Script 'mail_helper' called by obssrc Hello community, here is the log from the commit of package cosign for openSUSE:Factory checked in at 2026-07-18 22:24:25 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Comparing /work/SRC/openSUSE:Factory/cosign (Old) and /work/SRC/openSUSE:Factory/.cosign.new.24530 (New) ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "cosign" Sat Jul 18 22:24:25 2026 rev:37 rq:1366451 version:3.1.2 Changes: -------- --- /work/SRC/openSUSE:Factory/cosign/cosign.changes 2026-07-07 21:09:42.035775131 +0200 +++ /work/SRC/openSUSE:Factory/.cosign.new.24530/cosign.changes 2026-07-18 22:25:27.243019667 +0200 @@ -1,0 +2,45 @@ +Fri Jul 17 16:02:07 UTC 2026 - Marcus Meissner <[email protected]> + +- updated to 3.1.2 + ## Deprecations + + * Deprecate --payload for sign and verify commands (#4991) + + ## Features + + * docs: add OVHcloud KMS in available external plugins (#4962) + * Add insecure registry flag to ko publish in kind-verify-attestation workflow (#4970) + * Deprecate --output-attestation (#4958) + * Add bundle inspect command (#4842) + + ## Fixes + + * Guard against empty certificate PEM in mutate.Signature (#4998) + * fix(download): Validate predicate type for new bundle format + * Skip nil subject entries in IntotoSubjectClaimVerifier (#5016) + * Fix Makefile: fall back to "unknown" version info when built outside a git repo (#5000) + * fix(verify): skip identity validation for security keys (#5012) + * fix: include artifactType in OCI 1.1 signature referrer manifest + * Allow attestation download to handle both bundle types (#4996) + * Fix panic in dockerfile verify on malformed FROM lines (#4979) + * fix(release): restore signing-step auth and fail on image signing errors (#4978) + * feat(signing-config): add --base-config flag to override services from base config (#4977) + * fix: pass NewBundleFormat to KeyOpts in sign command (#4981) + * fix: ignore build stage references in dockerfile verify (#4961) + * fix: allow '=' in annotation values (#4957) + + ## Cleanup + + * Remove unused policy evaluation code (#4936) + * Remove unused signing code (#4918) + * Remove unused OCI code (#4935) + * Remove unused ephemeral signer (#4938) + + ## Documentation + + * feat: improve verify flag shell completions (#4965) + * docs: fix Short style and add Example fields to piv-tool subcommands (#4942) + * docs: add Example fields to env and bundle create commands (#4941) + * docs: fix Short style and add Example fields to pkcs11-tool subcommands + +------------------------------------------------------------------- Old: ---- cosign-3.1.1.tar.gz New: ---- cosign-3.1.2.tar.gz ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Other differences: ------------------ ++++++ cosign.spec ++++++ --- /var/tmp/diff_new_pack.vFyT68/_old 2026-07-18 22:25:28.083048037 +0200 +++ /var/tmp/diff_new_pack.vFyT68/_new 2026-07-18 22:25:28.087048173 +0200 @@ -17,7 +17,7 @@ Name: cosign -Version: 3.1.1 +Version: 3.1.2 Release: 0 Summary: Container Signing, Verification and Storage in an OCI registry License: Apache-2.0 ++++++ cosign-3.1.1.tar.gz -> cosign-3.1.2.tar.gz ++++++ ++++ 9774 lines of diff (skipped) ++++++ vendor.tar.zst ++++++ /work/SRC/openSUSE:Factory/cosign/vendor.tar.zst /work/SRC/openSUSE:Factory/.cosign.new.24530/vendor.tar.zst differ: char 5, line 1
