Chore(deps): Bump sigstore/gh-action-sigstore-python from 3.0.1 to 3.1.0#11
Conversation
[//]: # (dependabot-start)⚠️ **Dependabot is rebasing this PR**⚠️ Rebasing might not happen immediately, so don't worry if this takes some time. Note: if you make any changes to this PR yourself, they will take precedence over the rebase. Change-Id: I49a38ab7430ef2a3ca7977e071ac12c9930b381f --- [//]: # (dependabot-end) Bumps lfit/gerrit-review-action from 0.8 to 0.9. ## Release notes Sourced from lfit/gerrit-review-action's releases. v0.9 CI: Add basic config for validation @tykeal (#2) Feat: Initial try at gerrit-review action @tykeal (#3) Fix: quote all inputs @tykeal (#4) Feat: Make current jobs status an input @tykeal (#5) Fix: Use job.status @tykeal (#6) Fix: Correct job.status call @tykeal (#7) Refactor: reuse vote-type @tykeal (#8) Chore: Upgrade pre-commit hooks @tykeal (#10) Feat!: Switch to new ssh method @tykeal (#11) Fix: Add shell specifier to all run commands @tykeal (#12) Fix: Do a single line ssh command @tykeal (#13) Fix: Gerrit review options must be quoted @tykeal (#14) Feat: Allow non-voting status comments @tykeal (#16) Fix: Add missing '/' to GHA URL @tykeal (#17) Fix: Attempt to fix bad voting @tykeal (#18) CI: Build vote command up @tykeal (#19) CI: Add a debug statement @tykeal (#20) Fix: Remove unneeded single quotes @tykeal (#21) Chore: Update pre-commit hooks @tykeal (#22) Chore: Update deps and pre-commit @tykeal (#26) Chore: Update shimataro/ssh-key-action to v2.7.0 @askb (#28) Fix: Skip when jobs are run locally @askb (#29) Fix: Set ACT env for install SSH keys @askb (#30) [pre-commit.ci] pre-commit autoupdate @pre-commit-ci[bot] (#27) Maintenance Feat: Add README.md content, import updated template files @ModeSevenIndustrialSolutions (#31) Links Submit bugs/feature requests ## Commits 537251e Merge pull request #31 from modeseven-lfreleng-actions/import-template 17c7024 Feat: Add README.md content, import updated template files 7cde442 Merge pull request #27 from lfit/pre-commit-ci-update-config eed4e10 Chore: pre-commit autoupdate ea252e6 [pre-commit.ci] pre-commit autoupdate See full diff in compare view  Signed-off-by: dependabot[bot] <support@github.com> Signed-off-by: lfit.gh2gerrit <releng+lfit-gh2gerrit@linuxfoundation.org> Change-Id: I03b903a3a7a631a5352aab29e66aef6124020fe3 GitHub-PR: #1 GitHub-Hash: 137fd78ffec4615f
|
@dependabot recreate |
Bumps [sigstore/gh-action-sigstore-python](https://github.com/sigstore/gh-action-sigstore-python) from 3.0.1 to 3.1.0. - [Release notes](https://github.com/sigstore/gh-action-sigstore-python/releases) - [Changelog](https://github.com/sigstore/gh-action-sigstore-python/blob/main/CHANGELOG.md) - [Commits](sigstore/gh-action-sigstore-python@f7ad0af...f832326) --- updated-dependencies: - dependency-name: sigstore/gh-action-sigstore-python dependency-version: 3.1.0 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
82cfed3 to
3541396
Compare
|
PR: #11 |
|
Change raised in Gerrit by GitHub2Gerrit: https://gerrit.linuxfoundation.org/infra/c/releng/gerrit_to_platform/+/73830 |
|
Auto-closing pull request |
|
OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting If you change your mind, just re-open this PR and I'll resolve any conflicts on it. |
Bumps sigstore/gh-action-sigstore-python from 3.0.1 to 3.1.0. ## Release notes Sourced from sigstore/gh-action-sigstore-python's releases. v3.1.0 gh-action-sigstore-python is now compatible with Rekor v2 transparency log (but produced signature bundles still contain Rekor v1 entries by default). Changed The action now uses sigstore-python 4.1. All other dependencies are also updated (#220) Fixed Fixed incompatibility with Python 3.14 by upgrading dependencies (#225) Added rekor-version argument was added to control the Rekor transparency log version when signing. The default version in the gh-action-sigstore-python 3.x series will remain 1 (except when using staging: true). (#228) ## Changelog Sourced from sigstore/gh-action-sigstore-python's changelog. Changelog All notable changes to gh-action-sigstore-python will be documented in this file. The format is based on Keep a Changelog. All versions prior to 3.0.0 are untracked. [Unreleased] [3.1.0] gh-action-sigstore-python is now compatible with Rekor v2 transparency log (but produced signature bundles still contain Rekor v1 entries by default). Changed The action now uses sigstore-python 4.1. All other dependencies are also updated (#220) Fixed Fixed incompatibility with Python 3.14 by upgrading dependencies (#225) Added rekor-version argument was added to control the Rekor transparency log version when signing. The default version in the gh-action-sigstore-python 3.x series will remain 1 (except when using staging: true). (#228) [3.0.1] Changed The minimum Python version supported by this action is now 3.9 (#155) The action's Python dependencies are now fully pinned to specific versions (#165) Fixed The rfc3161-client dependency has been upgrades to 1.0.3 to resolve a security vulnerability (#182) [3.0.0] ... (truncated) ## Commits f832326 Prepare 3.1.0 release (#230) 3385d3a build(deps): bump astral-sh/setup-uv in the actions group (#232) 35fff1e Add rekor-version argument (#228) be60bbe build(deps): bump github/codeql-action in the actions group (#231) 72e7431 Actually upgrade dependencies (#225) ccdc279 ci, action: address zizmor findings, bump versions (#222) 709f8a4 build(deps): bump sigstore from 3.6.3 to 4.0.0 (#220) 5ce4031 requirements: Include main.in contents within dev.in (#221) ea888ad build(deps): bump the actions group with 3 updates (#218) 17565e2 build(deps): bump the python-dependencies group with 6 updates (#219) Additional commits viewable in compare view  Signed-off-by: dependabot[bot] <support@github.com> Signed-off-by: lfit.gh2gerrit <releng+lfit-gh2gerrit@linuxfoundation.org> Change-Id: Ib036229f3b8edbcc715fcd3abf40aa8a22060dee GitHub-PR: #11 GitHub-Hash: 044e017063eabdb2
Bumps sigstore/gh-action-sigstore-python from 3.0.1 to 3.1.0.
Release notes
Sourced from sigstore/gh-action-sigstore-python's releases.
Changelog
Sourced from sigstore/gh-action-sigstore-python's changelog.
... (truncated)
Commits
f832326Prepare 3.1.0 release (#230)3385d3abuild(deps): bump astral-sh/setup-uv in the actions group (#232)35fff1eAdd rekor-version argument (#228)be60bbebuild(deps): bump github/codeql-action in the actions group (#231)72e7431Actually upgrade dependencies (#225)ccdc279ci, action: address zizmor findings, bump versions (#222)709f8a4build(deps): bump sigstore from 3.6.3 to 4.0.0 (#220)5ce4031requirements: Include main.in contents within dev.in (#221)ea888adbuild(deps): bump the actions group with 3 updates (#218)17565e2build(deps): bump the python-dependencies group with 6 updates (#219)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge and block automerging@dependabot reopenwill reopen this PR if it is closed@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)