UNCLASSIFIED - NO CUI

Skip to content

Update all dependencies

Ghost User requested to merge renovate/all into development

This MR contains the following updates:

Package Type Update Change
sigstore/cosign ironbank-github patch v2.2.2 -> v2.2.3
trufflesecurity/trufflehog ironbank-github patch v3.66.2 -> v3.66.3

Warning

Some dependencies could not be looked up. Check the warning logs for more information.


Release Notes

sigstore/cosign (sigstore/cosign)

v2.2.3

Compare Source

Bug Fixes

  • Fix race condition on verification with multiple signatures attached to image (#​3486)
  • fix(clean): Fix clean cmd for private registries (#​3446)
  • Fixed BYO PKI verification (#​3427)

Features

  • Allow for option in cosign attest and attest-blob to upload attestation as supported in Rekor (#​3466)
  • Add support for OpenVEX predicate type (#​3405)

Documentation

  • Resolves #​3088: version sub-command expected behaviour documentation and testing (#​3447)
  • add examples for cosign attach signature cmd (#​3468)

Misc

  • Remove CertSubject function (#​3467)
  • Use local rekor and fulcio instances in e2e tests (#​3478)

Contributors

  • aalsabag
  • Bob Callaway
  • Carlos Tadeu Panato Junior
  • Colleen Murphy
  • Hayden B
  • Mukuls77
  • Omri Bornstein
  • Puerco
  • vivek kumar sahu
trufflesecurity/trufflehog (trufflesecurity/trufflehog)

v3.66.3

Compare Source

What's Changed

Full Changelog: https://github.com/trufflesecurity/trufflehog/compare/v3.66.2...v3.66.3


Configuration

📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 Automerge: Enabled.

Rebasing: Whenever MR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This MR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this MR, check this box

This MR has been generated by Renovate Bot.

Merge request reports