Skip to content

Releases: sigstore/gitsign

v0.14.0

28 Jan 19:06
dd51a25

Choose a tag to compare

Thanks to all contributors!

What's Changed

  • Bump the gomod group across 1 directory with 5 updates by @dependabot[bot] in #665
  • Bump github.com/coreos/go-oidc/v3 from 3.12.0 to 3.13.0 by @dependabot[bot] in #652
  • Bump golang.org/x/oauth2 from 0.28.0 to 0.29.0 by @dependabot[bot] in #667
  • Bump github.com/sigstore/cosign/v2 from 2.4.3 to 2.5.0 by @dependabot[bot] in #669
  • Bump golangci/golangci-lint-action from 6.5.2 to 7.0.0 by @dependabot[bot] in #662
  • Bump github.com/go-git/go-git/v5 from 5.14.0 to 5.16.0 by @dependabot[bot] in #668
  • Bump the actions group with 2 updates by @dependabot[bot] in #670
  • Bump github.com/sigstore/fulcio from 1.6.6 to 1.7.0 by @dependabot[bot] in #666
  • Bump the gomod group across 1 directory with 2 updates by @dependabot[bot] in #672
  • Bump actions/attest-build-provenance from 2.2.3 to 2.3.0 in the actions group by @dependabot[bot] in #673
  • Bump golangci/golangci-lint-action from 7.0.0 to 8.0.0 by @dependabot[bot] in #674
  • Bump actions/setup-go from 5.4.0 to 5.5.0 in the actions group by @dependabot[bot] in #678
  • Bump golang.org/x/oauth2 from 0.29.0 to 0.30.0 by @dependabot[bot] in #677
  • Bump golang.org/x/crypto from 0.37.0 to 0.38.0 by @dependabot[bot] in #676
  • Bump anchore/sbom-action from 0.19.0 to 0.20.0 in the actions group by @dependabot[bot] in #680
  • Bump github.com/sigstore/protobuf-specs from 0.4.1 to 0.4.2 in the gomod group by @dependabot[bot] in #679
  • Bump golang.org/x/crypto from 0.38.0 to 0.39.0 by @dependabot[bot] in #682
  • Bump github.com/go-git/go-git/v5 from 5.16.0 to 5.16.2 in the gomod group by @dependabot[bot] in #681
  • Bump the actions group with 2 updates by @dependabot[bot] in #683
  • Bump the gomod group with 3 updates by @dependabot[bot] in #684
  • update cosign to v2.5.2 by @k4leung4 in #685
  • Bump sigstore/cosign-installer from 3.8.2 to 3.9.0 in the actions group by @dependabot[bot] in #686
  • Bump github.com/go-viper/mapstructure/v2 from 2.2.1 to 2.3.0 in the go_modules group by @dependabot[bot] in #688
  • Bump sigstore/cosign-installer from 3.9.0 to 3.9.1 in the actions group by @dependabot[bot] in #689
  • Bump anchore/sbom-action from 0.20.1 to 0.20.2 in the actions group by @dependabot[bot] in #690
  • Bump golang.org/x/crypto from 0.39.0 to 0.40.0 by @dependabot[bot] in #692
  • Bump github.com/sigstore/protobuf-specs from 0.4.3 to 0.5.0 by @dependabot[bot] in #691
  • Bump sigstore/cosign-installer from 3.9.1 to 3.9.2 in the actions group by @dependabot[bot] in #694
  • Bump the gomod group with 2 updates by @dependabot[bot] in #695
  • Bump anchore/sbom-action from 0.20.2 to 0.20.4 in the actions group by @dependabot[bot] in #696
  • Bump github.com/coreos/go-oidc/v3 from 3.14.1 to 3.15.0 by @dependabot[bot] in #697
  • Bump github.com/sigstore/rekor from 1.3.10 to 1.4.0 by @dependabot[bot] in #698
  • Bump github.com/secure-systems-lab/go-securesystemslib from 0.9.0 to 0.9.1 in the gomod group by @dependabot[bot] in #699
  • Bump golang.org/x/crypto from 0.40.0 to 0.41.0 by @dependabot[bot] in #702
  • Bump google.golang.org/protobuf from 1.36.6 to 1.36.7 in the gomod group by @dependabot[bot] in #701
  • Bump the actions group with 2 updates by @dependabot[bot] in #700
  • Bump actions/checkout from 4.2.2 to 5.0.0 by @dependabot[bot] in #704
  • Bump the actions group with 2 updates by @dependabot[bot] in #703
  • Bump github.com/go-viper/mapstructure/v2 from 2.3.0 to 2.4.0 in the go_modules group by @dependabot[bot] in #705
  • Bump google.golang.org/protobuf from 1.36.7 to 1.36.8 in the gomod group by @dependabot[bot] in #706
  • Bump github.com/coreos/go-systemd/v22 from 22.5.0 to 22.6.0 by @dependabot[bot] in #707
  • Bump github.com/spf13/cobra from 1.9.1 to 1.10.1 by @dependabot[bot] in #713
  • Bump golang.org/x/oauth2 from 0.30.0 to 0.31.0 by @dependabot[bot] in #711
  • Bump actions/setup-go from 5.5.0 to 6.0.0 by @dependabot[bot] in #709
  • Bump the actions group across 1 directory with 2 updates by @dependabot[bot] in #717
  • Fix e2e ci by @puerco in #738
  • Update gitsign to latest versions of sigstore tooling by @adityasaky in #733
  • Bump github.com/sigstore/cosign/v3 from 3.0.3 to 3.0.4 by @dependabot[bot] in #739
  • Bump the actions group across 1 directory with 3 updates by @dependabot[bot] in #732
  • Bump actions/attest-build-provenance from 2.4.0 to 3.0.0 by @dependabot[bot] in #708
  • Bump github.com/sigstore/fulcio from 1.7.1 to 1.8.5 by @dependabot[bot] in #735
  • ci clean and general updates by @cpanato in #740
  • Expose predicate builder by @puerco in #737
  • Bump github.com/theupdateframework/go-tuf/v2 from 2.3.0 to 2.4.1 by @dependabot[bot] in #755
  • Bump golangci/golangci-lint-action from 8.0.0 to 9.2.0 by @dependabot[bot] in #742
  • Bump github.com/in-toto/in-toto-golang from 0.9.0 to 0.10.0 by @dependabot[bot] in #753
  • Bump actions/checkout from 5.0.0 to 6.0.2 by @dependabot[bot] in #754
  • Bump github.com/sigstore/rekor from 1.4.3 to 1.5.0 by @dependabot[bot] in #750
  • Bump golang.org/x/crypto from 0.46.0 to 0.47.0 by @dependabot[bot] in #746
  • Bump actions/cache from 4.2.4 to 5.0.2 by @dependabot[bot] in #744
  • (fix): gosec, staticcheck, errcheck fixes by @sampras343 in #724
  • Redirect browser stdout/err to TTY out. by @wlynch in #757

New Contributors

Full Changelog: v0.13.0...v0.14.0

v0.13.0

09 Apr 15:16
b17948d

Choose a tag to compare

What's Changed

New Contributors

Full Changelog: v0.12.0...v0.13.0

v0.12.0

04 Jan 16:34
9fc97de

Choose a tag to compare

What's Changed

  • Update release.yml - add attestations:write by @wlynch in #586
  • README: add warning about internet access by @philips in #596
  • attest: force https for rekor client by @wlynch in #610

New Contributors

Full Changelog: v0.11.0...v0.12.0

v0.11.0

04 Nov 23:52
8e08985

Choose a tag to compare

Changelog

  • 8e08985 Bump github.com/sigstore/cosign/v2 from 2.2.4 to 2.4.1 (#573)
  • 036c118 Fix matching of tlog entries to payload (#584)
  • da79e4b Fix unhandled extension issue for cached certs (#583)
  • 02af74d Update credential-cache messages to user (#582)
  • 51907a6 Support gitsign-credential-cache on Windows (#579)
  • 45f647b Bump google.golang.org/protobuf from 1.34.2 to 1.35.1 (#580)
  • 6b63283 Bump anchore/sbom-action from 0.17.3 to 0.17.4 in the actions group (#581)
  • 1b11c27 Trigger workflows on push only to main branch (#578)
  • 73821e1 Bump the gomod group across 1 directory with 2 updates (#577)
  • 0a530d1 Bump github.com/sigstore/fulcio from 1.5.1 to 1.6.5 (#575)
  • 3a6b5ff Bump Go to 1.23.2 and golangci-lint to 1.61 (#576)
  • ec41a4e Bump anchore/sbom-action from 0.17.2 to 0.17.3 in the actions group (#572)
  • a9e5bf9 Bump github.com/docker/docker (#553)
  • aa71ea8 Handle GeneralName as SAN (#571)
  • 7b9a59e Bump the actions group across 1 directory with 6 updates (#569)
  • 6619f72 Fix gitsign env test (#568)
  • 512c386 Bump the actions group with 2 updates (#552)
  • 7d7b847 e2e tests: Use beacon token. (#549)
  • 6ba65fc Bump github.com/sigstore/fulcio from 1.4.5 to 1.5.1 (#541)
  • 3a204ff Bump github.com/mattn/go-tty from 0.0.5 to 0.0.7 in the gomod group (#546)
  • 0504d6b Bump docker/login-action from 3.2.0 to 3.3.0 in the actions group (#545)
  • a7b5867 Bump anchore/sbom-action from 0.16.1 to 0.17.0 in the actions group (#543)
  • fdd6e3a update go to 1.22.5 and fix golangci-lint action (#542)
  • e999077 Bump github.com/sigstore/sigstore from 1.8.6 to 1.8.7 in the gomod group (#539)
  • 94dc609 Bump github.com/coreos/go-oidc/v3 from 3.10.0 to 3.11.0 (#540)
  • 7d10c99 Bump the actions group with 3 updates (#538)
  • 359a77d Bump google.golang.org/grpc from 1.64.0 to 1.64.1 (#536)
  • 1624fdb Bump golang.org/x/crypto from 0.24.0 to 0.25.0 (#535)
  • 0ba49a1 Bump github.com/sigstore/sigstore from 1.8.4 to 1.8.6 in the gomod group (#534)
  • 6431500 Support for Client Secret File (#533)
  • d911d96 Point to homebrew-core (#531)
  • 7819bd0 Bump actions/attest-build-provenance in the actions group (#530)
  • 56549b7 Bump actions/attest-build-provenance in the actions group (#529)
  • 3e5444a Updates ci/dependabot/release (#528)
  • d20b0f0 Bump github.com/spf13/cobra from 1.8.0 to 1.8.1 (#527)
  • 36ec1cc Bump imjasonh/setup-crane from 0.3 to 0.4 (#524)
  • bed15d1 Bump actions/checkout from 4.1.6 to 4.1.7 (#525)
  • 024ac5f Bump goreleaser/goreleaser-action from 5.1.0 to 6.0.0 (#521)
  • 42af7c1 Bump golang.org/x/oauth2 from 0.20.0 to 0.21.0 (#522)
  • 3c280a2 Bump golang.org/x/crypto from 0.23.0 to 0.24.0 (#523)
  • bc5ec37 resolves #516 adds support for private rekor for gitsign attest (#517)
  • d94bdd9 launchctl commands for macOS users (#520)
  • 51c08dc Bump github.com/sigstore/sigstore from 1.8.3 to 1.8.4 (#518)
  • 7dbcc46 Bump docker/login-action from 3.1.0 to 3.2.0 (#519)
  • 2818752 Bump anchore/sbom-action from 0.15.11 to 0.16.0 (#514)
  • 7c3d86d Bump actions/checkout from 4.1.5 to 4.1.6 (#513)

Thanks to all contributors!

v0.10.2

13 May 08:17
537cd20

Choose a tag to compare

What's Changed

Not much! All dependency bumps.

New Contributors

  • @jku made their first contribution in #496

Full Changelog: v0.10.1...v0.10.2

v0.10.1

02 Apr 18:37
337b099

Choose a tag to compare

Changelog

  • 337b099 update base image for gitsign to one with shell available (#484)

Thanks to all contributors!

v0.10.0

02 Apr 17:40
6ee714f

Choose a tag to compare

What's Changed

  • Bump github.com/go-jose/go-jose/v3 from 3.0.2 to 3.0.3 by @dependabot in #468
  • Bump gopkg.in/go-jose/go-jose.v2 from 2.6.1 to 2.6.3 by @dependabot in #467
  • Bump anchore/sbom-action from 0.15.8 to 0.15.9 by @dependabot in #475
  • Bump golang.org/x/crypto from 0.20.0 to 0.21.0 by @dependabot in #474
  • Bump google.golang.org/protobuf from 1.32.0 to 1.33.0 by @dependabot in #473
  • Bump golang.org/x/oauth2 from 0.17.0 to 0.18.0 by @dependabot in #472
  • Bump github.com/go-openapi/strfmt from 0.22.2 to 0.23.0 by @dependabot in #471
  • Bump github.com/go-openapi/swag from 0.22.9 to 0.23.0 by @dependabot in #470
  • Bump github.com/go-openapi/runtime from 0.27.1 to 0.28.0 by @dependabot in #469
  • Bump actions/checkout from 4.1.1 to 4.1.2 by @dependabot in #476
  • Bump github.com/docker/docker from 24.0.7+incompatible to 24.0.9+incompatible by @dependabot in #477
  • Bump github.com/coreos/go-oidc/v3 from 3.9.0 to 3.10.0 by @dependabot in #479
  • Bump actions/cache from 4.0.1 to 4.0.2 by @dependabot in #478
  • Bump github.com/sigstore/sigstore from 1.8.2 to 1.8.3 by @dependabot in #482
  • Bump anchore/sbom-action from 0.15.9 to 0.15.10 by @dependabot in #480
  • Bump github.com/go-git/go-git/v5 from 5.11.1-0.20240221104814-686a0f7a4928 to 5.12.0 by @dependabot in #481
  • add gitsign image by @cpanato in #483

Full Changelog: v0.9.0...v0.10.0

v0.9.0

02 Apr 17:25
e20deaa

Choose a tag to compare

Changelog

  • e20deaa Add config options for Autoclose and AutocloseTimeout (#466)
  • 3f2e97e Bump actions/cache from 4.0.0 to 4.0.1 (#456)
  • 9ba5809 Bump github.com/go-openapi/strfmt from 0.22.0 to 0.22.2 (#464)
  • 98923e1 Update to use go1.22 and ci udpates (#465)
  • b3da2e6 Enable autoclose for sigstore confirmation page. (#455)
  • c2ac22d CI updates and fix lints (#461)
  • cedcc9d Remove GITSIGN_LOG env variable. (#463)
  • 2e63fd0 Run e2e Go tests first. (#462)
  • 6f20ffd Add go-git based signer implementation. (#454)
  • 66e0ff5 Bump github.com/sigstore/protobuf-specs from 0.2.1 to 0.3.0 (#453)
  • 57153a0 Bump golangci/golangci-lint-action from 3.7.0 to 4.0.0 (#450)
  • 3eafadd Bump golang.org/x/oauth2 from 0.16.0 to 0.17.0 (#449)
  • ae02bda Add GITSIGN_TOKEN_PROVIDER docs (#447)
  • ff05b31 Add tokenProvider configuration for forcing OIDC providers. (#446)

Thanks to all contributors!

v0.8.1

12 Feb 08:59
bbd2c9c

Choose a tag to compare

What's Changed

Not much! All dependency bumps. 😎

Full Changelog: v0.8.0...v0.8.1

v0.8.0

09 Nov 22:42
cd66ccb

Choose a tag to compare

Rekor: https://search.sigstore.dev/?commitSha=01375268d822f8299a3d9c23f4fbd796c84bcaa5

Highlights

  • cd66ccb Add options for Rekor client, make public key fetcher configurable. (#399)
  • 530e976 Add gitsign initialize. (#321)
  • 4bda12e Fix offline verification marshalling, add e2e tests. (#330)

Thanks to all contributors!