Skip to content

[release-v0.42.x] bump github.com/sigstore/cosign/v2 from 2.6.4 to 2.6.5 - #3116

Merged
tekton-robot merged 1 commit into
release-v0.42.xfrom
dependabot/go_modules/release-v0.42.x/github.com/sigstore/cosign/v2-2.6.5
Aug 14, 2026
Merged

[release-v0.42.x] bump github.com/sigstore/cosign/v2 from 2.6.4 to 2.6.5#3116
tekton-robot merged 1 commit into
release-v0.42.xfrom
dependabot/go_modules/release-v0.42.x/github.com/sigstore/cosign/v2-2.6.5

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 11, 2026

Copy link
Copy Markdown
Contributor

Bumps github.com/sigstore/cosign/v2 from 2.6.4 to 2.6.5.

Release notes

Sourced from github.com/sigstore/cosign/v2's releases.

v2.6.5

Changelog

This release backports GHSA-fx35-mq7g-6g98 (Verification bypass via public key in legacy bundle) to Cosign v2.6.x.

We strongly encourage folks to continue their migration to the bundle format. The Cosign v3.1.x releases support both formats; the primary change being that the default for signing is the bundle format (although you can specify --new-bundle-format=false to sign with the old format). The verification commands in Cosign v3.1.x support both formats, and will try to detect the format for you for maximum compatibility.

Thanks to all contributors!

Commits

@dependabot dependabot Bot added dependencies Used by dependabot - identifies all PRs created by dependabot kind/misc Categorizes issue or PR as a miscellaneuous one. ok-to-test Indicates a non-member PR verified by an org member that is safe to test. release-note-none Denotes a PR that doesnt merit a release note. labels Aug 11, 2026
@tekton-robot tekton-robot added the size/S Denotes a PR that changes 10-29 lines, ignoring generated files. label Aug 11, 2026
@dependabot
dependabot Bot force-pushed the dependabot/go_modules/release-v0.42.x/github.com/sigstore/cosign/v2-2.6.5 branch from a59c398 to d750bdb Compare August 14, 2026 09:35
Bumps [github.com/sigstore/cosign/v2](https://github.com/sigstore/cosign) from 2.6.4 to 2.6.5.
- [Release notes](https://github.com/sigstore/cosign/releases)
- [Changelog](https://github.com/sigstore/cosign/blob/main/CHANGELOG.md)
- [Commits](sigstore/cosign@v2.6.4...v2.6.5)

---
updated-dependencies:
- dependency-name: github.com/sigstore/cosign/v2
  dependency-version: 2.6.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/go_modules/release-v0.42.x/github.com/sigstore/cosign/v2-2.6.5 branch from d750bdb to cbf5525 Compare August 14, 2026 10:03

@divyansh42 divyansh42 left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

/lgtm

@tekton-robot tekton-robot added the lgtm Indicates that a PR is ready to be merged. label Aug 14, 2026
@tekton-robot

Copy link
Copy Markdown
Contributor

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: divyansh42

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@tekton-robot tekton-robot added the approved Indicates a PR has been approved by an approver from all required OWNERS files. label Aug 14, 2026
@tekton-robot
tekton-robot merged commit 0bf39c3 into release-v0.42.x Aug 14, 2026
18 of 20 checks passed
@dependabot
dependabot Bot deleted the dependabot/go_modules/release-v0.42.x/github.com/sigstore/cosign/v2-2.6.5 branch August 14, 2026 13:48
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

approved Indicates a PR has been approved by an approver from all required OWNERS files. dependencies Used by dependabot - identifies all PRs created by dependabot kind/misc Categorizes issue or PR as a miscellaneuous one. lgtm Indicates that a PR is ready to be merged. ok-to-test Indicates a non-member PR verified by an org member that is safe to test. release-note-none Denotes a PR that doesnt merit a release note. size/S Denotes a PR that changes 10-29 lines, ignoring generated files.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants