Skip to content

Bump cosign to 3.0.6#232

Merged
Hayden-IO merged 1 commit into
sigstore:mainfrom
eshattow:bump306
May 7, 2026
Merged

Bump cosign to 3.0.6#232
Hayden-IO merged 1 commit into
sigstore:mainfrom
eshattow:bump306

Conversation

@eshattow
Copy link
Copy Markdown
Contributor

@eshattow eshattow commented Apr 16, 2026

  • Upgrade to newest cosign version

Resolves: #231

@eshattow eshattow marked this pull request as draft April 17, 2026 02:54
@eshattow eshattow marked this pull request as ready for review April 22, 2026 07:00
* Upgrade to newest cosign version
* Add comment with suggested command for generating cosign_checksums.txt
  snippet to allow additional bootstrap_*_sha env variables linux_ppc64le,
  linux_riscv64, and linux_s390x

Signed-off-by: E Shattow <eshattow@users.noreply.github.com>
@eshattow
Copy link
Copy Markdown
Contributor Author

eshattow commented May 6, 2026

@Hayden-IO it's been a few weeks can I have your reply on this? If you want me to break up the changes differently just let me know. Thanks! -E

Comment thread action.yml
@Hayden-IO Hayden-IO merged commit 6f9f177 into sigstore:main May 7, 2026
115 checks passed
@eshattow eshattow deleted the bump306 branch May 7, 2026 01:36
renovate Bot added a commit to sdwilsh/sOS that referenced this pull request May 7, 2026
##### [\`v4.1.2\`](https://github.com/sigstore/cosign-installer/releases/tag/v4.1.2)

#### What's Changed

- Bump cosign to 3.0.6 in [#232](sigstore/cosign-installer#232)

---
##### [\`v4.1.1\`](https://github.com/sigstore/cosign-installer/releases/tag/v4.1.1)

#### What's Changed

- chore: update default cosign-release to v3.0.5 in [#223](sigstore/cosign-installer#223)

**Full Changelog**: <sigstore/cosign-installer@v4.1.0...v4.1.1>

---
##### [\`v4.1.0\`](https://github.com/sigstore/cosign-installer/releases/tag/v4.1.0)

#### What's Changed

We recommend updating as soon as possible as this includes bug fixes for Cosign. We also recommend removing `with: cosign-release` and strongly discourage using `cosign-release` unless you have a specific reason to use an older version of Cosign.

- Bump cosign to 3.0.5 in [#220](sigstore/cosign-installer#220)
- fix: add retry to curl downloads for transient network failures in [#210](sigstore/cosign-installer#210)

**Full Changelog**: <sigstore/cosign-installer@v4.0.0...v4.1.0>
renovate Bot added a commit to sdwilsh/sOS that referenced this pull request May 8, 2026
##### [\`v4.1.2\`](https://github.com/sigstore/cosign-installer/releases/tag/v4.1.2)

#### What's Changed

- Bump cosign to 3.0.6 in [#232](sigstore/cosign-installer#232)

---
##### [\`v4.1.1\`](https://github.com/sigstore/cosign-installer/releases/tag/v4.1.1)

#### What's Changed

- chore: update default cosign-release to v3.0.5 in [#223](sigstore/cosign-installer#223)

**Full Changelog**: <sigstore/cosign-installer@v4.1.0...v4.1.1>

---
##### [\`v4.1.0\`](https://github.com/sigstore/cosign-installer/releases/tag/v4.1.0)

#### What's Changed

We recommend updating as soon as possible as this includes bug fixes for Cosign. We also recommend removing `with: cosign-release` and strongly discourage using `cosign-release` unless you have a specific reason to use an older version of Cosign.

- Bump cosign to 3.0.5 in [#220](sigstore/cosign-installer#220)
- fix: add retry to curl downloads for transient network failures in [#210](sigstore/cosign-installer#210)

**Full Changelog**: <sigstore/cosign-installer@v4.0.0...v4.1.0>
renovate Bot added a commit to sdwilsh/ansible-playbooks that referenced this pull request May 12, 2026
sdwilsh pushed a commit to sdwilsh/ansible-playbooks that referenced this pull request May 12, 2026
renovate Bot added a commit to sdwilsh/sOS that referenced this pull request May 15, 2026
##### [\`v4.1.2\`](https://github.com/sigstore/cosign-installer/releases/tag/v4.1.2)

##### What's Changed

- Bump cosign to 3.0.6 in [#232](sigstore/cosign-installer#232)

---
##### [\`v4.1.1\`](https://github.com/sigstore/cosign-installer/releases/tag/v4.1.1)

#### What's Changed

- chore: update default cosign-release to v3.0.5 in [#223](sigstore/cosign-installer#223)

**Full Changelog**: <sigstore/cosign-installer@v4.1.0...v4.1.1>

---
##### [\`v4.1.0\`](https://github.com/sigstore/cosign-installer/releases/tag/v4.1.0)

#### What's Changed

We recommend updating as soon as possible as this includes bug fixes for Cosign. We also recommend removing `with: cosign-release` and strongly discourage using `cosign-release` unless you have a specific reason to use an older version of Cosign.

- Bump cosign to 3.0.5 in [#220](sigstore/cosign-installer#220)
- fix: add retry to curl downloads for transient network failures in [#210](sigstore/cosign-installer#210)

**Full Changelog**: <sigstore/cosign-installer@v4.0.0...v4.1.0>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Bump cosign to 3.0.6 (tracking issue)

2 participants