11module github.com/sigstore/cosign/v3
22
3- go 1.24.9
3+ go 1.25.0
44
55require (
66 cuelang.org/go v0.15.0
@@ -15,8 +15,8 @@ require (
1515 github.com/go-jose/go-jose/v4 v4.1.3
1616 github.com/go-openapi/runtime v0.29.2
1717 github.com/go-openapi/strfmt v0.25.0
18- github.com/go-openapi/swag v0.25.1
19- github.com/go-openapi/swag/conv v0.25.1
18+ github.com/go-openapi/swag v0.25.3
19+ github.com/go-openapi/swag/conv v0.25.3
2020 github.com/go-piv/piv-go/v2 v2.4.0
2121 github.com/google/certificate-transparency-go v1.3.2
2222 github.com/google/go-cmp v0.7.0
@@ -33,17 +33,17 @@ require (
3333 github.com/nozzle/throttler v0.0.0-20180817012639-2ea982251481
3434 github.com/open-policy-agent/opa v1.10.1
3535 github.com/secure-systems-lab/go-securesystemslib v0.9.1
36- github.com/sigstore/fulcio v1.7.1
36+ github.com/sigstore/fulcio v1.8.2
3737 github.com/sigstore/protobuf-specs v0.5.0
38- github.com/sigstore/rekor v1.4.2
38+ github.com/sigstore/rekor v1.4.3
3939 github.com/sigstore/rekor-tiles/v2 v2.0.1
40- github.com/sigstore/sigstore v1.9.6-0.20250729224751-181c5d3339b3
40+ github.com/sigstore/sigstore v1.10.0
4141 github.com/sigstore/sigstore-go v1.1.3
42- github.com/sigstore/sigstore/pkg/signature/kms/aws v1.9.5
43- github.com/sigstore/sigstore/pkg/signature/kms/azure v1.9.5
44- github.com/sigstore/sigstore/pkg/signature/kms/gcp v1.9.6-0.20250729224751-181c5d3339b3
45- github.com/sigstore/sigstore/pkg/signature/kms/hashivault v1.9.5
46- github.com/sigstore/timestamp-authority v1.2.9
42+ github.com/sigstore/sigstore/pkg/signature/kms/aws v1.10.0
43+ github.com/sigstore/sigstore/pkg/signature/kms/azure v1.10.0
44+ github.com/sigstore/sigstore/pkg/signature/kms/gcp v1.10.0
45+ github.com/sigstore/sigstore/pkg/signature/kms/hashivault v1.10.0
46+ github.com/sigstore/timestamp-authority/v2 v2.0.2
4747 github.com/spf13/cobra v1.10.1
4848 github.com/spf13/pflag v1.0.10
4949 github.com/spf13/viper v1.21.0
@@ -53,11 +53,11 @@ require (
5353 github.com/transparency-dev/merkle v0.0.2
5454 github.com/withfig/autocomplete-tools/integrations/cobra v1.2.1
5555 gitlab.com/gitlab-org/api/client-go v0.160.0
56- golang.org/x/crypto v0.43 .0
56+ golang.org/x/crypto v0.44 .0
5757 golang.org/x/oauth2 v0.33.0
5858 golang.org/x/sync v0.18.0
59- golang.org/x/term v0.36 .0
60- google.golang.org/api v0.255 .0
59+ golang.org/x/term v0.37 .0
60+ google.golang.org/api v0.256 .0
6161 google.golang.org/protobuf v1.36.10
6262 k8s.io/api v0.34.2
6363 k8s.io/apimachinery v0.34.2
@@ -72,7 +72,7 @@ require (
7272 cloud.google.com/go/auth v0.17.0 // indirect
7373 cloud.google.com/go/auth/oauth2adapt v0.2.8 // indirect
7474 cloud.google.com/go/compute/metadata v0.9.0 // indirect
75- cloud.google.com/go/iam v1.5.2 // indirect
75+ cloud.google.com/go/iam v1.5.3 // indirect
7676 cloud.google.com/go/kms v1.23.2 // indirect
7777 cloud.google.com/go/longrunning v0.6.7 // indirect
7878 cloud.google.com/go/monitoring v1.24.2 // indirect
@@ -82,8 +82,8 @@ require (
8282 filippo.io/edwards25519 v1.1.0 // indirect
8383 github.com/AliyunContainerService/ack-ram-tool/pkg/credentials/provider v0.14.0 // indirect
8484 github.com/Azure/azure-sdk-for-go v68.0.0+incompatible // indirect
85- github.com/Azure/azure-sdk-for-go/sdk/azcore v1.19.1 // indirect
86- github.com/Azure/azure-sdk-for-go/sdk/azidentity v1.13.0 // indirect
85+ github.com/Azure/azure-sdk-for-go/sdk/azcore v1.20.0 // indirect
86+ github.com/Azure/azure-sdk-for-go/sdk/azidentity v1.13.1 // indirect
8787 github.com/Azure/azure-sdk-for-go/sdk/internal v1.11.2 // indirect
8888 github.com/Azure/azure-sdk-for-go/sdk/security/keyvault/azkeys v1.4.0 // indirect
8989 github.com/Azure/azure-sdk-for-go/sdk/security/keyvault/internal v1.2.0 // indirect
@@ -96,7 +96,7 @@ require (
9696 github.com/Azure/go-autorest/autorest/date v0.3.0 // indirect
9797 github.com/Azure/go-autorest/logger v0.2.1 // indirect
9898 github.com/Azure/go-autorest/tracing v0.6.0 // indirect
99- github.com/AzureAD/microsoft-authentication-library-for-go v1.5 .0 // indirect
99+ github.com/AzureAD/microsoft-authentication-library-for-go v1.6 .0 // indirect
100100 github.com/GoogleCloudPlatform/grpc-gcp-go/grpcgcp v1.5.3 // indirect
101101 github.com/GoogleCloudPlatform/opentelemetry-operations-go/detectors/gcp v1.29.0 // indirect
102102 github.com/GoogleCloudPlatform/opentelemetry-operations-go/exporter/metric v0.54.0 // indirect
@@ -117,8 +117,8 @@ require (
117117 github.com/asaskevich/govalidator v0.0.0-20230301143203-a9d515a09cc2 // indirect
118118 github.com/aws/aws-sdk-go v1.55.8 // indirect
119119 github.com/aws/aws-sdk-go-v2 v1.39.6 // indirect
120- github.com/aws/aws-sdk-go-v2/config v1.31.17 // indirect
121- github.com/aws/aws-sdk-go-v2/credentials v1.18.21 // indirect
120+ github.com/aws/aws-sdk-go-v2/config v1.31.20 // indirect
121+ github.com/aws/aws-sdk-go-v2/credentials v1.18.24 // indirect
122122 github.com/aws/aws-sdk-go-v2/feature/ec2/imds v1.18.13 // indirect
123123 github.com/aws/aws-sdk-go-v2/internal/configsources v1.4.13 // indirect
124124 github.com/aws/aws-sdk-go-v2/internal/endpoints/v2 v2.7.13 // indirect
@@ -127,10 +127,10 @@ require (
127127 github.com/aws/aws-sdk-go-v2/service/ecrpublic v1.33.2 // indirect
128128 github.com/aws/aws-sdk-go-v2/service/internal/accept-encoding v1.13.3 // indirect
129129 github.com/aws/aws-sdk-go-v2/service/internal/presigned-url v1.13.13 // indirect
130- github.com/aws/aws-sdk-go-v2/service/kms v1.47.1 // indirect
131- github.com/aws/aws-sdk-go-v2/service/sso v1.30.1 // indirect
132- github.com/aws/aws-sdk-go-v2/service/ssooidc v1.35.5 // indirect
133- github.com/aws/aws-sdk-go-v2/service/sts v1.39.1 // indirect
130+ github.com/aws/aws-sdk-go-v2/service/kms v1.48.2 // indirect
131+ github.com/aws/aws-sdk-go-v2/service/sso v1.30.3 // indirect
132+ github.com/aws/aws-sdk-go-v2/service/ssooidc v1.35.7 // indirect
133+ github.com/aws/aws-sdk-go-v2/service/sts v1.40.2 // indirect
134134 github.com/aws/smithy-go v1.23.2 // indirect
135135 github.com/beorn7/perks v1.0.1 // indirect
136136 github.com/blang/semver v3.5.1+incompatible // indirect
@@ -146,7 +146,7 @@ require (
146146 github.com/cockroachdb/apd/v3 v3.2.1 // indirect
147147 github.com/common-nighthawk/go-figure v0.0.0-20210622060536-734e95fb86be // indirect
148148 github.com/containerd/stargz-snapshotter/estargz v0.16.3 // indirect
149- github.com/coreos/go-oidc/v3 v3.14.1 // indirect
149+ github.com/coreos/go-oidc/v3 v3.16.0 // indirect
150150 github.com/cpuguy83/go-md2man/v2 v2.0.7 // indirect
151151 github.com/davecgh/go-spew v1.1.2-0.20180830191138-d8f796af33cc // indirect
152152 github.com/decred/dcrd/dcrec/secp256k1/v4 v4.4.0 // indirect
