Skip to content

Commit bb35ed6

Browse files
authored
Bump pipe-fittings to v2.9.1 to fix GHCR plugin install auth error (#4980)
* Bump pipe-fittings to v2.9.1 to fix GHCR plugin install auth error pipe-fittings v2.9.1 adds an anonymous retry to OCI pulls when stored GHCR credentials (from ~/.docker/config.json) are rejected. Without this, an expired or revoked PAT causes `steampipe plugin install` to fail with an opaque 403 even when the image is publicly pullable. Also picks up the pipe-fittings dependabot security sweep and GH Actions hardening included in v2.9.0. * Update cloud.bats test fixtures to match current turbot-ops/clitesting workspace The previous test fixtures referenced AWS account 632902152528 / alias 'nagraj-aaa', which no longer exist in the turbot-ops/clitesting test workspace. Updating to account 097350876455 / alias 'turbot-silverwater' to match the current workspace state.
1 parent 2c43534 commit bb35ed6

3 files changed

Lines changed: 126 additions & 127 deletions

File tree

go.mod

Lines changed: 39 additions & 40 deletions
Original file line numberDiff line numberDiff line change
@@ -1,8 +1,8 @@
11
module github.com/turbot/steampipe/v2
22

3-
go 1.24
3+
go 1.24.0
44

5-
toolchain go1.24.0
5+
toolchain go1.24.1
66

77
replace (
88
github.com/c-bata/go-prompt => github.com/turbot/go-prompt v0.2.6-steampipe.0.0.20221028122246-eb118ec58d50
@@ -19,7 +19,7 @@ require (
1919
github.com/fatih/color v1.18.0
2020
github.com/fsnotify/fsnotify v1.9.0
2121
github.com/gertd/go-pluralize v0.2.1
22-
github.com/go-git/go-git/v5 v5.16.2
22+
github.com/go-git/go-git/v5 v5.16.5
2323
github.com/google/uuid v1.6.0
2424
github.com/hashicorp/go-hclog v1.6.3
2525
github.com/hashicorp/go-plugin v1.6.3
@@ -42,20 +42,20 @@ require (
4242
github.com/spf13/viper v1.20.1
4343
github.com/thediveo/enumflag/v2 v2.0.7
4444
github.com/turbot/go-kit v1.3.0
45-
github.com/turbot/pipe-fittings/v2 v2.6.3
45+
github.com/turbot/pipe-fittings/v2 v2.9.1
4646
github.com/turbot/steampipe-plugin-sdk/v5 v5.11.7
4747
github.com/turbot/terraform-components v0.0.0-20250114051614-04b806a9cbed
4848
github.com/zclconf/go-cty v1.16.2 // indirect
4949
golang.org/x/exp v0.0.0-20250305212735-054e65f0b394
50-
golang.org/x/sync v0.15.0
51-
golang.org/x/text v0.26.0
52-
google.golang.org/grpc v1.73.0
53-
google.golang.org/protobuf v1.36.6
50+
golang.org/x/sync v0.19.0
51+
golang.org/x/text v0.32.0
52+
google.golang.org/grpc v1.79.3
53+
google.golang.org/protobuf v1.36.10
5454
)
5555

5656
require (
5757
cloud.google.com/go v0.120.0 // indirect
58-
cloud.google.com/go/compute/metadata v0.6.0 // indirect
58+
cloud.google.com/go/compute/metadata v0.9.0 // indirect
5959
cloud.google.com/go/iam v1.4.2 // indirect
6060
cloud.google.com/go/storage v1.51.0 // indirect
6161
github.com/AdaLogics/go-fuzz-headers v0.0.0-20240806141605-e8a1dd7889d6 // indirect
@@ -83,7 +83,7 @@ require (
8383
github.com/btubbs/datetime v0.1.1 // indirect
8484
github.com/cenkalti/backoff/v4 v4.3.0 // indirect
8585
github.com/cespare/xxhash/v2 v2.3.0 // indirect
86-
github.com/containerd/containerd v1.7.27 // indirect
86+
github.com/containerd/containerd v1.7.29 // indirect
8787
github.com/containerd/errdefs v1.0.0 // indirect
8888
github.com/containerd/log v0.1.0 // indirect
8989
github.com/cyphar/filepath-securejoin v0.4.1 // indirect
@@ -99,7 +99,7 @@ require (
9999
github.com/ghodss/yaml v1.0.0 // indirect
100100
github.com/go-git/gcfg v1.5.1-0.20230307220236-3a3c6141e376 // indirect
101101
github.com/go-git/go-billy/v5 v5.6.2 // indirect
102-
github.com/go-logr/logr v1.4.2 // indirect
102+
github.com/go-logr/logr v1.4.3 // indirect
103103
github.com/go-logr/stdr v1.2.2 // indirect
104104
github.com/go-ole/go-ole v1.3.0 // indirect
105105
github.com/go-playground/locales v0.14.1 // indirect
@@ -113,7 +113,7 @@ require (
113113
github.com/google/s2a-go v0.1.9 // indirect
114114
github.com/googleapis/enterprise-certificate-proxy v0.3.6 // indirect
115115
github.com/googleapis/gax-go/v2 v2.14.1 // indirect
116-
github.com/grpc-ecosystem/grpc-gateway/v2 v2.26.3 // indirect
116+
github.com/grpc-ecosystem/grpc-gateway/v2 v2.27.1 // indirect
117117
github.com/hashicorp/errwrap v1.1.0 // indirect
118118
github.com/hashicorp/go-cleanhttp v0.5.2 // indirect
119119
github.com/hashicorp/go-getter v1.7.9 // indirect
@@ -147,7 +147,7 @@ require (
147147
github.com/opencontainers/go-digest v1.0.0 // indirect
148148
github.com/pelletier/go-toml/v2 v2.2.3 // indirect
149149
github.com/pjbgf/sha1cd v0.3.2 // indirect
150-
github.com/prometheus/client_model v0.6.1 // indirect
150+
github.com/prometheus/client_model v0.6.2 // indirect
151151
github.com/prometheus/common v0.63.0 // indirect
152152
github.com/rivo/uniseg v0.4.7 // indirect
153153
github.com/rs/xid v1.6.0 // indirect
@@ -162,30 +162,30 @@ require (
162162
github.com/tklauser/numcpus v0.10.0 // indirect
163163
github.com/tkrajina/go-reflector v0.5.8 // indirect
164164
github.com/turbot/pipes-sdk-go v0.12.1 // indirect
165-
github.com/ulikunitz/xz v0.5.12 // indirect
165+
github.com/ulikunitz/xz v0.5.14 // indirect
166166
github.com/xlab/treeprint v1.2.0 // indirect
167167
github.com/zclconf/go-cty-yaml v1.1.0 // indirect
168168
go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc v0.60.0 // indirect
169169
go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.60.0 // indirect
170-
go.opentelemetry.io/otel v1.35.0 // indirect
170+
go.opentelemetry.io/otel v1.40.0 // indirect
171171
go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetricgrpc v1.35.0 // indirect
172172
go.opentelemetry.io/otel/exporters/otlp/otlptrace v1.35.0 // indirect
173173
go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc v1.35.0 // indirect
174-
go.opentelemetry.io/otel/metric v1.35.0 // indirect
175-
go.opentelemetry.io/otel/sdk v1.35.0 // indirect
176-
go.opentelemetry.io/otel/sdk/metric v1.35.0 // indirect
177-
go.opentelemetry.io/otel/trace v1.35.0 // indirect
178-
go.opentelemetry.io/proto/otlp v1.5.0 // indirect
174+
go.opentelemetry.io/otel/metric v1.40.0 // indirect
175+
go.opentelemetry.io/otel/sdk v1.40.0 // indirect
176+
go.opentelemetry.io/otel/sdk/metric v1.40.0 // indirect
177+
go.opentelemetry.io/otel/trace v1.40.0 // indirect
178+
go.opentelemetry.io/proto/otlp v1.7.1 // indirect
179179
go.uber.org/multierr v1.11.0 // indirect
180-
golang.org/x/oauth2 v0.28.0 // indirect
181-
golang.org/x/sys v0.33.0 // indirect
182-
golang.org/x/term v0.32.0 // indirect
183-
golang.org/x/time v0.11.0 // indirect
184-
golang.org/x/tools v0.33.0 // indirect
180+
golang.org/x/oauth2 v0.34.0 // indirect
181+
golang.org/x/sys v0.40.0 // indirect
182+
golang.org/x/term v0.38.0 // indirect
183+
golang.org/x/time v0.12.0 // indirect
184+
golang.org/x/tools v0.39.0 // indirect
185185
google.golang.org/api v0.227.0 // indirect
186186
google.golang.org/genproto v0.0.0-20250313205543-e70fdf4c4cb4 // indirect
187-
google.golang.org/genproto/googleapis/api v0.0.0-20250324211829-b45e905df463 // indirect
188-
google.golang.org/genproto/googleapis/rpc v0.0.0-20250324211829-b45e905df463 // indirect
187+
google.golang.org/genproto/googleapis/api v0.0.0-20251202230838-ff82c1b0f217 // indirect
188+
google.golang.org/genproto/googleapis/rpc v0.0.0-20251202230838-ff82c1b0f217 // indirect
189189
gopkg.in/warnings.v0 v0.1.2 // indirect
190190
gopkg.in/yaml.v2 v2.4.0 // indirect
191191
gopkg.in/yaml.v3 v3.0.1 // indirect
@@ -194,36 +194,35 @@ require (
194194
)
195195

196196
require (
197-
cel.dev/expr v0.23.0 // indirect
197+
cel.dev/expr v0.25.1 // indirect
198198
cloud.google.com/go/auth v0.15.0 // indirect
199199
cloud.google.com/go/auth/oauth2adapt v0.2.7 // indirect
200200
cloud.google.com/go/monitoring v1.24.0 // indirect
201-
github.com/GoogleCloudPlatform/opentelemetry-operations-go/detectors/gcp v1.27.0 // indirect
201+
github.com/GoogleCloudPlatform/opentelemetry-operations-go/detectors/gcp v1.30.0 // indirect
202202
github.com/GoogleCloudPlatform/opentelemetry-operations-go/exporter/metric v0.51.0 // indirect
203203
github.com/GoogleCloudPlatform/opentelemetry-operations-go/internal/resourcemapping v0.51.0 // indirect
204204
github.com/bmatcuk/doublestar v1.3.4 // indirect
205-
github.com/cncf/xds/go v0.0.0-20250326154945-ae57f3c0d45f // indirect
205+
github.com/cncf/xds/go v0.0.0-20251210132809-ee656c7534f5 // indirect
206206
github.com/containerd/platforms v0.2.1 // indirect
207-
github.com/envoyproxy/go-control-plane/envoy v1.32.4 // indirect
208-
github.com/envoyproxy/protoc-gen-validate v1.2.1 // indirect
209-
github.com/go-jose/go-jose/v4 v4.0.5 // indirect
207+
github.com/envoyproxy/go-control-plane/envoy v1.36.0 // indirect
208+
github.com/envoyproxy/protoc-gen-validate v1.3.0 // indirect
209+
github.com/go-jose/go-jose/v4 v4.1.3 // indirect
210210
github.com/go-viper/mapstructure/v2 v2.3.0 // indirect
211211
github.com/logrusorgru/aurora v2.0.3+incompatible // indirect
212212
github.com/munnerz/goautoneg v0.0.0-20191010083416-a7dc8b61c822 // indirect
213213
github.com/pkg/term v1.1.0 // indirect
214214
github.com/planetscale/vtprotobuf v0.6.1-0.20240319094008-0393e58bdf10 // indirect
215215
github.com/prometheus/client_golang v1.21.1 // indirect
216216
github.com/prometheus/procfs v0.16.0 // indirect
217-
github.com/spiffe/go-spiffe/v2 v2.5.0 // indirect
217+
github.com/spiffe/go-spiffe/v2 v2.6.0 // indirect
218218
github.com/tklauser/go-sysconf v0.3.15 // indirect
219219
github.com/yusufpapurcu/wmi v1.2.4 // indirect
220-
github.com/zeebo/errs v1.4.0 // indirect
221-
go.opentelemetry.io/auto/sdk v1.1.0 // indirect
222-
go.opentelemetry.io/contrib/detectors/gcp v1.35.0 // indirect
220+
go.opentelemetry.io/auto/sdk v1.2.1 // indirect
221+
go.opentelemetry.io/contrib/detectors/gcp v1.39.0 // indirect
223222
go.uber.org/mock v0.4.0 // indirect
224-
golang.org/x/crypto v0.38.0 // indirect
225-
golang.org/x/mod v0.25.0 // indirect
226-
golang.org/x/net v0.40.0 // indirect
223+
golang.org/x/crypto v0.46.0 // indirect
224+
golang.org/x/mod v0.30.0 // indirect
225+
golang.org/x/net v0.48.0 // indirect
227226
)
228227

229228
require (

0 commit comments

Comments
 (0)