chore(deps): update sigstore (8.19)#6124
Conversation
ℹ Artifact update noticeFile name: go.modIn order to perform the update(s) described in the table above, Renovate ran the
Details:
|
|
This pull request is now in conflicts. Could you fix it? 🙏 |
27eae4b to
6036544
Compare
|
This pull request is now in conflicts. Could you fix it? 🙏 |
6036544 to
8f0a394
Compare
36f339c to
fd03abf
Compare
|
This pull request is now in conflicts. Could you fix it? 🙏 |
6f99a74 to
0f1122e
Compare
0f1122e to
4c0b76d
Compare
4c0b76d to
2083416
Compare
ed7a900 to
fb61905
Compare
fb61905 to
b0f4cf5
Compare
b0f4cf5 to
9f27dd4
Compare
|
This pull request is now in conflicts. Could you fix it? 🙏 |
e36f96a to
64fe285
Compare
64fe285 to
4cf307f
Compare
4cf307f to
08a6f05
Compare
08a6f05 to
5f6da27
Compare
5f6da27 to
96e96d9
Compare
|
This pull request is now in conflicts. Could you fix it? 🙏 |
96e96d9 to
6a87e41
Compare
6a87e41 to
ca0b582
Compare
ca0b582 to
ef150cf
Compare
This PR contains the following updates:
v2.2.4->v2.6.3v0.5.0->v0.5.1v1.5.0->v1.5.1v1.10.5->v1.10.6v1.10.4->v1.10.6v1.10.4->v1.10.6v1.10.4->v1.10.6v1.10.4->v1.10.6v1.2.2->v1.2.9Warning
Some dependencies could not be looked up. Check the Dependency Dashboard for more information.
Release Notes
sigstore/cosign (github.com/sigstore/cosign/v2)
v2.6.3Compare Source
Changelog
v2.6.3 resolves GHSA-w6c6-c85g-mmv6.
fecddd3Fix DSSE predicate check (#4802)564c5b1Backport bundle detection to sign and attest (#4727)Thanks to all contributors!
v2.6.2Compare Source
v2.6.2 resolves GHSA-whqx-f9j3-ch6m.
Changes
v2.6.1Compare Source
Bug Fixes
v2.6.0Compare Source
v2.6.0 introduces a number of new features, including:
Example generation and verification of a signed in-toto statement:
Example container signing and verification using the new bundle format and referring artifacts:
Example usage of a signing config provided by the public good instance's TUF repository:
v2.6.0 leverages sigstore-go's signing and verification APIs gated behind these new flags. In an upcoming major release, we will be
updating Cosign to default to producing and consuming bundles to align with all other Sigstore SDKs.
Features
attest-blobthe ability to supply a complete in-toto statement, and add toverify-blob-attestationthe ability to verify with just a digest (#4306)Breaking API Changes
sign.SignerFromKeyOptsno longer generates a key. Instead, it returns whether or not the client needs to generate a key, and if so, clientsshould call
sign.KeylessSigner. This allows clients to more easily manage key generation.Bug Fixes
v2.5.3Compare Source
Features
Bug Fixes
v2.5.2Compare Source
Bug Fixes
Documentation
v2.5.1Compare Source
Features
Bug Fixes
Docs
verify-blobcmd examples (#4160)Releases
Contributors
v2.5.0Compare Source
v2.5.0 includes an implementation of the new bundle specification,
attesting and verifying OCI image attestations uploaded as OCI artifacts.
This feature is currently gated behind the
--new-bundle-formatflagwhen running
cosign attest.Features
Fixes
Contributors
v2.4.3Compare Source
Features
Bug Fixes
Cleanup
Contributors
v2.4.2Compare Source
Features
--trusted-root(#3933)Bug Fixes
Documentation
Contributors
v2.4.1Compare Source
v2.4.1 largely contains bug fixes and updates dependencies.
Features
Bug Fixes
Contributors
v2.4.0Compare Source
v2.4.0 begins the modernization of the Cosign client, which includes:
through a trust root file, instead of many different flags
In future updates, we'll include:
format during verification
Cosign-specific bundle format
We have also moved nightly Cosign container builds to GHCR instead of GCR.
Features
verify-blobandverify-blob-attestation(#3796)email_verifiedas string or boolean (#3819)Contributors
v2.3.0Compare Source
Features
Bug Fixes
bundleVerifiedto true after Rekor verification (Resolves #3740) (#3745)Documentation
Testing
Contributors
sigstore/protobuf-specs (github.com/sigstore/protobuf-specs)
v0.5.1Compare Source
sigstore/rekor (github.com/sigstore/rekor)
v1.5.1Compare Source
Features
Bug Fixes
sigstore/sigstore (github.com/sigstore/sigstore)
v1.10.6Compare Source
What's Changed
Full Changelog: sigstore/sigstore@v1.10.5...v1.10.6
sigstore/timestamp-authority (github.com/sigstore/timestamp-authority)
v1.2.9Compare Source
v1.2.8Compare Source
Features
v1.2.7Compare Source
Features
Bug Fixes
v1.2.6Compare Source
Features
Bug Fixes
v1.2.5Compare Source
Enhancements
Changes
Bug fixes
Misc
v1.2.4Compare Source
Changes
Bug fixes
Misc
v1.2.3Compare Source
Changes
Bug fixes
Misc
Configuration
📅 Schedule: Branch creation - "* 1 * * 1-5" (UTC), Automerge - At any time (no schedule defined).
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR has been generated by Renovate Bot.