Bump github.com/sigstore/fulcio from 1.8.5 to 1.8.6#426
Conversation
|
Hi @dependabot[bot]. Thanks for your PR. I'm waiting for a openshift member to verify that this patch is reasonable to test. If it is, they should reply with Regular contributors should join the org to skip this step. Once the patch is verified, the new status will be reflected by the I understand the commands that are listed here. DetailsInstructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. |
WalkthroughThis PR updates indirect Go module dependencies in ChangesDependency version updates
Estimated code review effort: 1 (Trivial) | ~5 minutes Suggested reviewers: 🚥 Pre-merge checks | ✅ 15✅ Passed checks (15 passed)
✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Comment |
kaovilai
left a comment
There was a problem hiding this comment.
unfortunately this contain go bump from fulcio from googleapis/enterprise-certificate-proxy#195
if not urgent i would wait for new fulcio.
but low risk as this is not lib repo in general.. we ship built binary.
|
rebase DetailsInstructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. |
Bumps [github.com/sigstore/fulcio](https://github.com/sigstore/fulcio) from 1.8.5 to 1.8.6. - [Release notes](https://github.com/sigstore/fulcio/releases) - [Changelog](https://github.com/sigstore/fulcio/blob/main/CHANGELOG.md) - [Commits](sigstore/fulcio@v1.8.5...v1.8.6) --- updated-dependencies: - dependency-name: github.com/sigstore/fulcio dependency-version: 1.8.6 dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com>
3302b9b to
04b1f43
Compare
|
[APPROVALNOTIFIER] This PR is NOT APPROVED This pull-request has been approved by: dependabot[bot] The full list of commands accepted by this bot can be found here. DetailsNeeds approval from an approver in each of these files:Approvers can indicate their approval by writing |
1 similar comment
|
[APPROVALNOTIFIER] This PR is NOT APPROVED This pull-request has been approved by: dependabot[bot] The full list of commands accepted by this bot can be found here. DetailsNeeds approval from an approver in each of these files:Approvers can indicate their approval by writing |
Bumps github.com/sigstore/fulcio from 1.8.5 to 1.8.6.
Release notes
Sourced from github.com/sigstore/fulcio's releases.
Changelog
Sourced from github.com/sigstore/fulcio's changelog.
Commits
378c654Block cross-host redirects and restrict bearer token to expected host (#2354)7a5d3e3bump builder image to use go1.26.3 (#2353)a05982ebuild(deps): bump go.step.sm/crypto from 0.75.0 to 0.81.0 (#2348)dfa63a8build(deps): bump golang from313faaeto2d6c802(#2344)7b3a344build(deps): bump google.golang.org/api from 0.279.0 to 0.280.0 (#2349)9290f7fbuild(deps): bump the all group with 2 updates (#2350)423d535build(deps): bump nginx from 1.31.0 to 1.31.1 in the all group (#2352)19a3f8ebuild(deps): bump the all group across 1 directory with 6 updates (#2337)6b597cebuild(deps): bump google.golang.org/api from 0.276.0 to 0.279.0 (#2338)0d1dc79build(deps): bump nginx from 1.29.8 to 1.31.0 in the all group (#2342)Summary by CodeRabbit