Skip to content

Conversation

renovate-rancher[bot]
Copy link
Contributor

This PR contains the following updates:

Package Type Update Change
github.com/sigstore/cosign/v2 require minor v2.4.3 -> v2.5.0

Warning

Some dependencies could not be looked up. Check the warning logs for more information.


Release Notes

sigstore/cosign (github.com/sigstore/cosign/v2)

v2.5.0

Compare Source

v2.5.0 includes an implementation of the new bundle specification,
attesting and verifying OCI image attestations uploaded as OCI artifacts.
This feature is currently gated behind the --new-bundle-format flag
when running cosign attest.

Features

  • Add support for new bundle specification for attesting/verifying OCI image attestations (#​3889)
  • Feat/non filename completions (#​4115)
  • Add TSA certificate related flags and fields for cosign attest (#​4079)

Fixes

  • cmd/cosign/cli: fix typo in ignoreTLogMessage (#​4111)
  • Fix replace with compliant image mediatype (#​4077)

Contributors

  • Bob Callaway
  • Carlos Tadeu Panato Junior
  • Cody Soyland
  • Dmitry Savintsev
  • Hayden B
  • Ramon Petgrave
  • Riccardo Schirone
  • Stef Graces
  • Ville Skyttä

Configuration

📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Renovate Bot.

Copy link
Contributor Author

ℹ Artifact update notice

File name: go.mod

In order to perform the update(s) described in the table above, Renovate ran the go get command, which resulted in the following additional change(s):

  • 27 additional dependencies were updated

Details:

Package Change
github.com/go-openapi/errors v0.22.0 -> v0.22.1
github.com/go-openapi/swag v0.23.0 -> v0.23.1
github.com/in-toto/attestation v1.1.0 -> v1.1.1
github.com/mailru/easyjson v0.7.7 -> v0.9.0
github.com/sagikazarmark/locafero v0.4.0 -> v0.7.0
github.com/sigstore/protobuf-specs v0.4.0 -> v0.4.1
github.com/sigstore/sigstore-go v0.7.0 -> v0.7.1
github.com/sigstore/timestamp-authority v1.2.4 -> v1.2.5
github.com/spf13/afero v1.11.0 -> v1.12.0
github.com/spf13/cast v1.7.0 -> v1.7.1
github.com/spf13/viper v1.19.0 -> v1.20.1
gitlab.com/gitlab-org/api/client-go v0.123.0 -> v0.127.0
go.opentelemetry.io/otel v1.34.0 -> v1.35.0
go.opentelemetry.io/otel/metric v1.34.0 -> v1.35.0
go.opentelemetry.io/otel/trace v1.34.0 -> v1.35.0
golang.org/x/crypto v0.35.0 -> v0.37.0
golang.org/x/mod v0.22.0 -> v0.24.0
golang.org/x/net v0.35.0 -> v0.38.0
golang.org/x/oauth2 v0.27.0 -> v0.29.0
golang.org/x/sync v0.11.0 -> v0.13.0
golang.org/x/sys v0.30.0 -> v0.32.0
golang.org/x/term v0.29.0 -> v0.31.0
golang.org/x/text v0.22.0 -> v0.24.0
golang.org/x/time v0.10.0 -> v0.11.0
google.golang.org/genproto/googleapis/api v0.0.0-20250115164207-1a7da9e5054f -> v0.0.0-20250303144028-a0af3efb3deb
google.golang.org/protobuf v1.36.5 -> v1.36.6
k8s.io/utils v0.0.0-20240502163921-fe8a2dddb1d0 -> v0.0.0-20241210054802-24370beab758

@holyspectral holyspectral merged commit e8861ea into main Apr 8, 2025
3 checks passed
@holyspectral holyspectral deleted the renovate/github.com-sigstore-cosign-v2-2.x branch April 8, 2025 19:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant