Skip to content
Permalink

Comparing changes

Choose two branches to see what’s changed or to start a new pull request. If you need to, you can also or learn more about diff comparisons.

Open a pull request

Create a new pull request by comparing changes across two branches. If you need to, you can also . Learn more about diff comparisons here.
base repository: sigstore/sigstore
Failed to load repositories. Confirm that selected base ref is valid, then try again.
Loading
base: v1.10.2
Choose a base ref
...
head repository: sigstore/sigstore
Failed to load repositories. Confirm that selected head ref is valid, then try again.
Loading
compare: v1.10.3
Choose a head ref
  • 12 commits
  • 25 files changed
  • 3 contributors

Commits on Dec 12, 2025

  1. build(deps): Bump golang.org/x/crypto in /test/fuzz (#2232)

    Bumps [golang.org/x/crypto](https://github.com/golang/crypto) from 0.43.0 to 0.45.0.
    - [Commits](golang/crypto@v0.43.0...v0.45.0)
    
    ---
    updated-dependencies:
    - dependency-name: golang.org/x/crypto
      dependency-version: 0.45.0
      dependency-type: indirect
    ...
    
    Signed-off-by: dependabot[bot] <[email protected]>
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
    dependabot[bot] authored Dec 12, 2025
    Configuration menu
    Copy the full SHA
    f5de82e View commit details
    Browse the repository at this point in the history
  2. build(deps): Bump github.com/google/go-containerregistry (#2228)

    Bumps the gomod group with 1 update in the / directory: [github.com/google/go-containerregistry](https://github.com/google/go-containerregistry).
    
    
    Updates `github.com/google/go-containerregistry` from 0.20.6 to 0.20.7
    - [Release notes](https://github.com/google/go-containerregistry/releases)
    - [Commits](google/go-containerregistry@v0.20.6...v0.20.7)
    
    ---
    updated-dependencies:
    - dependency-name: github.com/google/go-containerregistry
      dependency-version: 0.20.7
      dependency-type: direct:production
      update-type: version-update:semver-patch
      dependency-group: gomod
    ...
    
    Signed-off-by: dependabot[bot] <[email protected]>
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
    dependabot[bot] authored Dec 12, 2025
    Configuration menu
    Copy the full SHA
    afb1510 View commit details
    Browse the repository at this point in the history
  3. build(deps): Bump github.com/coreos/go-oidc/v3 from 3.16.0 to 3.17.0 (#…

    …2223)
    
    Bumps [github.com/coreos/go-oidc/v3](https://github.com/coreos/go-oidc) from 3.16.0 to 3.17.0.
    - [Release notes](https://github.com/coreos/go-oidc/releases)
    - [Commits](coreos/go-oidc@v3.16.0...v3.17.0)
    
    ---
    updated-dependencies:
    - dependency-name: github.com/coreos/go-oidc/v3
      dependency-version: 3.17.0
      dependency-type: direct:production
      update-type: version-update:semver-minor
    ...
    
    Signed-off-by: dependabot[bot] <[email protected]>
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
    dependabot[bot] authored Dec 12, 2025
    Configuration menu
    Copy the full SHA
    234b99d View commit details
    Browse the repository at this point in the history
  4. build(deps): Bump the all group with 2 updates (#2219)

    Bumps the all group with 2 updates: [actions/setup-go](https://github.com/actions/setup-go) and [golangci/golangci-lint-action](https://github.com/golangci/golangci-lint-action).
    
    
    Updates `actions/setup-go` from 6.0.0 to 6.1.0
    - [Release notes](https://github.com/actions/setup-go/releases)
    - [Commits](actions/setup-go@4469467...4dc6199)
    
    Updates `golangci/golangci-lint-action` from 9.0.0 to 9.1.0
    - [Release notes](https://github.com/golangci/golangci-lint-action/releases)
    - [Commits](golangci/golangci-lint-action@0a35821...e7fa5ac)
    
    ---
    updated-dependencies:
    - dependency-name: actions/setup-go
      dependency-version: 6.1.0
      dependency-type: direct:production
      update-type: version-update:semver-minor
      dependency-group: all
    - dependency-name: golangci/golangci-lint-action
      dependency-version: 9.1.0
      dependency-type: direct:production
      update-type: version-update:semver-minor
      dependency-group: all
    ...
    
    Signed-off-by: dependabot[bot] <[email protected]>
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
    dependabot[bot] authored Dec 12, 2025
    Configuration menu
    Copy the full SHA
    9e629f0 View commit details
    Browse the repository at this point in the history
  5. build(deps): Bump github.com/aws/aws-sdk-go-v2/service/kms (#2229)

    Bumps [github.com/aws/aws-sdk-go-v2/service/kms](https://github.com/aws/aws-sdk-go-v2) from 1.48.2 to 1.49.1.
    - [Release notes](https://github.com/aws/aws-sdk-go-v2/releases)
    - [Changelog](https://github.com/aws/aws-sdk-go-v2/blob/main/changelog-template.json)
    - [Commits](aws/aws-sdk-go-v2@service/kms/v1.48.2...service/ssm/v1.49.1)
    
    ---
    updated-dependencies:
    - dependency-name: github.com/aws/aws-sdk-go-v2/service/kms
      dependency-version: 1.49.1
      dependency-type: direct:production
      update-type: version-update:semver-minor
    ...
    
    Signed-off-by: dependabot[bot] <[email protected]>
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
    dependabot[bot] authored Dec 12, 2025
    Configuration menu
    Copy the full SHA
    63ab8d8 View commit details
    Browse the repository at this point in the history
  6. build(deps): Bump localstack/localstack in /test/e2e in the all group (

    …#2227)
    
    Bumps the all group in /test/e2e with 1 update: localstack/localstack.
    
    
    Updates `localstack/localstack` from 4.10.0 to 4.11.1
    
    ---
    updated-dependencies:
    - dependency-name: localstack/localstack
      dependency-version: 4.11.1
      dependency-type: direct:production
      update-type: version-update:semver-minor
      dependency-group: all
    ...
    
    Signed-off-by: dependabot[bot] <[email protected]>
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
    dependabot[bot] authored Dec 12, 2025
    Configuration menu
    Copy the full SHA
    cc26bb8 View commit details
    Browse the repository at this point in the history
  7. Add back ValidatePubKey as a deprecated, minimal function (#2235)

    This ended up causing a headache for downstream users. This adds back
    ValidatePubKey but without any external dependencies, and marks it as
    deprecated to instruct users to use the more comprehensive function.
    
    Signed-off-by: Hayden <[email protected]>
    Co-authored-by: Hayden <[email protected]>
    Hayden and Hayden-IO authored Dec 12, 2025
    Configuration menu
    Copy the full SHA
    0214948 View commit details
    Browse the repository at this point in the history
  8. build(deps): Bump golang.org/x/crypto in /pkg/signature/kms/aws (#2236)

    Bumps [golang.org/x/crypto](https://github.com/golang/crypto) from 0.44.0 to 0.45.0.
    - [Commits](golang/crypto@v0.44.0...v0.45.0)
    
    ---
    updated-dependencies:
    - dependency-name: golang.org/x/crypto
      dependency-version: 0.45.0
      dependency-type: indirect
    ...
    
    Signed-off-by: dependabot[bot] <[email protected]>
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
    dependabot[bot] authored Dec 12, 2025
    Configuration menu
    Copy the full SHA
    11dfe81 View commit details
    Browse the repository at this point in the history
  9. build(deps): Bump actions/checkout from 5.0.1 to 6.0.0 (#2220)

    Bumps [actions/checkout](https://github.com/actions/checkout) from 5.0.1 to 6.0.0.
    - [Release notes](https://github.com/actions/checkout/releases)
    - [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
    - [Commits](actions/checkout@93cb6ef...1af3b93)
    
    ---
    updated-dependencies:
    - dependency-name: actions/checkout
      dependency-version: 6.0.0
      dependency-type: direct:production
      update-type: version-update:semver-major
    ...
    
    Signed-off-by: dependabot[bot] <[email protected]>
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
    dependabot[bot] authored Dec 12, 2025
    Configuration menu
    Copy the full SHA
    bdc1a86 View commit details
    Browse the repository at this point in the history
  10. build(deps): Bump github.com/sigstore/sigstore (#2221)

    Bumps the tools group with 1 update in the /test/fuzz directory: [github.com/sigstore/sigstore](https://github.com/sigstore/sigstore).
    
    
    Updates `github.com/sigstore/sigstore` from 1.9.5 to 1.10.0
    - [Release notes](https://github.com/sigstore/sigstore/releases)
    - [Commits](v1.9.5...v1.10.0)
    
    ---
    updated-dependencies:
    - dependency-name: github.com/sigstore/sigstore
      dependency-version: 1.10.0
      dependency-type: direct:production
      update-type: version-update:semver-minor
      dependency-group: tools
    ...
    
    Signed-off-by: dependabot[bot] <[email protected]>
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
    dependabot[bot] authored Dec 12, 2025
    Configuration menu
    Copy the full SHA
    84f57b8 View commit details
    Browse the repository at this point in the history
  11. build(deps): Bump github.com/aws/aws-sdk-go-v2 in /pkg/signature/kms/…

    …aws (#2226)
    
    Bumps [github.com/aws/aws-sdk-go-v2](https://github.com/aws/aws-sdk-go-v2) from 1.39.6 to 1.40.0.
    - [Release notes](https://github.com/aws/aws-sdk-go-v2/releases)
    - [Changelog](https://github.com/aws/aws-sdk-go-v2/blob/main/changelog-template.json)
    - [Commits](aws/aws-sdk-go-v2@v1.39.6...v1.40.0)
    
    ---
    updated-dependencies:
    - dependency-name: github.com/aws/aws-sdk-go-v2
      dependency-version: 1.40.0
      dependency-type: direct:production
      update-type: version-update:semver-minor
    ...
    
    Signed-off-by: dependabot[bot] <[email protected]>
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
    dependabot[bot] authored Dec 12, 2025
    Configuration menu
    Copy the full SHA
    b257168 View commit details
    Browse the repository at this point in the history
  12. build(deps): Bump github.com/aws/aws-sdk-go-v2/config (#2230)

    Bumps [github.com/aws/aws-sdk-go-v2/config](https://github.com/aws/aws-sdk-go-v2) from 1.31.20 to 1.32.2.
    - [Release notes](https://github.com/aws/aws-sdk-go-v2/releases)
    - [Changelog](https://github.com/aws/aws-sdk-go-v2/blob/main/changelog-template.json)
    - [Commits](aws/aws-sdk-go-v2@config/v1.31.20...v1.32.2)
    
    ---
    updated-dependencies:
    - dependency-name: github.com/aws/aws-sdk-go-v2/config
      dependency-version: 1.32.2
      dependency-type: direct:production
      update-type: version-update:semver-minor
    ...
    
    Signed-off-by: dependabot[bot] <[email protected]>
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
    dependabot[bot] authored Dec 12, 2025
    Configuration menu
    Copy the full SHA
    72f0ed7 View commit details
    Browse the repository at this point in the history
Loading