xeol-io / xeol

A scanner for end-of-life (EOL) software and dependencies in container images, filesystems, and SBOMs
https://www.xeol.io/
Apache License 2.0
348 stars 21 forks source link

Bump github.com/notaryproject/notation from 1.0.0 to 1.2.0 #401

Closed dependabot[bot] closed 2 months ago

dependabot[bot] commented 2 months ago

Bumps github.com/notaryproject/notation from 1.0.0 to 1.2.0.

Release notes

Sourced from github.com/notaryproject/notation's releases.

v1.2.0

Vote PASSED [+4 -0]: #1022

Notation v1.2.0

Notation v1.2.0 is an implementation of the Notary Project Specifications v1.1.0.

Key features

  • Support OCI image-spec v1.1.0 and distribution-spec v1.1.0

    • Introduced new flag --force-referrers-tag (default to true) to the notation sign command, which allows users opt to the referrers tag schema instead of the referrers API.
    • The notation verify / list / inspect commands always attempt the referrers API first, automatically falling back to the referrers tag schema if the referrers API is not supported by the registry.
  • Support for RFC 3161 compliant Timestamping

    • Introduced two new flags --timestamp-url and --timestamp-root-cert in notation sign command for signing with timestamping, see the notation sign CLI spec for more details.
    • Support a new trust store type tsa in notation certificate command.
    • Support RFC 3161 timestamp verification in the notation verify command with updated trust policy, see the notation verify CLI spec for more details.
    • Support RFC 3161 timestamp in notation inspect command's output.
  • Added support for armv7 binary release.

Other changes

  • Upgraded to Golang v1.23

Deprecation

What's changed since v1.2.0-rc.1

  • bump: release v1.2.0-rc.1 (#1017)
  • bump: bump up for v1.2.0 stable release (#1021)

Full Changelog: https://github.com/notaryproject/notation/compare/v1.2.0-rc.1...v1.2.0

v1.2.0-rc.1

Vote PASSED [+4 -0]: #1017

Changes

  1. Added support for armv7 binary release.
  2. Updated notation inspect command with RFC 3161 timestamp in the output.

What's Changed

... (truncated)

Commits
  • 4700ad6 bump: release v1.2.0
  • 8ad226c bump: bump up for v1.2.0 stable release (#1021)
  • c9490d6 Merge pull request #1017 from Two-Hearts/release-1.2
  • b806f58 bump: release v1.2.0-rc.1
  • 2c9f8a6 bump: bump up dependencies for release-1.2 (#1014)
  • 7933156 refactor!: remove blob sign/verify related contents (#1011)
  • 767d1e3 refactor: update verifier (#1002)
  • ed77da1 build(deps): Bump github/codeql-action from 3.25.13 to 3.25.15 (#1001)
  • 2814d7e build(deps): Bump ossf/scorecard-action from 2.3.3 to 2.4.0 (#1000)
  • 2b6f104 build(deps): Bump golang.org/x/net from 0.23.0 to 0.27.0 (#999)
  • Additional commits viewable in compare view


Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot show ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
dependabot[bot] commented 2 months ago

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.