Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Bump github.com/sigstore/cosign/v2 from 2.2.4 to 2.3.0 (#350)
Bumps [github.com/sigstore/cosign/v2](https://github.com/sigstore/cosign) from 2.2.4 to 2.3.0. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/sigstore/cosign/releases">github.com/sigstore/cosign/v2's releases</a>.</em></p> <blockquote> <h1>v2.3.0</h1> <h2>Features</h2> <ul> <li>Add PayloadProvider interface to decouple AttestationToPayloadJSON from oci.Signature interface (<a href="https://redirect.github.com/sigstore/cosign/issues/3693">#3693</a>)</li> <li>add registry options to cosign save (<a href="https://redirect.github.com/sigstore/cosign/issues/3645">#3645</a>)</li> <li>Add debug providers command. (<a href="https://redirect.github.com/sigstore/cosign/issues/3728">#3728</a>)</li> <li>Make config layers in ociremote mountable (<a href="https://redirect.github.com/sigstore/cosign/issues/3741">#3741</a>)</li> <li>upgrade to go1.22 (<a href="https://redirect.github.com/sigstore/cosign/issues/3739">#3739</a>)</li> <li>adds tsa cert chain check for env var or tuf targets. (<a href="https://redirect.github.com/sigstore/cosign/issues/3600">#3600</a>)</li> <li>add --ca-roots and --ca-intermediates flags to 'cosign verify' (<a href="https://redirect.github.com/sigstore/cosign/issues/3464">#3464</a>)</li> <li>add handling of keyless verification for all verify commands (<a href="https://redirect.github.com/sigstore/cosign/issues/3761">#3761</a>)</li> </ul> <h2>Bug Fixes</h2> <ul> <li>fix: close attestationFile (<a href="https://redirect.github.com/sigstore/cosign/issues/3679">#3679</a>)</li> <li>Set <code>bundleVerified</code> to true after Rekor verification (Resolves <a href="https://redirect.github.com/sigstore/cosign/issues/3740">#3740</a>) (<a href="https://redirect.github.com/sigstore/cosign/issues/3745">#3745</a>)</li> </ul> <h2>Documentation</h2> <ul> <li>Document ImportKeyPair and LoadPrivateKey functions in pkg/cosign (<a href="https://redirect.github.com/sigstore/cosign/issues/3776">#3776</a>)</li> </ul> <h2>Testing</h2> <ul> <li>Refactor KMS E2E tests (<a href="https://redirect.github.com/sigstore/cosign/issues/3684">#3684</a>)</li> <li>Remove sign_blob_test.sh test (<a href="https://redirect.github.com/sigstore/cosign/issues/3707">#3707</a>)</li> <li>Remove KMS E2E test script (<a href="https://redirect.github.com/sigstore/cosign/issues/3702">#3702</a>)</li> <li>Refactor insecure registry E2E tests (<a href="https://redirect.github.com/sigstore/cosign/issues/3701">#3701</a>)</li> </ul> <h2>Contributors</h2> <ul> <li>Billy Lynch</li> <li>bminahan73</li> <li>Bob Callaway</li> <li>Carlos Tadeu Panato Junior</li> <li>Cody Soyland</li> <li>Colleen Murphy</li> <li>Dmitry Savintsev</li> <li>guangwu</li> <li>Hayden B</li> <li>Hector Fernandez</li> <li>ian hundere</li> <li>Jason Power</li> <li>Jon Johnson</li> <li>Max Lambrecht</li> <li>Meeki1l</li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/sigstore/cosign/compare/v2.2.4...v2.3.0">https://github.com/sigstore/cosign/compare/v2.2.4...v2.3.0</a></p> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/sigstore/cosign/blob/main/CHANGELOG.md">github.com/sigstore/cosign/v2's changelog</a>.</em></p> <blockquote> <h1>v2.3.0</h1> <h2>Features</h2> <ul> <li>Add PayloadProvider interface to decouple AttestationToPayloadJSON from oci.Signature interface (<a href="https://redirect.github.com/sigstore/cosign/issues/3693">#3693</a>)</li> <li>add registry options to cosign save (<a href="https://redirect.github.com/sigstore/cosign/issues/3645">#3645</a>)</li> <li>Add debug providers command. (<a href="https://redirect.github.com/sigstore/cosign/issues/3728">#3728</a>)</li> <li>Make config layers in ociremote mountable (<a href="https://redirect.github.com/sigstore/cosign/issues/3741">#3741</a>)</li> <li>upgrade to go1.22 (<a href="https://redirect.github.com/sigstore/cosign/issues/3739">#3739</a>)</li> <li>adds tsa cert chain check for env var or tuf targets. (<a href="https://redirect.github.com/sigstore/cosign/issues/3600">#3600</a>)</li> <li>add --ca-roots and --ca-intermediates flags to 'cosign verify' (<a href="https://redirect.github.com/sigstore/cosign/issues/3464">#3464</a>)</li> <li>add handling of keyless verification for all verify commands (<a href="https://redirect.github.com/sigstore/cosign/issues/3761">#3761</a>)</li> </ul> <h2>Bug Fixes</h2> <ul> <li>fix: close attestationFile (<a href="https://redirect.github.com/sigstore/cosign/issues/3679">#3679</a>)</li> <li>Set <code>bundleVerified</code> to true after Rekor verification (Resolves <a href="https://redirect.github.com/sigstore/cosign/issues/3740">#3740</a>) (<a href="https://redirect.github.com/sigstore/cosign/issues/3745">#3745</a>)</li> </ul> <h2>Documentation</h2> <ul> <li>Document ImportKeyPair and LoadPrivateKey functions in pkg/cosign (<a href="https://redirect.github.com/sigstore/cosign/issues/3776">#3776</a>)</li> </ul> <h2>Testing</h2> <ul> <li>Refactor KMS E2E tests (<a href="https://redirect.github.com/sigstore/cosign/issues/3684">#3684</a>)</li> <li>Remove sign_blob_test.sh test (<a href="https://redirect.github.com/sigstore/cosign/issues/3707">#3707</a>)</li> <li>Remove KMS E2E test script (<a href="https://redirect.github.com/sigstore/cosign/issues/3702">#3702</a>)</li> <li>Refactor insecure registry E2E tests (<a href="https://redirect.github.com/sigstore/cosign/issues/3701">#3701</a>)</li> </ul> <h2>Contributors</h2> <ul> <li>Billy Lynch</li> <li>bminahan73</li> <li>Bob Callaway</li> <li>Carlos Tadeu Panato Junior</li> <li>Cody Soyland</li> <li>Colleen Murphy</li> <li>Dmitry Savintsev</li> <li>guangwu</li> <li>Hayden B</li> <li>Hector Fernandez</li> <li>ian hundere</li> <li>Jason Power</li> <li>Jon Johnson</li> <li>Max Lambrecht</li> <li>Meeki1l</li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/sigstore/cosign/commit/deed3631520ddeb6cc7d81ace205a97342c8daab"><code>deed363</code></a> chore(deps): bump github.com/xanzy/go-gitlab from 0.106.0 to 0.107.0 (<a href="https://redirect.github.com/sigstore/cosign/issues/3792">#3792</a>)</li> <li><a href="https://github.com/sigstore/cosign/commit/c6f89f83c9e5721aa315b8e5a443421b528fb28d"><code>c6f89f8</code></a> chore(deps): bump github.com/buildkite/agent/v3 from 3.74.1 to 3.75.1 (<a href="https://redirect.github.com/sigstore/cosign/issues/3793">#3793</a>)</li> <li><a href="https://github.com/sigstore/cosign/commit/aeba4736c26d1b064f96f2138737cf72a803d079"><code>aeba473</code></a> Add CHANGELOG for v2.3.0 (<a href="https://redirect.github.com/sigstore/cosign/issues/3789">#3789</a>)</li> <li><a href="https://github.com/sigstore/cosign/commit/20d472467ab3b6a25d733f0899b0d9161257d6d0"><code>20d4724</code></a> chore(deps): bump github.com/google/go-containerregistry (<a href="https://redirect.github.com/sigstore/cosign/issues/3790">#3790</a>)</li> <li><a href="https://github.com/sigstore/cosign/commit/4684fd65453c68b6e0f1e4accb8cbd2573687f3b"><code>4684fd6</code></a> chore(deps): bump the gomod group with 5 updates (<a href="https://redirect.github.com/sigstore/cosign/issues/3780">#3780</a>)</li> <li><a href="https://github.com/sigstore/cosign/commit/3c6c5c92dcf0a609a2a6dbfef80f62f69c2e8756"><code>3c6c5c9</code></a> chore(deps): bump github.com/sigstore/fulcio from 1.4.5 to 1.5.1 (<a href="https://redirect.github.com/sigstore/cosign/issues/3784">#3784</a>)</li> <li><a href="https://github.com/sigstore/cosign/commit/05026ee992ffdba40ec2e15a4ad0f72cb81e1c0e"><code>05026ee</code></a> chore(deps): bump github.com/google/go-containerregistry (<a href="https://redirect.github.com/sigstore/cosign/issues/3783">#3783</a>)</li> <li><a href="https://github.com/sigstore/cosign/commit/f9270c01f5a8f6cb83e36659a5bd8190b92dd092"><code>f9270c0</code></a> chore(deps): bump google.golang.org/api from 0.187.0 to 0.188.0 (<a href="https://redirect.github.com/sigstore/cosign/issues/3782">#3782</a>)</li> <li><a href="https://github.com/sigstore/cosign/commit/4fd699ca8464ac32384dc7e07b7b683f7f85f051"><code>4fd699c</code></a> chore(deps): bump go.step.sm/crypto from 0.48.1 to 0.50.0 (<a href="https://redirect.github.com/sigstore/cosign/issues/3781">#3781</a>)</li> <li><a href="https://github.com/sigstore/cosign/commit/13d3a56434094087b516408cbe50675ab72ebe94"><code>13d3a56</code></a> chore(deps): bump the actions group across 1 directory with 2 updates (<a href="https://redirect.github.com/sigstore/cosign/issues/3785">#3785</a>)</li> <li>Additional commits viewable in <a href="https://github.com/sigstore/cosign/compare/v2.2.4...v2.3.0">compare view</a></li> </ul> </details> <br /> [![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=github.com/sigstore/cosign/v2&package-manager=go_modules&previous-version=2.2.4&new-version=2.3.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) </details> --------- Signed-off-by: dependabot[bot] <support@github.com> Signed-off-by: Kenny Leung <kleung@chainguard.dev> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: Kenny Leung <kleung@chainguard.dev>
- Loading branch information