@@ -5,111 +5,114 @@ go 1.20
5
5
require github.com/goharbor/harbor/src v0.0.0-20231031103200-f75a2f9407cb
6
6
7
7
require (
8
- github.com/aquasecurity/trivy v0.40.0
8
+ github.com/aquasecurity/trivy v0.51.2
9
9
github.com/go-co-op/gocron v1.28.0
10
10
github.com/imroc/req/v3 v3.35.0
11
11
)
12
12
13
- require github.com/spdx/tools-golang v0.5.0 // indirect
14
-
15
13
require (
16
14
github.com/FZambia/sentinel v1.1.1
17
15
github.com/aquasecurity/harbor-scanner-trivy v0.30.11
18
16
github.com/aquasecurity/kube-bench v0.6.12
19
17
github.com/caarlos0/env/v6 v6.10.1
20
- github.com/docker/docker v24 .0.7 +incompatible
21
- github.com/docker/go-connections v0.4 .0
22
- github.com/fsnotify/fsnotify v1.6 .0
18
+ github.com/docker/docker v26 .0.2 +incompatible
19
+ github.com/docker/go-connections v0.5 .0
20
+ github.com/fsnotify/fsnotify v1.7 .0
23
21
github.com/gin-gonic/gin v1.9.1
24
- github.com/go-openapi/errors v0.20.3
25
- github.com/go-openapi/runtime v0.25 .0
26
- github.com/go-openapi/strfmt v0.21.7
27
- github.com/go-openapi/swag v0.22.3
28
- github.com/go-openapi/validate v0.22.1
22
+ github.com/go-openapi/errors v0.22.0
23
+ github.com/go-openapi/runtime v0.28 .0
24
+ github.com/go-openapi/strfmt v0.23.0
25
+ github.com/go-openapi/swag v0.23.0
26
+ github.com/go-openapi/validate v0.24.0
29
27
github.com/goark/go-cvss v1.6.6
30
28
github.com/gocraft/work v0.5.1
31
29
github.com/goharbor/go-client v0.26.2
32
30
github.com/gomodule/redigo v2.0.0+incompatible
33
- github.com/gorilla/mux v1.8.0
31
+ github.com/gorilla/mux v1.8.1
34
32
github.com/onsi/ginkgo v1.16.5
35
- github.com/onsi/gomega v1.27.6
33
+ github.com/onsi/gomega v1.31.0
36
34
github.com/opencontainers/go-digest v1.0.0
37
35
github.com/pkg/errors v0.9.1
38
- github.com/prometheus/client_golang v1.14 .0
36
+ github.com/prometheus/client_golang v1.19 .0
39
37
github.com/sirupsen/logrus v1.9.3
40
- github.com/spf13/viper v1.15.0
41
- github.com/stretchr/testify v1.8.4
42
- github.com/testcontainers/testcontainers-go v0.17 .0
43
- go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.45 .0 // indirect
44
- golang.org/x/net v0.17 .0
45
- golang.org/x/oauth2 v0.10 .0
46
- golang.org/x/xerrors v0.0.0-20220907171357-04be3eba64a2
47
- k8s.io/api v0.26.3
48
- k8s.io/apimachinery v0.26.3
49
- k8s.io/apiserver v0.26.2
50
- k8s.io/client-go v0.26.3
51
- k8s.io/utils v0.0.0-20230220204549-a5ecb0141aa5
38
+ github.com/spf13/viper v1.18.2
39
+ github.com/stretchr/testify v1.9.0
40
+ github.com/testcontainers/testcontainers-go v0.30 .0
41
+ go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.49 .0 // indirect
42
+ golang.org/x/net v0.24 .0
43
+ golang.org/x/oauth2 v0.18 .0
44
+ golang.org/x/xerrors v0.0.0-20231012003039-104605ab7028
45
+ k8s.io/api v0.30.0
46
+ k8s.io/apimachinery v0.30.0
47
+ k8s.io/apiserver v0.29.0
48
+ k8s.io/client-go v0.30.0
49
+ k8s.io/utils v0.0.0-20231127182322-b307cd553661
52
50
sigs.k8s.io/controller-runtime v0.14.6
53
51
sigs.k8s.io/e2e-framework v0.2.0
54
52
)
55
53
56
54
require (
55
+ dario.cat/mergo v1.0.0 // indirect
57
56
github.com/Azure/go-ansiterm v0.0.0-20210617225240-d185dfc1b5a1 // indirect
58
57
github.com/Microsoft/go-winio v0.6.1 // indirect
59
58
github.com/Microsoft/hcsshim v0.11.4 // indirect
60
- github.com/aquasecurity/trivy-db v0.0.0-20230411140759-3c2ee2168575 // indirect
59
+ github.com/aquasecurity/trivy-db v0.0.0-20231005141211-4fc651f7ac8d // indirect
61
60
github.com/asaskevich/govalidator v0.0.0-20230301143203-a9d515a09cc2 // indirect
62
- github.com/aws/aws-sdk-go-v2 v1.17.7 // indirect
61
+ github.com/aws/aws-sdk-go-v2 v1.26.1 // indirect
63
62
github.com/aws/aws-sdk-go-v2/service/securityhub v1.23.5 // indirect
64
- github.com/aws/smithy-go v1.13.5 // indirect
63
+ github.com/aws/smithy-go v1.20.2 // indirect
65
64
github.com/beego/beego/v2 v2.0.6 // indirect
66
65
github.com/beorn7/perks v1.0.1 // indirect
67
66
github.com/bytedance/sonic v1.9.1 // indirect
68
67
github.com/cenkalti/backoff/v4 v4.2.1 // indirect
69
68
github.com/cespare/xxhash/v2 v2.2.0 // indirect
70
69
github.com/chenzhuoyu/base64x v0.0.0-20221115062448-fe3a3abad311 // indirect
71
- github.com/containerd/containerd v1.7.11 // indirect
70
+ github.com/containerd/containerd v1.7.16 // indirect
72
71
github.com/containerd/log v0.1.0 // indirect
73
- github.com/davecgh/go-spew v1.1.1 // indirect
74
- github.com/docker/distribution v2.8.2+incompatible // indirect
72
+ github.com/cpuguy83/dockercfg v0.3.1 // indirect
73
+ github.com/davecgh/go-spew v1.1.2-0.20180830191138-d8f796af33cc // indirect
74
+ github.com/distribution/reference v0.6.0 // indirect
75
+ github.com/docker/distribution v2.8.3+incompatible // indirect
75
76
github.com/docker/go-units v0.5.0 // indirect
76
- github.com/emicklei/go-restful/v3 v3.10.1 // indirect
77
- github.com/evanphx/json-patch v5.6 .0+incompatible // indirect
77
+ github.com/emicklei/go-restful/v3 v3.11.0 // indirect
78
+ github.com/evanphx/json-patch v5.7 .0+incompatible // indirect
78
79
github.com/evanphx/json-patch/v5 v5.6.0 // indirect
79
- github.com/felixge/httpsnoop v1.0.3 // indirect
80
+ github.com/felixge/httpsnoop v1.0.4 // indirect
80
81
github.com/gabriel-vasile/mimetype v1.4.2 // indirect
81
82
github.com/gin-contrib/sse v0.1.0 // indirect
82
- github.com/go-logr/logr v1.2.4 // indirect
83
+ github.com/go-logr/logr v1.4.1 // indirect
83
84
github.com/go-logr/stdr v1.2.2 // indirect
84
- github.com/go-logr/zapr v1.2.3 // indirect
85
- github.com/go-openapi/analysis v0.21.4 // indirect
86
- github.com/go-openapi/jsonpointer v0.19.5 // indirect
87
- github.com/go-openapi/jsonreference v0.20.0 // indirect
88
- github.com/go-openapi/loads v0.21.2 // indirect
89
- github.com/go-openapi/spec v0.20.8 // indirect
85
+ github.com/go-logr/zapr v1.3.0 // indirect
86
+ github.com/go-ole/go-ole v1.2.6 // indirect
87
+ github.com/go-openapi/analysis v0.23.0 // indirect
88
+ github.com/go-openapi/jsonpointer v0.21.0 // indirect
89
+ github.com/go-openapi/jsonreference v0.21.0 // indirect
90
+ github.com/go-openapi/loads v0.22.0 // indirect
91
+ github.com/go-openapi/spec v0.21.0 // indirect
90
92
github.com/go-playground/locales v0.14.1 // indirect
91
93
github.com/go-playground/universal-translator v0.18.1 // indirect
92
94
github.com/go-playground/validator/v10 v10.14.0 // indirect
93
95
github.com/go-task/slim-sprig v0.0.0-20230315185526-52ccab3ef572 // indirect
94
96
github.com/goark/errs v1.1.0 // indirect
95
97
github.com/goccy/go-json v0.10.2 // indirect
96
98
github.com/gogo/protobuf v1.3.2 // indirect
97
- github.com/golang/glog v1.1 .0 // indirect
99
+ github.com/golang/glog v1.2 .0 // indirect
98
100
github.com/golang/groupcache v0.0.0-20210331224755-41bb18bfe9da // indirect
99
101
github.com/golang/mock v1.6.0 // indirect
100
- github.com/golang/protobuf v1.5.3 // indirect
101
- github.com/google/gnostic v0.5.7-v3refs // indirect
102
- github.com/google/go-cmp v0.5.9 // indirect
103
- github.com/google/go-containerregistry v0.14.0 // indirect
102
+ github.com/golang/protobuf v1.5.4 // indirect
103
+ github.com/google/gnostic-models v0.6.8 // indirect
104
+ github.com/google/go-cmp v0.6.0 // indirect
105
+ github.com/google/go-containerregistry v0.19.1 // indirect
104
106
github.com/google/gofuzz v1.2.0 // indirect
105
107
github.com/google/pprof v0.0.0-20230426061923-93006964c1fc // indirect
106
- github.com/google/uuid v1.3.0 // indirect
108
+ github.com/google/uuid v1.6.0 // indirect
109
+ github.com/gorilla/websocket v1.5.0 // indirect
107
110
github.com/grpc-ecosystem/grpc-gateway/v2 v2.16.0 // indirect
108
111
github.com/hashicorp/errwrap v1.1.0 // indirect
109
112
github.com/hashicorp/go-multierror v1.1.1 // indirect
110
- github.com/hashicorp/golang-lru v0.5.4 // indirect
113
+ github.com/hashicorp/golang-lru v0.6.0 // indirect
111
114
github.com/hashicorp/hcl v1.0.0 // indirect
112
- github.com/imdario/mergo v0.3.13 // indirect
115
+ github.com/imdario/mergo v0.3.15 // indirect
113
116
github.com/jackc/chunkreader/v2 v2.0.1 // indirect
114
117
github.com/jackc/pgconn v1.14.0 // indirect
115
118
github.com/jackc/pgio v1.0.0 // indirect
@@ -118,88 +121,100 @@ require (
118
121
github.com/jackc/pgservicefile v0.0.0-20221227161230-091c0ba34f0a // indirect
119
122
github.com/josharian/intern v1.0.0 // indirect
120
123
github.com/json-iterator/go v1.1.12 // indirect
121
- github.com/klauspost/compress v1.16.0 // indirect
124
+ github.com/klauspost/compress v1.17.4 // indirect
122
125
github.com/klauspost/cpuid/v2 v2.2.4 // indirect
123
126
github.com/leodido/go-urn v1.2.4 // indirect
127
+ github.com/lufia/plan9stats v0.0.0-20211012122336-39d0f177ccd0 // indirect
124
128
github.com/magiconair/properties v1.8.7 // indirect
125
129
github.com/mailru/easyjson v0.7.7 // indirect
126
- github.com/mattn/go-isatty v0.0.19 // indirect
127
- github.com/matttproud/golang_protobuf_extensions v1.0.4 // indirect
130
+ github.com/mattn/go-isatty v0.0.20 // indirect
128
131
github.com/mitchellh/mapstructure v1.5.0 // indirect
129
- github.com/moby/patternmatcher v0.5.0 // indirect
132
+ github.com/moby/docker-image-spec v1.3.1 // indirect
133
+ github.com/moby/patternmatcher v0.6.0 // indirect
130
134
github.com/moby/spdystream v0.2.0 // indirect
131
135
github.com/moby/sys/sequential v0.5.0 // indirect
132
- github.com/moby/term v0.0.0-20221205130635-1aeaba878587 // indirect
136
+ github.com/moby/sys/user v0.1.0 // indirect
137
+ github.com/moby/term v0.5.0 // indirect
133
138
github.com/modern-go/concurrent v0.0.0-20180306012644-bacd9c7ef1dd // indirect
134
139
github.com/modern-go/reflect2 v1.0.2 // indirect
135
140
github.com/morikuni/aec v1.0.0 // indirect
136
141
github.com/munnerz/goautoneg v0.0.0-20191010083416-a7dc8b61c822 // indirect
142
+ github.com/mxk/go-flowrate v0.0.0-20140419014527-cca7078d478f // indirect
137
143
github.com/nxadm/tail v1.4.8 // indirect
138
144
github.com/oklog/ulid v1.3.1 // indirect
139
- github.com/onsi/ginkgo/v2 v2.9.5 // indirect
140
- github.com/opencontainers/image-spec v1.1.0-rc2.0.20221020182949-4df8887994e8 // indirect
141
- github.com/opencontainers/runc v1.1.12 // indirect
145
+ github.com/onsi/ginkgo/v2 v2.15.0 // indirect
146
+ github.com/opencontainers/image-spec v1.1.0 // indirect
142
147
github.com/opentracing/opentracing-go v1.2.0 // indirect
143
- github.com/pelletier/go-toml/v2 v2.0.8 // indirect
144
- github.com/pmezard/go-difflib v1.0.0 // indirect
145
- github.com/prometheus/client_model v0.3.0 // indirect
146
- github.com/prometheus/common v0.39.0 // indirect
147
- github.com/prometheus/procfs v0.8.0 // indirect
148
+ github.com/package-url/packageurl-go v0.1.2 // indirect
149
+ github.com/pelletier/go-toml/v2 v2.1.0 // indirect
150
+ github.com/pmezard/go-difflib v1.0.1-0.20181226105442-5d4384ee4fb2 // indirect
151
+ github.com/power-devops/perfstat v0.0.0-20210106213030-5aafc221ea8c // indirect
152
+ github.com/prometheus/client_model v0.6.1 // indirect
153
+ github.com/prometheus/common v0.48.0 // indirect
154
+ github.com/prometheus/procfs v0.12.0 // indirect
148
155
github.com/quic-go/qpack v0.4.0 // indirect
149
156
github.com/quic-go/qtls-go1-20 v0.3.1 // indirect
150
157
github.com/quic-go/quic-go v0.37.7 // indirect
151
158
github.com/robfig/cron v1.2.0 // indirect
152
159
github.com/robfig/cron/v3 v3.0.1 // indirect
153
- github.com/samber/lo v1.37.0 // indirect
160
+ github.com/sagikazarmark/locafero v0.4.0 // indirect
161
+ github.com/sagikazarmark/slog-shim v0.1.0 // indirect
162
+ github.com/samber/lo v1.39.0 // indirect
154
163
github.com/shiena/ansicolor v0.0.0-20200904210342-c7312218db18 // indirect
155
- github.com/spf13/afero v1.9.3 // indirect
156
- github.com/spf13/cast v1.5.0 // indirect
157
- github.com/spf13/jwalterweatherman v1.1.0 // indirect
164
+ github.com/shirou/gopsutil/v3 v3.23.12 // indirect
165
+ github.com/shoenig/go-m1cpu v0.1.6 // indirect
166
+ github.com/sourcegraph/conc v0.3.0 // indirect
167
+ github.com/spf13/afero v1.11.0 // indirect
168
+ github.com/spf13/cast v1.6.0 // indirect
158
169
github.com/spf13/pflag v1.0.5 // indirect
159
- github.com/stretchr/objx v0.5.0 // indirect
160
- github.com/subosito/gotenv v1.4.2 // indirect
170
+ github.com/stretchr/objx v0.5.2 // indirect
171
+ github.com/subosito/gotenv v1.6.0 // indirect
172
+ github.com/tklauser/go-sysconf v0.3.12 // indirect
173
+ github.com/tklauser/numcpus v0.6.1 // indirect
161
174
github.com/twitchyliquid64/golang-asm v0.15.1 // indirect
162
175
github.com/ugorji/go/codec v1.2.11 // indirect
163
176
github.com/vladimirvivien/gexe v0.2.0 // indirect
164
- go.mongodb.org/mongo-driver v1.11.3 // indirect
165
- go.opentelemetry.io/otel v1.19.0 // indirect
177
+ github.com/yusufpapurcu/wmi v1.2.3 // indirect
178
+ go.mongodb.org/mongo-driver v1.14.0 // indirect
179
+ go.opentelemetry.io/otel v1.24.0 // indirect
166
180
go.opentelemetry.io/otel/exporters/jaeger v1.0.0 // indirect
167
181
go.opentelemetry.io/otel/exporters/otlp/otlptrace v1.19.0 // indirect
168
182
go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp v1.19.0 // indirect
169
- go.opentelemetry.io/otel/metric v1.19 .0 // indirect
170
- go.opentelemetry.io/otel/sdk v1.19 .0 // indirect
171
- go.opentelemetry.io/otel/trace v1.19 .0 // indirect
183
+ go.opentelemetry.io/otel/metric v1.24 .0 // indirect
184
+ go.opentelemetry.io/otel/sdk v1.24 .0 // indirect
185
+ go.opentelemetry.io/otel/trace v1.24 .0 // indirect
172
186
go.opentelemetry.io/proto/otlp v1.0.0 // indirect
173
187
go.uber.org/atomic v1.10.0 // indirect
174
- go.uber.org/multierr v1.9 .0 // indirect
175
- go.uber.org/zap v1.24 .0 // indirect
188
+ go.uber.org/multierr v1.11 .0 // indirect
189
+ go.uber.org/zap v1.27 .0 // indirect
176
190
golang.org/x/arch v0.3.0 // indirect
177
- golang.org/x/crypto v0.17.0 // indirect
178
- golang.org/x/exp v0.0.0-20230425010034-47ecfdc1ba53 // indirect
179
- golang.org/x/mod v0.11.0 // indirect
180
- golang.org/x/sys v0.15.0 // indirect
181
- golang.org/x/term v0.15.0 // indirect
191
+ golang.org/x/crypto v0.22.0 // indirect
192
+ golang.org/x/exp v0.0.0-20231110203233-9a3e6036ecaa // indirect
193
+ golang.org/x/mod v0.16.0 // indirect
194
+ golang.org/x/sync v0.6.0 // indirect
195
+ golang.org/x/sys v0.19.0 // indirect
196
+ golang.org/x/term v0.19.0 // indirect
182
197
golang.org/x/text v0.14.0 // indirect
183
- golang.org/x/time v0.3 .0 // indirect
184
- golang.org/x/tools v0.10 .0 // indirect
198
+ golang.org/x/time v0.5 .0 // indirect
199
+ golang.org/x/tools v0.19 .0 // indirect
185
200
gomodules.xyz/jsonpatch/v2 v2.2.0 // indirect
186
- google.golang.org/appengine v1.6.7 // indirect
187
- google.golang.org/genproto/googleapis/api v0.0.0-20230711160842-782d3b101e98 // indirect
188
- google.golang.org/genproto/googleapis/rpc v0.0.0-20230711160842-782d3b101e98 // indirect
189
- google.golang.org/grpc v1.58.3 // indirect
190
- google.golang.org/protobuf v1.31 .0 // indirect
201
+ google.golang.org/appengine v1.6.8 // indirect
202
+ google.golang.org/genproto/googleapis/api v0.0.0-20240311173647-c811ad7063a7 // indirect
203
+ google.golang.org/genproto/googleapis/rpc v0.0.0-20240318140521-94a12d6c2237 // indirect
204
+ google.golang.org/grpc v1.63.2 // indirect
205
+ google.golang.org/protobuf v1.34 .0 // indirect
191
206
gopkg.in/inf.v0 v0.9.1 // indirect
192
207
gopkg.in/ini.v1 v1.67.0 // indirect
193
208
gopkg.in/tomb.v1 v1.0.0-20141024135613-dd632973f1e7 // indirect
194
209
gopkg.in/yaml.v2 v2.4.0 // indirect
195
210
gopkg.in/yaml.v3 v3.0.1 // indirect
196
- k8s.io/apiextensions-apiserver v0.26.1 // indirect
197
- k8s.io/component-base v0.26.3 // indirect
198
- k8s.io/klog/v2 v2.90 .1 // indirect
199
- k8s.io/kube-openapi v0.0.0-20221012153701-172d655c2280 // indirect
200
- sigs.k8s.io/json v0.0.0-20220713155537-f223a00ba0e2 // indirect
201
- sigs.k8s.io/structured-merge-diff/v4 v4.2.3 // indirect
202
- sigs.k8s.io/yaml v1.3 .0 // indirect
211
+ k8s.io/apiextensions-apiserver v0.29.0 // indirect
212
+ k8s.io/component-base v0.30.0 // indirect
213
+ k8s.io/klog/v2 v2.120 .1 // indirect
214
+ k8s.io/kube-openapi v0.0.0-20240228011516-70dd3763d340 // indirect
215
+ sigs.k8s.io/json v0.0.0-20221116044647-bc3834ca7abd // indirect
216
+ sigs.k8s.io/structured-merge-diff/v4 v4.4.1 // indirect
217
+ sigs.k8s.io/yaml v1.4 .0 // indirect
203
218
)
204
219
205
220
replace github.com/spdx/tools-golang => github.com/spdx/tools-golang v0.3.0
0 commit comments