Revisions of cosign

buildservice-autocommit accepted request 1077363 from Dirk Mueller's avatar Dirk Mueller (dirkmueller) (revision 6)
baserev update by copy to link target
Dirk Mueller's avatar Dirk Mueller (dirkmueller) committed (revision 5)
- fix buildtags
- build against a maintained golang version (upstream uses go1.20)
buildservice-autocommit accepted request 1006385 from Dirk Mueller's avatar Dirk Mueller (dirkmueller) (revision 4)
baserev update by copy to link target
Dirk Mueller's avatar Dirk Mueller (dirkmueller) committed (revision 3)
- use go-modules service to generate the vendor.tar and use zstd
Dirk Mueller's avatar Dirk Mueller (dirkmueller) committed (revision 2)
- update to 1.12.1:
  * fix: Pulls Fulcio root and intermediate when --certificate-chain is not
    passed into verify-blob command. The v1.12.0 release introduced a
    regression: when COSIGN_EXPERIMENTAL was not set, cosign verify-blob would
    check a --certificate (without a --certificate-chain provided) against the
    operating system root CA bundle. In this release, Cosign checks the
    certificate against Fulcio's CA root instead (restoring the earlier
    behavior).
  * fix: fix cert chain validation for verify-blob in non-experimental mode
  * fix: add COSIGN_EXPERIMENTAL=1 for verify-bloba
  * Fix BYO-root with intermediate to fetch intermediates from annotation
  * fix: fixing breaking changes in rekor v1.12.0 upgrade
Dirk Mueller's avatar Dirk Mueller (dirkmueller) committed (revision 1)
Displaying all 6 revisions
openSUSE Build Service is sponsored by