Skip to content

Commit 4bd5c84

Browse files
chore(deps): bump github.com/sigstore/rekor from 1.4.3 to 1.5.0 (#224)
* chore(deps): bump github.com/sigstore/rekor from 1.4.3 to 1.5.0 Bumps [github.com/sigstore/rekor](https://github.com/sigstore/rekor) from 1.4.3 to 1.5.0. - [Release notes](https://github.com/sigstore/rekor/releases) - [Changelog](https://github.com/sigstore/rekor/blob/main/CHANGELOG.md) - [Commits](sigstore/rekor@v1.4.3...v1.5.0) --- updated-dependencies: - dependency-name: github.com/sigstore/rekor dependency-version: 1.5.0 dependency-type: indirect ... Signed-off-by: dependabot[bot] <[email protected]> * test: Add new expected vulnerabilities to test results --------- Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: André Meira <[email protected]>
1 parent 74a6ee4 commit 4bd5c84

File tree

4 files changed

+59
-59
lines changed

4 files changed

+59
-59
lines changed

docs/multiple-tests/all-patterns/results.xml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -24,7 +24,7 @@
2424
<error
2525
source="vulnerability_medium"
2626
line="1"
27-
message="Insecure dependency maven/org.apache.logging.log4j/[email protected] (CVE-2025-68161: Apache Log4j: Apache Log4j Core: Missing TLS hostname verification in Socket appender) (update to 2.25.3)"
27+
message="Insecure dependency maven/org.apache.logging.log4j/[email protected] (CVE-2025-68161: Apache Log4j: Apache Log4j Core: Information disclosure via missing TLS hostname verification) (update to 2.25.3)"
2828
severity="warning"
2929
/>
3030
<error

docs/multiple-tests/pattern-vulnerability-medium/results.xml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -194,7 +194,7 @@
194194
<error
195195
source="vulnerability_medium"
196196
line="1"
197-
message="Insecure dependency maven/org.apache.logging.log4j/[email protected] (CVE-2025-68161: Apache Log4j: Apache Log4j Core: Missing TLS hostname verification in Socket appender) (update to 2.25.3)"
197+
message="Insecure dependency maven/org.apache.logging.log4j/[email protected] (CVE-2025-68161: Apache Log4j: Apache Log4j Core: Information disclosure via missing TLS hostname verification) (update to 2.25.3)"
198198
severity="warning"
199199
/>
200200
<error
@@ -215,7 +215,7 @@
215215
<error
216216
source="vulnerability_medium"
217217
line="14"
218-
message="Insecure dependency maven/org.apache.logging.log4j/[email protected] (CVE-2025-68161: Apache Log4j: Apache Log4j Core: Missing TLS hostname verification in Socket appender) (update to 2.25.3)"
218+
message="Insecure dependency maven/org.apache.logging.log4j/[email protected] (CVE-2025-68161: Apache Log4j: Apache Log4j Core: Information disclosure via missing TLS hostname verification) (update to 2.25.3)"
219219
severity="warning"
220220
/>
221221
</file>

go.mod

Lines changed: 16 additions & 16 deletions
Original file line numberDiff line numberDiff line change
@@ -20,11 +20,11 @@ require (
2020
al.essio.dev/pkg/shellescape v1.6.0 // indirect
2121
cel.dev/expr v0.24.0 // indirect
2222
cloud.google.com/go v0.121.6 // indirect
23-
cloud.google.com/go/auth v0.17.0 // indirect
23+
cloud.google.com/go/auth v0.18.0 // indirect
2424
cloud.google.com/go/auth/oauth2adapt v0.2.8 // indirect
2525
cloud.google.com/go/compute/metadata v0.9.0 // indirect
2626
cloud.google.com/go/iam v1.5.3 // indirect
27-
cloud.google.com/go/monitoring v1.24.2 // indirect
27+
cloud.google.com/go/monitoring v1.24.3 // indirect
2828
cloud.google.com/go/storage v1.57.1 // indirect
2929
cyphar.com/go-pathrs v0.2.1 // indirect
3030
dario.cat/mergo v1.0.2 // indirect
@@ -146,7 +146,7 @@ require (
146146
github.com/fsnotify/fsnotify v1.9.0 // indirect
147147
github.com/fvbommel/sortorder v1.1.0 // indirect
148148
github.com/fxamacker/cbor/v2 v2.9.0 // indirect
149-
github.com/go-chi/chi/v5 v5.2.3 // indirect
149+
github.com/go-chi/chi/v5 v5.2.4 // indirect
150150
github.com/go-errors/errors v1.4.2 // indirect
151151
github.com/go-git/gcfg v1.5.1-0.20230307220236-3a3c6141e376 // indirect
152152
github.com/go-git/go-billy/v5 v5.6.2 // indirect
@@ -157,12 +157,12 @@ require (
157157
github.com/go-logr/logr v1.4.3 // indirect
158158
github.com/go-logr/stdr v1.2.2 // indirect
159159
github.com/go-openapi/analysis v0.24.1 // indirect
160-
github.com/go-openapi/errors v0.22.4 // indirect
161-
github.com/go-openapi/jsonpointer v0.22.1 // indirect
162-
github.com/go-openapi/jsonreference v0.21.3 // indirect
160+
github.com/go-openapi/errors v0.22.6 // indirect
161+
github.com/go-openapi/jsonpointer v0.22.4 // indirect
162+
github.com/go-openapi/jsonreference v0.21.4 // indirect
163163
github.com/go-openapi/loads v0.23.2 // indirect
164164
github.com/go-openapi/runtime v0.29.2 // indirect
165-
github.com/go-openapi/spec v0.22.1 // indirect
165+
github.com/go-openapi/spec v0.22.3 // indirect
166166
github.com/go-openapi/strfmt v0.25.0 // indirect
167167
github.com/go-openapi/swag v0.25.4 // indirect
168168
github.com/go-openapi/swag/cmdutils v0.25.4 // indirect
@@ -195,8 +195,8 @@ require (
195195
github.com/google/licenseclassifier/v2 v2.0.0 // indirect
196196
github.com/google/s2a-go v0.1.9 // indirect
197197
github.com/google/uuid v1.6.0 // indirect
198-
github.com/googleapis/enterprise-certificate-proxy v0.3.7 // indirect
199-
github.com/googleapis/gax-go/v2 v2.15.0 // indirect
198+
github.com/googleapis/enterprise-certificate-proxy v0.3.9 // indirect
199+
github.com/googleapis/gax-go/v2 v2.16.0 // indirect
200200
github.com/gorilla/websocket v1.5.4-0.20250319132907-e064f32e3674 // indirect
201201
github.com/gosuri/uitable v0.0.4 // indirect
202202
github.com/gregjones/httpcache v0.0.0-20190611155906-901d90724c79 // indirect
@@ -316,7 +316,7 @@ require (
316316
github.com/shopspring/decimal v1.4.0 // indirect
317317
github.com/sigstore/cosign/v2 v2.6.2 // indirect
318318
github.com/sigstore/protobuf-specs v0.5.0 // indirect
319-
github.com/sigstore/rekor v1.4.3 // indirect
319+
github.com/sigstore/rekor v1.5.0 // indirect
320320
github.com/sigstore/rekor-tiles/v2 v2.0.1 // indirect
321321
github.com/sigstore/sigstore v1.10.3 // indirect
322322
github.com/sigstore/sigstore-go v1.1.4 // indirect
@@ -381,19 +381,19 @@ require (
381381
go.yaml.in/yaml/v3 v3.0.4 // indirect
382382
golang.org/x/crypto v0.46.0 // indirect
383383
golang.org/x/net v0.48.0 // indirect
384-
golang.org/x/oauth2 v0.33.0 // indirect
384+
golang.org/x/oauth2 v0.34.0 // indirect
385385
golang.org/x/sync v0.19.0 // indirect
386386
golang.org/x/sys v0.39.0 // indirect
387387
golang.org/x/term v0.38.0 // indirect
388388
golang.org/x/text v0.32.0 // indirect
389389
golang.org/x/time v0.14.0 // indirect
390390
golang.org/x/tools v0.40.0 // indirect
391391
golang.org/x/xerrors v0.0.0-20240716161551-93cc26a95ae9 // indirect
392-
google.golang.org/api v0.257.0 // indirect
393-
google.golang.org/genproto v0.0.0-20250922171735-9219d122eba9 // indirect
394-
google.golang.org/genproto/googleapis/api v0.0.0-20251022142026-3a174f9686a8 // indirect
395-
google.golang.org/genproto/googleapis/rpc v0.0.0-20251213004720-97cd9d5aeac2 // indirect
396-
google.golang.org/grpc v1.77.0 // indirect
392+
google.golang.org/api v0.260.0 // indirect
393+
google.golang.org/genproto v0.0.0-20251202230838-ff82c1b0f217 // indirect
394+
google.golang.org/genproto/googleapis/api v0.0.0-20251202230838-ff82c1b0f217 // indirect
395+
google.golang.org/genproto/googleapis/rpc v0.0.0-20251222181119-0a764e51fe1b // indirect
396+
google.golang.org/grpc v1.78.0 // indirect
397397
google.golang.org/protobuf v1.36.11 // indirect
398398
gopkg.in/cheggaaa/pb.v1 v1.0.28 // indirect
399399
gopkg.in/evanphx/json-patch.v4 v4.12.0 // indirect

0 commit comments

Comments
 (0)