Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Bump github.com/slsa-framework/slsa-verifier/v2 from 2.5.1 to 2.6.0 i…
…n /tooling (#3830) Bumps [github.com/slsa-framework/slsa-verifier/v2](https://github.com/slsa-framework/slsa-verifier) from 2.5.1 to 2.6.0. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/slsa-framework/slsa-verifier/releases">github.com/slsa-framework/slsa-verifier/v2's releases</a>.</em></p> <blockquote> <h2>v2.6.0</h2> <h2>What's Changed</h2> <ul> <li>chore: Update doc and digests for v2.5.1 by <a href="https://github.com/laurentsimon"><code>@â��laurentsimon</code></a> in <a href="https://redirect.github.com/slsa-framework/slsa-verifier/pull/748">slsa-framework/slsa-verifier#748</a></li> <li>fix(deps): update module google.golang.org/protobuf to v1.33.0 [security] by <a href="https://github.com/renovate-bot"><code>@â��renovate-bot</code></a> in <a href="https://redirect.github.com/slsa-framework/slsa-verifier/pull/743">slsa-framework/slsa-verifier#743</a></li> <li>fix(deps): update dependency org.apache.maven:maven-core to v3.9.6 by <a href="https://github.com/renovate-bot"><code>@â��renovate-bot</code></a> in <a href="https://redirect.github.com/slsa-framework/slsa-verifier/pull/718">slsa-framework/slsa-verifier#718</a></li> <li>chore: Update <code>@â��actions/github</code> v6 by <a href="https://github.com/laurentsimon"><code>@â��laurentsimon</code></a> in <a href="https://redirect.github.com/slsa-framework/slsa-verifier/pull/749">slsa-framework/slsa-verifier#749</a></li> <li>fix: use sigstore/pkg/fulcioroots to lessen deps by <a href="https://github.com/ramonpetgrave64"><code>@â��ramonpetgrave64</code></a> in <a href="https://redirect.github.com/slsa-framework/slsa-verifier/pull/746">slsa-framework/slsa-verifier#746</a></li> <li>feat: add ramonpetgrave64 as CODEOWNER by <a href="https://github.com/ramonpetgrave64"><code>@â��ramonpetgrave64</code></a> in <a href="https://redirect.github.com/slsa-framework/slsa-verifier/pull/750">slsa-framework/slsa-verifier#750</a></li> <li>chore(deps): update gcr.io/distroless/base:nonroot docker digest to 1a8ece8 by <a href="https://github.com/renovate-bot"><code>@â��renovate-bot</code></a> in <a href="https://redirect.github.com/slsa-framework/slsa-verifier/pull/701">slsa-framework/slsa-verifier#701</a></li> <li>chore(deps): update github-actions (major) by <a href="https://github.com/renovate-bot"><code>@â��renovate-bot</code></a> in <a href="https://redirect.github.com/slsa-framework/slsa-verifier/pull/719">slsa-framework/slsa-verifier#719</a></li> <li>fix(deps): update dependency org.apache.maven:maven-plugin-api to v3.9.6 by <a href="https://github.com/renovate-bot"><code>@â��renovate-bot</code></a> in <a href="https://redirect.github.com/slsa-framework/slsa-verifier/pull/751">slsa-framework/slsa-verifier#751</a></li> <li>chore(deps): update npm dev (major) by <a href="https://github.com/ramonpetgrave64"><code>@â��ramonpetgrave64</code></a> in <a href="https://redirect.github.com/slsa-framework/slsa-verifier/pull/753">slsa-framework/slsa-verifier#753</a></li> <li>fix(deps): update dependency org.apache.maven.plugin-tools:maven-plugin-annotations to v3.11.0 by <a href="https://github.com/renovate-bot"><code>@â��renovate-bot</code></a> in <a href="https://redirect.github.com/slsa-framework/slsa-verifier/pull/752">slsa-framework/slsa-verifier#752</a></li> <li>feat: fixes <a href="https://redirect.github.com/slsa-framework/slsa-verifier/issues/547">#547</a>: add npm sigstore-tuf suport by <a href="https://github.com/ramonpetgrave64"><code>@â��ramonpetgrave64</code></a> in <a href="https://redirect.github.com/slsa-framework/slsa-verifier/pull/731">slsa-framework/slsa-verifier#731</a></li> <li>fix(deps): update module github.com/sigstore/cosign/v2 to v2.2.4 [security] by <a href="https://github.com/renovate-bot"><code>@â��renovate-bot</code></a> in <a href="https://redirect.github.com/slsa-framework/slsa-verifier/pull/723">slsa-framework/slsa-verifier#723</a></li> <li>chore(deps): update golang:1.21 docker digest to 81811f8 by <a href="https://github.com/renovate-bot"><code>@â��renovate-bot</code></a> in <a href="https://redirect.github.com/slsa-framework/slsa-verifier/pull/693">slsa-framework/slsa-verifier#693</a></li> <li>chore: slsa-framework/[email protected]: add testdata by <a href="https://github.com/ramonpetgrave64"><code>@â��ramonpetgrave64</code></a> in <a href="https://redirect.github.com/slsa-framework/slsa-verifier/pull/758">slsa-framework/slsa-verifier#758</a></li> <li>chore(deps): update golang:1.21 docker digest to d83472f by <a href="https://github.com/renovate-bot"><code>@â��renovate-bot</code></a> in <a href="https://redirect.github.com/slsa-framework/slsa-verifier/pull/764">slsa-framework/slsa-verifier#764</a></li> <li>chore(deps): update gcr.io/distroless/base:nonroot docker digest to 53745e9 by <a href="https://github.com/renovate-bot"><code>@â��renovate-bot</code></a> in <a href="https://redirect.github.com/slsa-framework/slsa-verifier/pull/763">slsa-framework/slsa-verifier#763</a></li> <li>feat: workflow to update actions dist by <a href="https://github.com/ramonpetgrave64"><code>@â��ramonpetgrave64</code></a> in <a href="https://redirect.github.com/slsa-framework/slsa-verifier/pull/760">slsa-framework/slsa-verifier#760</a></li> <li>fix(deps): update dependency <code>@â��actions/core</code> to v1.10.1 by <a href="https://github.com/renovate-bot"><code>@â��renovate-bot</code></a> in <a href="https://redirect.github.com/slsa-framework/slsa-verifier/pull/717">slsa-framework/slsa-verifier#717</a></li> <li>chore: fix pr-title-checker by <a href="https://github.com/ianlewis"><code>@â��ianlewis</code></a> in <a href="https://redirect.github.com/slsa-framework/slsa-verifier/pull/770">slsa-framework/slsa-verifier#770</a></li> <li>chore: Update Renovate config by <a href="https://github.com/ianlewis"><code>@â��ianlewis</code></a> in <a href="https://redirect.github.com/slsa-framework/slsa-verifier/pull/769">slsa-framework/slsa-verifier#769</a></li> <li>fix: use pr_number as env variable by <a href="https://github.com/ramonpetgrave64"><code>@â��ramonpetgrave64</code></a> in <a href="https://redirect.github.com/slsa-framework/slsa-verifier/pull/771">slsa-framework/slsa-verifier#771</a></li> <li>fix: signoff commit by <a href="https://github.com/ramonpetgrave64"><code>@â��ramonpetgrave64</code></a> in <a href="https://redirect.github.com/slsa-framework/slsa-verifier/pull/767">slsa-framework/slsa-verifier#767</a></li> <li>chore(deps): bump golang.org/x/net from 0.22.0 to 0.23.0 by <a href="https://github.com/dependabot"><code>@â��dependabot</code></a> in <a href="https://redirect.github.com/slsa-framework/slsa-verifier/pull/781">slsa-framework/slsa-verifier#781</a></li> <li>chore(deps): bump github.com/hashicorp/go-retryablehttp from 0.7.5 to 0.7.7 by <a href="https://github.com/dependabot"><code>@â��dependabot</code></a> in <a href="https://redirect.github.com/slsa-framework/slsa-verifier/pull/782">slsa-framework/slsa-verifier#782</a></li> <li>chore(deps): bump undici from 5.28.3 to 5.28.4 in /actions/installer by <a href="https://github.com/dependabot"><code>@â��dependabot</code></a> in <a href="https://redirect.github.com/slsa-framework/slsa-verifier/pull/779">slsa-framework/slsa-verifier#779</a></li> <li>chore(deps-dev): bump braces from 3.0.2 to 3.0.3 in /actions/installer by <a href="https://github.com/dependabot"><code>@â��dependabot</code></a> in <a href="https://redirect.github.com/slsa-framework/slsa-verifier/pull/780">slsa-framework/slsa-verifier#780</a></li> <li>chore(deps): bump the npm_and_yarn group across 2 directories with 2 updates by <a href="https://github.com/dependabot"><code>@â��dependabot</code></a> in <a href="https://redirect.github.com/slsa-framework/slsa-verifier/pull/784">slsa-framework/slsa-verifier#784</a></li> <li>fix(deps): update golang.org/x/exp digest to 7f521ea by <a href="https://github.com/renovate-bot"><code>@â��renovate-bot</code></a> in <a href="https://redirect.github.com/slsa-framework/slsa-verifier/pull/775">slsa-framework/slsa-verifier#775</a></li> <li>fix: make download-artifacts.sh more flexible by <a href="https://github.com/ramonpetgrave64"><code>@â��ramonpetgrave64</code></a> in <a href="https://redirect.github.com/slsa-framework/slsa-verifier/pull/761">slsa-framework/slsa-verifier#761</a></li> <li>chore(deps): update golang:1.21 docker digest to b405b62 by <a href="https://github.com/renovate-bot"><code>@â��renovate-bot</code></a> in <a href="https://redirect.github.com/slsa-framework/slsa-verifier/pull/774">slsa-framework/slsa-verifier#774</a></li> <li>chore(deps): update npm dev by <a href="https://github.com/renovate-bot"><code>@â��renovate-bot</code></a> in <a href="https://redirect.github.com/slsa-framework/slsa-verifier/pull/650">slsa-framework/slsa-verifier#650</a></li> <li>fix(deps): update dependency org.apache.maven:maven-core to v3.9.8 by <a href="https://github.com/renovate-bot"><code>@â��renovate-bot</code></a> in <a href="https://redirect.github.com/slsa-framework/slsa-verifier/pull/787">slsa-framework/slsa-verifier#787</a></li> <li>chore(deps): update github-actions by <a href="https://github.com/renovate-bot"><code>@â��renovate-bot</code></a> in <a href="https://redirect.github.com/slsa-framework/slsa-verifier/pull/786">slsa-framework/slsa-verifier#786</a></li> <li>feat: vsa support by <a href="https://github.com/ramonpetgrave64"><code>@â��ramonpetgrave64</code></a> in <a href="https://redirect.github.com/slsa-framework/slsa-verifier/pull/777">slsa-framework/slsa-verifier#777</a></li> <li>fix: use tag for the builder in the release workflow by <a href="https://github.com/ramonpetgrave64"><code>@â��ramonpetgrave64</code></a> in <a href="https://redirect.github.com/slsa-framework/slsa-verifier/pull/788">slsa-framework/slsa-verifier#788</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/slsa-framework/slsa-verifier/compare/v2.5.1...v2.6.0">https://github.com/slsa-framework/slsa-verifier/compare/v2.5.1...v2.6.0</a></p> <h2>v2.6.0-rc.1</h2> <p><strong>This is a pre-release. DO NOT install</strong></p> <h2>What's Changed</h2> <ul> <li>chore: Update doc and digests for v2.5.1 by <a href="https://github.com/laurentsimon"><code>@â��laurentsimon</code></a> in <a href="https://redirect.github.com/slsa-framework/slsa-verifier/pull/748">slsa-framework/slsa-verifier#748</a></li> <li>fix(deps): update module google.golang.org/protobuf to v1.33.0 [security] by <a href="https://github.com/renovate-bot"><code>@â��renovate-bot</code></a> in <a href="https://redirect.github.com/slsa-framework/slsa-verifier/pull/743">slsa-framework/slsa-verifier#743</a></li> <li>fix(deps): update dependency org.apache.maven:maven-core to v3.9.6 by <a href="https://github.com/renovate-bot"><code>@â��renovate-bot</code></a> in <a href="https://redirect.github.com/slsa-framework/slsa-verifier/pull/718">slsa-framework/slsa-verifier#718</a></li> <li>chore: Update <code>@â��actions/github</code> v6 by <a href="https://github.com/laurentsimon"><code>@â��laurentsimon</code></a> in <a href="https://redirect.github.com/slsa-framework/slsa-verifier/pull/749">slsa-framework/slsa-verifier#749</a></li> </ul> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/slsa-framework/slsa-verifier/commit/3714a2a4684014deb874a0e737dffa0ee02dd647"><code>3714a2a</code></a> fix: use tag for the builder in the release workflow (<a href="https://redirect.github.com/slsa-framework/slsa-verifier/issues/788">#788</a>)</li> <li><a href="https://github.com/slsa-framework/slsa-verifier/commit/208ac12589fb119e1d15661af960c131e8fc9f47"><code>208ac12</code></a> feat: vsa support (<a href="https://redirect.github.com/slsa-framework/slsa-verifier/issues/777">#777</a>)</li> <li><a href="https://github.com/slsa-framework/slsa-verifier/commit/1049da48419ca600ee73c2103db33918d9f5c368"><code>1049da4</code></a> chore(deps): update github-actions (<a href="https://redirect.github.com/slsa-framework/slsa-verifier/issues/786">#786</a>)</li> <li><a href="https://github.com/slsa-framework/slsa-verifier/commit/903cddc5c33e1642e240ecc06f7872c7dd92baed"><code>903cddc</code></a> fix(deps): update dependency org.apache.maven:maven-core to v3.9.8 (<a href="https://redirect.github.com/slsa-framework/slsa-verifier/issues/787">#787</a>)</li> <li><a href="https://github.com/slsa-framework/slsa-verifier/commit/4bab78a528bb08e847fa3bf648ead7417306e6c1"><code>4bab78a</code></a> chore(deps): update npm dev (<a href="https://redirect.github.com/slsa-framework/slsa-verifier/issues/650">#650</a>)</li> <li><a href="https://github.com/slsa-framework/slsa-verifier/commit/163abe52e295ab4e02bed3204a3b81203ebd82d7"><code>163abe5</code></a> chore(deps): update golang:1.21 docker digest to b405b62 (<a href="https://redirect.github.com/slsa-framework/slsa-verifier/issues/774">#774</a>)</li> <li><a href="https://github.com/slsa-framework/slsa-verifier/commit/2f70fef663b1143bf50d461680c6ac4a97b73af3"><code>2f70fef</code></a> fix: make download-artifacts.sh more flexible (<a href="https://redirect.github.com/slsa-framework/slsa-verifier/issues/761">#761</a>)</li> <li><a href="https://github.com/slsa-framework/slsa-verifier/commit/b69efeea0bc4809d8fca48d01a1af6b29d35bf9b"><code>b69efee</code></a> fix(deps): update golang.org/x/exp digest to 7f521ea (<a href="https://redirect.github.com/slsa-framework/slsa-verifier/issues/775">#775</a>)</li> <li><a href="https://github.com/slsa-framework/slsa-verifier/commit/34ab20367861aadacf33ecd19aa46bbf02b27b91"><code>34ab203</code></a> chore(deps): bump the npm_and_yarn group across 2 directories with 2 updates ...</li> <li><a href="https://github.com/slsa-framework/slsa-verifier/commit/9fb6f246f8057c33be53d7ba2bf3a4f4cef450c5"><code>9fb6f24</code></a> chore(deps-dev): bump braces from 3.0.2 to 3.0.3 in /actions/installer (<a href="https://redirect.github.com/slsa-framework/slsa-verifier/issues/780">#780</a>)</li> <li>Additional commits viewable in <a href="https://github.com/slsa-framework/slsa-verifier/compare/v2.5.1...v2.6.0">compare view</a></li> </ul> </details> <br /> [![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=github.com/slsa-framework/slsa-verifier/v2&package-manager=go_modules&previous-version=2.5.1&new-version=2.6.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) </details>
- Loading branch information