Skip to content

Update sigstore/cosign-installer action to v4#1650

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/sigstore-cosign-installer-4.x
Open

Update sigstore/cosign-installer action to v4#1650
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/sigstore-cosign-installer-4.x

Conversation

@renovate
Copy link
Copy Markdown
Contributor

@renovate renovate Bot commented Apr 19, 2026

This PR contains the following updates:

Package Type Update Change
sigstore/cosign-installer action major v3v4.1.2

Release Notes

sigstore/cosign-installer (sigstore/cosign-installer)

v4.1.2

Compare Source

What's Changed

v4.1.1

Compare Source

What's Changed

  • chore: update default cosign-release to v3.0.5 in #​223

Full Changelog: sigstore/cosign-installer@v4.1.0...v4.1.1

v4.1.0

Compare Source

What's Changed

We recommend updating as soon as possible as this includes bug fixes for Cosign. We also recommend removing with: cosign-release and strongly discourage using cosign-release unless you have a specific reason to use an older version of Cosign.

  • Bump cosign to 3.0.5 in #​220
  • fix: add retry to curl downloads for transient network failures in #​210

Full Changelog: sigstore/cosign-installer@v4.0.0...v4.1.0

v4.0.0

Compare Source

What's Changed?

Note: You must upgrade to cosign-installer v4 if you want to install Cosign v3+. You may still install Cosign v2.x with cosign-installer v4.

In version v3+, using cosign sign-blob requires adding the --bundle flag which may require you to update your signing command.

  • Add support for Cosign v3 releases (#​201)

v3.10.1

Compare Source

What's Changed?

Note: cosign-installer v3.x cannot be used to install Cosign v3.x. You must upgrade to cosign-installer v4 in order to use Cosign v3.

Note: This is planned to be the final release of Cosign v2, though we will cut new releases for any critical security or bug fixes. We recommend transitioning to Cosign v3.

  • Bump default Cosign to v2.6.1 (#​203)

v3.10.0

Compare Source

What's Changed

  • Bump default Cosign to v2.6.0 in #​200

Full Changelog: sigstore/cosign-installer@v3.9.2...v3.10.0

v3.9.2

Compare Source

What's Changed

  • not fail fast and setup permissions in #​195
  • drop old unsupported versions <v2.0.0 in #​192
  • Update default to v2.5.3 in #​196

Full Changelog: sigstore/cosign-installer@v3.9.1...v3.9.2

v3.9.1

Compare Source

What's Changed

Full Changelog: sigstore/cosign-installer@v3.9.0...v3.9.1

v3.9.0

Compare Source

What's Changed

Full Changelog: sigstore/cosign-installer@v3...v3.9.0

v3.8.2

Compare Source

What's Changed

  • install cosign v2 from main in #​186

Full Changelog: sigstore/cosign-installer@v3...v3.8.2

v3.8.1

Compare Source

What's Changed

Full Changelog: sigstore/cosign-installer@v3...v3.8.1

v3.8.0

Compare Source

What's Changed

Full Changelog: sigstore/cosign-installer@v3...v3.8.0

v3.7.0

Compare Source

What's Changed

Full Changelog: sigstore/cosign-installer@v3.6.0...v3.7.0

v3.6.0

Compare Source

What's Changed

Full Changelog: sigstore/cosign-installer@v3...v3.6.0

v3.5.0

Compare Source

What's Changed

Full Changelog: sigstore/cosign-installer@v3.4.0...v3.5.0

v3.4.0

Compare Source

What's Changed

New Contributors

Full Changelog: sigstore/cosign-installer@v3...v3.4.0

v3.3.0

Compare Source

What's Changed

Full Changelog: sigstore/cosign-installer@v3.2.0...v3.3.0

v3.2.0

Compare Source

Note: This release comes with a fix for CVE-2023-46737 described in this Github Security Advisory. Please upgrade to this release ASAP

see https://github.com/sigstore/cosign/releases/tag/v2.2.1

What's Changed

New Contributors

Full Changelog: sigstore/cosign-installer@v3...v3.2.0

v3.1.2

Compare Source

What's Changed

New Contributors

Full Changelog: sigstore/cosign-installer@v3...v3.1.2

v3.1.1

Compare Source

What's Changed

Full Changelog: sigstore/cosign-installer@v3.1.0...v3.1.1

v3.1.0

Compare Source

What's Changed

New Contributors

Full Changelog: sigstore/cosign-installer@v3.0.5...v3.1.0

v3.0.5

Compare Source

What's Changed

Full Changelog: sigstore/cosign-installer@v3.0.4...v3.0.5

v3.0.4

Compare Source

  • Include fix for #​124
  • changes download URL for cosign binary to github.com instead of GCS

v3.0.3

Compare Source

What's Changed

  • bump to cosign v2.0.2 by @​bobcallaway in #​119
  • changes download URL for cosign binary to github.com instead of GCS

Full Changelog: sigstore/cosign-installer@v3.0.2...v3.0.3

v3.0.2

Compare Source

What's Changed

New Contributors

Full Changelog: sigstore/cosign-installer@v3...v3.0.2

v3.0.1

Compare Source

What's Changed

  • make cosign v2.0.0 default version by @​developer-guy in #​109
  • changes download URL for cosign binary to github.com instead of GCS

Full Changelog: sigstore/cosign-installer@v3.0.0...v3.0.1


Configuration

📅 Schedule: (in timezone Europe/Budapest)

  • Branch creation
    • Only on Sunday and Saturday (* * * * 0,6)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update Github_actions code labels Apr 19, 2026
@codecov
Copy link
Copy Markdown

codecov Bot commented Apr 19, 2026

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 93.37%. Comparing base (a077ac9) to head (6146b8b).
⚠️ Report is 6 commits behind head on main.

Additional details and impacted files
@@           Coverage Diff           @@
##             main    #1650   +/-   ##
=======================================
  Coverage   93.37%   93.37%           
=======================================
  Files          76       76           
  Lines        2386     2386           
  Branches      183      183           
=======================================
  Hits         2228     2228           
  Misses        132      132           
  Partials       26       26           

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@renovate renovate Bot changed the title Update sigstore/cosign-installer action to v4 Update sigstore/cosign-installer action to v4 - autoclosed Apr 19, 2026
@renovate renovate Bot closed this Apr 19, 2026
@renovate renovate Bot deleted the renovate/sigstore-cosign-installer-4.x branch April 19, 2026 12:58
@renovate renovate Bot changed the title Update sigstore/cosign-installer action to v4 - autoclosed Update sigstore/cosign-installer action to v4 Apr 24, 2026
@renovate renovate Bot reopened this Apr 24, 2026
@renovate renovate Bot force-pushed the renovate/sigstore-cosign-installer-4.x branch 3 times, most recently from f9af1bd to 8c4bced Compare April 29, 2026 13:14
@renovate renovate Bot force-pushed the renovate/sigstore-cosign-installer-4.x branch 2 times, most recently from 681ae64 to 1281c94 Compare May 12, 2026 11:49
@renovate renovate Bot force-pushed the renovate/sigstore-cosign-installer-4.x branch from 1281c94 to 6146b8b Compare May 22, 2026 19:51
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update Github_actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants