Skip to content

chore(deps): bump the all group across 1 directory with 20 updates - #1910

Merged
tekton-robot merged 1 commit into
release-v0.28.xfrom
dependabot/go_modules/release-v0.28.x/all-91ef13af4b
Aug 26, 2026
Merged

chore(deps): bump the all group across 1 directory with 20 updates#1910
tekton-robot merged 1 commit into
release-v0.28.xfrom
dependabot/go_modules/release-v0.28.x/all-91ef13af4b

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 24, 2026

Copy link
Copy Markdown
Contributor

Bumps the all group with 8 updates in the / directory:

Package From To
github.com/google/go-containerregistry 0.21.7 0.21.9
github.com/secure-systems-lab/go-securesystemslib 0.11.0 0.11.1
github.com/sigstore/cosign/v2 2.6.3 2.6.5
github.com/sigstore/rekor 1.5.2 1.5.4
github.com/tektoncd/pipeline 1.14.0 1.14.1
k8s.io/api 0.36.2 0.36.4
k8s.io/client-go 0.36.2 0.36.4
k8s.io/code-generator 0.36.2 0.36.4

Updates github.com/google/go-containerregistry from 0.21.7 to 0.21.9

Release notes

Sourced from github.com/google/go-containerregistry's releases.

v0.21.9

What's Changed

Full Changelog: google/go-containerregistry@v0.21.8...v0.21.9

v0.21.8

The artifacts attached to this release are missing SLSA provenance, see #2390.

What's Changed

New Contributors

Full Changelog: google/go-containerregistry@v0.21.7...v0.21.8

Commits
  • 7b32099 build(deps): bump the actions group with 3 updates (#2398)
  • 2a4447d fix: remove '.' from unsafe path prefixes (#2400)
  • 43cc3e8 fix: prevent data race on scope refreshes within remote.writer (#2396)
  • 7775aab actions: pin slsa generator version following linter exception (#2395)
  • 2ea098f Bump go version to 1.26.5 (#2388)
  • ec2e586 actions: reformat ALL actions (#2386)
  • ab819b6 actions: fix unformatted action (#2385)
  • eed9a20 actions: update actions to be pinned by hash (#2384)
  • 8a97709 build(deps): bump github.com/moby/moby/client (#2380)
  • d04bf7d tarball: use correct file extension for zstd/uncompressed (#2382)
  • Additional commits viewable in compare view

Updates github.com/secure-systems-lab/go-securesystemslib from 0.11.0 to 0.11.1

Commits
  • 662f0f7 Merge pull request #165 from secure-systems-lab/dependabot/go_modules/github....
  • 0b40db0 chore(deps): bump github.com/stretchr/testify from 1.11.1 to 1.12.0
  • e330185 Merge pull request #166 from secure-systems-lab/dependabot/go_modules/golang....
  • 1778905 chore(deps): bump golang.org/x/crypto from 0.54.0 to 0.55.0
  • 4d3d2c7 Merge pull request #164 from secure-systems-lab/dependabot/github_actions/act...
  • 379ec0d chore(deps): bump actions/checkout from 7.0.0 to 7.0.1
  • efcd6cb Merge pull request #163 from secure-systems-lab/dependabot/github_actions/act...
  • cd018df chore(deps): bump actions/setup-go from 6.5.0 to 7.0.0
  • 5cd75e5 Merge pull request #162 from secure-systems-lab/dependabot/go_modules/golang....
  • 4a8f3f8 chore(deps): bump golang.org/x/crypto from 0.53.0 to 0.54.0
  • Additional commits viewable in compare view

Updates github.com/sigstore/cosign/v2 from 2.6.3 to 2.6.5

Release notes

Sourced from github.com/sigstore/cosign/v2's releases.

v2.6.5

Changelog

This release backports GHSA-fx35-mq7g-6g98 (Verification bypass via public key in legacy bundle) to Cosign v2.6.x.

We strongly encourage folks to continue their migration to the bundle format. The Cosign v3.1.x releases support both formats; the primary change being that the default for signing is the bundle format (although you can specify --new-bundle-format=false to sign with the old format). The verification commands in Cosign v3.1.x support both formats, and will try to detect the format for you for maximum compatibility.

Thanks to all contributors!

v2.6.4

This release is a backport of OCI manifest fixes, and better support for cosign attestation download when you are using a mix of old Cosign signatures with the more recent bundle format.

We strongly encourage folks to continue their migration to the bundle format. The Cosign v3.1.x releases support both formats; the primary change being that the default for signing is the bundle format (although you can specify --new-bundle-format=false to sign with the old format). The verification commands in Cosign v3.1.x support both formats, and will try to detect the format for you for maximum compatibility.

Changelog

  • 26261f05411d5552949ee1d97df1f8e55ec0e13d Allow attestation download to handle both bundle types (#4996) (#5017)
  • d49a0c151125448fc247bb8c367518f46e1c0487 fix: include artifactType in OCI 1.1 signature referrer manifest (cherry-pick PR-4997 to release-2.6) (#5002)

Thanks to all contributors!

Commits

Updates github.com/sigstore/rekor from 1.5.2 to 1.5.4

Release notes

Sourced from github.com/sigstore/rekor's releases.

v1.5.4

Changelog

  • a36bd716fd0d81c314092718f37b53dc26b2af38 add changelog for v1.5.4 release (#2944)
  • 705fc05d8397407872ebce83598c6ab27ef2a13b Apply proactive hardening against malformed requests (GHSA-843x-px86-vq42) (#2945)
  • 5789c38f5cb272e7e41309d44985ce77cf01e56d build(deps): Bump github.com/go-swagger/go-swagger from 0.33.2 to 0.36.4 in /hack/tools in the all group across 1 directory (#2840)
  • 7dd85d3abf008c7d11e1721fc95c6f4f91e5c6a0 better handle connection issues (#2931)
  • a8544a8e30ac73774b52f573c05d8e31844d26dd build(deps): Bump github.com/tink-crypto/tink-go-gcpkms/v2 from 2.2.0 to 2.4.0 (#2939)
  • ee19b41b56d15ac955e2a6fa5d059270d69bd8e6 remove repetitive viper lookups from api endpoints (#2922)
  • f3441b54a6969017e2a4cb111eecca9bf35385a2 move CI containers to GHCR (#2943)
  • d53aa51f4c3960d3b448cac308dc4e416e15671a build(deps): Bump the all group across 1 directory with 3 updates (#2942)
  • 7af1d7c47fb9e893a3295b4a72553d2e9918dda3 build(deps): Bump golang.org/x/crypto from 0.54.0 to 0.55.0 (#2938)
  • ed250aa4865cf653e537fd84d8acc828a3889159 build(deps): Bump cloud.google.com/go/iam from 1.11.0 to 1.13.0 (#2937)
  • 78ba595f16b0bfda5f1e5d7c76c93c260c4d9eef build(deps): Bump gocloud.dev from 0.45.0 to 0.46.0 (#2940)
  • 6a6443e5230980a25a887a861f5c455eac46bf35 build(deps): Bump the all group with 4 updates (#2941)
  • a64a34535a43229d9b18d001f072a64b53a21004 build(deps): Bump google.com/cloudsdktool/google-cloud-cli (#2935)
  • f6fa665db64145e254fb8b6ea2605074e96f946e build(deps): Bump golang from 1.26.5 to 1.26.6 in the all group (#2934)
  • 2309dab576448029c276730735ccb76e5de52036 fix pprof arg (#2932)
  • 5a1909af34d1f25c569d127b9b05530b54f02a05 build(deps): Bump the all group across 1 directory with 6 updates (#2925)
  • d9790726d5be07f40c3e1aa01f7f842b43976a6c build(deps): Bump golang from 3aff665 to 2005724 (#2924)
  • e1564dc41944a9653b79bf98e00b4ddd46919d45 build(deps): Bump github.com/prometheus/client_golang (#2928)
  • a497c02c0a0db1817cdb5d865f84576cca3723b6 build(deps): Bump the all group with 4 updates (#2930)
  • aea3064bdb4fcaa3ec06ee1c66e885fe5dc9073d build(deps): Bump github.com/go-sql-driver/mysql from 1.9.3 to 1.10.0 (#2926)
  • 5486ddaa6db154049646f2cbf4d327145d85eee3 build(deps): Bump go.step.sm/crypto from 0.85.0 to 0.87.0 (#2927)
  • ebd7339c38c08f3ea865f63bc611b84d6d72f1df build(deps): Bump github.com/redis/go-redis/v9 from 9.20.1 to 9.22.0 (#2929)
  • d543a4a664465d8b99507fcd720af86539d5b817 build(deps): Bump google.com/cloudsdktool/google-cloud-cli (#2923)
  • eaa6d5b3d22096c9bfd7458ca66032df4354aee7 build(deps): upgrade grpc-ecosystem/go-grpc-middleware to v2 (#2921)
  • 1665651737fdea7d588a8bd71a2e5577abd2a928 build(deps): Migrate gopkg.in/yaml.v2 to sigs.k8s.io/yaml (#2919)
  • 24394e3bb6cceed5f17fa93972aba21b3e26d0f7 remove unused semver type version map (#2918)
  • 3a9dba1565ad62d20004b6edd62c2997b8c71f5e build(deps): Bump github.com/in-toto/in-toto-golang from 0.9.0 to 0.11.0 (#2823)
  • c4d4150e7fbdd45536cb79b32ced752a0c4a59c8 separate read/write sql traffic for indexservice into separate pools (#2914)
  • 99f7844c567c7f37440882414c30970242f9ecf2 test against valkey (#2916)
  • aef6385ce5132a39b8f9dfe0210e5f2599fef5e9 Change default CLI upload type to hashedrekord (#2885)
  • 1be154f685d656971fe80369cbb4e84ff3233886 fix shadowed err, wrong err label (#2907)
  • 2cdf437463fbfdd0e638c7965b5ca2dcf315f4c5 build(deps): Bump github.com/go-openapi/swag/conv from 0.27.3 to 0.28.0 (#2910)
  • e7730e022c63ac15673d9138059127bb1ff20c23 build(deps): Bump golang.org/x/mod from 0.37.0 to 0.38.0 (#2911)
  • df58502b6ba2e74d9687638ee8094ffd3a908a9d build(deps): Bump google.com/cloudsdktool/google-cloud-cli (#2909)
  • 730fa3757b2bb19efa4967c079a12dd1d2fc1581 build(deps): Bump github.com/go-chi/chi/v5 from 5.2.5 to 5.3.1 (#2912)
  • ace88208974be7481e44f6e849133a3b74e6e4d4 build(deps): Bump the all group with 4 updates (#2913)
  • dfe5a1c485c83b265696c1c9ea4399924d9af154 alpine: hash only the bytes read when computing the control.tar.gz digest (#2908)
  • a8f4a17c5628e2ccca90688086aef6ed87cbb38a Remove unmaintained scripts/createdb.sh dev helper (#2905)
  • 9573f1b131eb20b000f4752233ca63538429c600 test mysql with production dsn strings (#2906)
  • f3299aac1ff4e1c7278bbbde80cde66f279203bc build(deps): Bump golang.org/x/crypto in /hack/tools (#2882)
  • cc5737ee991c30c4b300f464f00a74beb4e18acb build(deps): Bump the all group across 1 directory with 6 updates (#2898)
  • 8485b5d69e1976880d0e6d05765e4489888228d4 build(deps): Bump cloud.google.com/go/pubsub from 1.50.2 to 1.51.0 (#2899)
  • 3d80df7ee97108beb93477477ff0a2411528db79 build(deps): Bump google.com/cloudsdktool/google-cloud-cli (#2897)
  • 09bf9caea7ee3874ac651f3b11375fd8c181b748 create interface for TrillianClient (#2896)
  • 671e78b6fc294999761fbd155e56ae54d1d23b93 build(deps): Bump the all group with 5 updates (#2900)
  • a00d60ef97b6016afe498c430bbd35a62f9b7fab build(deps): Bump go.step.sm/crypto from 0.77.7 to 0.85.0 (#2901)
  • ea4ed74526ad20b1a05e89fa387d03c123beafe1 build(deps): Bump actions/setup-go from 6.5.0 to 7.0.0 (#2902)
  • bde4e86e1e85cfb7ee4d48a7f98c9533051bac22 use more efficient table schema for indexes (#2903)

... (truncated)

Changelog

Sourced from github.com/sigstore/rekor's changelog.

v1.5.4

Features

  • search: add subject field for SAN-based lookup (#2850)
  • Change default CLI upload type to hashedrekord (#2885)
  • separate read/write sql traffic for indexservice into separate pools (#2914)

Bug Fixes

  • better handle connection issues (#2931)
  • fix pprof arg (#2932)
  • fix shadowed err, wrong err label (#2907)
  • alpine: hash only the bytes read when computing the control.tar.gz digest (#2908)
  • return a 400 error for invalid TreeID (#2895)
  • Return the file error instead of the URL error for a missing artifact path (#2872)
  • Apply proactive hardening against malformed requests (#2945)

Improvements

  • remove repetitive viper lookups from api endpoints (#2922)
  • move CI containers to GHCR (#2943)
  • remove unused semver type version map (#2918)
  • test against valkey (#2916)
  • Remove unmaintained scripts/createdb.sh dev helper (#2905)
  • test mysql with production dsn strings (#2906)
  • create interface for TrillianClient (#2896)
  • use more efficient table schema for indexes (#2903)
  • Migrate off deprecated golang.org/x/crypto/openpgp (#2883)
  • minimize duplicative JSON parsing while handling entries (#2880)
  • remove duplicative log entry (#2881)
  • optimize DSSE memory and cpu while parsing and verifying envs (#2879)
  • update builder to use go1.26.4 (#2873)
  • upgrade grpc-ecosystem/go-grpc-middleware to v2 (#2921)
  • Migrate gopkg.in/yaml.v2 to sigs.k8s.io/yaml (#2919)
  • numerous upgraded dependencies

Documentation

  • docs(cli): add usage examples to rekor-cli commands (#2851)

Contributors

  • ahmagdyfb
  • Bob Callaway
  • Carlos Tadeu Panato Junior
  • Chiman Jain
  • Hayden
  • Jason Hall
  • Nikhil J

... (truncated)

Commits
  • a36bd71 add changelog for v1.5.4 release (#2944)
  • 705fc05 Apply proactive hardening against malformed requests (GHSA-843x-px86-vq42) (#...
  • 5789c38 build(deps): Bump github.com/go-swagger/go-swagger from 0.33.2 to 0.36.4 in /...
  • 7dd85d3 better handle connection issues (#2931)
  • a8544a8 build(deps): Bump github.com/tink-crypto/tink-go-gcpkms/v2 from 2.2.0 to 2.4....
  • ee19b41 remove repetitive viper lookups from api endpoints (#2922)
  • f3441b5 move CI containers to GHCR (#2943)
  • d53aa51 build(deps): Bump the all group across 1 directory with 3 updates (#2942)
  • 7af1d7c build(deps): Bump golang.org/x/crypto from 0.54.0 to 0.55.0 (#2938)
  • ed250aa build(deps): Bump cloud.google.com/go/iam from 1.11.0 to 1.13.0 (#2937)
  • Additional commits viewable in compare view

Updates github.com/sigstore/sigstore from 1.10.8 to 1.10.9

Release notes

Sourced from github.com/sigstore/sigstore's releases.

v1.10.9

What's Changed

Note: sigstore/sigstore#2369 deprecates the TUF client. Use the TUF client from sigstore-go instead: https://github.com/sigstore/sigstore-go/tree/main/pkg/tuf

Full Changelog: sigstore/sigstore@v1.10.8...v1.10.9

Commits
  • ee9fe03 Fix Azure KMS support for RSA signatures (#2355)
  • b34fd13 feat(hashivault): token helper tests (#2176)
  • aed7c8b Dependencies updates (#2384)
  • 05a1d97 build(deps): Bump github.com/Azure/azure-sdk-for-go/sdk/security/keyvault/azk...
  • be12908 build(deps): Bump github.com/hashicorp/vault/api (#2351)
  • a8f8715 build(deps): Bump cloud.google.com/go/kms in /pkg/signature/kms/gcp (#2350)
  • d91673d build(deps): Bump github.com/aws/aws-sdk-go-v2/config (#2372)
  • c482e99 build(deps): Bump github.com/Azure/azure-sdk-for-go/sdk/azcore (#2347)
  • 6529cc3 build(deps): Bump github.com/aws/aws-sdk-go-v2/service/kms (#2376)
  • f95e2b7 build(deps): Bump golang.org/x/crypto in /pkg/signature/kms/azure (#2377)
  • Additional commits viewable in compare view

Updates github.com/sigstore/sigstore/pkg/signature/kms/aws from 1.10.8 to 1.10.9

Release notes

Sourced from github.com/sigstore/sigstore/pkg/signature/kms/aws's releases.

v1.10.9

What's Changed

Note: sigstore/sigstore#2369 deprecates the TUF client. Use the TUF client from sigstore-go instead: https://github.com/sigstore/sigstore-go/tree/main/pkg/tuf

Full Changelog: sigstore/sigstore@v1.10.8...v1.10.9

Commits
  • ee9fe03 Fix Azure KMS support for RSA signatures (#2355)
  • b34fd13 feat(hashivault): token helper tests (#2176)
  • aed7c8b Dependencies updates (#2384)
  • 05a1d97 build(deps): Bump github.com/Azure/azure-sdk-for-go/sdk/security/keyvault/azk...
  • be12908 build(deps): Bump github.com/hashicorp/vault/api (#2351)
  • a8f8715 build(deps): Bump cloud.google.com/go/kms in /pkg/signature/kms/gcp (#2350)
  • d91673d build(deps): Bump github.com/aws/aws-sdk-go-v2/config (#2372)
  • c482e99 build(deps): Bump github.com/Azure/azure-sdk-for-go/sdk/azcore (#2347)
  • 6529cc3 build(deps): Bump github.com/aws/aws-sdk-go-v2/service/kms (#2376)
  • f95e2b7 build(deps): Bump golang.org/x/crypto in /pkg/signature/kms/azure (#2377)
  • Additional commits viewable in compare view

Updates github.com/sigstore/sigstore/pkg/signature/kms/azure from 1.10.8 to 1.10.9

Release notes

Sourced from github.com/sigstore/sigstore/pkg/signature/kms/azure's releases.

v1.10.9

What's Changed

Note: sigstore/sigstore#2369 deprecates the TUF client. Use the TUF client from sigstore-go instead: https://github.com/sigstore/sigstore-go/tree/main/pkg/tuf

Full Changelog: sigstore/sigstore@v1.10.8...v1.10.9

Commits
  • ee9fe03 Fix Azure KMS support for RSA signatures (#2355)
  • b34fd13 feat(hashivault): token helper tests (#2176)
  • aed7c8b Dependencies updates (#2384)
  • 05a1d97 build(deps): Bump github.com/Azure/azure-sdk-for-go/sdk/security/keyvault/azk...
  • be12908 build(deps): Bump github.com/hashicorp/vault/api (#2351)
  • a8f8715 build(deps): Bump cloud.google.com/go/kms in /pkg/signature/kms/gcp (#2350)
  • d91673d build(deps): Bump github.com/aws/aws-sdk-go-v2/config (#2372)
  • c482e99 build(deps): Bump github.com/Azure/azure-sdk-for-go/sdk/azcore (#2347)
  • 6529cc3 build(deps): Bump github.com/aws/aws-sdk-go-v2/service/kms (#2376)
  • f95e2b7 build(deps): Bump golang.org/x/crypto in /pkg/signature/kms/azure (#2377)
  • Additional commits viewable in compare view

Updates github.com/sigstore/sigstore/pkg/signature/kms/gcp from 1.10.8 to 1.10.9

Release notes

Sourced from github.com/sigstore/sigstore/pkg/signature/kms/gcp's releases.

v1.10.9

What's Changed

Note: sigstore/sigstore#2369 deprecates the TUF client. Use the TUF client from sigstore-go instead: https://github.com/sigstore/sigstore-go/tree/main/pkg/tuf

Full Changelog: sigstore/sigstore@v1.10.8...v1.10.9

Commits
  • ee9fe03 Fix Azure KMS support for RSA signatures (#2355)
  • b34fd13 feat(hashivault): token helper tests (#2176)
  • aed7c8b Dependencies updates (#2384)
  • 05a1d97 build(deps): Bump github.com/Azure/azure-sdk-for-go/sdk/security/keyvault/azk...
  • be12908 build(deps): Bump github.com/hashicorp/vault/api (#2351)
  • a8f8715 build(deps): Bump cloud.google.com/go/kms in /pkg/signature/kms/gcp (#2350)
  • d91673d build(deps): Bump github.com/aws/aws-sdk-go-v2/config (#2372)
  • c482e99 build(deps): Bump github.com/Azure/azure-sdk-for-go/sdk/azcore (#2347)
  • 6529cc3 build(deps): Bump github.com/aws/aws-sdk-go-v2/service/kms (#2376)
  • f95e2b7 build(deps): Bump golang.org/x/crypto in /pkg/signature/kms/azure (#2377)
  • Additional commits viewable in compare view

Updates github.com/sigstore/sigstore/pkg/signature/kms/hashivault from 1.10.8 to 1.10.9

Release notes

Sourced from github.com/sigstore/sigstore/pkg/signature/kms/hashivault's releases.

v1.10.9

What's Changed

Note: sigstore/sigstore#2369 deprecates the TUF client. Use the TUF client from sigstore-go instead: https://github.com/sigstore/sigstore-go/tree/main/pkg/tuf

Full Changelog: sigstore/sigstore@v1.10.8...v1.10.9

Commits
  • ee9fe03 Fix Azure KMS support for RSA signatures (#2355)
  • b34fd13 feat(hashivault): token helper tests (#2176)
  • aed7c8b Dependencies updates (#2384)
  • 05a1d97 build(deps): Bump github.com/Azure/azure-sdk-for-go/sdk/security/keyvault/azk...
  • be12908 build(deps): Bump github.com/hashicorp/vault/api (#2351)
  • a8f8715 build(deps): Bump cloud.google.com/go/kms in /pkg/signature/kms/gcp (#2350)
  • d91673d build(deps): Bump github.com/aws/aws-sdk-go-v2/config (#2372)
  • c482e99 build(deps): Bump github.com/Azure/azure-sdk-for-go/sdk/azcore (#2347)
  • 6529cc3 build(deps): Bump github.com/aws/aws-sdk-go-v2/service/kms (#2376)
  • f95e2b7 build(deps): Bump golang.org/x/crypto in /pkg/signature/kms/azure (#2377)
  • Additional commits viewable in compare view

Updates github.com/stretchr/testify from 1.11.1 to 1.12.0

Release notes

Sourced from github.com/stretchr/testify's releases.

v1.12.0

What's Changed

Functional Changes

Fixes

Documentation, Build & CI

New Contributors

Bumps the all group with 8 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [github.com/google/go-containerregistry](https://github.com/google/go-containerregistry) | `0.21.7` | `0.21.9` |
| [github.com/secure-systems-lab/go-securesystemslib](https://github.com/secure-systems-lab/go-securesystemslib) | `0.11.0` | `0.11.1` |
| [github.com/sigstore/cosign/v2](https://github.com/sigstore/cosign) | `2.6.3` | `2.6.5` |
| [github.com/sigstore/rekor](https://github.com/sigstore/rekor) | `1.5.2` | `1.5.4` |
| [github.com/tektoncd/pipeline](https://github.com/tektoncd/pipeline) | `1.14.0` | `1.14.1` |
| [k8s.io/api](https://github.com/kubernetes/api) | `0.36.2` | `0.36.4` |
| [k8s.io/client-go](https://github.com/kubernetes/client-go) | `0.36.2` | `0.36.4` |
| [k8s.io/code-generator](https://github.com/kubernetes/code-generator) | `0.36.2` | `0.36.4` |



Updates `github.com/google/go-containerregistry` from 0.21.7 to 0.21.9
- [Release notes](https://github.com/google/go-containerregistry/releases)
- [Commits](google/go-containerregistry@v0.21.7...v0.21.9)

Updates `github.com/secure-systems-lab/go-securesystemslib` from 0.11.0 to 0.11.1
- [Release notes](https://github.com/secure-systems-lab/go-securesystemslib/releases)
- [Commits](secure-systems-lab/go-securesystemslib@v0.11.0...v0.11.1)

Updates `github.com/sigstore/cosign/v2` from 2.6.3 to 2.6.5
- [Release notes](https://github.com/sigstore/cosign/releases)
- [Changelog](https://github.com/sigstore/cosign/blob/main/CHANGELOG.md)
- [Commits](sigstore/cosign@v2.6.3...v2.6.5)

Updates `github.com/sigstore/rekor` from 1.5.2 to 1.5.4
- [Release notes](https://github.com/sigstore/rekor/releases)
- [Changelog](https://github.com/sigstore/rekor/blob/main/CHANGELOG.md)
- [Commits](sigstore/rekor@v1.5.2...v1.5.4)

Updates `github.com/sigstore/sigstore` from 1.10.8 to 1.10.9
- [Release notes](https://github.com/sigstore/sigstore/releases)
- [Commits](sigstore/sigstore@v1.10.8...v1.10.9)

Updates `github.com/sigstore/sigstore/pkg/signature/kms/aws` from 1.10.8 to 1.10.9
- [Release notes](https://github.com/sigstore/sigstore/releases)
- [Commits](sigstore/sigstore@v1.10.8...v1.10.9)

Updates `github.com/sigstore/sigstore/pkg/signature/kms/azure` from 1.10.8 to 1.10.9
- [Release notes](https://github.com/sigstore/sigstore/releases)
- [Commits](sigstore/sigstore@v1.10.8...v1.10.9)

Updates `github.com/sigstore/sigstore/pkg/signature/kms/gcp` from 1.10.8 to 1.10.9
- [Release notes](https://github.com/sigstore/sigstore/releases)
- [Commits](sigstore/sigstore@v1.10.8...v1.10.9)

Updates `github.com/sigstore/sigstore/pkg/signature/kms/hashivault` from 1.10.8 to 1.10.9
- [Release notes](https://github.com/sigstore/sigstore/releases)
- [Commits](sigstore/sigstore@v1.10.8...v1.10.9)

Updates `github.com/stretchr/testify` from 1.11.1 to 1.12.0
- [Release notes](https://github.com/stretchr/testify/releases)
- [Commits](stretchr/testify@v1.11.1...v1.12.0)

Updates `github.com/tektoncd/pipeline` from 1.14.0 to 1.14.1
- [Release notes](https://github.com/tektoncd/pipeline/releases)
- [Changelog](https://github.com/tektoncd/pipeline/blob/main/releases.md)
- [Commits](tektoncd/pipeline@v1.14.0...v1.14.1)

Updates `go.opentelemetry.io/otel/sdk/metric` from 1.43.0 to 1.44.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-go/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-go/blob/main/CHANGELOG.md)
- [Commits](open-telemetry/opentelemetry-go@v1.43.0...v1.44.0)

Updates `gocloud.dev` from 0.45.0 to 0.46.0
- [Release notes](https://github.com/google/go-cloud/releases)
- [Commits](google/go-cloud@v0.45.0...v0.46.0)

Updates `golang.org/x/crypto` from 0.53.0 to 0.55.0
- [Commits](golang/crypto@v0.53.0...v0.55.0)

Updates `google.golang.org/grpc` from 1.82.0 to 1.82.1
- [Release notes](https://github.com/grpc/grpc-go/releases)
- [Commits](grpc/grpc-go@v1.82.0...v1.82.1)

Updates `google.golang.org/protobuf` from 1.36.12-0.20260120151049-f2248ac996af to 1.36.12

Updates `k8s.io/api` from 0.36.2 to 0.36.4
- [Commits](kubernetes/api@v0.36.2...v0.36.4)

Updates `k8s.io/apimachinery` from 0.36.2 to 0.36.4
- [Commits](kubernetes/apimachinery@v0.36.2...v0.36.4)

Updates `k8s.io/client-go` from 0.36.2 to 0.36.4
- [Changelog](https://github.com/kubernetes/client-go/blob/master/CHANGELOG.md)
- [Commits](kubernetes/client-go@v0.36.2...v0.36.4)

Updates `k8s.io/code-generator` from 0.36.2 to 0.36.4
- [Commits](kubernetes/code-generator@v0.36.2...v0.36.4)

---
updated-dependencies:
- dependency-name: github.com/google/go-containerregistry
  dependency-version: 0.21.9
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all
- dependency-name: github.com/secure-systems-lab/go-securesystemslib
  dependency-version: 0.11.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all
- dependency-name: github.com/sigstore/cosign/v2
  dependency-version: 2.6.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all
- dependency-name: github.com/sigstore/rekor
  dependency-version: 1.5.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all
- dependency-name: github.com/sigstore/sigstore
  dependency-version: 1.10.9
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all
- dependency-name: github.com/sigstore/sigstore/pkg/signature/kms/aws
  dependency-version: 1.10.9
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all
- dependency-name: github.com/sigstore/sigstore/pkg/signature/kms/azure
  dependency-version: 1.10.9
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all
- dependency-name: github.com/sigstore/sigstore/pkg/signature/kms/gcp
  dependency-version: 1.10.9
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all
- dependency-name: github.com/sigstore/sigstore/pkg/signature/kms/hashivault
  dependency-version: 1.10.9
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all
- dependency-name: github.com/stretchr/testify
  dependency-version: 1.12.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all
- dependency-name: github.com/tektoncd/pipeline
  dependency-version: 1.14.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all
- dependency-name: go.opentelemetry.io/otel/sdk/metric
  dependency-version: 1.44.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all
- dependency-name: gocloud.dev
  dependency-version: 0.46.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all
- dependency-name: golang.org/x/crypto
  dependency-version: 0.55.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all
- dependency-name: google.golang.org/grpc
  dependency-version: 1.82.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all
- dependency-name: google.golang.org/protobuf
  dependency-version: 1.36.12
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all
- dependency-name: k8s.io/api
  dependency-version: 0.36.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all
- dependency-name: k8s.io/apimachinery
  dependency-version: 0.36.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all
- dependency-name: k8s.io/client-go
  dependency-version: 0.36.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all
- dependency-name: k8s.io/code-generator
  dependency-version: 0.36.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Used by dependabot - identifies all PRs created by dependabot kind/misc Categorizes issue or PR as a miscellaneuous one. ok-to-test Indicates a non-member PR verified by an org member that is safe to test. release-note-none Denotes a PR that doesnt merit a release note. labels Aug 24, 2026
@tekton-robot tekton-robot added the size/XL Denotes a PR that changes 500-999 lines, ignoring generated files. label Aug 24, 2026

@infernus01 infernus01 left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

/lgtm

@tekton-robot tekton-robot added the lgtm Indicates that a PR is ready to be merged. label Aug 25, 2026
@tekton-robot

Copy link
Copy Markdown
Contributor

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: anithapriyanatarajan

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Details Needs approval from an approver in each of these files:
  • OWNERS [anithapriyanatarajan]

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@tekton-robot tekton-robot added the approved Indicates a PR has been approved by an approver from all required OWNERS files. label Aug 26, 2026
@tekton-robot
tekton-robot merged commit 360dec0 into release-v0.28.x Aug 26, 2026
11 checks passed
@dependabot
dependabot Bot deleted the dependabot/go_modules/release-v0.28.x/all-91ef13af4b branch August 26, 2026 06:26
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

approved Indicates a PR has been approved by an approver from all required OWNERS files. dependencies Used by dependabot - identifies all PRs created by dependabot kind/misc Categorizes issue or PR as a miscellaneuous one. lgtm Indicates that a PR is ready to be merged. ok-to-test Indicates a non-member PR verified by an org member that is safe to test. release-note-none Denotes a PR that doesnt merit a release note. size/XL Denotes a PR that changes 500-999 lines, ignoring generated files.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants