11module github.com/sigstore/fulcio
22
3- go 1.24
4-
5- toolchain go1.24.4
3+ go 1.25.0
64
75require (
8- chainguard.dev/go-grpc-kit v0.17.11
9- chainguard.dev/sdk v0.1.29
10- cloud.google.com/go/security v1.19.0
6+ chainguard.dev/go-grpc-kit v0.17.15
7+ chainguard.dev/sdk v0.1.41
8+ cloud.google.com/go/security v1.19.2
119 github.com/PaesslerAG/jsonpath v0.1.1
1210 github.com/ThalesGroup/crypto11 v1.4.1
1311 github.com/asaskevich/govalidator v0.0.0-20230301143203-a9d515a09cc2
14- github.com/coreos/go-oidc/v3 v3.14.1
12+ github.com/coreos/go-oidc/v3 v3.15.0
1513 github.com/fsnotify/fsnotify v1.9.0
16- github.com/go-jose/go-jose/v4 v4.1.1
14+ github.com/go-jose/go-jose/v4 v4.1.2
1715 github.com/google/certificate-transparency-go v1.3.2
1816 github.com/google/go-cmp v0.7.0
1917 github.com/grpc-ecosystem/go-grpc-middleware v1.4.0
2018 github.com/grpc-ecosystem/go-grpc-prometheus v1.2.1-0.20230405093142-a5446fa24890
21- github.com/grpc-ecosystem/grpc-gateway/v2 v2.27.1
19+ github.com/grpc-ecosystem/grpc-gateway/v2 v2.27.2
2220 github.com/hashicorp/golang-lru/v2 v2.0.7
2321 github.com/magiconair/properties v1.8.10
24- github.com/prometheus/client_golang v1.22.0
22+ github.com/prometheus/client_golang v1.23.2
2523 github.com/prometheus/client_model v0.6.2
26- github.com/prometheus/common v0.65.0
24+ github.com/prometheus/common v0.66.1
2725 github.com/rs/cors v1.11.1
2826 github.com/sigstore/protobuf-specs v0.5.0
2927 github.com/sigstore/sigstore v1.9.5
3028 github.com/sigstore/sigstore/pkg/signature/kms/aws v1.9.5
3129 github.com/sigstore/sigstore/pkg/signature/kms/azure v1.9.5
3230 github.com/sigstore/sigstore/pkg/signature/kms/gcp v1.9.5
3331 github.com/sigstore/sigstore/pkg/signature/kms/hashivault v1.9.5
34- github.com/spf13/cobra v1.9 .1
35- github.com/spf13/pflag v1.0.7
36- github.com/spf13/viper v1.20.1
32+ github.com/spf13/cobra v1.10 .1
33+ github.com/spf13/pflag v1.0.10
34+ github.com/spf13/viper v1.21.0
3735 github.com/spiffe/go-spiffe/v2 v2.5.0
38- github.com/stretchr/testify v1.10.0
36+ github.com/stretchr/testify v1.11.1
3937 github.com/tink-crypto/tink-go-awskms/v2 v2.1.0
4038 github.com/tink-crypto/tink-go-gcpkms/v2 v2.2.0
4139 github.com/tink-crypto/tink-go/v2 v2.4.0
42- go.step.sm/crypto v0.67 .0
40+ go.step.sm/crypto v0.70 .0
4341 go.uber.org/zap v1.27.0
4442 goa.design/goa/v3 v3.21.1
45- google.golang.org/api v0.242 .0
46- google.golang.org/genproto/googleapis/api v0.0.0-20250715232539-7130f93afb79
47- google.golang.org/grpc v1.73.0
48- google.golang.org/protobuf v1.36.6
43+ google.golang.org/api v0.250 .0
44+ google.golang.org/genproto/googleapis/api v0.0.0-20250922171735-9219d122eba9
45+ google.golang.org/grpc v1.75.1
46+ google.golang.org/protobuf v1.36.9
4947 gopkg.in/yaml.v3 v3.0.1
50- sigs.k8s.io/release-utils v0.12.0
48+ sigs.k8s.io/release-utils v0.12.2
5149)
5250
5351require (
54- cloud.google.com/go v0.121.4 // indirect
55- cloud.google.com/go/auth v0.16.3 // indirect
52+ cloud.google.com/go v0.123.0 // indirect
53+ cloud.google.com/go/auth v0.16.5 // indirect
5654 cloud.google.com/go/auth/oauth2adapt v0.2.8 // indirect
57- cloud.google.com/go/compute/metadata v0.7 .0 // indirect
55+ cloud.google.com/go/compute/metadata v0.9 .0 // indirect
5856 cloud.google.com/go/iam v1.5.2 // indirect
59- cloud.google.com/go/kms v1.22 .0 // indirect
57+ cloud.google.com/go/kms v1.23 .0 // indirect
6058 cloud.google.com/go/longrunning v0.6.7 // indirect
6159 dario.cat/mergo v1.0.2 // indirect
6260 filippo.io/edwards25519 v1.1.0 // indirect
63- github.com/Azure/azure-sdk-for-go/sdk/azcore v1.18 .1 // indirect
64- github.com/Azure/azure-sdk-for-go/sdk/azidentity v1.10.1 // indirect
65- github.com/Azure/azure-sdk-for-go/sdk/internal v1.11.1 // indirect
61+ github.com/Azure/azure-sdk-for-go/sdk/azcore v1.19 .1 // indirect
62+ github.com/Azure/azure-sdk-for-go/sdk/azidentity v1.12.0 // indirect
63+ github.com/Azure/azure-sdk-for-go/sdk/internal v1.11.2 // indirect
6664 github.com/Azure/azure-sdk-for-go/sdk/security/keyvault/azkeys v1.4.0 // indirect
6765 github.com/Azure/azure-sdk-for-go/sdk/security/keyvault/internal v1.2.0 // indirect
68- github.com/AzureAD/microsoft-authentication-library-for-go v1.4.2 // indirect
66+ github.com/AzureAD/microsoft-authentication-library-for-go v1.5.0 // indirect
6967 github.com/Masterminds/goutils v1.1.1 // indirect
7068 github.com/Masterminds/semver/v3 v3.3.1 // indirect
7169 github.com/Masterminds/sprig/v3 v3.3.0 // indirect
7270 github.com/PaesslerAG/gval v1.2.4 // indirect
7371 github.com/aws/aws-sdk-go v1.55.7 // indirect
74- github.com/aws/aws-sdk-go-v2 v1.36.6 // indirect
75- github.com/aws/aws-sdk-go-v2/config v1.29.17 // indirect
76- github.com/aws/aws-sdk-go-v2/credentials v1.17.71 // indirect
77- github.com/aws/aws-sdk-go-v2/feature/ec2/imds v1.16.33 // indirect
78- github.com/aws/aws-sdk-go-v2/internal/configsources v1.3.37 // indirect
79- github.com/aws/aws-sdk-go-v2/internal/endpoints/v2 v2.6.37 // indirect
72+ github.com/aws/aws-sdk-go-v2 v1.39.1 // indirect
73+ github.com/aws/aws-sdk-go-v2/config v1.31.0 // indirect
74+ github.com/aws/aws-sdk-go-v2/credentials v1.18.14 // indirect
75+ github.com/aws/aws-sdk-go-v2/feature/ec2/imds v1.18.8 // indirect
76+ github.com/aws/aws-sdk-go-v2/internal/configsources v1.4.8 // indirect
77+ github.com/aws/aws-sdk-go-v2/internal/endpoints/v2 v2.7.8 // indirect
8078 github.com/aws/aws-sdk-go-v2/internal/ini v1.8.3 // indirect
81- github.com/aws/aws-sdk-go-v2/service/internal/accept-encoding v1.12.4 // indirect
82- github.com/aws/aws-sdk-go-v2/service/internal/presigned-url v1.12.18 // indirect
83- github.com/aws/aws-sdk-go-v2/service/kms v1.41 .0 // indirect
84- github.com/aws/aws-sdk-go-v2/service/sso v1.25.6 // indirect
85- github.com/aws/aws-sdk-go-v2/service/ssooidc v1.30.4 // indirect
86- github.com/aws/aws-sdk-go-v2/service/sts v1.34.1 // indirect
87- github.com/aws/smithy-go v1.22.4 // indirect
79+ github.com/aws/aws-sdk-go-v2/service/internal/accept-encoding v1.13.1 // indirect
80+ github.com/aws/aws-sdk-go-v2/service/internal/presigned-url v1.13.8 // indirect
81+ github.com/aws/aws-sdk-go-v2/service/kms v1.44 .0 // indirect
82+ github.com/aws/aws-sdk-go-v2/service/sso v1.29.4 // indirect
83+ github.com/aws/aws-sdk-go-v2/service/ssooidc v1.35.0 // indirect
84+ github.com/aws/aws-sdk-go-v2/service/sts v1.38.5 // indirect
85+ github.com/aws/smithy-go v1.23.0 // indirect
8886 github.com/beorn7/perks v1.0.1 // indirect
8987 github.com/cenkalti/backoff/v4 v4.3.0 // indirect
90- github.com/cenkalti/backoff/v5 v5.0.2 // indirect
88+ github.com/cenkalti/backoff/v5 v5.0.3 // indirect
9189 github.com/cespare/xxhash/v2 v2.3.0 // indirect
9290 github.com/chainguard-dev/clog v1.7.0 // indirect
9391 github.com/common-nighthawk/go-figure v0.0.0-20210622060536-734e95fb86be // indirect
@@ -96,14 +94,16 @@ require (
9694 github.com/go-jose/go-jose/v3 v3.0.4 // indirect
9795 github.com/go-logr/logr v1.4.3 // indirect
9896 github.com/go-logr/stdr v1.2.2 // indirect
99- github.com/go-viper/mapstructure/v2 v2.2.1 // indirect
100- github.com/golang-jwt/jwt/v5 v5.2.2 // indirect
97+ github.com/go-viper/mapstructure/v2 v2.4.0 // indirect
98+ github.com/golang-jwt/jwt/v5 v5.3.0 // indirect
10199 github.com/golang/protobuf v1.5.4 // indirect
102100 github.com/google/go-containerregistry v0.20.6 // indirect
103101 github.com/google/s2a-go v0.1.9 // indirect
104102 github.com/google/uuid v1.6.0 // indirect
105103 github.com/googleapis/enterprise-certificate-proxy v0.3.6 // indirect
106104 github.com/googleapis/gax-go/v2 v2.15.0 // indirect
105+ github.com/grpc-ecosystem/go-grpc-middleware/providers/prometheus v1.1.0 // indirect
106+ github.com/grpc-ecosystem/go-grpc-middleware/v2 v2.3.2 // indirect
107107 github.com/hashicorp/errwrap v1.1.0 // indirect
108108 github.com/hashicorp/go-cleanhttp v0.5.2 // indirect
109109 github.com/hashicorp/go-multierror v1.1.1 // indirect
@@ -113,56 +113,57 @@ require (
113113 github.com/hashicorp/go-secure-stdlib/strutil v0.1.2 // indirect
114114 github.com/hashicorp/go-sockaddr v1.0.7 // indirect
115115 github.com/hashicorp/hcl v1.0.1-vault-7 // indirect
116- github.com/hashicorp/vault/api v1.20 .0 // indirect
116+ github.com/hashicorp/vault/api v1.21 .0 // indirect
117117 github.com/huandu/xstrings v1.5.0 // indirect
118118 github.com/inconshreveable/mousetrap v1.1.0 // indirect
119119 github.com/jellydator/ttlcache/v3 v3.3.0 // indirect
120120 github.com/jmespath/go-jmespath v0.4.1-0.20220621161143-b0104c826a24 // indirect
121121 github.com/kylelemons/godebug v1.1.0 // indirect
122- github.com/letsencrypt/boulder v0.0.0-20240620165639-de9c06129bec // indirect
122+ github.com/letsencrypt/boulder v0.20250922.0 // indirect
123123 github.com/miekg/pkcs11 v1.1.1 // indirect
124124 github.com/mitchellh/copystructure v1.2.0 // indirect
125125 github.com/mitchellh/go-homedir v1.1.0 // indirect
126126 github.com/mitchellh/mapstructure v1.5.0 // indirect
127127 github.com/mitchellh/reflectwalk v1.0.2 // indirect
128128 github.com/munnerz/goautoneg v0.0.0-20191010083416-a7dc8b61c822 // indirect
129129 github.com/opencontainers/go-digest v1.0.0 // indirect
130- github.com/pelletier/go-toml/v2 v2.2.3 // indirect
130+ github.com/pelletier/go-toml/v2 v2.2.4 // indirect
131131 github.com/pkg/browser v0.0.0-20240102092130-5ac0b6a4141c // indirect
132132 github.com/pkg/errors v0.9.1 // indirect
133133 github.com/pmezard/go-difflib v1.0.1-0.20181226105442-5d4384ee4fb2 // indirect
134134 github.com/prometheus/procfs v0.17.0 // indirect
135135 github.com/ryanuber/go-glob v1.0.0 // indirect
136- github.com/sagikazarmark/locafero v0.9 .0 // indirect
137- github.com/secure-systems-lab/go-securesystemslib v0.9.0 // indirect
136+ github.com/sagikazarmark/locafero v0.12 .0 // indirect
137+ github.com/secure-systems-lab/go-securesystemslib v0.9.1 // indirect
138138 github.com/segmentio/ksuid v1.0.4 // indirect
139139 github.com/shopspring/decimal v1.4.0 // indirect
140140 github.com/skratchdot/open-golang v0.0.0-20200116055534-eef842397966 // indirect
141- github.com/sourcegraph/conc v0.3.0 // indirect
142- github.com/spf13/afero v1.14.0 // indirect
143- github.com/spf13/cast v1.9.2 // indirect
141+ github.com/spf13/afero v1.15.0 // indirect
142+ github.com/spf13/cast v1.10.0 // indirect
144143 github.com/subosito/gotenv v1.6.0 // indirect
145144 github.com/thales-e-security/pool v0.0.2 // indirect
146145 github.com/titanous/rocacheck v0.0.0-20171023193734-afe73141d399 // indirect
147- go.opentelemetry.io/auto/sdk v1.1.0 // indirect
148- go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc v0.62 .0 // indirect
149- go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.62 .0 // indirect
150- go.opentelemetry.io/otel v1.37 .0 // indirect
151- go.opentelemetry.io/otel/exporters/otlp/otlptrace v1.36 .0 // indirect
152- go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc v1.36 .0 // indirect
153- go.opentelemetry.io/otel/metric v1.37 .0 // indirect
154- go.opentelemetry.io/otel/sdk v1.37 .0 // indirect
155- go.opentelemetry.io/otel/trace v1.37 .0 // indirect
156- go.opentelemetry.io/proto/otlp v1.7 .0 // indirect
146+ go.opentelemetry.io/auto/sdk v1.2.1 // indirect
147+ go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc v0.63 .0 // indirect
148+ go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.63 .0 // indirect
149+ go.opentelemetry.io/otel v1.38 .0 // indirect
150+ go.opentelemetry.io/otel/exporters/otlp/otlptrace v1.38 .0 // indirect
151+ go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc v1.38 .0 // indirect
152+ go.opentelemetry.io/otel/metric v1.38 .0 // indirect
153+ go.opentelemetry.io/otel/sdk v1.38 .0 // indirect
154+ go.opentelemetry.io/otel/trace v1.38 .0 // indirect
155+ go.opentelemetry.io/proto/otlp v1.8 .0 // indirect
157156 go.uber.org/multierr v1.11.0 // indirect
158- golang.org/x/crypto v0.40.0 // indirect
159- golang.org/x/net v0.42.0 // indirect
160- golang.org/x/oauth2 v0.30.0 // indirect
161- golang.org/x/sync v0.16.0 // indirect
162- golang.org/x/sys v0.34.0 // indirect
163- golang.org/x/term v0.33.0 // indirect
164- golang.org/x/text v0.27.0 // indirect
165- golang.org/x/time v0.12.0 // indirect
166- google.golang.org/genproto v0.0.0-20250715232539-7130f93afb79 // indirect
167- google.golang.org/genproto/googleapis/rpc v0.0.0-20250715232539-7130f93afb79 // indirect
157+ go.yaml.in/yaml/v2 v2.4.2 // indirect
158+ go.yaml.in/yaml/v3 v3.0.4 // indirect
159+ golang.org/x/crypto v0.42.0 // indirect
160+ golang.org/x/net v0.44.0 // indirect
161+ golang.org/x/oauth2 v0.31.0 // indirect
162+ golang.org/x/sync v0.17.0 // indirect
163+ golang.org/x/sys v0.36.0 // indirect
164+ golang.org/x/term v0.35.0 // indirect
165+ golang.org/x/text v0.29.0 // indirect
166+ golang.org/x/time v0.13.0 // indirect
167+ google.golang.org/genproto v0.0.0-20250922171735-9219d122eba9 // indirect
168+ google.golang.org/genproto/googleapis/rpc v0.0.0-20250922171735-9219d122eba9 // indirect
168169)
0 commit comments