Skip to content

Commit

Permalink
Merge remote-tracking branch 'upstream/main' into add_dsse_type
Browse files Browse the repository at this point in the history
Signed-off-by: Bob Callaway <[email protected]>
  • Loading branch information
bobcallaway committed Jun 15, 2023
2 parents e4463e5 + 80c0f88 commit eb62e59
Show file tree
Hide file tree
Showing 5 changed files with 187 additions and 112 deletions.
2 changes: 1 addition & 1 deletion .github/workflows/tests.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -178,5 +178,5 @@ jobs:
uses: golangci/golangci-lint-action@639cd343e1d3b897ff35927a75193d57cfcba299 # v3.6.0
with:
# Required: the version of golangci-lint is required and must be specified without patch version: we always use the latest patch version.
version: v1.52
version: v1.53
args: --timeout=5m
75 changes: 75 additions & 0 deletions .golangci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -43,6 +43,81 @@ linters-settings:
- 'os\.Getenv.*'
- 'os\.LookupEnv.*'
exclude_godoc_examples: false
depguard:
rules:
main:
files:
- $all
- "!$test"
allow:
- $gostd

- github.com/open-policy-agent/opa/rego
- github.com/xanzy/go-gitlab
- github.com/spf13/cobra
- github.com/spf13/viper
- github.com/spf13/pflag
- github.com/pkg/errors
- github.com/moby/term
- github.com/google/go-cmp/cmp
- github.com/in-toto/in-toto-golang
- github.com/secure-systems-lab/go-securesystemslib
- github.com/cyberphone/json-canonicalization/go/src/webpki.org/jsoncanonicalizer
- github.com/digitorus/timestamp
- github.com/transparency-dev/merkle
- github.com/google/certificate-transparency-go
- github.com/go-openapi
- github.com/theupdateframework/go-tuf
- github.com/kelseyhightower/envconfig
- github.com/google/go-github
- github.com/buildkite/agent
- github.com/mitchellh/go-wordwrap
- github.com/withfig/autocomplete-tools/integrations/cobra
- github.com/awslabs/amazon-ecr-credential-helper/ecr-login
- github.com/chrismellard/docker-credential-acr-env/pkg/credhelper
- github.com/mozillazg/docker-credential-acr-helper/pkg/credhelper

- cuelang.org/go/cue/load
- cuelang.org/go/cue/cuecontext
- cuelang.org/go/encoding/json

- k8s.io/utils/pointer
- k8s.io/client-go
- k8s.io/api/core
- k8s.io/apimachinery
- sigs.k8s.io/release-utils/version

- github.com/spiffe/go-spiffe
- github.com/google/go-containerregistry
- github.com/sigstore

test:
files:
- $test
allow:
- $gostd
- github.com/google/go-cmp/cmp
- github.com/go-openapi
- github.com/google/go-containerregistry
- github.com/in-toto/in-toto-golang
- github.com/stretchr/testify
- github.com/pkg/errors
- github.com/theupdateframework/go-tuf
- github.com/google/certificate-transparency-go
- github.com/secure-systems-lab/go-securesystemslib
- github.com/transparency-dev/merkle/rfc6962
- github.com/depcheck-test/depcheck-test/depcheck
- github.com/cyberphone/json-canonicalization/go/src/webpki.org/jsoncanonicalizer

- k8s.io/api/core
- k8s.io/apimachinery
- k8s.io/utils/pointer

- github.com/sigstore/cosign
- github.com/sigstore/sigstore
- github.com/sigstore/rekor
- github.com/sigstore/fulcio

output:
uniq-by-line: false
issues:
Expand Down
2 changes: 1 addition & 1 deletion Makefile
Original file line number Diff line number Diff line change
Expand Up @@ -98,7 +98,7 @@ cross:
golangci-lint:
rm -f $(GOLANGCI_LINT_BIN) || :
set -e ;\
GOBIN=$(GOLANGCI_LINT_DIR) $(GOEXE) install github.com/golangci/golangci-lint/cmd/golangci-lint@v1.52.2 ;\
GOBIN=$(GOLANGCI_LINT_DIR) $(GOEXE) install github.com/golangci/golangci-lint/cmd/golangci-lint@v1.53.2 ;\

lint: golangci-lint ## Run golangci-lint linter
$(GOLANGCI_LINT_BIN) run -n
Expand Down
72 changes: 36 additions & 36 deletions go.mod
Original file line number Diff line number Diff line change
Expand Up @@ -31,11 +31,11 @@ require (
github.com/secure-systems-lab/go-securesystemslib v0.6.0
github.com/sigstore/fulcio v1.3.1
github.com/sigstore/rekor v1.2.2-0.20230530122220-67cc9e58bd23
github.com/sigstore/sigstore v1.6.6-0.20230602075123-c74dd4383337
github.com/sigstore/sigstore/pkg/signature/kms/aws v1.6.5
github.com/sigstore/sigstore/pkg/signature/kms/azure v1.6.5
github.com/sigstore/sigstore/pkg/signature/kms/gcp v1.6.5
github.com/sigstore/sigstore/pkg/signature/kms/hashivault v1.6.5
github.com/sigstore/sigstore v1.7.0
github.com/sigstore/sigstore/pkg/signature/kms/aws v1.7.0
github.com/sigstore/sigstore/pkg/signature/kms/azure v1.7.0
github.com/sigstore/sigstore/pkg/signature/kms/gcp v1.7.0
github.com/sigstore/sigstore/pkg/signature/kms/hashivault v1.7.0
github.com/sigstore/timestamp-authority v1.1.1
github.com/spf13/cobra v1.7.0
github.com/spf13/pflag v1.0.5
Expand All @@ -46,28 +46,28 @@ require (
github.com/transparency-dev/merkle v0.0.2
github.com/withfig/autocomplete-tools/integrations/cobra v1.2.1
github.com/xanzy/go-gitlab v0.85.0
go.step.sm/crypto v0.31.2
golang.org/x/crypto v0.9.0
golang.org/x/oauth2 v0.8.0
golang.org/x/sync v0.2.0
golang.org/x/term v0.8.0
google.golang.org/api v0.126.0
k8s.io/api v0.26.3
k8s.io/apimachinery v0.26.3
k8s.io/client-go v0.25.4
go.step.sm/crypto v0.32.0
golang.org/x/crypto v0.10.0
golang.org/x/oauth2 v0.9.0
golang.org/x/sync v0.3.0
golang.org/x/term v0.9.0
google.golang.org/api v0.127.0
k8s.io/api v0.26.6
k8s.io/apimachinery v0.26.6
k8s.io/client-go v0.26.6
k8s.io/utils v0.0.0-20230406110748-d93618cff8a2
sigs.k8s.io/release-utils v0.7.4
)

require (
cloud.google.com/go/compute v1.19.3 // indirect
cloud.google.com/go/compute/metadata v0.2.3 // indirect
cloud.google.com/go/iam v0.13.0 // indirect
cloud.google.com/go/kms v1.10.2 // indirect
cloud.google.com/go/iam v1.1.0 // indirect
cloud.google.com/go/kms v1.12.0 // indirect
filippo.io/edwards25519 v1.0.0 // indirect
github.com/AliyunContainerService/ack-ram-tool/pkg/credentials/alibabacloudsdkgo/helper v0.2.0 // indirect
github.com/Azure/azure-sdk-for-go v68.0.0+incompatible // indirect
github.com/Azure/azure-sdk-for-go/sdk/azcore v1.6.0 // indirect
github.com/Azure/azure-sdk-for-go/sdk/azcore v1.6.1 // indirect
github.com/Azure/azure-sdk-for-go/sdk/azidentity v1.3.0 // indirect
github.com/Azure/azure-sdk-for-go/sdk/internal v1.3.0 // indirect
github.com/Azure/azure-sdk-for-go/sdk/keyvault/azkeys v0.10.0 // indirect
Expand Down Expand Up @@ -98,21 +98,21 @@ require (
github.com/alibabacloud-go/tea-xml v1.1.2 // indirect
github.com/aliyun/credentials-go v1.2.3 // indirect
github.com/asaskevich/govalidator v0.0.0-20230301143203-a9d515a09cc2 // indirect
github.com/aws/aws-sdk-go v1.44.275 // indirect
github.com/aws/aws-sdk-go-v2 v1.18.0 // indirect
github.com/aws/aws-sdk-go-v2/config v1.18.23 // indirect
github.com/aws/aws-sdk-go-v2/credentials v1.13.22 // indirect
github.com/aws/aws-sdk-go-v2/feature/ec2/imds v1.13.3 // indirect
github.com/aws/aws-sdk-go-v2/internal/configsources v1.1.33 // indirect
github.com/aws/aws-sdk-go-v2/internal/endpoints/v2 v2.4.27 // indirect
github.com/aws/aws-sdk-go-v2/internal/ini v1.3.34 // indirect
github.com/aws/aws-sdk-go v1.44.282 // indirect
github.com/aws/aws-sdk-go-v2 v1.18.1 // indirect
github.com/aws/aws-sdk-go-v2/config v1.18.26 // indirect
github.com/aws/aws-sdk-go-v2/credentials v1.13.25 // indirect
github.com/aws/aws-sdk-go-v2/feature/ec2/imds v1.13.4 // indirect
github.com/aws/aws-sdk-go-v2/internal/configsources v1.1.34 // indirect
github.com/aws/aws-sdk-go-v2/internal/endpoints/v2 v2.4.28 // indirect
github.com/aws/aws-sdk-go-v2/internal/ini v1.3.35 // indirect
github.com/aws/aws-sdk-go-v2/service/ecr v1.15.0 // indirect
github.com/aws/aws-sdk-go-v2/service/ecrpublic v1.12.0 // indirect
github.com/aws/aws-sdk-go-v2/service/internal/presigned-url v1.9.27 // indirect
github.com/aws/aws-sdk-go-v2/service/kms v1.21.1 // indirect
github.com/aws/aws-sdk-go-v2/service/sso v1.12.10 // indirect
github.com/aws/aws-sdk-go-v2/service/ssooidc v1.14.10 // indirect
github.com/aws/aws-sdk-go-v2/service/sts v1.18.11 // indirect
github.com/aws/aws-sdk-go-v2/service/internal/presigned-url v1.9.28 // indirect
github.com/aws/aws-sdk-go-v2/service/kms v1.22.1 // indirect
github.com/aws/aws-sdk-go-v2/service/sso v1.12.11 // indirect
github.com/aws/aws-sdk-go-v2/service/ssooidc v1.14.11 // indirect
github.com/aws/aws-sdk-go-v2/service/sts v1.19.1 // indirect
github.com/aws/smithy-go v1.13.5 // indirect
github.com/beorn7/perks v1.0.1 // indirect
github.com/blang/semver v3.5.1+incompatible // indirect
Expand All @@ -134,7 +134,7 @@ require (
github.com/docker/docker v23.0.5+incompatible // indirect
github.com/docker/docker-credential-helpers v0.7.0 // indirect
github.com/docker/go-units v0.5.0 // indirect
github.com/emicklei/go-restful/v3 v3.8.0 // indirect
github.com/emicklei/go-restful/v3 v3.9.0 // indirect
github.com/emicklei/proto v1.10.0 // indirect
github.com/fsnotify/fsnotify v1.6.0 // indirect
github.com/gabriel-vasile/mimetype v1.4.2 // indirect
Expand Down Expand Up @@ -166,7 +166,7 @@ require (
github.com/google/s2a-go v0.1.4 // indirect
github.com/google/tink/go v1.7.0 // indirect
github.com/google/uuid v1.3.0 // indirect
github.com/googleapis/enterprise-certificate-proxy v0.2.3 // indirect
github.com/googleapis/enterprise-certificate-proxy v0.2.4 // indirect
github.com/googleapis/gax-go/v2 v2.10.0 // indirect
github.com/hashicorp/errwrap v1.1.0 // indirect
github.com/hashicorp/go-cleanhttp v0.5.2 // indirect
Expand All @@ -177,7 +177,7 @@ require (
github.com/hashicorp/go-secure-stdlib/strutil v0.1.2 // indirect
github.com/hashicorp/go-sockaddr v1.0.2 // indirect
github.com/hashicorp/hcl v1.0.0 // indirect
github.com/hashicorp/vault/api v1.9.1 // indirect
github.com/hashicorp/vault/api v1.9.2 // indirect
github.com/imdario/mergo v0.3.12 // indirect
github.com/inconshreveable/mousetrap v1.1.0 // indirect
github.com/jedisct1/go-minisign v0.0.0-20211028175153-1c139d1cc84b // indirect
Expand Down Expand Up @@ -245,9 +245,9 @@ require (
go.uber.org/zap v1.24.0 // indirect
golang.org/x/exp v0.0.0-20230321023759-10a507213a29 // indirect
golang.org/x/mod v0.10.0 // indirect
golang.org/x/net v0.10.0 // indirect
golang.org/x/sys v0.8.0 // indirect
golang.org/x/text v0.9.0 // indirect
golang.org/x/net v0.11.0 // indirect
golang.org/x/sys v0.9.0 // indirect
golang.org/x/text v0.10.0 // indirect
golang.org/x/time v0.3.0 // indirect
golang.org/x/tools v0.8.0 // indirect
google.golang.org/appengine v1.6.7 // indirect
Expand Down
Loading

0 comments on commit eb62e59

Please sign in to comment.