diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 5cc5e93..bd012f4 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -6,8 +6,10 @@ # Retagging keeps the digest, so the existing cosign signature remains valid for the new tag: # verification resolves the tag to the same signed digest. # -# If this job fails with "manifest unknown", the released commit was never built by ci — publish -# releases only for commits that reached main or develop through a push. +# A release published right after a merge races the branch build: ci takes minutes to build, +# scan and push the image, so this job first waits for the image to appear (up to 20 minutes). +# If it never appears, the released commit was never built by ci — publish releases only for +# commits that reached main or develop through a push. name: release on: @@ -30,8 +32,25 @@ jobs: username: ${{ github.actor }} password: ${{ secrets.GITHUB_TOKEN }} + - name: Wait for ci to publish the image for this commit + run: | + for i in $(seq 1 40); do + if docker buildx imagetools inspect "${IMAGE}:${{ github.sha }}" >/dev/null 2>&1; then + echo "image for ${{ github.sha }} is published" + exit 0 + fi + echo "not published yet — the branch build is still running (attempt $i/40)" + sleep 30 + done + echo "ci never published an image for ${{ github.sha }}" >&2 + exit 1 + + # Plain pull → tag → push, deliberately: `buildx imagetools create` wraps a single + # manifest into a NEW manifest list, so the version tag would get a different digest + # than the one ci signed and cosign verification at the tag would find no signature. + # Re-pushing the same manifest keeps the digest, so the signature keeps matching. - name: Point the version tag at the image ci built for this commit run: | - docker buildx imagetools create \ - --tag "${IMAGE}:${{ github.event.release.tag_name }}" \ - "${IMAGE}:${{ github.sha }}" + docker pull "${IMAGE}:${{ github.sha }}" + docker tag "${IMAGE}:${{ github.sha }}" "${IMAGE}:${{ github.event.release.tag_name }}" + docker push "${IMAGE}:${{ github.event.release.tag_name }}" diff --git a/CHANGELOG.md b/CHANGELOG.md index aae36d8..30bbb91 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -3,6 +3,63 @@ Notable changes to this service, newest first, per release. This file is written for whoever runs the service or integrates against it. +## v0.1.1 + +### Fixed — a version tag points at the signed image digest again + +Publishing a release re-pointed the version tag by rewrapping the image manifest into a new +manifest list, which gave the tag a **different digest from the one the signature covers** — so +verifying the signature on a version tag failed. The retag is now a plain pull, tag and push, which +keeps the digest and therefore keeps the signature valid. Separately, a release published right +after a merge could race the branch build; the job now waits for the image to be published before +tagging. + +**A version tag published before this needs one release re-publish** to be re-pointed at the signed +digest. Verifying the rolling `:develop` or `:latest` tag was never affected. + +### Changed — the metrics endpoint no longer offers OpenMetrics + +A scraper that asked for the OpenMetrics format by sending `Accept: application/openmetrics-text` +used to be answered in it, with the `# EOF` terminator that format requires. This service now +answers in the Prometheus text format whatever the scraper asks for, and writes no `# EOF`: + +```http +GET /metrics +Accept: application/openmetrics-text + +200 OK +Content-Type: text/plain; version=0.0.4; charset=utf-8 +``` + +**The metric names, labels and values are unchanged**, so Prometheus — and anything else that +accepts the plain-text exposition format — needs nothing done. Two setups need a look: a scrape +configuration that *requires* the OpenMetrics content type, and a check that reads a missing +`# EOF` as a truncated scrape. Both need their expectation relaxed. + +The endpoint itself is unchanged otherwise: still `/metrics` (or `METRICS_PATH`), still enabled by +default, and still answered only for trusted addresses (`METRICS_TRUSTED_IPS`, `127.0.0.1` by +default) — so if nothing scrapes this service, there is nothing to do. The change arrives from the +web framework this service is built on rather than from a change of its own, carried in with the +shared libraries below. + +### Notes + +- The shared libraries moved to their current releases — the auth client at v0.21.0 and the + platform kit at v1.11.2 — which carried the web framework, the HTTP stack and the JOSE library up + with them. No endpoint, field, error or setting of this service changed, and no configuration + needs touching. The move also clears two published advisories in the cryptography library this + service depends on; a third has no fix available yet and was already present before the move, and + the vulnerability scanner reports nothing this service's own code can reach. + +### Changed — the shared libraries move to their current releases + +`go-platform-kit` v1.11.3, `go-authbyte` v0.23.1 and `go-sec-events` v1.2.1, plus the image +library `golang.org/x/image` to v0.46.0. No endpoint, field, error or setting changes with them, +nothing in your configuration needs touching, and rendering behaviour is unchanged. Two crossed +releases are worth naming: `go-authbyte` v0.23.0 added a way to tell a natural person's identity +code from an organisation's, and `go-sec-events` v1.2.0 allows a