Skip to content

chore(deps): bump sigstore-verify from 0.6.6 to 0.8.0 - #9378

Merged
jamadeo merged 1 commit into
mainfrom
dependabot/cargo/sigstore-verify-0.8.0
May 22, 2026
Merged

chore(deps): bump sigstore-verify from 0.6.6 to 0.8.0#9378
jamadeo merged 1 commit into
mainfrom
dependabot/cargo/sigstore-verify-0.8.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github May 22, 2026

Copy link
Copy Markdown
Contributor

Bumps sigstore-verify from 0.6.6 to 0.8.0.

Release notes

Sourced from sigstore-verify's releases.

sigstore-verify-v0.8.0

Other

  • Replace direct chrono usage with jiff (#90)

sigstore-verify-v0.7.0

Added

  • support for GitHub's artifact attestation Sigstore instance (#88)
  • VerificationPolicy::skip_sct() builder method to skip Signed Certificate Timestamp verification (needed for trust domains whose certificates do not carry public Sigstore CT SCTs)

Changed

  • BREAKING: VerificationPolicy gained a new public field verify_sct: bool (defaults to true). Code that constructs VerificationPolicy via struct literal must add this field; users of Default::default() and the builder methods are unaffected.
  • BREAKING: SCT verification is now controlled independently by verify_sct rather than implicitly gated on verify_certificate. skip_certificate_chain() continues to disable both.
Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [sigstore-verify](https://github.com/prefix-dev/sigstore-rust) from 0.6.6 to 0.8.0.
- [Release notes](https://github.com/prefix-dev/sigstore-rust/releases)
- [Changelog](https://github.com/sigstore/sigstore-rust/blob/main/release-plz.toml)
- [Commits](sigstore/sigstore-rust@sigstore-verify-v0.6.6...sigstore-verify-v0.8.0)

---
updated-dependencies:
- dependency-name: sigstore-verify
  dependency-version: 0.8.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file rust Pull requests that update rust code labels May 22, 2026
@github-actions
github-actions Bot enabled auto-merge May 22, 2026 19:09
@jamadeo
jamadeo disabled auto-merge May 22, 2026 21:11
@jamadeo
jamadeo added this pull request to the merge queue May 22, 2026
Merged via the queue into main with commit a7d4625 May 22, 2026
23 checks passed
@jamadeo
jamadeo deleted the dependabot/cargo/sigstore-verify-0.8.0 branch May 22, 2026 22:26
lifeizhou-ap added a commit that referenced this pull request May 25, 2026
* main: (48 commits)
  docs: stats update (#9410)
  Build summon instructions per turn (#9329)
  Fix desktop chat search session limiting (#9366)
  fix(agents): serialize per-session agent creation to stop duplicate MCP init (#9357)
  chore(deps): bump image from 0.24.9 to 0.25.10 (#9383)
  chore(deps): bump agent-client-protocol from 0.11.1 to 0.12.1 (#9381)
  chore(deps): bump ctor from 0.2.9 to 1.0.6 (#9380)
  chore(deps): bump strum from 0.27.2 to 0.28.0 (#9384)
  chore(deps): bump lru from 0.16.3 to 0.18.0 (#9382)
  chore(deps): bump shlex from 1.3.0 to 2.0.1 (#9379)
  chore(deps): bump sigstore-verify from 0.6.6 to 0.8.0 (#9378)
  chore(deps): bump clap_mangen from 0.2.33 to 0.3.0 (#9377)
  chore(deps): bump the cargo-minor-and-patch group with 12 updates (#9376)
  chore(deps): bump qs and express in /documentation (#9375)
  chore(deps): bump docker/build-push-action from 6.18.0 to 7.2.0 (#9374)
  chore(deps): bump step-security/harden-runner from 2.19.1 to 2.19.4 (#9373)
  chore(deps): bump EmbarkStudios/cargo-deny-action from 2.0.17 to 2.0.19 (#9372)
  chore(deps): bump actions/setup-python from 5 to 6 (#9371)
  chore(deps): bump actions-rust-lang/setup-rust-toolchain from 1.16.0 to 1.16.1 (#9370)
  protocol cleanup (#9147)
  ...
shafqatevo pushed a commit to shafqatevo/goose that referenced this pull request Aug 7, 2026
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file rust Pull requests that update rust code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant