Sourced from github.com/sigstore/cosign/v2's releases.
v2.3.0
Features
- Add PayloadProvider interface to decouple AttestationToPayloadJSON from oci.Signature interface (#3693)
- add registry options to cosign save (#3645)
- Add debug providers command. (#3728)
- Make config layers in ociremote mountable (#3741)
- upgrade to go1.22 (#3739)
- adds tsa cert chain check for env var or tuf targets. (#3600)
- add --ca-roots and --ca-intermediates flags to 'cosign verify' (#3464)
- add handling of keyless verification for all verify commands (#3761)
Bug Fixes
- fix: close attestationFile (#3679)
- Set
bundleVerified
to true after Rekor verification (Resolves #3740) (#3745)Documentation
- Document ImportKeyPair and LoadPrivateKey functions in pkg/cosign (#3776)
Testing
- Refactor KMS E2E tests (#3684)
- Remove sign_blob_test.sh test (#3707)
- Remove KMS E2E test script (#3702)
- Refactor insecure registry E2E tests (#3701)
Contributors
- Billy Lynch
- bminahan73
- Bob Callaway
- Carlos Tadeu Panato Junior
- Cody Soyland
- Colleen Murphy
- Dmitry Savintsev
- guangwu
- Hayden B
- Hector Fernandez
- ian hundere
- Jason Power
- Jon Johnson
- Max Lambrecht
- Meeki1l
Full Changelog: https://github.com/sigstore/cosign/compare/v2.2.4...v2.3.0
Sourced from github.com/sigstore/cosign/v2's changelog.
v2.3.0
Features
- Add PayloadProvider interface to decouple AttestationToPayloadJSON from oci.Signature interface (#3693)
- add registry options to cosign save (#3645)
- Add debug providers command. (#3728)
- Make config layers in ociremote mountable (#3741)
- upgrade to go1.22 (#3739)
- adds tsa cert chain check for env var or tuf targets. (#3600)
- add --ca-roots and --ca-intermediates flags to 'cosign verify' (#3464)
- add handling of keyless verification for all verify commands (#3761)
Bug Fixes
- fix: close attestationFile (#3679)
- Set
bundleVerified
to true after Rekor verification (Resolves #3740) (#3745)Documentation
- Document ImportKeyPair and LoadPrivateKey functions in pkg/cosign (#3776)
Testing
- Refactor KMS E2E tests (#3684)
- Remove sign_blob_test.sh test (#3707)
- Remove KMS E2E test script (#3702)
- Refactor insecure registry E2E tests (#3701)
Contributors
- Billy Lynch
- bminahan73
- Bob Callaway
- Carlos Tadeu Panato Junior
- Cody Soyland
- Colleen Murphy
- Dmitry Savintsev
- guangwu
- Hayden B
- Hector Fernandez
- ian hundere
- Jason Power
- Jon Johnson
- Max Lambrecht
- Meeki1l
deed363
chore(deps): bump github.com/xanzy/go-gitlab from 0.106.0 to 0.107.0 (#3792)c6f89f8
chore(deps): bump github.com/buildkite/agent/v3 from 3.74.1 to 3.75.1
(#3793)aeba473
Add CHANGELOG for v2.3.0 (#3789)20d4724
chore(deps): bump github.com/google/go-containerregistry (#3790)4684fd6
chore(deps): bump the gomod group with 5 updates (#3780)3c6c5c9
chore(deps): bump github.com/sigstore/fulcio from 1.4.5 to 1.5.1 (#3784)05026ee
chore(deps): bump github.com/google/go-containerregistry (#3783)f9270c0
chore(deps): bump google.golang.org/api from 0.187.0 to 0.188.0 (#3782)4fd699c
chore(deps): bump go.step.sm/crypto from 0.48.1 to 0.50.0 (#3781)13d3a56
chore(deps): bump the actions group across 1 directory with 2 updates
(#3785)