Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
build(deps): bump github.com/sigstore/cosign/v2 from 2.4.1 to 2.4.2 (#…
…1517) Bumps [github.com/sigstore/cosign/v2](https://github.com/sigstore/cosign) from 2.4.1 to 2.4.2. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/sigstore/cosign/releases">github.com/sigstore/cosign/v2's releases</a>.</em></p> <blockquote> <h2>v2.4.2</h2> <h2>Features</h2> <ul> <li>Updated open-policy-agent to 1.1.0 library (<a href="https://redirect.github.com/sigstore/cosign/issues/4036">#4036</a>) <ul> <li>Note that only Rego v0 policies are supported at this time</li> </ul> </li> <li>Add UseSignedTimestamps to CheckOpts, refactor TSA options (<a href="https://redirect.github.com/sigstore/cosign/issues/4006">#4006</a>)</li> <li>Add support for verifying root checksum in cosign initialize (<a href="https://redirect.github.com/sigstore/cosign/issues/3953">#3953</a>)</li> <li>Detect if user supplied a valid protobuf bundle (<a href="https://redirect.github.com/sigstore/cosign/issues/3931">#3931</a>)</li> <li>Add a log message if user doesn't provide <code>--trusted-root</code> (<a href="https://redirect.github.com/sigstore/cosign/issues/3933">#3933</a>)</li> <li>Support mTLS towards container registry (<a href="https://redirect.github.com/sigstore/cosign/issues/3922">#3922</a>)</li> <li>Add bundle create helper command (<a href="https://redirect.github.com/sigstore/cosign/issues/3901">#3901</a>)</li> <li>Add trusted-root create helper command (<a href="https://redirect.github.com/sigstore/cosign/issues/3876">#3876</a>)</li> </ul> <h2>Bug Fixes</h2> <ul> <li>fix: set tls config while retaining other fields from default http transport (<a href="https://redirect.github.com/sigstore/cosign/issues/4007">#4007</a>)</li> <li>policy fuzzer: ignore known panics (<a href="https://redirect.github.com/sigstore/cosign/issues/3993">#3993</a>)</li> <li>Fix for multiple WithRemote options (<a href="https://redirect.github.com/sigstore/cosign/issues/3982">#3982</a>)</li> <li>Add nightly conformance test workflow (<a href="https://redirect.github.com/sigstore/cosign/issues/3979">#3979</a>)</li> <li>Fix copy --only for signatures + update/align docs (<a href="https://redirect.github.com/sigstore/cosign/issues/3904">#3904</a>)</li> </ul> <h2>Documentation</h2> <ul> <li>Remove usage.md from spec, point to client spec (<a href="https://redirect.github.com/sigstore/cosign/issues/3918">#3918</a>)</li> <li>move reference from gcr to ghcr (<a href="https://redirect.github.com/sigstore/cosign/issues/3897">#3897</a>)</li> </ul> <h2>Contributors</h2> <ul> <li>AdamKorcz</li> <li>Aditya Sirish</li> <li>Bob Callaway</li> <li>Carlos Tadeu Panato Junior</li> <li>Cody Soyland</li> <li>Colleen Murphy</li> <li>Hayden B</li> <li>Jussi Kukkonen</li> <li>Marco Franssen</li> <li>Nianyu Shen</li> <li>Slavek Kabrda</li> <li>Søren Juul</li> <li>Warren Hodgkinson</li> <li>Zach Steindler</li> </ul> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/sigstore/cosign/blob/main/CHANGELOG.md">github.com/sigstore/cosign/v2's changelog</a>.</em></p> <blockquote> <h1>v2.4.2</h1> <h2>Features</h2> <ul> <li>Updated open-policy-agent to 1.1.0 library (<a href="https://redirect.github.com/sigstore/cosign/issues/4036">#4036</a>) <ul> <li>Note that only Rego v0 policies are supported at this time</li> </ul> </li> <li>Add UseSignedTimestamps to CheckOpts, refactor TSA options (<a href="https://redirect.github.com/sigstore/cosign/issues/4006">#4006</a>)</li> <li>Add support for verifying root checksum in cosign initialize (<a href="https://redirect.github.com/sigstore/cosign/issues/3953">#3953</a>)</li> <li>Detect if user supplied a valid protobuf bundle (<a href="https://redirect.github.com/sigstore/cosign/issues/3931">#3931</a>)</li> <li>Add a log message if user doesn't provide <code>--trusted-root</code> (<a href="https://redirect.github.com/sigstore/cosign/issues/3933">#3933</a>)</li> <li>Support mTLS towards container registry (<a href="https://redirect.github.com/sigstore/cosign/issues/3922">#3922</a>)</li> <li>Add bundle create helper command (<a href="https://redirect.github.com/sigstore/cosign/issues/3901">#3901</a>)</li> <li>Add trusted-root create helper command (<a href="https://redirect.github.com/sigstore/cosign/issues/3876">#3876</a>)</li> </ul> <h2>Bug Fixes</h2> <ul> <li>fix: set tls config while retaining other fields from default http transport (<a href="https://redirect.github.com/sigstore/cosign/issues/4007">#4007</a>)</li> <li>policy fuzzer: ignore known panics (<a href="https://redirect.github.com/sigstore/cosign/issues/3993">#3993</a>)</li> <li>Fix for multiple WithRemote options (<a href="https://redirect.github.com/sigstore/cosign/issues/3982">#3982</a>)</li> <li>Add nightly conformance test workflow (<a href="https://redirect.github.com/sigstore/cosign/issues/3979">#3979</a>)</li> <li>Fix copy --only for signatures + update/align docs (<a href="https://redirect.github.com/sigstore/cosign/issues/3904">#3904</a>)</li> </ul> <h2>Documentation</h2> <ul> <li>Remove usage.md from spec, point to client spec (<a href="https://redirect.github.com/sigstore/cosign/issues/3918">#3918</a>)</li> <li>move reference from gcr to ghcr (<a href="https://redirect.github.com/sigstore/cosign/issues/3897">#3897</a>)</li> </ul> <h2>Contributors</h2> <ul> <li>AdamKorcz</li> <li>Aditya Sirish</li> <li>Bob Callaway</li> <li>Carlos Tadeu Panato Junior</li> <li>Cody Soyland</li> <li>Colleen Murphy</li> <li>Hayden B</li> <li>Jussi Kukkonen</li> <li>Marco Franssen</li> <li>Nianyu Shen</li> <li>Slavek Kabrda</li> <li>Søren Juul</li> <li>Warren Hodgkinson</li> <li>Zach Steindler</li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/sigstore/cosign/commit/b6df9c777c365ce063a7e65075f2b08a3c76de2f"><code>b6df9c7</code></a> update v2.4.2 changelog (<a href="https://redirect.github.com/sigstore/cosign/issues/4045">#4045</a>)</li> <li><a href="https://github.com/sigstore/cosign/commit/ff13ba49128e40ff2d3dc3783865ff37d220501c"><code>ff13ba4</code></a> chore(deps): bump github.com/open-policy-agent/opa from 0.68.0 to 1.1.0 (<a href="https://redirect.github.com/sigstore/cosign/issues/4036">#4036</a>)</li> <li><a href="https://github.com/sigstore/cosign/commit/4dc18dd3ee95c279b969f6eacfa01c00d1dd54a8"><code>4dc18dd</code></a> test against newer k8s, scaffolding release (<a href="https://redirect.github.com/sigstore/cosign/issues/4044">#4044</a>)</li> <li><a href="https://github.com/sigstore/cosign/commit/e4ff8e250f2826a475068d1ff85afba133a01d90"><code>e4ff8e2</code></a> chore(deps): bump cuelang.org/go from 0.11.2 to 0.12.0 (<a href="https://redirect.github.com/sigstore/cosign/issues/4035">#4035</a>)</li> <li><a href="https://github.com/sigstore/cosign/commit/cced6566051d44ee1be9045b8557bbe48f24792f"><code>cced656</code></a> fix warning message from golangci-lint (<a href="https://redirect.github.com/sigstore/cosign/issues/4043">#4043</a>)</li> <li><a href="https://github.com/sigstore/cosign/commit/486937b7b03a4987e7b8c8f5e69b218920632dae"><code>486937b</code></a> chore(deps): move github.com/xanzy/go-gitlab to gitlab.com/gitlab-org/api/cli...</li> <li><a href="https://github.com/sigstore/cosign/commit/9f142a537d554d313dc4355c4f4b3c1c81f4a3fd"><code>9f142a5</code></a> chore(deps): bump github.com/sigstore/sigstore-go (<a href="https://redirect.github.com/sigstore/cosign/issues/4034">#4034</a>)</li> <li><a href="https://github.com/sigstore/cosign/commit/4937bca94e46877bc3a59c3ebb668acc6e5ead23"><code>4937bca</code></a> chore(deps): bump the gomod group across 1 directory with 2 updates (<a href="https://redirect.github.com/sigstore/cosign/issues/4042">#4042</a>)</li> <li><a href="https://github.com/sigstore/cosign/commit/a71220e35ff28e3da4c78d1b725dbec7aacdd8c1"><code>a71220e</code></a> chore(deps): bump google.golang.org/api from 0.218.0 to 0.219.0 (<a href="https://redirect.github.com/sigstore/cosign/issues/4038">#4038</a>)</li> <li><a href="https://github.com/sigstore/cosign/commit/fcf13eb12cc48f8ae8755dc661247cf49b09e23a"><code>fcf13eb</code></a> chore(deps): bump sigs.k8s.io/release-utils from 0.9.0 to 0.11.0 (<a href="https://redirect.github.com/sigstore/cosign/issues/4040">#4040</a>)</li> <li>Additional commits viewable in <a href="https://github.com/sigstore/cosign/compare/v2.4.1...v2.4.2">compare view</a></li> </ul> </details> <br /> [![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=github.com/sigstore/cosign/v2&package-manager=go_modules&previous-version=2.4.1&new-version=2.4.2)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) </details> Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
- Loading branch information