Repository navigation
chore(deps): bump github.com/sigstore/sigstore-go from 1.1.4 to 1.2.1 in /policy/sigstore - #98
Conversation
LabelsThe following labels could not be found: Please fix the above issues or remove invalid values from |
Bumps [github.com/sigstore/sigstore-go](https://github.com/sigstore/sigstore-go) from 1.1.4 to 1.2.1. - [Release notes](https://github.com/sigstore/sigstore-go/releases) - [Commits](sigstore/sigstore-go@v1.1.4...v1.2.1) --- updated-dependencies: - dependency-name: github.com/sigstore/sigstore-go dependency-version: 1.2.1 dependency-type: direct:production ... Signed-off-by: dependabot[bot] <support@github.com>
125e964 to
ee2d579
Compare
|
Superseded by #101, which refreshed all six Go modules to equal or newer dependency versions and passed the full local and hosted CI suites. |
|
OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting If you change your mind, just re-open this PR and I'll resolve any conflicts on it. |
Bumps github.com/sigstore/sigstore-go from 1.1.4 to 1.2.1.
Release notes
Sourced from github.com/sigstore/sigstore-go's releases.
... (truncated)
Commits
4594ab4Check signature time against public key validity window (#642)3ad400cBump actions/checkout from 6.0.2 to 6.0.3 (#639)8ca80c4Fix conformance test failures for managed-key verification (#561) (#638)40d743aBump the minor-patch group across 2 directories with 10 updates (#637)7960906Bump golangci/golangci-lint-action from 9.2.0 to 9.2.1 (#631)ef6e924Encode Rekor v2 DSSE envelopes as hashedrekord (#627)56c2528Verify Rekor v2 inclusion using reconstructed leaf hash (#635)dbb07e6Prevent multi-log threshold bypasses via single compromised log (#633)7e8ee0fbundle: cap raw TlogEntries length before per-entry parse (#630)58c7950Bump github.com/in-toto/in-toto-golang from 0.10.0 to 0.11.0 (#624)