|
1 | 1 | module github.com/sigstore/timestamp-authority |
2 | 2 |
|
3 | | -go 1.23.6 |
4 | | - |
5 | | -toolchain go1.24.1 |
| 3 | +go 1.25.0 |
6 | 4 |
|
7 | 5 | require ( |
8 | | - cloud.google.com/go/security v1.18.5 |
| 6 | + cloud.google.com/go/security v1.19.1 |
9 | 7 | github.com/beevik/ntp v1.4.3 |
10 | | - github.com/digitorus/pkcs7 v0.0.0-20230818184609-3a137a874352 |
11 | | - github.com/digitorus/timestamp v0.0.0-20231217203849-220c5c2851b7 |
| 8 | + github.com/digitorus/pkcs7 v0.0.0-20250730155240-ffadbf3f398c |
| 9 | + github.com/digitorus/timestamp v0.0.0-20250524132541-c45532741eea |
12 | 10 | github.com/go-chi/chi v4.1.2+incompatible |
13 | | - github.com/go-openapi/errors v0.22.1 |
| 11 | + github.com/go-openapi/errors v0.22.2 |
14 | 12 | github.com/go-openapi/loads v0.22.0 |
15 | 13 | github.com/go-openapi/runtime v0.28.0 |
16 | 14 | github.com/go-openapi/spec v0.21.0 |
17 | 15 | github.com/go-openapi/strfmt v0.23.0 |
18 | | - github.com/go-openapi/swag v0.23.1 |
| 16 | + github.com/go-openapi/swag v0.24.1 |
19 | 17 | github.com/go-playground/validator/v10 v10.26.0 |
20 | 18 | github.com/google/go-cmp v0.7.0 |
21 | 19 | github.com/mitchellh/go-homedir v1.1.0 |
22 | 20 | github.com/mitchellh/mapstructure v1.5.0 |
23 | 21 | github.com/pkg/errors v0.9.1 |
24 | | - github.com/prometheus/client_golang v1.22.0 |
| 22 | + github.com/prometheus/client_golang v1.23.2 |
25 | 23 | github.com/rs/cors v1.11.1 |
26 | | - github.com/sigstore/sigstore v1.9.4 |
27 | | - github.com/sigstore/sigstore/pkg/signature/kms/aws v1.9.4 |
28 | | - github.com/sigstore/sigstore/pkg/signature/kms/azure v1.9.4 |
29 | | - github.com/sigstore/sigstore/pkg/signature/kms/gcp v1.9.4 |
30 | | - github.com/sigstore/sigstore/pkg/signature/kms/hashivault v1.9.4 |
31 | | - github.com/spf13/cobra v1.9.1 |
32 | | - github.com/spf13/pflag v1.0.6 |
| 24 | + github.com/sigstore/sigstore v1.9.5 |
| 25 | + github.com/sigstore/sigstore/pkg/signature/kms/aws v1.9.5 |
| 26 | + github.com/sigstore/sigstore/pkg/signature/kms/azure v1.9.5 |
| 27 | + github.com/sigstore/sigstore/pkg/signature/kms/gcp v1.9.5 |
| 28 | + github.com/sigstore/sigstore/pkg/signature/kms/hashivault v1.9.5 |
| 29 | + github.com/spf13/cobra v1.10.1 |
| 30 | + github.com/spf13/pflag v1.0.10 |
33 | 31 | github.com/spf13/viper v1.20.1 |
34 | 32 | github.com/tink-crypto/tink-go-awskms/v2 v2.1.0 |
35 | 33 | github.com/tink-crypto/tink-go-gcpkms/v2 v2.2.0 |
36 | 34 | github.com/tink-crypto/tink-go-hcvault/v2 v2.3.0 |
37 | 35 | github.com/tink-crypto/tink-go/v2 v2.4.0 |
38 | 36 | github.com/urfave/negroni v1.0.0 |
39 | | - go.step.sm/crypto v0.66.0 |
| 37 | + go.step.sm/crypto v0.70.0 |
40 | 38 | go.uber.org/goleak v1.3.0 |
41 | 39 | go.uber.org/zap v1.27.0 |
42 | | - golang.org/x/net v0.40.0 |
43 | | - google.golang.org/protobuf v1.36.6 |
44 | | - sigs.k8s.io/release-utils v0.11.1 |
45 | | - sigs.k8s.io/yaml v1.4.0 |
| 40 | + golang.org/x/net v0.43.0 |
| 41 | + google.golang.org/protobuf v1.36.8 |
| 42 | + sigs.k8s.io/release-utils v0.12.1 |
| 43 | + sigs.k8s.io/yaml v1.6.0 |
46 | 44 | ) |
47 | 45 |
|
48 | 46 | require ( |
49 | | - cloud.google.com/go v0.120.0 // indirect |
50 | | - cloud.google.com/go/auth v0.16.1 // indirect |
| 47 | + cloud.google.com/go v0.122.0 // indirect |
| 48 | + cloud.google.com/go/auth v0.16.5 // indirect |
51 | 49 | cloud.google.com/go/auth/oauth2adapt v0.2.8 // indirect |
52 | | - cloud.google.com/go/compute/metadata v0.7.0 // indirect |
| 50 | + cloud.google.com/go/compute/metadata v0.8.0 // indirect |
53 | 51 | cloud.google.com/go/iam v1.5.2 // indirect |
54 | 52 | cloud.google.com/go/kms v1.22.0 // indirect |
55 | 53 | cloud.google.com/go/longrunning v0.6.7 // indirect |
56 | 54 | filippo.io/edwards25519 v1.1.0 // indirect |
57 | | - github.com/Azure/azure-sdk-for-go/sdk/azcore v1.18.0 // indirect |
58 | | - github.com/Azure/azure-sdk-for-go/sdk/azidentity v1.10.0 // indirect |
59 | | - github.com/Azure/azure-sdk-for-go/sdk/internal v1.11.1 // indirect |
60 | | - github.com/Azure/azure-sdk-for-go/sdk/security/keyvault/azkeys v1.3.1 // indirect |
61 | | - github.com/Azure/azure-sdk-for-go/sdk/security/keyvault/internal v1.1.1 // indirect |
62 | | - github.com/AzureAD/microsoft-authentication-library-for-go v1.4.2 // indirect |
| 55 | + github.com/Azure/azure-sdk-for-go/sdk/azcore v1.19.0 // indirect |
| 56 | + github.com/Azure/azure-sdk-for-go/sdk/azidentity v1.11.0 // indirect |
| 57 | + github.com/Azure/azure-sdk-for-go/sdk/internal v1.11.2 // indirect |
| 58 | + github.com/Azure/azure-sdk-for-go/sdk/security/keyvault/azkeys v1.4.0 // indirect |
| 59 | + github.com/Azure/azure-sdk-for-go/sdk/security/keyvault/internal v1.2.0 // indirect |
| 60 | + github.com/AzureAD/microsoft-authentication-library-for-go v1.5.0 // indirect |
63 | 61 | github.com/asaskevich/govalidator v0.0.0-20230301143203-a9d515a09cc2 // indirect |
64 | | - github.com/aws/aws-sdk-go v1.55.6 // indirect |
65 | | - github.com/aws/aws-sdk-go-v2 v1.36.3 // indirect |
66 | | - github.com/aws/aws-sdk-go-v2/config v1.29.14 // indirect |
67 | | - github.com/aws/aws-sdk-go-v2/credentials v1.17.67 // indirect |
68 | | - github.com/aws/aws-sdk-go-v2/feature/ec2/imds v1.16.30 // indirect |
69 | | - github.com/aws/aws-sdk-go-v2/internal/configsources v1.3.34 // indirect |
70 | | - github.com/aws/aws-sdk-go-v2/internal/endpoints/v2 v2.6.34 // indirect |
| 62 | + github.com/aws/aws-sdk-go v1.55.7 // indirect |
| 63 | + github.com/aws/aws-sdk-go-v2 v1.38.3 // indirect |
| 64 | + github.com/aws/aws-sdk-go-v2/config v1.31.0 // indirect |
| 65 | + github.com/aws/aws-sdk-go-v2/credentials v1.18.10 // indirect |
| 66 | + github.com/aws/aws-sdk-go-v2/feature/ec2/imds v1.18.6 // indirect |
| 67 | + github.com/aws/aws-sdk-go-v2/internal/configsources v1.4.6 // indirect |
| 68 | + github.com/aws/aws-sdk-go-v2/internal/endpoints/v2 v2.7.6 // indirect |
71 | 69 | github.com/aws/aws-sdk-go-v2/internal/ini v1.8.3 // indirect |
72 | | - github.com/aws/aws-sdk-go-v2/service/internal/accept-encoding v1.12.3 // indirect |
73 | | - github.com/aws/aws-sdk-go-v2/service/internal/presigned-url v1.12.15 // indirect |
74 | | - github.com/aws/aws-sdk-go-v2/service/kms v1.38.3 // indirect |
75 | | - github.com/aws/aws-sdk-go-v2/service/sso v1.25.3 // indirect |
76 | | - github.com/aws/aws-sdk-go-v2/service/ssooidc v1.30.1 // indirect |
77 | | - github.com/aws/aws-sdk-go-v2/service/sts v1.33.19 // indirect |
78 | | - github.com/aws/smithy-go v1.22.2 // indirect |
| 70 | + github.com/aws/aws-sdk-go-v2/service/internal/accept-encoding v1.13.1 // indirect |
| 71 | + github.com/aws/aws-sdk-go-v2/service/internal/presigned-url v1.13.6 // indirect |
| 72 | + github.com/aws/aws-sdk-go-v2/service/kms v1.44.0 // indirect |
| 73 | + github.com/aws/aws-sdk-go-v2/service/sso v1.29.1 // indirect |
| 74 | + github.com/aws/aws-sdk-go-v2/service/ssooidc v1.34.2 // indirect |
| 75 | + github.com/aws/aws-sdk-go-v2/service/sts v1.38.2 // indirect |
| 76 | + github.com/aws/smithy-go v1.23.0 // indirect |
79 | 77 | github.com/beorn7/perks v1.0.1 // indirect |
80 | 78 | github.com/cenkalti/backoff/v4 v4.3.0 // indirect |
81 | 79 | github.com/cespare/xxhash/v2 v2.3.0 // indirect |
82 | 80 | github.com/common-nighthawk/go-figure v0.0.0-20210622060536-734e95fb86be // indirect |
83 | 81 | github.com/docker/go-units v0.5.0 // indirect |
84 | 82 | github.com/felixge/httpsnoop v1.0.4 // indirect |
85 | | - github.com/fsnotify/fsnotify v1.8.0 // indirect |
86 | | - github.com/gabriel-vasile/mimetype v1.4.8 // indirect |
87 | | - github.com/go-jose/go-jose/v4 v4.0.5 // indirect |
88 | | - github.com/go-logr/logr v1.4.2 // indirect |
| 83 | + github.com/fsnotify/fsnotify v1.9.0 // indirect |
| 84 | + github.com/gabriel-vasile/mimetype v1.4.10 // indirect |
| 85 | + github.com/go-jose/go-jose/v4 v4.1.2 // indirect |
| 86 | + github.com/go-logr/logr v1.4.3 // indirect |
89 | 87 | github.com/go-logr/stdr v1.2.2 // indirect |
90 | 88 | github.com/go-openapi/analysis v0.23.0 // indirect |
91 | | - github.com/go-openapi/jsonpointer v0.21.1 // indirect |
92 | | - github.com/go-openapi/jsonreference v0.21.0 // indirect |
| 89 | + github.com/go-openapi/jsonpointer v0.22.0 // indirect |
| 90 | + github.com/go-openapi/jsonreference v0.21.1 // indirect |
| 91 | + github.com/go-openapi/swag/cmdutils v0.24.0 // indirect |
| 92 | + github.com/go-openapi/swag/conv v0.24.0 // indirect |
| 93 | + github.com/go-openapi/swag/fileutils v0.24.0 // indirect |
| 94 | + github.com/go-openapi/swag/jsonname v0.24.0 // indirect |
| 95 | + github.com/go-openapi/swag/jsonutils v0.24.0 // indirect |
| 96 | + github.com/go-openapi/swag/loading v0.24.0 // indirect |
| 97 | + github.com/go-openapi/swag/mangling v0.24.0 // indirect |
| 98 | + github.com/go-openapi/swag/netutils v0.24.0 // indirect |
| 99 | + github.com/go-openapi/swag/stringutils v0.24.0 // indirect |
| 100 | + github.com/go-openapi/swag/typeutils v0.24.0 // indirect |
| 101 | + github.com/go-openapi/swag/yamlutils v0.24.0 // indirect |
93 | 102 | github.com/go-openapi/validate v0.24.0 // indirect |
94 | 103 | github.com/go-playground/locales v0.14.1 // indirect |
95 | 104 | github.com/go-playground/universal-translator v0.18.1 // indirect |
96 | 105 | github.com/go-viper/mapstructure/v2 v2.2.1 // indirect |
97 | | - github.com/golang-jwt/jwt/v5 v5.2.2 // indirect |
98 | | - github.com/google/go-containerregistry v0.20.3 // indirect |
| 106 | + github.com/golang-jwt/jwt/v5 v5.3.0 // indirect |
| 107 | + github.com/google/go-containerregistry v0.20.6 // indirect |
99 | 108 | github.com/google/s2a-go v0.1.9 // indirect |
100 | 109 | github.com/google/uuid v1.6.0 // indirect |
101 | 110 | github.com/googleapis/enterprise-certificate-proxy v0.3.6 // indirect |
102 | | - github.com/googleapis/gax-go/v2 v2.14.2 // indirect |
| 111 | + github.com/googleapis/gax-go/v2 v2.15.0 // indirect |
103 | 112 | github.com/hashicorp/errwrap v1.1.0 // indirect |
104 | 113 | github.com/hashicorp/go-cleanhttp v0.5.2 // indirect |
105 | 114 | github.com/hashicorp/go-multierror v1.1.1 // indirect |
106 | | - github.com/hashicorp/go-retryablehttp v0.7.7 // indirect |
| 115 | + github.com/hashicorp/go-retryablehttp v0.7.8 // indirect |
107 | 116 | github.com/hashicorp/go-rootcerts v1.0.2 // indirect |
108 | | - github.com/hashicorp/go-secure-stdlib/parseutil v0.1.7 // indirect |
| 117 | + github.com/hashicorp/go-secure-stdlib/parseutil v0.2.0 // indirect |
109 | 118 | github.com/hashicorp/go-secure-stdlib/strutil v0.1.2 // indirect |
110 | | - github.com/hashicorp/go-sockaddr v1.0.2 // indirect |
111 | | - github.com/hashicorp/hcl v1.0.0 // indirect |
112 | | - github.com/hashicorp/vault/api v1.16.0 // indirect |
| 119 | + github.com/hashicorp/go-sockaddr v1.0.6 // indirect |
| 120 | + github.com/hashicorp/hcl v1.0.1-vault-7 // indirect |
| 121 | + github.com/hashicorp/vault/api v1.20.0 // indirect |
113 | 122 | github.com/inconshreveable/mousetrap v1.1.0 // indirect |
114 | 123 | github.com/jellydator/ttlcache/v3 v3.3.0 // indirect |
115 | 124 | github.com/jmespath/go-jmespath v0.4.1-0.20220621161143-b0104c826a24 // indirect |
116 | 125 | github.com/josharian/intern v1.0.0 // indirect |
117 | 126 | github.com/kylelemons/godebug v1.1.0 // indirect |
118 | 127 | github.com/leodido/go-urn v1.4.0 // indirect |
119 | | - github.com/letsencrypt/boulder v0.0.0-20240620165639-de9c06129bec // indirect |
| 128 | + github.com/letsencrypt/boulder v0.20250902.0 // indirect |
120 | 129 | github.com/mailru/easyjson v0.9.0 // indirect |
121 | 130 | github.com/munnerz/goautoneg v0.0.0-20191010083416-a7dc8b61c822 // indirect |
122 | 131 | github.com/oklog/ulid v1.3.1 // indirect |
123 | 132 | github.com/opencontainers/go-digest v1.0.0 // indirect |
124 | 133 | github.com/opentracing/opentracing-go v1.2.0 // indirect |
125 | 134 | github.com/pelletier/go-toml/v2 v2.2.3 // indirect |
126 | 135 | github.com/pkg/browser v0.0.0-20240102092130-5ac0b6a4141c // indirect |
127 | | - github.com/prometheus/client_model v0.6.1 // indirect |
128 | | - github.com/prometheus/common v0.62.0 // indirect |
129 | | - github.com/prometheus/procfs v0.15.1 // indirect |
| 136 | + github.com/prometheus/client_model v0.6.2 // indirect |
| 137 | + github.com/prometheus/common v0.66.1 // indirect |
| 138 | + github.com/prometheus/procfs v0.17.0 // indirect |
130 | 139 | github.com/ryanuber/go-glob v1.0.0 // indirect |
131 | | - github.com/sagikazarmark/locafero v0.7.0 // indirect |
132 | | - github.com/secure-systems-lab/go-securesystemslib v0.9.0 // indirect |
133 | | - github.com/sigstore/protobuf-specs v0.4.1 // indirect |
134 | | - github.com/sourcegraph/conc v0.3.0 // indirect |
135 | | - github.com/spf13/afero v1.12.0 // indirect |
136 | | - github.com/spf13/cast v1.7.1 // indirect |
| 140 | + github.com/sagikazarmark/locafero v0.10.0 // indirect |
| 141 | + github.com/secure-systems-lab/go-securesystemslib v0.9.1 // indirect |
| 142 | + github.com/sigstore/protobuf-specs v0.5.0 // indirect |
| 143 | + github.com/sourcegraph/conc v0.3.1-0.20240121214520-5f936abd7ae8 // indirect |
| 144 | + github.com/spf13/afero v1.14.0 // indirect |
| 145 | + github.com/spf13/cast v1.9.2 // indirect |
137 | 146 | github.com/subosito/gotenv v1.6.0 // indirect |
138 | 147 | github.com/titanous/rocacheck v0.0.0-20171023193734-afe73141d399 // indirect |
139 | | - go.mongodb.org/mongo-driver v1.14.0 // indirect |
| 148 | + go.mongodb.org/mongo-driver v1.17.4 // indirect |
140 | 149 | go.opentelemetry.io/auto/sdk v1.1.0 // indirect |
141 | | - go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc v0.60.0 // indirect |
142 | | - go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.60.0 // indirect |
143 | | - go.opentelemetry.io/otel v1.35.0 // indirect |
144 | | - go.opentelemetry.io/otel/metric v1.35.0 // indirect |
145 | | - go.opentelemetry.io/otel/trace v1.35.0 // indirect |
| 150 | + go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc v0.63.0 // indirect |
| 151 | + go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.63.0 // indirect |
| 152 | + go.opentelemetry.io/otel v1.38.0 // indirect |
| 153 | + go.opentelemetry.io/otel/metric v1.38.0 // indirect |
| 154 | + go.opentelemetry.io/otel/trace v1.38.0 // indirect |
146 | 155 | go.uber.org/multierr v1.11.0 // indirect |
147 | | - golang.org/x/crypto v0.38.0 // indirect |
148 | | - golang.org/x/oauth2 v0.30.0 // indirect |
149 | | - golang.org/x/sync v0.14.0 // indirect |
150 | | - golang.org/x/sys v0.33.0 // indirect |
151 | | - golang.org/x/term v0.32.0 // indirect |
152 | | - golang.org/x/text v0.25.0 // indirect |
153 | | - golang.org/x/time v0.11.0 // indirect |
154 | | - google.golang.org/api v0.234.0 // indirect |
155 | | - google.golang.org/genproto v0.0.0-20250505200425-f936aa4a68b2 // indirect |
156 | | - google.golang.org/genproto/googleapis/api v0.0.0-20250505200425-f936aa4a68b2 // indirect |
157 | | - google.golang.org/genproto/googleapis/rpc v0.0.0-20250512202823-5a2f75b736a9 // indirect |
158 | | - google.golang.org/grpc v1.72.2 // indirect |
| 156 | + go.yaml.in/yaml/v2 v2.4.2 // indirect |
| 157 | + golang.org/x/crypto v0.41.0 // indirect |
| 158 | + golang.org/x/oauth2 v0.31.0 // indirect |
| 159 | + golang.org/x/sync v0.17.0 // indirect |
| 160 | + golang.org/x/sys v0.36.0 // indirect |
| 161 | + golang.org/x/term v0.34.0 // indirect |
| 162 | + golang.org/x/text v0.28.0 // indirect |
| 163 | + golang.org/x/time v0.13.0 // indirect |
| 164 | + google.golang.org/api v0.248.0 // indirect |
| 165 | + google.golang.org/genproto v0.0.0-20250826171959-ef028d996bc1 // indirect |
| 166 | + google.golang.org/genproto/googleapis/api v0.0.0-20250826171959-ef028d996bc1 // indirect |
| 167 | + google.golang.org/genproto/googleapis/rpc v0.0.0-20250826171959-ef028d996bc1 // indirect |
| 168 | + google.golang.org/grpc v1.75.0 // indirect |
159 | 169 | gopkg.in/yaml.v3 v3.0.1 // indirect |
160 | 170 | ) |
0 commit comments