diff --git a/package.json b/package.json index bd70adbc..d6d9f124 100644 --- a/package.json +++ b/package.json @@ -50,7 +50,7 @@ "@actions/http-client": "^4.0.1", "@actions/io": "^3.0.2", "@actions/tool-cache": "^4.0.0", - "@sigstore/bundle": "^4.0.0", + "@sigstore/bundle": "^5.0.0", "@sigstore/sign": "^4.1.1", "@sigstore/tuf": "^4.0.2", "@sigstore/verify": "^3.1.1", diff --git a/yarn.lock b/yarn.lock index fe40c424..f7a303cb 100644 --- a/yarn.lock +++ b/yarn.lock @@ -468,7 +468,7 @@ __metadata: "@actions/io": "npm:^3.0.2" "@actions/tool-cache": "npm:^4.0.0" "@eslint/js": "npm:^9.39.3" - "@sigstore/bundle": "npm:^4.0.0" + "@sigstore/bundle": "npm:^5.0.0" "@sigstore/sign": "npm:^4.1.1" "@sigstore/tuf": "npm:^4.0.2" "@sigstore/verify": "npm:^3.1.1" @@ -1337,6 +1337,15 @@ __metadata: languageName: node linkType: hard +"@sigstore/bundle@npm:^5.0.0": + version: 5.0.0 + resolution: "@sigstore/bundle@npm:5.0.0" + dependencies: + "@sigstore/protobuf-specs": "npm:^0.5.0" + checksum: 10/9d86dd7f8086832fff2a36ce84bd38a895fe951a8848963c1dddf1d0eb4d14394c94626fc53c4173f42be5ee8d7319b593ce3a77491e8b1497349c653decba90 + languageName: node + linkType: hard + "@sigstore/core@npm:^3.2.0": version: 3.2.0 resolution: "@sigstore/core@npm:3.2.0"