Bump github.com/sigstore/cosign/v2 from 2.6.2 to 2.6.3#186
Bump github.com/sigstore/cosign/v2 from 2.6.2 to 2.6.3#186dependabot[bot] wants to merge 1 commit intomainfrom
Conversation
Bumps [github.com/sigstore/cosign/v2](https://github.com/sigstore/cosign) from 2.6.2 to 2.6.3. - [Release notes](https://github.com/sigstore/cosign/releases) - [Changelog](https://github.com/sigstore/cosign/blob/main/CHANGELOG.md) - [Commits](sigstore/cosign@v2.6.2...v2.6.3) --- updated-dependencies: - dependency-name: github.com/sigstore/cosign/v2 dependency-version: 2.6.3 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com>
Kusari Analysis Results:
Both dependency and code security analyses independently recommend proceeding with this PR. The update bumps github.com/sigstore/cosign/v2 from v2.6.2 to v2.6.3. A pre-existing LOW-severity CVE (CVE-2026-24122, CVSS AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N, EPSS 0.029%) exists in both the old and new versions, meaning this PR neither introduces nor worsens any known security exposure, and no fix is currently available. The dependency is healthy, actively maintained, and Apache-2.0 licensed. Code analysis of the modified files (go.mod, go.sum) returned zero findings across all severity levels, with no secrets, no workflow issues, and govulncheck reporting no vulnerabilities. The combined risk profile remains low, and merging this minor version update is the best available action. Note View full detailed analysis result for more information on the output and the checks that were run.
Found this helpful? Give it a 👍 or 👎 reaction! |
|
@kusari-inspector rerun |
|
🔄 Run triggered at 21:56:49 UTC. Starting fresh analysis... |
|
@kusari-inspector rerun |
|
🔄 Run triggered at 22:01:44 UTC. Starting fresh analysis... |
|
Kusari PR Analysis rerun based on - 073a0e6 performed at: 2026-04-13T22:02:46Z - link to updated analysis |
Bumps github.com/sigstore/cosign/v2 from 2.6.2 to 2.6.3.
Release notes
Sourced from github.com/sigstore/cosign/v2's releases.
Changelog
Sourced from github.com/sigstore/cosign/v2's changelog.
Commits
fecddd3Fix DSSE predicate check (#4802)564c5b1Backport bundle detection to sign and attest (#4727)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)