Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

chore(go-tuf): Upgrade Go-TUF #18227

Merged
merged 4 commits into from
Jul 20, 2023
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
11 changes: 7 additions & 4 deletions LICENSE-3rdparty.csv
Original file line number Diff line number Diff line change
Expand Up @@ -955,6 +955,7 @@ core,github.com/google/s2a-go/internal/v2,Apache-2.0,Copyright (c) 2020 Google
core,github.com/google/s2a-go/internal/v2/certverifier,Apache-2.0,Copyright (c) 2020 Google
core,github.com/google/s2a-go/internal/v2/remotesigner,Apache-2.0,Copyright (c) 2020 Google
core,github.com/google/s2a-go/internal/v2/tlsconfigstore,Apache-2.0,Copyright (c) 2020 Google
core,github.com/google/s2a-go/stream,Apache-2.0,Copyright (c) 2020 Google
core,github.com/google/uuid,BSD-3-Clause,"Copyright (c) 2009,2014 Google Inc. All rights reserved | Paul Borman <[email protected]> | bmatsuo | cd1 | dansouza | dsymonds | jboverfelt | shawnps | theory | wallclockbuilder"
core,github.com/google/wire,Apache-2.0,Chris Lewis <[email protected]> <[email protected]> <[email protected]> | Christina Austin <[email protected]> | Eno Compton <[email protected]> | Google LLC | Issac Trotts <[email protected]> <[email protected]> | Kumbirai Tanekha <[email protected]> | Oleg Kovalov <[email protected]> | Robert van Gent <[email protected]> <[email protected]> | Ross Light <[email protected]> <[email protected]> | Tuo Shan <[email protected]> <[email protected]> | Yoichiro Shimizu <[email protected]> | Zachary Romero <[email protected]> | ktr <[email protected]>
core,github.com/googleapis/enterprise-certificate-proxy/client,Apache-2.0,Copyright 2017 Google Inc.
Expand Down Expand Up @@ -1311,6 +1312,7 @@ core,github.com/sassoftware/go-rpmutils/cpio,Apache-2.0,Copyright (c) SAS Instit
core,github.com/sassoftware/go-rpmutils/fileutil,Apache-2.0,Copyright (c) SAS Institute Inc.
core,github.com/secure-systems-lab/go-securesystemslib/cjson,MIT,Copyright (c) 2021 NYU Secure Systems Lab
core,github.com/secure-systems-lab/go-securesystemslib/dsse,MIT,Copyright (c) 2021 NYU Secure Systems Lab
core,github.com/secure-systems-lab/go-securesystemslib/signerverifier,MIT,Copyright (c) 2021 NYU Secure Systems Lab
core,github.com/sergi/go-diff/diffmatchpatch,MIT,Copyright (c) 2012-2016 The go-diff Authors. All rights reserved | Danny Yoo <[email protected]> | James Kolb <[email protected]> | Jonathan Amsterdam <[email protected]> | Markus Zimmermann <[email protected]> <[email protected]> <[email protected]> | Matt Kovars <[email protected]> | Osman Masood <[email protected]> | Robert Carlsen <[email protected]> | Rory Flynn <[email protected]> | Sergi Mansilla <[email protected]> | Shatrugna Sadhu <[email protected]> | Shawn Smith <[email protected]> | Stas Maksimov <[email protected]> | Tor Arvid Lund <[email protected]> | Zac Bergquist <[email protected]> | Örjan Persson <[email protected]>
core,github.com/shibumi/go-pathspec,Apache-2.0,Copyright (c) 2012 The Go Authors. All rights reserved.
core,github.com/shirou/gopsutil/v3/cpu,BSD-3-Clause,"Copyright (c) 2009 The Go Authors. All rights reserved | Copyright (c) 2014, WAKAYAMA Shirou"
Expand Down Expand Up @@ -1409,10 +1411,10 @@ core,github.com/twmb/franz-go/pkg/kversion,BSD-3-Clause,"Copyright 2020, Travis
core,github.com/twmb/franz-go/pkg/sasl,BSD-3-Clause,"Copyright 2020, Travis Bischel"
core,github.com/twmb/murmur3,BSD-3-Clause,"Copyright 2013, Sébastien Paolacci | Copyright 2018, Travis Bischel"
core,github.com/ugorji/go/codec,MIT,Copyright (c) 2012-2020 Ugorji Nwoke
core,github.com/ulikunitz/xz,BSD-3-Clause,Copyright (c) 2014-2021 Ulrich Kunitz
core,github.com/ulikunitz/xz/internal/hash,BSD-3-Clause,Copyright (c) 2014-2021 Ulrich Kunitz
core,github.com/ulikunitz/xz/internal/xlog,BSD-3-Clause,Copyright (c) 2014-2021 Ulrich Kunitz
core,github.com/ulikunitz/xz/lzma,BSD-3-Clause,Copyright (c) 2014-2021 Ulrich Kunitz
core,github.com/ulikunitz/xz,BSD-3-Clause,Copyright (c) 2014-2022 Ulrich Kunitz
core,github.com/ulikunitz/xz/internal/hash,BSD-3-Clause,Copyright (c) 2014-2022 Ulrich Kunitz
core,github.com/ulikunitz/xz/internal/xlog,BSD-3-Clause,Copyright (c) 2014-2022 Ulrich Kunitz
core,github.com/ulikunitz/xz/lzma,BSD-3-Clause,Copyright (c) 2014-2022 Ulrich Kunitz
core,github.com/uptrace/bun,BSD-2-Clause,Copyright (c) 2021 Vladimir Mihailenco. All rights reserved
core,github.com/uptrace/bun/dialect,BSD-2-Clause,Copyright (c) 2021 Vladimir Mihailenco. All rights reserved
core,github.com/uptrace/bun/dialect/feature,BSD-2-Clause,Copyright (c) 2021 Vladimir Mihailenco. All rights reserved
Expand Down Expand Up @@ -1859,6 +1861,7 @@ core,google.golang.org/genproto/googleapis/rpc/errdetails,Apache-2.0,Copyright 2
core,google.golang.org/genproto/googleapis/rpc/status,Apache-2.0,Copyright 2015 Google LLC
core,google.golang.org/genproto/googleapis/type/date,Apache-2.0,Copyright 2015 Google LLC
core,google.golang.org/genproto/googleapis/type/expr,Apache-2.0,Copyright 2015 Google LLC
core,google.golang.org/genproto/internal,Apache-2.0,Copyright 2015 Google LLC
core,google.golang.org/genproto/protobuf/field_mask,Apache-2.0,Copyright 2015 Google LLC
core,google.golang.org/grpc,Apache-2.0,Copyright 2014 gRPC authors.
core,google.golang.org/grpc/attributes,Apache-2.0,Copyright 2014 gRPC authors.
Expand Down
60 changes: 30 additions & 30 deletions go.mod
Original file line number Diff line number Diff line change
Expand Up @@ -57,7 +57,7 @@ require (
github.com/DataDog/datadog-operator v1.0.3
github.com/DataDog/ebpf-manager v0.2.10
github.com/DataDog/go-libddwaf v1.0.0
github.com/DataDog/go-tuf v0.3.0--fix-localmeta-fork
github.com/DataDog/go-tuf v1.0.0-0.5.2
github.com/DataDog/gopsutil v1.2.2
github.com/DataDog/nikos v1.12.0
github.com/DataDog/opentelemetry-mapping-go/pkg/otlp/attributes v0.5.2
Expand Down Expand Up @@ -118,7 +118,7 @@ require (
github.com/golang/mock v1.6.0
github.com/golang/protobuf v1.5.3
github.com/google/go-cmp v0.5.9
github.com/google/go-containerregistry v0.14.0
github.com/google/go-containerregistry v0.15.2
github.com/google/gofuzz v1.2.0
github.com/google/gopacket v1.1.19
github.com/google/pprof v0.0.0-20230602150820-91b7bce49751
Expand Down Expand Up @@ -159,19 +159,19 @@ require (
github.com/patrickmn/go-cache v2.1.0+incompatible
github.com/pkg/errors v0.9.1
github.com/prometheus/client_golang v1.16.0
github.com/prometheus/client_model v0.3.0
github.com/prometheus/client_model v0.4.0
github.com/prometheus/procfs v0.11.0
github.com/richardartoul/molecule v1.0.1-0.20221107223329-32cfee06a052
github.com/robfig/cron/v3 v3.0.1
github.com/samber/lo v1.38.1
github.com/samuel/go-zookeeper v0.0.0-20190923202752-2cc03de413da
github.com/secure-systems-lab/go-securesystemslib v0.5.0
github.com/secure-systems-lab/go-securesystemslib v0.7.0
github.com/shirou/gopsutil/v3 v3.23.2
github.com/shirou/w32 v0.0.0-20160930032740-bb4de0191aa4
github.com/sirupsen/logrus v1.9.3
github.com/skydive-project/go-debouncer v1.0.0
github.com/smira/go-xz v0.1.0
github.com/spf13/afero v1.9.3
github.com/spf13/afero v1.9.5
github.com/spf13/cast v1.5.1
github.com/spf13/cobra v1.7.0
github.com/spf13/pflag v1.0.5
Expand Down Expand Up @@ -218,7 +218,7 @@ require (
golang.org/x/time v0.3.0
golang.org/x/tools v0.11.0
golang.org/x/xerrors v0.0.0-20220907171357-04be3eba64a2
google.golang.org/genproto v0.0.0-20230525234025-438c736192d0 // indirect
google.golang.org/genproto v0.0.0-20230530153820-e85fd2cbaebc // indirect
google.golang.org/grpc v1.56.1
google.golang.org/grpc/examples v0.0.0-20221020162917-9127159caf5a
google.golang.org/protobuf v1.31.0
Expand All @@ -235,7 +235,7 @@ require (
k8s.io/client-go v0.25.5
k8s.io/cri-api v0.25.5 // Cannot be upgraded to 0.26 without lossing CRI API v1alpha2
k8s.io/klog v1.0.1-0.20200310124935-4ad0115ba9e4 // Min version that includes fix for Windows Nano
k8s.io/klog/v2 v2.80.1
k8s.io/klog/v2 v2.100.1
k8s.io/kube-aggregator v0.23.5
k8s.io/kube-openapi v0.0.0-20221012153701-172d655c2280
k8s.io/kube-state-metrics/v2 v2.7.0
Expand All @@ -246,10 +246,10 @@ require (
)

require (
cloud.google.com/go v0.110.0 // indirect
cloud.google.com/go/compute v1.19.1 // indirect
cloud.google.com/go v0.110.2 // indirect
cloud.google.com/go/compute v1.20.0 // indirect
cloud.google.com/go/compute/metadata v0.2.3 // indirect
cloud.google.com/go/iam v0.13.0 // indirect
cloud.google.com/go/iam v1.1.0 // indirect
cloud.google.com/go/storage v1.30.1 // indirect
code.cloudfoundry.org/cfhttp/v2 v2.0.0 // indirect
code.cloudfoundry.org/clock v1.0.0 // indirect
Expand Down Expand Up @@ -331,7 +331,7 @@ require (
github.com/dgryski/go-jump v0.0.0-20211018200510-ba001c3ffce0 // indirect
github.com/dgryski/go-rendezvous v0.0.0-20200823014737-9f7001d12a5f // indirect
github.com/dimchansky/utfbom v1.1.1 // indirect
github.com/docker/cli v23.0.1+incompatible // indirect
github.com/docker/cli v23.0.5+incompatible // indirect
github.com/docker/distribution v2.8.2+incompatible // indirect
github.com/docker/docker-credential-helpers v0.7.0 // indirect
github.com/docker/go-events v0.0.0-20190806004212-e31b211e4f1c // indirect
Expand All @@ -351,27 +351,27 @@ require (
github.com/go-logr/logr v1.2.4 // indirect
github.com/go-logr/stdr v1.2.2 // indirect
github.com/go-openapi/analysis v0.21.4 // indirect
github.com/go-openapi/errors v0.20.3 // indirect
github.com/go-openapi/jsonpointer v0.19.5 // indirect
github.com/go-openapi/jsonreference v0.20.0 // indirect
github.com/go-openapi/errors v0.20.4 // indirect
github.com/go-openapi/jsonpointer v0.19.6 // indirect
github.com/go-openapi/jsonreference v0.20.2 // indirect
github.com/go-openapi/loads v0.21.2 // indirect
github.com/go-openapi/runtime v0.26.0 // indirect
github.com/go-openapi/spec v0.20.9 // indirect
github.com/go-openapi/strfmt v0.21.7 // indirect
github.com/go-openapi/swag v0.22.3 // indirect
github.com/go-openapi/swag v0.22.4 // indirect
github.com/go-openapi/validate v0.22.1 // indirect
github.com/go-redis/redis/v8 v8.11.5 // indirect
github.com/go-test/deep v1.0.7 // indirect
github.com/godbus/dbus/v5 v5.0.6 // indirect
github.com/godbus/dbus/v5 v5.1.0 // indirect
github.com/gogo/googleapis v1.4.1 // indirect
github.com/golang-jwt/jwt/v4 v4.4.2 // indirect
github.com/golang-jwt/jwt/v4 v4.5.0 // indirect
github.com/golang/glog v1.1.1 // indirect
github.com/golang/snappy v0.0.4 // indirect
github.com/google/licenseclassifier/v2 v2.0.0 // indirect
github.com/google/uuid v1.3.0
github.com/google/wire v0.5.0 // indirect
github.com/googleapis/enterprise-certificate-proxy v0.2.3 // indirect
github.com/googleapis/gax-go/v2 v2.8.0 // indirect
github.com/googleapis/enterprise-certificate-proxy v0.2.5 // indirect
github.com/googleapis/gax-go/v2 v2.11.0 // indirect
github.com/googleapis/gnostic v0.5.5 // indirect
github.com/gorilla/websocket v1.5.0 // indirect
github.com/grpc-ecosystem/go-grpc-prometheus v1.2.0 // indirect
Expand All @@ -380,7 +380,7 @@ require (
github.com/hashicorp/go-cleanhttp v0.5.2 // indirect
github.com/hashicorp/go-hclog v1.2.0 // indirect
github.com/hashicorp/go-immutable-radix v1.3.1 // indirect
github.com/hashicorp/go-retryablehttp v0.7.2 // indirect
github.com/hashicorp/go-retryablehttp v0.7.4 // indirect
github.com/hashicorp/go-rootcerts v1.0.2 // indirect
github.com/hashicorp/go-version v1.6.0 // indirect
github.com/hashicorp/golang-lru v0.5.4 // indirect
Expand All @@ -390,7 +390,7 @@ require (
github.com/iancoleman/orderedmap v0.0.0-20190318233801-ac98e3ecb4b0 // indirect
github.com/ianlancetaylor/cgosymbolizer v0.0.0-20221208003206-eaf69f594683
github.com/ianlancetaylor/demangle v0.0.0-20230524184225-eabc099b10ab // indirect
github.com/in-toto/in-toto-golang v0.8.0 // indirect
github.com/in-toto/in-toto-golang v0.9.0 // indirect
github.com/inconshreveable/mousetrap v1.1.0 // indirect
github.com/itchyny/timefmt-go v0.1.5 // indirect
github.com/jbenet/go-context v0.0.0-20150711004518-d14ea06fba99 // indirect
Expand All @@ -405,7 +405,7 @@ require (
github.com/kballard/go-shellquote v0.0.0-20180428030007-95032a82bc51 // indirect
github.com/kevinburke/ssh_config v1.2.0 // indirect
github.com/kjk/lzma v0.0.0-20161016003348-3fd93898850d // indirect
github.com/klauspost/compress v1.16.3 // indirect
github.com/klauspost/compress v1.16.5 // indirect
github.com/klauspost/pgzip v1.2.5 // indirect
github.com/knadh/koanf v1.5.0 // indirect
github.com/knqyf263/go-apk-version v0.0.0-20200609155635-041fdbb8563f // indirect
Expand Down Expand Up @@ -475,7 +475,7 @@ require (
github.com/spdx/tools-golang v0.3.1-0.20230104082527-d6f58551be3f // indirect
github.com/spf13/jwalterweatherman v1.1.0 // indirect
github.com/stretchr/objx v0.5.0 // indirect
github.com/syndtr/goleveldb v1.0.1-0.20210819022825-2ae1ddf74ef7 // indirect
github.com/syndtr/goleveldb v1.0.1-0.20220721030215-126854af5e6d // indirect
github.com/tchap/go-patricia/v2 v2.3.1 // indirect
github.com/tedsuo/ifrit v0.0.0-20191009134036-9a97d0632f00 // indirect
github.com/tedsuo/rata v1.0.0 // indirect
Expand All @@ -491,8 +491,8 @@ require (
github.com/twmb/franz-go/pkg/kadm v1.8.1
github.com/twmb/franz-go/pkg/kmsg v1.4.0 // indirect
github.com/ugorji/go/codec v1.2.7 // indirect
github.com/ulikunitz/xz v0.5.10 // indirect
github.com/vbatts/tar-split v0.11.2 // indirect
github.com/ulikunitz/xz v0.5.11 // indirect
github.com/vbatts/tar-split v0.11.3 // indirect
github.com/vito/go-sse v1.0.0 // indirect
github.com/vmihailenco/msgpack/v5 v5.3.5 // indirect
github.com/vmihailenco/tagparser v0.1.2 // indirect
Expand Down Expand Up @@ -533,11 +533,11 @@ require (
go.opentelemetry.io/proto/otlp v0.19.0 // indirect
golang.org/x/crypto v0.11.0 // indirect
golang.org/x/mod v0.12.0
golang.org/x/oauth2 v0.8.0 // indirect
golang.org/x/oauth2 v0.9.0 // indirect
golang.org/x/term v0.10.0 // indirect
gomodules.xyz/jsonpatch/v2 v2.2.0 // indirect
gonum.org/v1/gonum v0.12.0 // indirect
google.golang.org/api v0.119.0 // indirect
google.golang.org/api v0.128.0 // indirect
google.golang.org/appengine v1.6.7 // indirect
gopkg.in/Knetic/govaluate.v3 v3.0.0 // indirect
gopkg.in/cheggaaa/pb.v1 v1.0.28 // indirect
Expand Down Expand Up @@ -583,23 +583,23 @@ require (
github.com/census-instrumentation/opencensus-proto v0.4.1 // indirect
github.com/cloudflare/circl v1.3.3 // indirect
github.com/godror/knownpb v0.1.0 // indirect
github.com/google/s2a-go v0.1.2 // indirect
github.com/google/s2a-go v0.1.4 // indirect
github.com/hashicorp/hcl/v2 v2.17.0 // indirect
github.com/kr/text v0.2.0 // indirect
github.com/open-telemetry/opentelemetry-collector-contrib/internal/coreinternal v0.75.0 // indirect
github.com/open-telemetry/opentelemetry-collector-contrib/internal/sharedcomponent v0.75.0 // indirect
github.com/open-telemetry/opentelemetry-collector-contrib/pkg/translator/opencensus v0.75.0 // indirect
github.com/rogpeppe/go-internal v1.10.0 // indirect
github.com/rs/zerolog v1.29.1 // indirect
github.com/sigstore/rekor v1.0.1 // indirect
github.com/sigstore/rekor v1.2.2 // indirect
github.com/soheilhy/cmux v0.1.5 // indirect
github.com/spaolacci/murmur3 v1.1.0 // indirect
github.com/zclconf/go-cty v1.13.2 // indirect
go4.org/intern v0.0.0-20211027215823-ae77deb06f29 // indirect
go4.org/unsafe/assume-no-moving-gc v0.0.0-20220617031537-928513b29760 // indirect
golang.org/x/exp/typeparams v0.0.0-20220613132600-b0d781184e0d // indirect
golang.org/x/lint v0.0.0-20210508222113-6edffad5e616 // indirect
google.golang.org/genproto/googleapis/api v0.0.0-20230525234020-1aefcd67740a // indirect
google.golang.org/genproto/googleapis/api v0.0.0-20230530153820-e85fd2cbaebc // indirect
google.golang.org/genproto/googleapis/rpc v0.0.0-20230530153820-e85fd2cbaebc // indirect
gopkg.in/ini.v1 v1.67.0 // indirect
gotest.tools/v3 v3.3.0 // indirect
Expand Down
Loading