Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Bump github.com/sigstore/sigstore from 1.8.9 to 1.8.10 (#236)
Bumps [github.com/sigstore/sigstore](https://github.com/sigstore/sigstore) from 1.8.9 to 1.8.10. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/sigstore/sigstore/releases">github.com/sigstore/sigstore's releases</a>.</em></p> <blockquote> <h2>v1.8.10</h2> <h2>What's Changed</h2> <ul> <li>fix(kms): fix CreateKey may panic when using GCP KMS by <a href="https://github.com/mozillazg"><code>@mozillazg</code></a> in <a href="https://redirect.github.com/sigstore/sigstore/pull/1829">sigstore/sigstore#1829</a></li> <li>update to go1.22.7 and ci job by <a href="https://github.com/cpanato"><code>@cpanato</code></a> in <a href="https://redirect.github.com/sigstore/sigstore/pull/1847">sigstore/sigstore#1847</a></li> <li>Mark TUF client as deprecated by <a href="https://github.com/haydentherapper"><code>@haydentherapper</code></a> in <a href="https://redirect.github.com/sigstore/sigstore/pull/1858">sigstore/sigstore#1858</a></li> <li>bump to go 1.22.8 by <a href="https://github.com/cpanato"><code>@cpanato</code></a> in <a href="https://redirect.github.com/sigstore/sigstore/pull/1865">sigstore/sigstore#1865</a></li> </ul> <p>and several dependencies updates</p> <h2>New Contributors</h2> <ul> <li><a href="https://github.com/mozillazg"><code>@mozillazg</code></a> made their first contribution in <a href="https://redirect.github.com/sigstore/sigstore/pull/1829">sigstore/sigstore#1829</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/sigstore/sigstore/compare/v1.8.9...v1.8.10">https://github.com/sigstore/sigstore/compare/v1.8.9...v1.8.10</a></p> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/sigstore/sigstore/commit/305ff9e7b256ec7b651d8d2358a0d0ac05a25c6d"><code>305ff9e</code></a> bump to go 1.22.8 (<a href="https://redirect.github.com/sigstore/sigstore/issues/1865">#1865</a>)</li> <li><a href="https://github.com/sigstore/sigstore/commit/d88a94963e8adf441531edc964be6096e1f1adc9"><code>d88a949</code></a> build(deps): Bump github.com/Azure/azure-sdk-for-go/sdk/azidentity (<a href="https://redirect.github.com/sigstore/sigstore/issues/1860">#1860</a>)</li> <li><a href="https://github.com/sigstore/sigstore/commit/cfde8635e05263f9f12913f209e57e5afd54d583"><code>cfde863</code></a> build(deps): Bump the gomod group across 1 directory with 3 updates (<a href="https://redirect.github.com/sigstore/sigstore/issues/1859">#1859</a>)</li> <li><a href="https://github.com/sigstore/sigstore/commit/e928a8411d89feb1814c75b60f99e1b7d56258b9"><code>e928a84</code></a> build(deps): Bump github.com/Azure/azure-sdk-for-go/sdk/azcore (<a href="https://redirect.github.com/sigstore/sigstore/issues/1861">#1861</a>)</li> <li><a href="https://github.com/sigstore/sigstore/commit/66f05db4fe891b86ad43c3328ebcd0346b54ec45"><code>66f05db</code></a> build(deps): Bump google.golang.org/api in /pkg/signature/kms/gcp (<a href="https://redirect.github.com/sigstore/sigstore/issues/1862">#1862</a>)</li> <li><a href="https://github.com/sigstore/sigstore/commit/f0978ed44a4cc452b4a231548027cf5b6106b8d4"><code>f0978ed</code></a> build(deps): Bump the all group with 2 updates (<a href="https://redirect.github.com/sigstore/sigstore/issues/1863">#1863</a>)</li> <li><a href="https://github.com/sigstore/sigstore/commit/9398b129c7659d4bf6aa7be9603c0b15e8387730"><code>9398b12</code></a> build(deps): Bump the all group in /test/e2e with 2 updates (<a href="https://redirect.github.com/sigstore/sigstore/issues/1864">#1864</a>)</li> <li><a href="https://github.com/sigstore/sigstore/commit/bd8ee68fd6246c6c4e81b2b25b586c3c8fd0fc63"><code>bd8ee68</code></a> Mark TUF client as deprecated (<a href="https://redirect.github.com/sigstore/sigstore/issues/1858">#1858</a>)</li> <li><a href="https://github.com/sigstore/sigstore/commit/c59dfa0a27eb8b289a2501cbd29f2c31e858bed1"><code>c59dfa0</code></a> build(deps): Bump golang.org/x/crypto from 0.25.0 to 0.28.0 (<a href="https://redirect.github.com/sigstore/sigstore/issues/1852">#1852</a>)</li> <li><a href="https://github.com/sigstore/sigstore/commit/bde3e532bafa49efa6c40a78f1937edf905b8cd2"><code>bde3e53</code></a> build(deps): Bump golang.org/x/term from 0.22.0 to 0.25.0 (<a href="https://redirect.github.com/sigstore/sigstore/issues/1851">#1851</a>)</li> <li>Additional commits viewable in <a href="https://github.com/sigstore/sigstore/compare/v1.8.9...v1.8.10">compare view</a></li> </ul> </details> <br /> [![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=github.com/sigstore/sigstore&package-manager=go_modules&previous-version=1.8.9&new-version=1.8.10)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
- Loading branch information