security event to be emitted from +work with no request behind it. Both are additions to the libraries. + ## v0.1.0 — 2026-09-01 Initial code. diff --git a/go.mod b/go.mod index 36029d6..f8f4b36 100644 --- a/go.mod +++ b/go.mod @@ -3,24 +3,23 @@ module github.com/go-make-bytes/previewbyte go 1.27.0 require ( - azugo.io/azugo v0.38.0 - azugo.io/core v0.38.0 - github.com/gmb-lib/go-authbyte v0.20.2 - github.com/gmb-lib/go-platform-kit v1.11.1 - github.com/gmb-lib/go-sec-events v1.1.4 + azugo.io/azugo v0.38.1 + azugo.io/core v0.38.1 + github.com/gmb-lib/go-authbyte v0.23.1 + github.com/gmb-lib/go-platform-kit v1.11.3 + github.com/gmb-lib/go-sec-events v1.2.1 github.com/go-quicktest/qt v1.102.0 github.com/klippa-app/go-pdfium v1.19.8 github.com/spf13/cobra v1.10.2 github.com/spf13/viper v1.21.0 - github.com/valyala/fasthttp v1.73.0 + github.com/valyala/fasthttp v1.74.0 go.uber.org/zap v1.28.0 - golang.org/x/image v0.45.0 + golang.org/x/image v0.46.0 ) require ( - azugo.io/opentelemetry v0.38.0 // indirect + azugo.io/opentelemetry v0.38.1 // indirect github.com/VictoriaMetrics/metrics v1.44.0 // indirect - github.com/andybalholm/brotli v1.2.3 // indirect github.com/cenkalti/backoff/v5 v5.0.3 // indirect github.com/cenkalti/backoff/v7 v7.0.0 // indirect github.com/cespare/xxhash/v2 v2.3.0 // indirect @@ -29,12 +28,12 @@ require ( github.com/felixge/httpsnoop v1.1.0 // indirect github.com/fsnotify/fsnotify v1.10.1 // indirect github.com/gabriel-vasile/mimetype v1.4.15 // indirect - github.com/go-jose/go-jose/v4 v4.1.4 // indirect + github.com/go-jose/go-jose/v4 v4.1.5 // indirect github.com/go-logr/logr v1.4.4 // indirect github.com/go-logr/stdr v1.2.2 // indirect github.com/go-playground/locales v0.14.1 // indirect github.com/go-playground/universal-translator v0.18.1 // indirect - github.com/go-playground/validator/v10 v10.30.3 // indirect + github.com/go-playground/validator/v10 v10.30.4 // indirect github.com/go-viper/mapstructure/v2 v2.5.0 // indirect github.com/goccy/go-json v0.10.6 // indirect github.com/golang-jwt/jwt/v5 v5.3.1 // indirect @@ -43,7 +42,7 @@ require ( github.com/grpc-ecosystem/grpc-gateway/v2 v2.30.0 // indirect github.com/inconshreveable/mousetrap v1.1.0 // indirect github.com/jolestar/go-commons-pool/v2 v2.1.2 // indirect - github.com/klauspost/compress v1.19.2 // indirect + github.com/klauspost/compress v1.20.0 // indirect github.com/kr/pretty v0.3.1 // indirect github.com/kr/text v0.2.0 // indirect github.com/lafriks/http2 v0.6.1 // indirect @@ -51,6 +50,7 @@ require ( github.com/leodido/go-urn v1.5.0 // indirect github.com/mattn/go-colorable v0.1.15 // indirect github.com/mattn/go-isatty v0.0.24 // indirect + github.com/molecule-man/go-brrr v1.1.0 // indirect github.com/oklog/ulid/v2 v2.1.2 // indirect github.com/pelletier/go-toml/v2 v2.4.3 // indirect github.com/pkg/errors v0.9.1 // indirect @@ -87,12 +87,12 @@ require ( go.uber.org/atomic v1.11.0 // indirect go.uber.org/multierr v1.11.0 // indirect go.yaml.in/yaml/v3 v3.0.5 // indirect - golang.org/x/crypto v0.55.0 // indirect - golang.org/x/net v0.58.0 // indirect - golang.org/x/sys v0.47.0 // indirect - golang.org/x/text v0.41.0 // indirect - google.golang.org/genproto/googleapis/api v0.0.0-20260825221802-da73d73af1c5 // indirect - google.golang.org/genproto/googleapis/rpc v0.0.0-20260825221802-da73d73af1c5 // indirect + golang.org/x/crypto v0.57.0 // indirect + golang.org/x/net v0.59.0 // indirect + golang.org/x/sys v0.48.0 // indirect + golang.org/x/text v0.42.0 // indirect + google.golang.org/genproto/googleapis/api v0.0.0-20260911204522-f61a6ca850bd // indirect + google.golang.org/genproto/googleapis/rpc v0.0.0-20260911204522-f61a6ca850bd // indirect google.golang.org/grpc v1.83.2 // indirect google.golang.org/protobuf v1.36.12 // indirect ) diff --git a/go.sum b/go.sum index 3990ae2..71ca8a5 100644 --- a/go.sum +++ b/go.sum @@ -1,15 +1,13 @@ -azugo.io/azugo v0.38.0 h1:YzNWdU21vK51MfeN58HnSa4xLQyMA4QlVZc+Pw4qnDk= -azugo.io/azugo v0.38.0/go.mod h1:YvKHoiKDbBQsdCMigUNjk6Q6J6Vyt+iyxpa4YgpUbrk= -azugo.io/core v0.38.0 h1:r1ZtL5sa5tSyeCY3b9ahTrNaZoCCwjb/t50BfBvRpno= -azugo.io/core v0.38.0/go.mod h1:/9fS927/BWXVYCjT7YWUqsOwApJBxBKGaFuEOQBmp1M= -azugo.io/opentelemetry v0.38.0 h1:qxzMWQz+nuhVrVMw9JE5XIkIvln/nh1n0Wu/1mCikeE= -azugo.io/opentelemetry v0.38.0/go.mod h1:Kymw6v9N/798FWcV5wnJwnw7yu6HZBAVdO4sryE080g= +azugo.io/azugo v0.38.1 h1:Muvr02Q7ssxs2oUpxeY+b1PfxTqz9JtjjCcg7FdcI4E= +azugo.io/azugo v0.38.1/go.mod h1:PH/aONUxq6QDuGiveD1uBl3EL/CoV8bcjiTXn+fC4g4= +azugo.io/core v0.38.1 h1:+MjyLCZkVtl0HAr4VhJi1F+RkkD+LWu4hXU4pTjSdmk= +azugo.io/core v0.38.1/go.mod h1:knobHOHMmF28FK/b/nOKcZ81RUKwBzy9vp7NrTigCaQ= +azugo.io/opentelemetry v0.38.1 h1:zqCdxCB1pVRsShVWxK/P2cHwtAxQl3VL9c3BIWm0158= +azugo.io/opentelemetry v0.38.1/go.mod h1:PZbsFyUJgGEhW3khqsFTdumJJqy2uSjJxMNmJjaMhm4= github.com/Masterminds/semver/v3 v3.4.0 h1:Zog+i5UMtVoCU8oKka5P7i9q9HgrJeGzI9SA1Xbatp0= github.com/Masterminds/semver/v3 v3.4.0/go.mod h1:4V+yj/TJE1HU9XfppCwVMZq3I84lprf4nC11bSS5beM= github.com/VictoriaMetrics/metrics v1.44.0 h1:Fr8yqQSV+ZfYaDD/anqk1E8e9YPgfleSleJmAI0M0Tw= github.com/VictoriaMetrics/metrics v1.44.0/go.mod h1:xDM82ULLYCYdFRgQ2JBxi8Uf1+8En1So9YUwlGTOqTc= -github.com/andybalholm/brotli v1.2.3 h1:8H1qwOkl2LPfjf3YezB90JnCliZb6SInJ/OJkEbA5NQ= -github.com/andybalholm/brotli v1.2.3/go.mod h1:rzTDkvFWvIrjDXZHkuS16NPggd91W3kUSvPlQ1pLaKY= github.com/bsm/ginkgo/v2 v2.12.0 h1:Ny8MWAHyOepLGlLKYmXG4IEkioBysk6GpaRTLC8zwWs= github.com/bsm/ginkgo/v2 v2.12.0/go.mod h1:SwYbGRRDovPVboqFv0tPTcG1sN61LM1Z4ARdbAV9g4c= github.com/bsm/gomega v1.27.10 h1:yeMWxP2pV2fG3FgAODIY8EiRE3dy0aeFYt4l7wh6yKA= @@ -40,14 +38,14 @@ github.com/fsnotify/fsnotify v1.10.1 h1:b0/UzAf9yR5rhf3RPm9gf3ehBPpf0oZKIjtpKrx5 github.com/fsnotify/fsnotify v1.10.1/go.mod h1:TLheqan6HD6GBK6PrDWyDPBaEV8LspOxvPSjC+bVfgo= github.com/gabriel-vasile/mimetype v1.4.15 h1:05iP/CYtZ/w455R/KZM6rZ5ieAdh99UPtd+d3YzLmaI= github.com/gabriel-vasile/mimetype v1.4.15/go.mod h1:azpTcoLcDZRNgFou5j+APrqQx9HqVPWa6ijYQIIVswQ= -github.com/gmb-lib/go-authbyte v0.20.2 h1:Xcx0DFK0sbUbcwvXu+rhXbnjBBLE3eoD8vwyoEdiw3I= -github.com/gmb-lib/go-authbyte v0.20.2/go.mod h1:L1nVmHM8/Dd0Eod4PzR2vLYFFvaeFf9X2pfcuQt/tWs= -github.com/gmb-lib/go-platform-kit v1.11.1 h1:UG2VTTLByAyH7X1q6cP/RECurFS6wGs9azPxIiUzZtY= -github.com/gmb-lib/go-platform-kit v1.11.1/go.mod h1:/ZCrZUjDBF+CniHa5xah3IfG0P7o6TqMYXK5ojvNkwU= -github.com/gmb-lib/go-sec-events v1.1.4 h1:CWAAG94+YTR+4BVYH9xpp3SclyL34BEsv6U+Mh+1wa4= -github.com/gmb-lib/go-sec-events v1.1.4/go.mod h1:37KRMAxICBrjH517lKTcd8pL3yU0yjAR3Eq7+nJqAew= -github.com/go-jose/go-jose/v4 v4.1.4 h1:moDMcTHmvE6Groj34emNPLs/qtYXRVcd6S7NHbHz3kA= -github.com/go-jose/go-jose/v4 v4.1.4/go.mod h1:x4oUasVrzR7071A4TnHLGSPpNOm2a21K9Kf04k1rs08= +github.com/gmb-lib/go-authbyte v0.23.1 h1:wJlQbkJY9fDQOdWJviLx0XAvKI+OmsLR7vs+lZeo158= +github.com/gmb-lib/go-authbyte v0.23.1/go.mod h1:hRgIYyht9dp5O9j1uKGCCeZd9EdRElAlM/ab0WwbW34= +github.com/gmb-lib/go-platform-kit v1.11.3 h1:jTkfSX/u3EzY6f4htPeUZ8Bhnz0qlhYyXoPH5YdpCMg= +github.com/gmb-lib/go-platform-kit v1.11.3/go.mod h1:3FiQ38e5OoSwyMXoysNzdN85/s0ci/nmG1SHhniyD0g= +github.com/gmb-lib/go-sec-events v1.2.1 h1:qga2AexhneNM92aCASfbhJOAiMV3piy5FggIF1SlQ5Q= +github.com/gmb-lib/go-sec-events v1.2.1/go.mod h1:fzg/dwpz7IByCAAAqhk7Pt+rnRCvzSuOW2qEImgVJD4= +github.com/go-jose/go-jose/v4 v4.1.5 h1:RjgjO2LOtWOJKUC5wpwY9LR3B3vwVAz6JS2YHfYU6eA= +github.com/go-jose/go-jose/v4 v4.1.5/go.mod h1:x4oUasVrzR7071A4TnHLGSPpNOm2a21K9Kf04k1rs08= github.com/go-logr/logr v1.2.2/go.mod h1:jdQByPbusPIv2/zmleS9BjJVeZ6kBagPoEUsqbVz/1A= github.com/go-logr/logr v1.4.4 h1:tG4xh9yMsRCAiodLVTxyrkzSZ9+o0L1Kg/+cPVcbP/8= github.com/go-logr/logr v1.4.4/go.mod h1:9T104GzyrTigFIr8wt5mBrctHMim0Nb2HLGrmQ40KvY= @@ -59,8 +57,8 @@ github.com/go-playground/locales v0.14.1 h1:EWaQ/wswjilfKLTECiXz7Rh+3BjFhfDFKv/o github.com/go-playground/locales v0.14.1/go.mod h1:hxrqLVvrK65+Rwrd5Fc6F2O76J/NuW9t0sjnWqG1slY= github.com/go-playground/universal-translator v0.18.1 h1:Bcnm0ZwsGyWbCzImXv+pAJnYK9S473LQFuzCbDbfSFY= github.com/go-playground/universal-translator v0.18.1/go.mod h1:xekY+UJKNuX9WP91TpwSH2VMlDf28Uj24BCp08ZFTUY= -github.com/go-playground/validator/v10 v10.30.3 h1:4MU6YkEwx7GbcPJOZxrtbu+QfF3pJLJuaYTeAH0DYy8= -github.com/go-playground/validator/v10 v10.30.3/go.mod h1:4Axh7oCNGcoGkqLoE4YWt6n20mcEIsPRlB7vPk3lpyc= +github.com/go-playground/validator/v10 v10.30.4 h1:9Rcod2ZPO6mOEG6b4GqyoHE/H6//Ze0RuhOo1hT1x0w= +github.com/go-playground/validator/v10 v10.30.4/go.mod h1:numpT+RPLE91R9oYWMY/R9zRgJBewr3IXHko4OISPpk= github.com/go-quicktest/qt v1.102.0 h1:HSQxCeh5YZH3EL3W39ixjtyaEhcWSXQHtHnMBzSs474= github.com/go-quicktest/qt v1.102.0/go.mod h1:p4lGIVX+8Wa6ZPNDvqcxq36XpUDLh42FLetFU7odllI= github.com/go-task/slim-sprig/v3 v3.0.0 h1:sUs3vkvUymDpBKi3qH1YSqBQk9+9D/8M2mN1vB6EwHI= @@ -85,8 +83,8 @@ github.com/inconshreveable/mousetrap v1.1.0 h1:wN+x4NVGpMsO7ErUn/mUI3vEoE6Jt13X2 github.com/inconshreveable/mousetrap v1.1.0/go.mod h1:vpF70FUmC8bwa3OWnCshd2FqLfsEA9PFc4w1p2J65bw= github.com/jolestar/go-commons-pool/v2 v2.1.2 h1:E+XGo58F23t7HtZiC/W6jzO2Ux2IccSH/yx4nD+J1CM= github.com/jolestar/go-commons-pool/v2 v2.1.2/go.mod h1:r4NYccrkS5UqP1YQI1COyTZ9UjPJAAGTUxzcsK1kqhY= -github.com/klauspost/compress v1.19.2 h1:hMRETovs/pu/dVWN7zIT1PGG8t509MwT6bO7XSi26R8= -github.com/klauspost/compress v1.19.2/go.mod h1:cwPg85FWrGar70rWktvGQj8/hthj3wpl0PGDogxkrSQ= +github.com/klauspost/compress v1.20.0 h1:a3C1ke2ohxFymNlb2HWAHjDeKCI90scRskErZkR0ezA= +github.com/klauspost/compress v1.20.0/go.mod h1:LUdAzn7YLVvxLpc7y3V1m40wESHTgc1422pwwBSKYuI= github.com/klauspost/cpuid/v2 v2.2.10 h1:tBs3QSyvjDyFTq3uoc/9xFpCuOsJQFNPiAhYdw2skhE= github.com/klauspost/cpuid/v2 v2.2.10/go.mod h1:hqwkgyIinND0mEev00jJYCxPNVRVXFQeu1XKlok6oO0= github.com/klippa-app/go-pdfium v1.19.8 h1:YxEOpo4pShbtcRDlvlryUNL8IK8fqxjU0qGbrct/nEk= @@ -105,6 +103,8 @@ github.com/mattn/go-colorable v0.1.15 h1:+u9SLTRGnXv73cEsnsmoZBom+dMU88B2M0aDcWy github.com/mattn/go-colorable v0.1.15/go.mod h1:6LmQG8QLFO4G5z1gPvYEzlUgJ2wF+stgPZH1UqBm1s8= github.com/mattn/go-isatty v0.0.24 h1:tGZZoVgT/KiqK1c8ocVLeDS8BSWMRd47J3Lbz7vsReI= github.com/mattn/go-isatty v0.0.24/go.mod h1:nMCL3Zebbrt45jsMDgnfIwz6ydEQApk5oEI3HqDio6A= +github.com/molecule-man/go-brrr v1.1.0 h1:rLBGSXA393y+5ttCBLkW34CHESop5tahrOFxVv/XDEU= +github.com/molecule-man/go-brrr v1.1.0/go.mod h1:7ybW6/7gA3oKY45jOfVNjSJDtrr6ea4tzbsTkjmQDC4= github.com/oklog/ulid/v2 v2.1.2 h1:IEclFb9JNvzYA6MW2SCxbLzcHTVsfqm3PrqGQJH5zec= github.com/oklog/ulid/v2 v2.1.2/go.mod h1:rcEKHmBBKfef9DhnvX7y1HZBYxjXb0cP5ExxNsTT1QQ= github.com/onsi/ginkgo/v2 v2.32.0 h1:Hw7s2pVrQo/8Yz5N77qdnpHaoc+c6cC9WIV1Jce+J6E= @@ -149,14 +149,12 @@ github.com/valkey-io/valkey-go v1.0.77 h1:0H5yQ8cOkISr5mU4NDNIgjHvA7bPs2ijgymPjB github.com/valkey-io/valkey-go v1.0.77/go.mod h1:gvC/r2m3eW4Hbj0YnjogTzNtFdPSM/D+NCqen+5OABM= github.com/valyala/bytebufferpool v1.0.0 h1:GqA5TC/0021Y/b9FG4Oi9Mr3q7XYx6KllzawFIhcdPw= github.com/valyala/bytebufferpool v1.0.0/go.mod h1:6bBcMArwyJ5K/AmCkWv1jt77kVWyCJ6HpOuEn7z0Csc= -github.com/valyala/fasthttp v1.73.0 h1:ocTOORnBWtJ+P8t/6wAjdkchMzdfHmWx2VD/DPbgZ7s= -github.com/valyala/fasthttp v1.73.0/go.mod h1:EtXQDHaR+5P18p8wqDRFpUhxr108Ga9mXvVJXHRrN2k= +github.com/valyala/fasthttp v1.74.0 h1:wMS9fnO2QTALozYx5pId2Vi7ZwU/epUkY8i/KPWCHoU= +github.com/valyala/fasthttp v1.74.0/go.mod h1:3ARmLamUcw7ElxVtC8PXaGzQ6VEuvnetlkrwIklQBSE= github.com/valyala/fastrand v1.1.0 h1:f+5HkLW4rsgzdNoleUOB69hyT9IlD2ZQh9GyDMfb5G8= github.com/valyala/fastrand v1.1.0/go.mod h1:HWqCzkrkg6QXT8V2EXWvXCoow7vLwOFN002oeRzjapQ= github.com/valyala/histogram v1.2.0 h1:wyYGAZZt3CpwUiIb9AU/Zbllg1llXyrtApRS815OLoQ= github.com/valyala/histogram v1.2.0/go.mod h1:Hb4kBwb4UxsaNbbbh+RRz8ZR6pdodR57tzWUS3BUzXY= -github.com/xyproto/randomstring v1.0.5 h1:YtlWPoRdgMu3NZtP45drfy1GKoojuR7hmRcnhZqKjWU= -github.com/xyproto/randomstring v1.0.5/go.mod h1:rgmS5DeNXLivK7YprL0pY+lTuhNQW3iGxZ18UQApw/E= github.com/zeebo/xxh3 v1.1.0 h1:s7DLGDK45Dyfg7++yxI0khrfwq9661w9EN78eP/UZVs= github.com/zeebo/xxh3 v1.1.0/go.mod h1:IisAie1LELR4xhVinxWS5+zf1lA4p0MW4T+w+W07F5s= go.elastic.co/ecszap v1.0.3 h1:RQtagS3uSftE8mPZ3msqb6mVI67jgcDuy1PUqiMv8ow= @@ -210,28 +208,28 @@ go.uber.org/zap v1.28.0/go.mod h1:rDLpOi171uODNm/mxFcuYWxDsqWSAVkFdX4XojSKg/Q= go.yaml.in/yaml/v3 v3.0.4/go.mod h1:DhzuOOF2ATzADvBadXxruRBLzYTpT36CKvDb3+aBEFg= go.yaml.in/yaml/v3 v3.0.5 h1:N6y/pJk8buWs9NY5ERU2HSMfm+IuD/OtfdAnq6kESPw= go.yaml.in/yaml/v3 v3.0.5/go.mod h1:HVTZu1O7/Vkt2N+BFy8Zza+lnLsABggaTM2ZpNIGuKg= -golang.org/x/crypto v0.55.0 h1:+KWHjbgOaAQ66dh/YlkZKHlz9ZUlq61AFirAR9ntP8M= -golang.org/x/crypto v0.55.0/go.mod h1:uq0V9dE/fzQuJtbnL+2EhWOE63vo164FY8xqEnV9xis= -golang.org/x/image v0.45.0 h1:FMb1nTbH5H9vF55SriQHgFw5GnNL9Jg6L25BwXKzhB0= -golang.org/x/image v0.45.0/go.mod h1:n62x/7RqlwXDvGsSU4u6IUTUf6KghUZ9Bt7cG/T9Fx4= -golang.org/x/mod v0.38.0 h1:MECBjubtXD7yj4HrhIUcywNaGeNVUdfVnxmPajOk4yk= -golang.org/x/mod v0.38.0/go.mod h1:V6Xz0pq8TQ3dGqVQ1FVHuelZpAL0uNhSkk9ogYP3c40= -golang.org/x/net v0.58.0 h1:ynWG7rqYi4ccpTEuPZ2QGWHktVEM9DMCj9yzDE0Q7To= -golang.org/x/net v0.58.0/go.mod h1:YwCddHnFlT7eLQqVprV19OnhLGtc5xOKgE0RyqgfWAU= -golang.org/x/sync v0.22.0 h1:SZjpbeLmrCk4xhRSZFNZW5gFUeCeFgjekvI/+gfScek= -golang.org/x/sync v0.22.0/go.mod h1:9xrNwdLfx4jkKbNva9FpL6vEN7evnE43NNNJQ2LF3+0= -golang.org/x/sys v0.47.0 h1:o7XGOvZQCADBQQ4Y7VNq2dRWQR7JmOUW8Kxx4ZsNgWs= -golang.org/x/sys v0.47.0/go.mod h1:4GL1E5IUh+htKOUEOaiffhrAeqysfVGipDYzABqnCmw= -golang.org/x/text v0.41.0 h1:vz/seA0lnX87Othu2f/0L24RcgrXD9/YFTSuGjj3rH8= -golang.org/x/text v0.41.0/go.mod h1:jvf1O8ajNzZqhSrQBPbutR/EB83Cc0CFrezNQIwbb5M= -golang.org/x/tools v0.48.0 h1:3+hClM1aLL5mjMKm5ovokw9epgRXPuu2tILgismM6RE= -golang.org/x/tools v0.48.0/go.mod h1:08xX0orndb/F7jJxGDicx061tyd5pcMto75YMAXr6lk= +golang.org/x/crypto v0.57.0 h1:3ZVCjf8Ggz7zneR/EHRVx68Ctf+2pmIMP2UFhh9cC6M= +golang.org/x/crypto v0.57.0/go.mod h1:Fdz0i5U6CoizGwLda9DttjSk6qlZo25zYNtR+ycvuZA= +golang.org/x/image v0.46.0 h1:b1+oYj0Jbp6K5MDT4i4/eZpYlk3V8SJhhDKh6LBHAyQ= +golang.org/x/image v0.46.0/go.mod h1:3B3W05VGVQyuXucLINLjXKrqISASfi4Xj+iCVkLMwew= +golang.org/x/mod v0.41.0 h1:qJmnOUb4YB+FsEuM3HcWucdZASCPGhsX6uljO6pog0c= +golang.org/x/mod v0.41.0/go.mod h1:Ek9pY8RKWXwsWvd3rQiHYtMqkjSUV+s1Rj7j4H5Ur6o= +golang.org/x/net v0.59.0 h1:5zfYln+w5XCxwrnMMJPufRgNoXEaGxl0wo5GqPXyues= +golang.org/x/net v0.59.0/go.mod h1:2DA/G1UfVbCpQPeWTmMPGY7Cs2PkBkwu743bVX5PIVg= +golang.org/x/sync v0.23.0 h1:KameEIfc1IkluZyXWLn39Wd4tURc6GbCiISGiZm2bQk= +golang.org/x/sync v0.23.0/go.mod h1:sUUOizhqBxiL6pEWpqNLUiaJn1ShEbZ6BBqskPbjZm0= +golang.org/x/sys v0.48.0 h1:bbX/i/6MgT9BVLM9RT1thmxL04yeTAhbEz4SyadbXoo= +golang.org/x/sys v0.48.0/go.mod h1:hNLxWAXmnKAxqDtdwIYC4bM9oQPEecfsnNMuSxOs3og= +golang.org/x/text v0.42.0 h1:JbOZXgfeCPU9gacVtYliJqOhD+zhrEqK4LfdpmlUZqI= +golang.org/x/text v0.42.0/go.mod h1:ojzP1Z+2QtioaF8DTtO8K5q7JWVVYwZKenzujK0Zd0E= +golang.org/x/tools v0.49.0 h1:3NI7VXzL9+1WZD52Dx2ttoPwD5DWrFGpl9mFZDlmisI= +golang.org/x/tools v0.49.0/go.mod h1:SJNXV9DBKT0UbdttsQjbfJlAE/q+y36++zo3uL3N0Oo= gonum.org/v1/gonum v0.17.0 h1:VbpOemQlsSMrYmn7T2OUvQ4dqxQXU+ouZFQsZOx50z4= gonum.org/v1/gonum v0.17.0/go.mod h1:El3tOrEuMpv2UdMrbNlKEh9vd86bmQ6vqIcDwxEOc1E= -google.golang.org/genproto/googleapis/api v0.0.0-20260825221802-da73d73af1c5 h1:izFU9hz7aeLI/Mi1J0991ae+xcwRLr7hTqWnB/9aIIU= -google.golang.org/genproto/googleapis/api v0.0.0-20260825221802-da73d73af1c5/go.mod h1:3LhxRw4YYkf+ylAfgaY9JlVLFKhokkCV8duhLLe7+t0= -google.golang.org/genproto/googleapis/rpc v0.0.0-20260825221802-da73d73af1c5 h1:1VUiZAXyC+zmiFYi+WLtBzr68Cj8wOofHjjrA/kkizc= -google.golang.org/genproto/googleapis/rpc v0.0.0-20260825221802-da73d73af1c5/go.mod h1:DjtHYE8FKJLivXcBEjGwndXfIC23G0VpXiXKqG179uA= +google.golang.org/genproto/googleapis/api v0.0.0-20260911204522-f61a6ca850bd h1:jgCQeWccunvocKNK2RjhQHNiSjSeMMuBpQ/5pbP+2lA= +google.golang.org/genproto/googleapis/api v0.0.0-20260911204522-f61a6ca850bd/go.mod h1:r4KD2hOq82JBWpTWkJ9NZLf6EwmRvAPIFmk7hPNtd+0= +google.golang.org/genproto/googleapis/rpc v0.0.0-20260911204522-f61a6ca850bd h1:29LZPNIJg+GEmJwZXruJJRwqy/wnWAYZXDtROToV/aQ= +google.golang.org/genproto/googleapis/rpc v0.0.0-20260911204522-f61a6ca850bd/go.mod h1:DjtHYE8FKJLivXcBEjGwndXfIC23G0VpXiXKqG179uA= google.golang.org/grpc v1.83.2 h1:EManeRomTObA0BU7I8vXgg/78uE5MJ9M8B39EX2WscU= google.golang.org/grpc v1.83.2/go.mod h1:YPI1hK3kDked6iHvgX3tR0y+nX/qpMFKhPgFsokw1S8= google.golang.org/protobuf v1.36.12 h1:pJOKDDOyeXErUroCihFAd5LQuwXBSpVnKGrj5o/fwxc=