Script 'mail_helper' called by obssrc
Hello community,

here is the log from the commit of package cosign for openSUSE:Factory checked 
in at 2026-07-18 22:24:25
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Comparing /work/SRC/openSUSE:Factory/cosign (Old)
 and      /work/SRC/openSUSE:Factory/.cosign.new.24530 (New)
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Package is "cosign"

Sat Jul 18 22:24:25 2026 rev:37 rq:1366451 version:3.1.2

Changes:
--------
--- /work/SRC/openSUSE:Factory/cosign/cosign.changes    2026-07-07 
21:09:42.035775131 +0200
+++ /work/SRC/openSUSE:Factory/.cosign.new.24530/cosign.changes 2026-07-18 
22:25:27.243019667 +0200
@@ -1,0 +2,45 @@
+Fri Jul 17 16:02:07 UTC 2026 - Marcus Meissner <[email protected]>
+
+- updated to 3.1.2
+  ## Deprecations
+
+  * Deprecate --payload for sign and verify commands (#4991)
+
+  ## Features
+
+  * docs: add OVHcloud KMS in available external plugins (#4962)
+  * Add insecure registry flag to ko publish in kind-verify-attestation 
workflow (#4970)
+  * Deprecate --output-attestation (#4958)
+  * Add bundle inspect command (#4842)
+
+  ## Fixes
+
+  * Guard against empty certificate PEM in mutate.Signature (#4998)
+  * fix(download): Validate predicate type for new bundle format
+  * Skip nil subject entries in IntotoSubjectClaimVerifier (#5016)
+  * Fix Makefile: fall back to "unknown" version info when built outside a git 
repo (#5000)
+  * fix(verify): skip identity validation for security keys (#5012)
+  * fix: include artifactType in OCI 1.1 signature referrer manifest
+  * Allow attestation download to handle both bundle types (#4996)
+  * Fix panic in dockerfile verify on malformed FROM lines (#4979)
+  * fix(release): restore signing-step auth and fail on image signing errors 
(#4978)
+  * feat(signing-config): add --base-config flag to override services from 
base config (#4977)
+  * fix: pass NewBundleFormat to KeyOpts in sign command (#4981)
+  * fix: ignore build stage references in dockerfile verify (#4961)
+  * fix: allow '=' in annotation values (#4957)
+
+  ## Cleanup
+
+  * Remove unused policy evaluation code (#4936)
+  * Remove unused signing code (#4918)
+  * Remove unused OCI code (#4935)
+  * Remove unused ephemeral signer (#4938)
+
+  ## Documentation
+
+  * feat: improve verify flag shell completions (#4965)
+  * docs: fix Short style and add Example fields to piv-tool subcommands 
(#4942)
+  * docs: add Example fields to env and bundle create commands (#4941)
+  * docs: fix Short style and add Example fields to pkcs11-tool subcommands
+
+-------------------------------------------------------------------

Old:
----
  cosign-3.1.1.tar.gz

New:
----
  cosign-3.1.2.tar.gz

++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Other differences:
------------------
++++++ cosign.spec ++++++
--- /var/tmp/diff_new_pack.vFyT68/_old  2026-07-18 22:25:28.083048037 +0200
+++ /var/tmp/diff_new_pack.vFyT68/_new  2026-07-18 22:25:28.087048173 +0200
@@ -17,7 +17,7 @@
 
 
 Name:           cosign
-Version:        3.1.1
+Version:        3.1.2
 Release:        0
 Summary:        Container Signing, Verification and Storage in an OCI registry
 License:        Apache-2.0

++++++ cosign-3.1.1.tar.gz -> cosign-3.1.2.tar.gz ++++++
++++ 9774 lines of diff (skipped)

++++++ vendor.tar.zst ++++++
/work/SRC/openSUSE:Factory/cosign/vendor.tar.zst 
/work/SRC/openSUSE:Factory/.cosign.new.24530/vendor.tar.zst differ: char 5, 
line 1

Reply via email to