@@ -66,7 +66,7 @@ replace github.com/charmbracelet/bubbletea => github.com/coder/bubbletea v1.2.2-
6666
6767// Trivy has some issues that we're floating patches for, and will hopefully
6868// be upstreamed eventually.
69- replace github.com/aquasecurity/trivy =>github.com/coder/trivy v0.0.0-20250527170238-9416a59d7019
69+ replace github.com/aquasecurity/trivy =>github.com/coder/trivy v0.0.0-20250807211036-0bb0acd620a8
7070
7171// afero/tarfs has a bug that breaks our usage. A PR has been submitted upstream.
7272// https://github.com/spf13/afero/pull/487
@@ -126,7 +126,7 @@ require (
126126github.com/go-jose/go-jose/v4 v4.1.1
127127github.com/go-logr/logr v1.4.3
128128github.com/go-playground/validator/v10 v10.27.0
129- github.com/gofrs/flock v0.12.0
129+ github.com/gofrs/flock v0.12.1
130130github.com/gohugoio/hugo v0.148.1
131131github.com/golang-jwt/jwt/v4 v4.5.2
132132github.com/golang-migrate/migrate/v4 v4.18.1
@@ -158,7 +158,7 @@ require (
158158github.com/mocktools/go-smtp-mock/v2 v2.5.0
159159github.com/muesli/termenv v0.16.0
160160github.com/natefinch/atomic v1.0.1
161- github.com/open-policy-agent/opa v1.4.2
161+ github.com/open-policy-agent/opa v1.6.0
162162github.com/ory/dockertest/v3 v3.12.0
163163github.com/pion/udp v0.1.4
164164github.com/pkg/browser v0.0.0-20240102092130-5ac0b6a4141c
@@ -170,12 +170,12 @@ require (
170170github.com/prometheus/common v0.65.0
171171github.com/quasilyte/go-ruleguard/dsl v0.3.22
172172github.com/robfig/cron/v3 v3.0.1
173- github.com/shirou/gopsutil/v4 v4.25.4
173+ github.com/shirou/gopsutil/v4 v4.25.5
174174github.com/skratchdot/open-golang v0.0.0-20200116055534-eef842397966
175175github.com/spf13/afero v1.14.0
176- github.com/spf13/pflag v1.0.6
176+ github.com/spf13/pflag v1.0.7
177177github.com/sqlc-dev/pqtype v0.3.0
178- github.com/stretchr/testify v1.10 .0
178+ github.com/stretchr/testify v1.11 .0
179179github.com/swaggo/http-swagger/v2 v2.0.1
180180github.com/swaggo/swag v1.16.2
181181github.com/tidwall/gjson v1.18.0
@@ -187,16 +187,16 @@ require (
187187go.mozilla.org/pkcs7 v0.9.0
188188go.nhat.io/otelsql v0.16.0
189189go.opentelemetry.io/otel v1.37.0
190- go.opentelemetry.io/otel/exporters/otlp/otlptrace v1.35 .0
191- go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc v1.35 .0
190+ go.opentelemetry.io/otel/exporters/otlp/otlptrace v1.36 .0
191+ go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc v1.36 .0
192192go.opentelemetry.io/otel/sdk v1.37.0
193193go.opentelemetry.io/otel/trace v1.37.0
194194go.uber.org/atomic v1.11.0
195195go.uber.org/goleak v1.3.1-0.20240429205332-517bace7cc29
196196go.uber.org/mock v0.6.0
197197go4.org/netipx v0.0.0-20230728180743-ad4cb58a6516
198198golang.org/x/crypto v0.41.0
199- golang.org/x/exp v0.0.0-20250408133849-7e4ce0ab07d0
199+ golang.org/x/exp v0.0.0-20250606033433-dcc06ee1d476
200200golang.org/x/mod v0.27.0
201201golang.org/x/net v0.43.0
202202golang.org/x/oauth2 v0.30.0
@@ -225,7 +225,7 @@ require (
225225cloud.google.com/go/longrunning v0.6.7 // indirect
226226dario.cat/mergo v1.0.1 // indirect
227227filippo.io/edwards25519 v1.1.0 // indirect
228- github.com/Azure/go-ansiterm v0.0.0-20230124172434-306776ec8161 // indirect
228+ github.com/Azure/go-ansiterm v0.0.0-20250102033503-faa5f7b0171c // indirect
229229github.com/DataDog/appsec-internal-go v1.11.2 // indirect
230230github.com/DataDog/datadog-agent/pkg/obfuscate v0.64.2 // indirect
231231github.com/DataDog/datadog-agent/pkg/proto v0.64.2 // indirect
@@ -244,7 +244,7 @@ require (
244244github.com/KyleBanks/depth v1.2.1 // indirect
245245github.com/Microsoft/go-winio v0.6.2 // indirect
246246github.com/Nvveen/Gotty v0.0.0-20120604004816-cd527374f1e5 // indirect
247- github.com/ProtonMail/go-crypto v1.1.6 // indirect
247+ github.com/ProtonMail/go-crypto v1.3.0 // indirect
248248github.com/agext/levenshtein v1.2.3 // indirect
249249github.com/agnivade/levenshtein v1.2.1 // indirect
250250github.com/akutz/memconn v0.1.0 // indirect
@@ -274,7 +274,7 @@ require (
274274github.com/beorn7/perks v1.0.1 // indirect
275275github.com/bep/godartsass/v2 v2.5.0 // indirect
276276github.com/bep/golibsass v1.2.0 // indirect
277- github.com/bmatcuk/doublestar/v4 v4.8.1 // indirect
277+ github.com/bmatcuk/doublestar/v4 v4.9.0 // indirect
278278github.com/charmbracelet/x/ansi v0.8.0 // indirect
279279github.com/charmbracelet/x/term v0.2.1 // indirect
280280github.com/chromedp/sysutil v1.1.0 // indirect
@@ -284,14 +284,14 @@ require (
284284github.com/containerd/continuity v0.4.5 // indirect
285285github.com/coreos/go-iptables v0.6.0 // indirect
286286github.com/dlclark/regexp2 v1.11.5 // indirect
287- github.com/docker/cli v28.1.1 +incompatible // indirect
288- github.com/docker/docker v28.1.1 +incompatible // indirect
287+ github.com/docker/cli v28.3.2 +incompatible // indirect
288+ github.com/docker/docker v28.3.3 +incompatible // indirect
289289github.com/docker/go-connections v0.5.0 // indirect
290290github.com/docker/go-units v0.5.0 // indirect
291291github.com/dop251/goja v0.0.0-20241024094426-79f3a7efcdbd // indirect
292292github.com/dustin/go-humanize v1.0.1
293293github.com/eapache/queue/v2 v2.0.0-20230407133247-75960ed334e4 // indirect
294- github.com/ebitengine/purego v0.8.3 // indirect
294+ github.com/ebitengine/purego v0.8.4 // indirect
295295github.com/elastic/go-windows v1.0.0 // indirect
296296github.com/erikgeiser/coninput v0.0.0-20211004153227-1c3628e74d0f // indirect
297297github.com/felixge/httpsnoop v1.0.4 // indirect
@@ -308,7 +308,6 @@ require (
308308github.com/go-playground/locales v0.14.1 // indirect
309309github.com/go-playground/universal-translator v0.18.1 // indirect
310310github.com/go-sourcemap/sourcemap v2.1.3+incompatible // indirect
311- github.com/go-test/deep v1.1.0 // indirect
312311github.com/go-viper/mapstructure/v2 v2.4.0 // indirect
313312github.com/gobwas/glob v0.2.3 // indirect
314313github.com/gobwas/httphead v0.1.0 // indirect
@@ -322,19 +321,18 @@ require (
322321github.com/google/btree v1.1.3 // indirect
323322github.com/google/go-querystring v1.1.0 // indirect
324323github.com/google/nftables v0.2.0 // indirect
325- github.com/google/pprof v0.0.0-20250403155104-27863c87afa6 // indirect
324+ github.com/google/pprof v0.0.0-20250607225305-033d6d78b36a // indirect
326325github.com/google/s2a-go v0.1.9 // indirect
327326github.com/google/shlex v0.0.0-20191202100458-e7afc7fbc510 // indirect
328327github.com/googleapis/enterprise-certificate-proxy v0.3.6 // indirect
329328github.com/googleapis/gax-go/v2 v2.15.0 // indirect
330329github.com/gorilla/css v1.0.1 // indirect
331- github.com/gorilla/mux v1.8.1 // indirect
332- github.com/grpc-ecosystem/grpc-gateway/v2 v2.26.1 // indirect
330+ github.com/grpc-ecosystem/grpc-gateway/v2 v2.26.3 // indirect
333331github.com/hashicorp/errwrap v1.1.0 // indirect
334332github.com/hashicorp/go-cleanhttp v0.5.2 // indirect
335333github.com/hashicorp/go-cty v1.5.0 // indirect
336334github.com/hashicorp/go-hclog v1.6.3 // indirect
337- github.com/hashicorp/go-retryablehttp v0.7.7 // indirect
335+ github.com/hashicorp/go-retryablehttp v0.7.8 // indirect
338336github.com/hashicorp/go-terraform-address v0.0.0-20240523040243-ccea9d309e0c
339337github.com/hashicorp/go-uuid v1.0.3 // indirect
340338github.com/hashicorp/hcl v1.0.1-vault-7 // indirect
@@ -366,14 +364,14 @@ require (
366364github.com/mdlayher/sdnotify v1.0.0 // indirect
367365github.com/mdlayher/socket v0.5.0 // indirect
368366github.com/microcosm-cc/bluemonday v1.0.27
369- github.com/miekg/dns v1.1.57 // indirect
367+ github.com/miekg/dns v1.1.58 // indirect
370368github.com/mitchellh/copystructure v1.2.0 // indirect
371369github.com/mitchellh/go-homedir v1.1.0 // indirect
372370github.com/mitchellh/go-ps v1.0.0 // indirect
373371github.com/mitchellh/go-testing-interface v1.14.1 // indirect
374372github.com/mitchellh/reflectwalk v1.0.2 // indirect
375373github.com/moby/docker-image-spec v1.3.1 // indirect
376- github.com/moby/term v0.5.0 // indirect
374+ github.com/moby/term v0.5.2 // indirect
377375github.com/modern-go/concurrent v0.0.0-20180306012644-bacd9c7ef1dd // indirect
378376github.com/modern-go/reflect2 v1.0.2 // indirect
379377github.com/muesli/ansi v0.0.0-20230316100256-276c6243b2f6 // indirect
@@ -445,7 +443,7 @@ require (
445443go.opentelemetry.io/contrib v1.19.0 // indirect
446444go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.61.0 // indirect
447445go.opentelemetry.io/otel/metric v1.37.0 // indirect
448- go.opentelemetry.io/proto/otlp v1.5 .0 // indirect
446+ go.opentelemetry.io/proto/otlp v1.7 .0 // indirect
449447go.uber.org/multierr v1.11.0 // indirect
450448go.uber.org/zap v1.27.0 // indirect
451449go4.org/mem v0.0.0-20220726221520-4f986261bf13 // indirect
@@ -461,7 +459,7 @@ require (
461459gopkg.in/yaml.v2 v2.4.0 // indirect
462460howett.net/plist v1.0.0 // indirect
463461kernel.org/pub/linux/libs/security/libcap/psx v1.2.73 // indirect
464- sigs.k8s.io/yaml v1.4 .0 // indirect
462+ sigs.k8s.io/yaml v1.5 .0 // indirect
465463)
466464
467465require github.com/coder/clistat v1.0.0
@@ -472,7 +470,7 @@ require (
472470github.com/charmbracelet/colorprofile v0.2.3-0.20250311203215-f60798e515dc // indirect
473471github.com/charmbracelet/x/cellbuf v0.0.13 // indirect
474472github.com/go-json-experiment/json v0.0.0-20250725192818-e39067aee2d2 // indirect
475- github.com/golang-jwt/jwt/v5 v5.2.2 // indirect
473+ github.com/golang-jwt/jwt/v5 v5.2.3 // indirect
476474github.com/xo/terminfo v0.0.0-20220910002029-abceb7e1c41e // indirect
477475)
478476
@@ -481,7 +479,7 @@ require (
481479github.com/brianvoe/gofakeit/v7 v7.4.0
482480github.com/coder/agentapi-sdk-go v0.0.0-20250505131810-560d1d88d225
483481github.com/coder/aisdk-go v0.0.9
484- github.com/coder/preview v1.0.3
482+ github.com/coder/preview v1.0.4
485483github.com/fsnotify/fsnotify v1.9.0
486484github.com/go-git/go-git/v5 v5.16.2
487485github.com/mark3labs/mcp-go v0.32.0
@@ -501,10 +499,15 @@ require (
501499github.com/GoogleCloudPlatform/opentelemetry-operations-go/exporter/metric v0.50.0 // indirect
502500github.com/GoogleCloudPlatform/opentelemetry-operations-go/internal/resourcemapping v0.50.0 // indirect
503501github.com/Masterminds/semver/v3 v3.3.1 // indirect
502+ github.com/alecthomas/chroma v0.10.0 // indirect
504503github.com/aquasecurity/go-version v0.0.1 // indirect
505- github.com/aquasecurity/trivy v0.58.2 // indirect
504+ github.com/aquasecurity/iamgo v0.0.10 // indirect
505+ github.com/aquasecurity/jfather v0.0.8 // indirect
506+ github.com/aquasecurity/trivy v0.61.1-0.20250407075540-f1329c7ea1aa // indirect
507+ github.com/aquasecurity/trivy-checks v1.11.3-0.20250604022615-9a7efa7c9169 // indirect
506508github.com/aws/aws-sdk-go v1.55.7 // indirect
507509github.com/bgentry/go-netrc v0.0.0-20140422174119-9fd32a8b3d3d // indirect
510+ github.com/cenkalti/backoff/v5 v5.0.2 // indirect
508511github.com/charmbracelet/x/exp/slice v0.0.0-20250327172914-2fdc97757edf // indirect
509512github.com/cncf/xds/go v0.0.0-20250501225837-2ac532fd4443 // indirect
510513github.com/dgryski/go-farm v0.0.0-20240924180020-3414d57e47da // indirect
@@ -513,6 +516,7 @@ require (
513516github.com/esiqveland/notify v0.13.3 // indirect
514517github.com/go-git/gcfg v1.5.1-0.20230307220236-3a3c6141e376 // indirect
515518github.com/go-git/go-billy/v5 v5.6.2 // indirect
519+ github.com/google/go-containerregistry v0.20.6 // indirect
516520github.com/gorilla/websocket v1.5.4-0.20250319132907-e064f32e3674 // indirect
517521github.com/hashicorp/go-getter v1.7.9 // indirect
518522github.com/hashicorp/go-safetemp v1.0.0 // indirect
@@ -522,20 +526,23 @@ require (
522526github.com/moby/sys/user v0.4.0 // indirect
523527github.com/nfnt/resize v0.0.0-20180221191011-83c6a9932646 // indirect
524528github.com/openai/openai-go v1.7.0 // indirect
529+ github.com/package-url/packageurl-go v0.1.3 // indirect
525530github.com/planetscale/vtprotobuf v0.6.1-0.20240319094008-0393e58bdf10 // indirect
526531github.com/puzpuzpuz/xsync/v3 v3.5.1 // indirect
527- github.com/samber/lo v1.50 .0 // indirect
532+ github.com/samber/lo v1.51 .0 // indirect
528533github.com/sergeymakinen/go-bmp v1.0.0 // indirect
529534github.com/sergeymakinen/go-ico v1.0.0-beta.0 // indirect
530535github.com/spiffe/go-spiffe/v2 v2.5.0 // indirect
531536github.com/tidwall/sjson v1.2.5 // indirect
532537github.com/tmaxmax/go-sse v0.10.0 // indirect
533538github.com/ulikunitz/xz v0.5.15 // indirect
539+ github.com/vektah/gqlparser/v2 v2.5.28 // indirect
534540github.com/yosida95/uritemplate/v3 v3.0.2 // indirect
535541github.com/zeebo/xxh3 v1.0.2 // indirect
536542go.opentelemetry.io/contrib/detectors/gcp v1.36.0 // indirect
537543go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc v0.61.0 // indirect
538544go.opentelemetry.io/otel/sdk/metric v1.37.0 // indirect
545+ go.yaml.in/yaml/v2 v2.4.2 // indirect
539546google.golang.org/genai v1.12.0 // indirect
540547gopkg.in/warnings.v0 v0.1.2 // indirect
541548k8s.io/utils v0.0.0-20241210054802-24370beab758 // indirect