Skip to content

Conversation

@BagToad
Copy link
Member

@BagToad BagToad commented Sep 3, 2025

This bumps sigstore/rekor to v1.4.1 to get a vulnerability fix in the downstream go-chi/chi.

This bumps sigstore/rekor to v1.4.1 to get a vulnerability fix in the downstream go-chi/chi
Copilot AI review requested due to automatic review settings September 3, 2025 03:14
@BagToad BagToad requested a review from a team as a code owner September 3, 2025 03:14
@BagToad BagToad requested a review from babakks September 3, 2025 03:14
Copy link
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull Request Overview

This PR updates the sigstore/rekor dependency from v1.3.10 to v1.4.1 to address a security vulnerability in the downstream go-chi/chi library. The update also includes several related dependency version bumps that are pulled in transitively.

  • Upgrades sigstore/rekor to v1.4.1 for security fix
  • Updates go-chi/chi from v4.1.2+incompatible to v5.2.2 (major version upgrade)
  • Bumps various other dependencies including Google Cloud libraries, OpenTelemetry packages, and gRPC

Tip: Customize your code reviews with copilot-instructions.md. Create the file or learn how to get started.

Copy link
Contributor

@ejahnGithub ejahnGithub left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM!

@BagToad BagToad merged commit e40170b into trunk Sep 3, 2025
13 checks passed
@BagToad BagToad deleted the kw/bump-rekor branch September 3, 2025 15:49
tmeijn pushed a commit to tmeijn/dotfiles that referenced this pull request Sep 12, 2025
This MR contains the following updates:

| Package | Update | Change |
|---|---|---|
| [cli/cli](https://github.com/cli/cli) | minor | `v2.78.0` -> `v2.79.0` |

MR created with the help of [el-capitano/tools/renovate-bot](https://gitlab.com/el-capitano/tools/renovate-bot).

**Proposed changes to behavior should be submitted there as MRs.**

---

### Release Notes

<details>
<summary>cli/cli (cli/cli)</summary>

### [`v2.79.0`](https://github.com/cli/cli/releases/tag/v2.79.0): GitHub CLI 2.79.0

[Compare Source](cli/cli@v2.78.0...v2.79.0)

#### Advanced Issue Search Support

The GitHub CLI now supports advanced issue search syntax using:

- Searching issues: `gh search issues <advanced issue search query>`
- Searching pull requests: `gh search prs <advanced issue search query>`
- While listing issues: `gh issue list --search <advanced issue search query>`
- While listing pull requests: `gh pr list --search <advanced issue search query>`

For more information about advanced issue search syntax, see: "[Filtering and Searching Issues and Merge Requests](https://docs.github.com/en/issues/tracking-your-work-with-issues/using-issues/filtering-and-searching-issues-and-pull-requests#building-advanced-filters-for-issues)"

#### Copy OAuth Code Automatically

The GitHub CLI now supports writing the OAuth one-time pass code to the clipboard automatically during authentication:

- While logging in: `gh auth login --clipboard` / `gh auth login -c`
- While refreshing the token: `gh auth refresh --clipboard` / `gh auth refresh -c`

#### What's Changed

##### ✨ Features

- feat: `gh auth` Automatically copy one-time OAuth code to clipboard by [@&#8203;ankddev](https://github.com/ankddev) in [#&#8203;11518](cli/cli#11518)
- feat: add support for `--ref` in `gh cache delete` by [@&#8203;luxass](https://github.com/luxass) in [#&#8203;11592](cli/cli#11592)
- Use advanced issue search by [@&#8203;babakks](https://github.com/babakks) in [#&#8203;11638](cli/cli#11638)

##### 📚 Docs & Chores

- docs(release create): difference `--generate-notes` and `--notes-from-tag` by [@&#8203;ankddev](https://github.com/ankddev) in [#&#8203;11534](cli/cli#11534)
- refactor tests: use `slices.Equal` to simplify code by [@&#8203;minxinyi](https://github.com/minxinyi) in [#&#8203;11364](cli/cli#11364)
- Remove mention of public preview in trustedroot.go by [@&#8203;jkylekelly](https://github.com/jkylekelly) in [#&#8203;11652](cli/cli#11652)

##### :dependabot: Dependencies

- Bump sigstore/rekor to v1.4.1 by [@&#8203;BagToad](https://github.com/BagToad) in [#&#8203;11654](cli/cli#11654)
- chore(deps): bump actions/stale from 9 to 10 by [@&#8203;dependabot](https://github.com/dependabot)\[bot] in [#&#8203;11663](cli/cli#11663)
- chore(deps): bump actions/setup-go from 5 to 6 by [@&#8203;dependabot](https://github.com/dependabot)\[bot] in [#&#8203;11662](cli/cli#11662)

#### New Contributors

- [@&#8203;minxinyi](https://github.com/minxinyi) made their first contribution in [#&#8203;11364](cli/cli#11364)
- [@&#8203;jkylekelly](https://github.com/jkylekelly) made their first contribution in [#&#8203;11652](cli/cli#11652)
- [@&#8203;luxass](https://github.com/luxass) made their first contribution in [#&#8203;11592](cli/cli#11592)

**Full Changelog**: <cli/cli@v2.78.0...v2.79.0>

</details>

---

### Configuration

📅 **Schedule**: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.

♻ **Rebasing**: Whenever MR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 **Ignore**: Close this MR and you won't be reminded about this update again.

---

 - [ ] <!-- rebase-check -->If you want to rebase/retry this MR, check this box

---

This MR has been generated by [Renovate Bot](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0MS45OC4xIiwidXBkYXRlZEluVmVyIjoiNDEuOTguMSIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOlsiUmVub3ZhdGUgQm90Il19-->
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants