Skip to content

Conversation

@sudo-bmitch
Copy link
Contributor

Fixes issue

Describe the change

Add support for the cosign v3 bundles while still pushing the non-bundle content to support existing clients. Eventually, only bundles will be supported.

Additional version bumps include:

  • sigstore/cosign to v3.0.2
  • anchore/syft to v1.38.0
  • anchore/sbom-action to v0.20.10
  • google/osv-scanner to v2.3.0

How to verify it

Changelog text

  • Feat: Add support for cosign v3 bundles.

Please verify and check that the pull request fulfills the following requirements

  • Tests have been added or not applicable
  • Documentation updates are included or not applicable (most documentation should be in the regclient.org repo)
  • Changes have been rebased to main
  • Multiple commits to the same code have been squashed
  • All changes have been human generated or created with a reproducible tool

Additional version bumps include:
- sigstore/cosign to v3.0.2
- anchore/syft to v1.38.0
- anchore/sbom-action to v0.20.10
- google/osv-scanner to v2.3.0

Signed-off-by: Brandon Mitchell <git@bmitch.net>
@sudo-bmitch sudo-bmitch merged commit 18fce93 into regclient:main Nov 19, 2025
4 checks passed
@sudo-bmitch sudo-bmitch deleted the pr-cosign-v3 branch November 19, 2025 22:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant