chore(deps): update sigstore (main) - #6687
Conversation
ℹ Artifact update noticeFile name: go.modIn order to perform the update(s) described in the table above, Renovate ran the
Details:
|
0ebd261 to
5221811
Compare
|
This pull request is now in conflicts. Could you fix it? 🙏 |
5221811 to
58bd5cb
Compare
|
This pull request is now in conflicts. Could you fix it? 🙏 |
58bd5cb to
c92e1af
Compare
c92e1af to
5cb6862
Compare
5cb6862 to
448c467
Compare
448c467 to
a7925d7
Compare
ℹ️ Artifact update noticeFile name: go.modIn order to perform the update(s) described in the table above, Renovate ran the
Details:
|
77a07ea to
7d97963
Compare
2e5af02 to
9c710d8
Compare
9c710d8 to
1736303
Compare
1736303 to
9307d78
Compare
|
This pull request is now in conflicts. Could you fix it? 🙏 |
9307d78 to
7bb3436
Compare
a29fdae to
2fc788a
Compare
2fc788a to
788317d
Compare
788317d to
0a56f07
Compare
0a56f07 to
1c3838e
Compare
1c3838e to
e14af43
Compare
e14af43 to
829e6a2
Compare
This PR contains the following updates:
v2.6.3→v2.6.4v1.5.2→v1.5.3v2.2.1→v2.3.0v1.10.8→v1.10.9v1.1.4→v1.3.0v2.1.2→v2.1.3Warning
Some dependencies could not be looked up. Check the Dependency Dashboard for more information.
Release Notes
sigstore/cosign (github.com/sigstore/cosign/v2)
v2.6.4Compare Source
This release is a backport of OCI manifest fixes, and better support for
cosign attestation downloadwhen you are using a mix of old Cosign signatures with the more recent bundle format.We strongly encourage folks to continue their migration to the bundle format. The Cosign v3.1.x releases support both formats; the primary change being that the default for signing is the bundle format (although you can specify
--new-bundle-format=falseto sign with the old format). The verification commands in Cosign v3.1.x support both formats, and will try to detect the format for you for maximum compatibility.Changelog
26261f0Allow attestation download to handle both bundle types (#4996) (#5017)d49a0c1fix: include artifactType in OCI 1.1 signature referrer manifest (cherry-pick PR-4997 to release-2.6) (#5002)Thanks to all contributors!
sigstore/rekor (github.com/sigstore/rekor)
v1.5.3Compare Source
Features
Improvements
sigstore/rekor-tiles (github.com/sigstore/rekor-tiles/v2)
v2.3.0Compare Source
What's Changed
v2.3.0 drops support for the DSSE entry type. All Sigstore SDKs will now upload DSSEs as hashedrekord entries, to support uploading large DSSEs, such as signed SBOMs, for the public instance. We strongly recommend not relying on the previous DSSE type in any way, as going forward, there will only be one supported entry type.
Breaking Changes
Library Features
Fixes
Full Changelog: sigstore/rekor-tiles@v2.2.1...v2.3.0
sigstore/sigstore (github.com/sigstore/sigstore)
v1.10.9Compare Source
What's Changed
Note: #2369 deprecates the TUF client. Use the TUF client from sigstore-go instead: https://github.com/sigstore/sigstore-go/tree/main/pkg/tuf
Full Changelog: sigstore/sigstore@v1.10.8...v1.10.9
sigstore/sigstore-go (github.com/sigstore/sigstore-go)
v1.3.0Compare Source
What's Changed
New Contributors
Full Changelog: sigstore/sigstore-go@v1.2.2...v1.3.0
v1.2.2Compare Source
What's Changed
Full Changelog: sigstore/sigstore-go@v1.2.1...v1.2.2
v1.2.1Compare Source
What's Changed
v1.2.1 resolves GHSA-wqqc-jjcq-vfxm.
Full Changelog: sigstore/sigstore-go@v1.2.0...v1.2.1
v1.2.0Compare Source
What's Changed
New Contributors
Full Changelog: sigstore/sigstore-go@v1.1.4...v1.2.0
sigstore/timestamp-authority (github.com/sigstore/timestamp-authority/v2)
v2.1.3Compare Source
What's Changed
v2.1.3 bumps the version of Go used to build the binaries and containers to the latest release, 1.26.4. This release also contains a number of changes related to RFC3161 compliance.
Full Changelog: sigstore/timestamp-authority@v2.1.2...v2.1.3
Configuration
📅 Schedule: Branch creation - Between 01:00 AM and 01:59 AM, Monday through Friday ( * 1 * * 1-5 ) (UTC), Automerge - At any time (no schedule defined).
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR has been generated by Renovate Bot.