Skip to content

Commit b7c23bb

Browse files
committed
chore: fix dependabot alerts
Signed-off-by: Ramkumar Chinchani <[email protected]>
1 parent 293f424 commit b7c23bb

File tree

8 files changed

+93
-79
lines changed

8 files changed

+93
-79
lines changed

.github/workflows/codeql-analysis.yml

+3-3
Original file line numberDiff line numberDiff line change
@@ -53,7 +53,7 @@ jobs:
5353

5454
# Initializes the CodeQL tools for scanning.
5555
- name: Initialize CodeQL
56-
uses: github/codeql-action/[email protected].15
56+
uses: github/codeql-action/[email protected].16
5757
with:
5858
languages: ${{ matrix.language }}
5959
# If you wish to specify custom queries, you can do so here or in a config file.
@@ -64,7 +64,7 @@ jobs:
6464
# Autobuild attempts to build any compiled languages (C/C++, C#, or Java).
6565
# If this step fails, then you should remove it and run the build manually (see below)
6666
- name: Autobuild
67-
uses: github/codeql-action/[email protected].15
67+
uses: github/codeql-action/[email protected].16
6868

6969
# ℹ️ Command-line programs to run using the OS shell.
7070
# 📚 https://git.io/JvXDl
@@ -77,4 +77,4 @@ jobs:
7777
# make release
7878

7979
- name: Perform CodeQL Analysis
80-
uses: github/codeql-action/[email protected].15
80+
uses: github/codeql-action/[email protected].16

.github/workflows/publish.yaml

+2-2
Original file line numberDiff line numberDiff line change
@@ -237,7 +237,7 @@ jobs:
237237
TRIVY_USERNAME: ${{ github.actor }}
238238
TRIVY_PASSWORD: ${{ secrets.GITHUB_TOKEN }}
239239
- name: Upload Trivy scan results to GitHub Security tab
240-
uses: github/codeql-action/[email protected].15
240+
uses: github/codeql-action/[email protected].16
241241
with:
242242
sarif_file: 'trivy-results.sarif'
243243

@@ -274,7 +274,7 @@ jobs:
274274
TRIVY_USERNAME: ${{ github.actor }}
275275
TRIVY_PASSWORD: ${{ secrets.GITHUB_TOKEN }}
276276
- name: Upload Trivy scan results to GitHub Security tab
277-
uses: github/codeql-action/[email protected].15
277+
uses: github/codeql-action/[email protected].16
278278
with:
279279
sarif_file: 'trivy-results.sarif'
280280

.github/workflows/scorecards.yaml

+1-1
Original file line numberDiff line numberDiff line change
@@ -57,6 +57,6 @@ jobs:
5757

5858
# Upload the results to GitHub's code scanning dashboard.
5959
- name: "Upload to code-scanning"
60-
uses: github/codeql-action/[email protected].15
60+
uses: github/codeql-action/[email protected].16
6161
with:
6262
sarif_file: results.sarif

go.mod

+17-17
Original file line numberDiff line numberDiff line change
@@ -3,16 +3,16 @@ module zotregistry.dev/zot
33
go 1.24
44

55
require (
6-
github.com/99designs/gqlgen v0.17.70
6+
github.com/99designs/gqlgen v0.17.72
77
github.com/Masterminds/semver v1.5.0
88
github.com/alicebob/miniredis/v2 v2.34.0
99
github.com/aquasecurity/trivy v0.61.1
1010
github.com/aquasecurity/trivy-db v0.0.0-20250227071930-8bd8a9b89e2d
11-
github.com/aws/aws-sdk-go v1.55.6
11+
github.com/aws/aws-sdk-go v1.55.7
1212
github.com/aws/aws-sdk-go-v2 v1.36.3
1313
github.com/aws/aws-sdk-go-v2/config v1.29.14
14-
github.com/aws/aws-sdk-go-v2/feature/dynamodb/attributevalue v1.18.12
15-
github.com/aws/aws-sdk-go-v2/service/dynamodb v1.42.4
14+
github.com/aws/aws-sdk-go-v2/feature/dynamodb/attributevalue v1.18.13
15+
github.com/aws/aws-sdk-go-v2/service/dynamodb v1.43.0
1616
github.com/aws/aws-sdk-go-v2/service/ecr v1.43.3
1717
github.com/aws/aws-sdk-go-v2/service/secretsmanager v1.35.4
1818
github.com/aws/aws-secretsmanager-caching-go v1.2.0
@@ -44,7 +44,7 @@ require (
4444
github.com/mitchellh/mapstructure v1.5.1-0.20231216201459-8508981c8b6c
4545
github.com/nmcclain/ldap v0.0.0-20210720162743-7f8d1e44eeba
4646
github.com/notaryproject/notation-core-go v1.3.0
47-
github.com/notaryproject/notation-go v1.3.1
47+
github.com/notaryproject/notation-go v1.3.2
4848
github.com/olekukonko/tablewriter v0.0.5
4949
github.com/opencontainers/distribution-spec/specs-go v0.0.0-20250123160558-a139cc423184
5050
github.com/opencontainers/go-digest v1.0.0
@@ -54,11 +54,11 @@ require (
5454
github.com/prometheus/client_golang v1.22.0
5555
github.com/prometheus/client_model v0.6.2
5656
github.com/redis/go-redis/v9 v9.7.3
57-
github.com/regclient/regclient v0.8.2
57+
github.com/regclient/regclient v0.8.3
5858
github.com/rs/zerolog v1.34.0
5959
github.com/santhosh-tekuri/jsonschema/v5 v5.3.1
6060
github.com/sigstore/cosign/v2 v2.5.0
61-
github.com/sigstore/sigstore v1.9.3
61+
github.com/sigstore/sigstore v1.9.4
6262
github.com/smartystreets/goconvey v1.8.1
6363
github.com/spf13/cast v1.7.1
6464
github.com/spf13/cobra v1.9.1
@@ -108,7 +108,7 @@ require (
108108
github.com/Azure/go-autorest/tracing v0.6.0 // indirect
109109
github.com/Azure/go-ntlmssp v0.0.0-20221128193559-754e69321358 // indirect
110110
github.com/AzureAD/microsoft-authentication-library-for-go v1.3.3 // indirect
111-
github.com/BurntSushi/toml v1.4.0 // indirect
111+
github.com/BurntSushi/toml v1.5.0 // indirect
112112
github.com/CycloneDX/cyclonedx-go v0.9.2 // indirect
113113
github.com/DataDog/zstd v1.5.5 // indirect
114114
github.com/GoogleCloudPlatform/docker-credential-gcr v2.0.5+incompatible // indirect
@@ -194,7 +194,7 @@ require (
194194
github.com/cncf/xds/go v0.0.0-20241223141626-cff3c89139a3 // indirect
195195
github.com/cockroachdb/apd/v3 v3.2.1 // indirect
196196
github.com/common-nighthawk/go-figure v0.0.0-20210622060536-734e95fb86be // indirect
197-
github.com/containerd/cgroups/v3 v3.0.3 // indirect
197+
github.com/containerd/cgroups/v3 v3.0.5 // indirect
198198
github.com/containerd/containerd v1.7.27 // indirect
199199
github.com/containerd/containerd/api v1.8.0 // indirect
200200
github.com/containerd/containerd/v2 v2.0.4 // indirect
@@ -208,8 +208,8 @@ require (
208208
github.com/containerd/stargz-snapshotter/estargz v0.16.3 // indirect
209209
github.com/containerd/ttrpc v1.2.7 // indirect
210210
github.com/containerd/typeurl/v2 v2.2.3 // indirect
211-
github.com/containers/storage v1.57.2 // indirect
212-
github.com/coreos/go-oidc/v3 v3.13.0 // indirect
211+
github.com/containers/storage v1.58.0 // indirect
212+
github.com/coreos/go-oidc/v3 v3.14.1 // indirect
213213
github.com/cpuguy83/go-md2man/v2 v2.0.6 // indirect
214214
github.com/cyberphone/json-canonicalization v0.0.0-20231217050601-ba74d44ecf5f // indirect
215215
github.com/cyphar/filepath-securejoin v0.4.1 // indirect
@@ -352,7 +352,7 @@ require (
352352
github.com/moby/sys/mountinfo v0.7.2 // indirect
353353
github.com/moby/sys/sequential v0.6.0 // indirect
354354
github.com/moby/sys/signal v0.7.1 // indirect
355-
github.com/moby/sys/user v0.3.0 // indirect
355+
github.com/moby/sys/user v0.4.0 // indirect
356356
github.com/moby/sys/userns v0.1.0 // indirect
357357
github.com/moby/term v0.5.2 // indirect
358358
github.com/modern-go/concurrent v0.0.0-20180306012644-bacd9c7ef1dd // indirect
@@ -373,8 +373,8 @@ require (
373373
github.com/onsi/ginkgo/v2 v2.22.2 // indirect
374374
github.com/onsi/gomega v1.36.2 // indirect
375375
github.com/open-policy-agent/opa v1.2.0 // indirect
376-
github.com/opencontainers/runtime-spec v1.2.0 // indirect
377-
github.com/opencontainers/selinux v1.11.1 // indirect
376+
github.com/opencontainers/runtime-spec v1.2.1 // indirect
377+
github.com/opencontainers/selinux v1.12.0 // indirect
378378
github.com/opentracing/opentracing-go v1.2.0 // indirect
379379
github.com/openvex/discovery v0.1.1-0.20240802171711-7c54efc57553 // indirect
380380
github.com/openvex/go-vex v0.2.5 // indirect
@@ -440,7 +440,7 @@ require (
440440
github.com/twitchtv/twirp v8.1.3+incompatible // indirect
441441
github.com/ulikunitz/xz v0.5.12 // indirect
442442
github.com/urfave/cli/v2 v2.27.6 // indirect
443-
github.com/vbatts/tar-split v0.11.7 // indirect
443+
github.com/vbatts/tar-split v0.12.1 // indirect
444444
github.com/veraison/go-cose v1.3.0 // indirect
445445
github.com/vmihailenco/msgpack/v5 v5.4.1 // indirect
446446
github.com/vmihailenco/tagparser/v2 v2.0.0 // indirect
@@ -491,13 +491,13 @@ require (
491491
go.uber.org/zap v1.27.0 // indirect
492492
golang.org/x/exp v0.0.0-20250305212735-054e65f0b394 // indirect
493493
golang.org/x/mod v0.24.0 // indirect
494-
golang.org/x/net v0.38.0 // indirect
494+
golang.org/x/net v0.39.0 // indirect
495495
golang.org/x/sync v0.13.0 // indirect
496496
golang.org/x/sys v0.32.0 // indirect
497497
golang.org/x/term v0.31.0 // indirect
498498
golang.org/x/text v0.24.0 // indirect
499499
golang.org/x/time v0.11.0 // indirect
500-
golang.org/x/tools v0.31.0 // indirect
500+
golang.org/x/tools v0.32.0 // indirect
501501
golang.org/x/xerrors v0.0.0-20240716161551-93cc26a95ae9 // indirect
502502
google.golang.org/api v0.227.0 // indirect
503503
google.golang.org/genproto v0.0.0-20250303144028-a0af3efb3deb // indirect

0 commit comments

Comments
 (0)