Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Bump github.com/sigstore/sigstore from 1.8.10 to 1.8.11 (#263)
Bumps [github.com/sigstore/sigstore](https://github.com/sigstore/sigstore) from 1.8.10 to 1.8.11. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/sigstore/sigstore/releases">github.com/sigstore/sigstore's releases</a>.</em></p> <blockquote> <h2>v1.8.11</h2> <h2>What's Changed</h2> <ul> <li>several dependabot updates</li> <li>Replace custom auth code with <code>azidentity.NewDefaultCredential</code> for Azure KMS client by <a href="https://github.com/malancas"><code>@malancas</code></a> in <a href="https://redirect.github.com/sigstore/sigstore/pull/1888">sigstore/sigstore#1888</a></li> <li>fix: set go module directive to 1.22.0 by <a href="https://github.com/dnwe"><code>@dnwe</code></a> in <a href="https://redirect.github.com/sigstore/sigstore/pull/1878">sigstore/sigstore#1878</a></li> </ul> <h2>New Contributors</h2> <ul> <li><a href="https://github.com/dnwe"><code>@dnwe</code></a> made their first contribution in <a href="https://redirect.github.com/sigstore/sigstore/pull/1878">sigstore/sigstore#1878</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/sigstore/sigstore/compare/v1.8.10...v1.8.11">https://github.com/sigstore/sigstore/compare/v1.8.10...v1.8.11</a></p> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/sigstore/sigstore/commit/185deaa2f5438a6e8ba828f625fee29724e3895c"><code>185deaa</code></a> build(deps): Bump golang.org/x/crypto from 0.29.0 to 0.31.0 (<a href="https://redirect.github.com/sigstore/sigstore/issues/1903">#1903</a>)</li> <li><a href="https://github.com/sigstore/sigstore/commit/7df71a7c913aa9f9fce2beb175bc36ed96ceee56"><code>7df71a7</code></a> build(deps): Bump cloud.google.com/go/kms (<a href="https://redirect.github.com/sigstore/sigstore/issues/1902">#1902</a>)</li> <li><a href="https://github.com/sigstore/sigstore/commit/f5270c42409d51d134b379af63c5063bc76981fe"><code>f5270c4</code></a> build(deps): Bump golang.org/x/crypto in /pkg/signature/kms/azure (<a href="https://redirect.github.com/sigstore/sigstore/issues/1905">#1905</a>)</li> <li><a href="https://github.com/sigstore/sigstore/commit/9bd204918fcfe7a13f633e33ccf27dd4cc5c5fc2"><code>9bd2049</code></a> build(deps): Bump google.golang.org/api in /pkg/signature/kms/gcp (<a href="https://redirect.github.com/sigstore/sigstore/issues/1906">#1906</a>)</li> <li><a href="https://github.com/sigstore/sigstore/commit/4e58ea1c70dbf8524a827228abc634c061cf9fd8"><code>4e58ea1</code></a> build(deps): Bump actions/cache from 4.1.2 to 4.2.0 in the all group (<a href="https://redirect.github.com/sigstore/sigstore/issues/1907">#1907</a>)</li> <li><a href="https://github.com/sigstore/sigstore/commit/7addd3b5d4f8af409093cc853f1fff5ce868b903"><code>7addd3b</code></a> build(deps): Bump localstack/localstack in /test/e2e in the all group (<a href="https://redirect.github.com/sigstore/sigstore/issues/1899">#1899</a>)</li> <li><a href="https://github.com/sigstore/sigstore/commit/cbdd1394652134f7090c7e505c568b4334669116"><code>cbdd139</code></a> build(deps): Bump the gomod group across 1 directory with 3 updates (<a href="https://redirect.github.com/sigstore/sigstore/issues/1900">#1900</a>)</li> <li><a href="https://github.com/sigstore/sigstore/commit/8041744654c92ee7fb4cbae516ea6bc9cb097fea"><code>8041744</code></a> build(deps): Bump github.com/stretchr/testify in /pkg/signature/kms/aws (<a href="https://redirect.github.com/sigstore/sigstore/issues/1893">#1893</a>)</li> <li><a href="https://github.com/sigstore/sigstore/commit/d66b91af4369a25b23b7e68b891c40af88a3b573"><code>d66b91a</code></a> build(deps): Bump google.golang.org/api in /pkg/signature/kms/gcp (<a href="https://redirect.github.com/sigstore/sigstore/issues/1894">#1894</a>)</li> <li><a href="https://github.com/sigstore/sigstore/commit/fa4a76d91fc401ddf46377efa1960b9cc2e0320b"><code>fa4a76d</code></a> build(deps): Bump github.com/stretchr/testify (<a href="https://redirect.github.com/sigstore/sigstore/issues/1895">#1895</a>)</li> <li>Additional commits viewable in <a href="https://github.com/sigstore/sigstore/compare/v1.8.10...v1.8.11">compare view</a></li> </ul> </details> <br /> [![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=github.com/sigstore/sigstore&package-manager=go_modules&previous-version=1.8.10&new-version=1.8.11)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
- Loading branch information