theupdateframework / go-tuf

Go implementation of The Update Framework (TUF)
https://theupdateframework.com
Apache License 2.0
625 stars 105 forks source link

chore(deps): bump securesystemslib from 0.30.0 to 0.31.0 #570

Closed dependabot[bot] closed 10 months ago

dependabot[bot] commented 10 months ago

Bumps securesystemslib from 0.30.0 to 0.31.0.

Release notes

Sourced from securesystemslib's releases.

v0.31.0

See CHANGELOG.md for details.

Changelog

Sourced from securesystemslib's changelog.

securesystemslib v0.31.0

Added

  • CryptoSigner: create from cryptography private key with new constructor (#675)
  • SSlibKey: create from cryptography public key with new from_crypto method (#678)
  • Release: auto-release with PyPI Trusted Publishing (#683)
  • Docs to migrate legacy key files (#658)

Removed

  • Removed SSlibKey.from_pem factory method in favor of from_crypto (#678)
Commits
  • cc0ead6 Merge pull request #684 from lukpueh/release-0.31.0
  • 833ba65 Merge pull request #685 from secure-systems-lab/dependabot/github_actions/pyp...
  • 3297f3d build(deps): bump pypa/gh-action-pypi-publish from 1.8.10 to 1.8.11
  • 2bb771a Release securesystemslib v0.31.0
  • cc5521a Merge pull request #681 from secure-systems-lab/dependabot/pip/cryptography-4...
  • e99a370 Merge pull request #682 from secure-systems-lab/dependabot/github_actions/goo...
  • 5f86ed9 Merge pull request #680 from secure-systems-lab/dependabot/pip/mypy-1.7.1
  • 6c6dae6 Merge pull request #654 from secure-systems-lab/dependabot/pip/coverage-7.3.2
  • f62f588 Merge pull request #683 from lukpueh/add-cd
  • 2c5a170 build: add cd GitHub workflow
  • Additional commits viewable in compare view


Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot show ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)