Skip to content

chore(deps): update sigstore repositories (minor)#1474

Closed
ocmbot[bot] wants to merge 1 commit into
mainfrom
renovate/sigstore
Closed

chore(deps): update sigstore repositories (minor)#1474
ocmbot[bot] wants to merge 1 commit into
mainfrom
renovate/sigstore

Conversation

@ocmbot

@ocmbot ocmbot Bot commented Dec 21, 2025

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Type Update Change Pending OpenSSF
github.com/sigstore/rekor-tiles indirect minor v0.1.11v0.99.1 OpenSSF Scorecard
github.com/sigstore/sigstore indirect minor v1.9.6-0.20251007084510-03d481d3b6fcv1.10.0 v1.10.3 (+2) OpenSSF Scorecard

Warning

Some dependencies could not be looked up. Check the Dependency Dashboard for more information.


Release Notes

sigstore/sigstore (github.com/sigstore/sigstore)

v1.10.0

Compare Source

Breaking change

#​2194 moves cryptoutils.ValidatePubKey to goodkey.ValidatePubKey to minimize the dependency tree for clients using the cryptoutils package.

Features

  • feat(hashivault): token helper in #​2174
  • set GoogleAPIClientOption on GCP KMS provider in #​2128

Refactoring

  • cryptoutils: move goodkey validation to separate package in #​2194
  • Stop depending on golang.org/x/crypto for sha3 in #​2209
  • remove duplicative dependency for portable browser opener in #​2178
  • consolidate deep Equal usage to one library in #​2177
  • Drop redundant aws-sdk-go dependency in the e2e kms tests in #​2172

Full Changelog: sigstore/sigstore@v1.9.5...v1.10.0


Configuration

📅 Schedule: Branch creation - Only on Sunday ( * * * * 0 ) (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Renovate Bot.

@ocmbot ocmbot Bot requested a review from a team as a code owner December 21, 2025 00:54
@ocmbot ocmbot Bot enabled auto-merge (squash) December 21, 2025 00:54
@github-actions github-actions Bot added kind/chore chore, maintenance, etc. kind/dependency dependency update, etc. size/s Small labels Dec 21, 2025
@ocmbot ocmbot Bot force-pushed the renovate/sigstore branch 3 times, most recently from 45d1898 to 13cfe4a Compare December 22, 2025 01:06

@frewilhelm frewilhelm left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Blocked as we plan to upgrade to cosign v3 (in ocm v1)

@ocmbot ocmbot Bot force-pushed the renovate/sigstore branch 21 times, most recently from e47b0cd to b4c405c Compare December 22, 2025 18:38
@ocmbot ocmbot Bot force-pushed the renovate/sigstore branch 5 times, most recently from 55be710 to aa8db55 Compare December 23, 2025 07:57
@ocmbot ocmbot Bot force-pushed the renovate/sigstore branch from aa8db55 to 8769b74 Compare December 23, 2025 08:20
@frewilhelm

Copy link
Copy Markdown
Contributor

The upgrade of github.com/sigstore/rekor-tiles is busted (see version bump) and github.com/sigstore/sigstore is fixed in #1432.

@frewilhelm frewilhelm closed this Dec 23, 2025
auto-merge was automatically disabled December 23, 2025 11:59

Pull request was closed

jakobmoellerdev pushed a commit that referenced this pull request Dec 23, 2025
Supersedes #1429,
#1352,
#1474,
and
#1354

---------

Signed-off-by: Frederic Wilhelm <frederic.wilhelm@sap.com>
@ocmbot ocmbot Bot deleted the renovate/sigstore branch December 23, 2025 12:55
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

kind/chore chore, maintenance, etc. kind/dependency dependency update, etc. size/s Small

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant