Skip to content

Bump github.com/sigstore/cosign/v3 from 3.1.2 to 3.1.3 - #726

Merged
zackbradys merged 1 commit into
mainfrom
dependabot/go_modules/main/github.com/sigstore/cosign/v3-3.1.3
Aug 10, 2026
Merged

Bump github.com/sigstore/cosign/v3 from 3.1.2 to 3.1.3#726
zackbradys merged 1 commit into
mainfrom
dependabot/go_modules/main/github.com/sigstore/cosign/v3-3.1.3

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 10, 2026

Copy link
Copy Markdown
Contributor

Bumps github.com/sigstore/cosign/v3 from 3.1.2 to 3.1.3.

Release notes

Sourced from github.com/sigstore/cosign/v3's releases.

v3.1.3

What's Changed

This release resolves GHSA-fx35-mq7g-6g98, a verification bypass using an unexpected public key in a legacy bundle.

Full Changelog: sigstore/cosign@v3.1.2...v3.1.3

Commits
  • 11926fa Verification bypass via public key in legacy bundle (GHSA-fx35-mq7g-6g98) (#5...
  • 4d589ba fix(blob): compare file checksums case-insensitively (#5036)
  • 83d9ec8 fix: prevent shell completions for various options not taking filenames (#5032)
  • 0238975 test(inspect): replace mock TSA client usage with local timestamp response ge...
  • d6d86c2 Supporting OCI Signing with X.509 Certificate Chain (#4614)
  • a3ee83c fix(pkcs11key): return an error instead of panicking when no key pair matches...
  • d6857f2 Auto-detect default digest algorithm for public keys (#5019)
  • See full diff in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [github.com/sigstore/cosign/v3](https://github.com/sigstore/cosign) from 3.1.2 to 3.1.3.
- [Release notes](https://github.com/sigstore/cosign/releases)
- [Changelog](https://github.com/sigstore/cosign/blob/main/CHANGELOG.md)
- [Commits](sigstore/cosign@v3.1.2...v3.1.3)

---
updated-dependencies:
- dependency-name: github.com/sigstore/cosign/v3
  dependency-version: 3.1.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file go Pull requests that update go code labels Aug 10, 2026
@github-project-automation github-project-automation Bot moved this to To Triage in Hauler Aug 10, 2026
@github-project-automation github-project-automation Bot moved this from To Triage to Testing in Hauler Aug 10, 2026
@zackbradys
zackbradys merged commit db79461 into main Aug 10, 2026
6 checks passed
@zackbradys
zackbradys deleted the dependabot/go_modules/main/github.com/sigstore/cosign/v3-3.1.3 branch August 10, 2026 14:07
@github-project-automation github-project-automation Bot moved this from Testing to Resolved in Hauler Aug 10, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file go Pull requests that update go code

Projects

Status: Resolved

Development

Successfully merging this pull request may close these issues.

1 participant