From 9614d4dd18cfcfab3db3b9aab1afcb8456eb090b Mon Sep 17 00:00:00 2001 From: Brandon Mitchell Date: Sun, 19 Apr 2026 10:07:04 -0400 Subject: [PATCH] Version bump - Alpine to v2.32.4 - govulncheck to v1.2.0 - go-git/go-git to v5.18.0 - regclient/regclient to v0.11.3 Signed-off-by: Brandon Mitchell --- .version-bump.lock | 8 ++++---- Dockerfile | 4 ++-- Dockerfile.buildkit | 4 ++-- Makefile | 2 +- go.mod | 4 ++-- go.sum | 8 ++++---- 6 files changed, 15 insertions(+), 15 deletions(-) diff --git a/.version-bump.lock b/.version-bump.lock index 4df3177..f0f3425 100644 --- a/.version-bump.lock +++ b/.version-bump.lock @@ -1,6 +1,6 @@ -{"name":"docker-arg-alpine-digest","key":"docker.io/library/alpine:3.23.3","version":"sha256:25109184c71bdad752c8312a8623239686a9a2071e8825f20acb8f2198c3f659"} -{"name":"docker-arg-alpine-tag","key":"docker.io/library/alpine","version":"3.23.3"} -{"name":"docker-arg-go-digest","key":"docker.io/library/golang:1.26.2-alpine","version":"sha256:c2a1f7b2095d046ae14b286b18413a05bb82c9bca9b25fe7ff5efef0f0826166"} +{"name":"docker-arg-alpine-digest","key":"docker.io/library/alpine:3.23.4","version":"sha256:5b10f432ef3da1b8d4c7eb6c487f2f5a8f096bc91145e68878dd4a5019afde11"} +{"name":"docker-arg-alpine-tag","key":"docker.io/library/alpine","version":"3.23.4"} +{"name":"docker-arg-go-digest","key":"docker.io/library/golang:1.26.2-alpine","version":"sha256:f85330846cde1e57ca9ec309382da3b8e6ae3ab943d2739500e08c86393a21b1"} {"name":"docker-arg-go-tag","key":"docker.io/library/golang","version":"1.26.2"} {"name":"gha-golang-release","key":"golang-latest","version":"1.26"} {"name":"gha-uses-commit","key":"https://github.com/actions/checkout.git:v6.0.2","version":"de0fac2e4500dabe0009e67214ff5f5447ce83dd"} @@ -20,7 +20,7 @@ {"name":"gha-uses-semver","key":"https://github.com/sigstore/cosign-installer.git","version":"v4.1.1"} {"name":"gha-uses-semver","key":"https://github.com/softprops/action-gh-release.git","version":"v3.0.0"} {"name":"go-mod-golang-release","key":"golang-latest","version":"1.26"} -{"name":"makefile-go-vulncheck","key":"https://go.googlesource.com/vuln.git","version":"v1.1.4"} +{"name":"makefile-go-vulncheck","key":"https://go.googlesource.com/vuln.git","version":"v1.2.0"} {"name":"makefile-gofumpt","key":"https://github.com/mvdan/gofumpt.git","version":"v0.9.2"} {"name":"makefile-gomajor","key":"https://github.com/icholy/gomajor.git","version":"v0.15.0"} {"name":"makefile-gosec","key":"https://github.com/securego/gosec.git","version":"v2.25.0"} diff --git a/Dockerfile b/Dockerfile index e76838e..058ef94 100644 --- a/Dockerfile +++ b/Dockerfile @@ -1,6 +1,6 @@ ARG REGISTRY=docker.io -ARG ALPINE_VER=3.23.3@sha256:25109184c71bdad752c8312a8623239686a9a2071e8825f20acb8f2198c3f659 -ARG GO_VER=1.26.2-alpine@sha256:c2a1f7b2095d046ae14b286b18413a05bb82c9bca9b25fe7ff5efef0f0826166 +ARG ALPINE_VER=3.23.4@sha256:5b10f432ef3da1b8d4c7eb6c487f2f5a8f096bc91145e68878dd4a5019afde11 +ARG GO_VER=1.26.2-alpine@sha256:f85330846cde1e57ca9ec309382da3b8e6ae3ab943d2739500e08c86393a21b1 FROM ${REGISTRY}/library/golang:${GO_VER} AS build RUN apk add --no-cache \ diff --git a/Dockerfile.buildkit b/Dockerfile.buildkit index 8e97725..b89fb4b 100644 --- a/Dockerfile.buildkit +++ b/Dockerfile.buildkit @@ -1,6 +1,6 @@ ARG REGISTRY=docker.io -ARG ALPINE_VER=3.23.3@sha256:25109184c71bdad752c8312a8623239686a9a2071e8825f20acb8f2198c3f659 -ARG GO_VER=1.26.2-alpine@sha256:c2a1f7b2095d046ae14b286b18413a05bb82c9bca9b25fe7ff5efef0f0826166 +ARG ALPINE_VER=3.23.4@sha256:5b10f432ef3da1b8d4c7eb6c487f2f5a8f096bc91145e68878dd4a5019afde11 +ARG GO_VER=1.26.2-alpine@sha256:f85330846cde1e57ca9ec309382da3b8e6ae3ab943d2739500e08c86393a21b1 FROM --platform=$BUILDPLATFORM ${REGISTRY}/library/golang:${GO_VER} AS build RUN apk add --no-cache \ diff --git a/Makefile b/Makefile index ae5da43..20b18d9 100644 --- a/Makefile +++ b/Makefile @@ -21,7 +21,7 @@ MARKDOWN_LINT_VER?=v0.22.0 GOFUMPT_VER?=v0.9.2 GOMAJOR_VER?=v0.15.0 GOSEC_VER?=v2.25.0 -GO_VULNCHECK_VER?=v1.1.4 +GO_VULNCHECK_VER?=v1.2.0 OSV_SCANNER_VER?=v2.3.5 STATICCHECK_VER?=v0.7.0 diff --git a/go.mod b/go.mod index 5b43e3b..b8338c6 100644 --- a/go.mod +++ b/go.mod @@ -4,9 +4,9 @@ go 1.26 require ( github.com/Masterminds/semver/v3 v3.4.0 - github.com/go-git/go-git/v5 v5.17.2 + github.com/go-git/go-git/v5 v5.18.0 github.com/goccy/go-yaml v1.19.2 - github.com/regclient/regclient v0.11.2 + github.com/regclient/regclient v0.11.3 github.com/spf13/cobra v1.10.2 ) diff --git a/go.sum b/go.sum index f082d23..936361b 100644 --- a/go.sum +++ b/go.sum @@ -33,8 +33,8 @@ github.com/go-git/go-billy/v5 v5.8.0 h1:I8hjc3LbBlXTtVuFNJuwYuMiHvQJDq1AT6u4DwDz github.com/go-git/go-billy/v5 v5.8.0/go.mod h1:RpvI/rw4Vr5QA+Z60c6d6LXH0rYJo0uD5SqfmrrheCY= github.com/go-git/go-git-fixtures/v4 v4.3.2-0.20231010084843-55a94097c399 h1:eMje31YglSBqCdIqdhKBW8lokaMrL3uTkpGYlE2OOT4= github.com/go-git/go-git-fixtures/v4 v4.3.2-0.20231010084843-55a94097c399/go.mod h1:1OCfN199q1Jm3HZlxleg+Dw/mwps2Wbk9frAWm+4FII= -github.com/go-git/go-git/v5 v5.17.2 h1:B+nkdlxdYrvyFK4GPXVU8w1U+YkbsgciIR7f2sZJ104= -github.com/go-git/go-git/v5 v5.17.2/go.mod h1:pW/VmeqkanRFqR6AljLcs7EA7FbZaN5MQqO7oZADXpo= +github.com/go-git/go-git/v5 v5.18.0 h1:O831KI+0PR51hM2kep6T8k+w0/LIAD490gvqMCvL5hM= +github.com/go-git/go-git/v5 v5.18.0/go.mod h1:pW/VmeqkanRFqR6AljLcs7EA7FbZaN5MQqO7oZADXpo= github.com/goccy/go-yaml v1.19.2 h1:PmFC1S6h8ljIz6gMRBopkjP1TVT7xuwrButHID66PoM= github.com/goccy/go-yaml v1.19.2/go.mod h1:XBurs7gK8ATbW4ZPGKgcbrY1Br56PdM69F7LkFRi1kA= github.com/golang/groupcache v0.0.0-20241129210726-2c02b8208cf8 h1:f+oWsMOmNPc8JmEHVZIycC7hBoQxHH9pNKQORJNozsQ= @@ -70,8 +70,8 @@ github.com/pkg/errors v0.9.1 h1:FEBLx1zS214owpjy7qsBeixbURkuhQAwrK5UwLGTwt4= github.com/pkg/errors v0.9.1/go.mod h1:bwawxfHBFNV+L2hUp1rHADufV3IMtnDRdf1r5NINEl0= github.com/pmezard/go-difflib v1.0.0 h1:4DBwDE0NGyQoBHbLQYPwSUPoCMWR5BEzIk/f1lZbAQM= github.com/pmezard/go-difflib v1.0.0/go.mod h1:iKH77koFhYxTK1pcRnkKkqfTogsbg7gZNVY4sRDYZ/4= -github.com/regclient/regclient v0.11.2 h1:BMBxbXpJkia8CPnGTbJoQnt980NDh9dKNFxX57ah1/Q= -github.com/regclient/regclient v0.11.2/go.mod h1:AWbO1F0DJGP7MNlwmDHjYbgOEftZsTB0N0AXT6pN2C4= +github.com/regclient/regclient v0.11.3 h1:aTnVRsgFaOmezgKp7caL3zINrZKAXsMbzS1oCgD7/cA= +github.com/regclient/regclient v0.11.3/go.mod h1:a4PDi+VyEbBuV/5hCfMjnYH8jvB7NgD0mdggwNRECy8= github.com/rogpeppe/go-internal v1.14.1 h1:UQB4HGPB6osV0SQTLymcB4TgvyWu6ZyliaW0tI/otEQ= github.com/rogpeppe/go-internal v1.14.1/go.mod h1:MaRKkUm5W0goXpeCfT7UZI6fk/L7L7so1lCWt35ZSgc= github.com/russross/blackfriday/v2 v2.1.0/go.mod h1:+Rmxgy9KzJVeS9/2gXHxylqXiyQDYRxCVz55jmeOWTM=