Skip to content

Commit cfb858c

Browse files
committed
fix(deps): lock file maintenance vulnfeeds
1 parent 713c9d7 commit cfb858c

File tree

12 files changed

+190
-200
lines changed

12 files changed

+190
-200
lines changed

vulnfeeds/cmd/alpine/Dockerfile

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -12,7 +12,7 @@
1212
# See the License for the specific language governing permissions and
1313
# limitations under the License.
1414

15-
FROM golang:1.25.1-alpine@sha256:b6ed3fd0452c0e9bcdef5597f29cc1418f61672e9d3a2f55bf02e7222c014abd AS GO_BUILD
15+
FROM golang:1.25.3-alpine@sha256:aee43c3ccbf24fdffb7295693b6e33b21e01baec1b2a55acc351fde345e9ec34 AS GO_BUILD
1616

1717
RUN mkdir /src
1818
WORKDIR /src
@@ -25,7 +25,7 @@ COPY ./ /src/
2525
RUN go build -o alpine-osv ./cmd/alpine/
2626

2727

28-
FROM gcr.io/google.com/cloudsdktool/google-cloud-cli:alpine@sha256:cdac858d976cb0e6bfdc3288fee5a0a7bf6348a009089be130b2009e28463c52
28+
FROM gcr.io/google.com/cloudsdktool/google-cloud-cli:alpine@sha256:4cc94374d91685c978681ee5486ecb92130ef87187d132a1a1eaa9bdd02d6032
2929

3030
WORKDIR /root/
3131
COPY --from=GO_BUILD /src/alpine-osv ./

vulnfeeds/cmd/combine-to-osv/Dockerfile

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -12,7 +12,7 @@
1212
# See the License for the specific language governing permissions and
1313
# limitations under the License.
1414

15-
FROM golang:1.25.1-alpine@sha256:b6ed3fd0452c0e9bcdef5597f29cc1418f61672e9d3a2f55bf02e7222c014abd AS GO_BUILD
15+
FROM golang:1.25.3-alpine@sha256:aee43c3ccbf24fdffb7295693b6e33b21e01baec1b2a55acc351fde345e9ec34 AS GO_BUILD
1616

1717
RUN mkdir /src
1818
WORKDIR /src
@@ -26,7 +26,7 @@ RUN go build -o combine-to-osv ./cmd/combine-to-osv/
2626
RUN go build -o download-cves ./cmd/download-cves/
2727

2828

29-
FROM gcr.io/google.com/cloudsdktool/google-cloud-cli:alpine@sha256:cdac858d976cb0e6bfdc3288fee5a0a7bf6348a009089be130b2009e28463c52
29+
FROM gcr.io/google.com/cloudsdktool/google-cloud-cli:alpine@sha256:4cc94374d91685c978681ee5486ecb92130ef87187d132a1a1eaa9bdd02d6032
3030
RUN apk --no-cache add jq
3131

3232
WORKDIR /root/

vulnfeeds/cmd/cpe-repo-gen/Dockerfile

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -12,7 +12,7 @@
1212
# See the License for the specific language governing permissions and
1313
# limitations under the License.
1414

15-
FROM golang:1.25.1-alpine@sha256:b6ed3fd0452c0e9bcdef5597f29cc1418f61672e9d3a2f55bf02e7222c014abd AS GO_BUILD
15+
FROM golang:1.25.3-alpine@sha256:aee43c3ccbf24fdffb7295693b6e33b21e01baec1b2a55acc351fde345e9ec34 AS GO_BUILD
1616

1717
RUN mkdir /src
1818
WORKDIR /src
@@ -24,7 +24,7 @@ RUN go mod download
2424
COPY ./ /src/
2525
RUN CGO_ENABLED=0 go build -o cpe-repo-gen ./cmd/cpe-repo-gen
2626

27-
FROM gcr.io/google.com/cloudsdktool/google-cloud-cli:alpine@sha256:cdac858d976cb0e6bfdc3288fee5a0a7bf6348a009089be130b2009e28463c52
27+
FROM gcr.io/google.com/cloudsdktool/google-cloud-cli:alpine@sha256:4cc94374d91685c978681ee5486ecb92130ef87187d132a1a1eaa9bdd02d6032
2828

2929
RUN apk add --no-cache unzip
3030

vulnfeeds/cmd/cve-bulk-converter/Dockerfile

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -12,7 +12,7 @@
1212
# See the License for the specific language governing permissions and
1313
# limitations under the License.
1414

15-
FROM golang:1.25.1-alpine@sha256:b6ed3fd0452c0e9bcdef5597f29cc1418f61672e9d3a2f55bf02e7222c014abd AS go_build
15+
FROM golang:1.25.3-alpine@sha256:aee43c3ccbf24fdffb7295693b6e33b21e01baec1b2a55acc351fde345e9ec34 AS go_build
1616

1717
RUN mkdir /src
1818
WORKDIR /src
@@ -25,7 +25,7 @@ RUN go mod download && go mod verify
2525
COPY ./ /src/
2626
RUN go build -o cve-bulk-converter ./cmd/cve-bulk-converter/
2727

28-
FROM gcr.io/google.com/cloudsdktool/google-cloud-cli:alpine@sha256:cdac858d976cb0e6bfdc3288fee5a0a7bf6348a009089be130b2009e28463c52
28+
FROM gcr.io/google.com/cloudsdktool/google-cloud-cli:alpine@sha256:4cc94374d91685c978681ee5486ecb92130ef87187d132a1a1eaa9bdd02d6032
2929
RUN apk --no-cache add jq
3030

3131
WORKDIR /root/

vulnfeeds/cmd/debian-copyright-mirror/Dockerfile

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -12,7 +12,7 @@
1212
# See the License for the specific language governing permissions and
1313
# limitations under the License.
1414

15-
FROM gcr.io/google.com/cloudsdktool/google-cloud-cli:alpine@sha256:cdac858d976cb0e6bfdc3288fee5a0a7bf6348a009089be130b2009e28463c52
15+
FROM gcr.io/google.com/cloudsdktool/google-cloud-cli:alpine@sha256:4cc94374d91685c978681ee5486ecb92130ef87187d132a1a1eaa9bdd02d6032
1616

1717
RUN apk add py3-yaml
1818

vulnfeeds/cmd/debian/Dockerfile

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -12,7 +12,7 @@
1212
# See the License for the specific language governing permissions and
1313
# limitations under the License.
1414

15-
FROM golang:1.25.1-alpine@sha256:b6ed3fd0452c0e9bcdef5597f29cc1418f61672e9d3a2f55bf02e7222c014abd AS GO_BUILD
15+
FROM golang:1.25.3-alpine@sha256:aee43c3ccbf24fdffb7295693b6e33b21e01baec1b2a55acc351fde345e9ec34 AS GO_BUILD
1616

1717
RUN mkdir /src
1818
WORKDIR /src
@@ -25,7 +25,7 @@ COPY ./ /src/
2525
RUN go build -o debian ./cmd/debian/
2626

2727

28-
FROM gcr.io/google.com/cloudsdktool/google-cloud-cli:alpine@sha256:cdac858d976cb0e6bfdc3288fee5a0a7bf6348a009089be130b2009e28463c52
28+
FROM gcr.io/google.com/cloudsdktool/google-cloud-cli:alpine@sha256:4cc94374d91685c978681ee5486ecb92130ef87187d132a1a1eaa9bdd02d6032
2929

3030
WORKDIR /root/
3131
COPY --from=GO_BUILD /src/debian ./

vulnfeeds/cmd/download-cves/Dockerfile

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -12,7 +12,7 @@
1212
# See the License for the specific language governing permissions and
1313
# limitations under the License.
1414

15-
FROM golang:1.25.1-alpine@sha256:b6ed3fd0452c0e9bcdef5597f29cc1418f61672e9d3a2f55bf02e7222c014abd AS GO_BUILD
15+
FROM golang:1.25.3-alpine@sha256:aee43c3ccbf24fdffb7295693b6e33b21e01baec1b2a55acc351fde345e9ec34 AS GO_BUILD
1616

1717
RUN mkdir /src
1818
WORKDIR /src
@@ -24,7 +24,7 @@ RUN go mod download
2424
COPY ./ /src/
2525
RUN go build -o download-cves ./cmd/download-cves/
2626

27-
FROM gcr.io/google.com/cloudsdktool/google-cloud-cli:alpine@sha256:cdac858d976cb0e6bfdc3288fee5a0a7bf6348a009089be130b2009e28463c52
27+
FROM gcr.io/google.com/cloudsdktool/google-cloud-cli:alpine@sha256:4cc94374d91685c978681ee5486ecb92130ef87187d132a1a1eaa9bdd02d6032
2828

2929
WORKDIR /usr/local/bin
3030
COPY --from=GO_BUILD /src/download-cves ./

vulnfeeds/cmd/nvd-cve-osv/Dockerfile

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -12,7 +12,7 @@
1212
# See the License for the specific language governing permissions and
1313
# limitations under the License.
1414

15-
FROM golang:1.25.1-alpine@sha256:b6ed3fd0452c0e9bcdef5597f29cc1418f61672e9d3a2f55bf02e7222c014abd AS GO_BUILD
15+
FROM golang:1.25.3-alpine@sha256:aee43c3ccbf24fdffb7295693b6e33b21e01baec1b2a55acc351fde345e9ec34 AS GO_BUILD
1616

1717
WORKDIR /go/src
1818

@@ -22,7 +22,7 @@ RUN go mod download && go mod verify
2222
COPY . .
2323
RUN CGO_ENABLED=0 go build -v -o /usr/local/bin ./cmd/nvd-cve-osv ./cmd/download-cves
2424

25-
FROM gcr.io/google.com/cloudsdktool/google-cloud-cli:alpine@sha256:cdac858d976cb0e6bfdc3288fee5a0a7bf6348a009089be130b2009e28463c52
25+
FROM gcr.io/google.com/cloudsdktool/google-cloud-cli:alpine@sha256:4cc94374d91685c978681ee5486ecb92130ef87187d132a1a1eaa9bdd02d6032
2626
RUN apk --no-cache add jq
2727

2828
COPY --from=GO_BUILD /usr/local/bin/ ./usr/local/bin/

vulnfeeds/go.mod

Lines changed: 24 additions & 24 deletions
Original file line numberDiff line numberDiff line change
@@ -3,33 +3,32 @@ module github.com/google/osv/vulnfeeds
33
go 1.24.6
44

55
require (
6-
cloud.google.com/go/secretmanager v1.15.0
6+
cloud.google.com/go/secretmanager v1.16.0
77
cloud.google.com/go/storage v1.57.0
88
github.com/aquasecurity/go-pep440-version v0.0.1
99
github.com/atombender/go-jsonschema v0.20.0
1010
github.com/charmbracelet/lipgloss v1.1.0
11-
github.com/go-git/go-git/v5 v5.16.2
11+
github.com/go-git/go-git/v5 v5.16.3
1212
github.com/google/go-cmp v0.7.0
1313
github.com/google/osv-scanner v1.9.2
1414
github.com/knqyf263/go-cpe v0.0.0-20230627041855-cb0794d06872
15-
github.com/ossf/osv-schema/bindings/go v0.0.0-20250926044009-f6ae0b6bae32
15+
github.com/ossf/osv-schema/bindings/go v0.0.0-20251021042217-ed6345fb08ca
1616
github.com/sethvargo/go-retry v0.3.0
17-
golang.org/x/exp v0.0.0-20250819193227-8b4c13bb791b
18-
google.golang.org/api v0.247.0
17+
google.golang.org/api v0.253.0
1918
gopkg.in/dnaeon/go-vcr.v4 v4.0.5
2019
gopkg.in/yaml.v2 v2.4.0
2120
)
2221

2322
require (
2423
cel.dev/expr v0.24.0 // indirect
2524
cloud.google.com/go v0.121.6 // indirect
26-
cloud.google.com/go/auth v0.16.5 // indirect
25+
cloud.google.com/go/auth v0.17.0 // indirect
2726
cloud.google.com/go/auth/oauth2adapt v0.2.8 // indirect
28-
cloud.google.com/go/compute/metadata v0.8.0 // indirect
27+
cloud.google.com/go/compute/metadata v0.9.0 // indirect
2928
cloud.google.com/go/iam v1.5.2 // indirect
3029
cloud.google.com/go/monitoring v1.24.2 // indirect
3130
dario.cat/mergo v1.0.2 // indirect
32-
github.com/GoogleCloudPlatform/opentelemetry-operations-go/detectors/gcp v1.27.0 // indirect
31+
github.com/GoogleCloudPlatform/opentelemetry-operations-go/detectors/gcp v1.29.0 // indirect
3332
github.com/GoogleCloudPlatform/opentelemetry-operations-go/exporter/metric v0.53.0 // indirect
3433
github.com/GoogleCloudPlatform/opentelemetry-operations-go/internal/resourcemapping v0.53.0 // indirect
3534
github.com/Microsoft/go-winio v0.6.2 // indirect
@@ -50,7 +49,7 @@ require (
5049
github.com/felixge/httpsnoop v1.0.4 // indirect
5150
github.com/go-git/gcfg v1.5.1-0.20230307220236-3a3c6141e376 // indirect
5251
github.com/go-git/go-billy/v5 v5.6.2 // indirect
53-
github.com/go-jose/go-jose/v4 v4.0.5 // indirect
52+
github.com/go-jose/go-jose/v4 v4.1.2 // indirect
5453
github.com/go-logr/logr v1.4.3 // indirect
5554
github.com/go-logr/stdr v1.2.2 // indirect
5655
github.com/goccy/go-yaml v1.18.0 // indirect
@@ -80,23 +79,24 @@ require (
8079
go.opentelemetry.io/contrib/detectors/gcp v1.36.0 // indirect
8180
go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc v0.61.0 // indirect
8281
go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.61.0 // indirect
83-
go.opentelemetry.io/otel v1.36.0 // indirect
84-
go.opentelemetry.io/otel/metric v1.36.0 // indirect
85-
go.opentelemetry.io/otel/sdk v1.36.0 // indirect
86-
go.opentelemetry.io/otel/sdk/metric v1.36.0 // indirect
87-
go.opentelemetry.io/otel/trace v1.36.0 // indirect
88-
golang.org/x/crypto v0.41.0 // indirect
89-
golang.org/x/net v0.43.0 // indirect
90-
golang.org/x/oauth2 v0.30.0 // indirect
91-
golang.org/x/sync v0.16.0 // indirect
92-
golang.org/x/sys v0.35.0 // indirect
93-
golang.org/x/text v0.28.0 // indirect
94-
golang.org/x/time v0.12.0 // indirect
82+
go.opentelemetry.io/otel v1.37.0 // indirect
83+
go.opentelemetry.io/otel/metric v1.37.0 // indirect
84+
go.opentelemetry.io/otel/sdk v1.37.0 // indirect
85+
go.opentelemetry.io/otel/sdk/metric v1.37.0 // indirect
86+
go.opentelemetry.io/otel/trace v1.37.0 // indirect
87+
golang.org/x/crypto v0.43.0 // indirect
88+
golang.org/x/exp v0.0.0-20251023183803-a4bb9ffd2546 // indirect
89+
golang.org/x/net v0.46.0 // indirect
90+
golang.org/x/oauth2 v0.32.0 // indirect
91+
golang.org/x/sync v0.17.0 // indirect
92+
golang.org/x/sys v0.37.0 // indirect
93+
golang.org/x/text v0.30.0 // indirect
94+
golang.org/x/time v0.14.0 // indirect
9595
golang.org/x/xerrors v0.0.0-20240903120638-7835f813f4da // indirect
9696
google.golang.org/genproto v0.0.0-20250603155806-513f23925822 // indirect
9797
google.golang.org/genproto/googleapis/api v0.0.0-20250818200422-3122310a409c // indirect
98-
google.golang.org/genproto/googleapis/rpc v0.0.0-20250818200422-3122310a409c // indirect
99-
google.golang.org/grpc v1.74.3 // indirect
100-
google.golang.org/protobuf v1.36.7 // indirect
98+
google.golang.org/genproto/googleapis/rpc v0.0.0-20251014184007-4626949a642f // indirect
99+
google.golang.org/grpc v1.76.0 // indirect
100+
google.golang.org/protobuf v1.36.10 // indirect
101101
gopkg.in/warnings.v0 v0.1.2 // indirect
102102
)

0 commit comments

Comments
 (0)