Skip to content

Commit 4c0884b

Browse files
committed
chore(deps): lock file maintenance vulnfeeds
1 parent f240c5a commit 4c0884b

File tree

12 files changed

+269
-242
lines changed

12 files changed

+269
-242
lines changed

vulnfeeds/cmd/alpine/Dockerfile

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -12,7 +12,7 @@
1212
# See the License for the specific language governing permissions and
1313
# limitations under the License.
1414

15-
FROM golang:1.22.5-alpine@sha256:8c9183f715b0b4eca05b8b3dbf59766aaedb41ec07477b132ee2891ac0110a07 AS GO_BUILD
15+
FROM golang:1.23.1-alpine@sha256:ac67716dd016429be8d4c2c53a248d7bcdf06d34127d3dc451bda6aa5a87bc06 AS GO_BUILD
1616

1717
RUN mkdir /src
1818
WORKDIR /src
@@ -25,7 +25,7 @@ COPY ./ /src/
2525
RUN go build -o alpine-osv ./cmd/alpine/
2626

2727

28-
FROM gcr.io/google.com/cloudsdktool/google-cloud-cli:alpine@sha256:d5da0344b23d03a6f2728657732c7a60300a91acaad9b8076c6fd30b1dfe1ff4
28+
FROM gcr.io/google.com/cloudsdktool/google-cloud-cli:alpine@sha256:e5932e1c9e2bd5a47dc07e1a2de4882d25b763b7cda15f11689752c0ed102620
2929

3030
WORKDIR /root/
3131
COPY --from=GO_BUILD /src/alpine-osv ./

vulnfeeds/cmd/combine-to-osv/Dockerfile

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -12,7 +12,7 @@
1212
# See the License for the specific language governing permissions and
1313
# limitations under the License.
1414

15-
FROM golang:1.22.5-alpine@sha256:8c9183f715b0b4eca05b8b3dbf59766aaedb41ec07477b132ee2891ac0110a07 AS GO_BUILD
15+
FROM golang:1.23.1-alpine@sha256:ac67716dd016429be8d4c2c53a248d7bcdf06d34127d3dc451bda6aa5a87bc06 AS GO_BUILD
1616

1717
RUN mkdir /src
1818
WORKDIR /src
@@ -26,7 +26,7 @@ RUN go build -o combine-to-osv ./cmd/combine-to-osv/
2626
RUN go build -o download-cves ./cmd/download-cves/
2727

2828

29-
FROM gcr.io/google.com/cloudsdktool/google-cloud-cli:491.0.0-alpine@sha256:6281dc09e2b3abbd6d8f93296c14f90028b40d7046c1b6ea638ed1f50415ef92
29+
FROM gcr.io/google.com/cloudsdktool/google-cloud-cli:491.0.0-alpine@sha256:e5932e1c9e2bd5a47dc07e1a2de4882d25b763b7cda15f11689752c0ed102620
3030
RUN apk --no-cache add jq
3131

3232
WORKDIR /root/

vulnfeeds/cmd/cpe-repo-gen/Dockerfile

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -12,7 +12,7 @@
1212
# See the License for the specific language governing permissions and
1313
# limitations under the License.
1414

15-
FROM golang:1.22.5-alpine@sha256:8c9183f715b0b4eca05b8b3dbf59766aaedb41ec07477b132ee2891ac0110a07 AS GO_BUILD
15+
FROM golang:1.23.1-alpine@sha256:ac67716dd016429be8d4c2c53a248d7bcdf06d34127d3dc451bda6aa5a87bc06 AS GO_BUILD
1616

1717
RUN mkdir /src
1818
WORKDIR /src
@@ -24,7 +24,7 @@ RUN go mod download
2424
COPY ./ /src/
2525
RUN CGO_ENABLED=0 go build -o cpe-repo-gen ./cmd/cpe-repo-gen
2626

27-
FROM gcr.io/google.com/cloudsdktool/google-cloud-cli:alpine@sha256:d5da0344b23d03a6f2728657732c7a60300a91acaad9b8076c6fd30b1dfe1ff4
27+
FROM gcr.io/google.com/cloudsdktool/google-cloud-cli:alpine@sha256:e5932e1c9e2bd5a47dc07e1a2de4882d25b763b7cda15f11689752c0ed102620
2828

2929
COPY --from=GO_BUILD /src/cpe-repo-gen ./
3030
COPY ./cmd/cpe-repo-gen/cpe-repo-gen_map.sh ./

vulnfeeds/cmd/debian-copyright-mirror/Dockerfile

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -12,7 +12,7 @@
1212
# See the License for the specific language governing permissions and
1313
# limitations under the License.
1414

15-
FROM gcr.io/google.com/cloudsdktool/google-cloud-cli:alpine@sha256:d5da0344b23d03a6f2728657732c7a60300a91acaad9b8076c6fd30b1dfe1ff4
15+
FROM gcr.io/google.com/cloudsdktool/google-cloud-cli:alpine@sha256:e5932e1c9e2bd5a47dc07e1a2de4882d25b763b7cda15f11689752c0ed102620
1616

1717
RUN apk add wget
1818

vulnfeeds/cmd/debian/Dockerfile

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -12,7 +12,7 @@
1212
# See the License for the specific language governing permissions and
1313
# limitations under the License.
1414

15-
FROM golang:1.22.5-alpine@sha256:8c9183f715b0b4eca05b8b3dbf59766aaedb41ec07477b132ee2891ac0110a07 AS GO_BUILD
15+
FROM golang:1.23.1-alpine@sha256:ac67716dd016429be8d4c2c53a248d7bcdf06d34127d3dc451bda6aa5a87bc06 AS GO_BUILD
1616

1717
RUN mkdir /src
1818
WORKDIR /src
@@ -25,7 +25,7 @@ COPY ./ /src/
2525
RUN go build -o debian-osv ./cmd/debian/
2626

2727

28-
FROM gcr.io/google.com/cloudsdktool/google-cloud-cli:alpine@sha256:d5da0344b23d03a6f2728657732c7a60300a91acaad9b8076c6fd30b1dfe1ff4
28+
FROM gcr.io/google.com/cloudsdktool/google-cloud-cli:alpine@sha256:e5932e1c9e2bd5a47dc07e1a2de4882d25b763b7cda15f11689752c0ed102620
2929

3030
WORKDIR /root/
3131
COPY --from=GO_BUILD /src/debian-osv ./

vulnfeeds/cmd/download-cves/Dockerfile

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -12,7 +12,7 @@
1212
# See the License for the specific language governing permissions and
1313
# limitations under the License.
1414

15-
FROM golang:1.22.5-alpine@sha256:8c9183f715b0b4eca05b8b3dbf59766aaedb41ec07477b132ee2891ac0110a07 AS GO_BUILD
15+
FROM golang:1.23.1-alpine@sha256:ac67716dd016429be8d4c2c53a248d7bcdf06d34127d3dc451bda6aa5a87bc06 AS GO_BUILD
1616

1717
RUN mkdir /src
1818
WORKDIR /src
@@ -24,7 +24,7 @@ RUN go mod download
2424
COPY ./ /src/
2525
RUN go build -o download-cves ./cmd/download-cves/
2626

27-
FROM gcr.io/google.com/cloudsdktool/google-cloud-cli:alpine@sha256:d5da0344b23d03a6f2728657732c7a60300a91acaad9b8076c6fd30b1dfe1ff4
27+
FROM gcr.io/google.com/cloudsdktool/google-cloud-cli:alpine@sha256:e5932e1c9e2bd5a47dc07e1a2de4882d25b763b7cda15f11689752c0ed102620
2828
RUN apk --no-cache add jq
2929

3030
WORKDIR /usr/local/bin

vulnfeeds/cmd/nvd-cve-osv/Dockerfile

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -12,7 +12,7 @@
1212
# See the License for the specific language governing permissions and
1313
# limitations under the License.
1414

15-
FROM golang:1.22.5-alpine@sha256:8c9183f715b0b4eca05b8b3dbf59766aaedb41ec07477b132ee2891ac0110a07 AS GO_BUILD
15+
FROM golang:1.23.1-alpine@sha256:ac67716dd016429be8d4c2c53a248d7bcdf06d34127d3dc451bda6aa5a87bc06 AS GO_BUILD
1616

1717
WORKDIR /go/src
1818

@@ -22,7 +22,7 @@ RUN go mod download && go mod verify
2222
COPY . .
2323
RUN CGO_ENABLED=0 go build -v -o /usr/local/bin ./cmd/nvd-cve-osv ./cmd/download-cves
2424

25-
FROM gcr.io/google.com/cloudsdktool/google-cloud-cli:alpine@sha256:d5da0344b23d03a6f2728657732c7a60300a91acaad9b8076c6fd30b1dfe1ff4 AS runtime
25+
FROM gcr.io/google.com/cloudsdktool/google-cloud-cli:alpine@sha256:e5932e1c9e2bd5a47dc07e1a2de4882d25b763b7cda15f11689752c0ed102620 AS runtime
2626
RUN apk --no-cache add jq
2727

2828
COPY --from=GO_BUILD /usr/local/bin/ ./usr/local/bin/

vulnfeeds/go.mod

Lines changed: 34 additions & 35 deletions
Original file line numberDiff line numberDiff line change
@@ -3,26 +3,26 @@ module github.com/google/osv/vulnfeeds
33
go 1.22.5
44

55
require (
6-
cloud.google.com/go/logging v1.10.0
7-
cloud.google.com/go/secretmanager v1.13.1
6+
cloud.google.com/go/logging v1.11.0
7+
cloud.google.com/go/secretmanager v1.14.0
88
github.com/aquasecurity/go-pep440-version v0.0.0-20210121094942-22b2f8951d46
99
github.com/atombender/go-jsonschema v0.16.0
1010
github.com/go-git/go-git/v5 v5.12.0
1111
github.com/google/go-cmp v0.6.0
12-
github.com/google/osv-scanner v1.7.4
12+
github.com/google/osv-scanner v1.8.4
1313
github.com/knqyf263/go-cpe v0.0.0-20230627041855-cb0794d06872
14-
github.com/sethvargo/go-retry v0.2.4
15-
golang.org/x/exp v0.0.0-20240604190554-fc45aab8b7f8
14+
github.com/sethvargo/go-retry v0.3.0
15+
golang.org/x/exp v0.0.0-20240904232852-e7e105dedf7e
1616
gopkg.in/yaml.v2 v2.4.0
1717
)
1818

1919
require (
20-
cloud.google.com/go v0.113.0 // indirect
21-
cloud.google.com/go/auth v0.4.1 // indirect
22-
cloud.google.com/go/auth/oauth2adapt v0.2.2 // indirect
23-
cloud.google.com/go/compute/metadata v0.3.0 // indirect
24-
cloud.google.com/go/iam v1.1.8 // indirect
25-
cloud.google.com/go/longrunning v0.5.7 // indirect
20+
cloud.google.com/go v0.115.1 // indirect
21+
cloud.google.com/go/auth v0.9.0 // indirect
22+
cloud.google.com/go/auth/oauth2adapt v0.2.4 // indirect
23+
cloud.google.com/go/compute/metadata v0.5.0 // indirect
24+
cloud.google.com/go/iam v1.1.13 // indirect
25+
cloud.google.com/go/longrunning v0.5.11 // indirect
2626
dario.cat/mergo v1.0.0 // indirect
2727
github.com/Microsoft/go-winio v0.6.1 // indirect
2828
github.com/ProtonMail/go-crypto v1.0.0 // indirect
@@ -33,13 +33,12 @@ require (
3333
github.com/felixge/httpsnoop v1.0.4 // indirect
3434
github.com/go-git/gcfg v1.5.1-0.20230307220236-3a3c6141e376 // indirect
3535
github.com/go-git/go-billy/v5 v5.5.0 // indirect
36-
github.com/go-logr/logr v1.4.1 // indirect
36+
github.com/go-logr/logr v1.4.2 // indirect
3737
github.com/go-logr/stdr v1.2.2 // indirect
3838
github.com/golang/groupcache v0.0.0-20210331224755-41bb18bfe9da // indirect
39-
github.com/golang/protobuf v1.5.4 // indirect
40-
github.com/google/s2a-go v0.1.7 // indirect
39+
github.com/google/s2a-go v0.1.8 // indirect
4140
github.com/googleapis/enterprise-certificate-proxy v0.3.2 // indirect
42-
github.com/googleapis/gax-go/v2 v2.12.4 // indirect
41+
github.com/googleapis/gax-go/v2 v2.13.0 // indirect
4342
github.com/jbenet/go-context v0.0.0-20150711004518-d14ea06fba99 // indirect
4443
github.com/kevinburke/ssh_config v1.2.0 // indirect
4544
github.com/package-url/packageurl-go v0.1.3 // indirect
@@ -49,26 +48,26 @@ require (
4948
github.com/skeema/knownhosts v1.2.2 // indirect
5049
github.com/xanzy/ssh-agent v0.3.3 // indirect
5150
go.opencensus.io v0.24.0 // indirect
52-
go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc v0.49.0 // indirect
53-
go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.49.0 // indirect
54-
go.opentelemetry.io/otel v1.24.0 // indirect
55-
go.opentelemetry.io/otel/metric v1.24.0 // indirect
56-
go.opentelemetry.io/otel/trace v1.24.0 // indirect
57-
golang.org/x/crypto v0.24.0 // indirect
58-
golang.org/x/mod v0.18.0 // indirect
59-
golang.org/x/net v0.26.0 // indirect
60-
golang.org/x/oauth2 v0.20.0 // indirect
61-
golang.org/x/sync v0.7.0 // indirect
62-
golang.org/x/sys v0.21.0 // indirect
63-
golang.org/x/text v0.16.0 // indirect
64-
golang.org/x/time v0.5.0 // indirect
65-
golang.org/x/tools v0.22.0 // indirect
51+
go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc v0.52.0 // indirect
52+
go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.53.0 // indirect
53+
go.opentelemetry.io/otel v1.28.0 // indirect
54+
go.opentelemetry.io/otel/metric v1.28.0 // indirect
55+
go.opentelemetry.io/otel/trace v1.28.0 // indirect
56+
golang.org/x/crypto v0.26.0 // indirect
57+
golang.org/x/mod v0.20.0 // indirect
58+
golang.org/x/net v0.28.0 // indirect
59+
golang.org/x/oauth2 v0.22.0 // indirect
60+
golang.org/x/sync v0.8.0 // indirect
61+
golang.org/x/sys v0.24.0 // indirect
62+
golang.org/x/text v0.17.0 // indirect
63+
golang.org/x/time v0.6.0 // indirect
64+
golang.org/x/tools v0.24.0 // indirect
6665
golang.org/x/xerrors v0.0.0-20231012003039-104605ab7028 // indirect
67-
google.golang.org/api v0.180.0 // indirect
68-
google.golang.org/genproto v0.0.0-20240401170217-c3f982113cda // indirect
69-
google.golang.org/genproto/googleapis/api v0.0.0-20240513163218-0867130af1f8 // indirect
70-
google.golang.org/genproto/googleapis/rpc v0.0.0-20240513163218-0867130af1f8 // indirect
71-
google.golang.org/grpc v1.64.1 // indirect
72-
google.golang.org/protobuf v1.34.1 // indirect
66+
google.golang.org/api v0.193.0 // indirect
67+
google.golang.org/genproto v0.0.0-20240814211410-ddb44dafa142 // indirect
68+
google.golang.org/genproto/googleapis/api v0.0.0-20240814211410-ddb44dafa142 // indirect
69+
google.golang.org/genproto/googleapis/rpc v0.0.0-20240814211410-ddb44dafa142 // indirect
70+
google.golang.org/grpc v1.65.0 // indirect
71+
google.golang.org/protobuf v1.34.2 // indirect
7372
gopkg.in/warnings.v0 v0.1.2 // indirect
7473
)

0 commit comments

Comments
 (0)