Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Bump github.com/sigstore/cosign/v2 from 2.2.2 to 2.2.3 (#236)
Bumps [github.com/sigstore/cosign/v2](https://github.com/sigstore/cosign) from 2.2.2 to 2.2.3. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/sigstore/cosign/releases">github.com/sigstore/cosign/v2's releases</a>.</em></p> <blockquote> <h1>v2.2.3</h1> <h2>Bug Fixes</h2> <ul> <li>Fix race condition on verification with multiple signatures attached to image (<a href="https://redirect.github.com/sigstore/cosign/issues/3486">#3486</a>)</li> <li>fix(clean): Fix clean cmd for private registries (<a href="https://redirect.github.com/sigstore/cosign/issues/3446">#3446</a>)</li> <li>Fixed BYO PKI verification (<a href="https://redirect.github.com/sigstore/cosign/issues/3427">#3427</a>)</li> </ul> <h2>Features</h2> <ul> <li>Allow for option in cosign attest and attest-blob to upload attestation as supported in Rekor (<a href="https://redirect.github.com/sigstore/cosign/issues/3466">#3466</a>)</li> <li>Add support for OpenVEX predicate type (<a href="https://redirect.github.com/sigstore/cosign/issues/3405">#3405</a>)</li> </ul> <h2>Documentation</h2> <ul> <li>Resolves <a href="https://redirect.github.com/sigstore/cosign/issues/3088">#3088</a>: <code>version</code> sub-command expected behaviour documentation and testing (<a href="https://redirect.github.com/sigstore/cosign/issues/3447">#3447</a>)</li> <li>add examples for cosign attach signature cmd (<a href="https://redirect.github.com/sigstore/cosign/issues/3468">#3468</a>)</li> </ul> <h2>Misc</h2> <ul> <li>Remove CertSubject function (<a href="https://redirect.github.com/sigstore/cosign/issues/3467">#3467</a>)</li> <li>Use local rekor and fulcio instances in e2e tests (<a href="https://redirect.github.com/sigstore/cosign/issues/3478">#3478</a>)</li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/sigstore/cosign/compare/v2.2.2...v2.2.3">https://github.com/sigstore/cosign/compare/v2.2.2...v2.2.3</a></p> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/sigstore/cosign/blob/main/CHANGELOG.md">github.com/sigstore/cosign/v2's changelog</a>.</em></p> <blockquote> <h1>v2.2.3</h1> <h2>Bug Fixes</h2> <ul> <li>Fix race condition on verification with multiple signatures attached to image (<a href="https://redirect.github.com/sigstore/cosign/issues/3486">#3486</a>)</li> <li>fix(clean): Fix clean cmd for private registries (<a href="https://redirect.github.com/sigstore/cosign/issues/3446">#3446</a>)</li> <li>Fixed BYO PKI verification (<a href="https://redirect.github.com/sigstore/cosign/issues/3427">#3427</a>)</li> </ul> <h2>Features</h2> <ul> <li>Allow for option in cosign attest and attest-blob to upload attestation as supported in Rekor (<a href="https://redirect.github.com/sigstore/cosign/issues/3466">#3466</a>)</li> <li>Add support for OpenVEX predicate type (<a href="https://redirect.github.com/sigstore/cosign/issues/3405">#3405</a>)</li> </ul> <h2>Documentation</h2> <ul> <li>Resolves <a href="https://redirect.github.com/sigstore/cosign/issues/3088">#3088</a>: <code>version</code> sub-command expected behaviour documentation and testing (<a href="https://redirect.github.com/sigstore/cosign/issues/3447">#3447</a>)</li> <li>add examples for cosign attach signature cmd (<a href="https://redirect.github.com/sigstore/cosign/issues/3468">#3468</a>)</li> </ul> <h2>Misc</h2> <ul> <li>Remove CertSubject function (<a href="https://redirect.github.com/sigstore/cosign/issues/3467">#3467</a>)</li> <li>Use local rekor and fulcio instances in e2e tests (<a href="https://redirect.github.com/sigstore/cosign/issues/3478">#3478</a>)</li> </ul> <h2>Contributors</h2> <ul> <li>aalsabag</li> <li>Bob Callaway</li> <li>Carlos Tadeu Panato Junior</li> <li>Colleen Murphy</li> <li>Hayden B</li> <li>Mukuls77</li> <li>Omri Bornstein</li> <li>Puerco</li> <li>vivek kumar sahu</li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/sigstore/cosign/commit/493e6e29e2ac830aaf05ec210b36d0a5a60c3b32"><code>493e6e2</code></a> Add changelog for v2.2.3 (<a href="https://redirect.github.com/sigstore/cosign/issues/3513">#3513</a>)</li> <li><a href="https://github.com/sigstore/cosign/commit/628df785e2b7a2af02c27333ed2d34bbf30dbcfa"><code>628df78</code></a> chore(deps): bump cpanato/vault-installer from 0.0.2 to 1.0.0 (<a href="https://redirect.github.com/sigstore/cosign/issues/3510">#3510</a>)</li> <li><a href="https://github.com/sigstore/cosign/commit/7be8de0613c2d77e1370717415ed02aee1a192b3"><code>7be8de0</code></a> chore(deps): bump google.golang.org/api from 0.157.0 to 0.159.0 (<a href="https://redirect.github.com/sigstore/cosign/issues/3508">#3508</a>)</li> <li><a href="https://github.com/sigstore/cosign/commit/554015cf21fc30a6ecfc4326023b504347792258"><code>554015c</code></a> chore(deps): bump the actions group with 3 updates (<a href="https://redirect.github.com/sigstore/cosign/issues/3509">#3509</a>)</li> <li><a href="https://github.com/sigstore/cosign/commit/8395d97b2cc3fdd640e30fe53a00447f2e91cb78"><code>8395d97</code></a> chore(deps): bump github.com/go-openapi/runtime from 0.26.2 to 0.27.1 (<a href="https://redirect.github.com/sigstore/cosign/issues/3507">#3507</a>)</li> <li><a href="https://github.com/sigstore/cosign/commit/1c90a3a962c5f22cd4323daa56acd431c015e30d"><code>1c90a3a</code></a> chore(deps): bump github.com/open-policy-agent/opa from 0.60.0 to 0.61.0 (<a href="https://redirect.github.com/sigstore/cosign/issues/3505">#3505</a>)</li> <li><a href="https://github.com/sigstore/cosign/commit/3f20bdee88ad68a45908fe96c5f364b60cf881f8"><code>3f20bde</code></a> chore(deps): bump github.com/buildkite/agent/v3 from 3.61.0 to 3.62.0 (<a href="https://redirect.github.com/sigstore/cosign/issues/3506">#3506</a>)</li> <li><a href="https://github.com/sigstore/cosign/commit/5d79ebffe9b091d4703397b0107e9e2270624656"><code>5d79ebf</code></a> chore(deps): bump the gomod group with 2 updates (<a href="https://redirect.github.com/sigstore/cosign/issues/3504">#3504</a>)</li> <li><a href="https://github.com/sigstore/cosign/commit/381c6570d5461d83146fe5dfe66a660d39747aa5"><code>381c657</code></a> fix cross test (<a href="https://redirect.github.com/sigstore/cosign/issues/3502">#3502</a>)</li> <li><a href="https://github.com/sigstore/cosign/commit/a445167d835d57599b7650e78af9bcd86ae7bd51"><code>a445167</code></a> Fix CI test failing (<a href="https://redirect.github.com/sigstore/cosign/issues/3501">#3501</a>)</li> <li>Additional commits viewable in <a href="https://github.com/sigstore/cosign/compare/v2.2.2...v2.2.3">compare view</a></li> </ul> </details> <br /> [![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=github.com/sigstore/cosign/v2&package-manager=go_modules&previous-version=2.2.2&new-version=2.2.3)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) </details> Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
- Loading branch information