Skip to content
This repository was archived by the owner on Jan 7, 2026. It is now read-only.

Conversation

@dnegreira
Copy link
Member

Update advisory for GHSA-4qg8-fj49-pxjh

github.com/sigstore/timestamp-authority is transitive dependencies
pulled in by github.com/sigstore/cosign.

Any attempts to bump timestamp-authority results in build failures.

There is currently a discussion upstream on how to migrate to cosign v3:
goreleaser/goreleaser#6195

Signed-off-by: David Negreira [email protected]

Update advisory for GHSA-4qg8-fj49-pxjh

github.com/sigstore/timestamp-authority is transitive dependencies
pulled in by github.com/sigstore/cosign.

Any attempts to bump timestamp-authority results in build failures.

There is currently a discussion upstream on how to migrate to cosign v3:
goreleaser/goreleaser#6195

Signed-off-by: David Negreira <[email protected]>
@dnegreira dnegreira added this pull request to the merge queue Dec 15, 2025
Merged via the queue into wolfi-dev:main with commit a75b9a5 Dec 15, 2025
4 checks passed
@dnegreira dnegreira deleted the goreleaser-timestamp-authority branch December 15, 2025 16:33
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants