Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

chore(deps): bump github.com/sigstore/sigstore/pkg/signature/kms/hashivault from 1.8.1 to 1.8.7 #2800

Conversation

dependabot[bot]
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Jul 31, 2024

Bumps github.com/sigstore/sigstore/pkg/signature/kms/hashivault from 1.8.1 to 1.8.7.

Release notes

Sourced from github.com/sigstore/sigstore/pkg/signature/kms/hashivault's releases.

v1.8.7

Dependencies updates only

What's Changed

Full Changelog: sigstore/sigstore@v1.8.6...v1.8.7

v1.8.6

What's Changed

New Contributors

Full Changelog: sigstore/sigstore@v1.8.5...v1.8.6

v1.8.5

Major are dependencies updates

What's Changed

... (truncated)

Commits
  • cb8b4bb sync go mod
  • 2506e5d build(deps): Bump the all group across 1 directory with 4 updates
  • 9a70270 build(deps): Bump google.golang.org/grpc in /pkg/signature/kms/gcp
  • f6b4bb5 build(deps): Bump the all group in /pkg/signature/kms/gcp with 2 updates
  • aebd23d build(deps): Bump actions/upload-artifact in the all group
  • ec4bc1a build(deps): Bump the all group across 1 directory with 2 updates
  • aeb9782 build(deps): Bump golang.org/x/crypto
  • 016e2e3 build(deps): Bump github.com/sigstore/sigstore
  • 8243831 build(deps): Bump hashicorp/vault in /test/e2e in the all group
  • 51d791e build(deps): Bump the all group in /pkg/signature/kms/aws with 4 updates
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

@dependabot dependabot bot requested review from a team as code owners July 31, 2024 14:57
@dependabot dependabot bot added dependencies go Pull requests that update Go code labels Jul 31, 2024
@dependabot dependabot bot force-pushed the dependabot/go_modules/github.com/sigstore/sigstore/pkg/signature/kms/hashivault-1.8.7 branch 4 times, most recently from ce5346a to 2032e72 Compare August 1, 2024 09:38
…ivault

Bumps [github.com/sigstore/sigstore/pkg/signature/kms/hashivault](https://github.com/sigstore/sigstore) from 1.8.1 to 1.8.7.
- [Release notes](https://github.com/sigstore/sigstore/releases)
- [Commits](sigstore/sigstore@v1.8.1...v1.8.7)

---
updated-dependencies:
- dependency-name: github.com/sigstore/sigstore/pkg/signature/kms/hashivault
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot force-pushed the dependabot/go_modules/github.com/sigstore/sigstore/pkg/signature/kms/hashivault-1.8.7 branch from 2032e72 to ec3fa31 Compare August 1, 2024 18:44
Signed-off-by: schristoff <28318173+schristoff@users.noreply.github.com>
Copy link

codecov bot commented Aug 2, 2024

Codecov Report

All modified and coverable lines are covered by tests ✅

Signed-off-by: schristoff <28318173+schristoff@users.noreply.github.com>
@phillebaba phillebaba added this pull request to the merge queue Aug 2, 2024
Merged via the queue into main with commit dc08529 Aug 2, 2024
32 checks passed
@phillebaba phillebaba deleted the dependabot/go_modules/github.com/sigstore/sigstore/pkg/signature/kms/hashivault-1.8.7 branch August 2, 2024 08:01
chaospuppy pushed a commit to chaospuppy/zarf that referenced this pull request Aug 5, 2024
…ivault from 1.8.1 to 1.8.7 (zarf-dev#2800)

Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: schristoff <28318173+schristoff@users.noreply.github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: schristoff <28318173+schristoff@users.noreply.github.com>
Signed-off-by: Tim Seagren <timseagren@defenseunicorns.com>
chaospuppy pushed a commit to chaospuppy/zarf that referenced this pull request Aug 5, 2024
…ivault from 1.8.1 to 1.8.7 (zarf-dev#2800)

Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: schristoff <28318173+schristoff@users.noreply.github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: schristoff <28318173+schristoff@users.noreply.github.com>
Signed-off-by: Tim Seagren <timseagren@defenseunicorns.com>
chaospuppy pushed a commit to chaospuppy/zarf that referenced this pull request Aug 5, 2024
…ivault from 1.8.1 to 1.8.7 (zarf-dev#2800)

Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: schristoff <28318173+schristoff@users.noreply.github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: schristoff <28318173+schristoff@users.noreply.github.com>
Signed-off-by: Tim Seagren <timseagren@defenseunicorns.com>
mjnagel pushed a commit to defenseunicorns/uds-core that referenced this pull request Aug 9, 2024
[![Mend
Renovate](https://app.renovatebot.com/images/banner.svg)](https://renovatebot.com)

This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
| ghcr.io/zarf-dev/packages/init | minor | `v0.37.0` -> `v0.38.1` |
| [zarf-dev/zarf](https://github.com/zarf-dev/zarf) | minor |
`v0.37.0` -> `v0.38.1` |

---

### Release Notes

<details>
<summary>zarf-dev/zarf (zarf-dev/zarf)</summary>

###
[`v0.38.1`](https://github.com/zarf-dev/zarf/compare/v0.38.0...v0.38.1)

[Compare
Source](https://github.com/zarf-dev/zarf/compare/v0.38.0...v0.38.1)

### [`v0.38.0`](https://github.com/zarf-dev/zarf/releases/tag/v0.38.0)

[Compare
Source](https://github.com/zarf-dev/zarf/compare/v0.37.0...v0.38.0)

#### What's Changed

- refactor: utilize invopop comment feature by
[@&#8203;AustinAbro321](https://github.com/AustinAbro321) in
[zarf-dev/zarf#2781
- fix: detect invalid helm release names by
[@&#8203;jamestexas](https://github.com/jamestexas) in
[zarf-dev/zarf#2784
- refactor: move gitea code to separate package by
[@&#8203;phillebaba](https://github.com/phillebaba) in
[zarf-dev/zarf#2785
- fix: add dependabot and disable renovate features by
[@&#8203;AustinAbro321](https://github.com/AustinAbro321) in
[zarf-dev/zarf#2789
- chore(deps): bump github/codeql-action from 3.24.0 to 3.25.15 by
[@&#8203;dependabot](https://github.com/dependabot) in
[zarf-dev/zarf#2792
- chore(deps): bump actions/upload-artifact from 4.3.1 to 4.3.4 by
[@&#8203;dependabot](https://github.com/dependabot) in
[zarf-dev/zarf#2791
- chore(deps): bump golangci/golangci-lint-action from 6.0.1 to 6.1.0 by
[@&#8203;dependabot](https://github.com/dependabot) in
[zarf-dev/zarf#2793
- chore(deps): bump docker/login-action from 3.0.0 to 3.3.0 by
[@&#8203;dependabot](https://github.com/dependabot) in
[zarf-dev/zarf#2794
- chore(deps): bump ossf/scorecard-action from 2.3.1 to 2.4.0 by
[@&#8203;dependabot](https://github.com/dependabot) in
[zarf-dev/zarf#2795
- chore(deps): bump k8s.io/component-base from 0.30.0 to 0.30.3 by
[@&#8203;dependabot](https://github.com/dependabot) in
[zarf-dev/zarf#2798
- ci: remove unneeded cve checking by
[@&#8203;AustinAbro321](https://github.com/AustinAbro321) in
[zarf-dev/zarf#2802
- chore(deps): bump github.com/mikefarah/yq/v4 from 4.43.1 to 4.44.2 by
[@&#8203;dependabot](https://github.com/dependabot) in
[zarf-dev/zarf#2799
- chore(deps): bump codecov/codecov-action from 4.4.1 to 4.5.0 by
[@&#8203;dependabot](https://github.com/dependabot) in
[zarf-dev/zarf#2808
- chore(deps): bump actions/create-github-app-token from 1.9.0 to 1.10.3
by [@&#8203;dependabot](https://github.com/dependabot) in
[zarf-dev/zarf#2809
- chore(deps): bump actions/download-artifact from 4.1.2 to 4.1.8 by
[@&#8203;dependabot](https://github.com/dependabot) in
[zarf-dev/zarf#2810
- chore(deps): bump actions/checkout from 4.1.1 to 4.1.7 by
[@&#8203;dependabot](https://github.com/dependabot) in
[zarf-dev/zarf#2807
- chore(deps): bump golang.org/x/crypto from 0.24.0 to 0.25.0 by
[@&#8203;dependabot](https://github.com/dependabot) in
[zarf-dev/zarf#2813
- chore(deps): bump github.com/goccy/go-yaml from 1.11.3 to 1.12.0 by
[@&#8203;dependabot](https://github.com/dependabot) in
[zarf-dev/zarf#2811
- chore(deps): bump aws-actions/configure-aws-credentials from 4.0.1 to
4.0.2 by [@&#8203;dependabot](https://github.com/dependabot) in
[zarf-dev/zarf#2806
- fix: resolve CVE-2024-41110 by
[@&#8203;AustinAbro321](https://github.com/AustinAbro321) in
[zarf-dev/zarf#2815
- refactor: git package by
[@&#8203;phillebaba](https://github.com/phillebaba) in
[zarf-dev/zarf#2790
- ci: better named gh jobs by
[@&#8203;AustinAbro321](https://github.com/AustinAbro321) in
[zarf-dev/zarf#2816
- chore(deps): bump actions/dependency-review-action from 4.1.3 to 4.3.4
by [@&#8203;dependabot](https://github.com/dependabot) in
[zarf-dev/zarf#2822
- chore(deps): bump actions/setup-node from 4.0.2 to 4.0.3 by
[@&#8203;dependabot](https://github.com/dependabot) in
[zarf-dev/zarf#2821
- chore: move context.TODO to context.Background() (4) by
[@&#8203;schristoff](https://github.com/schristoff) in
[zarf-dev/zarf#2749
- chore(deps): bump
github.com/sigstore/sigstore/pkg/signature/kms/hashivault from 1.8.1 to
1.8.7 by [@&#8203;dependabot](https://github.com/dependabot) in
[zarf-dev/zarf#2800
- chore: turn down codecov by
[@&#8203;schristoff](https://github.com/schristoff) in
[zarf-dev/zarf#2823
- chore(deps): bump github.com/sigstore/sigstore/pkg/signature/kms/gcp
from 1.8.1 to 1.8.7 by
[@&#8203;dependabot](https://github.com/dependabot) in
[zarf-dev/zarf#2812
- refactor: move and test HasImages by
[@&#8203;phillebaba](https://github.com/phillebaba) in
[zarf-dev/zarf#2831
- fix: disk pressure flakes by
[@&#8203;AustinAbro321](https://github.com/AustinAbro321) in
[zarf-dev/zarf#2832
- chore(deps): bump actions/upload-artifact from 4.3.4 to 4.3.5 by
[@&#8203;dependabot](https://github.com/dependabot) in
[zarf-dev/zarf#2834
- refactor: change isInternal variables to functions by
[@&#8203;AustinAbro321](https://github.com/AustinAbro321) in
[zarf-dev/zarf#2768
- chore: update obsolete versions by
[@&#8203;AustinAbro321](https://github.com/AustinAbro321) in
[zarf-dev/zarf#2830
- refactor: init zarf state by
[@&#8203;AustinAbro321](https://github.com/AustinAbro321) in
[zarf-dev/zarf#2833
- fix: ignore config file not found errors by
[@&#8203;AustinAbro321](https://github.com/AustinAbro321) in
[zarf-dev/zarf#2838
- fix: override tunnel details with user-provided settings by
[@&#8203;chaospuppy](https://github.com/chaospuppy) in
[zarf-dev/zarf#2841
- refactor: move package generation to a local variable by
[@&#8203;phillebaba](https://github.com/phillebaba) in
[zarf-dev/zarf#2835
- feat: move ZarfPackageConfig to it's own api-versioned package by
[@&#8203;AustinAbro321](https://github.com/AustinAbro321) in
[zarf-dev/zarf#2801
- refactor: replace debug logs with returning errors by
[@&#8203;phillebaba](https://github.com/phillebaba) in
[zarf-dev/zarf#2777
- refactor: proxy and add tests by
[@&#8203;phillebaba](https://github.com/phillebaba) in
[zarf-dev/zarf#2843
- chore(deps): bump github/codeql-action from 3.25.15 to 3.26.0 by
[@&#8203;dependabot](https://github.com/dependabot) in
[zarf-dev/zarf#2848
- chore(deps): bump actions/upload-artifact from 4.3.5 to 4.3.6 by
[@&#8203;dependabot](https://github.com/dependabot) in
[zarf-dev/zarf#2847
- test: add tests for FindImages by
[@&#8203;phillebaba](https://github.com/phillebaba) in
[zarf-dev/zarf#2850
- test: unit test index sha by
[@&#8203;AustinAbro321](https://github.com/AustinAbro321) in
[zarf-dev/zarf#2844
- chore(deps): bump github.com/spf13/viper from 1.18.2 to 1.19.0 by
[@&#8203;dependabot](https://github.com/dependabot) in
[zarf-dev/zarf#2828
- chore: update dos games by
[@&#8203;AustinAbro321](https://github.com/AustinAbro321) in
[zarf-dev/zarf#2845
- chore(deps): bump sigs.k8s.io/kustomize/api from 0.16.0 to 0.17.3 by
[@&#8203;dependabot](https://github.com/dependabot) in
[zarf-dev/zarf#2826
- chore(deps): bump github.com/pterm/pterm from 0.12.78 to 0.12.79 by
[@&#8203;dependabot](https://github.com/dependabot) in
[zarf-dev/zarf#2854
- fix: install grype during release by
[@&#8203;phillebaba](https://github.com/phillebaba) in
[zarf-dev/zarf#2857
- fix: import paths to avoid cycle by
[@&#8203;phillebaba](https://github.com/phillebaba) in
[zarf-dev/zarf#2861

#### New Contributors

- [@&#8203;jamestexas](https://github.com/jamestexas) made their first
contribution in
[zarf-dev/zarf#2784

**Full Changelog**:
zarf-dev/zarf@v0.37.0...v0.38.0

</details>

---

### Configuration

📅 **Schedule**: Branch creation - At any time (no schedule defined),
Automerge - At any time (no schedule defined).

🚦 **Automerge**: Disabled by config. Please merge this manually once you
are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about these
updates again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR was generated by [Mend
Renovate](https://www.mend.io/free-developer-tools/renovate/). View the
[repository job
log](https://developer.mend.io/github/defenseunicorns/uds-core).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiIzNy40NDAuNyIsInVwZGF0ZWRJblZlciI6IjM4LjIwLjEiLCJ0YXJnZXRCcmFuY2giOiJtYWluIiwibGFiZWxzIjpbXX0=-->

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies go Pull requests that update Go code ready-for-review
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants