Releases: sigstore/sigstore
Releases · sigstore/sigstore
v1.8.3
What's Changed
- Update embedded TUF root.json to version 9 from root-signing repo by @lkatalin in #1649
- add support for verifying IEEE P1363 encoded ECDSA sigs by @bobcallaway in #1686
Full Changelog: v1.8.2...v1.8.3
v1.8.2
What's Changed
- Add support for Ed25519ph Signer/Verifier by @ret2libc in #1595
- Convert ED25519phSignerVerifier to the Pure version by @ret2libc in #1616
- add client credential flow by @nkreiger in #1620
- Add support for autoclosing oauth flow window by @stgarf in #1618
- fix: adds TSA URI for customMetadata. by @ianhundere in #1646
New Contributors
- @ret2libc made their first contribution in #1595
- @nkreiger made their first contribution in #1620
- @stgarf made their first contribution in #1618
- @ianhundere made their first contribution in #1646
Full Changelog: v1.8.1...v1.8.2
v1.8.1
v1.8.0
What's Changed
- Bump the github.com/letsencrypt/boulder to the latest version to update vulnerable go-jose by @OlegOAndreev in #1548
- Update dependabot to weekly by @haydentherapper in #1569
- Adapt to simplified DSSE signing interface by @adityasaky in #1580
New Contributors
- @OlegOAndreev made their first contribution in #1548
Full Changelog: v1.7.6...v1.8.0
v1.7.6
What's Changed
- Fixes the error handling in kms/hashivault by @PuneetPunamiya in #1497
- Fix cosign generate Azure key pair bug by @malancas in #1525
Full Changelog: v1.7.5...v1.7.6
v1.7.5
What's Changed
- build(deps): bump cloud.google.com/go/kms from 1.15.2 to 1.15.3 in /pkg/signature/kms/gcp by @dependabot in #1459
- build(deps): bump github.com/aws/aws-sdk-go-v2/service/kms from 1.24.6 to 1.24.7 in /pkg/signature/kms/aws by @dependabot in #1458
- build(deps): bump github.com/sigstore/sigstore from 1.7.3 to 1.7.4 in /test/fuzz by @dependabot in #1457
- build(deps): bump actions/checkout from 4.1.0 to 4.1.1 by @dependabot in #1460
- build(deps): bump github.com/aws/aws-sdk-go from 1.45.25 to 1.45.27 in /pkg/signature/kms/aws by @dependabot in #1462
- build(deps): bump github.com/aws/aws-sdk-go-v2/config from 1.18.45 to 1.19.0 in /pkg/signature/kms/aws by @dependabot in #1461
- build(deps): bump github.com/aws/aws-sdk-go from 1.45.27 to 1.45.28 in /pkg/signature/kms/aws by @dependabot in #1464
- build(deps): bump google.golang.org/api from 0.147.0 to 0.148.0 in /pkg/signature/kms/gcp by @dependabot in #1463
- build(deps): bump github.com/aws/aws-sdk-go from 1.45.28 to 1.46.0 in /pkg/signature/kms/aws by @dependabot in #1466
- Create POLICY.md for algs/KMS by @haydentherapper in #1465
- build(deps): bump github.com/aws/aws-sdk-go from 1.46.0 to 1.46.1 in /pkg/signature/kms/aws by @dependabot in #1468
- build(deps): bump github.com/aws/aws-sdk-go from 1.46.1 to 1.46.2 in /pkg/signature/kms/aws by @dependabot in #1469
- build(deps): bump google.golang.org/grpc from 1.55.0 to 1.56.3 in /pkg/signature/kms/azure by @dependabot in #1477
- build(deps): bump google.golang.org/grpc from 1.55.0 to 1.56.3 in /pkg/signature/kms/hashivault by @dependabot in #1475
- build(deps): bump google.golang.org/grpc from 1.55.0 to 1.56.3 in /test/fuzz by @dependabot in #1474
- build(deps): bump hashicorp/vault from 1.15.0 to 1.15.1 in /test/e2e by @dependabot in #1472
- build(deps): bump github.com/aws/aws-sdk-go from 1.46.2 to 1.46.3 in /pkg/signature/kms/aws by @dependabot in #1471
- build(deps): bump github.com/aws/aws-sdk-go-v2/config from 1.19.0 to 1.19.1 in /pkg/signature/kms/aws by @dependabot in #1470
- build(deps): bump google.golang.org/grpc from 1.55.0 to 1.56.3 in /pkg/signature/kms/aws by @dependabot in #1476
- build(deps): bump google.golang.org/grpc from 1.55.0 to 1.56.3 by @dependabot in #1473
- build(deps): bump github.com/coreos/go-oidc/v3 from 3.6.0 to 3.7.0 by @dependabot in #1467
- bump go-tuf to v0.6.1 by @bobcallaway in #1479
Full Changelog: v1.7.4...v1.7.5
v1.7.4
What's Changed
- upgrade ci to run go1.21 and set min go version to 1.20 by @cpanato in #1372
- chore: Update the containers/image branch name by @haiyuewa in #1403
- Handles the error in kms/hashivault by @PuneetPunamiya in #1414
- update crypto/net/oauth2 dependencies by @cpanato in #1435
- ensure e2e tests run on new KMS modules by @bobcallaway in #1441
New Contributors
- @haiyuewa made their first contribution in #1403
- @PuneetPunamiya made their first contribution in #1414
Full Changelog: v1.7.3...v1.7.4
v1.7.3
What's Changed
- chore: update go-containerregistry by @k4leung4 in #1318
- fix(azure): RS512 should be used when key size is 512 by @shaneing in #1331
- Add VerifySignature integration test and cleanup other tests and print statements by @malancas in #1369
New Contributors
Full Changelog: v1.7.2...v1.7.3
v1.7.2
What's Changed
- fix race condition in unit test by @bobcallaway in #1263
- Specify hashes when comparing target meta. by @kommendorkapten in #1247
- hide warning from setup-gcloud by @bobcallaway in #1264
- Add support for additional Azure clouds (bug fix), add optional integration test by @malancas in #1272
- Bump TUF root version by @haydentherapper in #1312
Full Changelog: v1.7.1...v1.7.2