Skip to content

Conversation

red-hat-konflux[bot]
Copy link

@red-hat-konflux red-hat-konflux bot commented Oct 3, 2025

This PR contains the following updates:

Package Type Update Change
github.com/golang/snappy indirect major v0.0.4 -> v1.0.0
github.com/sigstore/sigstore-go indirect major v0.7.3 -> v1.1.3

Warning

Some dependencies could not be looked up. Check the warning logs for more information.


Release Notes

golang/snappy (github.com/golang/snappy)

v1.0.0

Compare Source

Latest stable version, as of March 2025.

sigstore/sigstore-go (github.com/sigstore/sigstore-go)

v1.1.3

Compare Source

What's Changed

  • Set user agent for TUF and Rekor v2 clients in #​525

Full Changelog: sigstore/sigstore-go@v1.1.2...v1.1.3

v1.1.2

Compare Source

What's Changed

  • Allow no timestamps to be provided when verifying a key in #​510
  • Support other key algorithms for Rekor v2 in #​520

Full Changelog: sigstore/sigstore-go@v1.1.1...v1.1.2

v1.1.1

Compare Source

What's Changed

  • Make conformance compatible with rekor v2 in #​505
  • Update GetSigningConfig to use signing_config.v0.2.json in #​506
  • Refactor SelectService to return Service rather than URL, add supported API versions in #​503
  • Remove noisy log message in #​507

Full Changelog: sigstore/sigstore-go@v1.1.0...v1.1.1

v1.1.0

Compare Source

sigstore-go v1.1.0 introduces support for Rekor v2, a redesigned and modernized transparency log that's cheaper to operate, easier to scale, and simpler to maintain.

What's Changed

Full Changelog: sigstore/sigstore-go@v1.0.0...v1.1.0

v1.0.0

Compare Source

We're very excited to release sigstore-go 1.0! View the blog post announcing this release for more details.

This release should contain the last set of breaking changes until version 2.0, including a few renames (such as SignedEntityVerifier -> Verifier and VerifyTimestampAuthority -> VerifySignedTimestamp). We are excited to begin a new phase of simple, stable APIs!

What's Changed

Full Changelog: sigstore/sigstore-go@v0.7.3...v1.0.0


Configuration

📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about these updates again.


  • If you want to rebase/retry this PR, check this box

To execute skipped test pipelines write comment /ok-to-test.

This PR has been generated by MintMaker (powered by Renovate Bot).

Signed-off-by: red-hat-konflux <126015336+red-hat-konflux[bot]@users.noreply.github.com>
Copy link
Author

ℹ Artifact update notice

File name: go.mod

In order to perform the update(s) described in the table above, Renovate ran the go get command, which resulted in the following additional change(s):

  • 56 additional dependencies were updated
  • The go directive was updated for compatibility reasons

Details:

Package Change
go 1.23.6 -> 1.24.0
go (toolchain) 1.24.1 -> 1.24.6
github.com/go-openapi/swag v0.23.1 -> v0.24.1
github.com/secure-systems-lab/go-securesystemslib v0.9.0 -> v0.9.1
github.com/sigstore/protobuf-specs v0.4.3 -> v0.5.0
github.com/sigstore/rekor v1.3.10 -> v1.4.2
github.com/sigstore/sigstore v1.9.5 -> v1.9.6-0.20250729224751-181c5d3339b3
github.com/spf13/cobra v1.9.1 -> v1.10.1
github.com/spf13/pflag v1.0.6 -> v1.0.10
golang.org/x/crypto v0.39.0 -> v0.42.0
google.golang.org/protobuf v1.36.6 -> v1.36.9
cloud.google.com/go v0.121.3 -> v0.121.6
cloud.google.com/go/auth v0.16.2 -> v0.16.5
cloud.google.com/go/compute/metadata v0.7.0 -> v0.8.0
github.com/Azure/azure-sdk-for-go/sdk/azcore v1.18.0 -> v1.18.2
github.com/Azure/azure-sdk-for-go/sdk/azidentity v1.10.1 -> v1.11.0
github.com/Azure/azure-sdk-for-go/sdk/internal v1.11.1 -> v1.11.2
github.com/aws/aws-sdk-go-v2 v1.36.5 -> v1.38.1
github.com/aws/aws-sdk-go-v2/config v1.29.16 -> v1.31.3
github.com/aws/aws-sdk-go-v2/credentials v1.17.70 -> v1.18.7
github.com/aws/aws-sdk-go-v2/feature/ec2/imds v1.16.32 -> v1.18.4
github.com/aws/aws-sdk-go-v2/internal/configsources v1.3.36 -> v1.4.4
github.com/aws/aws-sdk-go-v2/internal/endpoints/v2 v2.6.36 -> v2.7.4
github.com/aws/aws-sdk-go-v2/service/internal/accept-encoding v1.12.4 -> v1.13.0
github.com/aws/aws-sdk-go-v2/service/internal/presigned-url v1.12.17 -> v1.13.4
github.com/aws/aws-sdk-go-v2/service/kms v1.41.0 -> v1.44.0
github.com/aws/aws-sdk-go-v2/service/sso v1.25.5 -> v1.28.2
github.com/aws/aws-sdk-go-v2/service/ssooidc v1.30.3 -> v1.34.0
github.com/aws/aws-sdk-go-v2/service/sts v1.34.0 -> v1.38.0
github.com/aws/smithy-go v1.22.4 -> v1.22.5
github.com/cpuguy83/go-md2man/v2 v2.0.6 -> v2.0.7
github.com/docker/cli v27.5.0+incompatible -> v28.2.2+incompatible
github.com/go-jose/go-jose/v4 v4.0.5 -> v4.1.1
github.com/go-openapi/errors v0.22.1 -> v0.22.2
github.com/go-piv/piv-go/v2 v2.3.0 -> v2.4.0
github.com/go-viper/mapstructure/v2 v2.2.1 -> v2.4.0
github.com/golang-jwt/jwt/v5 v5.2.2 -> v5.3.0
github.com/google/go-containerregistry v0.20.3 -> v0.20.6
github.com/googleapis/gax-go/v2 v2.14.2 -> v2.15.0
github.com/jellydator/ttlcache/v3 v3.3.0 -> v3.4.0
github.com/sigstore/sigstore/pkg/signature/kms/gcp v1.9.5 -> v1.9.6-0.20250729224751-181c5d3339b3
github.com/sigstore/timestamp-authority v1.2.8 -> v1.2.9
github.com/theupdateframework/go-tuf/v2 v2.0.2 -> v2.2.0
go.opentelemetry.io/otel v1.37.0 -> v1.38.0
go.opentelemetry.io/otel/metric v1.37.0 -> v1.38.0
go.yaml.in/yaml/v3 v3.0.3 -> v3.0.4
golang.org/x/mod v0.25.0 -> v0.28.0
golang.org/x/net v0.41.0 -> v0.43.0
golang.org/x/sync v0.15.0 -> v0.17.0
golang.org/x/sys v0.33.0 -> v0.36.0
golang.org/x/term v0.32.0 -> v0.35.0
golang.org/x/text v0.26.0 -> v0.29.0
google.golang.org/api v0.240.0 -> v0.248.0
google.golang.org/genproto/googleapis/api v0.0.0-20250603155806-513f23925822 -> v0.0.0-20250818200422-3122310a409c
google.golang.org/genproto/googleapis/rpc v0.0.0-20250603155806-513f23925822 -> v0.0.0-20250818200422-3122310a409c
google.golang.org/grpc v1.73.0 -> v1.75.0
sigs.k8s.io/release-utils v0.11.1 -> v0.12.1
sigs.k8s.io/yaml v1.5.0 -> v1.6.0

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants