Skip to content

chore(deps): Bump sigstore/cosign-installer from 3.9.2 to 4.1.1#552

Merged
urunc-bot[bot] merged 1 commit intomainfrom
dependabot/github_actions/sigstore/cosign-installer-4.1.1
Apr 8, 2026
Merged

chore(deps): Bump sigstore/cosign-installer from 3.9.2 to 4.1.1#552
urunc-bot[bot] merged 1 commit intomainfrom
dependabot/github_actions/sigstore/cosign-installer-4.1.1

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot bot commented on behalf of github Apr 2, 2026

Bumps sigstore/cosign-installer from 3.9.2 to 4.1.1.

Release notes

Sourced from sigstore/cosign-installer's releases.

v4.1.1

What's Changed

Full Changelog: sigstore/cosign-installer@v4.1.0...v4.1.1

v4.1.0

What's Changed

We recommend updating as soon as possible as this includes bug fixes for Cosign. We also recommend removing with: cosign-release and strongly discourage using cosign-release unless you have a specific reason to use an older version of Cosign.

Full Changelog: sigstore/cosign-installer@v4.0.0...v4.1.0

v4.0.0

What's Changed?

Note: You must upgrade to cosign-installer v4 if you want to install Cosign v3+. You may still install Cosign v2.x with cosign-installer v4.

In version v3+, using cosign sign-blob requires adding the --bundle flag which may require you to update your signing command.

  • Add support for Cosign v3 releases (#201)

v3.10.1

What's Changed?

Note: cosign-installer v3.x cannot be used to install Cosign v3.x. You must upgrade to cosign-installer v4 in order to use Cosign v3.

Note: This is planned to be the final release of Cosign v2, though we will cut new releases for any critical security or bug fixes. We recommend transitioning to Cosign v3.

  • Bump default Cosign to v2.6.1 (#203)

v3.10.0

What's Changed

Full Changelog: sigstore/cosign-installer@v3.9.2...v3.10.0

Commits

@dependabot dependabot bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Apr 2, 2026
@netlify
Copy link
Copy Markdown

netlify bot commented Apr 2, 2026

Deploy Preview for urunc canceled.

Name Link
🔨 Latest commit 1123188
🔍 Latest deploy log https://app.netlify.com/projects/urunc/deploys/69d65c68f596e700084b259f

Copy link
Copy Markdown
Contributor

@cmainas cmainas left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

It seems it works.

@cmainas cmainas self-requested a review April 8, 2026 06:44
@cmainas
Copy link
Copy Markdown
Contributor

cmainas commented Apr 8, 2026

@dependabot rebase

@dependabot dependabot bot force-pushed the dependabot/github_actions/sigstore/cosign-installer-4.1.1 branch from d8778f4 to b538b1f Compare April 8, 2026 06:45
Bumps [sigstore/cosign-installer](https://github.com/sigstore/cosign-installer) from 3.9.2 to 4.1.1.
- [Release notes](https://github.com/sigstore/cosign-installer/releases)
- [Commits](sigstore/cosign-installer@d58896d...cad07c2)

---
updated-dependencies:
- dependency-name: sigstore/cosign-installer
  dependency-version: 4.1.1
  dependency-type: direct:production
  update-type: version-update:semver-major
...

PR: #552
Signed-off-by: dependabot[bot] <support@github.com>
Reviewed-by: Charalampos Mainas <cmainas@nubificus.co.uk>
Approved-by: Charalampos Mainas <cmainas@nubificus.co.uk>
@github-actions github-actions bot force-pushed the dependabot/github_actions/sigstore/cosign-installer-4.1.1 branch from b538b1f to 1123188 Compare April 8, 2026 13:47
@urunc-bot urunc-bot bot merged commit 24d6103 into main Apr 8, 2026
7 checks passed
@dependabot dependabot bot deleted the dependabot/github_actions/sigstore/cosign-installer-4.1.1 branch April 8, 2026 13:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code ok-to-test

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant