Skip to content

Commit 7b48ac4

Browse files
authored
fix(deps): update osv-scanner minor (#1472)
This PR contains the following updates: | Package | Change | Age | Adoption | Passing | Confidence | Type | Update | |---|---|---|---|---|---|---|---| | [deps.dev/api/v3](https://redirect.github.com/google/deps.dev) | `v3.0.0-20241223232618-f8b47b9fbbab` -> `v3.0.0-20250114022823-c1ebdca3d00a` | [![age](https://developer.mend.io/api/mc/badges/age/go/deps.dev%2fapi%2fv3/v3.0.0-20250114022823-c1ebdca3d00a?slim=true)](https://docs.renovatebot.com/merge-confidence/) | [![adoption](https://developer.mend.io/api/mc/badges/adoption/go/deps.dev%2fapi%2fv3/v3.0.0-20250114022823-c1ebdca3d00a?slim=true)](https://docs.renovatebot.com/merge-confidence/) | [![passing](https://developer.mend.io/api/mc/badges/compatibility/go/deps.dev%2fapi%2fv3/v3.0.0-20241223232618-f8b47b9fbbab/v3.0.0-20250114022823-c1ebdca3d00a?slim=true)](https://docs.renovatebot.com/merge-confidence/) | [![confidence](https://developer.mend.io/api/mc/badges/confidence/go/deps.dev%2fapi%2fv3/v3.0.0-20241223232618-f8b47b9fbbab/v3.0.0-20250114022823-c1ebdca3d00a?slim=true)](https://docs.renovatebot.com/merge-confidence/) | require | patch | | [deps.dev/util/maven](https://redirect.github.com/google/deps.dev) | `3e2fcc7` -> `c1ebdca` | [![age](https://developer.mend.io/api/mc/badges/age/go/deps.dev%2futil%2fmaven/v0.0.0-20250114022823-c1ebdca3d00a?slim=true)](https://docs.renovatebot.com/merge-confidence/) | [![adoption](https://developer.mend.io/api/mc/badges/adoption/go/deps.dev%2futil%2fmaven/v0.0.0-20250114022823-c1ebdca3d00a?slim=true)](https://docs.renovatebot.com/merge-confidence/) | [![passing](https://developer.mend.io/api/mc/badges/compatibility/go/deps.dev%2futil%2fmaven/v0.0.0-20241223234259-3e2fcc756990/v0.0.0-20250114022823-c1ebdca3d00a?slim=true)](https://docs.renovatebot.com/merge-confidence/) | [![confidence](https://developer.mend.io/api/mc/badges/confidence/go/deps.dev%2futil%2fmaven/v0.0.0-20241223234259-3e2fcc756990/v0.0.0-20250114022823-c1ebdca3d00a?slim=true)](https://docs.renovatebot.com/merge-confidence/) | require | digest | | [deps.dev/util/resolve](https://redirect.github.com/google/deps.dev) | `d36e05e` -> `c1ebdca` | [![age](https://developer.mend.io/api/mc/badges/age/go/deps.dev%2futil%2fresolve/v0.0.0-20250114022823-c1ebdca3d00a?slim=true)](https://docs.renovatebot.com/merge-confidence/) | [![adoption](https://developer.mend.io/api/mc/badges/adoption/go/deps.dev%2futil%2fresolve/v0.0.0-20250114022823-c1ebdca3d00a?slim=true)](https://docs.renovatebot.com/merge-confidence/) | [![passing](https://developer.mend.io/api/mc/badges/compatibility/go/deps.dev%2futil%2fresolve/v0.0.0-20241223234119-d36e05e6460f/v0.0.0-20250114022823-c1ebdca3d00a?slim=true)](https://docs.renovatebot.com/merge-confidence/) | [![confidence](https://developer.mend.io/api/mc/badges/confidence/go/deps.dev%2futil%2fresolve/v0.0.0-20241223234119-d36e05e6460f/v0.0.0-20250114022823-c1ebdca3d00a?slim=true)](https://docs.renovatebot.com/merge-confidence/) | require | digest | | [deps.dev/util/semver](https://redirect.github.com/google/deps.dev) | `018358f` -> `c1ebdca` | [![age](https://developer.mend.io/api/mc/badges/age/go/deps.dev%2futil%2fsemver/v0.0.0-20250114022823-c1ebdca3d00a?slim=true)](https://docs.renovatebot.com/merge-confidence/) | [![adoption](https://developer.mend.io/api/mc/badges/adoption/go/deps.dev%2futil%2fsemver/v0.0.0-20250114022823-c1ebdca3d00a?slim=true)](https://docs.renovatebot.com/merge-confidence/) | [![passing](https://developer.mend.io/api/mc/badges/compatibility/go/deps.dev%2futil%2fsemver/v0.0.0-20241223233905-018358ffdd50/v0.0.0-20250114022823-c1ebdca3d00a?slim=true)](https://docs.renovatebot.com/merge-confidence/) | [![confidence](https://developer.mend.io/api/mc/badges/confidence/go/deps.dev%2futil%2fsemver/v0.0.0-20241223233905-018358ffdd50/v0.0.0-20250114022823-c1ebdca3d00a?slim=true)](https://docs.renovatebot.com/merge-confidence/) | require | digest | | [github.com/gkampitakis/go-snaps](https://redirect.github.com/gkampitakis/go-snaps) | `v0.5.7` -> `v0.5.8` | [![age](https://developer.mend.io/api/mc/badges/age/go/github.com%2fgkampitakis%2fgo-snaps/v0.5.8?slim=true)](https://docs.renovatebot.com/merge-confidence/) | [![adoption](https://developer.mend.io/api/mc/badges/adoption/go/github.com%2fgkampitakis%2fgo-snaps/v0.5.8?slim=true)](https://docs.renovatebot.com/merge-confidence/) | [![passing](https://developer.mend.io/api/mc/badges/compatibility/go/github.com%2fgkampitakis%2fgo-snaps/v0.5.7/v0.5.8?slim=true)](https://docs.renovatebot.com/merge-confidence/) | [![confidence](https://developer.mend.io/api/mc/badges/confidence/go/github.com%2fgkampitakis%2fgo-snaps/v0.5.7/v0.5.8?slim=true)](https://docs.renovatebot.com/merge-confidence/) | require | patch | | [github.com/go-git/go-billy/v5](https://redirect.github.com/go-git/go-billy) | `v5.6.0` -> `v5.6.2` | [![age](https://developer.mend.io/api/mc/badges/age/go/github.com%2fgo-git%2fgo-billy%2fv5/v5.6.2?slim=true)](https://docs.renovatebot.com/merge-confidence/) | [![adoption](https://developer.mend.io/api/mc/badges/adoption/go/github.com%2fgo-git%2fgo-billy%2fv5/v5.6.2?slim=true)](https://docs.renovatebot.com/merge-confidence/) | [![passing](https://developer.mend.io/api/mc/badges/compatibility/go/github.com%2fgo-git%2fgo-billy%2fv5/v5.6.0/v5.6.2?slim=true)](https://docs.renovatebot.com/merge-confidence/) | [![confidence](https://developer.mend.io/api/mc/badges/confidence/go/github.com%2fgo-git%2fgo-billy%2fv5/v5.6.0/v5.6.2?slim=true)](https://docs.renovatebot.com/merge-confidence/) | require | patch | | [github.com/go-git/go-git/v5](https://redirect.github.com/go-git/go-git) | `v5.13.0` -> `v5.13.1` | [![age](https://developer.mend.io/api/mc/badges/age/go/github.com%2fgo-git%2fgo-git%2fv5/v5.13.1?slim=true)](https://docs.renovatebot.com/merge-confidence/) | [![adoption](https://developer.mend.io/api/mc/badges/adoption/go/github.com%2fgo-git%2fgo-git%2fv5/v5.13.1?slim=true)](https://docs.renovatebot.com/merge-confidence/) | [![passing](https://developer.mend.io/api/mc/badges/compatibility/go/github.com%2fgo-git%2fgo-git%2fv5/v5.13.0/v5.13.1?slim=true)](https://docs.renovatebot.com/merge-confidence/) | [![confidence](https://developer.mend.io/api/mc/badges/confidence/go/github.com%2fgo-git%2fgo-git%2fv5/v5.13.0/v5.13.1?slim=true)](https://docs.renovatebot.com/merge-confidence/) | require | patch | | [github.com/ossf/osv-schema/bindings/go](https://redirect.github.com/ossf/osv-schema) | `57fd3dd` -> `8059be3` | [![age](https://developer.mend.io/api/mc/badges/age/go/github.com%2fossf%2fosv-schema%2fbindings%2fgo/v0.0.0-20250120003634-8059be3f33a9?slim=true)](https://docs.renovatebot.com/merge-confidence/) | [![adoption](https://developer.mend.io/api/mc/badges/adoption/go/github.com%2fossf%2fosv-schema%2fbindings%2fgo/v0.0.0-20250120003634-8059be3f33a9?slim=true)](https://docs.renovatebot.com/merge-confidence/) | [![passing](https://developer.mend.io/api/mc/badges/compatibility/go/github.com%2fossf%2fosv-schema%2fbindings%2fgo/v0.0.0-20241210213101-57fd3ddb15aa/v0.0.0-20250120003634-8059be3f33a9?slim=true)](https://docs.renovatebot.com/merge-confidence/) | [![confidence](https://developer.mend.io/api/mc/badges/confidence/go/github.com%2fossf%2fosv-schema%2fbindings%2fgo/v0.0.0-20241210213101-57fd3ddb15aa/v0.0.0-20250120003634-8059be3f33a9?slim=true)](https://docs.renovatebot.com/merge-confidence/) | require | digest | | golang.org/x/exp | `b2144cd` -> `7588d65` | [![age](https://developer.mend.io/api/mc/badges/age/go/golang.org%2fx%2fexp/v0.0.0-20250106191152-7588d65b2ba8?slim=true)](https://docs.renovatebot.com/merge-confidence/) | [![adoption](https://developer.mend.io/api/mc/badges/adoption/go/golang.org%2fx%2fexp/v0.0.0-20250106191152-7588d65b2ba8?slim=true)](https://docs.renovatebot.com/merge-confidence/) | [![passing](https://developer.mend.io/api/mc/badges/compatibility/go/golang.org%2fx%2fexp/v0.0.0-20241217172543-b2144cdd0a67/v0.0.0-20250106191152-7588d65b2ba8?slim=true)](https://docs.renovatebot.com/merge-confidence/) | [![confidence](https://developer.mend.io/api/mc/badges/confidence/go/golang.org%2fx%2fexp/v0.0.0-20241217172543-b2144cdd0a67/v0.0.0-20250106191152-7588d65b2ba8?slim=true)](https://docs.renovatebot.com/merge-confidence/) | require | digest | | golang.org/x/net | `v0.33.0` -> `v0.34.0` | [![age](https://developer.mend.io/api/mc/badges/age/go/golang.org%2fx%2fnet/v0.34.0?slim=true)](https://docs.renovatebot.com/merge-confidence/) | [![adoption](https://developer.mend.io/api/mc/badges/adoption/go/golang.org%2fx%2fnet/v0.34.0?slim=true)](https://docs.renovatebot.com/merge-confidence/) | [![passing](https://developer.mend.io/api/mc/badges/compatibility/go/golang.org%2fx%2fnet/v0.33.0/v0.34.0?slim=true)](https://docs.renovatebot.com/merge-confidence/) | [![confidence](https://developer.mend.io/api/mc/badges/confidence/go/golang.org%2fx%2fnet/v0.33.0/v0.34.0?slim=true)](https://docs.renovatebot.com/merge-confidence/) | require | minor | | golang.org/x/sync | `v0.7.0` -> `v0.10.0` | [![age](https://developer.mend.io/api/mc/badges/age/go/golang.org%2fx%2fsync/v0.10.0?slim=true)](https://docs.renovatebot.com/merge-confidence/) | [![adoption](https://developer.mend.io/api/mc/badges/adoption/go/golang.org%2fx%2fsync/v0.10.0?slim=true)](https://docs.renovatebot.com/merge-confidence/) | [![passing](https://developer.mend.io/api/mc/badges/compatibility/go/golang.org%2fx%2fsync/v0.7.0/v0.10.0?slim=true)](https://docs.renovatebot.com/merge-confidence/) | [![confidence](https://developer.mend.io/api/mc/badges/confidence/go/golang.org%2fx%2fsync/v0.7.0/v0.10.0?slim=true)](https://docs.renovatebot.com/merge-confidence/) | require | minor | | golang.org/x/term | `v0.27.0` -> `v0.28.0` | [![age](https://developer.mend.io/api/mc/badges/age/go/golang.org%2fx%2fterm/v0.28.0?slim=true)](https://docs.renovatebot.com/merge-confidence/) | [![adoption](https://developer.mend.io/api/mc/badges/adoption/go/golang.org%2fx%2fterm/v0.28.0?slim=true)](https://docs.renovatebot.com/merge-confidence/) | [![passing](https://developer.mend.io/api/mc/badges/compatibility/go/golang.org%2fx%2fterm/v0.27.0/v0.28.0?slim=true)](https://docs.renovatebot.com/merge-confidence/) | [![confidence](https://developer.mend.io/api/mc/badges/confidence/go/golang.org%2fx%2fterm/v0.27.0/v0.28.0?slim=true)](https://docs.renovatebot.com/merge-confidence/) | require | minor | | [google.golang.org/grpc](https://redirect.github.com/grpc/grpc-go) | `v1.69.2` -> `v1.69.4` | [![age](https://developer.mend.io/api/mc/badges/age/go/google.golang.org%2fgrpc/v1.69.4?slim=true)](https://docs.renovatebot.com/merge-confidence/) | [![adoption](https://developer.mend.io/api/mc/badges/adoption/go/google.golang.org%2fgrpc/v1.69.4?slim=true)](https://docs.renovatebot.com/merge-confidence/) | [![passing](https://developer.mend.io/api/mc/badges/compatibility/go/google.golang.org%2fgrpc/v1.69.2/v1.69.4?slim=true)](https://docs.renovatebot.com/merge-confidence/) | [![confidence](https://developer.mend.io/api/mc/badges/confidence/go/google.golang.org%2fgrpc/v1.69.2/v1.69.4?slim=true)](https://docs.renovatebot.com/merge-confidence/) | require | patch | | [google.golang.org/protobuf](https://redirect.github.com/protocolbuffers/protobuf-go) | `v1.36.1` -> `v1.36.3` | [![age](https://developer.mend.io/api/mc/badges/age/go/google.golang.org%2fprotobuf/v1.36.3?slim=true)](https://docs.renovatebot.com/merge-confidence/) | [![adoption](https://developer.mend.io/api/mc/badges/adoption/go/google.golang.org%2fprotobuf/v1.36.3?slim=true)](https://docs.renovatebot.com/merge-confidence/) | [![passing](https://developer.mend.io/api/mc/badges/compatibility/go/google.golang.org%2fprotobuf/v1.36.1/v1.36.3?slim=true)](https://docs.renovatebot.com/merge-confidence/) | [![confidence](https://developer.mend.io/api/mc/badges/confidence/go/google.golang.org%2fprotobuf/v1.36.1/v1.36.3?slim=true)](https://docs.renovatebot.com/merge-confidence/) | require | patch | --- ### Release Notes <details> <summary>gkampitakis/go-snaps (github.com/gkampitakis/go-snaps)</summary> ### [`v0.5.8`](https://redirect.github.com/gkampitakis/go-snaps/releases/tag/v0.5.8) [Compare Source](https://redirect.github.com/gkampitakis/go-snaps/compare/v0.5.7...v0.5.8) #### What's Changed - feat: implement matchYAML by [@&#8203;gkampitakis](https://redirect.github.com/gkampitakis) in [https://github.com/gkampitakis/go-snaps/pull/114](https://redirect.github.com/gkampitakis/go-snaps/pull/114) - feat: implement matchStandaloneJSON by [@&#8203;gkampitakis](https://redirect.github.com/gkampitakis) in [https://github.com/gkampitakis/go-snaps/pull/113](https://redirect.github.com/gkampitakis/go-snaps/pull/113) **Full Changelog**: gkampitakis/go-snaps@v0.5.7...v0.5.8 </details> <details> <summary>go-git/go-billy (github.com/go-git/go-billy/v5)</summary> ### [`v5.6.2`](https://redirect.github.com/go-git/go-billy/releases/tag/v5.6.2) [Compare Source](https://redirect.github.com/go-git/go-billy/compare/v5.6.1...v5.6.2) #### What's Changed - Enable the `iofs` adapter to also return other interfaces from `io/fs` by [@&#8203;JAORMX](https://redirect.github.com/JAORMX) in [https://github.com/go-git/go-billy/pull/102](https://redirect.github.com/go-git/go-billy/pull/102) - build: Bump dependencies by [@&#8203;pjbgf](https://redirect.github.com/pjbgf) in [https://github.com/go-git/go-billy/pull/103](https://redirect.github.com/go-git/go-billy/pull/103) #### New Contributors - [@&#8203;JAORMX](https://redirect.github.com/JAORMX) made their first contribution in [https://github.com/go-git/go-billy/pull/102](https://redirect.github.com/go-git/go-billy/pull/102) **Full Changelog**: go-git/go-billy@v5.6.1...v5.6.2 ### [`v5.6.1`](https://redirect.github.com/go-git/go-billy/releases/tag/v5.6.1) [Compare Source](https://redirect.github.com/go-git/go-billy/compare/v5.6.0...v5.6.1) #### What's Changed - build: bump github/codeql-action from 3.26.11 to 3.27.0 by [@&#8203;dependabot](https://redirect.github.com/dependabot) in [https://github.com/go-git/go-billy/pull/88](https://redirect.github.com/go-git/go-billy/pull/88) - build: bump github/codeql-action from 3.27.0 to 3.27.1 by [@&#8203;dependabot](https://redirect.github.com/dependabot) in [https://github.com/go-git/go-billy/pull/89](https://redirect.github.com/go-git/go-billy/pull/89) - build: bump github/codeql-action from 3.27.1 to 3.27.4 by [@&#8203;dependabot](https://redirect.github.com/dependabot) in [https://github.com/go-git/go-billy/pull/90](https://redirect.github.com/go-git/go-billy/pull/90) - build: bump github/codeql-action from 3.27.4 to 3.27.5 by [@&#8203;dependabot](https://redirect.github.com/dependabot) in [https://github.com/go-git/go-billy/pull/91](https://redirect.github.com/go-git/go-billy/pull/91) - Bump dependencies and build housekeeping by [@&#8203;pjbgf](https://redirect.github.com/pjbgf) in [https://github.com/go-git/go-billy/pull/95](https://redirect.github.com/go-git/go-billy/pull/95) **Full Changelog**: go-git/go-billy@v5.6.0...v5.6.1 </details> <details> <summary>go-git/go-git (github.com/go-git/go-git/v5)</summary> ### [`v5.13.1`](https://redirect.github.com/go-git/go-git/releases/tag/v5.13.1) [Compare Source](https://redirect.github.com/go-git/go-git/compare/v5.13.0...v5.13.1) #### What's Changed - build: bump github.com/go-git/go-billy/v5 from 5.6.0 to 5.6.1 by [@&#8203;dependabot](https://redirect.github.com/dependabot) in [https://github.com/go-git/go-git/pull/1327](https://redirect.github.com/go-git/go-git/pull/1327) - build: bump github.com/elazarl/goproxy from 1.2.1 to 1.2.2 by [@&#8203;dependabot](https://redirect.github.com/dependabot) in [https://github.com/go-git/go-git/pull/1329](https://redirect.github.com/go-git/go-git/pull/1329) - build: bump github.com/elazarl/goproxy from 1.2.2 to 1.2.3 by [@&#8203;dependabot](https://redirect.github.com/dependabot) in [https://github.com/go-git/go-git/pull/1340](https://redirect.github.com/go-git/go-git/pull/1340) - Revert "plumbing: transport/ssh, Add support for SSH [@&#8203;cert-authority](https://redirect.github.com/cert-authority)." by [@&#8203;pjbgf](https://redirect.github.com/pjbgf) in [#&#8203;1346](https://redirect.github.com/go-git/go-git/issues/1346) **Full Changelog**: go-git/go-git@v5.13.0...v5.13.1 </details> <details> <summary>grpc/grpc-go (google.golang.org/grpc)</summary> ### [`v1.69.4`](https://redirect.github.com/grpc/grpc-go/releases/tag/v1.69.4): Release 1.69.4 [Compare Source](https://redirect.github.com/grpc/grpc-go/compare/v1.69.2...v1.69.4) ### Bug Fixes - rbac: fix support for :path header matchers, which would previously never successfully match ([#&#8203;7965](https://redirect.github.com/grpc/grpc-go/issues/7965)). ### Documentation - examples/features/csm_observability: update example client and server to use the helloworld service instead of echo service ([#&#8203;7945](https://redirect.github.com/grpc/grpc-go/issues/7945)). </details> <details> <summary>protocolbuffers/protobuf-go (google.golang.org/protobuf)</summary> ### [`v1.36.3`](https://redirect.github.com/protocolbuffers/protobuf-go/releases/tag/v1.36.3) [Compare Source](https://redirect.github.com/protocolbuffers/protobuf-go/compare/v1.36.2...v1.36.3) **Full Changelog**: protocolbuffers/protobuf-go@v1.36.2...v1.36.3 Bug fixes: [CL/642575](https://go-review.googlesource.com/c/protobuf/+/642575): reflect/protodesc: fix panic when working with dynamicpb [CL/641036](https://go-review.googlesource.com/c/protobuf/+/641036): cmd/protoc-gen-go: remove json struct tags from unexported fields User-visible changes: [CL/641876](https://go-review.googlesource.com/c/protobuf/+/641876): proto: add example for GetExtension, SetExtension [CL/642015](https://go-review.googlesource.com/c/protobuf/+/642015): runtime/protolazy: replace internal doc link with external link Maintenance: [CL/641635](https://go-review.googlesource.com/c/protobuf/+/641635): all: split flags.ProtoLegacyWeak out of flags.ProtoLegacy [CL/641019](https://go-review.googlesource.com/c/protobuf/+/641019): internal/impl: remove unused exporter parameter [CL/641018](https://go-review.googlesource.com/c/protobuf/+/641018): internal/impl: switch to reflect.Value.IsZero [CL/641035](https://go-review.googlesource.com/c/protobuf/+/641035): internal/impl: clean up unneeded Go<1.12 MapRange() alternative [CL/641017](https://go-review.googlesource.com/c/protobuf/+/641017): types/dynamicpb: switch atomicExtFiles to atomic.Uint64 type ### [`v1.36.2`](https://redirect.github.com/protocolbuffers/protobuf-go/releases/tag/v1.36.2) [Compare Source](https://redirect.github.com/protocolbuffers/protobuf-go/compare/v1.36.1...v1.36.2) **Full Changelog**: protocolbuffers/protobuf-go@v1.36.1...v1.36.2 Bug fixes: [CL/638515](https://go-review.googlesource.com/c/protobuf/+/638515): internal/impl: fix WhichOneof() to work with synthetic oneofs </details> --- ### Configuration 📅 **Schedule**: Branch creation - "before 6am on monday" in timezone Australia/Sydney, Automerge - At any time (no schedule defined). 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 👻 **Immortal**: This PR will be recreated if closed unmerged. Get [config help](https://redirect.github.com/renovatebot/renovate/discussions) if that's undesired. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/google/osv-scanner). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiIzOS44NS4wIiwidXBkYXRlZEluVmVyIjoiMzkuMTA3LjAiLCJ0YXJnZXRCcmFuY2giOiJtYWluIiwibGFiZWxzIjpbImRlcGVuZGVuY2llcyJdfQ==-->
1 parent 399c409 commit 7b48ac4

