Skip to content

chore(deps): Bump chainguard-dev/cosign from 0.4.14 to 0.5.0 - #404

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/terraform/chainguard-dev/cosign-0.5.0
Open

chore(deps): Bump chainguard-dev/cosign from 0.4.14 to 0.5.0#404
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/terraform/chainguard-dev/cosign-0.5.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 14, 2026

Copy link
Copy Markdown
Contributor

Bumps chainguard-dev/cosign from 0.4.14 to 0.5.0.

Release notes

Sourced from chainguard-dev/cosign's releases.

Release v0.5.0

Changelog

  • 7a6c1633f8671f5da7d3df40311493197ecf5840 feat(secant): add SignBundleDigest for fetch-free single-digest signing (#633)
  • fb096cc0f4c290261bb9f4e7cb44055f5b003982 chore(deps): bump golang.org/x/oauth2 from 0.36.0 to 0.37.0 (#631)
  • 543747475d2f3395477bb92960fd3cfeb62c9dfc chore(deps): bump golang.org/x/time from 0.15.0 to 0.16.0 (#632)
  • cfbc519da95871f697bfbe364b734f4cd6ef93d1 chore(deps): bump google.golang.org/grpc from 1.83.1 to 1.83.2 (#630)
  • ae72a50c03f4474334ebca613bde4ee9e2220391 chore(deps): bump github.com/prometheus/client_model from 0.6.2 to 0.6.3 (#629)
  • 79428d64de2182b5098b2532bf2e2f0c33b3f38b chore(deps): bump step-security/harden-runner from 2.21.0 to 2.21.1 (#627)
  • de668c69806803a1782db9e1c47614adbe6d03ab chore(deps): bump zizmorcore/zizmor-action from 0.6.2 to 0.6.3 (#628)

Release v0.4.20

Changelog

  • 9b1f2db8660c0fb3961b3825e9472fdd2b60b1d8 chore(deps): bump google.golang.org/grpc from 1.82.1 to 1.83.1 (#625)
  • 63910bb2a478817af105791145a2b4e5789b8ec7 Bump Go to 1.27.0 and golangci-lint to v2.13 (#626)
  • fea61d250a1fa4a6f41e6c698d3aa2a98a6ee0cd chore(deps): bump github.com/chainguard-dev/terraform-provider-oci from 0.1.10 to 0.1.11 (#624)
  • 665bcfe817375b354eaa283ae18a476b133486ea fix(secant): SignBundle signs index children like legacy Sign (#623)
  • f9ccb8fd1280e9a89d2fa00cbe1ca1afb709da60 chore(deps): bump github.com/go-openapi/runtime from 0.33.0 to 0.33.1 (#622)
  • a46dd6ff395e7f3c94960eb820fe9bee3734ce31 chore(deps): bump github.com/go-openapi/swag/conv from 0.29.0 to 0.29.1 (#621)
  • 357f61953d94882c6f61341662c50a4d5a5040d1 chore(deps): bump github.com/sigstore/protobuf-specs from 0.5.1 to 0.5.2 (#620)
  • 00967c0ff98f9d6b5f0e861bf59a69df69c5ca85 chore(deps): bump github.com/google/go-containerregistry from 0.21.9 to 0.22.0 (#619)

Release v0.4.19

Changelog

  • 44cac55c3518c94785843f0e4fb656f4a56d3f6d chore: bump github.com/sigstore/rekor to 1.5.4 (#616)
  • 86b051260fb81c148e6b56bb6e459e9abd8f16f8 chore(deps): bump github.com/secure-systems-lab/go-securesystemslib from 0.11.0 to 0.11.1 (#614)
  • aa5cfc2e10037e6d9ce874e3cd27cd5365bdc7f6 chore(deps): bump github.com/go-openapi/swag/conv from 0.28.0 to 0.29.0 (#613)
  • 60df70cf8bdea8c6842da842a38f8970afb3fecb cosign: bump to v3.1.3, pin policy-controller to unreleased fix (#612)
  • 12122fbf98af4fffc804253825403b803cc85d8c chore(deps): bump github.com/chainguard-dev/terraform-provider-oci from 0.1.9 to 0.1.10 (#611)
  • b9b3659282cd952cb138cfb2682cd18a054867a5 chore(deps): bump step-security/action-actionlint from 1.72.0 to 1.73.1 (#610)

Release v0.4.18

Changelog

  • d8622b5a7c350ff4a065ad2523e686419723e9e2 chore(deps): bump step-security/harden-runner from 2.20.1 to 2.21.0 (#609)

Release v0.4.17

Changelog

  • a231f2d59d3482cdb5d3643a167699d40faf537a secant: add a non-recursive mode to Sign (#608)

Release v0.4.16

Changelog

  • 19f58663d72cad25349fbbb5d2f328f10fcfa436 chore(deps): bump github.com/chainguard-dev/terraform-provider-oci from 0.1.8 to 0.1.9 (#607)
  • fb5adf71f8215473b2d57fc139e2f58ddc4d3548 chore(deps): bump google.golang.org/protobuf from 1.36.12-0.20260120151049-f2248ac996af to 1.36.12 (#606)
  • 0f2376bae9663a354ea324305f99d105e71604ab Add a chainguard-token-cache OIDC provider (#605)

Release v0.4.15

Changelog

  • ff5fd0dd8e720619bd9d55b949b03f882ed8d214 chore(deps): bump github.com/google/go-containerregistry from 0.21.8 to 0.21.9 (#603)
  • f419dfc32f4ddabedb5ffa80303361c0fb51ce26 chore(deps): bump github.com/prometheus/client_golang from 1.23.2 to 1.24.1 (#601)
  • 7d76e7018545a841e7687ff12a1171fe28ada431 chore(deps): bump github.com/chainguard-dev/terraform-provider-oci from 0.1.7 to 0.1.8 (#602)
  • 5a2624a3ce205b4c9af5bc411965690474717eb6 secant: add rekor rate limiter wait-duration metric (#600)

... (truncated)

Commits
  • 7a6c163 feat(secant): add SignBundleDigest for fetch-free single-digest signing (#633)
  • fb096cc chore(deps): bump golang.org/x/oauth2 from 0.36.0 to 0.37.0 (#631)
  • 5437474 chore(deps): bump golang.org/x/time from 0.15.0 to 0.16.0 (#632)
  • cfbc519 chore(deps): bump google.golang.org/grpc from 1.83.1 to 1.83.2 (#630)
  • ae72a50 chore(deps): bump github.com/prometheus/client_model from 0.6.2 to 0.6.3 (#629)
  • 79428d6 chore(deps): bump step-security/harden-runner from 2.21.0 to 2.21.1 (#627)
  • de668c6 chore(deps): bump zizmorcore/zizmor-action from 0.6.2 to 0.6.3 (#628)
  • 9b1f2db chore(deps): bump google.golang.org/grpc from 1.82.1 to 1.83.1 (#625)
  • 63910bb Bump Go to 1.27.0 and golangci-lint to v2.13 (#626)
  • fea61d2 chore(deps): bump github.com/chainguard-dev/terraform-provider-oci from 0.1.1...
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [chainguard-dev/cosign](https://github.com/chainguard-dev/terraform-provider-cosign) from 0.4.14 to 0.5.0.
- [Release notes](https://github.com/chainguard-dev/terraform-provider-cosign/releases)
- [Commits](chainguard-dev/terraform-provider-cosign@v0.4.14...v0.5.0)

---
updated-dependencies:
- dependency-name: chainguard-dev/cosign
  dependency-version: 0.5.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file terraform Pull requests that update Terraform code labels Sep 14, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file terraform Pull requests that update Terraform code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants