Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion cmd/verify/attestation.go
Original file line number Diff line number Diff line change
Expand Up @@ -11,7 +11,7 @@ import (
"path/filepath"
"strings"

"github.com/google/go-github/v89/github"
"github.com/google/go-github/v91/github"
"github.com/liatrio/autogov/pkg/certid"
"github.com/liatrio/autogov/pkg/cli"
ghclient "github.com/liatrio/autogov/pkg/github"
Expand Down
11 changes: 1 addition & 10 deletions go.mod
Original file line number Diff line number Diff line change
Expand Up @@ -10,7 +10,7 @@ require (
github.com/go-git/go-billy/v5 v5.9.1
github.com/go-git/go-git/v5 v5.19.2
github.com/go-openapi/strfmt v0.27.2
github.com/google/go-github/v89 v89.0.0
github.com/google/go-github/v91 v91.0.0
github.com/open-policy-agent/opa v1.20.2
github.com/opencontainers/image-spec v1.1.1
github.com/sigstore/cosign/v3 v3.1.3
Expand All @@ -35,16 +35,13 @@ require (
github.com/ProtonMail/go-crypto v1.4.1 // indirect
github.com/agnivade/levenshtein v1.2.1 // indirect
github.com/asaskevich/govalidator v0.0.0-20230301143203-a9d515a09cc2 // indirect
github.com/blang/semver v3.5.1+incompatible // indirect
github.com/cenkalti/backoff/v5 v5.0.3 // indirect
github.com/cespare/xxhash/v2 v2.3.0 // indirect
github.com/charmbracelet/x/ansi v0.10.2 // indirect
github.com/cli/safeexec v1.0.1 // indirect
github.com/cloudflare/circl v1.6.3 // indirect
github.com/coreos/go-oidc/v3 v3.20.0 // indirect
github.com/cyphar/filepath-securejoin v0.6.1 // indirect
github.com/danieljoos/wincred v1.2.2 // indirect
github.com/davecgh/go-spew v1.1.2-0.20180830191138-d8f796af33cc // indirect
github.com/decred/dcrd/dcrec/secp256k1/v4 v4.4.1 // indirect
github.com/dustin/go-humanize v1.0.1 // indirect
github.com/emirpasic/gods v1.18.1 // indirect
Expand All @@ -61,15 +58,11 @@ require (
github.com/go-openapi/runtime v0.33.0 // indirect
github.com/go-openapi/runtime/server-middleware v0.30.0 // indirect
github.com/go-openapi/spec v0.22.9 // indirect
github.com/go-openapi/swag v0.28.0 // indirect
github.com/go-openapi/swag/cmdutils v0.28.0 // indirect
github.com/go-openapi/swag/conv v0.28.0 // indirect
github.com/go-openapi/swag/fileutils v0.28.0 // indirect
github.com/go-openapi/swag/jsonname v0.26.1 // indirect
github.com/go-openapi/swag/jsonutils v0.28.0 // indirect
github.com/go-openapi/swag/loading v0.28.0 // indirect
github.com/go-openapi/swag/mangling v0.28.0 // indirect
github.com/go-openapi/swag/netutils v0.28.0 // indirect
github.com/go-openapi/swag/pools v0.28.0 // indirect
github.com/go-openapi/swag/stringutils v0.28.0 // indirect
github.com/go-openapi/swag/typeutils v0.28.0 // indirect
Expand Down Expand Up @@ -110,10 +103,8 @@ require (
github.com/pjbgf/sha1cd v0.6.0 // indirect
github.com/pkg/browser v0.0.0-20240102092130-5ac0b6a4141c // indirect
github.com/pkg/errors v0.9.1 // indirect
github.com/pmezard/go-difflib v1.0.1-0.20181226105442-5d4384ee4fb2 // indirect
github.com/rcrowley/go-metrics v0.0.0-20250401214520-65e299d6c5c9 // indirect
github.com/sagikazarmark/locafero v0.11.0 // indirect
github.com/sassoftware/relic v7.2.1+incompatible // indirect
github.com/sassoftware/relic/v8 v8.2.0 // indirect
github.com/secure-systems-lab/go-securesystemslib v0.11.0 // indirect
github.com/segmentio/asm v1.2.1 // indirect
Expand Down
393 changes: 114 additions & 279 deletions go.sum

Large diffs are not rendered by default.

2 changes: 1 addition & 1 deletion pkg/attestations/attestations.go
Original file line number Diff line number Diff line change
Expand Up @@ -20,7 +20,7 @@ import (
"strings"
"time"

"github.com/google/go-github/v89/github"
"github.com/google/go-github/v91/github"
bundleutils "github.com/liatrio/autogov/pkg/bundle"
"github.com/liatrio/autogov/pkg/certid"
"github.com/liatrio/autogov/pkg/digest"
Expand Down
2 changes: 1 addition & 1 deletion pkg/attestations/attestations_example_test.go
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@ import (
"context"
"fmt"

"github.com/google/go-github/v89/github"
"github.com/google/go-github/v91/github"
)

// ExampleGetFromGitHub shows verifying GitHub attestations with sigstore-go (trusted
Expand Down
2 changes: 1 addition & 1 deletion pkg/attestations/attestations_test.go
Original file line number Diff line number Diff line change
Expand Up @@ -14,7 +14,7 @@ import (
"testing"
"time"

"github.com/google/go-github/v89/github"
"github.com/google/go-github/v91/github"
"github.com/liatrio/autogov/pkg/certid"
"github.com/liatrio/autogov/pkg/root"
)
Expand Down
2 changes: 1 addition & 1 deletion pkg/download/download.go
Original file line number Diff line number Diff line change
Expand Up @@ -8,7 +8,7 @@ import (
"path/filepath"
"strings"

"github.com/google/go-github/v89/github"
"github.com/google/go-github/v91/github"
"github.com/liatrio/autogov/pkg/attestations"
"github.com/liatrio/autogov/pkg/digest"
ghclient "github.com/liatrio/autogov/pkg/github"
Expand Down
2 changes: 1 addition & 1 deletion pkg/download/download_test.go
Original file line number Diff line number Diff line change
Expand Up @@ -10,7 +10,7 @@ import (
"strings"
"testing"

"github.com/google/go-github/v89/github"
"github.com/google/go-github/v91/github"
"github.com/spf13/cobra"
)

Expand Down
2 changes: 1 addition & 1 deletion pkg/github/client.go
Original file line number Diff line number Diff line change
Expand Up @@ -3,7 +3,7 @@ package github
import (
"os"

"github.com/google/go-github/v89/github"
"github.com/google/go-github/v91/github"
"github.com/spf13/viper"
)

Expand Down
2 changes: 1 addition & 1 deletion pkg/orchestrate/verify.go
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,7 @@ import (
"fmt"
"path/filepath"

"github.com/google/go-github/v89/github"
"github.com/google/go-github/v91/github"
"github.com/liatrio/autogov/pkg/attestations"
"github.com/liatrio/autogov/pkg/certid"
"github.com/sigstore/cosign/v3/pkg/oci"
Expand Down
2 changes: 1 addition & 1 deletion pkg/orchestrate/verify_test.go
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,7 @@ import (
"path/filepath"
"testing"

"github.com/google/go-github/v89/github"
"github.com/google/go-github/v91/github"
"github.com/liatrio/autogov/pkg/certid"
"github.com/stretchr/testify/assert"
)
Expand Down
2 changes: 1 addition & 1 deletion pkg/policy/ghrelease.go
Original file line number Diff line number Diff line change
Expand Up @@ -12,7 +12,7 @@ import (
"strings"
"time"

gogithub "github.com/google/go-github/v89/github"
gogithub "github.com/google/go-github/v91/github"

"github.com/liatrio/autogov/pkg/digest"
"github.com/liatrio/autogov/pkg/github"
Expand Down
4 changes: 2 additions & 2 deletions pkg/policy/ghrelease_test.go
Original file line number Diff line number Diff line change
Expand Up @@ -14,7 +14,7 @@ import (
"testing"
"time"

gogithub "github.com/google/go-github/v89/github"
gogithub "github.com/google/go-github/v91/github"

"github.com/liatrio/autogov/pkg/digest"
)
Expand Down Expand Up @@ -84,7 +84,7 @@ func (f *fakeGHReleaseClient) DownloadReleaseAsset(ctx context.Context, owner, r
func makeRelease(tag string, assets map[string]int64) *gogithub.RepositoryRelease {
r := &gogithub.RepositoryRelease{TagName: tag}
for name, id := range assets {
r.Assets = append(r.Assets, &gogithub.ReleaseAsset{ID: gogithub.Ptr(id), Name: gogithub.Ptr(name)})
r.Assets = append(r.Assets, &gogithub.ReleaseAsset{ID: new(id), Name: new(name)})
}
return r
}
Expand Down
2 changes: 1 addition & 1 deletion pkg/predicate/config.go
Original file line number Diff line number Diff line change
Expand Up @@ -7,7 +7,7 @@ import (
"fmt"
"os"

"github.com/google/go-github/v89/github"
"github.com/google/go-github/v91/github"
"github.com/xeipuuv/gojsonschema"
)

Expand Down
2 changes: 1 addition & 1 deletion pkg/predicate/source_review_service.go
Original file line number Diff line number Diff line change
Expand Up @@ -8,7 +8,7 @@ import (
"strconv"
"time"

gh "github.com/google/go-github/v89/github"
gh "github.com/google/go-github/v91/github"
)

// ReviewService abstracts the GitHub REST calls the source-review predicate
Expand Down
2 changes: 1 addition & 1 deletion pkg/predicate/source_review_service_test.go
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@ import (
"net/http"
"testing"

gh "github.com/google/go-github/v89/github"
gh "github.com/google/go-github/v91/github"
)

func TestAddPage(t *testing.T) {
Expand Down
2 changes: 1 addition & 1 deletion pkg/predicate/sourcereview.go
Original file line number Diff line number Diff line change
Expand Up @@ -8,7 +8,7 @@ import (
"strings"
"time"

gh "github.com/google/go-github/v89/github"
gh "github.com/google/go-github/v91/github"
ghclient "github.com/liatrio/autogov/pkg/github"
)

Expand Down
52 changes: 26 additions & 26 deletions pkg/predicate/sourcereview_test.go
Original file line number Diff line number Diff line change
Expand Up @@ -12,7 +12,7 @@ import (
"testing"
"time"

gh "github.com/google/go-github/v89/github"
gh "github.com/google/go-github/v91/github"
"github.com/liatrio/autogov/pkg/attestations"
)

Expand Down Expand Up @@ -189,7 +189,7 @@ func (m *mockReviewService) GetRepository(_ context.Context, _, _ string) (*gh.R
if db == "" {
db = "main"
}
return &gh.Repository{DefaultBranch: gh.Ptr(db)}, srResp(), nil
return &gh.Repository{DefaultBranch: new(db)}, srResp(), nil
}

func (m *mockReviewService) GetPullRequest(_ context.Context, _, _ string, _ int) (*gh.PullRequest, *gh.Response, error) {
Expand All @@ -200,39 +200,39 @@ func (m *mockReviewService) GetPullRequest(_ context.Context, _, _ string, _ int
if m.getPRCallCount <= m.getPRFailAttempts {
// simulate the propagation race: the PR resolves but merged_by hasn't
// propagated on this attempt yet.
return &gh.PullRequest{Number: gh.Ptr(0)}, srResp(), nil
return &gh.PullRequest{Number: new(0)}, srResp(), nil
}
// nil getPR is the default: the best-effort caller tolerates a nil PR and simply
// records no merger, so existing tests that never set getPR do not panic.
return m.getPR, srResp(), nil
}

func srUser(login string, id int64, typ string) *gh.User {
return &gh.User{Login: gh.Ptr(login), ID: gh.Ptr(id), Type: gh.Ptr(typ)}
return &gh.User{Login: new(login), ID: new(id), Type: new(typ)}
}

func srReview(u *gh.User, state, commitID string, at time.Time) *gh.PullRequestReview {
return &gh.PullRequestReview{
ID: gh.Ptr(at.UnixNano()),
ID: new(at.UnixNano()),
User: u,
State: gh.Ptr(state),
State: new(state),
SubmittedAt: &gh.Timestamp{Time: at},
CommitID: gh.Ptr(commitID),
AuthorAssociation: gh.Ptr("MEMBER"),
CommitID: new(commitID),
AuthorAssociation: new("MEMBER"), //nolint:staticcheck // SA1019 concerns Events API; this fixture models the Reviews REST response, where author_association remains available.
}
}

// srMergedPR builds the merged PR whose merge produced srSourceSHA.
func srMergedPR() *gh.PullRequest {
return &gh.PullRequest{
Number: gh.Ptr(7),
Number: new(7),
User: srUser("author", srAuthorID, "User"),
Head: &gh.PullRequestBranch{SHA: gh.Ptr(srHeadSHA)},
Base: &gh.PullRequestBranch{Ref: gh.Ptr("main")},
MergeCommitSHA: gh.Ptr(srSourceSHA),
Head: &gh.PullRequestBranch{SHA: new(srHeadSHA)},
Base: &gh.PullRequestBranch{Ref: new("main")},
MergeCommitSHA: new(srSourceSHA),
MergedAt: &gh.Timestamp{Time: srBaseTime.Add(time.Hour)},
HTMLURL: gh.Ptr("https://github.com/liatrio/autogov/pull/7"),
Title: gh.Ptr("a change"),
HTMLURL: new("https://github.com/liatrio/autogov/pull/7"),
Title: new("a change"),
}
}

Expand Down Expand Up @@ -275,7 +275,7 @@ func srValidate(t *testing.T, c *SourceReview) {
func srBypassActor(actorType string, id int64, mode string) *gh.BypassActor {
at := gh.BypassActorType(actorType)
bm := gh.BypassMode(mode)
return &gh.BypassActor{ActorID: gh.Ptr(id), ActorType: &at, BypassMode: &bm}
return &gh.BypassActor{ActorID: new(id), ActorType: &at, BypassMode: &bm}
}

func TestFetchTechnicalControls(t *testing.T) {
Expand Down Expand Up @@ -505,7 +505,7 @@ var continuityCommitTime = continuityStart.Add(1000 * time.Hour)
// srR0Commit is the single R0 commit returned by ListCommits in continuity tests.
func srR0Commit() *gh.RepositoryCommit {
return &gh.RepositoryCommit{
SHA: gh.Ptr("r0commit00000000000000000000000000000000"),
SHA: new("r0commit00000000000000000000000000000000"),
Commit: &gh.Commit{Committer: &gh.CommitAuthor{Date: &gh.Timestamp{Time: continuityCommitTime}}},
}
}
Expand Down Expand Up @@ -735,7 +735,7 @@ func TestContinuity_P9b_CommitWalkTruncated(t *testing.T) {
// P9b: the commit list keeps advertising more pages past the cap -> fail closed.
pages := make([][]*gh.RepositoryCommit, continuityMaxCommitPages+1)
for i := range pages {
pages[i] = []*gh.RepositoryCommit{{SHA: gh.Ptr(fmt.Sprintf("c%039d", i))}}
pages[i] = []*gh.RepositoryCommit{{SHA: new(fmt.Sprintf("c%039d", i))}}
}
hist := []*RulesetVersion{srVersion(1, continuityStart)}
states := map[int64]*RulesetVersionState{1: cleanL3State()}
Expand Down Expand Up @@ -908,7 +908,7 @@ func TestContinuity_P17_CommitDateBeforeStartFailsClosed(t *testing.T) {
states := map[int64]*RulesetVersionState{1: cleanL3State()}
m := continuityMock(hist, states, &gh.RepositoryRuleset{})
m.commits = []*gh.RepositoryCommit{{
SHA: gh.Ptr("tooold00000000000000000000000000000000aa"),
SHA: new("tooold00000000000000000000000000000000aa"),
Commit: &gh.Commit{Committer: &gh.CommitAuthor{Date: &gh.Timestamp{Time: continuityStart.Add(-time.Hour)}}},
}}
c := srBuildContinuity(t, m)
Expand Down Expand Up @@ -1277,10 +1277,10 @@ func TestNewSourceReview_OnlyOpenPRs_QuirkIncomplete(t *testing.T) {
// the ListPullRequestsWithCommit default-branch quirk returns only OPEN PRs
// for a SHA not on the default branch -> incompleteness, NOT a false hard fail.
open := &gh.PullRequest{
Number: gh.Ptr(9),
Number: new(9),
User: srUser("author", srAuthorID, "User"),
Head: &gh.PullRequestBranch{SHA: gh.Ptr(srHeadSHA)},
Base: &gh.PullRequestBranch{Ref: gh.Ptr("main")},
Head: &gh.PullRequestBranch{SHA: new(srHeadSHA)},
Base: &gh.PullRequestBranch{Ref: new("main")},
// no MergedAt, no matching MergeCommitSHA -> not selected.
}
c := srBuild(t, &mockReviewService{prs: []*gh.PullRequest{open}}, srOpts())
Expand Down Expand Up @@ -1425,7 +1425,7 @@ func TestNewSourceReview_ApproversDeterministicOrder(t *testing.T) {
func TestNewSourceReview_BoundsUntrustedStrings(t *testing.T) {
longLogin := strings.Repeat("L", 5000)
pr := srMergedPR()
pr.HTMLURL = gh.Ptr("https://example.com/" + strings.Repeat("u", 5000))
pr.HTMLURL = new("https://example.com/" + strings.Repeat("u", 5000))
m := &mockReviewService{
prs: []*gh.PullRequest{pr},
reviews: []*gh.PullRequestReview{srReview(srUser(longLogin, 2, "User"), reviewStateApproved, srHeadSHA, srBaseTime.Add(time.Minute))},
Expand Down Expand Up @@ -1457,11 +1457,11 @@ func TestNewSourceReview_PRNumberDoesNotBypassMergeMatch(t *testing.T) {
// queried source revision (and is not even merged) must NOT be bound to it via
// --pr-number. Otherwise an unreviewed commit could borrow another PR's approvals.
wellReviewedButUnrelated := &gh.PullRequest{
Number: gh.Ptr(99),
Number: new(99),
User: srUser("author", srAuthorID, "User"),
Head: &gh.PullRequestBranch{SHA: gh.Ptr(srHeadSHA)},
Base: &gh.PullRequestBranch{Ref: gh.Ptr("main")},
MergeCommitSHA: gh.Ptr("a-totally-different-commit-sha"),
Head: &gh.PullRequestBranch{SHA: new(srHeadSHA)},
Base: &gh.PullRequestBranch{Ref: new("main")},
MergeCommitSHA: new("a-totally-different-commit-sha"),
// not merged (zero MergedAt)
}
opts := srOpts()
Expand Down
Loading
Loading