Skip to content

Conversation

@sondavidb
Copy link
Contributor

@sondavidb sondavidb commented Dec 12, 2025

Issue #, if available:
Fix dependabot security alert

Description of changes:
Update sigstore to v2.0.3 in cosign

Testing done:

  • I've reviewed the guidance in CONTRIBUTING.md

License Acceptance

By submitting this pull request, I confirm that my contribution is made under the terms of the Apache 2.0 license.

@sondavidb sondavidb requested a review from a team as a code owner December 12, 2025 01:37
@pendo324
Copy link
Member

Hey, the intention of this go.mod file is that we will only ever bump the actual cosign version (e.g. https://github.com/runfinch/finch-core/blob/main/rootfs/cosign/go.mod#L5), not the indirect dependencies

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants