@@ -35,7 +35,7 @@ require (
3535 github.com/google/go-cmp v0.7.0
3636 github.com/google/go-containerregistry v0.20.7
3737 github.com/google/go-github/v63 v63.0.0
38- github.com/google/osv-scalibr v0.3.4
38+ github.com/google/osv-scalibr v0.4.0
3939 github.com/google/uuid v1.6.0
4040 github.com/gorilla/handlers v1.5.2
4141 github.com/gorilla/securecookie v1.1.2
@@ -121,7 +121,7 @@ require (
121121 cyphar.com/go-pathrs v0.2.1 // indirect
122122 deps.dev/api/v3 v3.0.0-20250903005441-604c45d5b44b // indirect
123123 deps.dev/api/v3alpha v0.0.0-20250903005441-604c45d5b44b // indirect
124- deps.dev/util/maven v0.0.0-20250903005441-604c45d5b44b // indirect
124+ deps.dev/util/maven v0.0.0-20251104021112-20ad94767ddf // indirect
125125 deps.dev/util/pypi v0.0.0-20250903005441-604c45d5b44b // indirect
126126 deps.dev/util/resolve v0.0.0-20250903005441-604c45d5b44b // indirect
127127 deps.dev/util/semver v0.0.0-20250903005441-604c45d5b44b // indirect
@@ -145,6 +145,7 @@ require (
145145 github.com/agext/levenshtein v1.2.3 // indirect
146146 github.com/alecthomas/chroma/v2 v2.18.0 // indirect
147147 github.com/alecthomas/participle/v2 v2.1.4 // indirect
148+ github.com/anchore/go-lzo v0.1.0 // indirect
148149 github.com/anchore/go-struct-converter v0.0.0-20240925125616-a0883641c664 // indirect
149150 github.com/antithesishq/antithesis-sdk-go v0.4.3-default-no-op // indirect
150151 github.com/antlr4-go/antlr/v4 v4.13.1 // indirect
@@ -173,6 +174,7 @@ require (
173174 github.com/charmbracelet/x/exp/slice v0.0.0-20250616121729-19b66ab4499b // indirect
174175 github.com/charmbracelet/x/term v0.2.1 // indirect
175176 github.com/cncf/xds/go v0.0.0-20251022180443-0feb69152e9f // indirect
177+ github.com/compose-spec/compose-go/v2 v2.8.1 // indirect
176178 github.com/containerd/cgroups/v3 v3.1.0 // indirect
177179 github.com/containerd/containerd v1.7.29 // indirect
178180 github.com/containerd/containerd/api v1.10.0 // indirect
@@ -190,14 +192,19 @@ require (
190192 github.com/decred/dcrd/dcrec/secp256k1/v4 v4.4.0 // indirect
191193 github.com/deitch/magic v0.0.0-20240306090643-c67ab88f10cb // indirect
192194 github.com/dimchansky/utfbom v1.1.1 // indirect
195+ github.com/diskfs/go-diskfs v1.7.0 // indirect
193196 github.com/distribution/reference v0.6.0 // indirect
197+ github.com/djherbis/times v1.6.0 // indirect
194198 github.com/dlclark/regexp2 v1.11.5 // indirect
195199 github.com/docker/go-connections v0.6.0 // indirect
196200 github.com/docker/go-events v0.0.0-20190806004212-e31b211e4f1c // indirect
197201 github.com/docker/go-units v0.5.0 // indirect
202+ github.com/dsoprea/go-exfat v0.0.0-20190906070738-5e932fbdb589 // indirect
203+ github.com/dsoprea/go-logging v0.0.0-20200710184922-b02d349568dd // indirect
198204 github.com/dustin/go-humanize v1.0.1 // indirect
199205 github.com/edsrzf/mmap-go v1.1.0 // indirect
200206 github.com/elliotchance/orderedmap v1.8.0 // indirect
207+ github.com/elliotwutingfeng/asciiset v0.0.0-20230602022725-51bbb787efab // indirect
201208 github.com/emicklei/go-restful/v3 v3.13.0 // indirect
202209 github.com/envoyproxy/go-control-plane/envoy v1.35.0 // indirect
203210 github.com/envoyproxy/protoc-gen-validate v1.2.1 // indirect
@@ -207,6 +214,7 @@ require (
207214 github.com/felixge/httpsnoop v1.0.4 // indirect
208215 github.com/fxamacker/cbor/v2 v2.9.0 // indirect
209216 github.com/go-chi/chi/v5 v5.2.3 // indirect
217+ github.com/go-errors/errors v1.0.2 // indirect
210218 github.com/go-jose/go-jose/v4 v4.1.3 // indirect
211219 github.com/go-ole/go-ole v1.2.6 // indirect
212220 github.com/go-openapi/swag/cmdutils v0.24.0 // indirect
@@ -220,6 +228,7 @@ require (
220228 github.com/go-openapi/swag/stringutils v0.25.1 // indirect
221229 github.com/go-openapi/swag/typeutils v0.25.1 // indirect
222230 github.com/go-openapi/swag/yamlutils v0.25.1 // indirect
231+ github.com/go-restruct/restruct v1.2.0-alpha // indirect
223232 github.com/go-sql-driver/mysql v1.9.3 // indirect
224233 github.com/goccy/go-yaml v1.18.0 // indirect
225234 github.com/gogo/protobuf v1.3.2 // indirect
@@ -256,7 +265,10 @@ require (
256265 github.com/lestrrat-go/jwx/v3 v3.0.12 // indirect
257266 github.com/lestrrat-go/option v1.0.1 // indirect
258267 github.com/lestrrat-go/option/v2 v2.0.0 // indirect
268+ github.com/lunixbochs/struc v0.0.0-20200707160740-784aaebc1d40 // indirect
269+ github.com/masahiro331/go-ext4-filesystem v0.0.0-20240620024024-ca14e6327bbd // indirect
259270 github.com/mattn/go-localereader v0.0.1 // indirect
271+ github.com/mattn/go-shellwords v1.0.12 // indirect
260272 github.com/mfridman/interpolate v0.0.2 // indirect
261273 github.com/micromdm/plist v0.2.1 // indirect
262274 github.com/minio/highwayhash v1.0.4-0.20251030100505-070ab1a87a76 // indirect
@@ -288,8 +300,10 @@ require (
288300 github.com/opencontainers/selinux v1.13.0 // indirect
289301 github.com/openfga/api/proto v0.0.0-20250909172242-b4b2a12f5c67 // indirect
290302 github.com/openfga/language/pkg/go v0.2.0-beta.2.0.20251027165255-0f8f255e5f6c // indirect
291- github.com/ossf/osv-schema/bindings/go v0.0.0-20250805051309-c463400aa925 // indirect
303+ github.com/ossf/osv-schema/bindings/go v0.0.0-20251029033743-5e05f9d00d92 // indirect
292304 github.com/package-url/packageurl-go v0.1.3 // indirect
305+ github.com/pierrec/lz4/v4 v4.1.22 // indirect
306+ github.com/pkg/xattr v0.4.10 // indirect
293307 github.com/planetscale/vtprotobuf v0.6.1-0.20240319094008-0393e58bdf10 // indirect
294308 github.com/pressly/goose/v3 v3.26.0 // indirect
295309 github.com/prometheus/otlptranslator v0.0.2 // indirect
@@ -327,9 +341,11 @@ require (
327341 github.com/tonistiigi/go-csvvalue v0.0.0-20240814133006-030d3b2625d0 // indirect
328342 github.com/transparency-dev/formats v0.0.0-20250421220931-bb8ad4d07c26 // indirect
329343 github.com/transparency-dev/tessera v1.0.0-rc3 // indirect
344+ github.com/ulikunitz/xz v0.5.14 // indirect
330345 github.com/valyala/fastjson v1.6.4 // indirect
331346 github.com/vektah/gqlparser/v2 v2.5.31 // indirect
332347 github.com/x448/float16 v0.8.4 // indirect
348+ github.com/xhit/go-str2duration/v2 v2.1.0 // indirect
333349 github.com/xi2/xz v0.0.0-20171230120015-48954b6210f8 // indirect
334350 github.com/xo/terminfo v0.0.0-20220910002029-abceb7e1c41e // indirect
335351 github.com/yuin/goldmark-emoji v1.0.6 // indirect
@@ -366,11 +382,12 @@ require (
366382 modernc.org/mathutil v1.7.1 // indirect
367383 modernc.org/memory v1.11.0 // indirect
368384 modernc.org/sqlite v1.40.1 // indirect
369- osv.dev/bindings/go v0.0.0-20250808040635-c189436f8791 // indirect
385+ osv.dev/bindings/go v0.0.0-20251029235023-a02c549eeac2 // indirect
370386 sigs.k8s.io/controller-runtime v0.22.4 // indirect
371387 sigs.k8s.io/json v0.0.0-20241014173422-cfa47c3a1cc8 // indirect
372388 sigs.k8s.io/randfill v1.0.0 // indirect
373389 sigs.k8s.io/structured-merge-diff/v6 v6.3.0 // indirect
390+ www.velocidex.com/golang/go-ntfs v0.2.0 // indirect
374391 www.velocidex.com/golang/regparser v0.0.0-20250203141505-31e704a67ef7 // indirect
375392)
376393
0 commit comments