11module github.com/sigstore/cosign/v3
22
3- go 1.25.7
3+ go 1.26.0
44
55require (
66 cuelang.org/go v0.16.0
@@ -12,11 +12,11 @@ require (
1212 github.com/depcheck-test/depcheck-test v0.0.0-20220607135614-199033aaa936
1313 github.com/digitorus/timestamp v0.0.0-20250524132541-c45532741eea
1414 github.com/dustin/go-humanize v1.0.1
15- github.com/go-jose/go-jose/v4 v4.1.3
16- github.com/go-openapi/runtime v0.29.3
17- github.com/go-openapi/strfmt v0.26.1
18- github.com/go-openapi/swag/conv v0.25.5
19- github.com/go-piv/piv-go/v2 v2.5 .0
15+ github.com/go-jose/go-jose/v4 v4.1.4
16+ github.com/go-openapi/runtime v0.29.4
17+ github.com/go-openapi/strfmt v0.26.2
18+ github.com/go-openapi/swag/conv v0.26.0
19+ github.com/go-piv/piv-go/v2 v2.6 .0
2020 github.com/google/certificate-transparency-go v1.3.3
2121 github.com/google/go-cmp v0.7.0
2222 github.com/google/go-containerregistry v0.21.3
@@ -30,18 +30,18 @@ require (
3030 github.com/moby/term v0.5.2
3131 github.com/mozillazg/docker-credential-acr-helper v0.4.0
3232 github.com/nozzle/throttler v0.0.0-20180817012639-2ea982251481
33- github.com/open-policy-agent/opa v1.15.0
34- github.com/secure-systems-lab/go-securesystemslib v0.10 .0
33+ github.com/open-policy-agent/opa v1.16.1
34+ github.com/secure-systems-lab/go-securesystemslib v0.11 .0
3535 github.com/sigstore/fulcio v1.8.5
36- github.com/sigstore/protobuf-specs v0.5.0
36+ github.com/sigstore/protobuf-specs v0.5.1
3737 github.com/sigstore/rekor v1.5.1
3838 github.com/sigstore/rekor-tiles/v2 v2.0.1
39- github.com/sigstore/sigstore v1.10.4
39+ github.com/sigstore/sigstore v1.10.5
4040 github.com/sigstore/sigstore-go v1.1.4
41- github.com/sigstore/sigstore/pkg/signature/kms/aws v1.10.4
42- github.com/sigstore/sigstore/pkg/signature/kms/azure v1.10.4
43- github.com/sigstore/sigstore/pkg/signature/kms/gcp v1.10.4
44- github.com/sigstore/sigstore/pkg/signature/kms/hashivault v1.10.4
41+ github.com/sigstore/sigstore/pkg/signature/kms/aws v1.10.5
42+ github.com/sigstore/sigstore/pkg/signature/kms/azure v1.10.5
43+ github.com/sigstore/sigstore/pkg/signature/kms/gcp v1.10.5
44+ github.com/sigstore/sigstore/pkg/signature/kms/hashivault v1.10.5
4545 github.com/sigstore/timestamp-authority/v2 v2.0.4
4646 github.com/spf13/cobra v1.10.2
4747 github.com/spf13/pflag v1.0.10
@@ -52,35 +52,35 @@ require (
5252 github.com/transparency-dev/merkle v0.0.2
5353 github.com/withfig/autocomplete-tools/integrations/cobra v1.2.1
5454 gitlab.com/gitlab-org/api/client-go v1.23.0
55- golang.org/x/crypto v0.49 .0
55+ golang.org/x/crypto v0.50 .0
5656 golang.org/x/oauth2 v0.36.0
5757 golang.org/x/sync v0.20.0
58- golang.org/x/term v0.41 .0
59- google.golang.org/api v0.273 .0
60- google.golang.org/protobuf v1.36.11
61- k8s.io/api v0.35.3
62- k8s.io/apimachinery v0.35.3
63- k8s.io/client-go v0.35.3
58+ golang.org/x/term v0.42 .0
59+ google.golang.org/api v0.277 .0
60+ google.golang.org/protobuf v1.36.12-0.20260120151049-f2248ac996af
61+ k8s.io/api v0.36.0
62+ k8s.io/apimachinery v0.36.0
63+ k8s.io/client-go v0.36.0
6464 k8s.io/utils v0.0.0-20260319190234-28399d86e0b5
65- sigs.k8s.io/release-utils v0.12.3
65+ sigs.k8s.io/release-utils v0.12.4
6666)
6767
6868require (
6969 cloud.google.com/go v0.123.0 // indirect
70- cloud.google.com/go/auth v0.19 .0 // indirect
70+ cloud.google.com/go/auth v0.20 .0 // indirect
7171 cloud.google.com/go/auth/oauth2adapt v0.2.8 // indirect
7272 cloud.google.com/go/compute/metadata v0.9.0 // indirect
73- cloud.google.com/go/iam v1.6 .0 // indirect
74- cloud.google.com/go/kms v1.26 .0 // indirect
75- cloud.google.com/go/longrunning v0.8 .0 // indirect
73+ cloud.google.com/go/iam v1.10 .0 // indirect
74+ cloud.google.com/go/kms v1.28 .0 // indirect
75+ cloud.google.com/go/longrunning v0.12 .0 // indirect
7676 cuelabs.dev/go/oci/ociregistry v0.0.0-20251212221603-3adeb8663819 // indirect
7777 filippo.io/edwards25519 v1.2.0 // indirect
7878 github.com/AliyunContainerService/ack-ram-tool/pkg/credentials/provider v0.20.0 // indirect
7979 github.com/AliyunContainerService/ack-ram-tool/pkg/ecsmetadata v0.0.10 // indirect
8080 github.com/Azure/azure-sdk-for-go v68.0.0+incompatible // indirect
81- github.com/Azure/azure-sdk-for-go/sdk/azcore v1.21.0 // indirect
81+ github.com/Azure/azure-sdk-for-go/sdk/azcore v1.21.1 // indirect
8282 github.com/Azure/azure-sdk-for-go/sdk/azidentity v1.13.1 // indirect
83- github.com/Azure/azure-sdk-for-go/sdk/internal v1.11.2 // indirect
83+ github.com/Azure/azure-sdk-for-go/sdk/internal v1.12.0 // indirect
8484 github.com/Azure/azure-sdk-for-go/sdk/security/keyvault/azkeys v1.4.0 // indirect
8585 github.com/Azure/azure-sdk-for-go/sdk/security/keyvault/internal v1.2.0 // indirect
8686 github.com/Azure/go-ansiterm v0.0.0-20250102033503-faa5f7b0171c // indirect
@@ -92,7 +92,7 @@ require (
9292 github.com/Azure/go-autorest/autorest/date v0.3.1 // indirect
9393 github.com/Azure/go-autorest/logger v0.2.2 // indirect
9494 github.com/Azure/go-autorest/tracing v0.6.1 // indirect
95- github.com/AzureAD/microsoft-authentication-library-for-go v1.7.0 // indirect
95+ github.com/AzureAD/microsoft-authentication-library-for-go v1.7.1 // indirect
9696 github.com/Microsoft/go-winio v0.6.2 // indirect
9797 github.com/agnivade/levenshtein v1.2.1 // indirect
9898 github.com/alibabacloud-go/alibabacloud-gateway-spi v0.0.5 // indirect
@@ -109,26 +109,26 @@ require (
109109 github.com/aliyun/credentials-go v1.4.12 // indirect
110110 github.com/asaskevich/govalidator v0.0.0-20230301143203-a9d515a09cc2 // indirect
111111 github.com/aws/aws-sdk-go v1.55.8 // indirect
112- github.com/aws/aws-sdk-go-v2 v1.41.5 // indirect
113- github.com/aws/aws-sdk-go-v2/config v1.32.12 // indirect
114- github.com/aws/aws-sdk-go-v2/credentials v1.19.13 // indirect
115- github.com/aws/aws-sdk-go-v2/feature/ec2/imds v1.18.21 // indirect
116- github.com/aws/aws-sdk-go-v2/internal/configsources v1.4.21 // indirect
117- github.com/aws/aws-sdk-go-v2/internal/endpoints/v2 v2.7.21 // indirect
118- github.com/aws/aws-sdk-go-v2/internal/ini v1.8.6 // indirect
112+ github.com/aws/aws-sdk-go-v2 v1.41.7 // indirect
113+ github.com/aws/aws-sdk-go-v2/config v1.32.16 // indirect
114+ github.com/aws/aws-sdk-go-v2/credentials v1.19.16 // indirect
115+ github.com/aws/aws-sdk-go-v2/feature/ec2/imds v1.18.23 // indirect
116+ github.com/aws/aws-sdk-go-v2/internal/configsources v1.4.23 // indirect
117+ github.com/aws/aws-sdk-go-v2/internal/endpoints/v2 v2.7.23 // indirect
118+ github.com/aws/aws-sdk-go-v2/internal/v4a v1.4.24 // indirect
119119 github.com/aws/aws-sdk-go-v2/service/ecr v1.55.3 // indirect
120120 github.com/aws/aws-sdk-go-v2/service/ecrpublic v1.38.10 // indirect
121- github.com/aws/aws-sdk-go-v2/service/internal/accept-encoding v1.13.7 // indirect
122- github.com/aws/aws-sdk-go-v2/service/internal/presigned-url v1.13.21 // indirect
123- github.com/aws/aws-sdk-go-v2/service/kms v1.50.3 // indirect
124- github.com/aws/aws-sdk-go-v2/service/signin v1.0.9 // indirect
125- github.com/aws/aws-sdk-go-v2/service/sso v1.30.14 // indirect
126- github.com/aws/aws-sdk-go-v2/service/ssooidc v1.35.18 // indirect
127- github.com/aws/aws-sdk-go-v2/service/sts v1.41.10 // indirect
128- github.com/aws/smithy-go v1.24.2 // indirect
121+ github.com/aws/aws-sdk-go-v2/service/internal/accept-encoding v1.13.9 // indirect
122+ github.com/aws/aws-sdk-go-v2/service/internal/presigned-url v1.13.23 // indirect
123+ github.com/aws/aws-sdk-go-v2/service/kms v1.51.0 // indirect
124+ github.com/aws/aws-sdk-go-v2/service/signin v1.0.11 // indirect
125+ github.com/aws/aws-sdk-go-v2/service/sso v1.30.17 // indirect
126+ github.com/aws/aws-sdk-go-v2/service/ssooidc v1.35.21 // indirect
127+ github.com/aws/aws-sdk-go-v2/service/sts v1.42.1 // indirect
128+ github.com/aws/smithy-go v1.25.1 // indirect
129129 github.com/beorn7/perks v1.0.1 // indirect
130130 github.com/blang/semver v3.5.1+incompatible // indirect
131- github.com/buildkite/go-pipeline v0.16 .0 // indirect
131+ github.com/buildkite/go-pipeline v0.17 .0 // indirect
132132 github.com/buildkite/interpolate v0.1.5 // indirect
133133 github.com/buildkite/roko v1.4.0 // indirect
134134 github.com/cenkalti/backoff/v4 v4.3.0 // indirect
@@ -142,41 +142,41 @@ require (
142142 github.com/coreos/go-oidc/v3 v3.17.0 // indirect
143143 github.com/cpuguy83/go-md2man/v2 v2.0.7 // indirect
144144 github.com/davecgh/go-spew v1.1.2-0.20180830191138-d8f796af33cc // indirect
145- github.com/decred/dcrd/dcrec/secp256k1/v4 v4.4.0 // indirect
145+ github.com/decred/dcrd/dcrec/secp256k1/v4 v4.4.1 // indirect
146146 github.com/digitorus/pkcs7 v0.0.0-20250730155240-ffadbf3f398c // indirect
147147 github.com/dimchansky/utfbom v1.1.1 // indirect
148148 github.com/docker/cli v29.3.0+incompatible // indirect
149149 github.com/docker/distribution v2.8.3+incompatible // indirect
150- github.com/docker/docker-credential-helpers v0.9.5 // indirect
150+ github.com/docker/docker-credential-helpers v0.9.6 // indirect
151151 github.com/docker/go-units v0.5.0 // indirect
152152 github.com/emicklei/go-restful/v3 v3.13.0 // indirect
153153 github.com/emicklei/proto v1.14.3 // indirect
154154 github.com/felixge/httpsnoop v1.0.4 // indirect
155- github.com/fsnotify/fsnotify v1.9 .0 // indirect
155+ github.com/fsnotify/fsnotify v1.10 .0 // indirect
156156 github.com/fxamacker/cbor/v2 v2.9.0 // indirect
157157 github.com/go-chi/chi v4.1.2+incompatible // indirect
158158 github.com/go-chi/chi/v5 v5.2.5 // indirect
159159 github.com/go-logr/logr v1.4.3 // indirect
160160 github.com/go-logr/stdr v1.2.2 // indirect
161161 github.com/go-openapi/analysis v0.25.0 // indirect
162162 github.com/go-openapi/errors v0.22.7 // indirect
163- github.com/go-openapi/jsonpointer v0.22.5 // indirect
163+ github.com/go-openapi/jsonpointer v0.23.1 // indirect
164164 github.com/go-openapi/jsonreference v0.21.5 // indirect
165165 github.com/go-openapi/loads v0.23.3 // indirect
166166 github.com/go-openapi/spec v0.22.4 // indirect
167- github.com/go-openapi/swag v0.25.5 // indirect
168- github.com/go-openapi/swag/cmdutils v0.25.5 // indirect
169- github.com/go-openapi/swag/fileutils v0.25.5 // indirect
170- github.com/go-openapi/swag/jsonname v0.25.5 // indirect
171- github.com/go-openapi/swag/jsonutils v0.25.5 // indirect
172- github.com/go-openapi/swag/loading v0.25.5 // indirect
173- github.com/go-openapi/swag/mangling v0.25.5 // indirect
174- github.com/go-openapi/swag/netutils v0.25.5 // indirect
175- github.com/go-openapi/swag/stringutils v0.25.5 // indirect
176- github.com/go-openapi/swag/typeutils v0.25.5 // indirect
177- github.com/go-openapi/swag/yamlutils v0.25.5 // indirect
167+ github.com/go-openapi/swag v0.26.0 // indirect
168+ github.com/go-openapi/swag/cmdutils v0.26.0 // indirect
169+ github.com/go-openapi/swag/fileutils v0.26.0 // indirect
170+ github.com/go-openapi/swag/jsonname v0.26.0 // indirect
171+ github.com/go-openapi/swag/jsonutils v0.26.0 // indirect
172+ github.com/go-openapi/swag/loading v0.26.0 // indirect
173+ github.com/go-openapi/swag/mangling v0.26.0 // indirect
174+ github.com/go-openapi/swag/netutils v0.26.0 // indirect
175+ github.com/go-openapi/swag/stringutils v0.26.0 // indirect
176+ github.com/go-openapi/swag/typeutils v0.26.0 // indirect
177+ github.com/go-openapi/swag/yamlutils v0.26.0 // indirect
178178 github.com/go-openapi/validate v0.25.2 // indirect
179- github.com/go-sql-driver/mysql v1.9.3 // indirect
179+ github.com/go-sql-driver/mysql v1.10.0 // indirect
180180 github.com/go-viper/mapstructure/v2 v2.5.0 // indirect
181181 github.com/gobwas/glob v0.2.3 // indirect
182182 github.com/goccy/go-json v0.10.6 // indirect
@@ -186,11 +186,11 @@ require (
186186 github.com/google/gnostic-models v0.7.1 // indirect
187187 github.com/google/go-querystring v1.2.0 // indirect
188188 github.com/google/s2a-go v0.1.9 // indirect
189- github.com/google/trillian v1.7.2 // indirect
189+ github.com/google/trillian v1.7.3 // indirect
190190 github.com/google/uuid v1.6.0 // indirect
191- github.com/googleapis/enterprise-certificate-proxy v0.3.14 // indirect
192- github.com/googleapis/gax-go/v2 v2.19 .0 // indirect
193- github.com/grpc-ecosystem/grpc-gateway/v2 v2.27.7 // indirect
191+ github.com/googleapis/enterprise-certificate-proxy v0.3.15 // indirect
192+ github.com/googleapis/gax-go/v2 v2.22 .0 // indirect
193+ github.com/grpc-ecosystem/grpc-gateway/v2 v2.28.0 // indirect
194194 github.com/hashicorp/errwrap v1.1.0 // indirect
195195 github.com/hashicorp/go-cleanhttp v0.5.2 // indirect
196196 github.com/hashicorp/go-multierror v1.1.1 // indirect
@@ -205,22 +205,22 @@ require (
205205 github.com/inconshreveable/mousetrap v1.1.0 // indirect
206206 github.com/jackc/pgpassfile v1.0.0 // indirect
207207 github.com/jackc/pgservicefile v0.0.0-20240606120523-5a60cdf6a761 // indirect
208- github.com/jackc/pgx/v5 v5.8.0 // indirect
208+ github.com/jackc/pgx/v5 v5.9.1 // indirect
209209 github.com/jackc/puddle/v2 v2.2.2 // indirect
210210 github.com/jedisct1/go-minisign v0.0.0-20241212093149-d2f9f49435c7 // indirect
211211 github.com/jellydator/ttlcache/v3 v3.4.0 // indirect
212212 github.com/jmespath/go-jmespath v0.4.1-0.20220621161143-b0104c826a24 // indirect
213213 github.com/json-iterator/go v1.1.12 // indirect
214- github.com/klauspost/compress v1.18.5 // indirect
214+ github.com/klauspost/compress v1.18.6 // indirect
215215 github.com/kylelemons/godebug v1.1.0 // indirect
216216 github.com/lestrrat-go/blackmagic v1.0.4 // indirect
217- github.com/lestrrat-go/dsig v1.0 .0 // indirect
217+ github.com/lestrrat-go/dsig v1.3 .0 // indirect
218218 github.com/lestrrat-go/dsig-secp256k1 v1.0.0 // indirect
219219 github.com/lestrrat-go/httpcc v1.0.1 // indirect
220- github.com/lestrrat-go/httprc/v3 v3.0.2 // indirect
221- github.com/lestrrat-go/jwx/v3 v3.0.13 // indirect
220+ github.com/lestrrat-go/httprc/v3 v3.0.5 // indirect
221+ github.com/lestrrat-go/jwx/v3 v3.1.0 // indirect
222222 github.com/lestrrat-go/option/v2 v2.0.0 // indirect
223- github.com/letsencrypt/boulder v0.20260324 .0 // indirect
223+ github.com/letsencrypt/boulder v0.20260428 .0 // indirect
224224 github.com/mitchellh/go-homedir v1.1.0 // indirect
225225 github.com/mitchellh/mapstructure v1.5.1-0.20231216201459-8508981c8b6c // indirect
226226 github.com/modern-go/concurrent v0.0.0-20180306012644-bacd9c7ef1dd // indirect
@@ -240,7 +240,7 @@ require (
240240 github.com/prometheus/client_model v0.6.2 // indirect
241241 github.com/prometheus/common v0.67.5 // indirect
242242 github.com/prometheus/procfs v0.20.1 // indirect
243- github.com/protocolbuffers/txtpbfmt v0.0.0-20260217160748-a481f6a22f94 // indirect
243+ github.com/protocolbuffers/txtpbfmt v0.0.0-20260420112717-c39628bde8b5 // indirect
244244 github.com/rcrowley/go-metrics v0.0.0-20250401214520-65e299d6c5c9 // indirect
245245 github.com/rogpeppe/go-internal v1.14.1 // indirect
246246 github.com/rs/cors v1.11.1 // indirect
@@ -267,41 +267,41 @@ require (
267267 github.com/transparency-dev/formats v0.1.0 // indirect
268268 github.com/urfave/negroni v1.0.0 // indirect
269269 github.com/valyala/fastjson v1.6.10 // indirect
270- github.com/vbatts/tar-split v0.12.2 // indirect
270+ github.com/vbatts/tar-split v0.12.3 // indirect
271271 github.com/vektah/gqlparser/v2 v2.5.32 // indirect
272272 github.com/x448/float16 v0.8.4 // indirect
273273 github.com/xeipuuv/gojsonpointer v0.0.0-20190905194746-02993c407bfb // indirect
274274 github.com/xeipuuv/gojsonreference v0.0.0-20180127040603-bd5ef7bd5415 // indirect
275275 github.com/yashtewari/glob-intersection v0.2.0 // indirect
276276 go.opentelemetry.io/auto/sdk v1.2.1 // indirect
277- go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc v0.67 .0 // indirect
278- go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.67 .0 // indirect
279- go.opentelemetry.io/otel v1.42 .0 // indirect
280- go.opentelemetry.io/otel/metric v1.42 .0 // indirect
281- go.opentelemetry.io/otel/trace v1.42 .0 // indirect
282- go.step.sm/crypto v0.77.1 // indirect
277+ go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc v0.68 .0 // indirect
278+ go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.68 .0 // indirect
279+ go.opentelemetry.io/otel v1.43 .0 // indirect
280+ go.opentelemetry.io/otel/metric v1.43 .0 // indirect
281+ go.opentelemetry.io/otel/trace v1.43 .0 // indirect
282+ go.step.sm/crypto v0.77.9 // indirect
283283 go.uber.org/multierr v1.11.0 // indirect
284284 go.uber.org/zap v1.27.1 // indirect
285- go.yaml.in/yaml/v2 v2.4.3 // indirect
285+ go.yaml.in/yaml/v2 v2.4.4 // indirect
286286 go.yaml.in/yaml/v3 v3.0.4 // indirect
287- golang.org/x/mod v0.34 .0 // indirect
288- golang.org/x/net v0.52 .0 // indirect
289- golang.org/x/sys v0.42 .0 // indirect
290- golang.org/x/text v0.35 .0 // indirect
287+ golang.org/x/mod v0.35 .0 // indirect
288+ golang.org/x/net v0.53 .0 // indirect
289+ golang.org/x/sys v0.43 .0 // indirect
290+ golang.org/x/text v0.36 .0 // indirect
291291 golang.org/x/time v0.15.0 // indirect
292- golang.org/x/tools v0.43 .0 // indirect
292+ golang.org/x/tools v0.44 .0 // indirect
293293 google.golang.org/genproto v0.0.0-20260319201613-d00831a3d3e7 // indirect
294- google.golang.org/genproto/googleapis/api v0.0.0-20260319201613-d00831a3d3e7 // indirect
295- google.golang.org/genproto/googleapis/rpc v0.0.0-20260319201613-d00831a3d3e7 // indirect
296- google.golang.org/grpc v1.79.3 // indirect
294+ google.golang.org/genproto/googleapis/api v0.0.0-20260427160629-7cedc36a6bc4 // indirect
295+ google.golang.org/genproto/googleapis/rpc v0.0.0-20260427160629-7cedc36a6bc4 // indirect
296+ google.golang.org/grpc v1.80.0 // indirect
297297 gopkg.in/evanphx/json-patch.v4 v4.13.0 // indirect
298298 gopkg.in/inf.v0 v0.9.1 // indirect
299299 gopkg.in/ini.v1 v1.67.1 // indirect
300300 gopkg.in/yaml.v3 v3.0.1 // indirect
301- k8s.io/klog/v2 v2.130.1 // indirect
302- k8s.io/kube-openapi v0.0.0-20260319004828-5883c5ee87b9 // indirect
301+ k8s.io/klog/v2 v2.140.0 // indirect
302+ k8s.io/kube-openapi v0.0.0-20260502001324-b7f5293f4787 // indirect
303303 sigs.k8s.io/json v0.0.0-20250730193827-2d320260d730 // indirect
304304 sigs.k8s.io/randfill v1.0.0 // indirect
305- sigs.k8s.io/structured-merge-diff/v6 v6.3.0 // indirect
305+ sigs.k8s.io/structured-merge-diff/v6 v6.3.2 // indirect
306306 sigs.k8s.io/yaml v1.6.0 // indirect
307307)
0 commit comments