chore(deps): update dependency sigstore/cosign to v2.6.3 #153

Merged
CSRBot merged 1 commits from renovate/sigstore-cosign-2.x into master 2026-04-14 14:10:36 +02:00
Collaborator

This PR contains the following updates:

Package Update Change
sigstore/cosign patch v2.6.2 -> v2.6.3

⚠️ Warning

Some dependencies could not be looked up. Check the warning logs for more information.


Release Notes

sigstore/cosign (sigstore/cosign)

v2.6.3

Compare Source

Changelog

v2.6.3 resolves GHSA-w6c6-c85g-mmv6.

Thanks to all contributors!

Configuration

📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Renovate Bot.

This PR contains the following updates: | Package | Update | Change | |---|---|---| | [sigstore/cosign](https://github.com/sigstore/cosign) | patch | `v2.6.2` -> `v2.6.3` | --- > ⚠️ **Warning** > > Some dependencies could not be looked up. Check the warning logs for more information. --- ### Release Notes <details> <summary>sigstore/cosign (sigstore/cosign)</summary> ### [`v2.6.3`](https://github.com/sigstore/cosign/releases/tag/v2.6.3) [Compare Source](https://github.com/sigstore/cosign/compare/v2.6.2...v2.6.3) #### Changelog v2.6.3 resolves [GHSA-w6c6-c85g-mmv6](https://github.com/sigstore/cosign/security/advisories/GHSA-w6c6-c85g-mmv6). - [`fecddd3`](https://github.com/sigstore/cosign/commit/fecddd3c22045a39f52392e71e79f66854b41352) Fix DSSE predicate check ([#&#8203;4802](https://github.com/sigstore/cosign/issues/4802)) - [`564c5b1`](https://github.com/sigstore/cosign/commit/564c5b1b0bed7bd991910774c47df1150ffb8aa8) Backport bundle detection to sign and attest ([#&#8203;4727](https://github.com/sigstore/cosign/issues/4727)) ##### Thanks to all contributors! </details> --- ### Configuration 📅 **Schedule**: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined). 🚦 **Automerge**: Enabled. ♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Renovate Bot](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0MS4xNDAuMSIsInVwZGF0ZWRJblZlciI6IjQxLjE0MC4xIiwidGFyZ2V0QnJhbmNoIjoibWFzdGVyIiwibGFiZWxzIjpbInJlbm92YXRlL2F1dG9tZXJnZSIsInJlbm92YXRlL2dpdGh1Yi1hY3Rpb24iXX0=-->
CSRBot added 1 commit 2026-04-14 12:55:27 +02:00
chore(deps): update dependency sigstore/cosign to v2.6.3
All checks were successful
Lint Golang files / Run golang CI linter (stable, ubuntu-latest-amd64) (push) Successful in 17s
Run Golang tests / Run unit tests (stable, ubuntu-latest-amd64) (push) Successful in 8s
Lint Golang files / Run golang CI linter (stable, ubuntu-latest-amd64) (pull_request) Successful in 17s
Run Golang tests / Run unit tests (stable, ubuntu-latest-amd64) (pull_request) Successful in 8s
Lint Markdown files / Run markdown linter (pull_request) Successful in 6s
Lint Golang files / Run golang CI linter (stable, ubuntu-latest-arm64) (push) Successful in 1m11s
Run Golang tests / Run unit tests (stable, ubuntu-latest-arm64) (push) Successful in 36s
Lint Golang files / Run golang CI linter (stable, ubuntu-latest-arm64) (pull_request) Successful in 1m11s
Run Golang tests / Run unit tests (stable, ubuntu-latest-arm64) (pull_request) Successful in 37s
a78b483f52
CSRBot scheduled this pull request to auto merge when all checks succeed 2026-04-14 12:55:32 +02:00
CSRBot merged commit cf8a8440d7 into master 2026-04-14 14:10:36 +02:00
CSRBot deleted branch renovate/sigstore-cosign-2.x 2026-04-14 14:10:37 +02:00
Sign in to join this conversation.
No Reviewers
No Label
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: volker.raschek/dcmerge#153