This issue lists Renovate updates and detected dependencies. Read the [Dependency Dashboard](https://docs.renovatebot.com/key-concepts/dashboard/) docs to learn more. ## Repository problems Renovate tried to run on this repository, but found these problems. - WARN: Cannot access vulnerability alerts. Please ensure permissions have been granted. ## Rate-Limited These updates are currently rate-limited. Click on a checkbox below to force their creation now. - [ ] <!-- unlimit-branch=renovate/alauda-v0.65.0-patch-patch-upgrades -->chore(deps): update dependency go to v1.26.7 (alauda-v0.65.0) - [ ] <!-- unlimit-branch=renovate/alauda-v0.65.0-go-official-packages -->chore(deps): update dependency go to v1.27.0 (alauda-v0.65.0) - [ ] <!-- unlimit-branch=renovate/alauda-v0.68.2-go-official-packages -->chore(deps): update dependency go to v1.27.0 (alauda-v0.68.2) - [ ] <!-- unlimit-branch=renovate/alauda-v0.70.0-go-official-packages -->chore(deps): update dependency go to v1.27.0 (alauda-v0.70.0) - [ ] <!-- create-all-rate-limited-prs -->🔐 **Create all rate-limited PRs at once** 🔐 ## Edited/Blocked These updates have been manually edited so Renovate will no longer make changes. To discard all commits and start over, click on a checkbox. - [ ] <!-- rebase-branch=renovate/alauda-v0.65.0-go-github.com-hashicorp-go-retryablehttp-vulnerability -->fix(deps): update module github.com/hashicorp/go-retryablehttp to v0.7.7 [security] (alauda-v0.65.0) - [ ] <!-- rebase-branch=renovate/alauda-v0.65.0-go-google.golang.org-grpc-vulnerability -->chore(deps): update module google.golang.org/grpc to v1.82.1 [security] (alauda-v0.65.0) - [ ] <!-- rebase-branch=renovate/alauda-v0.65.0-go-google.golang.org-protobuf-vulnerability -->chore(deps): update module google.golang.org/protobuf to v1.33.0 [security] (alauda-v0.65.0) - [ ] <!-- rebase-branch=renovate/alauda-v0.65.0-go-github.com-docker-distribution-vulnerability -->fix(deps): update module github.com/docker/distribution to v2.8.2+incompatible [security] (alauda-v0.65.0) - [ ] <!-- rebase-branch=renovate/alauda-v0.65.0-go-golang.org-x-text-vulnerability -->fix(deps): update module golang.org/x/text to v0.39.0 [security] (alauda-v0.65.0) - [ ] <!-- rebase-branch=renovate/alauda-v0.65.0-go-github.com-open-policy-agent-opa-vulnerability -->fix(deps): update module github.com/open-policy-agent/opa to v1 [security] (alauda-v0.65.0) - [ ] <!-- rebase-branch=renovate/alauda-v0.68.2-go-google.golang.org-grpc-vulnerability -->chore(deps): update module google.golang.org/grpc to v1.82.1 [security] (alauda-v0.68.2) - [ ] <!-- rebase-branch=renovate/alauda-v0.68.2-go-google.golang.org-protobuf-vulnerability -->chore(deps): update module google.golang.org/protobuf to v1.33.0 [security] (alauda-v0.68.2) - [ ] <!-- rebase-branch=renovate/alauda-v0.68.2-go-github.com-docker-distribution-vulnerability -->fix(deps): update module github.com/docker/distribution to v2.8.2+incompatible [security] (alauda-v0.68.2) - [ ] <!-- rebase-branch=renovate/alauda-v0.68.2-go-golang.org-x-text-vulnerability -->fix(deps): update module golang.org/x/text to v0.39.0 [security] (alauda-v0.68.2) - [ ] <!-- rebase-branch=renovate/alauda-v0.68.2-go-github.com-open-policy-agent-opa-vulnerability -->fix(deps): update module github.com/open-policy-agent/opa to v1 [security] (alauda-v0.68.2) - [ ] <!-- rebase-branch=renovate/alauda-v0.70.0-go-google.golang.org-grpc-vulnerability -->chore(deps): update module google.golang.org/grpc to v1.82.1 [security] (alauda-v0.70.0) - [ ] <!-- rebase-branch=renovate/alauda-v0.70.0-go-google.golang.org-protobuf-vulnerability -->chore(deps): update module google.golang.org/protobuf to v1.33.0 [security] (alauda-v0.70.0) - [ ] <!-- rebase-branch=renovate/alauda-v0.70.0-go-github.com-docker-distribution-vulnerability -->fix(deps): update module github.com/docker/distribution to v2.8.2+incompatible [security] (alauda-v0.70.0) - [ ] <!-- rebase-branch=renovate/alauda-v0.70.0-go-golang.org-x-text-vulnerability -->fix(deps): update module golang.org/x/text to v0.39.0 [security] (alauda-v0.70.0) - [ ] <!-- rebase-branch=renovate/alauda-v0.70.0-go-github.com-open-policy-agent-opa-vulnerability -->fix(deps): update module github.com/open-policy-agent/opa to v1 [security] (alauda-v0.70.0) ## Open These updates have all been created already. Click a checkbox below to force a retry/rebase of any. - [ ] <!-- rebase-branch=renovate/alauda-v0.65.0-go-github.com-containerd-containerd-vulnerability -->[chore(deps): update module github.com/containerd/containerd to v1.7.33 [security] (alauda-v0.65.0)](../pull/149) - [ ] <!-- rebase-branch=renovate/alauda-v0.65.0-go-github.com-klauspost-compress-vulnerability -->[chore(deps): update module github.com/klauspost/compress to v1.18.7 [security] (alauda-v0.65.0)](../pull/184) - [ ] <!-- rebase-branch=renovate/alauda-v0.65.0-go-github.com-sigstore-cosign-v2-vulnerability -->[chore(deps): update module github.com/sigstore/cosign/v2 to v2.6.3 [security] (alauda-v0.65.0)](../pull/167) - [ ] <!-- rebase-branch=renovate/alauda-v0.65.0-go-oras.land-oras-go-v2-vulnerability -->[chore(deps): update module oras.land/oras-go/v2 to v2.6.2 [security] (alauda-v0.65.0)](../pull/175) - [ ] <!-- rebase-branch=renovate/alauda-v0.65.0-go-github.com-containerd-containerd-v2-vulnerability -->[fix(deps): update module github.com/containerd/containerd/v2 to v2.2.5 [security] (alauda-v0.65.0)](../pull/148) - [ ] <!-- rebase-branch=renovate/alauda-v0.65.0-go-github.com-sigstore-rekor-vulnerability -->[fix(deps): update module github.com/sigstore/rekor to v1.5.2 [security] (alauda-v0.65.0)](../pull/170) - [ ] <!-- rebase-branch=renovate/alauda-v0.65.0-go-github.com-go-chi-chi-v5-vulnerability -->[chore(deps): update module github.com/go-chi/chi/v5 to v5.3.0 [security] (alauda-v0.65.0)](../pull/185) - [ ] <!-- rebase-branch=renovate/alauda-v0.65.0-go-github.com-go-git-go-billy-v5-vulnerability -->[chore(deps): update module github.com/go-git/go-billy/v5 to v5.9.0 [security] (alauda-v0.65.0)](../pull/141) - [ ] <!-- rebase-branch=renovate/alauda-v0.65.0-go-github.com-google-cel-go-vulnerability -->[chore(deps): update module github.com/google/cel-go to v0.30.0 [security] (alauda-v0.65.0)](../pull/186) - [ ] <!-- rebase-branch=renovate/alauda-v0.65.0-go-github.com-quic-go-quic-go-vulnerability -->[chore(deps): update module github.com/quic-go/quic-go to v0.59.1 [security] (alauda-v0.65.0)](../pull/182) - [ ] <!-- rebase-branch=renovate/alauda-v0.65.0-go-github.com-sigstore-sigstore-go-vulnerability -->[chore(deps): update module github.com/sigstore/sigstore-go to v1.2.1 [security] (alauda-v0.65.0)](../pull/179) - [ ] <!-- rebase-branch=renovate/alauda-v0.65.0-go-github.com-sigstore-timestamp-authority-v2-vulnerability -->[chore(deps): update module github.com/sigstore/timestamp-authority/v2 to v2.1.0 [security] (alauda-v0.65.0)](../pull/176) - [ ] <!-- rebase-branch=renovate/alauda-v0.65.0-go-go.opentelemetry.io-otel-vulnerability -->[chore(deps): update module go.opentelemetry.io/otel to v1.44.0 [security] (alauda-v0.65.0)](../pull/187) - [ ] <!-- rebase-branch=renovate/alauda-v0.65.0-go-golang.org-x-sys-vulnerability -->[chore(deps): update module golang.org/x/sys to v0.44.0 [security] (alauda-v0.65.0)](../pull/147) - [ ] <!-- rebase-branch=renovate/alauda-v0.65.0-go-github.com-go-git-go-git-v5-vulnerability -->[fix(deps): update module github.com/go-git/go-git/v5 to v5.19.2 [security] (alauda-v0.65.0)](../pull/198) - [ ] <!-- rebase-branch=renovate/alauda-v0.65.0-go-github.com-moby-buildkit-vulnerability -->[fix(deps): update module github.com/moby/buildkit to v0.31.1 [security] (alauda-v0.65.0)](../pull/204) - [ ] <!-- rebase-branch=renovate/alauda-v0.65.0-go-golang.org-x-crypto-vulnerability -->[fix(deps): update module golang.org/x/crypto to v0.52.0 [security] (alauda-v0.65.0)](../pull/159) - [ ] <!-- rebase-branch=renovate/alauda-v0.65.0-go-golang.org-x-mod-vulnerability -->[fix(deps): update module golang.org/x/mod to v0.40.0 [security] (alauda-v0.65.0)](../pull/199) - [ ] <!-- rebase-branch=renovate/alauda-v0.65.0-go-golang.org-x-net-vulnerability -->[fix(deps): update module golang.org/x/net to v0.56.0 [security] (alauda-v0.65.0)](../pull/160) - [ ] <!-- rebase-branch=renovate/alauda-v0.68.2-go-github.com-klauspost-compress-vulnerability -->[chore(deps): update module github.com/klauspost/compress to v1.18.7 [security] (alauda-v0.68.2)](../pull/188) - [ ] <!-- rebase-branch=renovate/alauda-v0.68.2-go-github.com-sigstore-cosign-v2-vulnerability -->[chore(deps): update module github.com/sigstore/cosign/v2 to v2.6.3 [security] (alauda-v0.68.2)](../pull/168) - [ ] <!-- rebase-branch=renovate/alauda-v0.68.2-go-oras.land-oras-go-v2-vulnerability -->[chore(deps): update module oras.land/oras-go/v2 to v2.6.2 [security] (alauda-v0.68.2)](../pull/183) - [ ] <!-- rebase-branch=renovate/alauda-v0.68.2-go-github.com-go-git-go-git-v5-vulnerability -->[fix(deps): update module github.com/go-git/go-git/v5 to v5.19.2 [security] (alauda-v0.68.2)](../pull/200) - [ ] <!-- rebase-branch=renovate/alauda-v0.68.2-go-github.com-go-chi-chi-v5-vulnerability -->[chore(deps): update module github.com/go-chi/chi/v5 to v5.3.0 [security] (alauda-v0.68.2)](../pull/189) - [ ] <!-- rebase-branch=renovate/alauda-v0.68.2-go-github.com-google-cel-go-vulnerability -->[chore(deps): update module github.com/google/cel-go to v0.30.0 [security] (alauda-v0.68.2)](../pull/190) - [ ] <!-- rebase-branch=renovate/alauda-v0.68.2-go-github.com-sigstore-sigstore-go-vulnerability -->[chore(deps): update module github.com/sigstore/sigstore-go to v1.2.1 [security] (alauda-v0.68.2)](../pull/180) - [ ] <!-- rebase-branch=renovate/alauda-v0.68.2-go-go.opentelemetry.io-otel-vulnerability -->[chore(deps): update module go.opentelemetry.io/otel to v1.44.0 [security] (alauda-v0.68.2)](../pull/191) - [ ] <!-- rebase-branch=renovate/alauda-v0.68.2-go-github.com-moby-buildkit-vulnerability -->[fix(deps): update module github.com/moby/buildkit to v0.31.1 [security] (alauda-v0.68.2)](../pull/205) - [ ] <!-- rebase-branch=renovate/alauda-v0.68.2-go-golang.org-x-mod-vulnerability -->[fix(deps): update module golang.org/x/mod to v0.40.0 [security] (alauda-v0.68.2)](../pull/201) - [ ] <!-- rebase-branch=renovate/alauda-v0.68.2-go-golang.org-x-net-vulnerability -->[fix(deps): update module golang.org/x/net to v0.56.0 [security] (alauda-v0.68.2)](../pull/192) - [ ] <!-- rebase-branch=renovate/alauda-v0.68.2-patch-patch-upgrades -->[chore(deps): update dependency go to v1.26.7 (alauda-v0.68.2)](../pull/137) - [ ] <!-- rebase-branch=renovate/alauda-v0.70.0-go-github.com-klauspost-compress-vulnerability -->[chore(deps): update module github.com/klauspost/compress to v1.18.7 [security] (alauda-v0.70.0)](../pull/193) - [ ] <!-- rebase-branch=renovate/alauda-v0.70.0-go-github.com-sigstore-cosign-v2-vulnerability -->[chore(deps): update module github.com/sigstore/cosign/v2 to v2.6.3 [security] (alauda-v0.70.0)](../pull/169) - [ ] <!-- rebase-branch=renovate/alauda-v0.70.0-go-oras.land-oras-go-v2-vulnerability -->[chore(deps): update module oras.land/oras-go/v2 to v2.6.2 [security] (alauda-v0.70.0)](../pull/177) - [ ] <!-- rebase-branch=renovate/alauda-v0.70.0-go-github.com-go-git-go-git-v5-vulnerability -->[fix(deps): update module github.com/go-git/go-git/v5 to v5.19.2 [security] (alauda-v0.70.0)](../pull/202) - [ ] <!-- rebase-branch=renovate/alauda-v0.70.0-go-github.com-sigstore-rekor-vulnerability -->[fix(deps): update module github.com/sigstore/rekor to v1.5.2 [security] (alauda-v0.70.0)](../pull/172) - [ ] <!-- rebase-branch=renovate/alauda-v0.70.0-go-github.com-go-chi-chi-v5-vulnerability -->[chore(deps): update module github.com/go-chi/chi/v5 to v5.3.0 [security] (alauda-v0.70.0)](../pull/194) - [ ] <!-- rebase-branch=renovate/alauda-v0.70.0-go-github.com-google-cel-go-vulnerability -->[chore(deps): update module github.com/google/cel-go to v0.30.0 [security] (alauda-v0.70.0)](../pull/195) - [ ] <!-- rebase-branch=renovate/alauda-v0.70.0-go-github.com-sigstore-sigstore-go-vulnerability -->[chore(deps): update module github.com/sigstore/sigstore-go to v1.2.1 [security] (alauda-v0.70.0)](../pull/181) - [ ] <!-- rebase-branch=renovate/alauda-v0.70.0-go-github.com-sigstore-timestamp-authority-v2-vulnerability -->[chore(deps): update module github.com/sigstore/timestamp-authority/v2 to v2.1.0 [security] (alauda-v0.70.0)](../pull/178) - [ ] <!-- rebase-branch=renovate/alauda-v0.70.0-go-go.opentelemetry.io-otel-vulnerability -->[chore(deps): update module go.opentelemetry.io/otel to v1.44.0 [security] (alauda-v0.70.0)](../pull/196) - [ ] <!-- rebase-branch=renovate/alauda-v0.70.0-go-github.com-moby-buildkit-vulnerability -->[fix(deps): update module github.com/moby/buildkit to v0.31.1 [security] (alauda-v0.70.0)](../pull/206) - [ ] <!-- rebase-branch=renovate/alauda-v0.70.0-go-golang.org-x-mod-vulnerability -->[fix(deps): update module golang.org/x/mod to v0.40.0 [security] (alauda-v0.70.0)](../pull/203) - [ ] <!-- rebase-branch=renovate/alauda-v0.70.0-go-golang.org-x-net-vulnerability -->[fix(deps): update module golang.org/x/net to v0.56.0 [security] (alauda-v0.70.0)](../pull/197) - [ ] <!-- rebase-branch=renovate/alauda-v0.70.0-patch-patch-upgrades -->[chore(deps): update dependency go to v1.22.12 (alauda-v0.70.0)](../pull/146) - [ ] <!-- rebase-all-open-prs -->**Click on this checkbox to rebase all open PRs at once** ## Vulnerabilities `321`/`351` CVEs have Renovate fixes. <details><summary>gomod</summary> <blockquote> <details><summary>go.mod</summary> <blockquote> <details><summary>github.com/containerd/containerd/v2</summary> <blockquote> - [GO-2026-5622](https://osv.dev/vulnerability/GO-2026-5622) (fixed in >= 2.2.5) - [GHSA-xhf5-7wjv-pqxp](https://osv.dev/vulnerability/GHSA-xhf5-7wjv-pqxp) (fixed in >= 2.2.5) - [GO-2026-5338](https://osv.dev/vulnerability/GO-2026-5338) (fixed in >= 2.2.5) - [GO-2026-5064](https://osv.dev/vulnerability/GO-2026-5064) (fixed in >= 2.2.5) - [GHSA-33vj-92qq-66hc](https://osv.dev/vulnerability/GHSA-33vj-92qq-66hc) (fixed in >= 2.2.5) - [GHSA-rgh6-rfwx-v388](https://osv.dev/vulnerability/GHSA-rgh6-rfwx-v388) (fixed in >= 2.2.5) - [GHSA-jpcc-p29g-p8mq](https://osv.dev/vulnerability/GHSA-jpcc-p29g-p8mq) (fixed in >= 2.2.5) - [GO-2026-5378](https://osv.dev/vulnerability/GO-2026-5378) (fixed in >= 2.2.4) - [GHSA-cvxm-645q-p574](https://osv.dev/vulnerability/GHSA-cvxm-645q-p574) (fixed in >= 2.2.5) - [GO-2026-5475](https://osv.dev/vulnerability/GO-2026-5475) (fixed in >= 2.2.5) - [GO-2026-5758](https://osv.dev/vulnerability/GO-2026-5758) (fixed in >= 2.2.5) - [GHSA-fqw6-gf59-qr4w](https://osv.dev/vulnerability/GHSA-fqw6-gf59-qr4w) (fixed in >= 2.2.4) </blockquote> </details> <details><summary>github.com/go-git/go-git/v5</summary> <blockquote> - [GHSA-w5pp-99ch-qj29](https://osv.dev/vulnerability/GHSA-w5pp-99ch-qj29) (fixed in >= 5.19.1) - [GHSA-crhj-59gh-8x96](https://osv.dev/vulnerability/GHSA-crhj-59gh-8x96) (fixed in >= 5.19.1) - [GO-2026-6214](https://osv.dev/vulnerability/GO-2026-6214) (fixed in >= 5.19.2) - [GO-2026-5693](https://osv.dev/vulnerability/GO-2026-5693) (fixed in >= 5.19.1) - [GHSA-389r-gv7p-r3rp](https://osv.dev/vulnerability/GHSA-389r-gv7p-r3rp) (fixed in >= 5.19.0) - [GHSA-m7cr-m3pv-hgrp](https://osv.dev/vulnerability/GHSA-m7cr-m3pv-hgrp) (fixed in >= 5.19.1) - [GO-2026-5496](https://osv.dev/vulnerability/GO-2026-5496) (fixed in >= 5.19.1) - [GO-2026-6213](https://osv.dev/vulnerability/GO-2026-6213) (fixed in >= 5.19.2) - [GO-2026-5074](https://osv.dev/vulnerability/GO-2026-5074) (fixed in >= 5.19.0) - [GHSA-qgq7-7hm3-q39j](https://osv.dev/vulnerability/GHSA-qgq7-7hm3-q39j) (fixed in >= 5.19.2) - [GO-2026-5336](https://osv.dev/vulnerability/GO-2026-5336) (fixed in >= 5.19.1) - [GHSA-hc8v-wwc9-vgxm](https://osv.dev/vulnerability/GHSA-hc8v-wwc9-vgxm) (fixed in >= 5.19.2) </blockquote> </details> <details><summary>github.com/moby/buildkit</summary> <blockquote> - [GHSA-72x6-4j93-7w86](https://osv.dev/vulnerability/GHSA-72x6-4j93-7w86) (fixed in >= 0.31.1) - [GHSA-7236-3392-c5c6](https://osv.dev/vulnerability/GHSA-7236-3392-c5c6) (fixed in >= 0.31.1) </blockquote> </details> <details><summary>github.com/sigstore/rekor</summary> <blockquote> - [GHSA-47q9-m4ww-924m](https://osv.dev/vulnerability/GHSA-47q9-m4ww-924m) (fixed in >= 1.5.2) - [GO-2026-5778](https://osv.dev/vulnerability/GO-2026-5778) (fixed in >= 1.5.2) </blockquote> </details> <details><summary>golang.org/x/crypto</summary> <blockquote> - [GO-2026-5015](https://osv.dev/vulnerability/GO-2026-5015) (fixed in >= 0.52.0) - [GHSA-q4h4-gmj2-qvw2](https://osv.dev/vulnerability/GHSA-q4h4-gmj2-qvw2) (fixed in >= 0.52.0) - [GHSA-89gr-r52h-f8rx](https://osv.dev/vulnerability/GHSA-89gr-r52h-f8rx) (fixed in >= 0.52.0) - [GHSA-jppx-rxg9-jmrx](https://osv.dev/vulnerability/GHSA-jppx-rxg9-jmrx) (fixed in >= 0.52.0) - [GHSA-qpw4-5x99-6vjp](https://osv.dev/vulnerability/GHSA-qpw4-5x99-6vjp) (fixed in >= 0.52.0) - [GO-2026-5013](https://osv.dev/vulnerability/GO-2026-5013) (fixed in >= 0.52.0) - [GO-2026-5033](https://osv.dev/vulnerability/GO-2026-5033) (fixed in >= 0.52.0) - [GO-2026-5016](https://osv.dev/vulnerability/GO-2026-5016) (fixed in >= 0.52.0) - [GHSA-45gg-vh54-h5m9](https://osv.dev/vulnerability/GHSA-45gg-vh54-h5m9) (fixed in >= 0.52.0) - [GO-2026-5014](https://osv.dev/vulnerability/GO-2026-5014) (fixed in >= 0.52.0) - [GHSA-9m57-25v3-79x9](https://osv.dev/vulnerability/GHSA-9m57-25v3-79x9) (fixed in >= 0.52.0) - [GHSA-5cgq-3rg8-m6cv](https://osv.dev/vulnerability/GHSA-5cgq-3rg8-m6cv) (fixed in >= 0.52.0) - [GHSA-78mq-xcr3-xm33](https://osv.dev/vulnerability/GHSA-78mq-xcr3-xm33) (fixed in >= 0.52.0) - [GO-2026-5018](https://osv.dev/vulnerability/GO-2026-5018) (fixed in >= 0.52.0) - [GHSA-vgwf-h737-ff37](https://osv.dev/vulnerability/GHSA-vgwf-h737-ff37) (fixed in >= 0.52.0) - [GHSA-f5wc-c3c7-36mc](https://osv.dev/vulnerability/GHSA-f5wc-c3c7-36mc) (fixed in >= 0.52.0) - [GO-2026-5020](https://osv.dev/vulnerability/GO-2026-5020) (fixed in >= 0.52.0) - [GO-2026-5017](https://osv.dev/vulnerability/GO-2026-5017) (fixed in >= 0.52.0) - [GO-2026-5932](https://osv.dev/vulnerability/GO-2026-5932) - [GO-2026-5021](https://osv.dev/vulnerability/GO-2026-5021) (fixed in >= 0.52.0) - [GO-2026-5006](https://osv.dev/vulnerability/GO-2026-5006) (fixed in >= 0.52.0) - [GHSA-w879-237q-wc7r](https://osv.dev/vulnerability/GHSA-w879-237q-wc7r) (fixed in >= 0.52.0) - [GO-2026-5019](https://osv.dev/vulnerability/GO-2026-5019) (fixed in >= 0.52.0) - [GHSA-x527-x647-q7gg](https://osv.dev/vulnerability/GHSA-x527-x647-q7gg) (fixed in >= 0.52.0) - [GO-2026-5023](https://osv.dev/vulnerability/GO-2026-5023) (fixed in >= 0.52.0) - [GHSA-rm3j-f69w-wqmq](https://osv.dev/vulnerability/GHSA-rm3j-f69w-wqmq) (fixed in >= 0.52.0) - [GO-2026-5005](https://osv.dev/vulnerability/GO-2026-5005) (fixed in >= 0.52.0) </blockquote> </details> <details><summary>golang.org/x/mod</summary> <blockquote> - [GO-2026-6180](https://osv.dev/vulnerability/GO-2026-6180) (fixed in >= 0.40.0) - [GO-2026-6179](https://osv.dev/vulnerability/GO-2026-6179) (fixed in >= 0.40.0) </blockquote> </details> <details><summary>golang.org/x/net</summary> <blockquote> - [GO-2026-5030](https://osv.dev/vulnerability/GO-2026-5030) (fixed in >= 0.55.0) - [GO-2026-5028](https://osv.dev/vulnerability/GO-2026-5028) (fixed in >= 0.55.0) - [GHSA-5cv4-jp36-h3mw](https://osv.dev/vulnerability/GHSA-5cv4-jp36-h3mw) (fixed in >= 0.55.0) - [GO-2026-5026](https://osv.dev/vulnerability/GO-2026-5026) (fixed in >= 0.55.0) - [GO-2026-5027](https://osv.dev/vulnerability/GO-2026-5027) (fixed in >= 0.55.0) - [GO-2026-5029](https://osv.dev/vulnerability/GO-2026-5029) (fixed in >= 0.55.0) - [GO-2026-5025](https://osv.dev/vulnerability/GO-2026-5025) (fixed in >= 0.55.0) - [GO-2026-5942](https://osv.dev/vulnerability/GO-2026-5942) (fixed in >= 0.56.0) </blockquote> </details> <details><summary>golang.org/x/text</summary> <blockquote> - [GO-2026-5970](https://osv.dev/vulnerability/GO-2026-5970) (fixed in >= 0.39.0) </blockquote> </details> <details><summary>github.com/docker/docker</summary> <blockquote> - [GHSA-6hwg-w5jg-9c6x](https://osv.dev/vulnerability/GHSA-6hwg-w5jg-9c6x) - [GHSA-pxq6-2prw-chj9](https://osv.dev/vulnerability/GHSA-pxq6-2prw-chj9) - [GO-2026-5617](https://osv.dev/vulnerability/GO-2026-5617) - [GO-2026-5668](https://osv.dev/vulnerability/GO-2026-5668) - [GHSA-x86f-5xw2-fm2r](https://osv.dev/vulnerability/GHSA-x86f-5xw2-fm2r) (fixed in > 28.5.2) - [GHSA-qrqr-3x5j-2xw9](https://osv.dev/vulnerability/GHSA-qrqr-3x5j-2xw9) - [GO-2026-4883](https://osv.dev/vulnerability/GO-2026-4883) - [GO-2026-4887](https://osv.dev/vulnerability/GO-2026-4887) - [GHSA-j249-ghv5-7mxv](https://osv.dev/vulnerability/GHSA-j249-ghv5-7mxv) - [GHSA-vp62-88p7-qqf5](https://osv.dev/vulnerability/GHSA-vp62-88p7-qqf5) (fixed in > 28.5.2) - [GHSA-x744-4wpc-v9h2](https://osv.dev/vulnerability/GHSA-x744-4wpc-v9h2) (fixed in >= 29.3.1) - [GHSA-rg2x-37c3-w2rh](https://osv.dev/vulnerability/GHSA-rg2x-37c3-w2rh) (fixed in > 28.5.2) - [GO-2026-5746](https://osv.dev/vulnerability/GO-2026-5746) </blockquote> </details> <details><summary>github.com/containerd/containerd</summary> <blockquote> - [GO-2026-5622](https://osv.dev/vulnerability/GO-2026-5622) - [GHSA-xhf5-7wjv-pqxp](https://osv.dev/vulnerability/GHSA-xhf5-7wjv-pqxp) (fixed in >= 1.7.33) - [GO-2026-5338](https://osv.dev/vulnerability/GO-2026-5338) - [GO-2026-5064](https://osv.dev/vulnerability/GO-2026-5064) - [GHSA-jpcc-p29g-p8mq](https://osv.dev/vulnerability/GHSA-jpcc-p29g-p8mq) (fixed in >= 1.7.33) - [GO-2026-5378](https://osv.dev/vulnerability/GO-2026-5378) (fixed in >= 1.7.32) - [GO-2026-5475](https://osv.dev/vulnerability/GO-2026-5475) (fixed in >= 1.7.33) - [GO-2026-5758](https://osv.dev/vulnerability/GO-2026-5758) (fixed in >= 1.7.33) - [GHSA-fqw6-gf59-qr4w](https://osv.dev/vulnerability/GHSA-fqw6-gf59-qr4w) (fixed in >= 1.7.32) </blockquote> </details> <details><summary>github.com/go-chi/chi/v5</summary> <blockquote> - [GO-2026-5777](https://osv.dev/vulnerability/GO-2026-5777) (fixed in >= 5.3.0) - [GO-2026-5774](https://osv.dev/vulnerability/GO-2026-5774) (fixed in >= 5.3.0) - [GO-2026-5775](https://osv.dev/vulnerability/GO-2026-5775) (fixed in >= 5.3.0) </blockquote> </details> <details><summary>github.com/go-git/go-billy/v5</summary> <blockquote> - [GO-2026-5490](https://osv.dev/vulnerability/GO-2026-5490) (fixed in >= 5.9.0) - [GO-2026-5597](https://osv.dev/vulnerability/GO-2026-5597) (fixed in >= 5.9.0) - [GHSA-qw64-3x98-g7q2](https://osv.dev/vulnerability/GHSA-qw64-3x98-g7q2) (fixed in >= 5.9.0) - [GHSA-m3xc-h892-ggx6](https://osv.dev/vulnerability/GHSA-m3xc-h892-ggx6) (fixed in >= 5.9.0) </blockquote> </details> <details><summary>github.com/google/cel-go</summary> <blockquote> - [GO-2026-6094](https://osv.dev/vulnerability/GO-2026-6094) (fixed in >= 0.30.0) - [GHSA-gcjh-h69q-9w9g](https://osv.dev/vulnerability/GHSA-gcjh-h69q-9w9g) (fixed in >= 0.29.0) </blockquote> </details> <details><summary>github.com/klauspost/compress</summary> <blockquote> - [GO-2026-5841](https://osv.dev/vulnerability/GO-2026-5841) (fixed in >= 1.18.7) </blockquote> </details> <details><summary>github.com/moby/go-archive</summary> <blockquote> - [GHSA-hfg8-hc9c-6c3h](https://osv.dev/vulnerability/GHSA-hfg8-hc9c-6c3h) (fixed in >= 0.3.0) </blockquote> </details> <details><summary>github.com/quic-go/quic-go</summary> <blockquote> - [GO-2026-5676](https://osv.dev/vulnerability/GO-2026-5676) (fixed in >= 0.59.1) - [GHSA-vvgj-x9jq-8cj9](https://osv.dev/vulnerability/GHSA-vvgj-x9jq-8cj9) (fixed in >= 0.59.1) </blockquote> </details> <details><summary>github.com/sigstore/cosign/v2</summary> <blockquote> - [GO-2026-4529](https://osv.dev/vulnerability/GO-2026-4529) - [GO-2026-5694](https://osv.dev/vulnerability/GO-2026-5694) (fixed in >= 2.6.3) </blockquote> </details> <details><summary>github.com/sigstore/sigstore-go</summary> <blockquote> - [GHSA-wqqc-jjcq-vfxm](https://osv.dev/vulnerability/GHSA-wqqc-jjcq-vfxm) (fixed in >= 1.2.1) - [GO-2026-6162](https://osv.dev/vulnerability/GO-2026-6162) (fixed in >= 1.2.1) - [GHSA-9vcr-p3rj-q5q6](https://osv.dev/vulnerability/GHSA-9vcr-p3rj-q5q6) (fixed in >= 1.2.0) - [GO-2026-5952](https://osv.dev/vulnerability/GO-2026-5952) (fixed in >= 1.2.0) </blockquote> </details> <details><summary>github.com/sigstore/timestamp-authority/v2</summary> <blockquote> - [GO-2026-5851](https://osv.dev/vulnerability/GO-2026-5851) (fixed in >= 2.1.0) - [GHSA-9c54-x2g4-v92j](https://osv.dev/vulnerability/GHSA-9c54-x2g4-v92j) (fixed in >= 2.1.0) </blockquote> </details> <details><summary>go.opentelemetry.io/otel</summary> <blockquote> - [GO-2026-5158](https://osv.dev/vulnerability/GO-2026-5158) (fixed in >= 1.44.0) </blockquote> </details> <details><summary>golang.org/x/sys</summary> <blockquote> - [GO-2026-5024](https://osv.dev/vulnerability/GO-2026-5024) (fixed in >= 0.44.0) </blockquote> </details> <details><summary>google.golang.org/grpc</summary> <blockquote> - [GO-2026-6061](https://osv.dev/vulnerability/GO-2026-6061) (fixed in >= 1.82.1) - [GHSA-hrxh-6v49-42gf](https://osv.dev/vulnerability/GHSA-hrxh-6v49-42gf) (fixed in >= 1.82.1) </blockquote> </details> <details><summary>oras.land/oras-go/v2</summary> <blockquote> - [GO-2026-5880](https://osv.dev/vulnerability/GO-2026-5880) (fixed in >= 2.6.2) - [GHSA-8xwf-rjm4-xvhv](https://osv.dev/vulnerability/GHSA-8xwf-rjm4-xvhv) (fixed in >= 2.6.1) - [GO-2026-5884](https://osv.dev/vulnerability/GO-2026-5884) (fixed in >= 2.6.1) - [GO-2026-5882](https://osv.dev/vulnerability/GO-2026-5882) (fixed in >= 2.6.1) - [GO-2026-5885](https://osv.dev/vulnerability/GO-2026-5885) (fixed in >= 2.6.1) - [GHSA-vh4v-2xq2-g5cg](https://osv.dev/vulnerability/GHSA-vh4v-2xq2-g5cg) (fixed in >= 2.6.1) - [GHSA-xf85-363p-868w](https://osv.dev/vulnerability/GHSA-xf85-363p-868w) (fixed in >= 2.6.1) - [GHSA-fxhp-mv3v-67qp](https://osv.dev/vulnerability/GHSA-fxhp-mv3v-67qp) (fixed in >= 2.6.2) - [GO-2026-5879](https://osv.dev/vulnerability/GO-2026-5879) (fixed in >= 2.6.1) - [GHSA-jxpm-75mh-9fp7](https://osv.dev/vulnerability/GHSA-jxpm-75mh-9fp7) (fixed in >= 2.6.1) </blockquote> </details> <details><summary>github.com/moby/moby</summary> <blockquote> - [GHSA-pxq6-2prw-chj9](https://osv.dev/vulnerability/GHSA-pxq6-2prw-chj9) - [GO-2026-5617](https://osv.dev/vulnerability/GO-2026-5617) - [GO-2026-5668](https://osv.dev/vulnerability/GO-2026-5668) - [GO-2026-4883](https://osv.dev/vulnerability/GO-2026-4883) - [GO-2026-4887](https://osv.dev/vulnerability/GO-2026-4887) - [GHSA-x744-4wpc-v9h2](https://osv.dev/vulnerability/GHSA-x744-4wpc-v9h2) (fixed in >= 29.3.1) - [GO-2026-5746](https://osv.dev/vulnerability/GO-2026-5746) </blockquote> </details> </blockquote> </details> <details><summary>integration/testdata/fixtures/repo/gomod/go.mod</summary> <blockquote> <details><summary>github.com/open-policy-agent/opa</summary> <blockquote> - [GO-2022-0316](https://osv.dev/vulnerability/GO-2022-0316) (fixed in >= 0.37.2) - [GHSA-hcw3-j74m-qc58](https://osv.dev/vulnerability/GHSA-hcw3-j74m-qc58) (fixed in >= 0.37.2) - [GO-2022-0574](https://osv.dev/vulnerability/GO-2022-0574) (fixed in >= 0.42.0) - [GHSA-2m4x-4q9j-w97g](https://osv.dev/vulnerability/GHSA-2m4x-4q9j-w97g) (fixed in >= 0.42.0) - [GHSA-6m8w-jc87-6cr7](https://osv.dev/vulnerability/GHSA-6m8w-jc87-6cr7) (fixed in >= 1.4.0) - [GO-2024-3141](https://osv.dev/vulnerability/GO-2024-3141) (fixed in >= 0.68.0) - [GO-2022-0587](https://osv.dev/vulnerability/GO-2022-0587) (fixed in >= 0.40.0) - [GO-2025-3660](https://osv.dev/vulnerability/GO-2025-3660) (fixed in >= 1.4.0) - [GHSA-c77r-fh37-x2px](https://osv.dev/vulnerability/GHSA-c77r-fh37-x2px) (fixed in >= 0.68.0) - [GHSA-x7f3-62pm-9p38](https://osv.dev/vulnerability/GHSA-x7f3-62pm-9p38) (fixed in >= 0.40.0) </blockquote> </details> <details><summary>golang.org/x/net</summary> <blockquote> - [GO-2024-2687](https://osv.dev/vulnerability/GO-2024-2687) (fixed in >= 0.23.0) - [GO-2022-0288](https://osv.dev/vulnerability/GO-2022-0288) (fixed in >= 0.0.0-20211209124913-491a49abca63) - [GO-2024-3333](https://osv.dev/vulnerability/GO-2024-3333) (fixed in >= 0.33.0) - [GHSA-4374-p667-p6c8](https://osv.dev/vulnerability/GHSA-4374-p667-p6c8) (fixed in >= 0.17.0) - [GHSA-xrjj-mj9h-534m](https://osv.dev/vulnerability/GHSA-xrjj-mj9h-534m) (fixed in >= 0.4.0) - [GO-2023-1571](https://osv.dev/vulnerability/GO-2023-1571) (fixed in >= 0.7.0) - [GO-2023-2102](https://osv.dev/vulnerability/GO-2023-2102) (fixed in >= 0.17.0) - [GO-2025-3503](https://osv.dev/vulnerability/GO-2025-3503) (fixed in >= 0.36.0) - [GO-2026-5030](https://osv.dev/vulnerability/GO-2026-5030) (fixed in >= 0.55.0) - [GO-2026-4918](https://osv.dev/vulnerability/GO-2026-4918) (fixed in >= 0.53.0) - [GHSA-qppj-fm5r-hxr3](https://osv.dev/vulnerability/GHSA-qppj-fm5r-hxr3) (fixed in >= 0.17.0) - [GO-2026-4441](https://osv.dev/vulnerability/GO-2026-4441) (fixed in >= 0.45.0) - [GO-2026-5028](https://osv.dev/vulnerability/GO-2026-5028) (fixed in >= 0.55.0) - [GHSA-2wrh-6pvc-2jm9](https://osv.dev/vulnerability/GHSA-2wrh-6pvc-2jm9) (fixed in >= 0.13.0) - [GO-2022-0969](https://osv.dev/vulnerability/GO-2022-0969) (fixed in >= 0.0.0-20220906165146-f3363e06e74c) - [GHSA-5cv4-jp36-h3mw](https://osv.dev/vulnerability/GHSA-5cv4-jp36-h3mw) (fixed in >= 0.55.0) - [GO-2026-5026](https://osv.dev/vulnerability/GO-2026-5026) (fixed in >= 0.55.0) - [GO-2023-1988](https://osv.dev/vulnerability/GO-2023-1988) (fixed in >= 0.13.0) - [GHSA-4v7x-pqxf-cx7m](https://osv.dev/vulnerability/GHSA-4v7x-pqxf-cx7m) (fixed in >= 0.23.0) - [GO-2026-5027](https://osv.dev/vulnerability/GO-2026-5027) (fixed in >= 0.55.0) - [GO-2026-5029](https://osv.dev/vulnerability/GO-2026-5029) (fixed in >= 0.55.0) - [GHSA-vvpx-j8f3-3w6h](https://osv.dev/vulnerability/GHSA-vvpx-j8f3-3w6h) (fixed in >= 0.7.0) - [GHSA-69cg-p879-7622](https://osv.dev/vulnerability/GHSA-69cg-p879-7622) (fixed in >= 0.0.0-20220906165146-f3363e06e74c) - [GO-2025-3595](https://osv.dev/vulnerability/GO-2025-3595) (fixed in >= 0.38.0) - [GO-2026-5025](https://osv.dev/vulnerability/GO-2026-5025) (fixed in >= 0.55.0) - [GO-2022-1144](https://osv.dev/vulnerability/GO-2022-1144) (fixed in >= 0.4.0) - [GHSA-vvgc-356p-c3xw](https://osv.dev/vulnerability/GHSA-vvgc-356p-c3xw) (fixed in >= 0.38.0) - [GHSA-qxp5-gwg8-xv66](https://osv.dev/vulnerability/GHSA-qxp5-gwg8-xv66) (fixed in >= 0.36.0) - [GO-2026-5942](https://osv.dev/vulnerability/GO-2026-5942) (fixed in >= 0.56.0) - [GO-2026-4440](https://osv.dev/vulnerability/GO-2026-4440) (fixed in >= 0.45.0) </blockquote> </details> <details><summary>golang.org/x/sys</summary> <blockquote> - [GHSA-p782-xgp4-8hr8](https://osv.dev/vulnerability/GHSA-p782-xgp4-8hr8) (fixed in >= 0.0.0-20220412211240-33da011f77ad) - [GO-2022-0493](https://osv.dev/vulnerability/GO-2022-0493) (fixed in >= 0.0.0-20220412211240-33da011f77ad) - [GO-2026-5024](https://osv.dev/vulnerability/GO-2026-5024) (fixed in >= 0.44.0) </blockquote> </details> <details><summary>github.com/docker/distribution</summary> <blockquote> - [GHSA-hqxw-f8mx-cpmw](https://osv.dev/vulnerability/GHSA-hqxw-f8mx-cpmw) (fixed in >= 2.8.2-beta.1) - [GHSA-qq97-vm5h-rrhg](https://osv.dev/vulnerability/GHSA-qq97-vm5h-rrhg) (fixed in >= 2.8.0) - [GO-2022-0379](https://osv.dev/vulnerability/GO-2022-0379) (fixed in >= 2.8.0+incompatible) </blockquote> </details> <details><summary>github.com/docker/docker</summary> <blockquote> - [GO-2023-1699](https://osv.dev/vulnerability/GO-2023-1699) (fixed in >= 20.10.24+incompatible) - [GO-2024-3005](https://osv.dev/vulnerability/GO-2024-3005) (fixed in >= 25.0.6+incompatible) - [GHSA-vp35-85q5-9f25](https://osv.dev/vulnerability/GHSA-vp35-85q5-9f25) (fixed in >= 20.10.20) - [GHSA-6hwg-w5jg-9c6x](https://osv.dev/vulnerability/GHSA-6hwg-w5jg-9c6x) - [GHSA-pxq6-2prw-chj9](https://osv.dev/vulnerability/GHSA-pxq6-2prw-chj9) - [GO-2023-1701](https://osv.dev/vulnerability/GO-2023-1701) (fixed in >= 20.10.24+incompatible) - [GO-2025-3829](https://osv.dev/vulnerability/GO-2025-3829) (fixed in >= 25.0.13+incompatible) - [GHSA-2mm7-x5h6-5pvq](https://osv.dev/vulnerability/GHSA-2mm7-x5h6-5pvq) (fixed in >= 20.10.14) - [GO-2026-5617](https://osv.dev/vulnerability/GO-2026-5617) - [GHSA-mq39-4gv4-mvpx](https://osv.dev/vulnerability/GHSA-mq39-4gv4-mvpx) (fixed in >= 23.0.11) - [GHSA-jq35-85cj-fj4p](https://osv.dev/vulnerability/GHSA-jq35-85cj-fj4p) (fixed in >= 20.10.27) - [GO-2023-1700](https://osv.dev/vulnerability/GO-2023-1700) (fixed in >= 20.10.24+incompatible) - [GHSA-6wrf-mxfj-pf5p](https://osv.dev/vulnerability/GHSA-6wrf-mxfj-pf5p) (fixed in >= 20.10.24) - [GO-2026-5668](https://osv.dev/vulnerability/GO-2026-5668) - [GHSA-x86f-5xw2-fm2r](https://osv.dev/vulnerability/GHSA-x86f-5xw2-fm2r) (fixed in > 28.5.2) - [GO-2022-1107](https://osv.dev/vulnerability/GO-2022-1107) (fixed in >= 20.10.20+incompatible) - [GHSA-rc4r-wh2q-q6c4](https://osv.dev/vulnerability/GHSA-rc4r-wh2q-q6c4) (fixed in >= 20.10.18) - [GO-2024-2512](https://osv.dev/vulnerability/GO-2024-2512) (fixed in >= 24.0.9+incompatible) - [GHSA-qrqr-3x5j-2xw9](https://osv.dev/vulnerability/GHSA-qrqr-3x5j-2xw9) - [GO-2026-4883](https://osv.dev/vulnerability/GO-2026-4883) - [GHSA-xw73-rw38-6vjc](https://osv.dev/vulnerability/GHSA-xw73-rw38-6vjc) (fixed in >= 24.0.9) - [GHSA-33pg-m6jh-5237](https://osv.dev/vulnerability/GHSA-33pg-m6jh-5237) (fixed in >= 20.10.24) - [GO-2026-4887](https://osv.dev/vulnerability/GO-2026-4887) - [GHSA-j249-ghv5-7mxv](https://osv.dev/vulnerability/GHSA-j249-ghv5-7mxv) - [GHSA-vp62-88p7-qqf5](https://osv.dev/vulnerability/GHSA-vp62-88p7-qqf5) (fixed in > 28.5.2) - [GHSA-x744-4wpc-v9h2](https://osv.dev/vulnerability/GHSA-x744-4wpc-v9h2) (fixed in >= 29.3.1) - [GHSA-232p-vwff-86mp](https://osv.dev/vulnerability/GHSA-232p-vwff-86mp) (fixed in >= 20.10.24) - [GO-2022-0985](https://osv.dev/vulnerability/GO-2022-0985) (fixed in >= 20.10.18+incompatible) - [GHSA-4vq8-7jfc-9cvp](https://osv.dev/vulnerability/GHSA-4vq8-7jfc-9cvp) (fixed in >= 25.0.13) - [GHSA-rg2x-37c3-w2rh](https://osv.dev/vulnerability/GHSA-rg2x-37c3-w2rh) (fixed in > 28.5.2) - [GO-2022-0390](https://osv.dev/vulnerability/GO-2022-0390) (fixed in >= 20.10.14+incompatible) - [GO-2026-5746](https://osv.dev/vulnerability/GO-2026-5746) </blockquote> </details> <details><summary>golang.org/x/crypto</summary> <blockquote> - [GO-2026-5015](https://osv.dev/vulnerability/GO-2026-5015) (fixed in >= 0.52.0) - [GHSA-q4h4-gmj2-qvw2](https://osv.dev/vulnerability/GHSA-q4h4-gmj2-qvw2) (fixed in >= 0.52.0) - [GHSA-89gr-r52h-f8rx](https://osv.dev/vulnerability/GHSA-89gr-r52h-f8rx) (fixed in >= 0.52.0) - [GO-2023-2402](https://osv.dev/vulnerability/GO-2023-2402) (fixed in >= 0.17.0) - [GHSA-jppx-rxg9-jmrx](https://osv.dev/vulnerability/GHSA-jppx-rxg9-jmrx) (fixed in >= 0.52.0) - [GO-2025-4116](https://osv.dev/vulnerability/GO-2025-4116) (fixed in >= 0.43.0) - [GHSA-qpw4-5x99-6vjp](https://osv.dev/vulnerability/GHSA-qpw4-5x99-6vjp) (fixed in >= 0.52.0) - [GHSA-f6x5-jh6r-wrfv](https://osv.dev/vulnerability/GHSA-f6x5-jh6r-wrfv) (fixed in >= 0.45.0) - [GO-2026-5013](https://osv.dev/vulnerability/GO-2026-5013) (fixed in >= 0.52.0) - [GO-2025-4134](https://osv.dev/vulnerability/GO-2025-4134) (fixed in >= 0.45.0) - [GO-2026-5033](https://osv.dev/vulnerability/GO-2026-5033) (fixed in >= 0.52.0) - [GO-2026-5016](https://osv.dev/vulnerability/GO-2026-5016) (fixed in >= 0.52.0) - [GHSA-45gg-vh54-h5m9](https://osv.dev/vulnerability/GHSA-45gg-vh54-h5m9) (fixed in >= 0.52.0) - [GO-2026-5014](https://osv.dev/vulnerability/GO-2026-5014) (fixed in >= 0.52.0) - [GHSA-8c26-wmh5-6g9v](https://osv.dev/vulnerability/GHSA-8c26-wmh5-6g9v) (fixed in >= 0.0.0-20220314234659-1baeb1ce4c0b) - [GHSA-9m57-25v3-79x9](https://osv.dev/vulnerability/GHSA-9m57-25v3-79x9) (fixed in >= 0.52.0) - [GHSA-j5w8-q4qc-rx2x](https://osv.dev/vulnerability/GHSA-j5w8-q4qc-rx2x) (fixed in >= 0.45.0) - [GO-2021-0356](https://osv.dev/vulnerability/GO-2021-0356) (fixed in >= 0.0.0-20220314234659-1baeb1ce4c0b) - [GHSA-3vm4-22fp-5rfm](https://osv.dev/vulnerability/GHSA-3vm4-22fp-5rfm) (fixed in >= 0.0.0-20201216223049-8b5274cf687f) - [GO-2022-0968](https://osv.dev/vulnerability/GO-2022-0968) (fixed in >= 0.0.0-20211202192323-5770296d904e) - [GO-2025-3487](https://osv.dev/vulnerability/GO-2025-3487) (fixed in >= 0.35.0) - [GHSA-5cgq-3rg8-m6cv](https://osv.dev/vulnerability/GHSA-5cgq-3rg8-m6cv) (fixed in >= 0.52.0) - [GO-2021-0227](https://osv.dev/vulnerability/GO-2021-0227) (fixed in >= 0.0.0-20201216223049-8b5274cf687f) - [GO-2024-3321](https://osv.dev/vulnerability/GO-2024-3321) (fixed in >= 0.31.0) - [GHSA-78mq-xcr3-xm33](https://osv.dev/vulnerability/GHSA-78mq-xcr3-xm33) (fixed in >= 0.52.0) - [GHSA-45x7-px36-x8w8](https://osv.dev/vulnerability/GHSA-45x7-px36-x8w8) (fixed in >= 0.0.0-20231218163308-9d2ee975ef9f) - [GHSA-v778-237x-gjrc](https://osv.dev/vulnerability/GHSA-v778-237x-gjrc) (fixed in >= 0.31.0) - [GO-2026-5018](https://osv.dev/vulnerability/GO-2026-5018) (fixed in >= 0.52.0) - [GHSA-vgwf-h737-ff37](https://osv.dev/vulnerability/GHSA-vgwf-h737-ff37) (fixed in >= 0.52.0) - [GHSA-f5wc-c3c7-36mc](https://osv.dev/vulnerability/GHSA-f5wc-c3c7-36mc) (fixed in >= 0.52.0) - [GHSA-gwc9-m7rh-j2ww](https://osv.dev/vulnerability/GHSA-gwc9-m7rh-j2ww) (fixed in >= 0.0.0-20211202192323-5770296d904e) - [GO-2025-4135](https://osv.dev/vulnerability/GO-2025-4135) (fixed in >= 0.45.0) - [GO-2026-5020](https://osv.dev/vulnerability/GO-2026-5020) (fixed in >= 0.52.0) - [GO-2026-5017](https://osv.dev/vulnerability/GO-2026-5017) (fixed in >= 0.52.0) - [GO-2024-2961](https://osv.dev/vulnerability/GO-2024-2961) (fixed in >= 0.0.0-20220525230936-793ad666bf5e) - [GHSA-hcg3-q754-cr77](https://osv.dev/vulnerability/GHSA-hcg3-q754-cr77) (fixed in >= 0.35.0) - [GO-2026-5932](https://osv.dev/vulnerability/GO-2026-5932) - [GO-2026-5021](https://osv.dev/vulnerability/GO-2026-5021) (fixed in >= 0.52.0) - [GO-2026-5006](https://osv.dev/vulnerability/GO-2026-5006) (fixed in >= 0.52.0) - [GHSA-w879-237q-wc7r](https://osv.dev/vulnerability/GHSA-w879-237q-wc7r) (fixed in >= 0.52.0) - [GO-2026-5019](https://osv.dev/vulnerability/GO-2026-5019) (fixed in >= 0.52.0) - [GHSA-x527-x647-q7gg](https://osv.dev/vulnerability/GHSA-x527-x647-q7gg) (fixed in >= 0.52.0) - [GO-2026-5023](https://osv.dev/vulnerability/GO-2026-5023) (fixed in >= 0.52.0) - [GHSA-rm3j-f69w-wqmq](https://osv.dev/vulnerability/GHSA-rm3j-f69w-wqmq) (fixed in >= 0.52.0) - [GO-2026-5005](https://osv.dev/vulnerability/GO-2026-5005) (fixed in >= 0.52.0) </blockquote> </details> <details><summary>golang.org/x/text</summary> <blockquote> - [GHSA-ppp9-7jff-5vj2](https://osv.dev/vulnerability/GHSA-ppp9-7jff-5vj2) (fixed in >= 0.3.7) - [GHSA-69ch-w2m2-3vjp](https://osv.dev/vulnerability/GHSA-69ch-w2m2-3vjp) (fixed in >= 0.3.8) - [GO-2021-0113](https://osv.dev/vulnerability/GO-2021-0113) (fixed in >= 0.3.7) - [GO-2026-5970](https://osv.dev/vulnerability/GO-2026-5970) (fixed in >= 0.39.0) - [GO-2022-1059](https://osv.dev/vulnerability/GO-2022-1059) (fixed in >= 0.3.8) </blockquote> </details> <details><summary>google.golang.org/grpc</summary> <blockquote> - [GO-2026-6061](https://osv.dev/vulnerability/GO-2026-6061) (fixed in >= 1.82.1) - [GO-2023-2153](https://osv.dev/vulnerability/GO-2023-2153) (fixed in >= 1.56.3) - [GHSA-m425-mq94-257g](https://osv.dev/vulnerability/GHSA-m425-mq94-257g) (fixed in >= 1.56.3) - [GHSA-p77j-4mvh-x3m3](https://osv.dev/vulnerability/GHSA-p77j-4mvh-x3m3) (fixed in >= 1.79.3) - [GHSA-hrxh-6v49-42gf](https://osv.dev/vulnerability/GHSA-hrxh-6v49-42gf) (fixed in >= 1.82.1) - [GO-2026-4762](https://osv.dev/vulnerability/GO-2026-4762) (fixed in >= 1.79.3) </blockquote> </details> <details><summary>google.golang.org/protobuf</summary> <blockquote> - [GO-2024-2611](https://osv.dev/vulnerability/GO-2024-2611) (fixed in >= 1.33.0) - [GHSA-8r3f-844c-mc37](https://osv.dev/vulnerability/GHSA-8r3f-844c-mc37) (fixed in >= 1.33.0) </blockquote> </details> <details><summary>gopkg.in/yaml.v3</summary> <blockquote> - [GO-2022-0603](https://osv.dev/vulnerability/GO-2022-0603) (fixed in >= 3.0.0-20220521103104-8f96da9f5d5e) - [GHSA-hp87-p4gw-j4gq](https://osv.dev/vulnerability/GHSA-hp87-p4gw-j4gq) (fixed in >= 3.0.1) </blockquote> </details> </blockquote> </details> <details><summary>integration/testdata/fixtures/repo/gomod/submod/go.mod</summary> <blockquote> <details><summary>github.com/docker/distribution</summary> <blockquote> - [GHSA-hqxw-f8mx-cpmw](https://osv.dev/vulnerability/GHSA-hqxw-f8mx-cpmw) (fixed in >= 2.8.2-beta.1) - [GHSA-qq97-vm5h-rrhg](https://osv.dev/vulnerability/GHSA-qq97-vm5h-rrhg) (fixed in >= 2.8.0) - [GO-2022-0379](https://osv.dev/vulnerability/GO-2022-0379) (fixed in >= 2.8.0+incompatible) </blockquote> </details> </blockquote> </details> <details><summary>pkg/dependency/parser/golang/mod/testdata/go116/go.mod</summary> <blockquote> <details><summary>gopkg.in/yaml.v3</summary> <blockquote> - [GO-2022-0603](https://osv.dev/vulnerability/GO-2022-0603) (fixed in >= 3.0.0-20220521103104-8f96da9f5d5e) - [GHSA-hp87-p4gw-j4gq](https://osv.dev/vulnerability/GHSA-hp87-p4gw-j4gq) (fixed in >= 3.0.1) </blockquote> </details> </blockquote> </details> <details><summary>pkg/dependency/parser/golang/mod/testdata/replaced-with-local-path-and-version-mismatch/go.mod</summary> <blockquote> <details><summary>gopkg.in/yaml.v3</summary> <blockquote> - [GO-2022-0603](https://osv.dev/vulnerability/GO-2022-0603) (fixed in >= 3.0.0-20220521103104-8f96da9f5d5e) - [GHSA-hp87-p4gw-j4gq](https://osv.dev/vulnerability/GHSA-hp87-p4gw-j4gq) (fixed in >= 3.0.1) </blockquote> </details> </blockquote> </details> <details><summary>pkg/dependency/parser/golang/mod/testdata/replaced-with-local-path-and-version/go.mod</summary> <blockquote> <details><summary>gopkg.in/yaml.v3</summary> <blockquote> - [GO-2022-0603](https://osv.dev/vulnerability/GO-2022-0603) (fixed in >= 3.0.0-20220521103104-8f96da9f5d5e) - [GHSA-hp87-p4gw-j4gq](https://osv.dev/vulnerability/GHSA-hp87-p4gw-j4gq) (fixed in >= 3.0.1) </blockquote> </details> </blockquote> </details> <details><summary>pkg/dependency/parser/golang/mod/testdata/replaced-with-local-path/go.mod</summary> <blockquote> <details><summary>gopkg.in/yaml.v3</summary> <blockquote> - [GO-2022-0603](https://osv.dev/vulnerability/GO-2022-0603) (fixed in >= 3.0.0-20220521103104-8f96da9f5d5e) - [GHSA-hp87-p4gw-j4gq](https://osv.dev/vulnerability/GHSA-hp87-p4gw-j4gq) (fixed in >= 3.0.1) </blockquote> </details> </blockquote> </details> <details><summary>pkg/dependency/parser/golang/mod/testdata/replaced-with-version-mismatch/go.mod</summary> <blockquote> <details><summary>gopkg.in/yaml.v3</summary> <blockquote> - [GO-2022-0603](https://osv.dev/vulnerability/GO-2022-0603) (fixed in >= 3.0.0-20220521103104-8f96da9f5d5e) - [GHSA-hp87-p4gw-j4gq](https://osv.dev/vulnerability/GHSA-hp87-p4gw-j4gq) (fixed in >= 3.0.1) </blockquote> </details> </blockquote> </details> <details><summary>pkg/fanal/analyzer/language/golang/mod/testdata/pkg/mod/github.com/aquasecurity/go-dep-parser@v0.0.0-20220406074731-71021a481237/go.mod</summary> <blockquote> <details><summary>github.com/hashicorp/go-retryablehttp</summary> <blockquote> - [GO-2024-2947](https://osv.dev/vulnerability/GO-2024-2947) (fixed in >= 0.7.7) - [GHSA-v6v8-xj6m-xwqh](https://osv.dev/vulnerability/GHSA-v6v8-xj6m-xwqh) (fixed in >= 0.7.7) </blockquote> </details> <details><summary>golang.org/x/mod</summary> <blockquote> - [GO-2026-6180](https://osv.dev/vulnerability/GO-2026-6180) (fixed in >= 0.40.0) - [GO-2026-6179](https://osv.dev/vulnerability/GO-2026-6179) (fixed in >= 0.40.0) </blockquote> </details> <details><summary>golang.org/x/net</summary> <blockquote> - [GO-2024-2687](https://osv.dev/vulnerability/GO-2024-2687) (fixed in >= 0.23.0) - [GO-2022-0288](https://osv.dev/vulnerability/GO-2022-0288) (fixed in >= 0.0.0-20211209124913-491a49abca63) - [GO-2024-3333](https://osv.dev/vulnerability/GO-2024-3333) (fixed in >= 0.33.0) - [GHSA-4374-p667-p6c8](https://osv.dev/vulnerability/GHSA-4374-p667-p6c8) (fixed in >= 0.17.0) - [GHSA-xrjj-mj9h-534m](https://osv.dev/vulnerability/GHSA-xrjj-mj9h-534m) (fixed in >= 0.4.0) - [GO-2023-1571](https://osv.dev/vulnerability/GO-2023-1571) (fixed in >= 0.7.0) - [GO-2023-2102](https://osv.dev/vulnerability/GO-2023-2102) (fixed in >= 0.17.0) - [GO-2025-3503](https://osv.dev/vulnerability/GO-2025-3503) (fixed in >= 0.36.0) - [GO-2026-5030](https://osv.dev/vulnerability/GO-2026-5030) (fixed in >= 0.55.0) - [GO-2026-4918](https://osv.dev/vulnerability/GO-2026-4918) (fixed in >= 0.53.0) - [GHSA-qppj-fm5r-hxr3](https://osv.dev/vulnerability/GHSA-qppj-fm5r-hxr3) (fixed in >= 0.17.0) - [GO-2026-4441](https://osv.dev/vulnerability/GO-2026-4441) (fixed in >= 0.45.0) - [GO-2026-5028](https://osv.dev/vulnerability/GO-2026-5028) (fixed in >= 0.55.0) - [GHSA-2wrh-6pvc-2jm9](https://osv.dev/vulnerability/GHSA-2wrh-6pvc-2jm9) (fixed in >= 0.13.0) - [GO-2022-0969](https://osv.dev/vulnerability/GO-2022-0969) (fixed in >= 0.0.0-20220906165146-f3363e06e74c) - [GHSA-5cv4-jp36-h3mw](https://osv.dev/vulnerability/GHSA-5cv4-jp36-h3mw) (fixed in >= 0.55.0) - [GO-2026-5026](https://osv.dev/vulnerability/GO-2026-5026) (fixed in >= 0.55.0) - [GO-2023-1988](https://osv.dev/vulnerability/GO-2023-1988) (fixed in >= 0.13.0) - [GHSA-4v7x-pqxf-cx7m](https://osv.dev/vulnerability/GHSA-4v7x-pqxf-cx7m) (fixed in >= 0.23.0) - [GO-2026-5027](https://osv.dev/vulnerability/GO-2026-5027) (fixed in >= 0.55.0) - [GO-2026-5029](https://osv.dev/vulnerability/GO-2026-5029) (fixed in >= 0.55.0) - [GHSA-vvpx-j8f3-3w6h](https://osv.dev/vulnerability/GHSA-vvpx-j8f3-3w6h) (fixed in >= 0.7.0) - [GHSA-69cg-p879-7622](https://osv.dev/vulnerability/GHSA-69cg-p879-7622) (fixed in >= 0.0.0-20220906165146-f3363e06e74c) - [GO-2025-3595](https://osv.dev/vulnerability/GO-2025-3595) (fixed in >= 0.38.0) - [GO-2026-5025](https://osv.dev/vulnerability/GO-2026-5025) (fixed in >= 0.55.0) - [GO-2022-1144](https://osv.dev/vulnerability/GO-2022-1144) (fixed in >= 0.4.0) - [GHSA-vvgc-356p-c3xw](https://osv.dev/vulnerability/GHSA-vvgc-356p-c3xw) (fixed in >= 0.38.0) - [GHSA-qxp5-gwg8-xv66](https://osv.dev/vulnerability/GHSA-qxp5-gwg8-xv66) (fixed in >= 0.36.0) - [GO-2026-5942](https://osv.dev/vulnerability/GO-2026-5942) (fixed in >= 0.56.0) - [GO-2026-4440](https://osv.dev/vulnerability/GO-2026-4440) (fixed in >= 0.45.0) </blockquote> </details> <details><summary>golang.org/x/text</summary> <blockquote> - [GO-2026-5970](https://osv.dev/vulnerability/GO-2026-5970) (fixed in >= 0.39.0) </blockquote> </details> </blockquote> </details> <details><summary>pkg/fanal/analyzer/language/golang/mod/testdata/pkg/mod/github.com/aquasecurity/go-dep-parser@v0.0.0-20230219131432-590b1dfb6edd/go.mod</summary> <blockquote> <details><summary>github.com/hashicorp/go-retryablehttp</summary> <blockquote> - [GO-2024-2947](https://osv.dev/vulnerability/GO-2024-2947) (fixed in >= 0.7.7) - [GHSA-v6v8-xj6m-xwqh](https://osv.dev/vulnerability/GHSA-v6v8-xj6m-xwqh) (fixed in >= 0.7.7) </blockquote> </details> <details><summary>golang.org/x/mod</summary> <blockquote> - [GO-2026-6180](https://osv.dev/vulnerability/GO-2026-6180) (fixed in >= 0.40.0) - [GO-2026-6179](https://osv.dev/vulnerability/GO-2026-6179) (fixed in >= 0.40.0) </blockquote> </details> <details><summary>golang.org/x/net</summary> <blockquote> - [GO-2024-2687](https://osv.dev/vulnerability/GO-2024-2687) (fixed in >= 0.23.0) - [GO-2022-0288](https://osv.dev/vulnerability/GO-2022-0288) (fixed in >= 0.0.0-20211209124913-491a49abca63) - [GO-2024-3333](https://osv.dev/vulnerability/GO-2024-3333) (fixed in >= 0.33.0) - [GHSA-4374-p667-p6c8](https://osv.dev/vulnerability/GHSA-4374-p667-p6c8) (fixed in >= 0.17.0) - [GHSA-xrjj-mj9h-534m](https://osv.dev/vulnerability/GHSA-xrjj-mj9h-534m) (fixed in >= 0.4.0) - [GO-2023-1571](https://osv.dev/vulnerability/GO-2023-1571) (fixed in >= 0.7.0) - [GO-2023-2102](https://osv.dev/vulnerability/GO-2023-2102) (fixed in >= 0.17.0) - [GO-2025-3503](https://osv.dev/vulnerability/GO-2025-3503) (fixed in >= 0.36.0) - [GO-2026-5030](https://osv.dev/vulnerability/GO-2026-5030) (fixed in >= 0.55.0) - [GO-2026-4918](https://osv.dev/vulnerability/GO-2026-4918) (fixed in >= 0.53.0) - [GHSA-qppj-fm5r-hxr3](https://osv.dev/vulnerability/GHSA-qppj-fm5r-hxr3) (fixed in >= 0.17.0) - [GO-2026-4441](https://osv.dev/vulnerability/GO-2026-4441) (fixed in >= 0.45.0) - [GO-2026-5028](https://osv.dev/vulnerability/GO-2026-5028) (fixed in >= 0.55.0) - [GHSA-2wrh-6pvc-2jm9](https://osv.dev/vulnerability/GHSA-2wrh-6pvc-2jm9) (fixed in >= 0.13.0) - [GO-2022-0969](https://osv.dev/vulnerability/GO-2022-0969) (fixed in >= 0.0.0-20220906165146-f3363e06e74c) - [GHSA-5cv4-jp36-h3mw](https://osv.dev/vulnerability/GHSA-5cv4-jp36-h3mw) (fixed in >= 0.55.0) - [GO-2026-5026](https://osv.dev/vulnerability/GO-2026-5026) (fixed in >= 0.55.0) - [GO-2023-1988](https://osv.dev/vulnerability/GO-2023-1988) (fixed in >= 0.13.0) - [GHSA-4v7x-pqxf-cx7m](https://osv.dev/vulnerability/GHSA-4v7x-pqxf-cx7m) (fixed in >= 0.23.0) - [GO-2026-5027](https://osv.dev/vulnerability/GO-2026-5027) (fixed in >= 0.55.0) - [GO-2026-5029](https://osv.dev/vulnerability/GO-2026-5029) (fixed in >= 0.55.0) - [GHSA-vvpx-j8f3-3w6h](https://osv.dev/vulnerability/GHSA-vvpx-j8f3-3w6h) (fixed in >= 0.7.0) - [GHSA-69cg-p879-7622](https://osv.dev/vulnerability/GHSA-69cg-p879-7622) (fixed in >= 0.0.0-20220906165146-f3363e06e74c) - [GO-2025-3595](https://osv.dev/vulnerability/GO-2025-3595) (fixed in >= 0.38.0) - [GO-2026-5025](https://osv.dev/vulnerability/GO-2026-5025) (fixed in >= 0.55.0) - [GO-2022-1144](https://osv.dev/vulnerability/GO-2022-1144) (fixed in >= 0.4.0) - [GHSA-vvgc-356p-c3xw](https://osv.dev/vulnerability/GHSA-vvgc-356p-c3xw) (fixed in >= 0.38.0) - [GHSA-qxp5-gwg8-xv66](https://osv.dev/vulnerability/GHSA-qxp5-gwg8-xv66) (fixed in >= 0.36.0) - [GO-2026-5942](https://osv.dev/vulnerability/GO-2026-5942) (fixed in >= 0.56.0) - [GO-2026-4440](https://osv.dev/vulnerability/GO-2026-4440) (fixed in >= 0.45.0) </blockquote> </details> <details><summary>golang.org/x/text</summary> <blockquote> - [GO-2026-5970](https://osv.dev/vulnerability/GO-2026-5970) (fixed in >= 0.39.0) </blockquote> </details> </blockquote> </details> </blockquote> </details> ## Detected dependencies > [!NOTE] > Detected dependencies section has been truncated <details><summary>gomod</summary> <blockquote> <details><summary>go.mod</summary> - `go 1.26.3` - `github.com/Azure/azure-sdk-for-go v68.0.0+incompatible` - `github.com/Azure/azure-sdk-for-go/sdk/azcore v1.21.0` - `github.com/Azure/azure-sdk-for-go/sdk/azidentity v1.13.1` - `github.com/BurntSushi/toml v1.6.0` - `github.com/CycloneDX/cyclonedx-go v0.9.2` - `github.com/GoogleCloudPlatform/docker-credential-gcr v2.0.5+incompatible` - `github.com/Masterminds/sprig/v3 v3.3.0` - `github.com/NYTimes/gziphandler v1.1.1` - `github.com/alecthomas/chroma v0.10.0` - `github.com/alicebob/miniredis/v2 v2.35.0` - `github.com/apparentlymart/go-cidr v1.1.0` - `github.com/aquasecurity/bolt-fixtures v0.0.0-20200903104109-d34e7f983986@d34e7f983986` - `github.com/aquasecurity/go-gem-version v0.0.0-20201115065557-8eed6fe000ce@8eed6fe000ce` - `github.com/aquasecurity/go-npm-version v0.0.2` - `github.com/aquasecurity/go-pep440-version v0.0.1` - `github.com/aquasecurity/go-version v0.0.1` - `github.com/aquasecurity/iamgo v0.0.10` - `github.com/aquasecurity/table v1.11.0` - `github.com/aquasecurity/testdocker v0.0.0-20250616060700-ba6845ac6d17@ba6845ac6d17` - `github.com/aquasecurity/tml v0.6.1` - `github.com/aquasecurity/trivy-checks v1.11.3-0.20250604022615-9a7efa7c9169@9a7efa7c9169` - `github.com/aquasecurity/trivy-db v0.0.0-20250723062229-56ec1e482238@56ec1e482238` - `github.com/aquasecurity/trivy-java-db v0.0.0-20240109071736-184bd7481d48@184bd7481d48` - `github.com/aquasecurity/trivy-kubernetes v0.9.1` - `github.com/aws/aws-sdk-go-v2 v1.41.5` - `github.com/aws/aws-sdk-go-v2/config v1.32.12` - `github.com/aws/aws-sdk-go-v2/credentials v1.19.12` - `github.com/aws/aws-sdk-go-v2/service/ec2 v1.234.0` - `github.com/aws/aws-sdk-go-v2/service/ecr v1.45.2` - `github.com/aws/aws-sdk-go-v2/service/s3 v1.97.3` - `github.com/aws/smithy-go v1.24.2` - `github.com/bitnami/go-version v0.0.0-20231130084017-bb00604d650c@bb00604d650c` - `github.com/bmatcuk/doublestar/v4 v4.9.1` - `github.com/cenkalti/backoff/v4 v4.3.0` - `github.com/cheggaaa/pb/v3 v3.1.7` - `github.com/containerd/containerd/v2 v2.2.1` - `github.com/containerd/platforms v1.0.0-rc.2` - `github.com/distribution/reference v0.6.0` - `github.com/docker/cli v29.2.1+incompatible` - `github.com/docker/go-connections v0.6.0` - `github.com/docker/go-units v0.5.0` - `github.com/fatih/color v1.18.0` - `github.com/go-git/go-git/v5 v5.18.0` - `github.com/go-redis/redis/v8 v8.11.5` - `github.com/gocsaf/csaf/v3 v3.3.0` - `github.com/golang-jwt/jwt/v5 v5.3.0` - `github.com/google/go-containerregistry v0.20.7` - `github.com/google/go-github/v62 v62.0.0` - `github.com/google/licenseclassifier/v2 v2.0.0` - `github.com/google/uuid v1.6.0` - `github.com/google/wire v0.6.0` - `github.com/hashicorp/go-getter v1.8.6` - `github.com/hashicorp/go-multierror v1.1.1` - `github.com/hashicorp/go-retryablehttp v0.7.8` - `github.com/hashicorp/go-uuid v1.0.3` - `github.com/hashicorp/go-version v1.8.0` - `github.com/hashicorp/golang-lru/v2 v2.0.7` - `github.com/hashicorp/hc-install v0.9.2` - `github.com/hashicorp/hcl/v2 v2.24.0` - `github.com/hashicorp/terraform-exec v0.23.0` - `github.com/in-toto/in-toto-golang v0.11.0` - `github.com/knqyf263/go-apk-version v0.0.0-20200609155635-041fdbb8563f@041fdbb8563f` - `github.com/knqyf263/go-deb-version v0.0.0-20241115132648-6f4aee6ccd23@6f4aee6ccd23` - `github.com/knqyf263/go-rpm-version v0.0.0-20220614171824-631e686d1075@631e686d1075` - `github.com/knqyf263/go-rpmdb v0.1.1` - `github.com/knqyf263/nested v0.0.1` - `github.com/kylelemons/godebug v1.1.0` - `github.com/liamg/memoryfs v1.6.0` - `github.com/magefile/mage v1.15.0` - `github.com/masahiro331/go-disk v0.0.0-20240625071113-56c933208fee@56c933208fee` - `github.com/masahiro331/go-ebs-file v0.0.0-20240917043618-e6d2bea5c32e@e6d2bea5c32e` - `github.com/masahiro331/go-ext4-filesystem v0.0.0-20240620024024-ca14e6327bbd@ca14e6327bbd` - `github.com/masahiro331/go-mvn-version v0.0.0-20250131095131-f4974fa13b8a@f4974fa13b8a` - `github.com/masahiro331/go-vmdk-parser v0.0.0-20221225061455-612096e4bbbd@612096e4bbbd` - `github.com/masahiro331/go-xfs-filesystem v0.0.0-20231205045356-1b22259a6c44@1b22259a6c44` - `github.com/mattn/go-shellwords v1.0.12` - `github.com/mitchellh/go-homedir v1.1.0` - `github.com/mitchellh/hashstructure/v2 v2.0.2` - `github.com/mitchellh/mapstructure v1.5.1-0.20231216201459-8508981c8b6c@8508981c8b6c` - `github.com/moby/buildkit v0.28.1` - `github.com/moby/docker-image-spec v1.3.1` - `github.com/open-policy-agent/opa v1.8.0` - `github.com/opencontainers/go-digest v1.0.0` - `github.com/opencontainers/image-spec v1.1.1` - `github.com/openvex/discovery v0.1.1-0.20240802171711-7c54efc57553@7c54efc57553` - `github.com/openvex/go-vex v0.2.5` - `github.com/owenrumney/go-sarif/v2 v2.3.3` - `github.com/package-url/packageurl-go v0.1.3` - `github.com/quasilyte/go-ruleguard/dsl v0.3.22` - `github.com/rust-secure-code/go-rustaudit v0.0.0-20250226111315-e20ec32e963c@e20ec32e963c` - `github.com/samber/lo v1.51.0` - `github.com/sassoftware/go-rpmutils v0.4.0` - `github.com/secure-systems-lab/go-securesystemslib v0.10.0` - `github.com/sigstore/rekor v1.5.0` - `github.com/sirupsen/logrus v1.9.4` - `github.com/sosedoff/gitkit v0.4.0` - `github.com/spf13/cast v1.10.0` - `github.com/spf13/cobra v1.10.2` - `github.com/spf13/pflag v1.0.10` - `github.com/spf13/viper v1.21.0` - `github.com/stretchr/testify v1.11.1` - `github.com/testcontainers/testcontainers-go v0.38.0` - `github.com/testcontainers/testcontainers-go/modules/localstack v0.38.0` - `github.com/tetratelabs/wazero v1.11.0` - `github.com/twitchtv/twirp v8.1.3+incompatible` - `github.com/xeipuuv/gojsonschema v1.2.0` - `github.com/xlab/treeprint v1.2.0` - `github.com/zclconf/go-cty v1.16.3` - `github.com/zclconf/go-cty-yaml v1.1.0` - `go.etcd.io/bbolt v1.4.3` - `golang.org/x/crypto v0.50.0` - `golang.org/x/mod v0.34.0` - `golang.org/x/net v0.53.0` - `golang.org/x/sync v0.20.0` - `golang.org/x/term v0.42.0` - `golang.org/x/text v0.36.0` - `golang.org/x/vuln v1.1.4` - `golang.org/x/xerrors v0.0.0-20240716161551-93cc26a95ae9@93cc26a95ae9` - `google.golang.org/protobuf v1.36.11` - `gopkg.in/yaml.v3 v3.0.1` - `helm.sh/helm/v3 v3.20.2` - `k8s.io/api v0.35.1` - `k8s.io/utils v0.0.0-20251002143259-bc988d571ff4@bc988d571ff4` - `modernc.org/sqlite v1.38.0` - `github.com/docker/docker v28.5.2+incompatible` - `github.com/moby/moby/api v1.54.0` - `github.com/moby/moby/client v0.3.0` - `github.com/rogpeppe/go-internal v1.14.1` - `buf.build/gen/go/bufbuild/bufplugin/protocolbuffers/go v1.36.10-20250718181942-e35f9b667443.1@e35f9b667443` - `buf.build/gen/go/bufbuild/protovalidate/protocolbuffers/go v1.36.10-20250912141014-52f32327d4b0.1@52f32327d4b0` - `buf.build/gen/go/bufbuild/registry/connectrpc/go v1.19.1-20250924144421-cb55f06efbd2.2@cb55f06efbd2` - `buf.build/gen/go/bufbuild/registry/protocolbuffers/go v1.36.10-20250924144421-cb55f06efbd2.1@cb55f06efbd2` - `buf.build/gen/go/pluginrpc/pluginrpc/protocolbuffers/go v1.36.10-20241007202033-cf42259fcbfc.1@cf42259fcbfc` - `buf.build/go/app v0.1.0` - `buf.build/go/bufplugin v0.9.0` - `buf.build/go/interrupt v1.1.0` - `buf.build/go/protovalidate v1.0.0` - `buf.build/go/protoyaml v0.6.0` - `buf.build/go/spdx v0.2.0` - `buf.build/go/standard v0.1.0` - `cel.dev/expr v0.25.1` - `cloud.google.com/go v0.123.0` - `cloud.google.com/go/auth v0.18.2` - `cloud.google.com/go/auth/oauth2adapt v0.2.8` - `cloud.google.com/go/compute/metadata v0.9.0` - `cloud.google.com/go/iam v1.5.3` - `cloud.google.com/go/monitoring v1.24.3` - `cloud.google.com/go/storage v1.61.3` - `connectrpc.com/connect v1.19.1` - `connectrpc.com/otelconnect v0.8.0` - `cyphar.com/go-pathrs v0.2.1` - `dario.cat/mergo v1.0.2` - `github.com/Azure/azure-sdk-for-go/sdk/internal v1.11.2` - `github.com/Azure/go-ansiterm v0.0.0-20250102033503-faa5f7b0171c@faa5f7b0171c` - `github.com/Azure/go-autorest v14.2.0+incompatible` - `github.com/Azure/go-autorest/autorest v0.11.29` - `github.com/Azure/go-autorest/autorest/adal v0.9.23` - `github.com/Azure/go-autorest/autorest/date v0.3.0` - `github.com/Azure/go-autorest/logger v0.2.1` - `github.com/Azure/go-autorest/tracing v0.6.0` - `github.com/AzureAD/microsoft-authentication-library-for-go v1.6.0` - `github.com/DataDog/zstd v1.5.5` - `github.com/GoogleCloudPlatform/opentelemetry-operations-go/detectors/gcp v1.30.0` - `github.com/GoogleCloudPlatform/opentelemetry-operations-go/exporter/metric v0.55.0` - `github.com/GoogleCloudPlatform/opentelemetry-operations-go/internal/resourcemapping v0.55.0` - `github.com/Intevation/gval v1.3.0` - `github.com/Intevation/jsonpath v0.2.1` - `github.com/MakeNowJust/heredoc v1.0.0` - `github.com/Masterminds/goutils v1.1.1` - `github.com/Masterminds/semver/v3 v3.4.0` - `github.com/Masterminds/squirrel v1.5.4` - `github.com/Microsoft/go-winio v0.6.2` - `github.com/Microsoft/hcsshim v0.14.0-rc.1` - `github.com/ProtonMail/go-crypto v1.3.0` - `github.com/VividCortex/ewma v1.2.0` - `github.com/agext/levenshtein v1.2.3` - `github.com/agnivade/levenshtein v1.2.1` </details> </blockquote> </details> --- - [ ] <!-- manual job -->Check this box to trigger a request for Renovate to run again on this repository
This issue lists Renovate updates and detected dependencies. Read the Dependency Dashboard docs to learn more.
Repository problems
Renovate tried to run on this repository, but found these problems.
Rate-Limited
These updates are currently rate-limited. Click on a checkbox below to force their creation now.
Edited/Blocked
These updates have been manually edited so Renovate will no longer make changes. To discard all commits and start over, click on a checkbox.
Open
These updates have all been created already. Click a checkbox below to force a retry/rebase of any.
Vulnerabilities
321/351CVEs have Renovate fixes.gomod
Detected dependencies
Note
Detected dependencies section has been truncated
gomod