This PR contains the following updates:
| Package | Update | Change |
|---|---|---|
| [sigstore/cosign](https://github.com/sigstore/cosign) | patch | `v3.1.2` → `v3.1.3` |
---
> ⚠️ **Warning**
>
> Some dependencies could not be looked up. Check the [Dependency Dashboard](issues/156) for more information.
---
### Release Notes
<details>
<summary>sigstore/cosign (sigstore/cosign)</summary>
### [`v3.1.3`](https://github.com/sigstore/cosign/releases/tag/v3.1.3)
[Compare Source](https://github.com/sigstore/cosign/compare/v3.1.2...v3.1.3)
#### What's Changed
This release resolves GHSA-fx35-mq7g-6g98, a verification bypass using an unexpected public key in a legacy bundle.
- Auto-detect default digest algorithm for public keys in [#​5019](https://github.com/sigstore/cosign/pull/5019)
- fix(pkcs11key): return an error instead of panicking when no key pair matches in [#​5022](https://github.com/sigstore/cosign/pull/5022)
- Supporting OCI Signing with X.509 Certificate Chain in [#​4614](https://github.com/sigstore/cosign/pull/4614)
- test(inspect): replace mock TSA client usage with local timestamp response generator in [#​5021](https://github.com/sigstore/cosign/pull/5021)
- fix: prevent shell completions for various options not taking filenames in [#​5032](https://github.com/sigstore/cosign/pull/5032)
- fix(blob): compare file checksums case-insensitively in [#​5036](https://github.com/sigstore/cosign/pull/5036)
- Verification bypass via public key in legacy bundle (GHSA-fx35-mq7g-6g98) in [#​5040](https://github.com/sigstore/cosign/pull/5040)
**Full Changelog**: <https://github.com/sigstore/cosign/compare/v3.1.2...v3.1.3>
</details>
---
### Configuration
📅 **Schedule**: (UTC)
- Branch creation
- At any time (no schedule defined)
- Automerge
- At any time (no schedule defined)
🚦 **Automerge**: Enabled.
♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about this update again.
---
- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box
---
This PR has been generated by [Mend Renovate](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yODguMCIsInVwZGF0ZWRJblZlciI6IjQzLjI4OC4wIiwidGFyZ2V0QnJhbmNoIjoibWFzdGVyIiwibGFiZWxzIjpbInJlbm92YXRlL2F1dG9tZXJnZSIsInJlbm92YXRlL2dpdGh1Yi1hY3Rpb24iXX0=-->
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
This PR contains the following updates:
v3.1.2→v3.1.3Release Notes
sigstore/cosign (sigstore/cosign)
v3.1.3Compare Source
What's Changed
This release resolves GHSA-fx35-mq7g-6g98, a verification bypass using an unexpected public key in a legacy bundle.
Full Changelog: https://github.com/sigstore/cosign/compare/v3.1.2...v3.1.3
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR has been generated by Mend Renovate.
View command line instructions
Checkout
From your project repository, check out a new branch and test the changes.