Commit graph

351 commits

Author SHA1 Message Date
Michael Hoffman
5fea94ed9e Revert change to deps 2025-02-01 15:48:58 -05:00
Michael Hoffman
e226a79dc5 Autolink delete tests 2025-02-01 15:46:09 -05:00
Andy Feller
a6c9c511ea
Merge pull request #10319 from cli/dependabot/go_modules/github.com/in-toto/attestation-1.1.1
Bump github.com/in-toto/attestation from 1.1.0 to 1.1.1
2025-01-30 08:44:34 -05:00
dependabot[bot]
532be61d6b
Bump github.com/in-toto/attestation from 1.1.0 to 1.1.1
Bumps [github.com/in-toto/attestation](https://github.com/in-toto/attestation) from 1.1.0 to 1.1.1.
- [Release notes](https://github.com/in-toto/attestation/releases)
- [Commits](https://github.com/in-toto/attestation/compare/v1.1.0...v1.1.1)

---
updated-dependencies:
- dependency-name: github.com/in-toto/attestation
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2025-01-27 14:35:50 +00:00
Cody Soyland
d60c4fbd7b
go mod tidy
Signed-off-by: Cody Soyland <codysoyland@github.com>
2025-01-24 16:26:49 -05:00
Cody Soyland
b582b5830b
Upgrade sigstore-go to v0.7.0: fixes #10114 formatting issue
Signed-off-by: Cody Soyland <codysoyland@github.com>
2025-01-24 16:24:00 -05:00
dependabot[bot]
9f801771a8
Bump google.golang.org/protobuf from 1.36.3 to 1.36.4
Bumps google.golang.org/protobuf from 1.36.3 to 1.36.4.

---
updated-dependencies:
- dependency-name: google.golang.org/protobuf
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2025-01-24 14:49:07 +00:00
Otto Kekäläinen
b19e682455
Update test to be compatible with latest Glamour v0.8.0
Latest Glamour has slightly changed logic in line length / wrapping,
resulting test failures due to string mismatch. Update tests and bump
dependency to v0.8.0, and others to the bare minimal level as generated
by `go mod tidy`.

This was detected then building the GitHub cli package `gh` in Debian
started to fail with src:golang-github-charmbracelet-glamour 0.8.0-1.

Closes: #10179
2025-01-22 20:13:40 -08:00
William Martin
113fe646f3 Bump go module version to 1.23 2025-01-22 12:10:03 +01:00
dependabot[bot]
9eb8002764 Bump github.com/google/go-containerregistry from 0.20.2 to 0.20.3
Bumps [github.com/google/go-containerregistry](https://github.com/google/go-containerregistry) from 0.20.2 to 0.20.3.
- [Release notes](https://github.com/google/go-containerregistry/releases)
- [Changelog](https://github.com/google/go-containerregistry/blob/main/.goreleaser.yml)
- [Commits](https://github.com/google/go-containerregistry/compare/v0.20.2...v0.20.3)

---
updated-dependencies:
- dependency-name: github.com/google/go-containerregistry
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2025-01-22 12:10:03 +01:00
Kynan Ware
60f8417d4b
Merge pull request #10250 from cli/dependabot/go_modules/google.golang.org/protobuf-1.36.3
Bump google.golang.org/protobuf from 1.36.2 to 1.36.3
2025-01-16 14:21:33 -07:00
Andy Feller
07c63558b8
Merge pull request #10184 from cli/dependabot/go_modules/github.com/gabriel-vasile/mimetype-1.4.8
Bump github.com/gabriel-vasile/mimetype from 1.4.7 to 1.4.8
2025-01-16 15:56:25 -05:00
dependabot[bot]
2757d22b4b
Bump google.golang.org/protobuf from 1.36.2 to 1.36.3
Bumps google.golang.org/protobuf from 1.36.2 to 1.36.3.

---
updated-dependencies:
- dependency-name: google.golang.org/protobuf
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2025-01-15 14:49:31 +00:00
Tyler McGoffin
adc5f01d23
Merge pull request #10214 from cli/dependabot/go_modules/github.com/sigstore/protobuf-specs-0.3.3
Bump github.com/sigstore/protobuf-specs from 0.3.2 to 0.3.3
2025-01-14 16:08:39 -08:00
dependabot[bot]
7300f0d568
Bump github.com/gabriel-vasile/mimetype from 1.4.7 to 1.4.8
Bumps [github.com/gabriel-vasile/mimetype](https://github.com/gabriel-vasile/mimetype) from 1.4.7 to 1.4.8.
- [Release notes](https://github.com/gabriel-vasile/mimetype/releases)
- [Commits](https://github.com/gabriel-vasile/mimetype/compare/v1.4.7...v1.4.8)

---
updated-dependencies:
- dependency-name: github.com/gabriel-vasile/mimetype
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2025-01-13 15:23:32 +00:00
Meredith Lancaster
112552fec1
Merge pull request #10185 from malancas/fetch-artifact-attestation-bundles-with-sas-url 2025-01-13 08:20:33 -07:00
dependabot[bot]
567624b550
Bump github.com/mattn/go-colorable from 0.1.13 to 0.1.14
Bumps [github.com/mattn/go-colorable](https://github.com/mattn/go-colorable) from 0.1.13 to 0.1.14.
- [Commits](https://github.com/mattn/go-colorable/compare/v0.1.13...v0.1.14)

---
updated-dependencies:
- dependency-name: github.com/mattn/go-colorable
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2025-01-10 14:39:26 +00:00
dependabot[bot]
ae36160ea5
Bump github.com/sigstore/protobuf-specs from 0.3.2 to 0.3.3
Bumps [github.com/sigstore/protobuf-specs](https://github.com/sigstore/protobuf-specs) from 0.3.2 to 0.3.3.
- [Release notes](https://github.com/sigstore/protobuf-specs/releases)
- [Changelog](https://github.com/sigstore/protobuf-specs/blob/main/CHANGELOG.md)
- [Commits](https://github.com/sigstore/protobuf-specs/compare/v0.3.2...v0.3.3)

---
updated-dependencies:
- dependency-name: github.com/sigstore/protobuf-specs
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2025-01-10 14:39:20 +00:00
Meredith Lancaster
b1af4b0ce3
Merge branch 'trunk' into fetch-artifact-attestation-bundles-with-sas-url 2025-01-06 12:49:27 -07:00
Andy Feller
757966ca7c Bump cli/go-gh for indirect security vulnerability 2025-01-06 14:27:03 -05:00
Meredith Lancaster
706314b005
Merge branch 'trunk' into fetch-artifact-attestation-bundles-with-sas-url 2025-01-06 09:57:57 -07:00
Tyler McGoffin
939e183cd6 Upgrade golang.org/x/net to v0.33.0 2024-12-23 11:43:51 -08:00
dependabot[bot]
ede6c4de1a
Bump github.com/cpuguy83/go-md2man/v2 from 2.0.5 to 2.0.6
Bumps [github.com/cpuguy83/go-md2man/v2](https://github.com/cpuguy83/go-md2man) from 2.0.5 to 2.0.6.
- [Release notes](https://github.com/cpuguy83/go-md2man/releases)
- [Commits](https://github.com/cpuguy83/go-md2man/compare/v2.0.5...v2.0.6)

---
updated-dependencies:
- dependency-name: github.com/cpuguy83/go-md2man/v2
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2024-12-17 14:41:05 +00:00
Meredith Lancaster
45121f6674 go mod tidy
Signed-off-by: Meredith Lancaster <malancas@github.com>
2024-12-16 12:02:42 -07:00
Meredith Lancaster
7160f7ef50 Merge branch 'trunk' into fetch-artifact-attestation-bundles-with-sas-url 2024-12-13 15:25:00 -07:00
Phill MV
c789b56da4
Merge pull request #9954 from cli/phillmv/improve-gh-at-inspect 2024-12-13 09:50:52 -05:00
dependabot[bot]
1af421012e
Bump golang.org/x/crypto from 0.29.0 to 0.31.0
Bumps [golang.org/x/crypto](https://github.com/golang/crypto) from 0.29.0 to 0.31.0.
- [Commits](https://github.com/golang/crypto/compare/v0.29.0...v0.31.0)

---
updated-dependencies:
- dependency-name: golang.org/x/crypto
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
2024-12-12 12:30:56 +00:00
Phill MV
bbc47fbac7 go mod tidy 2024-12-11 16:52:40 -05:00
William Martin
8d8ac515d0
Merge pull request #9942 from cli/dependabot/go_modules/github.com/gabriel-vasile/mimetype-1.4.7
Bump github.com/gabriel-vasile/mimetype from 1.4.6 to 1.4.7
2024-12-02 14:03:25 +01:00
Andy Feller
c94def8b51 Bump cli/go-gh for codespace fix 2024-11-27 15:54:38 -05:00
dependabot[bot]
6b2c552978
Bump github.com/gabriel-vasile/mimetype from 1.4.6 to 1.4.7
Bumps [github.com/gabriel-vasile/mimetype](https://github.com/gabriel-vasile/mimetype) from 1.4.6 to 1.4.7.
- [Release notes](https://github.com/gabriel-vasile/mimetype/releases)
- [Commits](https://github.com/gabriel-vasile/mimetype/compare/v1.4.6...v1.4.7)

---
updated-dependencies:
- dependency-name: github.com/gabriel-vasile/mimetype
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2024-11-20 15:00:03 +00:00
Meredith Lancaster
bfd140c0e5 initial pass at fetching bundles with sas urls
Signed-off-by: Meredith Lancaster <malancas@github.com>
2024-11-06 07:57:18 -07:00
dependabot[bot]
815fcb72b5
Bump github.com/creack/pty from 1.1.23 to 1.1.24
Bumps [github.com/creack/pty](https://github.com/creack/pty) from 1.1.23 to 1.1.24.
- [Release notes](https://github.com/creack/pty/releases)
- [Commits](https://github.com/creack/pty/compare/v1.1.23...v1.1.24)

---
updated-dependencies:
- dependency-name: github.com/creack/pty
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2024-11-01 14:10:24 +00:00
William Martin
30d9fc53d1 Update testscript to use hard fork 2024-10-25 16:29:23 +02:00
William Martin
787a243323 Update go-internal to redact more token types in Acceptance tests 2024-10-24 15:14:51 +02:00
William Martin
2433475d3f Use forked testscript for token redaction 2024-10-23 14:13:26 +02:00
Andy Feller
6cb25c8a91
Merge pull request #9752 from cli/dependabot/go_modules/github.com/gabriel-vasile/mimetype-1.4.6
build(deps): bump github.com/gabriel-vasile/mimetype from 1.4.5 to 1.4.6
2024-10-17 13:05:32 -04:00
Tyler McGoffin
44fdb3320d Upgrade go-gh version to 2.11.0 2024-10-15 11:56:43 -07:00
dependabot[bot]
d709dd5b59
build(deps): bump github.com/gabriel-vasile/mimetype from 1.4.5 to 1.4.6
Bumps [github.com/gabriel-vasile/mimetype](https://github.com/gabriel-vasile/mimetype) from 1.4.5 to 1.4.6.
- [Release notes](https://github.com/gabriel-vasile/mimetype/releases)
- [Commits](https://github.com/gabriel-vasile/mimetype/compare/v1.4.5...v1.4.6)

---
updated-dependencies:
- dependency-name: github.com/gabriel-vasile/mimetype
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2024-10-14 14:22:07 +00:00
William Martin
d7465bdf3c Initial testscript introduction 2024-10-11 16:31:16 +02:00
William Martin
f47af31c46 Bump cli/oauth to 1.1.1 2024-10-09 13:30:37 +02:00
bagtoad
ca01bb8f9c Handle errors from parsing hostname in auth flow 2024-10-08 16:12:40 -06:00
dependabot[bot]
29192daa23
build(deps): bump github.com/theupdateframework/go-tuf/v2
Bumps [github.com/theupdateframework/go-tuf/v2](https://github.com/theupdateframework/go-tuf) from 2.0.0 to 2.0.1.
- [Release notes](https://github.com/theupdateframework/go-tuf/releases)
- [Changelog](https://github.com/theupdateframework/go-tuf/blob/master/.goreleaser.yaml)
- [Commits](https://github.com/theupdateframework/go-tuf/compare/v2.0.0...v2.0.1)

---
updated-dependencies:
- dependency-name: github.com/theupdateframework/go-tuf/v2
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
2024-10-01 18:15:14 +00:00
Kynan Ware
be7631c7c8
Merge branch 'trunk' into dependabot/go_modules/github.com/cpuguy83/go-md2man/v2-2.0.5 2024-09-23 12:27:49 -06:00
dependabot[bot]
1ef71409f3
build(deps): bump github.com/henvic/httpretty from 0.1.3 to 0.1.4
Bumps [github.com/henvic/httpretty](https://github.com/henvic/httpretty) from 0.1.3 to 0.1.4.
- [Commits](https://github.com/henvic/httpretty/compare/v0.1.3...v0.1.4)

---
updated-dependencies:
- dependency-name: github.com/henvic/httpretty
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2024-09-20 14:11:28 +00:00
dependabot[bot]
1511c9f225
build(deps): bump github.com/cpuguy83/go-md2man/v2 from 2.0.4 to 2.0.5
Bumps [github.com/cpuguy83/go-md2man/v2](https://github.com/cpuguy83/go-md2man) from 2.0.4 to 2.0.5.
- [Release notes](https://github.com/cpuguy83/go-md2man/releases)
- [Commits](https://github.com/cpuguy83/go-md2man/compare/v2.0.4...v2.0.5)

---
updated-dependencies:
- dependency-name: github.com/cpuguy83/go-md2man/v2
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2024-09-17 14:28:48 +00:00
William Martin
420d80b498 Update go-gh to use api subdomains 2024-09-16 15:21:42 +02:00
dependabot[bot]
fbdf0ccb75
build(deps): bump github.com/sigstore/sigstore-go from 0.6.1 to 0.6.2
Bumps [github.com/sigstore/sigstore-go](https://github.com/sigstore/sigstore-go) from 0.6.1 to 0.6.2.
- [Release notes](https://github.com/sigstore/sigstore-go/releases)
- [Commits](https://github.com/sigstore/sigstore-go/compare/v0.6.1...v0.6.2)

---
updated-dependencies:
- dependency-name: github.com/sigstore/sigstore-go
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2024-09-11 14:39:44 +00:00
Cody Soyland
8446079656
Upgrade to sigstore-go v0.6.1
Signed-off-by: Cody Soyland <codysoyland@github.com>
2024-09-04 16:38:13 -04:00
dependabot[bot]
0835642d3f
build(deps): bump github.com/creack/pty from 1.1.21 to 1.1.23 (#9459)
Bumps [github.com/creack/pty](https://github.com/creack/pty) from 1.1.21 to 1.1.23.
- [Release notes](https://github.com/creack/pty/releases)
- [Commits](https://github.com/creack/pty/compare/v1.1.21...v1.1.23)

---
updated-dependencies:
- dependency-name: github.com/creack/pty
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-08-14 11:35:19 -07:00