Skip to content

chore(deps): bump the sigstore group across 1 directory with 5 updates - #1982

Open
dependabot[bot] wants to merge 1 commit into
release-v0.27.xfrom
dependabot/go_modules/release-v0.27.x/sigstore-c229aaa348
Open

dependabot[bot] wants to merge 1 commit into
release-v0.27.xfrom
dependabot/go_modules/release-v0.27.x/sigstore-c229aaa348

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 16, 2026 •

Copy link
Copy Markdown
Contributor

⚠️ Dependabot is rebasing this PR ⚠️

Rebasing might not happen immediately, so don't worry if this takes some time.

Note: if you make any changes to this PR yourself, they will take precedence over the rebase.


Bumps the sigstore group with 5 updates in the / directory:

Package From To
github.com/sigstore/sigstore 1.10.9 1.10.11
github.com/sigstore/sigstore/pkg/signature/kms/aws 1.10.9 1.10.11
github.com/sigstore/sigstore/pkg/signature/kms/azure 1.10.9 1.10.11
github.com/sigstore/sigstore/pkg/signature/kms/gcp 1.10.9 1.10.11
github.com/sigstore/sigstore/pkg/signature/kms/hashivault 1.10.9 1.10.11

Updates github.com/sigstore/sigstore from 1.10.9 to 1.10.11

Release notes

Sourced from github.com/sigstore/sigstore's releases.

v1.10.11 rolls back the release to a previous commit where the minimum Go version is 1.25.0. An upcoming v1.11.0 will require 1.27.0.

v1.10.10

What's Changed

New Contributors

Full Changelog: sigstore/sigstore@v1.10.9...v1.10.10

Commits
  • e8841f5 build(deps): Bump hashicorp/vault in /test/e2e in the all group (#2412)
  • 5b3d739 Fix Azure KMS ECDSA signature verification (r||s ordering + padding) (#2410)
  • ba4de68 build(deps): Bump github.com/aws/aws-sdk-go-v2/config (#2406)
  • 1abcedd build(deps): Bump github.com/Azure/azure-sdk-for-go/sdk/azcore (#2407)
  • d579148 build(deps): Bump github.com/aws/aws-sdk-go-v2/service/kms (#2404)
  • d922cb8 build(deps): Bump google.golang.org/api in /pkg/signature/kms/gcp (#2408)
  • 80fd95e Add retryable HTTP transport (#2396)
  • 00d66b6 build(deps): Bump google.golang.org/grpc in /pkg/signature/kms/gcp (#2411)
  • 5c8aef3 build(deps): Bump the gomod group across 2 directories with 7 updates (#2398)
  • 9bcbddf build(deps): Bump github.com/secure-systems-lab/go-securesystemslib (#2397)
  • Additional commits viewable in compare view

Updates github.com/sigstore/sigstore/pkg/signature/kms/aws from 1.10.9 to 1.10.11

Release notes

Sourced from github.com/sigstore/sigstore/pkg/signature/kms/aws's releases.

v1.10.11 rolls back the release to a previous commit where the minimum Go version is 1.25.0. An upcoming v1.11.0 will require 1.27.0.

v1.10.10

What's Changed

New Contributors

Full Changelog: sigstore/sigstore@v1.10.9...v1.10.10

Commits
  • e8841f5 build(deps): Bump hashicorp/vault in /test/e2e in the all group (#2412)
  • 5b3d739 Fix Azure KMS ECDSA signature verification (r||s ordering + padding) (#2410)
  • ba4de68 build(deps): Bump github.com/aws/aws-sdk-go-v2/config (#2406)
  • 1abcedd build(deps): Bump github.com/Azure/azure-sdk-for-go/sdk/azcore (#2407)
  • d579148 build(deps): Bump github.com/aws/aws-sdk-go-v2/service/kms (#2404)
  • d922cb8 build(deps): Bump google.golang.org/api in /pkg/signature/kms/gcp (#2408)
  • 80fd95e Add retryable HTTP transport (#2396)
  • 00d66b6 build(deps): Bump google.golang.org/grpc in /pkg/signature/kms/gcp (#2411)
  • 5c8aef3 build(deps): Bump the gomod group across 2 directories with 7 updates (#2398)
  • 9bcbddf build(deps): Bump github.com/secure-systems-lab/go-securesystemslib (#2397)
  • Additional commits viewable in compare view

Updates github.com/sigstore/sigstore/pkg/signature/kms/azure from 1.10.9 to 1.10.11

Release notes

Sourced from github.com/sigstore/sigstore/pkg/signature/kms/azure's releases.

v1.10.11 rolls back the release to a previous commit where the minimum Go version is 1.25.0. An upcoming v1.11.0 will require 1.27.0.

v1.10.10

What's Changed

New Contributors

Full Changelog: sigstore/sigstore@v1.10.9...v1.10.10

Commits
  • e8841f5 build(deps): Bump hashicorp/vault in /test/e2e in the all group (#2412)
  • 5b3d739 Fix Azure KMS ECDSA signature verification (r||s ordering + padding) (#2410)
  • ba4de68 build(deps): Bump github.com/aws/aws-sdk-go-v2/config (#2406)
  • 1abcedd build(deps): Bump github.com/Azure/azure-sdk-for-go/sdk/azcore (#2407)
  • d579148 build(deps): Bump github.com/aws/aws-sdk-go-v2/service/kms (#2404)
  • d922cb8 build(deps): Bump google.golang.org/api in /pkg/signature/kms/gcp (#2408)
  • 80fd95e Add retryable HTTP transport (#2396)
  • 00d66b6 build(deps): Bump google.golang.org/grpc in /pkg/signature/kms/gcp (#2411)
  • 5c8aef3 build(deps): Bump the gomod group across 2 directories with 7 updates (#2398)
  • 9bcbddf build(deps): Bump github.com/secure-systems-lab/go-securesystemslib (#2397)
  • Additional commits viewable in compare view

Updates github.com/sigstore/sigstore/pkg/signature/kms/gcp from 1.10.9 to 1.10.11

Release notes

Sourced from github.com/sigstore/sigstore/pkg/signature/kms/gcp's releases.

v1.10.11 rolls back the release to a previous commit where the minimum Go version is 1.25.0. An upcoming v1.11.0 will require 1.27.0.

v1.10.10

What's Changed

New Contributors

Full Changelog: sigstore/sigstore@v1.10.9...v1.10.10

Commits
  • e8841f5 build(deps): Bump hashicorp/vault in /test/e2e in the all group (#2412)
  • 5b3d739 Fix Azure KMS ECDSA signature verification (r||s ordering + padding) (#2410)
  • ba4de68 build(deps): Bump github.com/aws/aws-sdk-go-v2/config (#2406)
  • 1abcedd build(deps): Bump github.com/Azure/azure-sdk-for-go/sdk/azcore (#2407)
  • d579148 build(deps): Bump github.com/aws/aws-sdk-go-v2/service/kms (#2404)
  • d922cb8 build(deps): Bump google.golang.org/api in /pkg/signature/kms/gcp (#2408)
  • 80fd95e Add retryable HTTP transport (#2396)
  • 00d66b6 build(deps): Bump google.golang.org/grpc in /pkg/signature/kms/gcp (#2411)
  • 5c8aef3 build(deps): Bump the gomod group across 2 directories with 7 updates (#2398)
  • 9bcbddf build(deps): Bump github.com/secure-systems-lab/go-securesystemslib (#2397)
  • Additional commits viewable in compare view

Updates github.com/sigstore/sigstore/pkg/signature/kms/hashivault from 1.10.9 to 1.10.11

Release notes

Sourced from github.com/sigstore/sigstore/pkg/signature/kms/hashivault's releases.

v1.10.11 rolls back the release to a previous commit where the minimum Go version is 1.25.0. An upcoming v1.11.0 will require 1.27.0.

v1.10.10

What's Changed

New Contributors

Full Changelog: sigstore/sigstore@v1.10.9...v1.10.10

Commits
  • e8841f5 build(deps): Bump hashicorp/vault in /test/e2e in the all group (#2412)
  • 5b3d739 Fix Azure KMS ECDSA signature verification (r||s ordering + padding) (#2410)
  • ba4de68 build(deps): Bump github.com/aws/aws-sdk-go-v2/config (#2406)
  • 1abcedd build(deps): Bump github.com/Azure/azure-sdk-for-go/sdk/azcore (#2407)
  • d579148 build(deps): Bump github.com/aws/aws-sdk-go-v2/service/kms (#2404)
  • d922cb8 build(deps): Bump google.golang.org/api in /pkg/signature/kms/gcp (#2408)
  • 80fd95e Add retryable HTTP transport (#2396)
  • 00d66b6 build(deps): Bump google.golang.org/grpc in /pkg/signature/kms/gcp (#2411)
  • 5c8aef3 build(deps): Bump the gomod group across 2 directories with 7 updates (#2398)
  • 9bcbddf build(deps): Bump github.com/secure-systems-lab/go-securesystemslib (#2397)
  • Additional commits viewable in compare view

@dependabot dependabot Bot added dependencies Used by dependabot - identifies all PRs created by dependabot kind/misc Categorizes issue or PR as a miscellaneuous one. ok-to-test Indicates a non-member PR verified by an org member that is safe to test. release-note-none Denotes a PR that doesnt merit a release note. labels Sep 16, 2026
@tekton-robot

Copy link
Copy Markdown
Contributor

[APPROVALNOTIFIER] This PR is NOT APPROVED

This pull-request has been approved by:
To complete the pull request process, please assign ab-ghosh after the PR has been reviewed.
You can assign the PR to them by writing /assign @ab-ghosh in a comment when ready.

The full list of commands accepted by this bot can be found here.

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@tekton-robot tekton-robot added the size/L Denotes a PR that changes 100-499 lines, ignoring generated files. label Sep 16, 2026
@dependabot dependabot Bot changed the title chore(deps): bump the sigstore group with 5 updates chore(deps): bump the sigstore group across 1 directory with 5 updates Sep 21, 2026
@dependabot
dependabot Bot force-pushed the dependabot/go_modules/release-v0.27.x/sigstore-c229aaa348 branch 2 times, most recently from 2fb0b72 to 86dc10d Compare September 28, 2026 14:17
@infernus01

Copy link
Copy Markdown
Member

/retest

@dependabot
dependabot Bot force-pushed the dependabot/go_modules/release-v0.27.x/sigstore-c229aaa348 branch from 86dc10d to 9a8f8f8 Compare September 29, 2026 06:50
Bumps the sigstore group with 5 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [github.com/sigstore/sigstore](https://github.com/sigstore/sigstore) | `1.10.9` | `1.10.11` |
| [github.com/sigstore/sigstore/pkg/signature/kms/aws](https://github.com/sigstore/sigstore) | `1.10.9` | `1.10.11` |
| [github.com/sigstore/sigstore/pkg/signature/kms/azure](https://github.com/sigstore/sigstore) | `1.10.9` | `1.10.11` |
| [github.com/sigstore/sigstore/pkg/signature/kms/gcp](https://github.com/sigstore/sigstore) | `1.10.9` | `1.10.11` |
| [github.com/sigstore/sigstore/pkg/signature/kms/hashivault](https://github.com/sigstore/sigstore) | `1.10.9` | `1.10.11` |



Updates `github.com/sigstore/sigstore` from 1.10.9 to 1.10.11
- [Release notes](https://github.com/sigstore/sigstore/releases)
- [Commits](sigstore/sigstore@v1.10.9...v1.10.11)

Updates `github.com/sigstore/sigstore/pkg/signature/kms/aws` from 1.10.9 to 1.10.11
- [Release notes](https://github.com/sigstore/sigstore/releases)
- [Commits](sigstore/sigstore@v1.10.9...v1.10.11)

Updates `github.com/sigstore/sigstore/pkg/signature/kms/azure` from 1.10.9 to 1.10.11
- [Release notes](https://github.com/sigstore/sigstore/releases)
- [Commits](sigstore/sigstore@v1.10.9...v1.10.11)

Updates `github.com/sigstore/sigstore/pkg/signature/kms/gcp` from 1.10.9 to 1.10.11
- [Release notes](https://github.com/sigstore/sigstore/releases)
- [Commits](sigstore/sigstore@v1.10.9...v1.10.11)

Updates `github.com/sigstore/sigstore/pkg/signature/kms/hashivault` from 1.10.9 to 1.10.11
- [Release notes](https://github.com/sigstore/sigstore/releases)
- [Commits](sigstore/sigstore@v1.10.9...v1.10.11)

---
updated-dependencies:
- dependency-name: github.com/sigstore/sigstore
  dependency-version: 1.10.10
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: sigstore
- dependency-name: github.com/sigstore/sigstore/pkg/signature/kms/aws
  dependency-version: 1.10.10
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: sigstore
- dependency-name: github.com/sigstore/sigstore/pkg/signature/kms/azure
  dependency-version: 1.10.10
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: sigstore
- dependency-name: github.com/sigstore/sigstore/pkg/signature/kms/gcp
  dependency-version: 1.10.10
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: sigstore
- dependency-name: github.com/sigstore/sigstore/pkg/signature/kms/hashivault
  dependency-version: 1.10.10
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: sigstore
...

Signed-off-by: dependabot[bot] <[email protected]>
@dependabot
dependabot Bot force-pushed the dependabot/go_modules/release-v0.27.x/sigstore-c229aaa348 branch from 9a8f8f8 to 9625eb6 Compare October 5, 2026 14:19
@tekton-robot tekton-robot added the needs-rebase Indicates a PR cannot be merged because it has merge conflicts with HEAD. label Oct 9, 2026
@tekton-robot

Copy link
Copy Markdown
Contributor

@dependabot: PR needs rebase.

Details

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Used by dependabot - identifies all PRs created by dependabot kind/misc Categorizes issue or PR as a miscellaneuous one. needs-rebase Indicates a PR cannot be merged because it has merge conflicts with HEAD. ok-to-test Indicates a non-member PR verified by an org member that is safe to test. release-note-none Denotes a PR that doesnt merit a release note. size/L Denotes a PR that changes 100-499 lines, ignoring generated files.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants