sigstore/rekor
22
3- go 1.23.6
3+ go 1.24.0
44
5- toolchain go1.24.1
5+ toolchain go1.24.6
66
77require (
88 github.com/asaskevich/govalidator v0.0.0-20230301143203-a9d515a09cc2
99 github.com/blang/semver v3.5.1+incompatible
1010 github.com/cavaliercoder/go-rpm v0.0.0-20200122174316-8cb9fd9c31a8
1111 github.com/go-chi/chi v4.1.2+incompatible
12- github.com/go-openapi/errors v0.22.1
12+ github.com/go-openapi/errors v0.22.2
1313 github.com/go-openapi/loads v0.22.0
1414 github.com/go-openapi/runtime v0.28.0
1515 github.com/go-openapi/spec v0.21.0
1616 github.com/go-openapi/strfmt v0.23.0
1717 github.com/go-openapi/swag v0.23.1
1818 github.com/go-openapi/validate v0.24.0
1919 github.com/google/go-cmp v0.7.0
20- github.com/google/rpmpack v0.7.0
20+ github.com/google/rpmpack v0.7.1
2121 github.com/google/trillian v1.7.2
2222 github.com/in-toto/in-toto-golang v0.9.0
2323 github.com/jedisct1/go-minisign v0.0.0-20241212093149-d2f9f49435c7
2424 github.com/mitchellh/go-homedir v1.1.0
2525 github.com/mitchellh/mapstructure v1.5.0
2626 github.com/pkg/errors v0.9.1 // indirect
27- github.com/prometheus/client_golang v1.22 .0
27+ github.com/prometheus/client_golang v1.23 .0
2828 github.com/rs/cors v1.11.1
2929 github.com/sassoftware/relic v7.2.1+incompatible
30- github.com/secure-systems-lab/go-securesystemslib v0.9.0
30+ github.com/secure-systems-lab/go-securesystemslib v0.9.1
3131 github.com/sigstore/sigstore v1.9.5
3232 github.com/spf13/cobra v1.9.1
33- github.com/spf13/pflag v1.0.6
33+ github.com/spf13/pflag v1.0.7
3434 github.com/spf13/viper v1.20.1
3535 github.com/theupdateframework/go-tuf v0.7.0
3636 github.com/transparency-dev/merkle v0.0.2
3737 github.com/veraison/go-cose v1.3.0
3838 github.com/zalando/go-keyring v0.2.6 // indirect
3939 go.uber.org/goleak v1.3.0
4040 go.uber.org/zap v1.27.0
41- gocloud.dev v0.40 .0
42- golang.org/x/crypto v0.39 .0
43- golang.org/x/mod v0.25 .0
44- golang.org/x/net v0.41 .0
45- golang.org/x/sync v0.15 .0
46- google.golang.org/genproto v0.0.0-20250528174236-200df99c418a // indirect
47- google.golang.org/grpc v1.73.0
48- google.golang.org/protobuf v1.36.6
41+ gocloud.dev v0.43 .0
42+ golang.org/x/crypto v0.41 .0
43+ golang.org/x/mod v0.27 .0
44+ golang.org/x/net v0.43 .0
45+ golang.org/x/sync v0.16 .0
46+ google.golang.org/genproto v0.0.0-20250818200422-3122310a409c // indirect
47+ google.golang.org/grpc v1.74.2
48+ google.golang.org/protobuf v1.36.7
4949 gopkg.in/ini.v1 v1.67.0
50- sigs.k8s.io/release-utils v0.11 .1
50+ sigs.k8s.io/release-utils v0.12 .1
5151 sigs.k8s.io/yaml v1.5.0
5252)
5353
5454require (
5555 cloud.google.com/go/profiler v0.4.3
56- cloud.google.com/go/pubsub v1.49 .0
56+ cloud.google.com/go/pubsub v1.50 .0
5757 github.com/AdamKorcz/go-fuzz-headers-1 v0.0.0-20230919221257-8b5d3ce2d11d
5858 github.com/DATA-DOG/go-sqlmock v1.5.2
5959 github.com/cyberphone/json-canonicalization v0.0.0-20241213102144-19d51d7fe467
6060 github.com/go-redis/redismock/v9 v9.2.0
61- github.com/go-sql-driver/mysql v1.9.2
61+ github.com/go-sql-driver/mysql v1.9.3
6262 github.com/golang/mock v1.7.0-rc.1
6363 github.com/hashicorp/go-cleanhttp v0.5.2
6464 github.com/hashicorp/go-retryablehttp v0.7.8
6565 github.com/jmoiron/sqlx v1.4.0
66- github.com/redis/go-redis/v9 v9.9 .0
66+ github.com/redis/go-redis/v9 v9.10 .0
6767 github.com/sassoftware/relic/v7 v7.6.2
68- github.com/sigstore/protobuf-specs v0.4.2
69- github.com/sigstore/sigstore/pkg/signature/kms/aws v1.9.4
70- github.com/sigstore/sigstore/pkg/signature/kms/azure v1.9.4
71- github.com/sigstore/sigstore/pkg/signature/kms/gcp v1.9.4
72- github.com/sigstore/sigstore/pkg/signature/kms/hashivault v1.9.4
68+ github.com/sigstore/protobuf-specs v0.5.0
69+ github.com/sigstore/sigstore/pkg/signature/kms/aws v1.9.5
70+ github.com/sigstore/sigstore/pkg/signature/kms/azure v1.9.5
71+ github.com/sigstore/sigstore/pkg/signature/kms/gcp v1.9.5
72+ github.com/sigstore/sigstore/pkg/signature/kms/hashivault v1.9.5
7373 github.com/stretchr/testify v1.10.0
7474 github.com/tink-crypto/tink-go-awskms/v2 v2.1.0
7575 github.com/tink-crypto/tink-go-gcpkms/v2 v2.2.0
7676 github.com/tink-crypto/tink-go/v2 v2.4.0
77- golang.org/x/exp v0.0.0-20250531010427-b6e5de432a8b
78- google.golang.org/genproto/googleapis/rpc v0.0.0-20250603155806-513f23925822
77+ golang.org/x/exp v0.0.0-20250819193227-8b4c13bb791b
78+ google.golang.org/genproto/googleapis/rpc v0.0.0-20250818200422-3122310a409c
7979)
8080
8181require (
8282 cel.dev/expr v0.24.0 // indirect
83- cloud.google.com/go/auth v0.16.2 // indirect
83+ cloud.google.com/go/auth v0.16.5 // indirect
8484)
8585
8686require (
8787 al.essio.dev/pkg/shellescape v1.6.0 // indirect
8888 cloud.google.com/go/auth/oauth2adapt v0.2.8 // indirect
89- cloud.google.com/go/compute/metadata v0.7 .0 // indirect
89+ cloud.google.com/go/compute/metadata v0.8 .0 // indirect
9090 cloud.google.com/go/longrunning v0.6.7 // indirect
9191 cloud.google.com/go/monitoring v1.24.2 // indirect
92+ cloud.google.com/go/pubsub/v2 v2.0.0 // indirect
9293 filippo.io/edwards25519 v1.1.0 // indirect
93- github.com/Azure/azure-sdk-for-go/sdk/azcore v1.18 .0 // indirect
94- github.com/Azure/azure-sdk-for-go/sdk/azidentity v1.10.1 // indirect
95- github.com/Azure/azure-sdk-for-go/sdk/internal v1.11.1 // indirect
94+ github.com/Azure/azure-sdk-for-go/sdk/azcore v1.19 .0 // indirect
95+ github.com/Azure/azure-sdk-for-go/sdk/azidentity v1.11.0 // indirect
96+ github.com/Azure/azure-sdk-for-go/sdk/internal v1.11.2 // indirect
9697 github.com/Azure/azure-sdk-for-go/sdk/security/keyvault/azkeys v1.4.0 // indirect
9798 github.com/Azure/azure-sdk-for-go/sdk/security/keyvault/internal v1.2.0 // indirect
9899 github.com/AzureAD/microsoft-authentication-library-for-go v1.4.2 // indirect
99- github.com/GoogleCloudPlatform/opentelemetry-operations-go/detectors/gcp v1.27 .0 // indirect
100- github.com/GoogleCloudPlatform/opentelemetry-operations-go/exporter/metric v0.51 .0 // indirect
101- github.com/GoogleCloudPlatform/opentelemetry-operations-go/internal/resourcemapping v0.51 .0 // indirect
102- github.com/aws/aws-sdk-go v1.55.6 // indirect
103- github.com/aws/aws-sdk-go-v2 v1.36.4 // indirect
104- github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream v1.6.10 // indirect
105- github.com/aws/aws-sdk-go-v2/config v1.29.16 // indirect
106- github.com/aws/aws-sdk-go-v2/credentials v1.17.69 // indirect
107- github.com/aws/aws-sdk-go-v2/feature/ec2/imds v1.16.31 // indirect
108- github.com/aws/aws-sdk-go-v2/feature/s3/manager v1.17.77 // indirect
109- github.com/aws/aws-sdk-go-v2/internal/configsources v1.3.35 // indirect
110- github.com/aws/aws-sdk-go-v2/internal/endpoints/v2 v2.6.35 // indirect
100+ github.com/GoogleCloudPlatform/opentelemetry-operations-go/detectors/gcp v1.29 .0 // indirect
101+ github.com/GoogleCloudPlatform/opentelemetry-operations-go/exporter/metric v0.53 .0 // indirect
102+ github.com/GoogleCloudPlatform/opentelemetry-operations-go/internal/resourcemapping v0.53 .0 // indirect
103+ github.com/aws/aws-sdk-go v1.55.7 // indirect
104+ github.com/aws/aws-sdk-go-v2 v1.38.1 // indirect
105+ github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream v1.7.0 // indirect
106+ github.com/aws/aws-sdk-go-v2/config v1.31.2 // indirect
107+ github.com/aws/aws-sdk-go-v2/credentials v1.18.6 // indirect
108+ github.com/aws/aws-sdk-go-v2/feature/ec2/imds v1.18.4 // indirect
109+ github.com/aws/aws-sdk-go-v2/feature/s3/manager v1.19.0 // indirect
110+ github.com/aws/aws-sdk-go-v2/internal/configsources v1.4.4 // indirect
111+ github.com/aws/aws-sdk-go-v2/internal/endpoints/v2 v2.7.4 // indirect
111112 github.com/aws/aws-sdk-go-v2/internal/ini v1.8.3 // indirect
112- github.com/aws/aws-sdk-go-v2/internal/v4a v1.3.34 // indirect
113- github.com/aws/aws-sdk-go-v2/service/internal/accept-encoding v1.12.3 // indirect
114- github.com/aws/aws-sdk-go-v2/service/internal/checksum v1.7.2 // indirect
115- github.com/aws/aws-sdk-go-v2/service/internal/presigned-url v1.12.16 // indirect
116- github.com/aws/aws-sdk-go-v2/service/internal/s3shared v1.18.15 // indirect
117- github.com/aws/aws-sdk-go-v2/service/kms v1.41 .0 // indirect
118- github.com/aws/aws-sdk-go-v2/service/s3 v1.80.0 // indirect
119- github.com/aws/aws-sdk-go-v2/service/sso v1.25.4 // indirect
120- github.com/aws/aws-sdk-go-v2/service/ssooidc v1.30 .2 // indirect
121- github.com/aws/aws-sdk-go-v2/service/sts v1.33.21 // indirect
122- github.com/aws/smithy-go v1.22.3 // indirect
113+ github.com/aws/aws-sdk-go-v2/internal/v4a v1.4.4 // indirect
114+ github.com/aws/aws-sdk-go-v2/service/internal/accept-encoding v1.13.0 // indirect
115+ github.com/aws/aws-sdk-go-v2/service/internal/checksum v1.8.4 // indirect
116+ github.com/aws/aws-sdk-go-v2/service/internal/presigned-url v1.13.4 // indirect
117+ github.com/aws/aws-sdk-go-v2/service/internal/s3shared v1.19.4 // indirect
118+ github.com/aws/aws-sdk-go-v2/service/kms v1.44 .0 // indirect
119+ github.com/aws/aws-sdk-go-v2/service/s3 v1.87.1 // indirect
120+ github.com/aws/aws-sdk-go-v2/service/sso v1.28.2 // indirect
121+ github.com/aws/aws-sdk-go-v2/service/ssooidc v1.33 .2 // indirect
122+ github.com/aws/aws-sdk-go-v2/service/sts v1.38.0 // indirect
123+ github.com/aws/smithy-go v1.22.5 // indirect
123124 github.com/cavaliergopher/cpio v1.0.1 // indirect
124125 github.com/cenkalti/backoff/v4 v4.3.0 // indirect
125126 github.com/cncf/xds/go v0.0.0-20250501225837-2ac532fd4443 // indirect
@@ -128,57 +129,57 @@ require (
128129 github.com/envoyproxy/go-control-plane/envoy v1.32.4 // indirect
129130 github.com/envoyproxy/protoc-gen-validate v1.2.1 // indirect
130131 github.com/felixge/httpsnoop v1.0.4 // indirect
131- github.com/go-jose/go-jose/v4 v4.0.5 // indirect
132+ github.com/go-jose/go-jose/v4 v4.1.2 // indirect
132133 github.com/go-logr/logr v1.4.3 // indirect
133134 github.com/go-logr/stdr v1.2.2 // indirect
134135 github.com/go-viper/mapstructure/v2 v2.2.1 // indirect
135- github.com/golang-jwt/jwt/v5 v5.2.2 // indirect
136- github.com/google/pprof v0.0.0-20250602020802-c6617b811d0e // indirect
136+ github.com/golang-jwt/jwt/v5 v5.3.0 // indirect
137+ github.com/google/pprof v0.0.0-20250820193118-f64d9cf942d6 // indirect
137138 github.com/google/s2a-go v0.1.9 // indirect
138139 github.com/hashicorp/errwrap v1.1.0 // indirect
139140 github.com/hashicorp/go-multierror v1.1.1 // indirect
140141 github.com/hashicorp/go-rootcerts v1.0.2 // indirect
141142 github.com/hashicorp/go-secure-stdlib/parseutil v0.2.0 // indirect
142143 github.com/hashicorp/go-secure-stdlib/strutil v0.1.2 // indirect
143144 github.com/hashicorp/go-sockaddr v1.0.7 // indirect
144- github.com/hashicorp/vault/api v1.16 .0 // indirect
145+ github.com/hashicorp/vault/api v1.20 .0 // indirect
145146 github.com/jellydator/ttlcache/v3 v3.3.0 // indirect
146147 github.com/jmespath/go-jmespath v0.4.1-0.20220621161143-b0104c826a24 // indirect
147148 github.com/klauspost/compress v1.18.0 // indirect
148149 github.com/klauspost/pgzip v1.2.6 // indirect
149150 github.com/kylelemons/godebug v1.1.0 // indirect
150- github.com/mattn/go-sqlite3 v1.14.28 // indirect
151+ github.com/mattn/go-sqlite3 v1.14.32 // indirect
151152 github.com/munnerz/goautoneg v0.0.0-20191010083416-a7dc8b61c822 // indirect
152153 github.com/pkg/browser v0.0.0-20240102092130-5ac0b6a4141c // indirect
153154 github.com/planetscale/vtprotobuf v0.6.1-0.20250313105119-ba97887b0a25 // indirect
154155 github.com/pmezard/go-difflib v1.0.1-0.20181226105442-5d4384ee4fb2 // indirect
155156 github.com/ryanuber/go-glob v1.0.0 // indirect
156- github.com/sagikazarmark/locafero v0.9 .0 // indirect
157- github.com/sourcegraph/conc v0.3.0 // indirect
157+ github.com/sagikazarmark/locafero v0.10 .0 // indirect
158+ github.com/sourcegraph/conc v0.3.1-0.20240121214520-5f936abd7ae8 // indirect
158159 github.com/spiffe/go-spiffe/v2 v2.5.0 // indirect
159160 github.com/zeebo/errs v1.4.0 // indirect
160161 go.opentelemetry.io/auto/sdk v1.1.0 // indirect
161- go.opentelemetry.io/contrib/detectors/gcp v1.36 .0 // indirect
162- go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc v0.61 .0 // indirect
163- go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.61 .0 // indirect
164- go.opentelemetry.io/otel v1.36 .0 // indirect
165- go.opentelemetry.io/otel/metric v1.36 .0 // indirect
166- go.opentelemetry.io/otel/sdk v1.36 .0 // indirect
167- go.opentelemetry.io/otel/sdk/metric v1.36 .0 // indirect
168- go.opentelemetry.io/otel/trace v1.36 .0 // indirect
162+ go.opentelemetry.io/contrib/detectors/gcp v1.37 .0 // indirect
163+ go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc v0.62 .0 // indirect
164+ go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.62 .0 // indirect
165+ go.opentelemetry.io/otel v1.37 .0 // indirect
166+ go.opentelemetry.io/otel/metric v1.37 .0 // indirect
167+ go.opentelemetry.io/otel/sdk v1.37 .0 // indirect
168+ go.opentelemetry.io/otel/sdk/metric v1.37 .0 // indirect
169+ go.opentelemetry.io/otel/trace v1.37 .0 // indirect
169170 go.yaml.in/yaml/v2 v2.4.2 // indirect
170- golang.org/x/text v0.26 .0 // indirect
171+ golang.org/x/text v0.28 .0 // indirect
171172 golang.org/x/time v0.12.0 // indirect
172- google.golang.org/genproto/googleapis/api v0.0.0-20250528174236-200df99c418a // indirect
173+ google.golang.org/genproto/googleapis/api v0.0.0-20250818200422-3122310a409c // indirect
173174 k8s.io/klog/v2 v2.130.1 // indirect
174- software.sslmate.com/src/go-pkcs12 v0.5 .0 // indirect
175+ software.sslmate.com/src/go-pkcs12 v0.6 .0 // indirect
175176)
176177
177178require (
178- cloud.google.com/go v0.121.2 // indirect
179+ cloud.google.com/go v0.121.6 // indirect
179180 cloud.google.com/go/iam v1.5.2 // indirect
180181 cloud.google.com/go/kms v1.22.0 // indirect
181- cloud.google.com/go/storage v1.55 .0 // indirect
182+ cloud.google.com/go/storage v1.56 .0 // indirect
182183 github.com/beorn7/perks v1.0.1 // indirect
183184 github.com/cavaliercoder/badio v0.0.0-20160213150051-ce5280129e9e // indirect
184185 github.com/cespare/xxhash/v2 v2.3.0 // indirect
@@ -188,44 +189,43 @@ require (
188189 github.com/fsnotify/fsnotify v1.9.0 // indirect
189190 github.com/fxamacker/cbor/v2 v2.7.0 // indirect
190191 github.com/go-openapi/analysis v0.23.0 // indirect
191- github.com/go-openapi/jsonpointer v0.21.1 // indirect
192+ github.com/go-openapi/jsonpointer v0.21.2 // indirect
192193 github.com/go-openapi/jsonreference v0.21.0 // indirect
193194 github.com/godbus/dbus/v5 v5.1.0 // indirect
194- github.com/golang/groupcache v0.0.0-20241129210726-2c02b8208cf8 // indirect
195- github.com/google/go-containerregistry v0.20.3 // indirect
195+ github.com/google/go-containerregistry v0.20.6 // indirect
196196 github.com/google/uuid v1.6.0 // indirect
197- github.com/google/wire v0.6 .0 // indirect
197+ github.com/google/wire v0.7 .0 // indirect
198198 github.com/googleapis/enterprise-certificate-proxy v0.3.6 // indirect
199- github.com/googleapis/gax-go/v2 v2.14.2 // indirect
200- github.com/hashicorp/hcl v1.0.0 // indirect
199+ github.com/googleapis/gax-go/v2 v2.15.0 // indirect
200+ github.com/hashicorp/hcl v1.0.1-vault-7 // indirect
201201 github.com/howeyc/gopass v0.0.0-20210920133722-c8aef6fb66ef // indirect
202202 github.com/inconshreveable/mousetrap v1.1.0 // indirect
203203 github.com/josharian/intern v1.0.0 // indirect
204- github.com/letsencrypt/boulder v0.0.0-20240620165639-de9c06129bec // indirect
204+ github.com/letsencrypt/boulder v0.20250819.0 // indirect
205205 github.com/mailru/easyjson v0.9.0 // indirect
206206 github.com/oklog/ulid v1.3.1 // indirect
207207 github.com/opencontainers/go-digest v1.0.0 // indirect
208208 github.com/opentracing/opentracing-go v1.2.0 // indirect
209209 github.com/pelletier/go-toml/v2 v2.2.3 // indirect
210210 github.com/prometheus/client_model v0.6.2 // indirect
211- github.com/prometheus/common v0.64 .0 // indirect
212- github.com/prometheus/procfs v0.16.1 // indirect
211+ github.com/prometheus/common v0.65 .0 // indirect
212+ github.com/prometheus/procfs v0.17.0 // indirect
213213 github.com/shibumi/go-pathspec v1.3.0 // indirect
214214 github.com/spf13/afero v1.14.0 // indirect
215- github.com/spf13/cast v1.9.0 // indirect
215+ github.com/spf13/cast v1.9.2 // indirect
216216 github.com/subosito/gotenv v1.6.0 // indirect
217217 github.com/titanous/rocacheck v0.0.0-20171023193734-afe73141d399 // indirect
218- github.com/ulikunitz/xz v0.5.12 // indirect
218+ github.com/ulikunitz/xz v0.5.13 // indirect
219219 github.com/x448/float16 v0.8.4 // indirect
220- go.mongodb.org/mongo-driver v1.17.3 // indirect
220+ go.mongodb.org/mongo-driver v1.17.4 // indirect
221221 go.opencensus.io v0.24.0 // indirect
222- go.step.sm/crypto v0.67 .0
222+ go.step.sm/crypto v0.70 .0
223223 go.uber.org/multierr v1.11.0 // indirect
224224 golang.org/x/oauth2 v0.30.0 // indirect
225- golang.org/x/sys v0.33 .0 // indirect
226- golang.org/x/term v0.32 .0 // indirect
225+ golang.org/x/sys v0.35 .0 // indirect
226+ golang.org/x/term v0.34 .0 // indirect
227227 golang.org/x/xerrors v0.0.0-20240903120638-7835f813f4da // indirect
228- google.golang.org/api v0.237 .0
228+ google.golang.org/api v0.248 .0
229229 gopkg.in/yaml.v2 v2.4.0
230230 gopkg.in/yaml.v3 v3.0.1 // indirect
231231)
0 commit comments