Skip to content

chore(deps): update sigstore (9.3) - #6712

Open
elastic-renovate-prod[bot] wants to merge 1 commit into
9.3from
renovate/9.3-sigstore
Open

chore(deps): update sigstore (9.3)#6712
elastic-renovate-prod[bot] wants to merge 1 commit into
9.3from
renovate/9.3-sigstore

Conversation

@elastic-renovate-prod

@elastic-renovate-prod elastic-renovate-prod Bot commented Jun 4, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
github.com/sigstore/cosign/v2 v2.6.3v2.6.4 age confidence
github.com/sigstore/rekor v1.5.2v1.5.3 age confidence
github.com/sigstore/rekor-tiles/v2 v2.2.1v2.3.0 age confidence
github.com/sigstore/sigstore v1.10.8v1.10.9 age confidence
github.com/sigstore/sigstore-go v1.1.4v1.3.0 age confidence
github.com/sigstore/timestamp-authority/v2 v2.1.2v2.1.3 age confidence

Warning

Some dependencies could not be looked up. Check the Dependency Dashboard for more information.


Release Notes

sigstore/cosign (github.com/sigstore/cosign/v2)

v2.6.4

Compare Source

This release is a backport of OCI manifest fixes, and better support for cosign attestation download when you are using a mix of old Cosign signatures with the more recent bundle format.

We strongly encourage folks to continue their migration to the bundle format. The Cosign v3.1.x releases support both formats; the primary change being that the default for signing is the bundle format (although you can specify --new-bundle-format=false to sign with the old format). The verification commands in Cosign v3.1.x support both formats, and will try to detect the format for you for maximum compatibility.

Changelog

  • 26261f0 Allow attestation download to handle both bundle types (#​4996) (#​5017)
  • d49a0c1 fix: include artifactType in OCI 1.1 signature referrer manifest (cherry-pick PR-4997 to release-2.6) (#​5002)
Thanks to all contributors!
sigstore/rekor (github.com/sigstore/rekor)

v1.5.3

Compare Source

Features

  • return 499 when clients disconnect instead of 500 (#​2870)

Improvements

  • Change max upperbound on latency metrics (#​2868)
sigstore/rekor-tiles (github.com/sigstore/rekor-tiles/v2)

v2.3.0

Compare Source

What's Changed

v2.3.0 drops support for the DSSE entry type. All Sigstore SDKs will now upload DSSEs as hashedrekord entries, to support uploading large DSSEs, such as signed SBOMs, for the public instance. We strongly recommend not relying on the previous DSSE type in any way, as going forward, there will only be one supported entry type.

Breaking Changes
Library Features
  • Add ToEntryHash and VerifyLogEntryWithHash in #​787
Fixes
  • don't return full panic in user-facing error message in #​707
  • ensure error can be Unwrapped in #​710
  • defensive fix if err is wrapped in #​708
  • Limit client response reads, set default timeouts, and validate digest sizes in #​806

Full Changelog: sigstore/rekor-tiles@v2.2.1...v2.3.0

sigstore/sigstore (github.com/sigstore/sigstore)

v1.10.9

Compare Source

What's Changed

Note: #​2369 deprecates the TUF client. Use the TUF client from sigstore-go instead: https://github.com/sigstore/sigstore-go/tree/main/pkg/tuf

  • Deprecate TUF client, ValidatePubKey in #​2369
  • docs: add OVHcloud KMS in available external plugins in #​2359
  • fix(oauthflow): default the device flow poll interval to 5s per RFC 8628 in #​2381
  • Add BrowserOpener field to InteractiveIDTokenGetter in #​2383
  • Fix Azure KMS support for RSA signatures in #​2355

Full Changelog: sigstore/sigstore@v1.10.8...v1.10.9

sigstore/sigstore-go (github.com/sigstore/sigstore-go)

v1.3.0

Compare Source

What's Changed

New Contributors

Full Changelog: sigstore/sigstore-go@v1.2.2...v1.3.0

v1.2.2

Compare Source

What's Changed

  • Reject certificate identity with no SAN or issuer criteria in #​645
  • Support Verification in sigstore/cosign with X.509 Certificate Chain in #​581

Full Changelog: sigstore/sigstore-go@v1.2.1...v1.2.2

v1.2.1

Compare Source

What's Changed

v1.2.1 resolves GHSA-wqqc-jjcq-vfxm.

  • Check signature time against public key validity window in #​642

Full Changelog: sigstore/sigstore-go@v1.2.0...v1.2.1

v1.2.0

Compare Source

What's Changed

New Contributors

Full Changelog: sigstore/sigstore-go@v1.1.4...v1.2.0

sigstore/timestamp-authority (github.com/sigstore/timestamp-authority/v2)

v2.1.3

Compare Source

What's Changed

v2.1.3 bumps the version of Go used to build the binaries and containers to the latest release, 1.26.4. This release also contains a number of changes related to RFC3161 compliance.

  • count unknown EKUs when enforcing single timestamping usage in #​1389
  • bound json nonce length before parsing in parsejsonrequest in #​1402
  • reject timestamp response missing the requested nonce in #​1405
  • Fix --timeout flag reporting its value type as "format" in help in #​1413
  • handle client disconnection as 499 error = in #​1417
  • require timestamping leaf certificate to be an end-entity in #​1416

Full Changelog: sigstore/timestamp-authority@v2.1.2...v2.1.3


Configuration

📅 Schedule: Branch creation - Between 01:00 AM and 01:59 AM, Monday through Friday ( * 1 * * 1-5 ) (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Enabled.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Renovate Bot.

@elastic-renovate-prod
elastic-renovate-prod Bot requested a review from a team as a code owner June 4, 2026 16:16
@elastic-renovate-prod elastic-renovate-prod Bot added backport-skip dependencies Pull requests that update a dependency file renovate renovate-auto-approve Team:Security-Cloud Services Security Data Experience - Cloud Services team. labels Jun 4, 2026
@elastic-renovate-prod
elastic-renovate-prod Bot enabled auto-merge June 4, 2026 16:16
@elastic-renovate-prod

elastic-renovate-prod Bot commented Jun 4, 2026

Copy link
Copy Markdown
Contributor Author

ℹ Artifact update notice

File name: go.mod

In order to perform the update(s) described in the table above, Renovate ran the go get command, which resulted in the following additional change(s):

  • 7 additional dependencies were updated

Details:

Package Change
go.opentelemetry.io/otel v1.43.0 -> v1.44.0
go.opentelemetry.io/otel/metric v1.43.0 -> v1.44.0
go.opentelemetry.io/otel/sdk v1.43.0 -> v1.44.0
go.opentelemetry.io/otel/sdk/metric v1.43.0 -> v1.44.0
go.opentelemetry.io/otel/trace v1.43.0 -> v1.44.0
github.com/go-openapi/analysis v0.25.1 -> v0.25.2
github.com/go-openapi/runtime v0.32.2 -> v0.32.3

@elastic-renovate-prod
elastic-renovate-prod Bot force-pushed the renovate/9.3-sigstore branch from f0f6eb7 to 07caa0f Compare June 11, 2026 22:53
@elastic-renovate-prod elastic-renovate-prod Bot changed the title chore(deps): update module github.com/sigstore/sigstore-go to v1.2.0 (9.3) chore(deps): update module github.com/sigstore/sigstore-go to v1.2.1 (9.3) Jun 11, 2026
@elastic-renovate-prod
elastic-renovate-prod Bot force-pushed the renovate/9.3-sigstore branch from 07caa0f to 5a46e6d Compare June 12, 2026 02:53
@elastic-renovate-prod elastic-renovate-prod Bot changed the title chore(deps): update module github.com/sigstore/sigstore-go to v1.2.1 (9.3) chore(deps): update sigstore (9.3) Jun 12, 2026
@mergify

mergify Bot commented Jul 1, 2026

Copy link
Copy Markdown
Contributor

This pull request is now in conflicts. Could you fix it? 🙏
To fixup this pull request, you can check out it locally. See documentation: https://help.github.com/articles/checking-out-pull-requests-locally/

git fetch upstream
git checkout -b renovate/9.3-sigstore upstream/renovate/9.3-sigstore
git merge upstream/9.3
git push upstream renovate/9.3-sigstore

@elastic-renovate-prod
elastic-renovate-prod Bot force-pushed the renovate/9.3-sigstore branch from 5a46e6d to ed6e2f6 Compare July 1, 2026 07:02
@elastic-renovate-prod
elastic-renovate-prod Bot force-pushed the renovate/9.3-sigstore branch from ed6e2f6 to 84809a4 Compare July 1, 2026 07:25
@elastic-renovate-prod
elastic-renovate-prod Bot force-pushed the renovate/9.3-sigstore branch 2 times, most recently from bdab9e0 to 82ffc91 Compare July 1, 2026 07:27
@elastic-renovate-prod
elastic-renovate-prod Bot force-pushed the renovate/9.3-sigstore branch from 82ffc91 to e9a0151 Compare July 1, 2026 10:07
@elastic-renovate-prod
elastic-renovate-prod Bot force-pushed the renovate/9.3-sigstore branch from e9a0151 to 35b9911 Compare July 3, 2026 22:58
@elastic-renovate-prod

elastic-renovate-prod Bot commented Jul 3, 2026

Copy link
Copy Markdown
Contributor Author

ℹ️ Artifact update notice

File name: go.mod

In order to perform the update(s) described in the table above, Renovate ran the go get command, which resulted in the following additional change(s):

  • 19 additional dependencies were updated

Details:

Package Change
go.opentelemetry.io/otel/sdk v1.43.0 -> v1.44.0
go.opentelemetry.io/otel/sdk/metric v1.43.0 -> v1.44.0
github.com/go-openapi/swag/conv v0.27.1 -> v0.27.3
github.com/go-openapi/swag/fileutils v0.27.1 -> v0.27.3
github.com/go-openapi/swag/jsonutils v0.27.1 -> v0.27.3
github.com/go-openapi/swag/loading v0.27.1 -> v0.27.3
github.com/go-openapi/swag/mangling v0.27.1 -> v0.27.3
github.com/go-openapi/swag/pools v0.27.1 -> v0.27.3
github.com/go-openapi/swag/stringutils v0.27.1 -> v0.27.3
github.com/go-openapi/swag/typeutils v0.27.1 -> v0.27.3
github.com/go-openapi/swag/yamlutils v0.27.1 -> v0.27.3
github.com/go-openapi/analysis v0.25.1 -> v0.25.5
github.com/go-openapi/loads v0.23.3 -> v0.25.0
github.com/go-openapi/runtime v0.32.2 -> v0.33.0
github.com/go-openapi/spec v0.22.5 -> v0.22.9
github.com/go-openapi/strfmt v0.26.3 -> v0.27.0
github.com/go-openapi/validate v0.25.3 -> v0.26.1
google.golang.org/genproto/googleapis/api v0.0.0-20260706201446-f0a921348800 -> v0.0.0-20260727163830-6c54dddc4772
google.golang.org/genproto/googleapis/rpc v0.0.0-20260706201446-f0a921348800 -> v0.0.0-20260720155508-bb71a54f79dc

@elastic-renovate-prod
elastic-renovate-prod Bot force-pushed the renovate/9.3-sigstore branch from 35b9911 to d01e0a1 Compare July 8, 2026 03:13
@elastic-renovate-prod
elastic-renovate-prod Bot force-pushed the renovate/9.3-sigstore branch from d01e0a1 to 3320024 Compare July 8, 2026 19:17
@elastic-renovate-prod
elastic-renovate-prod Bot force-pushed the renovate/9.3-sigstore branch from 3320024 to 1052902 Compare July 9, 2026 23:01
@elastic-renovate-prod
elastic-renovate-prod Bot force-pushed the renovate/9.3-sigstore branch from 1052902 to c4b0c6e Compare July 19, 2026 14:57
@mergify

mergify Bot commented Jul 23, 2026

Copy link
Copy Markdown
Contributor

This pull request is now in conflicts. Could you fix it? 🙏
To fixup this pull request, you can check out it locally. See documentation: https://help.github.com/articles/checking-out-pull-requests-locally/

git fetch upstream
git checkout -b renovate/9.3-sigstore upstream/renovate/9.3-sigstore
git merge upstream/9.3
git push upstream renovate/9.3-sigstore

@elastic-renovate-prod
elastic-renovate-prod Bot force-pushed the renovate/9.3-sigstore branch from c4b0c6e to fbde849 Compare July 23, 2026 03:02
@elastic-renovate-prod
elastic-renovate-prod Bot force-pushed the renovate/9.3-sigstore branch from fbde849 to 5aebd8a Compare July 30, 2026 21:28
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

backport-skip dependencies Pull requests that update a dependency file renovate renovate-auto-approve Team:Security-Cloud Services Security Data Experience - Cloud Services team.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants