build(deps): bump sigstore/cosign-installer from 3.5.0 to 3.10.0
Type: Pull Request
State: Merged
Association: Contributor
Comments: 0
(9 months ago)
(9 months ago)
(9 months ago)
by JoannaaKL
dependencies github_actions
⚠️ Dependabot is rebasing this PR ⚠️
Rebasing might not happen immediately, so don't worry if this takes some time.
Note: if you make any changes to this PR yourself, they will take precedence over the rebase.
Bumps sigstore/cosign-installer from 3.5.0 to 3.10.0.
Release notes
Sourced from sigstore/cosign-installer's releases.
v3.10.0
What's Changed
- Bump default Cosign to v2.6.0 in sigstore/cosign-installer#200
Full Changelog: https://github.com/sigstore/cosign-installer/compare/v3.9.2...v3.10.0
v3.9.2
What's Changed
- not fail fast and setup permissions in sigstore/cosign-installer#195
- drop old unsupported versions <v2.0.0 in sigstore/cosign-installer#192
- Update default to v2.5.3 in sigstore/cosign-installer#196
Full Changelog: https://github.com/sigstore/cosign-installer/compare/v3.9.1...v3.9.2
v3.9.1
What's Changed
- default action install to use release v2.5.1 by
@cpanatoin sigstore/cosign-installer#193- default cosign to v2.5.2 by
@cpanatoin sigstore/cosign-installer#194Full Changelog: https://github.com/sigstore/cosign-installer/compare/v3.9.0...v3.9.1
v3.9.0
What's Changed
- Bump actions/setup-go from 5.4.0 to 5.5.0 by
@dependabotin sigstore/cosign-installer#189- bump cosign install to use release v2.5.0 as default by
@cpanatoin sigstore/cosign-installer#191Full Changelog: https://github.com/sigstore/cosign-installer/compare/v3...v3.9.0
v3.8.2
What's Changed
- install cosign v2 from main in sigstore/cosign-installer#186
Full Changelog: https://github.com/sigstore/cosign-installer/compare/v3...v3.8.2
v3.8.1
What's Changed
- use cosign 2.4.3 and other updates by
@cpanatoin sigstore/cosign-installer#182Full Changelog: https://github.com/sigstore/cosign-installer/compare/v3...v3.8.1
v3.8.0
What's Changed
- test action against all non-rc releases, verify entry in rekor log by
@bobcallawayin sigstore/cosign-installer#179- bump for cosign v2.4.2 release by
@bobcallawayin sigstore/cosign-installer#181Full Changelog: https://github.com/sigstore/cosign-installer/compare/v3...v3.8.0
... (truncated)
Commits
d7543c9Bump default Cosign to v2.6.0 (#200)920f20fBump actions/setup-go from 5.5.0 to 6.0.0 (#199)bb9dfc1Bump actions/github-script from 7.0.1 to 8.0.0 (#198)074636bBump actions/checkout from 4.2.2 to 5.0.0 (#197)d58896dUpdate default to v2.5.3 (#196)e40248cdrop old unsupported versions <v2.0.0 (#192)d9374b9not fail fast and setup permissions (#195)398d4b0default cosign to v2.5.2 (#194)84f54a2default action install to use release v2.5.1 (#193)fb28c2bbump cosign install to use release v2.5.0 as default (#191)- Additional commits viewable in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge and block automerging@dependabot reopenwill reopen this PR if it is closed@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
Pull Request Statistics
3
1
+1
-1
Package Dependencies
sigstore/cosign-installer
actions
3.5.0 → 3.10.0
Minor
Technical Details
| ID: | 8220451 |
| UUID: | 2850428975 |
| Node ID: | PR_kwDOODGMVM6p5hgv |
| Host: | GitHub |
| Repository: | github/github-mcp-server |
| Merge State: | Unknown |