Skip to content

[v14] chore: Bump github.com/sigstore/cosign/v2 to 2.2.4#40498

Merged
codingllama merged 4 commits intobranch/v14from
codingllama/bump-cosign-2.2.4-v14
Apr 16, 2024
Merged

[v14] chore: Bump github.com/sigstore/cosign/v2 to 2.2.4#40498
codingllama merged 4 commits intobranch/v14from
codingllama/bump-cosign-2.2.4-v14

Conversation

@codingllama
Copy link
Copy Markdown
Contributor

@codingllama codingllama commented Apr 11, 2024

Manual backport of #40485 to branch/v14.

Changelog: Updated cosign to address CVE-2024-29902 and CVE-2024-29903

@codingllama codingllama force-pushed the codingllama/bump-cosign-2.2.4-v14 branch from f7ab3bc to 9eccc2f Compare April 15, 2024 18:00
@codingllama
Copy link
Copy Markdown
Contributor Author

@greedy52, could you take a look at the Database Access test errors here? I believe we've seen this before.

* Update mongodb driver to 1.31.1

* test bumping max to 400
@greedy52
Copy link
Copy Markdown
Contributor

greedy52 commented Apr 16, 2024

I cherry-picked #35625 (but retained the go.mod and go.sum from this change). Should be good now. Only test-related changes.

@codingllama
Copy link
Copy Markdown
Contributor Author

Many thanks, @greedy52!

@codingllama codingllama added this pull request to the merge queue Apr 16, 2024
@github-merge-queue github-merge-queue Bot removed this pull request from the merge queue due to failed status checks Apr 16, 2024
@codingllama codingllama added this pull request to the merge queue Apr 16, 2024
Merged via the queue into branch/v14 with commit 3b9ab4d Apr 16, 2024
@codingllama codingllama deleted the codingllama/bump-cosign-2.2.4-v14 branch April 16, 2024 14:29
@camscale camscale mentioned this pull request Apr 24, 2024
This was referenced Aug 6, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants