Skip to content

Update module github.com/sigstore/rekor-tiles/v2 to v2.3.0#482

Open
renovate-rancher[bot] wants to merge 1 commit into
mainfrom
renovate/github.com-sigstore-rekor-tiles-v2-2.x
Open

Update module github.com/sigstore/rekor-tiles/v2 to v2.3.0#482
renovate-rancher[bot] wants to merge 1 commit into
mainfrom
renovate/github.com-sigstore-rekor-tiles-v2-2.x

Conversation

@renovate-rancher

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
github.com/sigstore/rekor-tiles/v2 v2.2.1v2.3.0 age confidence

Release Notes

sigstore/rekor-tiles (github.com/sigstore/rekor-tiles/v2)

v2.3.0

Compare Source

What's Changed

v2.3.0 drops support for the DSSE entry type. All Sigstore SDKs will now upload DSSEs as hashedrekord entries, to support uploading large DSSEs, such as signed SBOMs, for the public instance. We strongly recommend not relying on the previous DSSE type in any way, as going forward, there will only be one supported entry type.

Breaking Changes
Library Features
  • Add ToEntryHash and VerifyLogEntryWithHash in #​787
Fixes
  • don't return full panic in user-facing error message in #​707
  • ensure error can be Unwrapped in #​710
  • defensive fix if err is wrapped in #​708
  • Limit client response reads, set default timeouts, and validate digest sizes in #​806

Full Changelog: sigstore/rekor-tiles@v2.2.1...v2.3.0


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate.

@renovate-rancher renovate-rancher Bot requested a review from a team as a code owner June 17, 2026 06:24
@renovate-rancher renovate-rancher Bot requested a review from kyledong-suse June 17, 2026 06:24
@renovate-rancher

Copy link
Copy Markdown
Contributor Author

ℹ️ Artifact update notice

File name: go.mod

In order to perform the update(s) described in the table above, Renovate ran the go get command, which resulted in the following additional change(s):

  • 15 additional dependencies were updated

Details:

Package Change
github.com/sigstore/sigstore v1.10.6 -> v1.10.8
github.com/grpc-ecosystem/grpc-gateway/v2 v2.27.7 -> v2.29.0
github.com/letsencrypt/boulder v0.20260223.0 -> v0.20260309.0
github.com/secure-systems-lab/go-securesystemslib v0.10.0 -> v0.11.0
github.com/sigstore/protobuf-specs v0.5.0 -> v0.5.1
github.com/theupdateframework/go-tuf/v2 v2.4.1 -> v2.4.2-0.20260407074541-7e8f69f906ef
github.com/transparency-dev/formats v0.0.0-20251017110053-404c0d5b696c -> v0.1.0
go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.65.0 -> v0.67.0
go.opentelemetry.io/otel v1.43.0 -> v1.44.0
go.opentelemetry.io/otel/metric v1.43.0 -> v1.44.0
go.opentelemetry.io/otel/trace v1.43.0 -> v1.44.0
go.yaml.in/yaml/v2 v2.4.3 -> v2.4.4
google.golang.org/genproto/googleapis/api v0.0.0-20260316180232-0b37fe3546d5 -> v0.0.0-20260414002931-afd174a4e478
google.golang.org/genproto/googleapis/rpc v0.0.0-20260316180232-0b37fe3546d5 -> v0.0.0-20260523011958-0a33c5d7ca68
k8s.io/klog/v2 v2.130.1 -> v2.140.0

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants