123.json (3359B)
1 { 2 "number": 123, 3 "title": "chore(deps): update sigstore/cosign-installer action to v4 - autoclosed", 4 "state": "closed", 5 "diff_file": "123.diff", 6 "author": "renovate[bot]", 7 "created_at": "2026-03-25T20:18:03Z", 8 "closed_at": "2026-03-25T23:09:16Z", 9 "merged_at": null, 10 "base_ref": "main", 11 "head_ref": "renovate/major-github-actions", 12 "labels": [ 13 "type/major-update" 14 ], 15 "assignees": [], 16 "requested_reviewers": [], 17 "body": "This PR contains the following updates:\n\n| Package | Type | Update | Change |\n|---|---|---|---|\n| [sigstore/cosign-installer](https://redirect.github.com/sigstore/cosign-installer) | action | major | `v3.10.1` \u2192 `v4.1.0` |\n\n---\n\n### Release Notes\n\n<details>\n<summary>sigstore/cosign-installer (sigstore/cosign-installer)</summary>\n\n### [`v4.1.0`](https://redirect.github.com/sigstore/cosign-installer/releases/tag/v4.1.0)\n\n[Compare Source](https://redirect.github.com/sigstore/cosign-installer/compare/v4.0.0...v4.1.0)\n\n#### What's Changed\n\nWe recommend updating as soon as possible as this includes bug fixes for Cosign. We also recommend removing `with: cosign-release` and strongly discourage using `cosign-release` unless you have a specific reason to use an older version of Cosign.\n\n- Bump cosign to 3.0.5 in [#​220](https://redirect.github.com/sigstore/cosign-installer/pull/220)\n- fix: add retry to curl downloads for transient network failures in [#​210](https://redirect.github.com/sigstore/cosign-installer/pull/210)\n\n**Full Changelog**: <https://github.com/sigstore/cosign-installer/compare/v4.0.0...v4.1.0>\n\n### [`v4.0.0`](https://redirect.github.com/sigstore/cosign-installer/releases/tag/v4.0.0)\n\n[Compare Source](https://redirect.github.com/sigstore/cosign-installer/compare/v3.10.1...v4.0.0)\n\n#### What's Changed?\n\n**Note:** You must upgrade to cosign-installer v4 if you want to install [Cosign v3+](https://blog.sigstore.dev/cosign-3-0-available/). You may still install Cosign v2.x with cosign-installer v4.\n\nIn version v3+, using `cosign sign-blob` requires adding the `--bundle` flag which may require you to update your signing command.\n\n- Add support for Cosign v3 releases ([#​201](https://redirect.github.com/sigstore/cosign-installer/issues/201))\n\n</details>\n\n---\n\n### Configuration\n\n\ud83d\udcc5 **Schedule**: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).\n\n\ud83d\udea6 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.\n\n\u267b **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.\n\n\ud83d\udd15 **Ignore**: Close this PR and you won't be reminded about this update again.\n\n---\n\n - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box\n\n---\n\nThis PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/MTRNord/cluster).\n<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My42Ni40IiwidXBkYXRlZEluVmVyIjoiNDMuNjYuNCIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOlsidHlwZS9tYWpvci11cGRhdGUiXX0=-->\n", 18 "comments": [ 19 { 20 "author": "MTRNord", 21 "created_at": "2026-03-25T22:52:54Z", 22 "body": "Blocked on zot support for the newer format :(" 23 } 24 ], 25 "review_comments": [] 26 }