Skip to content

Commit 819d566

Browse files
Bump github.com/sigstore/cosign/v2 from 2.5.0 to 2.5.2 (#1611)
* Bump github.com/sigstore/cosign/v2 from 2.5.0 to 2.5.2 Bumps [github.com/sigstore/cosign/v2](https://github.com/sigstore/cosign) from 2.5.0 to 2.5.2. - [Release notes](https://github.com/sigstore/cosign/releases) - [Changelog](https://github.com/sigstore/cosign/blob/main/CHANGELOG.md) - [Commits](sigstore/cosign@v2.5.0...v2.5.2) --- updated-dependencies: - dependency-name: github.com/sigstore/cosign/v2 dependency-version: 2.5.2 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com> * update API call Signed-off-by: Bob Callaway <bcallaway@google.com> --------- Signed-off-by: dependabot[bot] <support@github.com> Signed-off-by: Bob Callaway <bcallaway@google.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: Bob Callaway <bcallaway@google.com>
1 parent dfd237f commit 819d566

File tree

3 files changed

+85
-95
lines changed

3 files changed

+85
-95
lines changed

cmd/prober/write.go

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -285,7 +285,7 @@ func rekorWriteEndpoint(ctx context.Context, cert *x509.Certificate, priv *ecdsa
285285
if err != nil {
286286
return fmt.Errorf("getting rekor public keys: %w", err)
287287
}
288-
if err = cosign.VerifyTLogEntryOffline(ctx, &logEntryAnon, rekorPubKeys); err == nil {
288+
if err = cosign.VerifyTLogEntryOffline(ctx, &logEntryAnon, rekorPubKeys, nil); err == nil {
289289
verified = "true"
290290
}
291291
return err

go.mod

Lines changed: 22 additions & 24 deletions
Original file line numberDiff line numberDiff line change
@@ -32,7 +32,7 @@ require (
3232
github.com/mitchellh/mapstructure v1.5.1-0.20231216201459-8508981c8b6c
3333
github.com/prometheus/client_golang v1.22.0
3434
github.com/ryanuber/go-glob v1.0.0
35-
github.com/sigstore/cosign/v2 v2.5.0
35+
github.com/sigstore/cosign/v2 v2.5.2
3636
github.com/sigstore/fulcio v1.7.1
3737
github.com/sigstore/rekor v1.3.10
3838
github.com/sigstore/sigstore v1.9.5
@@ -62,7 +62,7 @@ require (
6262
require (
6363
bitbucket.org/creachadair/shell v0.0.8 // indirect
6464
cel.dev/expr v0.23.0 // indirect
65-
cloud.google.com/go v0.120.0 // indirect
65+
cloud.google.com/go v0.121.1 // indirect
6666
cloud.google.com/go/auth v0.16.2 // indirect
6767
cloud.google.com/go/auth/oauth2adapt v0.2.8 // indirect
6868
cloud.google.com/go/compute/metadata v0.7.0 // indirect
@@ -92,7 +92,6 @@ require (
9292
github.com/GoogleCloudPlatform/grpc-gcp-go/grpcgcp v1.5.2 // indirect
9393
github.com/GoogleCloudPlatform/opentelemetry-operations-go/detectors/gcp v1.27.0 // indirect
9494
github.com/Microsoft/go-winio v0.6.2 // indirect
95-
github.com/ProtonMail/go-crypto v0.0.0-20230923063757-afb1ddc0824c // indirect
9695
github.com/ThalesIgnite/crypto11 v1.2.5 // indirect
9796
github.com/alibabacloud-go/alibabacloud-gateway-spi v0.0.4 // indirect
9897
github.com/alibabacloud-go/cr-20160607 v1.0.1 // indirect
@@ -106,7 +105,7 @@ require (
106105
github.com/alibabacloud-go/tea-xml v1.1.3 // indirect
107106
github.com/aliyun/credentials-go v1.3.2 // indirect
108107
github.com/asaskevich/govalidator v0.0.0-20230301143203-a9d515a09cc2 // indirect
109-
github.com/aws/aws-sdk-go v1.55.6 // indirect
108+
github.com/aws/aws-sdk-go v1.55.7 // indirect
110109
github.com/aws/aws-sdk-go-v2 v1.36.4 // indirect
111110
github.com/aws/aws-sdk-go-v2/config v1.29.16 // indirect
112111
github.com/aws/aws-sdk-go-v2/credentials v1.17.69 // indirect
@@ -127,7 +126,7 @@ require (
127126
github.com/beorn7/perks v1.0.1 // indirect
128127
github.com/blang/semver v3.5.1+incompatible // indirect
129128
github.com/blendle/zapdriver v1.3.1 // indirect
130-
github.com/buildkite/agent/v3 v3.95.1 // indirect
129+
github.com/buildkite/agent/v3 v3.98.2 // indirect
131130
github.com/buildkite/go-pipeline v0.13.3 // indirect
132131
github.com/buildkite/interpolate v0.1.5 // indirect
133132
github.com/buildkite/roko v1.3.1 // indirect
@@ -137,31 +136,30 @@ require (
137136
github.com/cespare/xxhash/v2 v2.3.0 // indirect
138137
github.com/chrismellard/docker-credential-acr-env v0.0.0-20230304212654-82a0ddb27589 // indirect
139138
github.com/clbanning/mxj/v2 v2.7.0 // indirect
140-
github.com/cloudflare/circl v1.6.1 // indirect
141139
github.com/cncf/xds/go v0.0.0-20250326154945-ae57f3c0d45f // indirect
142140
github.com/cockroachdb/cockroach-go/v2 v2.4.0 // indirect
143141
github.com/common-nighthawk/go-figure v0.0.0-20210622060536-734e95fb86be // indirect
144142
github.com/containerd/stargz-snapshotter/estargz v0.16.3 // indirect
145143
github.com/coreos/go-oidc/v3 v3.14.1 // indirect
146144
github.com/coreos/go-semver v0.3.1 // indirect
147145
github.com/coreos/go-systemd/v22 v22.5.0 // indirect
148-
github.com/cyberphone/json-canonicalization v0.0.0-20231011164504-785e29786b46 // indirect
146+
github.com/cyberphone/json-canonicalization v0.0.0-20241213102144-19d51d7fe467 // indirect
149147
github.com/davecgh/go-spew v1.1.2-0.20180830191138-d8f796af33cc // indirect
150148
github.com/digitorus/pkcs7 v0.0.0-20230818184609-3a137a874352 // indirect
151149
github.com/digitorus/timestamp v0.0.0-20231217203849-220c5c2851b7 // indirect
152150
github.com/dimchansky/utfbom v1.1.1 // indirect
153-
github.com/docker/cli v27.5.0+incompatible // indirect
151+
github.com/docker/cli v28.2.2+incompatible // indirect
154152
github.com/docker/distribution v2.8.3+incompatible // indirect
155-
github.com/docker/docker-credential-helpers v0.8.2 // indirect
153+
github.com/docker/docker-credential-helpers v0.9.3 // indirect
156154
github.com/dustin/go-humanize v1.0.1 // indirect
157155
github.com/emicklei/go-restful/v3 v3.11.0 // indirect
158156
github.com/envoyproxy/go-control-plane/envoy v1.32.4 // indirect
159157
github.com/envoyproxy/protoc-gen-validate v1.2.1 // indirect
160158
github.com/felixge/httpsnoop v1.0.4 // indirect
161-
github.com/fsnotify/fsnotify v1.8.0 // indirect
159+
github.com/fsnotify/fsnotify v1.9.0 // indirect
162160
github.com/fxamacker/cbor/v2 v2.7.0 // indirect
163161
github.com/go-chi/chi v4.1.2+incompatible // indirect
164-
github.com/go-logr/logr v1.4.2 // indirect
162+
github.com/go-logr/logr v1.4.3 // indirect
165163
github.com/go-logr/stdr v1.2.2 // indirect
166164
github.com/go-openapi/analysis v0.23.0 // indirect
167165
github.com/go-openapi/errors v0.22.1 // indirect
@@ -180,8 +178,8 @@ require (
180178
github.com/golang/protobuf v1.5.4 // indirect
181179
github.com/golang/snappy v0.0.4 // indirect
182180
github.com/google/gnostic-models v0.6.9 // indirect
183-
github.com/google/go-containerregistry v0.20.4-0.20250225234217-098045d5e61f // indirect
184-
github.com/google/go-github/v55 v55.0.0 // indirect
181+
github.com/google/go-containerregistry v0.20.6 // indirect
182+
github.com/google/go-github/v72 v72.0.0 // indirect
185183
github.com/google/go-querystring v1.1.0 // indirect
186184
github.com/google/s2a-go v0.1.9 // indirect
187185
github.com/googleapis/enterprise-certificate-proxy v0.3.6 // indirect
@@ -223,10 +221,10 @@ require (
223221
github.com/oklog/ulid v1.3.1 // indirect
224222
github.com/oleiade/reflections v1.1.0 // indirect
225223
github.com/opencontainers/go-digest v1.0.0 // indirect
226-
github.com/opencontainers/image-spec v1.1.0 // indirect
224+
github.com/opencontainers/image-spec v1.1.1 // indirect
227225
github.com/opentracing/opentracing-go v1.2.0 // indirect
228226
github.com/pborman/uuid v1.2.1 // indirect
229-
github.com/pelletier/go-toml/v2 v2.2.3 // indirect
227+
github.com/pelletier/go-toml/v2 v2.2.4 // indirect
230228
github.com/pkg/browser v0.0.0-20240102092130-5ac0b6a4141c // indirect
231229
github.com/pkg/errors v0.9.1 // indirect
232230
github.com/planetscale/vtprotobuf v0.6.1-0.20240319094008-0393e58bdf10 // indirect
@@ -241,11 +239,11 @@ require (
241239
github.com/secure-systems-lab/go-securesystemslib v0.9.0 // indirect
242240
github.com/segmentio/ksuid v1.0.4 // indirect
243241
github.com/shibumi/go-pathspec v1.3.0 // indirect
244-
github.com/sigstore/protobuf-specs v0.4.1 // indirect
245-
github.com/sigstore/sigstore/pkg/signature/kms/aws v1.9.4 // indirect
246-
github.com/sigstore/sigstore/pkg/signature/kms/azure v1.9.4 // indirect
247-
github.com/sigstore/sigstore/pkg/signature/kms/gcp v1.9.4 // indirect
248-
github.com/sigstore/sigstore/pkg/signature/kms/hashivault v1.9.4 // indirect
242+
github.com/sigstore/protobuf-specs v0.4.3 // indirect
243+
github.com/sigstore/sigstore/pkg/signature/kms/aws v1.9.5 // indirect
244+
github.com/sigstore/sigstore/pkg/signature/kms/azure v1.9.5 // indirect
245+
github.com/sigstore/sigstore/pkg/signature/kms/gcp v1.9.5 // indirect
246+
github.com/sigstore/sigstore/pkg/signature/kms/hashivault v1.9.5 // indirect
249247
github.com/sirupsen/logrus v1.9.3 // indirect
250248
github.com/skratchdot/open-golang v0.0.0-20200116055534-eef842397966 // indirect
251249
github.com/sourcegraph/conc v0.3.0 // indirect
@@ -266,10 +264,10 @@ require (
266264
github.com/tjfoc/gmsm v1.4.1 // indirect
267265
github.com/tomasen/realip v0.0.0-20180522021738-f0c99a92ddce // indirect
268266
github.com/transparency-dev/merkle v0.0.2 // indirect
269-
github.com/vbatts/tar-split v0.11.6 // indirect
267+
github.com/vbatts/tar-split v0.12.1 // indirect
270268
github.com/x448/float16 v0.8.4 // indirect
271269
github.com/zeebo/errs v1.4.0 // indirect
272-
gitlab.com/gitlab-org/api/client-go v0.127.0 // indirect
270+
gitlab.com/gitlab-org/api/client-go v0.130.1 // indirect
273271
go.etcd.io/etcd/api/v3 v3.6.0 // indirect
274272
go.etcd.io/etcd/client/pkg/v3 v3.6.0 // indirect
275273
go.etcd.io/etcd/client/v3 v3.6.0 // indirect
@@ -292,9 +290,9 @@ require (
292290
golang.org/x/sys v0.33.0 // indirect
293291
golang.org/x/term v0.32.0 // indirect
294292
golang.org/x/text v0.26.0 // indirect
295-
golang.org/x/tools v0.33.0 // indirect
293+
golang.org/x/tools v0.34.0 // indirect
296294
google.golang.org/api v0.237.0 // indirect
297-
google.golang.org/genproto/googleapis/api v0.0.0-20250505200425-f936aa4a68b2 // indirect
295+
google.golang.org/genproto/googleapis/api v0.0.0-20250519155744-55703ea1f237 // indirect
298296
google.golang.org/genproto/googleapis/rpc v0.0.0-20250603155806-513f23925822 // indirect
299297
gopkg.in/evanphx/json-patch.v4 v4.12.0 // indirect
300298
gopkg.in/inf.v0 v0.9.1 // indirect

0 commit comments

Comments
 (0)