chore(deps): update dependency sigstore/cosign to v3.1.3 #184

Merged
CSRBot merged 1 commits from renovate/sigstore-cosign-3.x into master 2026-08-09 23:05:12 +02:00
Collaborator

This PR contains the following updates:

Package Update Change
sigstore/cosign patch v3.1.2v3.1.3

Release Notes

sigstore/cosign (sigstore/cosign)

v3.1.3

Compare Source

What's Changed

This release resolves GHSA-fx35-mq7g-6g98, a verification bypass using an unexpected public key in a legacy bundle.

  • Auto-detect default digest algorithm for public keys in #​5019
  • fix(pkcs11key): return an error instead of panicking when no key pair matches in #​5022
  • Supporting OCI Signing with X.509 Certificate Chain in #​4614
  • test(inspect): replace mock TSA client usage with local timestamp response generator in #​5021
  • fix: prevent shell completions for various options not taking filenames in #​5032
  • fix(blob): compare file checksums case-insensitively in #​5036
  • Verification bypass via public key in legacy bundle (GHSA-fx35-mq7g-6g98) in #​5040

Full Changelog: https://github.com/sigstore/cosign/compare/v3.1.2...v3.1.3


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate CLI.

This PR contains the following updates: | Package | Update | Change | |---|---|---| | [sigstore/cosign](https://github.com/sigstore/cosign) | patch | `v3.1.2` → `v3.1.3` | --- ### Release Notes <details> <summary>sigstore/cosign (sigstore/cosign)</summary> ### [`v3.1.3`](https://github.com/sigstore/cosign/releases/tag/v3.1.3) [Compare Source](https://github.com/sigstore/cosign/compare/v3.1.2...v3.1.3) #### What's Changed This release resolves GHSA-fx35-mq7g-6g98, a verification bypass using an unexpected public key in a legacy bundle. - Auto-detect default digest algorithm for public keys in [#&#8203;5019](https://github.com/sigstore/cosign/pull/5019) - fix(pkcs11key): return an error instead of panicking when no key pair matches in [#&#8203;5022](https://github.com/sigstore/cosign/pull/5022) - Supporting OCI Signing with X.509 Certificate Chain in [#&#8203;4614](https://github.com/sigstore/cosign/pull/4614) - test(inspect): replace mock TSA client usage with local timestamp response generator in [#&#8203;5021](https://github.com/sigstore/cosign/pull/5021) - fix: prevent shell completions for various options not taking filenames in [#&#8203;5032](https://github.com/sigstore/cosign/pull/5032) - fix(blob): compare file checksums case-insensitively in [#&#8203;5036](https://github.com/sigstore/cosign/pull/5036) - Verification bypass via public key in legacy bundle (GHSA-fx35-mq7g-6g98) in [#&#8203;5040](https://github.com/sigstore/cosign/pull/5040) **Full Changelog**: <https://github.com/sigstore/cosign/compare/v3.1.2...v3.1.3> </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Enabled. ♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yODguMCIsInVwZGF0ZWRJblZlciI6IjQ0LjE2LjEiLCJ0YXJnZXRCcmFuY2giOiJtYXN0ZXIiLCJsYWJlbHMiOlsicmVub3ZhdGUvYXV0b21lcmdlIiwicmVub3ZhdGUvZ2l0aHViLWFjdGlvbiJdfQ==-->
CODEOWNERS rules requested review from volker.raschek 2026-08-06 05:03:44 +02:00
CSRBot scheduled this pull request to auto merge when all checks succeed 2026-08-06 05:03:45 +02:00
volker.raschek was assigned by CSRBot 2026-08-06 08:03:01 +02:00
CSRBot added 1 commit 2026-08-09 23:04:22 +02:00
chore(deps): update dependency sigstore/cosign to v3.1.3
Helm / helm-lint (push) Successful in 10s
Helm / helm-unittest (push) Successful in 21s
Helm / helm-lint (pull_request) Successful in 14s
Helm / helm-unittest (pull_request) Successful in 18s
d6d2f7f632
CSRBot force-pushed renovate/sigstore-cosign-3.x from dd31b04e86 to d6d2f7f632 2026-08-09 23:04:22 +02:00 Compare
CSRBot merged commit 992a105ee7 into master 2026-08-09 23:05:12 +02:00
CSRBot deleted branch renovate/sigstore-cosign-3.x 2026-08-09 23:05:13 +02:00
Sign in to join this conversation.
No Reviewers
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: volker.raschek/athens-proxy-charts#184