Skip to content

[release-v0.37.x] bump github.com/sigstore/cosign/v2 from 2.6.2 to 2.6.3 - #2975

Merged
tekton-robot merged 1 commit into
release-v0.37.xfrom
dependabot/go_modules/release-v0.37.x/github.com/sigstore/cosign/v2-2.6.3
Jul 13, 2026
Merged

tekton-robot merged 1 commit into
release-v0.37.xfrom
dependabot/go_modules/release-v0.37.x/github.com/sigstore/cosign/v2-2.6.3

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 3, 2026 •

Copy link
Copy Markdown
Contributor

Bumps github.com/sigstore/cosign/v2 from 2.6.2 to 2.6.3.

Release notes

Sourced from github.com/sigstore/cosign/v2's releases.

v2.6.3

Changelog

v2.6.3 resolves GHSA-w6c6-c85g-mmv6.

  • fecddd3c22045a39f52392e71e79f66854b41352 Fix DSSE predicate check (#4802)
  • 564c5b1b0bed7bd991910774c47df1150ffb8aa8 Backport bundle detection to sign and attest (#4727)

Thanks to all contributors!

Changelog

Sourced from github.com/sigstore/cosign/v2's changelog.

v3.0.5

Deprecations

  • Deprecate rekor-entry-type flag (#4691)
  • Deprecate cosign triangulate (#4676)
  • Deprecate cosign copy (#4681)

Features

  • Automatically require signed timestamp with Rekor v2 entries (#4666)
  • Allow --local-image with --new-bundle-format for v2 and v3 signatures (#4626)
  • Add mTLS support for TSA client connections when signing with a signing config (#4620)
  • Enforce TSA requirement for Rekor v2, Fuclio signing (#4683)

Bug Fixes

  • Add empty predicate to cosign sign when payload type is application/vnd.in-toto+json (#4635)
  • fix: avoid panic on malformed attestation payload (#4651)
  • fix: avoid panic on malformed tlog entries (#4649)
  • fix: avoid panic on malformed replace payload (#4653)
  • Gracefully fail if bundle payload body is not a string (#4648)
  • Verify validity of chain rather than just certificate (#4663)
  • fix: avoid panic on malformed tlog entry body (#4652)

Documentation

  • docs(cosign): clarify RFC3161 revocation semantics (#4642)
  • Fix typo in CLI help (#4701)

v3.0.4

v3.0.4 resolves GHSA-whqx-f9j3-ch6m.

Changes

  • Fix bundle verify path for old bundle/trusted root (GHSA-whqx-f9j3-ch6m) (#4623)
  • Optimize cosign tree performance by caching digest resolution (#4612)
  • Don't require a trusted root to verify offline with a key (#4613)
  • Support default services for trusted-root and signing-config creation (#4592)
Commits

@dependabot dependabot Bot added dependencies Used by dependabot - identifies all PRs created by dependabot kind/misc Categorizes issue or PR as a miscellaneuous one. ok-to-test Indicates a non-member PR verified by an org member that is safe to test. release-note-none Denotes a PR that doesnt merit a release note. labels Jul 3, 2026
@tekton-robot tekton-robot added the size/S Denotes a PR that changes 10-29 lines, ignoring generated files. label Jul 3, 2026
vdemeester
vdemeester previously approved these changes Jul 3, 2026

@vdemeester vdemeester left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

/lgtm

@vdemeester

Copy link
Copy Markdown
Member

/lgtm

@tekton-robot

Copy link
Copy Markdown
Contributor

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: vdemeester

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@tekton-robot tekton-robot added lgtm Indicates that a PR is ready to be merged. approved Indicates a PR has been approved by an approver from all required OWNERS files. labels Jul 3, 2026
@divyansh42

Copy link
Copy Markdown
Member

@dependabot rebase

@dependabot dependabot Bot changed the title Bump github.com/sigstore/cosign/v2 from 2.6.2 to 2.6.3 chore(deps): bump github.com/sigstore/cosign/v2 from 2.6.2 to 2.6.3 Jul 8, 2026
@dependabot
dependabot Bot force-pushed the dependabot/go_modules/release-v0.37.x/github.com/sigstore/cosign/v2-2.6.3 branch from f533811 to 91b82a9 Compare July 8, 2026 17:21
@tekton-robot tekton-robot added size/L Denotes a PR that changes 100-499 lines, ignoring generated files. and removed lgtm Indicates that a PR is ready to be merged. size/S Denotes a PR that changes 10-29 lines, ignoring generated files. labels Jul 8, 2026
@divyansh42

Copy link
Copy Markdown
Member

/lgtm

@tekton-robot tekton-robot added the lgtm Indicates that a PR is ready to be merged. label Jul 8, 2026
@dependabot dependabot Bot changed the title chore(deps): bump github.com/sigstore/cosign/v2 from 2.6.2 to 2.6.3 [release-v0.37.x] bump github.com/sigstore/cosign/v2 from 2.6.2 to 2.6.3 Jul 9, 2026
@dependabot
dependabot Bot force-pushed the dependabot/go_modules/release-v0.37.x/github.com/sigstore/cosign/v2-2.6.3 branch from 91b82a9 to ba65fbd Compare July 9, 2026 14:40
@tekton-robot tekton-robot removed the lgtm Indicates that a PR is ready to be merged. label Jul 9, 2026
@tekton-robot tekton-robot added size/S Denotes a PR that changes 10-29 lines, ignoring generated files. and removed size/L Denotes a PR that changes 100-499 lines, ignoring generated files. labels Jul 9, 2026
@divyansh42

Copy link
Copy Markdown
Member

/retest

@dependabot
dependabot Bot force-pushed the dependabot/go_modules/release-v0.37.x/github.com/sigstore/cosign/v2-2.6.3 branch from ba65fbd to 0afe800 Compare July 9, 2026 15:31
@divyansh42

Copy link
Copy Markdown
Member

@dependabot rebase

@dependabot
dependabot Bot force-pushed the dependabot/go_modules/release-v0.37.x/github.com/sigstore/cosign/v2-2.6.3 branch 3 times, most recently from fe2f684 to 3f7a9a3 Compare July 13, 2026 03:49
Bumps [github.com/sigstore/cosign/v2](https://github.com/sigstore/cosign) from 2.6.2 to 2.6.3.
- [Release notes](https://github.com/sigstore/cosign/releases)
- [Changelog](https://github.com/sigstore/cosign/blob/main/CHANGELOG.md)
- [Commits](sigstore/cosign@v2.6.2...v2.6.3)

---
updated-dependencies:
- dependency-name: github.com/sigstore/cosign/v2
  dependency-version: 2.6.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/go_modules/release-v0.37.x/github.com/sigstore/cosign/v2-2.6.3 branch from 3f7a9a3 to 4acb3e8 Compare July 13, 2026 04:47
@divyansh42

Copy link
Copy Markdown
Member

/lgtm

@tekton-robot tekton-robot added the lgtm Indicates that a PR is ready to be merged. label Jul 13, 2026
@tekton-robot
tekton-robot merged commit 265456a into release-v0.37.x Jul 13, 2026
12 checks passed
@dependabot
dependabot Bot deleted the dependabot/go_modules/release-v0.37.x/github.com/sigstore/cosign/v2-2.6.3 branch July 13, 2026 05:12
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

approved Indicates a PR has been approved by an approver from all required OWNERS files. dependencies Used by dependabot - identifies all PRs created by dependabot kind/misc Categorizes issue or PR as a miscellaneuous one. lgtm Indicates that a PR is ready to be merged. ok-to-test Indicates a non-member PR verified by an org member that is safe to test. release-note-none Denotes a PR that doesnt merit a release note. size/S Denotes a PR that changes 10-29 lines, ignoring generated files.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants