From 62a0211ff80cffca58f56d4045d9660c128196da Mon Sep 17 00:00:00 2001 From: Mend Renovate Date: Mon, 18 Mar 2024 02:04:38 +0100 Subject: [PATCH] fix(deps): update osv-scanner minor (#864) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit [![Mend Renovate](https://app.renovatebot.com/images/banner.svg)](https://renovatebot.com) This PR contains the following updates: | Package | Type | Update | Change | Age | Adoption | Passing | Confidence | |---|---|---|---|---|---|---|---| | [deps.dev/api/v3alpha](https://togithub.com/google/deps.dev) | require | digest | `3ec708c` -> `38ffc8d` | | | | | | [deps.dev/util/maven](https://togithub.com/google/deps.dev) | require | digest | `3ec708c` -> `38ffc8d` | | | | | | [deps.dev/util/resolve](https://togithub.com/google/deps.dev) | require | digest | `3ec708c` -> `38ffc8d` | | | | | | [deps.dev/util/semver](https://togithub.com/google/deps.dev) | require | digest | `3ec708c` -> `38ffc8d` | | | | | | [github.com/google/go-containerregistry](https://togithub.com/google/go-containerregistry) | require | patch | `v0.19.0` -> `v0.19.1` | [![age](https://developer.mend.io/api/mc/badges/age/go/github.com%2fgoogle%2fgo-containerregistry/v0.19.1?slim=true)](https://docs.renovatebot.com/merge-confidence/) | [![adoption](https://developer.mend.io/api/mc/badges/adoption/go/github.com%2fgoogle%2fgo-containerregistry/v0.19.1?slim=true)](https://docs.renovatebot.com/merge-confidence/) | [![passing](https://developer.mend.io/api/mc/badges/compatibility/go/github.com%2fgoogle%2fgo-containerregistry/v0.19.0/v0.19.1?slim=true)](https://docs.renovatebot.com/merge-confidence/) | [![confidence](https://developer.mend.io/api/mc/badges/confidence/go/github.com%2fgoogle%2fgo-containerregistry/v0.19.0/v0.19.1?slim=true)](https://docs.renovatebot.com/merge-confidence/) | | [github.com/ianlancetaylor/demangle](https://togithub.com/ianlancetaylor/demangle) | require | digest | `1f824a1` -> `bd984b5` | | | | | | [github.com/jedib0t/go-pretty/v6](https://togithub.com/jedib0t/go-pretty) | require | patch | `v6.5.4` -> `v6.5.5` | [![age](https://developer.mend.io/api/mc/badges/age/go/github.com%2fjedib0t%2fgo-pretty%2fv6/v6.5.5?slim=true)](https://docs.renovatebot.com/merge-confidence/) | [![adoption](https://developer.mend.io/api/mc/badges/adoption/go/github.com%2fjedib0t%2fgo-pretty%2fv6/v6.5.5?slim=true)](https://docs.renovatebot.com/merge-confidence/) | [![passing](https://developer.mend.io/api/mc/badges/compatibility/go/github.com%2fjedib0t%2fgo-pretty%2fv6/v6.5.4/v6.5.5?slim=true)](https://docs.renovatebot.com/merge-confidence/) | [![confidence](https://developer.mend.io/api/mc/badges/confidence/go/github.com%2fjedib0t%2fgo-pretty%2fv6/v6.5.4/v6.5.5?slim=true)](https://docs.renovatebot.com/merge-confidence/) | | [go](https://go.dev/) ([source](https://togithub.com/golang/go)) | golang | minor | `1.21.8` -> `1.22.1` | [![age](https://developer.mend.io/api/mc/badges/age/golang-version/go/1.22.1?slim=true)](https://docs.renovatebot.com/merge-confidence/) | [![adoption](https://developer.mend.io/api/mc/badges/adoption/golang-version/go/1.22.1?slim=true)](https://docs.renovatebot.com/merge-confidence/) | [![passing](https://developer.mend.io/api/mc/badges/compatibility/golang-version/go/1.21.8/1.22.1?slim=true)](https://docs.renovatebot.com/merge-confidence/) | [![confidence](https://developer.mend.io/api/mc/badges/confidence/golang-version/go/1.21.8/1.22.1?slim=true)](https://docs.renovatebot.com/merge-confidence/) | | golang.org/x/exp | require | digest | `814bf88` -> `c7f7c64` | | | | | --- ### Release Notes
google/go-containerregistry (github.com/google/go-containerregistry) ### [`v0.19.1`](https://togithub.com/google/go-containerregistry/releases/tag/v0.19.1) [Compare Source](https://togithub.com/google/go-containerregistry/compare/v0.19.0...v0.19.1) #### What's Changed - Bump golang.org/x/net from 0.10.0 to 0.17.0 in /pkg/authn/k8schain by [@​dependabot](https://togithub.com/dependabot) in [https://github.com/google/go-containerregistry/pull/1815](https://togithub.com/google/go-containerregistry/pull/1815) - Bump golang.org/x/ packages by [@​jonjohnsonjr](https://togithub.com/jonjohnsonjr) in [https://github.com/google/go-containerregistry/pull/1892](https://togithub.com/google/go-containerregistry/pull/1892) **Full Changelog**: https://github.com/google/go-containerregistry/compare/v0.19.0...v0.19.1
jedib0t/go-pretty (github.com/jedib0t/go-pretty/v6) ### [`v6.5.5`](https://togithub.com/jedib0t/go-pretty/releases/tag/v6.5.5) [Compare Source](https://togithub.com/jedib0t/go-pretty/compare/v6.5.4...v6.5.5) #### What's Changed - replace imports of ioutil with io by [@​Skeeve](https://togithub.com/Skeeve) in [https://github.com/jedib0t/go-pretty/pull/304](https://togithub.com/jedib0t/go-pretty/pull/304) - table: mixed-mode alignment and sorting by [@​jedib0t](https://togithub.com/jedib0t) in [https://github.com/jedib0t/go-pretty/pull/306](https://togithub.com/jedib0t/go-pretty/pull/306) #### New Contributors - [@​Skeeve](https://togithub.com/Skeeve) made their first contribution in [https://github.com/jedib0t/go-pretty/pull/304](https://togithub.com/jedib0t/go-pretty/pull/304) **Full Changelog**: https://github.com/jedib0t/go-pretty/compare/v6.5.4...v6.5.5
golang/go (go) ### [`v1.22.1`](https://togithub.com/golang/go/compare/go1.22.0...go1.22.1) ### [`v1.22.0`](https://togithub.com/golang/go/compare/go1.21.7...go1.22rc1)
--- ### Configuration 📅 **Schedule**: Branch creation - "before 6am on monday" in timezone Australia/Sydney, Automerge - At any time (no schedule defined). 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 👻 **Immortal**: This PR will be recreated if closed unmerged. Get [config help](https://togithub.com/renovatebot/renovate/discussions) if that's undesired. --- - [ ] If you want to rebase/retry this PR, check this box --- This PR has been generated by [Mend Renovate](https://www.mend.io/free-developer-tools/renovate/). View repository job log [here](https://developer.mend.io/github/google/osv-scanner). --------- Co-authored-by: Rex P <106129829+another-rex@users.noreply.github.com> --- go.mod | 16 ++++++++-------- go.sum | 32 ++++++++++++++++---------------- 2 files changed, 24 insertions(+), 24 deletions(-) diff --git a/go.mod b/go.mod index 307e4af692..17bd73ec06 100644 --- a/go.mod +++ b/go.mod @@ -3,10 +3,10 @@ module github.com/google/osv-scanner go 1.21.8 require ( - deps.dev/api/v3alpha v0.0.0-20240223021916-3ec708cc3f2e - deps.dev/util/maven v0.0.0-20240223021916-3ec708cc3f2e - deps.dev/util/resolve v0.0.0-20240223021916-3ec708cc3f2e - deps.dev/util/semver v0.0.0-20240223021916-3ec708cc3f2e + deps.dev/api/v3alpha v0.0.0-20240312000934-38ffc8dd1d92 + deps.dev/util/maven v0.0.0-20240312000934-38ffc8dd1d92 + deps.dev/util/resolve v0.0.0-20240312000934-38ffc8dd1d92 + deps.dev/util/semver v0.0.0-20240312000934-38ffc8dd1d92 github.com/BurntSushi/toml v1.3.2 github.com/CycloneDX/cyclonedx-go v0.8.0 github.com/charmbracelet/bubbles v0.18.0 @@ -18,9 +18,9 @@ require ( github.com/go-git/go-billy/v5 v5.5.0 github.com/go-git/go-git/v5 v5.11.0 github.com/google/go-cmp v0.6.0 - github.com/google/go-containerregistry v0.19.0 - github.com/ianlancetaylor/demangle v0.0.0-20240205174729-1f824a1a9b87 - github.com/jedib0t/go-pretty/v6 v6.5.4 + github.com/google/go-containerregistry v0.19.1 + github.com/ianlancetaylor/demangle v0.0.0-20240312041847-bd984b5ce465 + github.com/jedib0t/go-pretty/v6 v6.5.5 github.com/muesli/reflow v0.3.0 github.com/owenrumney/go-sarif/v2 v2.3.0 github.com/package-url/packageurl-go v0.1.2 @@ -29,7 +29,7 @@ require ( github.com/tidwall/gjson v1.17.1 github.com/tidwall/sjson v1.2.5 github.com/urfave/cli/v2 v2.27.1 - golang.org/x/exp v0.0.0-20240222234643-814bf88cf225 + golang.org/x/exp v0.0.0-20240314144324-c7f7c6466f7f golang.org/x/mod v0.16.0 golang.org/x/sync v0.6.0 golang.org/x/term v0.18.0 diff --git a/go.sum b/go.sum index 6457064bd0..03f5e9beab 100644 --- a/go.sum +++ b/go.sum @@ -1,13 +1,13 @@ dario.cat/mergo v1.0.0 h1:AGCNq9Evsj31mOgNPcLyXc+4PNABt905YmuqPYYpBWk= dario.cat/mergo v1.0.0/go.mod h1:uNxQE+84aUszobStD9th8a29P2fMDhsBdgRYvZOxGmk= -deps.dev/api/v3alpha v0.0.0-20240223021916-3ec708cc3f2e h1:j+XxPZqnh0+wYMpThhLmhEJ3Z7WWNxSyuKxt5Boulmc= -deps.dev/api/v3alpha v0.0.0-20240223021916-3ec708cc3f2e/go.mod h1:uRN72FJn1F0FD/2ZYUOqdyFMu8VUsyHxvmZAMW30/DA= -deps.dev/util/maven v0.0.0-20240223021916-3ec708cc3f2e h1:hobs8WiaVXuAQR5TcpY6o+4OQ4L2e/eRgeDpErY73Xw= -deps.dev/util/maven v0.0.0-20240223021916-3ec708cc3f2e/go.mod h1:SBW3EribdkZYk6zxi5oVn/ZECvi4ixb7EGgEWfSimNk= -deps.dev/util/resolve v0.0.0-20240223021916-3ec708cc3f2e h1:zWDl+k5IArlMv0LqmR2oWjz5mxdv793ZYtfG4Aex51k= -deps.dev/util/resolve v0.0.0-20240223021916-3ec708cc3f2e/go.mod h1:jf1QVEA+0Tj8gSiKyKabwsx4M5zK1LC49xjphwNP5ko= -deps.dev/util/semver v0.0.0-20240223021916-3ec708cc3f2e h1:HMFaNLemk4CVmP0WEP/wLhDcp/xmq80oKtY83dKpdN0= -deps.dev/util/semver v0.0.0-20240223021916-3ec708cc3f2e/go.mod h1:jkcH+k02gWHBiZ7G4OnUOkSZ6WDq54Pt5DrOA8FN8Uo= +deps.dev/api/v3alpha v0.0.0-20240312000934-38ffc8dd1d92 h1:iOI1Nf2XI9FGluEmEFuKT6XgfFUb0LESmfUcVuOBNDA= +deps.dev/api/v3alpha v0.0.0-20240312000934-38ffc8dd1d92/go.mod h1:uRN72FJn1F0FD/2ZYUOqdyFMu8VUsyHxvmZAMW30/DA= +deps.dev/util/maven v0.0.0-20240312000934-38ffc8dd1d92 h1:Ddwk4QwKRzOFGtVCrll5F4tE22Fr0zPbt8bJf+plIPk= +deps.dev/util/maven v0.0.0-20240312000934-38ffc8dd1d92/go.mod h1:SBW3EribdkZYk6zxi5oVn/ZECvi4ixb7EGgEWfSimNk= +deps.dev/util/resolve v0.0.0-20240312000934-38ffc8dd1d92 h1:U8EfM+tLxvNJRELjYNH6f70vDe927q/Ywd3zJRx7G7c= +deps.dev/util/resolve v0.0.0-20240312000934-38ffc8dd1d92/go.mod h1:jf1QVEA+0Tj8gSiKyKabwsx4M5zK1LC49xjphwNP5ko= +deps.dev/util/semver v0.0.0-20240312000934-38ffc8dd1d92 h1:apadfwF7+yCUGynV8PuI0ERui4eELKE3AMeLiMnQGqU= +deps.dev/util/semver v0.0.0-20240312000934-38ffc8dd1d92/go.mod h1:jkcH+k02gWHBiZ7G4OnUOkSZ6WDq54Pt5DrOA8FN8Uo= github.com/BurntSushi/toml v1.3.2 h1:o7IhLm0Msx3BaB+n3Ag7L8EVlByGnpq14C4YWiu/gL8= github.com/BurntSushi/toml v1.3.2/go.mod h1:CxXYINrC8qIiEnFrOxCa7Jy5BFHlXnUU2pbicEuybxQ= github.com/CycloneDX/cyclonedx-go v0.8.0 h1:FyWVj6x6hoJrui5uRQdYZcSievw3Z32Z88uYzG/0D6M= @@ -105,17 +105,17 @@ github.com/google/go-cmp v0.5.5/go.mod h1:v8dTdLbMG2kIc/vJvl+f65V22dbkXbowE6jgT/ github.com/google/go-cmp v0.5.9/go.mod h1:17dUlkBOakJ0+DkrSSNjCkIjxS6bF9zb3elmeNGIjoY= github.com/google/go-cmp v0.6.0 h1:ofyhxvXcZhMsU5ulbFiLKl/XBFqE1GSq7atu8tAmTRI= github.com/google/go-cmp v0.6.0/go.mod h1:17dUlkBOakJ0+DkrSSNjCkIjxS6bF9zb3elmeNGIjoY= -github.com/google/go-containerregistry v0.19.0 h1:uIsMRBV7m/HDkDxE/nXMnv1q+lOOSPlQ/ywc5JbB8Ic= -github.com/google/go-containerregistry v0.19.0/go.mod h1:u0qB2l7mvtWVR5kNcbFIhFY1hLbf8eeGapA+vbFDCtQ= +github.com/google/go-containerregistry v0.19.1 h1:yMQ62Al6/V0Z7CqIrrS1iYoA5/oQCm88DeNujc7C1KY= +github.com/google/go-containerregistry v0.19.1/go.mod h1:YCMFNQeeXeLF+dnhhWkqDItx/JSkH01j1Kis4PsjzFI= github.com/gorilla/css v1.0.0/go.mod h1:Dn721qIggHpt4+EFCcTLTU/vk5ySda2ReITrtgBl60c= github.com/gorilla/css v1.0.1 h1:ntNaBIghp6JmvWnxbZKANoLyuXTPZ4cAMlo6RyhlbO8= github.com/gorilla/css v1.0.1/go.mod h1:BvnYkspnSzMmwRK+b8/xgNPLiIuNZr6vbZBTPQ2A3b0= -github.com/ianlancetaylor/demangle v0.0.0-20240205174729-1f824a1a9b87 h1:IG+58MeF0K/wSXknV4FMOABt6B4VZCguRDxYSCJqWb4= -github.com/ianlancetaylor/demangle v0.0.0-20240205174729-1f824a1a9b87/go.mod h1:gx7rwoVhcfuVKG5uya9Hs3Sxj7EIvldVofAWIUtGouw= +github.com/ianlancetaylor/demangle v0.0.0-20240312041847-bd984b5ce465 h1:KwWnWVWCNtNq/ewIX7HIKnELmEx2nDP42yskD/pi7QE= +github.com/ianlancetaylor/demangle v0.0.0-20240312041847-bd984b5ce465/go.mod h1:gx7rwoVhcfuVKG5uya9Hs3Sxj7EIvldVofAWIUtGouw= github.com/jbenet/go-context v0.0.0-20150711004518-d14ea06fba99 h1:BQSFePA1RWJOlocH6Fxy8MmwDt+yVQYULKfN0RoTN8A= github.com/jbenet/go-context v0.0.0-20150711004518-d14ea06fba99/go.mod h1:1lJo3i6rXxKeerYnT8Nvf0QmHCRC1n8sfWVwXF2Frvo= -github.com/jedib0t/go-pretty/v6 v6.5.4 h1:gOGo0613MoqUcf0xCj+h/V3sHDaZasfv152G6/5l91s= -github.com/jedib0t/go-pretty/v6 v6.5.4/go.mod h1:5LQIxa52oJ/DlDSLv0HEkWOFMDGoWkJb9ss5KqPpJBg= +github.com/jedib0t/go-pretty/v6 v6.5.5 h1:PpIU8lOjxvVYGGKule0QxxJfNysUSbC9lggQU2cpZJc= +github.com/jedib0t/go-pretty/v6 v6.5.5/go.mod h1:5LQIxa52oJ/DlDSLv0HEkWOFMDGoWkJb9ss5KqPpJBg= github.com/kevinburke/ssh_config v1.2.0 h1:x584FjTGwHzMwvHx18PXxbBVzfnxogHaAReU4gf13a4= github.com/kevinburke/ssh_config v1.2.0/go.mod h1:CT57kijsi8u/K/BOFA39wgDQJ9CxiF4nAY/ojJ6r6mM= github.com/klauspost/compress v1.17.7 h1:ehO88t2UGzQK66LMdE8tibEd1ErmzZjNEqWkjLAKQQg= @@ -257,8 +257,8 @@ golang.org/x/crypto v0.3.1-0.20221117191849-2c476679df9a/go.mod h1:hebNnKkNXi2Uz golang.org/x/crypto v0.7.0/go.mod h1:pYwdfH91IfpZVANVyUOhSIPZaFoJGxTFbZhFTx+dXZU= golang.org/x/crypto v0.21.0 h1:X31++rzVUdKhX5sWmSOFZxx8UW/ldWx55cbf08iNAMA= golang.org/x/crypto v0.21.0/go.mod h1:0BP7YvVV9gBbVKyeTG0Gyn+gZm94bibOW5BjDEYAOMs= -golang.org/x/exp v0.0.0-20240222234643-814bf88cf225 h1:LfspQV/FYTatPTr/3HzIcmiUFH7PGP+OQ6mgDYo3yuQ= -golang.org/x/exp v0.0.0-20240222234643-814bf88cf225/go.mod h1:CxmFvTBINI24O/j8iY7H1xHzx2i4OsyguNBmN/uPtqc= +golang.org/x/exp v0.0.0-20240314144324-c7f7c6466f7f h1:3CW0unweImhOzd5FmYuRsD4Y4oQFKZIjAnKbjV4WIrw= +golang.org/x/exp v0.0.0-20240314144324-c7f7c6466f7f/go.mod h1:CxmFvTBINI24O/j8iY7H1xHzx2i4OsyguNBmN/uPtqc= golang.org/x/mod v0.6.0-dev.0.20220419223038-86c51ed26bb4/go.mod h1:jJ57K6gSWd91VN4djpZkiMVwK6gcyfeH4XE8wZrZaV4= golang.org/x/mod v0.8.0/go.mod h1:iBbtSCu2XBx23ZKBPSOrRkjjQPZFPuis4dIYUhu/chs= golang.org/x/mod v0.16.0 h1:QX4fJ0Rr5cPQCF7O9lh9Se4pmwfwskqZfq5moyldzic=