Skip to content

Bump github.com/sigstore/sigstore from 1.8.2 to 1.10.4#3480

Open
dependabot[bot] wants to merge 1 commit intomasterfrom
dependabot/go_modules/github.com/sigstore/sigstore-1.10.4
Open

Bump github.com/sigstore/sigstore from 1.8.2 to 1.10.4#3480
dependabot[bot] wants to merge 1 commit intomasterfrom
dependabot/go_modules/github.com/sigstore/sigstore-1.10.4

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot bot commented on behalf of github Jan 22, 2026

Bumps github.com/sigstore/sigstore from 1.8.2 to 1.10.4.

Release notes

Sourced from github.com/sigstore/sigstore's releases.

v1.10.4

What's Changed

Full Changelog: sigstore/sigstore@v1.10.3...v1.10.4

v1.10.3

What's Changed

v1.10.3 adds ValidatePubKey back to the cryptoutils package to avoid a breaking API change.

Full Changelog: sigstore/sigstore@v1.10.2...v1.10.3

v1.10.2

Functionally equivalent to v1.10.0. v1.10.1 has been retracted to remove copied code.

v1.10.0

Breaking change

sigstore/sigstore#2194 moves cryptoutils.ValidatePubKey to goodkey.ValidatePubKey to minimize the dependency tree for clients using the cryptoutils package.

Features

Refactoring

v1.10.0

Breaking change

sigstore/sigstore#2194 moves cryptoutils.ValidatePubKey to goodkey.ValidatePubKey to minimize the dependency tree for clients using the cryptoutils package.

Features

Refactoring

... (truncated)

Commits
  • 8ec410a Escape target name - GHSA-fcv2-xgw5-pqxf (#2265)
  • deef0ee build(deps): Bump golang.org/x/crypto in /test/cliplugin/localkms (#2256)
  • 641406c build(deps): Bump the gomod group across 2 directories with 4 updates (#2255)
  • 1bfd00e build(deps): Bump the tools group across 1 directory with 2 updates (#2254)
  • 714ac99 build(deps): Bump hashicorp/vault in /test/e2e in the all group (#2253)
  • 626b82b build(deps): Bump localstack/localstack in /test/e2e in the all group (#2241)
  • 72f0ed7 build(deps): Bump github.com/aws/aws-sdk-go-v2/config (#2230)
  • b257168 build(deps): Bump github.com/aws/aws-sdk-go-v2 in /pkg/signature/kms/aws (#2226)
  • 84f57b8 build(deps): Bump github.com/sigstore/sigstore (#2221)
  • bdc1a86 build(deps): Bump actions/checkout from 5.0.1 to 6.0.0 (#2220)
  • Additional commits viewable in compare view

Note
Automatic rebases have been disabled on this pull request as it has been open for over 30 days.

@dependabot dependabot bot added dependencies Pull requests that update a dependency file go Pull requests that update Go code labels Jan 22, 2026
@chrisnovakovic
Copy link
Copy Markdown
Contributor

@dependabot rebase

Bumps [github.com/sigstore/sigstore](https://github.com/sigstore/sigstore) from 1.8.2 to 1.10.4.
- [Release notes](https://github.com/sigstore/sigstore/releases)
- [Commits](sigstore/sigstore@v1.8.2...v1.10.4)

---
updated-dependencies:
- dependency-name: github.com/sigstore/sigstore
  dependency-version: 1.10.4
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot force-pushed the dependabot/go_modules/github.com/sigstore/sigstore-1.10.4 branch from b2bed94 to 20a83c5 Compare April 15, 2026 16:50
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file go Pull requests that update Go code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant