Skip to content

chore(deps): bump github.com/sigstore/sigstore-go from 1.1.4 to 1.2.1 in /policy/sigstore - #98

Closed
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/go_modules/policy/sigstore/github.com/sigstore/sigstore-go-1.2.1
Closed

dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/go_modules/policy/sigstore/github.com/sigstore/sigstore-go-1.2.1

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 6, 2026 •

Copy link
Copy Markdown
Contributor

Bumps github.com/sigstore/sigstore-go from 1.1.4 to 1.2.1.

Release notes

Sourced from github.com/sigstore/sigstore-go's releases.

v1.2.1

What's Changed

v1.2.1 resolves GHSA-wqqc-jjcq-vfxm.

Full Changelog: sigstore/sigstore-go@v1.2.0...v1.2.1

v1.2.0

What's Changed

... (truncated)

Commits
  • 4594ab4 Check signature time against public key validity window (#642)
  • 3ad400c Bump actions/checkout from 6.0.2 to 6.0.3 (#639)
  • 8ca80c4 Fix conformance test failures for managed-key verification (#561) (#638)
  • 40d743a Bump the minor-patch group across 2 directories with 10 updates (#637)
  • 7960906 Bump golangci/golangci-lint-action from 9.2.0 to 9.2.1 (#631)
  • ef6e924 Encode Rekor v2 DSSE envelopes as hashedrekord (#627)
  • 56c2528 Verify Rekor v2 inclusion using reconstructed leaf hash (#635)
  • dbb07e6 Prevent multi-log threshold bypasses via single compromised log (#633)
  • 7e8ee0f bundle: cap raw TlogEntries length before per-entry parse (#630)
  • 58c7950 Bump github.com/in-toto/in-toto-golang from 0.10.0 to 0.11.0 (#624)
  • Additional commits viewable in compare view

@dependabot @github

dependabot Bot commented on behalf of github Aug 6, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: policy. Please create it before Dependabot can add it to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file go Pull requests that update go code labels Aug 6, 2026
Bumps [github.com/sigstore/sigstore-go](https://github.com/sigstore/sigstore-go) from 1.1.4 to 1.2.1.
- [Release notes](https://github.com/sigstore/sigstore-go/releases)
- [Commits](sigstore/sigstore-go@v1.1.4...v1.2.1)

---
updated-dependencies:
- dependency-name: github.com/sigstore/sigstore-go
  dependency-version: 1.2.1
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/go_modules/policy/sigstore/github.com/sigstore/sigstore-go-1.2.1 branch from 125e964 to ee2d579 Compare August 6, 2026 01:03
@jmgilman

jmgilman commented Aug 6, 2026

Copy link
Copy Markdown
Contributor

Superseded by #101, which refreshed all six Go modules to equal or newer dependency versions and passed the full local and hosted CI suites.

@jmgilman jmgilman closed this Aug 6, 2026
@dependabot @github

dependabot Bot commented on behalf of github Aug 6, 2026

Copy link
Copy Markdown
Contributor Author

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@dependabot
dependabot Bot deleted the dependabot/go_modules/policy/sigstore/github.com/sigstore/sigstore-go-1.2.1 branch August 6, 2026 01:36
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file go Pull requests that update go code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant