Skip to content

chore(deps): update dependency sigstore/cosign to v3.1.3 - #6016

Open
renovate-fullsend[bot] wants to merge 1 commit into
mainfrom
renovate/sigstore-cosign-3.x
Open

chore(deps): update dependency sigstore/cosign to v3.1.3#6016
renovate-fullsend[bot] wants to merge 1 commit into
mainfrom
renovate/sigstore-cosign-3.x

Conversation

@renovate-fullsend

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Update Change
sigstore/cosign patch 3.1.23.1.3

Warning

Some dependencies could not be looked up. Check the Dependency Dashboard for more information.


Release Notes

sigstore/cosign (sigstore/cosign)

v3.1.3

Compare Source

What's Changed

This release resolves GHSA-fx35-mq7g-6g98, a verification bypass using an unexpected public key in a legacy bundle.

  • Auto-detect default digest algorithm for public keys in #​5019
  • fix(pkcs11key): return an error instead of panicking when no key pair matches in #​5022
  • Supporting OCI Signing with X.509 Certificate Chain in #​4614
  • test(inspect): replace mock TSA client usage with local timestamp response generator in #​5021
  • fix: prevent shell completions for various options not taking filenames in #​5032
  • fix(blob): compare file checksums case-insensitively in #​5036
  • Verification bypass via public key in legacy bundle (GHSA-fx35-mq7g-6g98) in #​5040

Full Changelog: sigstore/cosign@v3.1.2...v3.1.3


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate.

@renovate-fullsend
renovate-fullsend Bot requested a review from a team as a code owner August 8, 2026 15:22
@fullsend-ai-review

fullsend-ai-review Bot commented Aug 8, 2026

Copy link
Copy Markdown

🤖 Finished Review · ✅ Success · Started 3:23 PM UTC · Completed 3:33 PM UTC

Commit: 763a87c · View workflow run →

@codecov

codecov Bot commented Aug 8, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.

📢 Thoughts on this report? Let us know!

@fullsend-ai-review

fullsend-ai-review Bot commented Aug 8, 2026

Copy link
Copy Markdown

Review

Findings

Medium

  • [protected-path] scripts/renovate/update-tirith-checksums.sh — This file is under scripts/, a protected path requiring human approval. The PR is a Renovate-automated cosign version bump (3.1.2 → 3.1.3) addressing upstream security advisory GHSA-fx35-mq7g-6g98. The change is well-scoped (version string + SHA256 hash update only), but human approval is always required for protected-path changes.
Previous run

Review

Findings

Medium

  • [protected-path] scripts/renovate/update-tirith-checksums.sh — This file is under scripts/, a protected path requiring human approval. The PR is a Renovate-automated cosign version bump (3.1.2 → 3.1.3) addressing upstream security advisory GHSA-fx35-mq7g-6g98. The change is well-scoped (version string + SHA256 hash update only), but human approval is always required for protected-path changes.

Labels: Renovate dependency update for cosign addressing security advisory GHSA-fx35-mq7g-6g98

@fullsend-ai-review fullsend-ai-review Bot added requires-manual-review Review requires human judgment dependencies Pull requests that update a dependency file security Security threat model and related concerns labels Aug 8, 2026
@renovate-fullsend
renovate-fullsend Bot force-pushed the renovate/sigstore-cosign-3.x branch from 763a87c to 397c648 Compare August 9, 2026 03:49
@fullsend-ai-review

fullsend-ai-review Bot commented Aug 9, 2026

Copy link
Copy Markdown

🤖 Finished Review · ✅ Success · Started 3:50 AM UTC · Completed 4:00 AM UTC

Commit: 397c648 · View workflow run →

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file requires-manual-review Review requires human judgment security Security threat model and related concerns

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants