This PR contains the following updates:
| Package | Update | Change |
|---|---|---|
| [sigstore/cosign](https://github.com/sigstore/cosign) | patch | `v3.1.2` → `v3.1.3` |
---
### Release Notes
<details>
<summary>sigstore/cosign (sigstore/cosign)</summary>
### [`v3.1.3`](https://github.com/sigstore/cosign/releases/tag/v3.1.3)
[Compare Source](https://github.com/sigstore/cosign/compare/v3.1.2...v3.1.3)
#### What's Changed
This release resolves GHSA-fx35-mq7g-6g98, a verification bypass using an unexpected public key in a legacy bundle.
- Auto-detect default digest algorithm for public keys in [#​5019](https://github.com/sigstore/cosign/pull/5019)
- fix(pkcs11key): return an error instead of panicking when no key pair matches in [#​5022](https://github.com/sigstore/cosign/pull/5022)
- Supporting OCI Signing with X.509 Certificate Chain in [#​4614](https://github.com/sigstore/cosign/pull/4614)
- test(inspect): replace mock TSA client usage with local timestamp response generator in [#​5021](https://github.com/sigstore/cosign/pull/5021)
- fix: prevent shell completions for various options not taking filenames in [#​5032](https://github.com/sigstore/cosign/pull/5032)
- fix(blob): compare file checksums case-insensitively in [#​5036](https://github.com/sigstore/cosign/pull/5036)
- Verification bypass via public key in legacy bundle (GHSA-fx35-mq7g-6g98) in [#​5040](https://github.com/sigstore/cosign/pull/5040)
**Full Changelog**: <https://github.com/sigstore/cosign/compare/v3.1.2...v3.1.3>
</details>
---
### Configuration
📅 **Schedule**: (UTC)
- Branch creation
- At any time (no schedule defined)
- Automerge
- At any time (no schedule defined)
🚦 **Automerge**: Enabled.
♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about this update again.
---
- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box
---
This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yODguMCIsInVwZGF0ZWRJblZlciI6IjQ0LjE3LjAiLCJ0YXJnZXRCcmFuY2giOiJtYXN0ZXIiLCJsYWJlbHMiOlsicmVub3ZhdGUvYXV0b21lcmdlIiwicmVub3ZhdGUvZ2l0aHViLWFjdGlvbiJdfQ==-->
CODEOWNERS rules
requested review from volker.raschek 2026-08-06 05:16:10 +02:00
CSRBot
scheduled this pull request to auto merge when all checks succeed 2026-08-06 05:16:13 +02:00
volker.raschek
was assigned by CSRBot2026-08-06 08:18:29 +02:00
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
This PR contains the following updates:
v3.1.2→v3.1.3Release Notes
sigstore/cosign (sigstore/cosign)
v3.1.3Compare Source
What's Changed
This release resolves GHSA-fx35-mq7g-6g98, a verification bypass using an unexpected public key in a legacy bundle.
Full Changelog: https://github.com/sigstore/cosign/compare/v3.1.2...v3.1.3
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR has been generated by Mend Renovate CLI.
9cf7123761to571dc04f8f