Conversation
cfe6a4d to
5647ffc
Compare
c8c2d0f to
f3b8b9a
Compare
Bumps [github.com/sigstore/cosign/v2](https://github.com/sigstore/cosign) from 2.4.1 to 2.6.3. - [Changelog](https://github.com/sigstore/cosign/blob/main/CHANGELOG.md) - [Commits](sigstore/cosign@v2.4.1...v2.6.3) --- updated-dependencies: - dependency-name: github.com/sigstore/cosign/v2 dependency-version: 2.6.3 dependency-type: indirect update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
f3b8b9a to
a744112
Compare
rcaril
approved these changes
Apr 27, 2026
rcaril
added a commit
that referenced
this pull request
Apr 27, 2026
### Change summary Reverts the transitive dependency bumps introduced by PRs #1739–#1753 which broke `go tool -modfile=tools/go.mod goreleaser check` due to an incompatibility between goreleaser v2.9.0 and the newer gitlab-org/api/client-go (v0.143.3) pulled in transitively by the sigstore/cosign bump (#1753). All Submissions: * [x] Have you followed the guidelines in our Contributing document? * [x] Have you checked to ensure there aren't other open [Pull Requests](https://github.com/fastly/cli/pulls) for the same update/change? <!-- You can erase any parts of this template not applicable to your Pull Request. --> ### New Feature Submissions: * [x] Does your submission pass tests? ### Are there any considerations that need to be addressed for release? We'll need to do a fast follow up PR after this to correct the go-releaser format deprecations.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps github.com/sigstore/cosign/v2 from 2.4.1 to 2.6.3.
Changelog
Sourced from github.com/sigstore/cosign/v2's changelog.
... (truncated)
Commits
fecddd3Fix DSSE predicate check (#4802)564c5b1Backport bundle detection to sign and attest (#4727)3ade80cFix bundle verify path for old bundle/trusted root (#4624)c4e6a78v2.6 branch - bump sigstore deps (#4619)634fabeBump sigstore-go, move conformance back to tagged releasec5545edPartially populate the output of cosign verify when working with new bundles ...e191024bump go builder to use 1.25.1 and cosign (#4417)37fbfc7Require exclusively a SigningConfig or service URLs when signing (#4403)b1acaebAdd a terminal spinner while signing with sigstore-go (#4402)2581dfdchore(deps): bump the gomod group across 1 directory with 8 updates (#4401)