Skip to content

chore(deps): Bump chainguard-dev/cosign from 0.4.14 to 0.4.20 - #399

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/terraform/chainguard-dev/cosign-0.4.20
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/terraform/chainguard-dev/cosign-0.4.20

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 8, 2026

Copy link
Copy Markdown
Contributor

Bumps chainguard-dev/cosign from 0.4.14 to 0.4.20.

Release notes

Sourced from chainguard-dev/cosign's releases.

Release v0.4.20

Changelog

  • 9b1f2db8660c0fb3961b3825e9472fdd2b60b1d8 chore(deps): bump google.golang.org/grpc from 1.82.1 to 1.83.1 (#625)
  • 63910bb2a478817af105791145a2b4e5789b8ec7 Bump Go to 1.27.0 and golangci-lint to v2.13 (#626)
  • fea61d250a1fa4a6f41e6c698d3aa2a98a6ee0cd chore(deps): bump github.com/chainguard-dev/terraform-provider-oci from 0.1.10 to 0.1.11 (#624)
  • 665bcfe817375b354eaa283ae18a476b133486ea fix(secant): SignBundle signs index children like legacy Sign (#623)
  • f9ccb8fd1280e9a89d2fa00cbe1ca1afb709da60 chore(deps): bump github.com/go-openapi/runtime from 0.33.0 to 0.33.1 (#622)
  • a46dd6ff395e7f3c94960eb820fe9bee3734ce31 chore(deps): bump github.com/go-openapi/swag/conv from 0.29.0 to 0.29.1 (#621)
  • 357f61953d94882c6f61341662c50a4d5a5040d1 chore(deps): bump github.com/sigstore/protobuf-specs from 0.5.1 to 0.5.2 (#620)
  • 00967c0ff98f9d6b5f0e861bf59a69df69c5ca85 chore(deps): bump github.com/google/go-containerregistry from 0.21.9 to 0.22.0 (#619)

Release v0.4.19

Changelog

  • 44cac55c3518c94785843f0e4fb656f4a56d3f6d chore: bump github.com/sigstore/rekor to 1.5.4 (#616)
  • 86b051260fb81c148e6b56bb6e459e9abd8f16f8 chore(deps): bump github.com/secure-systems-lab/go-securesystemslib from 0.11.0 to 0.11.1 (#614)
  • aa5cfc2e10037e6d9ce874e3cd27cd5365bdc7f6 chore(deps): bump github.com/go-openapi/swag/conv from 0.28.0 to 0.29.0 (#613)
  • 60df70cf8bdea8c6842da842a38f8970afb3fecb cosign: bump to v3.1.3, pin policy-controller to unreleased fix (#612)
  • 12122fbf98af4fffc804253825403b803cc85d8c chore(deps): bump github.com/chainguard-dev/terraform-provider-oci from 0.1.9 to 0.1.10 (#611)
  • b9b3659282cd952cb138cfb2682cd18a054867a5 chore(deps): bump step-security/action-actionlint from 1.72.0 to 1.73.1 (#610)

Release v0.4.18

Changelog

  • d8622b5a7c350ff4a065ad2523e686419723e9e2 chore(deps): bump step-security/harden-runner from 2.20.1 to 2.21.0 (#609)

Release v0.4.17

Changelog

  • a231f2d59d3482cdb5d3643a167699d40faf537a secant: add a non-recursive mode to Sign (#608)

Release v0.4.16

Changelog

  • 19f58663d72cad25349fbbb5d2f328f10fcfa436 chore(deps): bump github.com/chainguard-dev/terraform-provider-oci from 0.1.8 to 0.1.9 (#607)
  • fb5adf71f8215473b2d57fc139e2f58ddc4d3548 chore(deps): bump google.golang.org/protobuf from 1.36.12-0.20260120151049-f2248ac996af to 1.36.12 (#606)
  • 0f2376bae9663a354ea324305f99d105e71604ab Add a chainguard-token-cache OIDC provider (#605)

Release v0.4.15

Changelog

  • ff5fd0dd8e720619bd9d55b949b03f882ed8d214 chore(deps): bump github.com/google/go-containerregistry from 0.21.8 to 0.21.9 (#603)
  • f419dfc32f4ddabedb5ffa80303361c0fb51ce26 chore(deps): bump github.com/prometheus/client_golang from 1.23.2 to 1.24.1 (#601)
  • 7d76e7018545a841e7687ff12a1171fe28ada431 chore(deps): bump github.com/chainguard-dev/terraform-provider-oci from 0.1.7 to 0.1.8 (#602)
  • 5a2624a3ce205b4c9af5bc411965690474717eb6 secant: add rekor rate limiter wait-duration metric (#600)
  • 82112cdbb2c110bd8473a59cec9f2c9659d7472d chore(deps): bump github.com/sigstore/sigstore from 1.10.8 to 1.10.9 (#597)
  • 76e688f6518acba22cb311db5194081e2f2c2f4e Drop deprecated sigstore/pkg/tuf import from secant (#599)
  • 24350bf12bb723ccfc33703e96e1a25ae394ce00 chore(deps): bump step-security/harden-runner from 2.20.0 to 2.20.1 (#598)
  • 634d95a0234bb955ccc030f8a4798a2afd9820cd chore(deps): bump github.com/google/go-containerregistry from 0.21.7 to 0.21.8 (#596)
  • 147fb6fc0946cb1342f215530332763513930169 chore(deps): bump github.com/hashicorp/terraform-plugin-log from 0.10.0 to 0.11.0 in the terraform group (#595)
  • f1587368acabbcde4d8bfaeac225be7fed7b6b8e chore(deps): bump zizmorcore/zizmor-action from 0.6.1 to 0.6.2 (#594)
Commits
  • 9b1f2db chore(deps): bump google.golang.org/grpc from 1.82.1 to 1.83.1 (#625)
  • 63910bb Bump Go to 1.27.0 and golangci-lint to v2.13 (#626)
  • fea61d2 chore(deps): bump github.com/chainguard-dev/terraform-provider-oci from 0.1.1...
  • 665bcfe fix(secant): SignBundle signs index children like legacy Sign (#623)
  • f9ccb8f chore(deps): bump github.com/go-openapi/runtime from 0.33.0 to 0.33.1 (#622)
  • a46dd6f chore(deps): bump github.com/go-openapi/swag/conv from 0.29.0 to 0.29.1 (#621)
  • 357f619 chore(deps): bump github.com/sigstore/protobuf-specs from 0.5.1 to 0.5.2 (#620)
  • 00967c0 chore(deps): bump github.com/google/go-containerregistry from 0.21.9 to 0.22....
  • 44cac55 chore: bump github.com/sigstore/rekor to 1.5.4 (#616)
  • 86b0512 chore(deps): bump github.com/secure-systems-lab/go-securesystemslib from 0.11...
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [chainguard-dev/cosign](https://github.com/chainguard-dev/terraform-provider-cosign) from 0.4.14 to 0.4.20.
- [Release notes](https://github.com/chainguard-dev/terraform-provider-cosign/releases)
- [Commits](chainguard-dev/terraform-provider-cosign@v0.4.14...v0.4.20)

---
updated-dependencies:
- dependency-name: chainguard-dev/cosign
  dependency-version: 0.4.20
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file terraform Pull requests that update Terraform code labels Sep 8, 2026
@dependabot @github

dependabot Bot commented on behalf of github Sep 14, 2026

Copy link
Copy Markdown
Contributor Author

Superseded by #404.

@dependabot dependabot Bot closed this Sep 14, 2026
@dependabot
dependabot Bot deleted the dependabot/terraform/chainguard-dev/cosign-0.4.20 branch September 14, 2026 13:15
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file terraform Pull requests that update Terraform code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants