API: models.Bundle.BundleType is now a public API
(#1089)
CLI: The sigstore plumbing subcommand hierarchy has been added. This
hierarchy is for developer-only interactions, such as fixing malformed
Sigstore bundles. These subcommands are not considered stable until
explicitly documented as such.
(#1089)
Changed
CLI: The default console logger now emits to stderr, rather than stdout
(#1089)
API: models.Bundle.BundleType is now a public API
(#1089)
CLI: The sigstore plumbing subcommand hierarchy has been added. This
hierarchy is for developer-only interactions, such as fixing malformed
Sigstore bundles. These subcommands are not considered stable until
explicitly documented as such.
(#1089)
Changed
CLI: The default console logger now emits to stderr, rather than stdout
(#1089)
[3.1.0]
Added
API: dsse.StatementBuilder has been added. It can be used to construct an
in-toto Statement for subsequent enveloping and signing.
This API is public but is not considered stable until the next major
release.
(#1077)
API: dsse.Digest, dsse.DigestSet, and dsse.Subject have been added.
These types can be used with the StatementBuilder API as part of in-toto
Statement construction.
These API are public but are not considered stable until the next major
release.
(#1078)
Changed
API: verify_dsse now rejects bundles with DSSE envelopes that have more than
one signature, rather than checking all signatures against the same key
(#1062)
[3.0.0]
Maintainers' note: this is a major release, with significant public API and CLI
changes. We strongly recommend you read the entries below to fully
understand the changes between 2.x and 3.x.
Added
API: Signer.sign_artifact() has been added, replacing the removed
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot squash and merge` will squash and merge this PR after your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge and block automerging
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
- `@dependabot show ignore conditions` will show all of the ignore conditions of the specified dependency
- `@dependabot ignore major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
- `@dependabot ignore minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
- `@dependabot ignore ` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
- `@dependabot unignore ` will remove all of the ignore conditions of the specified dependency
- `@dependabot unignore ` will remove the ignore condition of the specified dependency and ignore conditions
Updates the requirements on sigstore to permit the latest version. Updates
sigstore
to 3.2.0Release notes
Sourced from sigstore's releases.
Changelog
Sourced from sigstore's changelog.
... (truncated)
Commits
fc29ec1
prep 3.2.0 (#1094)a966b3e
addfix-bundle
plumbing command (#1089)93e3c5b
build(deps): update ruff requirement from <0.6.1 to <0.6.2 (#1093)b193d67
build(deps): update ruff requirement from <0.5.8 to <0.6.1 (#1092)b3e707f
build(deps): bump github/codeql-action from 3.26.0 to 3.26.2 in the actions g...dcba009
build(deps): update ruff requirement from <0.5.7 to <0.5.8 (#1090)e6270b8
build(deps): bump actions/upload-artifact from 4.3.5 to 4.3.6 in /.github/act...5ab49d7
build(deps): bump the actions group with 2 updates (#1086)19b74c9
build(deps): bump actions/upload-artifact from 4.3.4 to 4.3.5 in /.github/act...54ee6cf
build(deps): update ruff requirement from <0.5.6 to <0.5.7 (#1084)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase
.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot show