slsa-github-generator
slsa-github-generator copied to clipboard
Update module github.com/sigstore/sigstore to v1.4.0
trafficstars
This PR contains the following updates:
| Package | Type | Update | Change |
|---|---|---|---|
| github.com/sigstore/sigstore | require | minor | v1.3.1 -> v1.4.0 |
Release Notes
sigstore/sigstore
v1.4.0
What's Changed
- Bump github/codeql-action from 2.1.16 to 2.1.17 by @dependabot in https://github.com/sigstore/sigstore/pull/582
- Bump github.com/aws/aws-sdk-go from 1.44.63 to 1.44.64 by @dependabot in https://github.com/sigstore/sigstore/pull/583
- Bump google.golang.org/protobuf from 1.28.0 to 1.28.1 by @dependabot in https://github.com/sigstore/sigstore/pull/584
- ci: enable gofumpt with extra by @Dentrax in https://github.com/sigstore/sigstore/pull/278
- Bump github.com/aws/aws-sdk-go from 1.44.64 to 1.44.65 by @dependabot in https://github.com/sigstore/sigstore/pull/586
- Bump google.golang.org/api from 0.89.0 to 0.90.0 by @dependabot in https://github.com/sigstore/sigstore/pull/585
- add pkce values to device code flow by @bobcallaway in https://github.com/sigstore/sigstore/pull/516
- Bump github.com/aws/aws-sdk-go-v2/service/kms from 1.18.0 to 1.18.1 by @dependabot in https://github.com/sigstore/sigstore/pull/591
- Bump github.com/aws/aws-sdk-go from 1.44.65 to 1.44.67 by @dependabot in https://github.com/sigstore/sigstore/pull/588
- Bump github.com/aws/aws-sdk-go-v2/config from 1.15.14 to 1.15.15 by @dependabot in https://github.com/sigstore/sigstore/pull/590
- Bump github.com/aws/aws-sdk-go from 1.44.67 to 1.44.68 by @dependabot in https://github.com/sigstore/sigstore/pull/593
- Bump github/codeql-action from 2.1.17 to 2.1.18 by @dependabot in https://github.com/sigstore/sigstore/pull/595
- Bump google.golang.org/api from 0.90.0 to 0.91.0 by @dependabot in https://github.com/sigstore/sigstore/pull/596
- Bump github.com/go-rod/rod from 0.108.1 to 0.108.2 by @dependabot in https://github.com/sigstore/sigstore/pull/597
- Bump github.com/aws/aws-sdk-go from 1.44.68 to 1.44.70 by @dependabot in https://github.com/sigstore/sigstore/pull/598
- Bump actions/cache from 3.0.5 to 3.0.6 by @dependabot in https://github.com/sigstore/sigstore/pull/599
- Fix issue #600. When using StaticTokenGetter do not make network calls. by @vaikas in https://github.com/sigstore/sigstore/pull/601
- Bump github.com/aws/aws-sdk-go from 1.44.70 to 1.44.71 by @dependabot in https://github.com/sigstore/sigstore/pull/603
- Bump github.com/aws/aws-sdk-go-v2 from 1.16.8 to 1.16.9 by @dependabot in https://github.com/sigstore/sigstore/pull/604
- Use well-known OIDC config for device endpoints by @bobcallaway in https://github.com/sigstore/sigstore/pull/602
- Migrate to go 1.18 for Fuzzing by @naveensrinivasan in https://github.com/sigstore/sigstore/pull/592
- Bump github.com/aws/aws-sdk-go-v2/service/kms from 1.18.1 to 1.18.2 by @dependabot in https://github.com/sigstore/sigstore/pull/606
- Bump github.com/aws/aws-sdk-go from 1.44.71 to 1.44.72 by @dependabot in https://github.com/sigstore/sigstore/pull/605
- Bump github.com/aws/aws-sdk-go-v2/config from 1.15.15 to 1.15.17 by @dependabot in https://github.com/sigstore/sigstore/pull/608
- Bump github.com/aws/aws-sdk-go from 1.44.72 to 1.44.73 by @dependabot in https://github.com/sigstore/sigstore/pull/610
- Bump github.com/aws/aws-sdk-go-v2/service/kms from 1.18.2 to 1.18.4 by @dependabot in https://github.com/sigstore/sigstore/pull/616
- Bump github.com/go-rod/rod from 0.108.2 to 0.109.0 by @dependabot in https://github.com/sigstore/sigstore/pull/618
- Bump google.golang.org/api from 0.91.0 to 0.92.0 by @dependabot in https://github.com/sigstore/sigstore/pull/613
- Bump github.com/aws/aws-sdk-go-v2/config from 1.15.17 to 1.16.1 by @dependabot in https://github.com/sigstore/sigstore/pull/620
- Bump actions/cache from 3.0.6 to 3.0.7 by @dependabot in https://github.com/sigstore/sigstore/pull/611
- Bump github.com/aws/aws-sdk-go from 1.44.73 to 1.44.76 by @dependabot in https://github.com/sigstore/sigstore/pull/621
- Bump github.com/aws/aws-sdk-go-v2/config from 1.16.1 to 1.17.0 by @dependabot in https://github.com/sigstore/sigstore/pull/625
- Bump github.com/go-rod/rod from 0.109.0 to 0.109.1 by @dependabot in https://github.com/sigstore/sigstore/pull/626
- Add a more friendly error in pubkey failure by @rikatz in https://github.com/sigstore/sigstore/pull/623
- remove old swagger commands from Makefile and fix typo by @bobcallaway in https://github.com/sigstore/sigstore/pull/624
New Contributors
- @vaikas made their first contribution in https://github.com/sigstore/sigstore/pull/601
- @rikatz made their first contribution in https://github.com/sigstore/sigstore/pull/623
Full Changelog: https://github.com/sigstore/sigstore/compare/v1.3.1...v1.4.0
Configuration
📅 Schedule: Branch creation - "every weekend" (UTC), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
- [ ] If you want to rebase/retry this PR, click this checkbox.
This PR has been generated by Mend Renovate. View repository job log here.