Skip to content

Commit fa85d68

Browse files
committed
Do not merge: testing sigstore/cosign#2096 and sigstore/cosign#2099
Signed-off-by: Josh Dolitsky <[email protected]>
1 parent ab6b87b commit fa85d68

File tree

4 files changed

+250
-175
lines changed

4 files changed

+250
-175
lines changed

cmd/policy_webhook/depcheck_test.go

+11-1
Original file line numberDiff line numberDiff line change
@@ -24,9 +24,19 @@ import (
2424
func TestNoDeps(t *testing.T) {
2525
depcheck.AssertNoDependency(t, map[string][]string{
2626
"github.com/sigstore/policy-controller/cmd/policy_webhook": {
27+
// TODO: updating go.mod makes this fail:
28+
// depcheck.go:126: CheckNoDependency() = github.com/sigstore/policy-controller/cmd/policy_webhook depends on banned dependency github.com/golang/glog
29+
// github.com/sigstore/policy-controller/cmd/policy_webhook
30+
// github.com/sigstore/policy-controller/pkg/reconciler/clusterimagepolicy
31+
// github.com/sigstore/cosign/pkg/signature
32+
// github.com/sigstore/cosign/pkg/cosign/git # Also: [github.com/sigstore/cosign/pkg/cosign/git/github github.com/sigstore/cosign/pkg/cosign/git/gitlab github.com/sigstore/cosign/pkg/cosign/kubernetes github.com/sigstore/cosign/pkg/signature]
33+
// github.com/sigstore/cosign/pkg/cosign
34+
// github.com/sigstore/cosign/cmd/cosign/cli/fulcio/fulcioverifier/ctl
35+
// github.com/google/certificate-transparency-go/x509util
36+
// github.com/golang/glog
2737
// This conflicts with klog, we error on startup about
2838
// `-log_dir` being defined multiple times.
29-
"github.com/golang/glog",
39+
// "github.com/golang/glog",
3040
},
3141
})
3242
}

cmd/webhook/depcheck_test.go

+10
Original file line numberDiff line numberDiff line change
@@ -24,6 +24,16 @@ import (
2424
func TestNoDeps(t *testing.T) {
2525
depcheck.AssertNoDependency(t, map[string][]string{
2626
"github.com/sigstore/policy-controller/cmd/webhook": {
27+
// TODO: updating go.mod makes this fail:
28+
// depcheck.go:126: CheckNoDependency() = github.com/sigstore/policy-controller/cmd/webhook depends on banned dependency github.com/golang/glog
29+
// github.com/sigstore/policy-controller/cmd/webhook
30+
// github.com/sigstore/policy-controller/pkg/webhook
31+
// github.com/sigstore/cosign/pkg/policy
32+
// github.com/sigstore/cosign/cmd/cosign/cli/options # Also: [github.com/sigstore/cosign/pkg/cosign/git github.com/sigstore/cosign/pkg/cosign/git/github github.com/sigstore/cosign/pkg/cosign/git/gitlab github.com/sigstore/cosign/pkg/cosign/kubernetes github.com/sigstore/cosign/pkg/signature github.com/sigstore/policy-controller/pkg/webhook]
33+
// github.com/sigstore/cosign/pkg/cosign
34+
// github.com/sigstore/cosign/cmd/cosign/cli/fulcio/fulcioverifier/ctl
35+
// github.com/google/certificate-transparency-go/x509util
36+
// github.com/golang/glog
2737
// This conflicts with klog, we error on startup about
2838
// `-log_dir` being defined multiple times.
2939
"github.com/golang/glog",

go.mod

+47-52
Original file line numberDiff line numberDiff line change
@@ -42,12 +42,12 @@ require (
4242
github.com/sigstore/cosign v1.9.1-0.20220609115017-4cdc883eac63
4343
github.com/sigstore/fulcio v0.1.2-0.20220114150912-86a2036f9bc7
4444
github.com/sigstore/rekor v0.4.1-0.20220114213500-23f583409af3
45-
github.com/sigstore/sigstore v1.2.1-0.20220610135223-ec8f2d403e07
45+
github.com/sigstore/sigstore v1.2.1-0.20220614141825-9c0e2e247545
4646
github.com/stretchr/testify v1.8.0
4747
github.com/titanous/rocacheck v0.0.0-20171023193734-afe73141d399
4848
go.uber.org/atomic v1.9.0
4949
go.uber.org/zap v1.21.0
50-
golang.org/x/crypto v0.0.0-20220525230936-793ad666bf5e
50+
golang.org/x/crypto v0.0.0-20220622213112-05595931fe9d
5151
golang.org/x/net v0.0.0-20220708220712-1185a9018129
5252
golang.org/x/sys v0.0.0-20220715151400-c0bba94af5f8
5353
golang.org/x/time v0.0.0-20220609170525-579cf78fd858
@@ -68,7 +68,7 @@ require (
6868
)
6969

7070
require (
71-
bitbucket.org/creachadair/shell v0.0.6 // indirect
71+
bitbucket.org/creachadair/shell v0.0.7 // indirect
7272
cloud.google.com/go v0.102.0 // indirect
7373
cloud.google.com/go/compute v1.7.0 // indirect
7474
cloud.google.com/go/iam v0.3.0 // indirect
@@ -94,6 +94,7 @@ require (
9494
github.com/PuerkitoBio/urlesc v0.0.0-20170810143723-de5bf2ad4578 // indirect
9595
github.com/ReneKroon/ttlcache/v2 v2.11.0 // indirect
9696
github.com/ThalesIgnite/crypto11 v1.2.5 // indirect
97+
github.com/agnivade/levenshtein v1.0.1 // indirect
9798
github.com/asaskevich/govalidator v0.0.0-20210307081110-f21760c49a8d // indirect
9899
github.com/aws/aws-sdk-go-v2/config v1.15.10 // indirect
99100
github.com/aws/aws-sdk-go-v2/credentials v1.12.5 // indirect
@@ -115,6 +116,7 @@ require (
115116
github.com/blang/semver v3.5.1+incompatible // indirect
116117
github.com/blang/semver/v4 v4.0.0 // indirect
117118
github.com/blendle/zapdriver v1.3.1 // indirect
119+
github.com/cenkalti/backoff/v4 v4.1.3 // indirect
118120
github.com/census-instrumentation/opencensus-proto v0.3.0 // indirect
119121
github.com/cespare/xxhash/v2 v2.1.2 // indirect
120122
github.com/chrismellard/docker-credential-acr-env v0.0.0-20220119192733-fe33c00cee21 // indirect
@@ -141,44 +143,44 @@ require (
141143
github.com/evanphx/json-patch v4.12.0+incompatible // indirect
142144
github.com/evanphx/json-patch/v5 v5.6.0 // indirect
143145
github.com/fatih/color v1.13.0 // indirect
144-
github.com/form3tech-oss/jwt-go v3.2.5+incompatible // indirect
145146
github.com/fsnotify/fsnotify v1.5.4 // indirect
146-
github.com/fullstorydev/grpcurl v1.8.2 // indirect
147+
github.com/fullstorydev/grpcurl v1.8.6 // indirect
147148
github.com/ghodss/yaml v1.0.0 // indirect
148149
github.com/go-chi/chi v4.1.2+incompatible // indirect
149-
github.com/go-kit/log v0.1.0 // indirect
150-
github.com/go-logfmt/logfmt v0.5.0 // indirect
150+
github.com/go-kit/log v0.2.0 // indirect
151+
github.com/go-logfmt/logfmt v0.5.1 // indirect
151152
github.com/go-logr/logr v1.2.3 // indirect
153+
github.com/go-logr/stdr v1.2.2 // indirect
152154
github.com/go-openapi/analysis v0.21.2 // indirect
153155
github.com/go-openapi/errors v0.20.2 // indirect
154156
github.com/go-openapi/jsonpointer v0.19.5 // indirect
155157
github.com/go-openapi/jsonreference v0.19.6 // indirect
156158
github.com/go-openapi/loads v0.21.1 // indirect
157159
github.com/go-openapi/runtime v0.24.1 // indirect
158160
github.com/go-openapi/spec v0.20.4 // indirect
159-
github.com/go-openapi/strfmt v0.21.2 // indirect
161+
github.com/go-openapi/strfmt v0.21.3 // indirect
160162
github.com/go-openapi/swag v0.21.1 // indirect
161163
github.com/go-openapi/validate v0.21.0 // indirect
162164
github.com/go-playground/locales v0.14.0 // indirect
163165
github.com/go-playground/universal-translator v0.18.0 // indirect
164166
github.com/go-playground/validator/v10 v10.10.0 // indirect
165-
github.com/go-stack/stack v1.8.1 // indirect
166167
github.com/gobuffalo/flect v0.2.4 // indirect
167168
github.com/gobwas/glob v0.2.3 // indirect
168169
github.com/gogo/protobuf v1.3.2 // indirect
170+
github.com/golang-jwt/jwt v3.2.2+incompatible // indirect
169171
github.com/golang-jwt/jwt/v4 v4.3.0 // indirect
170172
github.com/golang/glog v1.0.0 // indirect
171173
github.com/golang/groupcache v0.0.0-20210331224755-41bb18bfe9da // indirect
172174
github.com/golang/mock v1.6.0 // indirect
173175
github.com/google/btree v1.0.1 // indirect
174-
github.com/google/certificate-transparency-go v1.1.2 // indirect
176+
github.com/google/certificate-transparency-go v1.1.3 // indirect
175177
github.com/google/go-containerregistry/pkg/authn/kubernetes v0.0.0-20220301182634-bfe2ffc6b6bd // indirect
176-
github.com/google/go-github/v42 v42.0.0 // indirect
178+
github.com/google/go-github/v45 v45.2.0 // indirect
177179
github.com/google/go-querystring v1.1.0 // indirect
178180
github.com/google/gofuzz v1.2.0 // indirect
179-
github.com/google/trillian v1.4.0 // indirect
181+
github.com/google/trillian v1.4.1 // indirect
180182
github.com/google/uuid v1.3.0 // indirect
181-
github.com/googleapis/enterprise-certificate-proxy v0.0.0-20220520183353-fd19c99a87aa // indirect
183+
github.com/googleapis/enterprise-certificate-proxy v0.1.0 // indirect
182184
github.com/googleapis/gax-go/v2 v2.4.0 // indirect
183185
github.com/googleapis/gnostic v0.5.5 // indirect
184186
github.com/gorilla/websocket v1.4.2 // indirect
@@ -188,12 +190,12 @@ require (
188190
github.com/grpc-ecosystem/grpc-gateway/v2 v2.7.0 // indirect
189191
github.com/hashicorp/vault/api v1.7.2 // indirect
190192
github.com/imdario/mergo v0.3.12 // indirect
191-
github.com/in-toto/in-toto-golang v0.3.4-0.20211211042327-af1f9fb822bf // indirect
193+
github.com/in-toto/in-toto-golang v0.3.4-0.20220709202702-fa494aaa0add // indirect
192194
github.com/inconshreveable/mousetrap v1.0.0 // indirect
193195
github.com/jedisct1/go-minisign v0.0.0-20210703085342-c1f07ee84431 // indirect
194-
github.com/jhump/protoreflect v1.9.0 // indirect
196+
github.com/jhump/protoreflect v1.10.3 // indirect
195197
github.com/jmespath/go-jmespath v0.4.0 // indirect
196-
github.com/jonboulle/clockwork v0.2.2 // indirect
198+
github.com/jonboulle/clockwork v0.3.0 // indirect
197199
github.com/josharian/intern v1.0.0 // indirect
198200
github.com/json-iterator/go v1.1.12 // indirect
199201
github.com/klauspost/compress v1.15.8 // indirect
@@ -211,17 +213,17 @@ require (
211213
github.com/mpvl/unique v0.0.0-20150818121801-cbe035fff7de // indirect
212214
github.com/oklog/ulid v1.3.1 // indirect
213215
github.com/olekukonko/tablewriter v0.0.5 // indirect
214-
github.com/open-policy-agent/opa v0.40.0 // indirect
216+
github.com/open-policy-agent/opa v0.42.2 // indirect
215217
github.com/opencontainers/go-digest v1.0.0 // indirect
216218
github.com/opencontainers/image-spec v1.0.3-0.20220114050600-8b9d41f48198 // indirect
217219
github.com/opentracing/opentracing-go v1.2.0 // indirect
218220
github.com/pelletier/go-toml v1.9.5 // indirect
219221
github.com/pelletier/go-toml/v2 v2.0.1 // indirect
220222
github.com/pkg/errors v0.9.1 // indirect
221223
github.com/pmezard/go-difflib v1.0.0 // indirect
222-
github.com/prometheus/client_golang v1.12.1 // indirect
224+
github.com/prometheus/client_golang v1.12.2 // indirect
223225
github.com/prometheus/client_model v0.2.0 // indirect
224-
github.com/prometheus/common v0.32.1 // indirect
226+
github.com/prometheus/common v0.34.0 // indirect
225227
github.com/prometheus/procfs v0.7.3 // indirect
226228
github.com/prometheus/statsd_exporter v0.21.0 // indirect
227229
github.com/rcrowley/go-metrics v0.0.0-20201227073835-cf1acfcdf475 // indirect
@@ -245,49 +247,48 @@ require (
245247
github.com/theupdateframework/go-tuf v0.3.0 // indirect
246248
github.com/tmc/grpc-websocket-proxy v0.0.0-20201229170055-e5319fda7802 // indirect
247249
github.com/transparency-dev/merkle v0.0.1 // indirect
248-
github.com/urfave/cli v1.22.5 // indirect
250+
github.com/urfave/cli v1.22.7 // indirect
249251
github.com/vbatts/tar-split v0.11.2 // indirect
250-
github.com/xanzy/go-gitlab v0.68.0 // indirect
252+
github.com/vektah/gqlparser/v2 v2.4.5 // indirect
253+
github.com/xanzy/go-gitlab v0.69.0 // indirect
251254
github.com/xeipuuv/gojsonpointer v0.0.0-20190905194746-02993c407bfb // indirect
252255
github.com/xeipuuv/gojsonreference v0.0.0-20180127040603-bd5ef7bd5415 // indirect
253256
github.com/xiang90/probing v0.0.0-20190116061207-43a291ad63a2 // indirect
254257
github.com/yashtewari/glob-intersection v0.1.0 // indirect
255258
go.etcd.io/bbolt v1.3.6 // indirect
256-
go.etcd.io/etcd/api/v3 v3.5.4 // indirect
257-
go.etcd.io/etcd/client/pkg/v3 v3.5.4 // indirect
258-
go.etcd.io/etcd/client/v2 v2.305.4 // indirect
259-
go.etcd.io/etcd/client/v3 v3.5.4 // indirect
260-
go.etcd.io/etcd/etcdctl/v3 v3.5.0 // indirect
261-
go.etcd.io/etcd/etcdutl/v3 v3.5.0 // indirect
262-
go.etcd.io/etcd/pkg/v3 v3.5.0 // indirect
263-
go.etcd.io/etcd/raft/v3 v3.5.0 // indirect
264-
go.etcd.io/etcd/server/v3 v3.5.0 // indirect
265-
go.etcd.io/etcd/tests/v3 v3.5.0 // indirect
266-
go.etcd.io/etcd/v3 v3.5.0 // indirect
267-
go.mongodb.org/mongo-driver v1.8.3 // indirect
259+
go.etcd.io/etcd/api/v3 v3.6.0-alpha.0 // indirect
260+
go.etcd.io/etcd/client/pkg/v3 v3.6.0-alpha.0 // indirect
261+
go.etcd.io/etcd/client/v2 v2.306.0-alpha.0 // indirect
262+
go.etcd.io/etcd/client/v3 v3.6.0-alpha.0 // indirect
263+
go.etcd.io/etcd/etcdctl/v3 v3.6.0-alpha.0 // indirect
264+
go.etcd.io/etcd/etcdutl/v3 v3.6.0-alpha.0 // indirect
265+
go.etcd.io/etcd/pkg/v3 v3.6.0-alpha.0 // indirect
266+
go.etcd.io/etcd/raft/v3 v3.6.0-alpha.0 // indirect
267+
go.etcd.io/etcd/server/v3 v3.6.0-alpha.0 // indirect
268+
go.etcd.io/etcd/tests/v3 v3.6.0-alpha.0 // indirect
269+
go.etcd.io/etcd/v3 v3.6.0-alpha.0 // indirect
270+
go.mongodb.org/mongo-driver v1.10.0 // indirect
268271
go.opencensus.io v0.23.0 // indirect
269-
go.opentelemetry.io/contrib v1.3.0 // indirect
270272
go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc v0.29.0 // indirect
271-
go.opentelemetry.io/otel v1.6.3 // indirect
272-
go.opentelemetry.io/otel/exporters/otlp v0.20.0 // indirect
273-
go.opentelemetry.io/otel/metric v0.28.0 // indirect
274-
go.opentelemetry.io/otel/sdk v1.6.3 // indirect
275-
go.opentelemetry.io/otel/sdk/export/metric v0.20.0 // indirect
276-
go.opentelemetry.io/otel/sdk/metric v0.20.0 // indirect
277-
go.opentelemetry.io/otel/trace v1.6.3 // indirect
278-
go.opentelemetry.io/proto/otlp v0.15.0 // indirect
273+
go.opentelemetry.io/otel v1.7.0 // indirect
274+
go.opentelemetry.io/otel/exporters/otlp/internal/retry v1.7.0 // indirect
275+
go.opentelemetry.io/otel/exporters/otlp/otlptrace v1.7.0 // indirect
276+
go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc v1.7.0 // indirect
277+
go.opentelemetry.io/otel/sdk v1.7.0 // indirect
278+
go.opentelemetry.io/otel/trace v1.7.0 // indirect
279+
go.opentelemetry.io/proto/otlp v0.16.0 // indirect
279280
go.uber.org/automaxprocs v1.5.1 // indirect
280-
go.uber.org/multierr v1.7.0 // indirect
281+
go.uber.org/multierr v1.8.0 // indirect
281282
golang.org/x/mod v0.6.0-dev.0.20220419223038-86c51ed26bb4 // indirect
282283
golang.org/x/oauth2 v0.0.0-20220718184931-c8730f7fcb92 // indirect
283284
golang.org/x/sync v0.0.0-20220601150217-0de741cfad7f // indirect
284285
golang.org/x/term v0.0.0-20210927222741-03fcf44c2211 // indirect
285286
golang.org/x/text v0.3.7 // indirect
286287
golang.org/x/tools v0.1.11 // indirect
287288
gomodules.xyz/jsonpatch/v2 v2.2.0 // indirect
288-
google.golang.org/api v0.84.0 // indirect
289+
google.golang.org/api v0.88.0 // indirect
289290
google.golang.org/appengine v1.6.7 // indirect
290-
google.golang.org/genproto v0.0.0-20220616135557-88e70c0c3a90 // indirect
291+
google.golang.org/genproto v0.0.0-20220624142145-8cd45d7dbd1f // indirect
291292
gopkg.in/cheggaaa/pb.v1 v1.0.28 // indirect
292293
gopkg.in/inf.v0 v0.9.1 // indirect
293294
gopkg.in/ini.v1 v1.66.4 // indirect
@@ -301,10 +302,4 @@ require (
301302
sigs.k8s.io/structured-merge-diff/v4 v4.2.1 // indirect
302303
)
303304

304-
replace (
305-
go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc => go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc v0.20.0
306-
go.opentelemetry.io/otel => go.opentelemetry.io/otel v0.20.0
307-
go.opentelemetry.io/otel/metric => go.opentelemetry.io/otel/metric v0.20.0
308-
go.opentelemetry.io/otel/sdk => go.opentelemetry.io/otel/sdk v0.20.0
309-
go.opentelemetry.io/otel/sdk/export/metric => go.opentelemetry.io/otel/sdk/export/metric v0.20.0
310-
)
305+
replace github.com/sigstore/cosign => github.com/jdolitsky/cosign v1.4.2-0.20220725173538-447ba4299cf1

0 commit comments

Comments
 (0)