@@ -174,16 +174,16 @@ require (
174174 github.com/go-openapi/jsonreference v0.21.3 // indirect
175175 github.com/go-openapi/loads v0.23.2 // indirect
176176 github.com/go-openapi/spec v0.22.1 // indirect
177- github.com/go-openapi/swag/cmdutils v0.25.1 // indirect
178- github.com/go-openapi/swag/fileutils v0.25.1 // indirect
179- github.com/go-openapi/swag/jsonname v0.25.1 // indirect
180- github.com/go-openapi/swag/jsonutils v0.25.1 // indirect
181- github.com/go-openapi/swag/loading v0.25.1 // indirect
182- github.com/go-openapi/swag/mangling v0.25.1 // indirect
183- github.com/go-openapi/swag/netutils v0.25.1 // indirect
184- github.com/go-openapi/swag/stringutils v0.25.1 // indirect
185- github.com/go-openapi/swag/typeutils v0.25.1 // indirect
186- github.com/go-openapi/swag/yamlutils v0.25.1 // indirect
177+ github.com/go-openapi/swag/cmdutils v0.25.3 // indirect
178+ github.com/go-openapi/swag/fileutils v0.25.3 // indirect
179+ github.com/go-openapi/swag/jsonname v0.25.3 // indirect
180+ github.com/go-openapi/swag/jsonutils v0.25.3 // indirect
181+ github.com/go-openapi/swag/loading v0.25.3 // indirect
182+ github.com/go-openapi/swag/mangling v0.25.3 // indirect
183+ github.com/go-openapi/swag/netutils v0.25.3 // indirect
184+ github.com/go-openapi/swag/stringutils v0.25.3 // indirect
185+ github.com/go-openapi/swag/typeutils v0.25.3 // indirect
186+ github.com/go-openapi/swag/yamlutils v0.25.3 // indirect
187187 github.com/go-openapi/validate v0.25.1 // indirect
188188 github.com/go-sql-driver/mysql v1.9.3 // indirect
189189 github.com/go-viper/mapstructure/v2 v2.4.0 // indirect
@@ -199,7 +199,7 @@ require (
199199 github.com/google/s2a-go v0.1.9 // indirect
200200 github.com/google/trillian v1.7.2 // indirect
201201 github.com/google/uuid v1.6.0 // indirect
202- github.com/googleapis/enterprise-certificate-proxy v0.3.6 // indirect
202+ github.com/googleapis/enterprise-certificate-proxy v0.3.7 // indirect
203203 github.com/googleapis/gax-go/v2 v2.15.0 // indirect
204204 github.com/grpc-ecosystem/grpc-gateway/v2 v2.27.3 // indirect
205205 github.com/hashicorp/errwrap v1.1.0 // indirect
@@ -211,8 +211,8 @@ require (
211211 github.com/hashicorp/go-secure-stdlib/strutil v0.1.2 // indirect
212212 github.com/hashicorp/go-sockaddr v1.0.7 // indirect
213213 github.com/hashicorp/golang-lru/v2 v2.0.7 // indirect
214- github.com/hashicorp/hcl v1.0.1-vault-5 // indirect
215- github.com/hashicorp/vault/api v1.16 .0 // indirect
214+ github.com/hashicorp/hcl v1.0.1-vault-7 // indirect
215+ github.com/hashicorp/vault/api v1.22 .0 // indirect
216216 github.com/inconshreveable/mousetrap v1.1.0 // indirect
217217 github.com/jackc/pgpassfile v1.0.0 // indirect
218218 github.com/jackc/pgservicefile v0.0.0-20240606120523-5a60cdf6a761 // indirect
@@ -232,12 +232,13 @@ require (
232232 github.com/lestrrat-go/jwx/v3 v3.0.11 // indirect
233233 github.com/lestrrat-go/option v1.0.1 // indirect
234234 github.com/lestrrat-go/option/v2 v2.0.0 // indirect
235- github.com/letsencrypt/boulder v0.0.0-20240620165639-de9c06129bec // indirect
235+ github.com/letsencrypt/boulder v0.20251110.0 // indirect
236236 github.com/mitchellh/go-homedir v1.1.0 // indirect
237237 github.com/mitchellh/mapstructure v1.5.1-0.20231216201459-8508981c8b6c // indirect
238238 github.com/modern-go/concurrent v0.0.0-20180306012644-bacd9c7ef1dd // indirect
239239 github.com/modern-go/reflect2 v1.0.3-0.20250322232337-35a7c28c31ee // indirect
240240 github.com/munnerz/goautoneg v0.0.0-20191010083416-a7dc8b61c822 // indirect
241+ github.com/natefinch/atomic v1.0.1 // indirect
241242 github.com/oklog/ulid v1.3.1 // indirect
242243 github.com/oleiade/reflections v1.1.0 // indirect
243244 github.com/opencontainers/go-digest v1.0.0 // indirect
@@ -250,7 +251,7 @@ require (
250251 github.com/pmezard/go-difflib v1.0.1-0.20181226105442-5d4384ee4fb2 // indirect
251252 github.com/prometheus/client_golang v1.23.2 // indirect
252253 github.com/prometheus/client_model v0.6.2 // indirect
253- github.com/prometheus/common v0.66.1 // indirect
254+ github.com/prometheus/common v0.67.2 // indirect
254255 github.com/prometheus/procfs v0.17.0 // indirect
255256 github.com/protocolbuffers/txtpbfmt v0.0.0-20251016062345-16587c79cd91 // indirect
256257 github.com/rcrowley/go-metrics v0.0.0-20250401214520-65e299d6c5c9 // indirect
@@ -261,11 +262,10 @@ require (
261262 github.com/sagikazarmark/locafero v0.11.0 // indirect
262263 github.com/sassoftware/relic v7.2.1+incompatible // indirect
263264 github.com/segmentio/asm v1.2.0 // indirect
264- github.com/segmentio/ksuid v1.0.4 // indirect
265265 github.com/shibumi/go-pathspec v1.3.0 // indirect
266266 github.com/sigstore/rekor-tiles v0.1.11 // indirect
267+ github.com/sigstore/timestamp-authority v1.2.9 // indirect
267268 github.com/sirupsen/logrus v1.9.4-0.20230606125235-dd1b4c2e81af // indirect
268- github.com/skratchdot/open-golang v0.0.0-20200116055534-eef842397966 // indirect
269269 github.com/sourcegraph/conc v0.3.1-0.20240121214520-5f936abd7ae8 // indirect
270270 github.com/spf13/afero v1.15.0 // indirect
271271 github.com/spf13/cast v1.10.0 // indirect
@@ -301,21 +301,21 @@ require (
301301 go.opentelemetry.io/otel/sdk v1.38.0 // indirect
302302 go.opentelemetry.io/otel/sdk/metric v1.38.0 // indirect
303303 go.opentelemetry.io/otel/trace v1.38.0 // indirect
304- go.step.sm/crypto v0.73 .0 // indirect
304+ go.step.sm/crypto v0.74 .0 // indirect
305305 go.uber.org/multierr v1.11.0 // indirect
306306 go.uber.org/zap v1.27.0 // indirect
307- go.yaml.in/yaml/v2 v2.4.2 // indirect
307+ go.yaml.in/yaml/v2 v2.4.3 // indirect
308308 go.yaml.in/yaml/v3 v3.0.4 // indirect
309309 golang.org/x/exp v0.0.0-20250620022241-b7579e27df2b // indirect
310- golang.org/x/mod v0.29 .0 // indirect
311- golang.org/x/net v0.46 .0 // indirect
312- golang.org/x/sys v0.37 .0 // indirect
313- golang.org/x/text v0.30 .0 // indirect
310+ golang.org/x/mod v0.30 .0 // indirect
311+ golang.org/x/net v0.47 .0 // indirect
312+ golang.org/x/sys v0.38 .0 // indirect
313+ golang.org/x/text v0.31 .0 // indirect
314314 golang.org/x/time v0.14.0 // indirect
315315 golang.org/x/tools v0.38.0 // indirect
316316 google.golang.org/genproto v0.0.0-20250922171735-9219d122eba9 // indirect
317317 google.golang.org/genproto/googleapis/api v0.0.0-20250929231259-57b25ae835d4 // indirect
318- google.golang.org/genproto/googleapis/rpc v0.0.0-20251029180050-ab9386a59fda // indirect
318+ google.golang.org/genproto/googleapis/rpc v0.0.0-20251103181224-f26f9409b101 // indirect
319319 google.golang.org/grpc v1.76.0 // indirect
320320 gopkg.in/evanphx/json-patch.v4 v4.12.0 // indirect
321321 gopkg.in/inf.v0 v0.9.1 // indirect
0 commit comments