Skip to content

chore(deps): update dependency sigstore/cosign to v3.1.3 - #6016

Merged
ralphbean merged 1 commit into
mainfrom
renovate/sigstore-cosign-3.x
Aug 10, 2026
Merged

chore(deps): update dependency sigstore/cosign to v3.1.3#6016
ralphbean merged 1 commit into
mainfrom
renovate/sigstore-cosign-3.x

Conversation

@renovate-fullsend

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Update Change
sigstore/cosign patch 3.1.23.1.3

Warning

Some dependencies could not be looked up. Check the Dependency Dashboard for more information.


Release Notes

sigstore/cosign (sigstore/cosign)

v3.1.3

Compare Source

What's Changed

This release resolves GHSA-fx35-mq7g-6g98, a verification bypass using an unexpected public key in a legacy bundle.

  • Auto-detect default digest algorithm for public keys in #​5019
  • fix(pkcs11key): return an error instead of panicking when no key pair matches in #​5022
  • Supporting OCI Signing with X.509 Certificate Chain in #​4614
  • test(inspect): replace mock TSA client usage with local timestamp response generator in #​5021
  • fix: prevent shell completions for various options not taking filenames in #​5032
  • fix(blob): compare file checksums case-insensitively in #​5036
  • Verification bypass via public key in legacy bundle (GHSA-fx35-mq7g-6g98) in #​5040

Full Changelog: sigstore/cosign@v3.1.2...v3.1.3


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate.

@renovate-fullsend
renovate-fullsend Bot requested a review from a team as a code owner August 8, 2026 15:22
@fullsend-ai-review

fullsend-ai-review Bot commented Aug 8, 2026

Copy link
Copy Markdown

🤖 Finished Review · ✅ Success · Started 3:23 PM UTC · Completed 3:33 PM UTC

Commit: 763a87c · View workflow run →

@codecov

codecov Bot commented Aug 8, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.

📢 Thoughts on this report? Let us know!

@fullsend-ai-review

fullsend-ai-review Bot commented Aug 8, 2026

Copy link
Copy Markdown

Review

Findings

Medium

  • [protected-path] scripts/renovate/update-tirith-checksums.sh — This file is under scripts/, a protected path requiring human approval. The PR is a Renovate-automated cosign version bump (3.1.2 → 3.1.3) addressing upstream security advisory GHSA-fx35-mq7g-6g98. The change is well-scoped (version string + SHA256 hash update only), but human approval is always required for protected-path changes.
Previous run

Review

Findings

Medium

  • [protected-path] scripts/renovate/update-tirith-checksums.sh — This file is under scripts/, a protected path requiring human approval. The PR is a Renovate-automated cosign version bump (3.1.2 → 3.1.3) addressing upstream security advisory GHSA-fx35-mq7g-6g98. The change is well-scoped (version string + SHA256 hash update only), but human approval is always required for protected-path changes.
Previous run (2)

Review

Findings

Medium

  • [protected-path] scripts/renovate/update-tirith-checksums.sh — This file is under scripts/, a protected path requiring human approval. The PR is a Renovate-automated cosign version bump (3.1.2 → 3.1.3) addressing upstream security advisory GHSA-fx35-mq7g-6g98. The change is well-scoped (version string + SHA256 hash update only), but human approval is always required for protected-path changes.
Previous run (3)

Review

Findings

Medium

  • [protected-path] scripts/renovate/update-tirith-checksums.sh — This file is under scripts/, a protected path requiring human approval. The PR is a Renovate-automated cosign version bump (3.1.2 → 3.1.3) addressing upstream security advisory GHSA-fx35-mq7g-6g98. The change is well-scoped (version string + SHA256 hash update only), but human approval is always required for protected-path changes.
Previous run (4)

Review

Findings

Medium

  • [protected-path] scripts/renovate/update-tirith-checksums.sh — This file is under scripts/, a protected path requiring human approval. The PR is a Renovate-automated cosign version bump (3.1.2 → 3.1.3) addressing upstream security advisory GHSA-fx35-mq7g-6g98. The change is well-scoped (version string + SHA256 hash update only), but human approval is always required for protected-path changes.

Labels: Renovate dependency update for cosign addressing security advisory GHSA-fx35-mq7g-6g98

@fullsend-ai-review fullsend-ai-review Bot added requires-manual-review Review requires human judgment dependencies Pull requests that update a dependency file security Security threat model and related concerns labels Aug 8, 2026
@renovate-fullsend
renovate-fullsend Bot force-pushed the renovate/sigstore-cosign-3.x branch from 763a87c to 397c648 Compare August 9, 2026 03:49
@fullsend-ai-review

fullsend-ai-review Bot commented Aug 9, 2026

Copy link
Copy Markdown

🤖 Finished Review · ✅ Success · Started 3:50 AM UTC · Completed 4:00 AM UTC

Commit: 397c648 · View workflow run →

@renovate-fullsend
renovate-fullsend Bot force-pushed the renovate/sigstore-cosign-3.x branch from 397c648 to 3dcfe73 Compare August 9, 2026 15:21
@fullsend-ai-review

fullsend-ai-review Bot commented Aug 9, 2026

Copy link
Copy Markdown

🤖 Finished Review · ✅ Success · Started 3:22 PM UTC · Completed 3:35 PM UTC

Commit: 3dcfe73 · View workflow run →

@renovate-fullsend
renovate-fullsend Bot force-pushed the renovate/sigstore-cosign-3.x branch from 3dcfe73 to c3ae789 Compare August 10, 2026 03:51
@fullsend-ai-review

fullsend-ai-review Bot commented Aug 10, 2026

Copy link
Copy Markdown

🤖 Finished Review · ✅ Success · Started 3:52 AM UTC · Completed 4:05 AM UTC

Commit: c3ae789 · View workflow run →

@renovate-fullsend
renovate-fullsend Bot force-pushed the renovate/sigstore-cosign-3.x branch from c3ae789 to 7a1ea72 Compare August 10, 2026 15:32
@fullsend-ai-review

fullsend-ai-review Bot commented Aug 10, 2026

Copy link
Copy Markdown

🤖 Finished Review · ✅ Success · Started 3:34 PM UTC · Completed 3:44 PM UTC

Commit: 7a1ea72 · View workflow run →

@ralphbean
ralphbean added this pull request to the merge queue Aug 10, 2026
Merged via the queue into main with commit 4d92a16 Aug 10, 2026
15 checks passed
@ralphbean
ralphbean deleted the renovate/sigstore-cosign-3.x branch August 10, 2026 16:26
@fullsend-ai-retro

fullsend-ai-retro Bot commented Aug 10, 2026

Copy link
Copy Markdown

🤖 Finished Retro · ✅ Success · Started 4:28 PM UTC · Completed 4:35 PM UTC

Commit: 7a1ea72 · View workflow run →

@fullsend-ai-retro

Copy link
Copy Markdown

Retro: PR #6016 — Renovate cosign patch bump (3.1.2 → 3.1.3)

This PR was a Renovate-automated 2-line dependency update (version string + SHA256 hash) to scripts/renovate/update-tirith-checksums.sh, addressing security advisory GHSA-fx35-mq7g-6g98.

Timeline

  1. Aug 8 15:22 UTC — Renovate opens PR. Review agent run docs: Add agent-compatible code problem document #1 produces a single medium-severity protected-path finding, correctly noting human approval is required for changes under scripts/. Labels applied: security, dependencies, requires-manual-review.
  2. Aug 9 03:49 – Aug 10 15:33 UTC — Renovate rebases the branch 4 times to keep it current with main. Each rebase triggers a new review agent run (runs Add problem areas: Tekton pipeline review, migration path, multi-tenancy #2docs: add agent infrastructure problem document #5), each producing the identical finding on a functionally identical 2-line diff.
  3. Aug 10 16:20 UTCralphbean approves.
  4. Aug 10 16:26 UTC — Merged via merge queue.

Total: 5 review agent runs, 10 workflow dispatches (7 succeeded, 3 skipped), all for the same 2-line change.

What went well

  • The review agent's finding was accurate and well-scoped every time — it correctly identified the protected-path constraint and described the change clearly.
  • The sticky comment pattern kept the PR comment thread clean despite 5 runs.
  • Human reviewer approved promptly after the final rebase.

What could go better

  • Redundant review runs on Renovate rebases: 4 of the 5 review runs were pure token waste — the effective diff was identical across all commits. This is a well-known issue cluster.
  • Time to merge a security patch: The PR addressed a security advisory but sat for ~2 days before human review. This is a human workflow concern, not an agent gap.

No new proposals — existing coverage is comprehensive

Every improvement pattern identified in this retro is already covered by existing open issues:

This PR provides additional supporting evidence for that issue cluster — specifically, 5 identical review runs producing the same protected-path finding on a 2-line Renovate security patch over 2 days.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file requires-manual-review Review requires human judgment security Security threat model and related concerns

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant