chore(deps): update sigstore (8.19)#6124
chore(deps): update sigstore (8.19)#6124elastic-renovate-prod[bot] wants to merge 1 commit into8.19from
Conversation
ℹ Artifact update noticeFile name: go.modIn order to perform the update(s) described in the table above, Renovate ran the
Details:
|
|
This pull request is now in conflicts. Could you fix it? 🙏 |
27eae4b to
6036544
Compare
|
This pull request is now in conflicts. Could you fix it? 🙏 |
6036544 to
8f0a394
Compare
36f339c to
fd03abf
Compare
|
This pull request is now in conflicts. Could you fix it? 🙏 |
6f99a74 to
0f1122e
Compare
0f1122e to
4c0b76d
Compare
4c0b76d to
2083416
Compare
2083416 to
6ae854e
Compare
|
This pull request is now in conflicts. Could you fix it? 🙏 |
6ae854e to
34e5b6a
Compare
|
This pull request is now in conflicts. Could you fix it? 🙏 |
34e5b6a to
4f59887
Compare
4f59887 to
69a64db
Compare
This PR contains the following updates:
v2.2.4->v2.6.3v0.5.0->v0.5.1v1.5.0->v1.5.1v1.10.4->v1.10.5v1.10.4->v1.10.5v1.10.4->v1.10.5v1.10.4->v1.10.5v1.10.4->v1.10.5v1.2.2->v1.2.9Warning
Some dependencies could not be looked up. Check the Dependency Dashboard for more information.
Release Notes
sigstore/cosign (github.com/sigstore/cosign/v2)
v2.6.3Compare Source
Changelog
v2.6.3 resolves GHSA-w6c6-c85g-mmv6.
fecddd3Fix DSSE predicate check (#4802)564c5b1Backport bundle detection to sign and attest (#4727)Thanks to all contributors!
v2.6.2Compare Source
v2.6.2 resolves GHSA-whqx-f9j3-ch6m.
Changes
v2.6.1Compare Source
Bug Fixes
v2.6.0Compare Source
v2.6.0 introduces a number of new features, including:
Example generation and verification of a signed in-toto statement:
Example container signing and verification using the new bundle format and referring artifacts:
Example usage of a signing config provided by the public good instance's TUF repository:
v2.6.0 leverages sigstore-go's signing and verification APIs gated behind these new flags. In an upcoming major release, we will be
updating Cosign to default to producing and consuming bundles to align with all other Sigstore SDKs.
Features
attest-blobthe ability to supply a complete in-toto statement, and add toverify-blob-attestationthe ability to verify with just a digest (#4306)Breaking API Changes
sign.SignerFromKeyOptsno longer generates a key. Instead, it returns whether or not the client needs to generate a key, and if so, clientsshould call
sign.KeylessSigner. This allows clients to more easily manage key generation.Bug Fixes
v2.5.3Compare Source
Features
Bug Fixes
v2.5.2Compare Source
Bug Fixes
Documentation
v2.5.1Compare Source
Features
Bug Fixes
Docs
verify-blobcmd examples (#4160)Releases
Contributors
v2.5.0Compare Source
v2.5.0 includes an implementation of the new bundle specification,
attesting and verifying OCI image attestations uploaded as OCI artifacts.
This feature is currently gated behind the
--new-bundle-formatflagwhen running
cosign attest.Features
Fixes
Contributors
v2.4.3Compare Source
Features
Bug Fixes
Cleanup
Contributors
v2.4.2Compare Source
Features
--trusted-root(#3933)Bug Fixes
Documentation
Contributors
v2.4.1Compare Source
v2.4.1 largely contains bug fixes and updates dependencies.
Features
Bug Fixes
Contributors
v2.4.0Compare Source
v2.4.0 begins the modernization of the Cosign client, which includes:
through a trust root file, instead of many different flags
In future updates, we'll include:
format during verification
Cosign-specific bundle format
We have also moved nightly Cosign container builds to GHCR instead of GCR.
Features
verify-blobandverify-blob-attestation(#3796)email_verifiedas string or boolean (#3819)Contributors
v2.3.0Compare Source
Features
Bug Fixes
bundleVerifiedto true after Rekor verification (Resolves #3740) (#3745)Documentation
Testing
Contributors
sigstore/protobuf-specs (github.com/sigstore/protobuf-specs)
v0.5.1Compare Source
sigstore/rekor (github.com/sigstore/rekor)
v1.5.1Compare Source
Features
Bug Fixes
sigstore/sigstore (github.com/sigstore/sigstore)
v1.10.5Compare Source
What's Changed
Full Changelog: sigstore/sigstore@v1.10.4...v1.10.5
sigstore/timestamp-authority (github.com/sigstore/timestamp-authority)
v1.2.9Compare Source
v1.2.8Compare Source
Features
v1.2.7Compare Source
Features
Bug Fixes
v1.2.6Compare Source
Features
Bug Fixes
v1.2.5Compare Source
Enhancements
Changes
Bug fixes
Misc
v1.2.4Compare Source
Changes
Bug fixes
Misc
v1.2.3Compare Source
Changes
Bug fixes
Misc
Configuration
📅 Schedule: Branch creation - "* 1 * * 1-5" (UTC), Automerge - At any time (no schedule defined).
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR has been generated by Renovate Bot.