Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

fix(deps): update module github.com/sigstore/fulcio to v1.4.5 #2371

Closed
wants to merge 1 commit into from

Conversation

renovate[bot]
Copy link
Contributor

@renovate renovate bot commented Apr 6, 2024

Mend Renovate

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
github.com/sigstore/fulcio v1.4.3 -> v1.4.5 age adoption passing confidence

Release Notes

sigstore/fulcio (github.com/sigstore/fulcio)

v1.4.5

Compare Source

Features

  • Add Codefresh OIDC provider (#​1593)

Contributors

  • ilia-medvedev-codefresh

v1.4.4

Compare Source

Features

  • Add production OIDC provider for Eclipse (#​1472)
  • Change parseExtension function to be public (#​1584)
  • Allow exposed metrics port to be overridden (#​1518)
  • add configurable idle timeout

Bug Fixes

  • Fix docker-compose service order (#​1537)
  • Fix debug docker-compose setup (#​1529)
  • Fix docker-compose file (#​1560)

Documentation

  • Create new-idp-requirements.md (#​1447)
  • docs: Add back descriptive content on cert issuing (#​1494)
  • Added GitLab OIDC documentation to the /docs/oidc.md file that was missing. (#​1574)

Misc

  • update builder to use go1.21.6
  • Move kubernetes CA processing in config.prepare (#​1454)
  • Lots of dependabot updates

Contributors

  • Bob Callaway
  • Carlos Tadeu Panato Junior
  • Colleen Murphy
  • Cyril Cordoui
  • Hayden B
  • John Kjell
  • Paul Welch
  • Tanner Jones

Configuration

📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate. View repository job log here.

@renovate renovate bot added the dependencies Pull requests that update a dependency file label Apr 6, 2024
Copy link
Contributor Author

renovate bot commented Apr 6, 2024

⚠ Artifact update problem

Renovate failed to update an artifact related to this branch. You probably do not want to merge this PR as-is.

♻ Renovate will retry this branch, including artifacts, only when one of the following happens:

  • any of the package files in this branch needs updating, or
  • the branch becomes conflicted, or
  • you click the rebase/retry checkbox if found above, or
  • you rename this PR's title to start with "rebase!" to trigger it manually

The artifact failure details are included below:

File name: go.sum
Command failed: go get -d -t ./...
go: downloading github.com/containers/ocicrypt v1.1.10
go: downloading github.com/containers/storage v1.53.0
go: downloading github.com/opencontainers/go-digest v1.0.0
go: downloading github.com/opencontainers/image-spec v1.1.0
go: downloading github.com/sirupsen/logrus v1.9.3
go: downloading github.com/vbauerster/mpb/v8 v8.7.2
go: downloading golang.org/x/exp v0.0.0-20240404231335-c0f41cb1a7a0
go: downloading golang.org/x/sync v0.7.0
go: downloading golang.org/x/term v0.19.0
go: downloading github.com/stretchr/testify v1.9.0
go: downloading github.com/docker/distribution v2.8.3+incompatible
go: downloading github.com/docker/go-connections v0.5.0
go: downloading gopkg.in/yaml.v3 v3.0.1
go: downloading github.com/docker/docker v25.0.5+incompatible
go: downloading github.com/containers/libtrust v0.0.0-20230121012942-c1716e8a8d01
go: downloading dario.cat/mergo v1.0.0
go: downloading go.etcd.io/bbolt v1.3.9
go: downloading github.com/mattn/go-sqlite3 v1.14.22
go: downloading github.com/klauspost/compress v1.17.7
go: downloading github.com/klauspost/pgzip v1.2.6
go: downloading github.com/ulikunitz/xz v0.5.12
go: downloading github.com/proglottis/gpgme v0.1.3
go: downloading github.com/sigstore/fulcio v1.4.5
go: downloading github.com/sigstore/sigstore v1.8.3
go: downloading golang.org/x/crypto v0.22.0
go: downloading github.com/xeipuuv/gojsonschema v1.2.0
go: downloading github.com/secure-systems-lab/go-securesystemslib v0.8.0
go: downloading golang.org/x/sys v0.19.0
go: downloading github.com/acarl005/stripansi v0.0.0-20180116102854-5a71ef0e047d
go: downloading github.com/mattn/go-runewidth v0.0.15
go: downloading github.com/VividCortex/ewma v1.2.0
go: downloading github.com/docker/docker-credential-helpers v0.8.1
go: downloading github.com/distribution/reference v0.6.0
go: downloading github.com/docker/cli v25.0.5+incompatible
go: downloading github.com/BurntSushi/toml v1.3.2
go: downloading github.com/davecgh/go-spew v1.1.1
go: downloading github.com/pmezard/go-difflib v1.0.0
go: downloading github.com/gorilla/mux v1.8.1
go: downloading github.com/moby/sys/user v0.1.0
go: downloading github.com/pkg/errors v0.9.1
go: downloading go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.49.0
go: downloading go.opentelemetry.io/otel/trace v1.24.0
go: downloading go.opentelemetry.io/otel v1.24.0
go: downloading github.com/manifoldco/promptui v0.9.0
go: downloading github.com/sylabs/sif/v2 v2.15.2
go: downloading github.com/cyberphone/json-canonicalization v0.0.0-20231217050601-ba74d44ecf5f
go: downloading github.com/sigstore/rekor v1.2.2
go: downloading github.com/go-openapi/strfmt v0.23.0
go: downloading golang.org/x/oauth2 v0.19.0
go: downloading github.com/hashicorp/go-retryablehttp v0.7.5
go: downloading github.com/vbatts/tar-split v0.11.5
go: downloading github.com/letsencrypt/boulder v0.0.0-20230907030200-6d76a0f91e1e
go: downloading github.com/xeipuuv/gojsonreference v0.0.0-20180127040603-bd5ef7bd5415
go: downloading github.com/google/go-containerregistry v0.19.0
go: downloading github.com/go-jose/go-jose/v3 v3.0.3
go: downloading google.golang.org/grpc v1.62.1
go: downloading go.mozilla.org/pkcs7 v0.0.0-20210826202110-33d05740a352
go: downloading github.com/miekg/pkcs11 v1.1.1
go: downloading github.com/stefanberger/go-pkcs11uri v0.0.0-20201008174630-78d3cae3a980
go: downloading github.com/rivo/uniseg v0.4.4
go: downloading github.com/json-iterator/go v1.1.12
go: downloading github.com/containerd/log v0.1.0
go: downloading github.com/opencontainers/runtime-spec v1.2.0
go: downloading github.com/syndtr/gocapability v0.0.0-20200815063812-42c35b437635
go: downloading github.com/docker/go-units v0.5.0
go: downloading github.com/Microsoft/go-winio v0.6.1
go: downloading github.com/felixge/httpsnoop v1.0.4
go: downloading go.opentelemetry.io/otel/metric v1.24.0
go: downloading github.com/chzyer/readline v1.5.1
go: downloading github.com/google/uuid v1.6.0
go: downloading github.com/asaskevich/govalidator v0.0.0-20230301143203-a9d515a09cc2
go: downloading github.com/go-openapi/errors v0.22.0
go: downloading github.com/mitchellh/mapstructure v1.5.0
go: downloading github.com/oklog/ulid v1.3.1
go: downloading go.mongodb.org/mongo-driver v1.14.0
go: downloading github.com/coreos/go-oidc/v3 v3.10.0
go: downloading github.com/segmentio/ksuid v1.0.4
go: downloading github.com/skratchdot/open-golang v0.0.0-20200116055534-eef842397966
go: downloading github.com/go-openapi/runtime v0.26.0
go: downloading github.com/go-openapi/swag v0.23.0
go: downloading github.com/go-openapi/validate v0.22.1
go: downloading github.com/hashicorp/go-cleanhttp v0.5.2
go: downloading github.com/google/go-intervals v0.0.2
go: downloading github.com/hashicorp/go-multierror v1.1.1
go: downloading github.com/opencontainers/selinux v1.11.0
go: downloading github.com/containerd/stargz-snapshotter/estargz v0.15.1
go: downloading github.com/cyphar/filepath-securejoin v0.2.4
go: downloading github.com/ostreedev/ostree-go v0.0.0-20210805093236-719684c64e4f
go: downloading github.com/xeipuuv/gojsonpointer v0.0.0-20190905194746-02993c407bfb
go: downloading github.com/titanous/rocacheck v0.0.0-20171023193734-afe73141d399
go: downloading github.com/golang/protobuf v1.5.4
go: downloading github.com/modern-go/concurrent v0.0.0-20180306012644-bacd9c7ef1dd
go: downloading github.com/modern-go/reflect2 v1.0.2
go: downloading github.com/moby/sys/mountinfo v0.7.1
go: downloading github.com/gogo/protobuf v1.3.2
go: downloading golang.org/x/tools v0.20.0
go: downloading github.com/go-logr/logr v1.4.1
go: downloading golang.org/x/net v0.24.0
go: downloading github.com/go-jose/go-jose/v4 v4.0.1
go: downloading github.com/mailru/easyjson v0.7.7
go: downloading github.com/opentracing/opentracing-go v1.2.0
go: downloading golang.org/x/mod v0.17.0
go: downloading github.com/tchap/go-patricia/v2 v2.3.1
go: downloading github.com/hashicorp/errwrap v1.1.0
go: downloading gopkg.in/go-jose/go-jose.v2 v2.6.3
go: downloading google.golang.org/protobuf v1.33.0
go: downloading google.golang.org/genproto/googleapis/rpc v0.0.0-20240318140521-94a12d6c2237
go: downloading github.com/go-openapi/analysis v0.21.4
go: downloading github.com/go-openapi/jsonpointer v0.19.6
go: downloading github.com/go-openapi/loads v0.21.2
go: downloading github.com/go-openapi/spec v0.20.9
go: downloading github.com/go-logr/stdr v1.2.2
go: downloading github.com/josharian/intern v1.0.0
go: downloading gopkg.in/yaml.v2 v2.4.0
go: downloading github.com/Microsoft/hcsshim v0.12.0-rc.3
go: downloading github.com/mistifyio/go-zfs/v3 v3.0.1
go: downloading github.com/mattn/go-shellwords v1.0.12
go: downloading github.com/go-openapi/jsonreference v0.20.2
go: downloading github.com/docker/go-metrics v0.0.1
go: downloading golang.org/x/text v0.14.0
go: downloading github.com/prometheus/client_golang v1.19.0
go: downloading github.com/beorn7/perks v1.0.1
go: downloading github.com/cespare/xxhash/v2 v2.2.0
go: downloading github.com/prometheus/client_model v0.6.0
go: downloading github.com/prometheus/common v0.51.1
go: downloading github.com/prometheus/procfs v0.12.0
go: downloading go.opencensus.io v0.24.0
go: downloading github.com/containerd/cgroups/v3 v3.0.2
go: downloading github.com/containerd/errdefs v0.1.0
go: downloading github.com/golang/groupcache v0.0.0-20210331224755-41bb18bfe9da
github.com/containers/image/v5/pkg/docker/config tested by
	github.com/containers/image/v5/pkg/docker/config.test imports
	github.com/docker/docker/registry imports
	github.com/docker/distribution/registry/client/auth imports
	github.com/docker/distribution/registry/client imports
	github.com/docker/distribution/registry/storage/cache imports
	github.com/docker/distribution/metrics imports
	github.com/docker/go-metrics imports
	github.com/prometheus/client_golang/prometheus imports
	github.com/prometheus/common/model imports
	slices: package slices is not in GOROOT (/opt/containerbase/tools/golang/1.20.14/src/slices)
note: imported by a module that requires go 1.21

Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
@renovate renovate bot force-pushed the renovate/github.com-sigstore-fulcio-1.x branch from ada9553 to ba7c66b Compare April 8, 2024 11:21
@mtrmac
Copy link
Collaborator

mtrmac commented Apr 8, 2024

This does not change any code relevant to c/image. See #2320 for earlier versions.

@mtrmac mtrmac closed this Apr 8, 2024
Copy link
Contributor Author

renovate bot commented Apr 8, 2024

Renovate Ignore Notification

Because you closed this PR without merging, Renovate will ignore this update (v1.4.5). You will get a PR once a newer version is released. To ignore this dependency forever, add it to the ignoreDeps array of your Renovate config.

If you accidentally closed this PR, or if you changed your mind: rename this PR to get a fresh replacement PR.

@renovate renovate bot deleted the renovate/github.com-sigstore-fulcio-1.x branch April 8, 2024 13:53
@mtrmac mtrmac mentioned this pull request Apr 15, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Pull requests that update a dependency file
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

1 participant