Skip to content

Commit f1193af

Browse files
authored
Merge pull request #598 from kubernetes-sigs/dependabot/go_modules/all-eea2af3d85
Bump the all group across 1 directory with 2 updates
2 parents d9a38a0 + c693540 commit f1193af

3 files changed

Lines changed: 108 additions & 102 deletions

File tree

.github/workflows/release.yml

Lines changed: 19 additions & 14 deletions
Original file line numberDiff line numberDiff line change
@@ -60,8 +60,8 @@ jobs:
6060
runs-on: ubuntu-latest
6161

6262
permissions:
63-
id-token: write
64-
contents: write
63+
id-token: write # To sign the attestation
64+
contents: write # To push to the release
6565

6666
needs:
6767
- release
@@ -76,19 +76,24 @@ jobs:
7676
id: tag
7777
run: echo "tag_name=${GITHUB_REF#refs/*/}" >> "$GITHUB_OUTPUT"
7878

79-
- name: Install tejolote
80-
uses: kubernetes-sigs/release-actions/setup-tejolote@8af7b2a5596dff526de9db59b2c4b8457e9f52a1 # v0.4.0
79+
- uses: actions/setup-go@4b73464bb391d4059bd26b0524d20df3927bd417 # v6.3.0
80+
with:
81+
go-version-file: go.mod
82+
cache: false
8183

82-
- run: |
83-
tejolote attest --artifacts github://kubernetes-sigs/tejolote/${{ steps.tag.outputs.tag_name }} github://kubernetes-sigs/tejolote/"${GITHUB_RUN_ID}" --output tejolote.intoto.json --sign
84+
- name: Setup bnd
85+
uses: carabiner-dev/actions/install/bnd@440c76def32d40be101b68d1f6a6b284b79aa74c # v1.1.2
86+
87+
- name: Build tejolote from source
88+
run: go build -o "${{ runner.temp }}/tejolote" ./cmd/tejolote/
89+
90+
- name: Generate and sign provenance
8491
env:
8592
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
93+
run: |
94+
"${{ runner.temp }}/tejolote" attest \
95+
--artifacts github://kubernetes-sigs/tejolote/${{ steps.tag.outputs.tag_name }} \
96+
github://kubernetes-sigs/tejolote/"${GITHUB_RUN_ID}" --output provenance.json
8697
87-
- name: Release
88-
uses: softprops/action-gh-release@153bb8e04406b158c6c84fc1615b65b24149a1fe # v2.6.1
89-
with:
90-
files: tejolote.intoto.json
91-
tag_name: "${{ steps.tag.outputs.tag_name }}"
92-
token: ${{ secrets.GITHUB_TOKEN }}
93-
env:
94-
GITHUB_REPOSITORY: kubernetes-sigs/tejolote
98+
bnd statement provenance.json -o tejolote-${{ steps.tag.outputs.tag_name }}.provenance.json \
99+
gh release upload ${{ steps.tag.outputs.tag_name }} tejolote-${{ steps.tag.outputs.tag_name }}.provenance.json

go.mod

Lines changed: 27 additions & 26 deletions
Original file line numberDiff line numberDiff line change
@@ -3,7 +3,7 @@ module sigs.k8s.io/tejolote
33
go 1.26.1
44

55
require (
6-
chainguard.dev/apko v1.1.15
6+
chainguard.dev/apko v1.1.16
77
cloud.google.com/go/pubsub/v2 v2.5.0
88
cloud.google.com/go/storage v1.61.3
99
github.com/go-git/go-git/v5 v5.17.0
@@ -18,7 +18,7 @@ require (
1818
github.com/stretchr/testify v1.11.1
1919
github.com/uwu-tools/magex v0.10.1
2020
golang.org/x/sync v0.20.0
21-
google.golang.org/api v0.272.0
21+
google.golang.org/api v0.273.0
2222
google.golang.org/protobuf v1.36.11
2323
sigs.k8s.io/release-sdk v0.12.6
2424
sigs.k8s.io/release-utils v0.12.3
@@ -67,22 +67,23 @@ require (
6767
github.com/anchore/go-struct-converter v0.0.0-20230627203149-c72ef8859ca9 // indirect
6868
github.com/asaskevich/govalidator v0.0.0-20230301143203-a9d515a09cc2 // indirect
6969
github.com/avast/retry-go/v4 v4.7.0 // indirect
70-
github.com/aws/aws-sdk-go-v2 v1.41.1 // indirect
71-
github.com/aws/aws-sdk-go-v2/config v1.32.7 // indirect
72-
github.com/aws/aws-sdk-go-v2/credentials v1.19.7 // indirect
73-
github.com/aws/aws-sdk-go-v2/feature/ec2/imds v1.18.17 // indirect
74-
github.com/aws/aws-sdk-go-v2/internal/configsources v1.4.17 // indirect
75-
github.com/aws/aws-sdk-go-v2/internal/endpoints/v2 v2.7.17 // indirect
76-
github.com/aws/aws-sdk-go-v2/internal/ini v1.8.4 // indirect
70+
github.com/aws/aws-sdk-go-v2 v1.41.4 // indirect
71+
github.com/aws/aws-sdk-go-v2/config v1.32.12 // indirect
72+
github.com/aws/aws-sdk-go-v2/credentials v1.19.12 // indirect
73+
github.com/aws/aws-sdk-go-v2/feature/ec2/imds v1.18.20 // indirect
74+
github.com/aws/aws-sdk-go-v2/internal/configsources v1.4.20 // indirect
75+
github.com/aws/aws-sdk-go-v2/internal/endpoints/v2 v2.7.20 // indirect
76+
github.com/aws/aws-sdk-go-v2/internal/ini v1.8.6 // indirect
7777
github.com/aws/aws-sdk-go-v2/service/ecr v1.45.1 // indirect
7878
github.com/aws/aws-sdk-go-v2/service/ecrpublic v1.33.2 // indirect
79-
github.com/aws/aws-sdk-go-v2/service/internal/accept-encoding v1.13.4 // indirect
80-
github.com/aws/aws-sdk-go-v2/service/internal/presigned-url v1.13.17 // indirect
81-
github.com/aws/aws-sdk-go-v2/service/signin v1.0.5 // indirect
82-
github.com/aws/aws-sdk-go-v2/service/sso v1.30.9 // indirect
83-
github.com/aws/aws-sdk-go-v2/service/ssooidc v1.35.13 // indirect
84-
github.com/aws/aws-sdk-go-v2/service/sts v1.41.6 // indirect
85-
github.com/aws/smithy-go v1.24.0 // indirect
79+
github.com/aws/aws-sdk-go-v2/service/internal/accept-encoding v1.13.7 // indirect
80+
github.com/aws/aws-sdk-go-v2/service/internal/presigned-url v1.13.20 // indirect
81+
github.com/aws/aws-sdk-go-v2/service/kms v1.50.3 // indirect
82+
github.com/aws/aws-sdk-go-v2/service/signin v1.0.8 // indirect
83+
github.com/aws/aws-sdk-go-v2/service/sso v1.30.13 // indirect
84+
github.com/aws/aws-sdk-go-v2/service/ssooidc v1.35.17 // indirect
85+
github.com/aws/aws-sdk-go-v2/service/sts v1.41.9 // indirect
86+
github.com/aws/smithy-go v1.24.2 // indirect
8687
github.com/awslabs/amazon-ecr-credential-helper/ecr-login v0.10.1 // indirect
8788
github.com/blang/semver v3.5.1+incompatible // indirect
8889
github.com/blang/semver/v4 v4.0.0 // indirect
@@ -148,7 +149,7 @@ require (
148149
github.com/go-openapi/swag/typeutils v0.25.5 // indirect
149150
github.com/go-openapi/swag/yamlutils v0.25.5 // indirect
150151
github.com/go-openapi/validate v0.25.2 // indirect
151-
github.com/go-piv/piv-go/v2 v2.4.0 // indirect
152+
github.com/go-piv/piv-go/v2 v2.5.0 // indirect
152153
github.com/go-viper/mapstructure/v2 v2.5.0 // indirect
153154
github.com/gogo/protobuf v1.3.2 // indirect
154155
github.com/golang-jwt/jwt/v4 v4.5.2 // indirect
@@ -163,8 +164,8 @@ require (
163164
github.com/google/s2a-go v0.1.9 // indirect
164165
github.com/google/uuid v1.6.0 // indirect
165166
github.com/googleapis/enterprise-certificate-proxy v0.3.14 // indirect
166-
github.com/googleapis/gax-go/v2 v2.18.0 // indirect
167-
github.com/grpc-ecosystem/grpc-gateway/v2 v2.27.4 // indirect
167+
github.com/googleapis/gax-go/v2 v2.19.0 // indirect
168+
github.com/grpc-ecosystem/grpc-gateway/v2 v2.28.0 // indirect
168169
github.com/hashicorp/go-cleanhttp v0.5.2 // indirect
169170
github.com/hashicorp/go-retryablehttp v0.7.8 // indirect
170171
github.com/in-toto/in-toto-golang v0.9.0 // indirect
@@ -236,16 +237,16 @@ require (
236237
go.opencensus.io v0.24.0 // indirect
237238
go.opentelemetry.io/auto/sdk v1.2.1 // indirect
238239
go.opentelemetry.io/contrib/detectors/gcp v1.39.0 // indirect
239-
go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc v0.63.0 // indirect
240-
go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.63.0 // indirect
240+
go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc v0.67.0 // indirect
241+
go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.65.0 // indirect
241242
go.opentelemetry.io/otel v1.42.0 // indirect
242243
go.opentelemetry.io/otel/metric v1.42.0 // indirect
243244
go.opentelemetry.io/otel/sdk v1.42.0 // indirect
244245
go.opentelemetry.io/otel/sdk/metric v1.42.0 // indirect
245246
go.opentelemetry.io/otel/trace v1.42.0 // indirect
246247
go.uber.org/multierr v1.11.0 // indirect
247248
go.uber.org/zap v1.27.1 // indirect
248-
go.yaml.in/yaml/v2 v2.4.3 // indirect
249+
go.yaml.in/yaml/v2 v2.4.4 // indirect
249250
go.yaml.in/yaml/v3 v3.0.4 // indirect
250251
golang.org/x/crypto v0.49.0 // indirect
251252
golang.org/x/mod v0.34.0 // indirect
@@ -255,17 +256,17 @@ require (
255256
golang.org/x/term v0.41.0 // indirect
256257
golang.org/x/text v0.35.0 // indirect
257258
golang.org/x/time v0.15.0 // indirect
258-
google.golang.org/genproto v0.0.0-20260217215200-42d3e9bedb6d // indirect
259+
google.golang.org/genproto v0.0.0-20260316180232-0b37fe3546d5 // indirect
259260
google.golang.org/genproto/googleapis/api v0.0.0-20260316180232-0b37fe3546d5 // indirect
260-
google.golang.org/genproto/googleapis/rpc v0.0.0-20260311181403-84a4fc48630c // indirect
261-
google.golang.org/grpc v1.79.2 // indirect
261+
google.golang.org/genproto/googleapis/rpc v0.0.0-20260319201613-d00831a3d3e7 // indirect
262+
google.golang.org/grpc v1.79.3 // indirect
262263
gopkg.in/evanphx/json-patch.v4 v4.13.0 // indirect
263264
gopkg.in/inf.v0 v0.9.1 // indirect
264265
gopkg.in/ini.v1 v1.67.1 // indirect
265266
gopkg.in/warnings.v0 v0.1.2 // indirect
266267
gopkg.in/yaml.v3 v3.0.1 // indirect
267268
k8s.io/api v0.34.1 // indirect
268-
k8s.io/apimachinery v0.35.2 // indirect
269+
k8s.io/apimachinery v0.35.3 // indirect
269270
k8s.io/client-go v0.34.1 // indirect
270271
k8s.io/klog/v2 v2.130.1 // indirect
271272
k8s.io/kube-openapi v0.0.0-20250910181357-589584f1c912 // indirect

0 commit comments

Comments
 (0)