File tree

4 files changed

+65
-62
lines changed

4 files changed

+65
-62
lines changed

experimental/javareach/go.mod

+1-1
Original file line numberDiff line numberDiff line change
@@ -4,7 +4,7 @@ go 1.23
44

55
require (
66
github.com/google/osv-scalibr v0.1.5
7-
golang.org/x/sync v0.7.0
7+
golang.org/x/sync v0.10.0
88
)
99

1010
require (

experimental/javareach/go.sum

+2-2
Original file line numberDiff line numberDiff line change
@@ -14,7 +14,7 @@ github.com/stretchr/testify v1.7.0 h1:nwc3DEeHmmLAfoZucVR881uASk0Mfjw8xYJ99tb5Cc
1414
github.com/stretchr/testify v1.7.0/go.mod h1:6Fq8oRcR53rry900zMqJjRRixrwX3KX962/h/Wwjteg=
1515
go.uber.org/multierr v1.11.0 h1:blXXJkSxSSfBVBlC76pxqeO+LN3aDfLQo+309xJstO0=
1616
go.uber.org/multierr v1.11.0/go.mod h1:20+QtiLqy0Nd6FdQB9TLXag12DsQkrbs3htMFfDN80Y=
17-
golang.org/x/sync v0.7.0 h1:YsImfSBoP9QPYL0xyKJPq0gcaJdG3rInoqxTWbfQu9M=
18-
golang.org/x/sync v0.7.0/go.mod h1:Czt+wKu1gCyEFDUtn0jG5QVvpJ6rzVqr5aXyt9drQfk=
17+
golang.org/x/sync v0.10.0 h1:3NQrjDixjgGwUOCaF8w2+VYHv0Ve/vGYSbdkTa98gmQ=
18+
golang.org/x/sync v0.10.0/go.mod h1:Czt+wKu1gCyEFDUtn0jG5QVvpJ6rzVqr5aXyt9drQfk=
1919
gopkg.in/yaml.v3 v3.0.1 h1:fxVm/GzAzEWqLHuvctI91KS9hhNmmWOoWu0XTYJS7CA=
2020
gopkg.in/yaml.v3 v3.0.1/go.mod h1:K4uyk7z7BCEPqu6E+C64Yfv1cQ7kz7rIZviUmN+EgEM=

go.mod

+20-19
Original file line numberDiff line numberDiff line change
@@ -3,41 +3,41 @@ module github.com/google/osv-scanner
33
go 1.23.5
44

55
require (
6-
deps.dev/api/v3 v3.0.0-20241223232618-f8b47b9fbbab
7-
deps.dev/util/maven v0.0.0-20241223234259-3e2fcc756990
8-
deps.dev/util/resolve v0.0.0-20241223234119-d36e05e6460f
9-
deps.dev/util/semver v0.0.0-20241223233905-018358ffdd50
6+
deps.dev/api/v3 v3.0.0-20250114022823-c1ebdca3d00a
7+
deps.dev/util/maven v0.0.0-20250114022823-c1ebdca3d00a
8+
deps.dev/util/resolve v0.0.0-20250114022823-c1ebdca3d00a
9+
deps.dev/util/semver v0.0.0-20250114022823-c1ebdca3d00a
1010
github.com/BurntSushi/toml v1.4.0
1111
github.com/CycloneDX/cyclonedx-go v0.9.2
1212
github.com/charmbracelet/bubbles v0.20.0
1313
github.com/charmbracelet/bubbletea v1.2.4
1414
github.com/charmbracelet/glamour v0.8.0
1515
github.com/charmbracelet/lipgloss v1.0.0
16-
github.com/gkampitakis/go-snaps v0.5.7
17-
github.com/go-git/go-billy/v5 v5.6.0
18-
github.com/go-git/go-git/v5 v5.13.0
16+
github.com/gkampitakis/go-snaps v0.5.8
17+
github.com/go-git/go-billy/v5 v5.6.2
18+
github.com/go-git/go-git/v5 v5.13.1
1919
github.com/google/go-cmp v0.6.0
2020
github.com/google/osv-scalibr v0.1.6-0.20250120233754-46a5374f26ee
2121
github.com/ianlancetaylor/demangle v0.0.0-20240912202439-0a2b6291aafd
2222
github.com/jedib0t/go-pretty/v6 v6.6.5
2323
github.com/muesli/reflow v0.3.0
2424
github.com/opencontainers/go-digest v1.0.0
25-
github.com/ossf/osv-schema/bindings/go v0.0.0-20241210213101-57fd3ddb15aa
25+
github.com/ossf/osv-schema/bindings/go v0.0.0-20250120003634-8059be3f33a9
2626
github.com/owenrumney/go-sarif/v2 v2.3.3
2727
github.com/package-url/packageurl-go v0.1.3
2828
github.com/pandatix/go-cvss v0.6.2
2929
github.com/tidwall/gjson v1.18.0
3030
github.com/tidwall/pretty v1.2.1
3131
github.com/tidwall/sjson v1.2.5
3232
github.com/urfave/cli/v2 v2.27.5
33-
golang.org/x/exp v0.0.0-20241217172543-b2144cdd0a67
33+
golang.org/x/exp v0.0.0-20250106191152-7588d65b2ba8
3434
golang.org/x/mod v0.22.0
35-
golang.org/x/net v0.33.0
35+
golang.org/x/net v0.34.0
3636
golang.org/x/sync v0.10.0
37-
golang.org/x/term v0.27.0
37+
golang.org/x/term v0.28.0
3838
golang.org/x/vuln v1.0.4
39-
google.golang.org/grpc v1.69.2
40-
google.golang.org/protobuf v1.36.1
39+
google.golang.org/grpc v1.69.4
40+
google.golang.org/protobuf v1.36.3
4141
gopkg.in/ini.v1 v1.67.0
4242
gopkg.in/yaml.v3 v3.0.1
4343
)
@@ -67,7 +67,7 @@ require (
6767
github.com/containerd/ttrpc v1.2.4 // indirect
6868
github.com/containerd/typeurl/v2 v2.1.1 // indirect
6969
github.com/cpuguy83/go-md2man/v2 v2.0.5 // indirect
70-
github.com/cyphar/filepath-securejoin v0.2.5 // indirect
70+
github.com/cyphar/filepath-securejoin v0.3.6 // indirect
7171
github.com/davecgh/go-spew v1.1.1 // indirect
7272
github.com/deitch/magic v0.0.0-20240306090643-c67ab88f10cb // indirect
7373
github.com/dlclark/regexp2 v1.11.0 // indirect
@@ -79,12 +79,13 @@ require (
7979
github.com/erikgeiser/coninput v0.0.0-20211004153227-1c3628e74d0f // indirect
8080
github.com/erikvarga/go-rpmdb v0.0.0-20240208180226-b97e041ef9af // indirect
8181
github.com/felixge/httpsnoop v1.0.3 // indirect
82-
github.com/gkampitakis/ciinfo v0.3.0 // indirect
82+
github.com/gkampitakis/ciinfo v0.3.1 // indirect
8383
github.com/gkampitakis/go-diff v1.3.2 // indirect
8484
github.com/go-git/gcfg v1.5.1-0.20230307220236-3a3c6141e376 // indirect
8585
github.com/go-logr/logr v1.4.2 // indirect
8686
github.com/go-logr/stdr v1.2.2 // indirect
8787
github.com/gobwas/glob v0.2.3 // indirect
88+
github.com/goccy/go-yaml v1.15.13 // indirect
8889
github.com/gogo/protobuf v1.3.2 // indirect
8990
github.com/golang/groupcache v0.0.0-20210331224755-41bb18bfe9da // indirect
9091
github.com/google/go-containerregistry v0.20.2 // indirect
@@ -118,7 +119,7 @@ require (
118119
github.com/pjbgf/sha1cd v0.3.0 // indirect
119120
github.com/pkg/errors v0.9.1 // indirect
120121
github.com/rivo/uniseg v0.4.7 // indirect
121-
github.com/rogpeppe/go-internal v1.12.0 // indirect
122+
github.com/rogpeppe/go-internal v1.13.1 // indirect
122123
github.com/russross/blackfriday/v2 v2.1.0 // indirect
123124
github.com/sahilm/fuzzy v0.1.1 // indirect
124125
github.com/sergi/go-diff v1.3.2-0.20230802210424-5b0b94c5c0d3 // indirect
@@ -139,10 +140,10 @@ require (
139140
go.opentelemetry.io/otel/metric v1.31.0 // indirect
140141
go.opentelemetry.io/otel/trace v1.31.0 // indirect
141142
go.uber.org/multierr v1.11.0 // indirect
142-
golang.org/x/crypto v0.31.0 // indirect
143-
golang.org/x/sys v0.28.0 // indirect
143+
golang.org/x/crypto v0.32.0 // indirect
144+
golang.org/x/sys v0.29.0 // indirect
144145
golang.org/x/text v0.21.0 // indirect
145-
golang.org/x/tools v0.28.0 // indirect
146+
golang.org/x/tools v0.29.0 // indirect
146147
golang.org/x/xerrors v0.0.0-20231012003039-104605ab7028 // indirect
147148
google.golang.org/genproto v0.0.0-20240123012728-ef4313101c80 // indirect
148149
google.golang.org/genproto/googleapis/api v0.0.0-20241015192408-796eee8c2d53 // indirect

0 commit comments

Comments
 (0)