Closed renovate[bot] closed 3 months ago
[!CAUTION]
Review failed
The pull request is closed.
The updates involve a version increment of the cosign-installer
action from v3.5.0
to v3.6.0
in two GitHub Actions workflow files: release.yml
and verify.yml
. This change aims to leverage improvements and potential fixes in the latest version of the action, enhancing the installation process of the cosign
tool within the workflows. No other logic or control flow adjustments were made in these files.
Files | Change Summary |
---|---|
.github/workflows/release.yml |
Updated cosign-installer action from v3.5.0 to v3.6.0 . |
.github/workflows/verify.yml |
Updated cosign-installer action from v3.5.0 to v3.6.0 . |
Thank you for using CodeRabbit. We offer it for free to the OSS community and would appreciate your support in helping us grow. If you find it useful, would you consider giving us a shout-out on your favorite social media?
This PR contains the following updates:
v3.5.0
->v3.6.0
Release Notes
sigstore/cosign-installer (sigstore/cosign-installer)
### [`v3.6.0`](https://togithub.com/sigstore/cosign-installer/releases/tag/v3.6.0) [Compare Source](https://togithub.com/sigstore/cosign-installer/compare/v3.5.0...v3.6.0) #### What's Changed - Bump actions/checkout from 4.1.2 to 4.1.3 by [@dependabot](https://togithub.com/dependabot) in [https://github.com/sigstore/cosign-installer/pull/161](https://togithub.com/sigstore/cosign-installer/pull/161) - Bump actions/checkout from 4.1.3 to 4.1.4 by [@dependabot](https://togithub.com/dependabot) in [https://github.com/sigstore/cosign-installer/pull/162](https://togithub.com/sigstore/cosign-installer/pull/162) - Bump actions/setup-go from 5.0.0 to 5.0.1 by [@dependabot](https://togithub.com/dependabot) in [https://github.com/sigstore/cosign-installer/pull/163](https://togithub.com/sigstore/cosign-installer/pull/163) - Bump actions/checkout from 4.1.4 to 4.1.5 by [@dependabot](https://togithub.com/dependabot) in [https://github.com/sigstore/cosign-installer/pull/164](https://togithub.com/sigstore/cosign-installer/pull/164) - Bump actions/checkout from 4.1.5 to 4.1.6 by [@dependabot](https://togithub.com/dependabot) in [https://github.com/sigstore/cosign-installer/pull/165](https://togithub.com/sigstore/cosign-installer/pull/165) - Bump actions/checkout from 4.1.6 to 4.1.7 by [@dependabot](https://togithub.com/dependabot) in [https://github.com/sigstore/cosign-installer/pull/166](https://togithub.com/sigstore/cosign-installer/pull/166) - Bump actions/setup-go from 5.0.1 to 5.0.2 by [@dependabot](https://togithub.com/dependabot) in [https://github.com/sigstore/cosign-installer/pull/167](https://togithub.com/sigstore/cosign-installer/pull/167) - pin public key used for verification by [@bobcallaway](https://togithub.com/bobcallaway) in [https://github.com/sigstore/cosign-installer/pull/169](https://togithub.com/sigstore/cosign-installer/pull/169) - bump default version to v2.4.0 release by [@bobcallaway](https://togithub.com/bobcallaway) in [https://github.com/sigstore/cosign-installer/pull/168](https://togithub.com/sigstore/cosign-installer/pull/168) - update readme for new release by [@bobcallaway](https://togithub.com/bobcallaway) in [https://github.com/sigstore/cosign-installer/pull/170](https://togithub.com/sigstore/cosign-installer/pull/170) **Full Changelog**: https://github.com/sigstore/cosign-installer/compare/v3...v3.6.0Configuration
📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.