Skip to content

chore(deps): Bump chainguard-dev/cosign from 0.4.2 to 0.4.3#327

Open
dependabot[bot] wants to merge 1 commit intomainfrom
dependabot/terraform/chainguard-dev/cosign-0.4.3
Open

chore(deps): Bump chainguard-dev/cosign from 0.4.2 to 0.4.3#327
dependabot[bot] wants to merge 1 commit intomainfrom
dependabot/terraform/chainguard-dev/cosign-0.4.3

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot Bot commented on behalf of github May 8, 2026

Bumps chainguard-dev/cosign from 0.4.2 to 0.4.3.

Release notes

Sourced from chainguard-dev/cosign's releases.

Release v0.4.3

Changelog

  • 4b882cbe47161aa5cec86c223322d04625803f81 Raise attest predicate size limit from 10 MiB to 32 MiB (#537)
  • fd1f48905a1f6a3b838b459063adde423c3661b0 chore(deps): bump step-security/harden-runner from 2.19.0 to 2.19.1 (#536)
  • 2d8192ab34d2261ea605509596ac43847ca16579 chore(deps): bump github.com/chainguard-dev/terraform-provider-oci from 0.1.3 to 0.1.4 (#534)
  • 518ee99d6c7a3f9f80396c3c7ef0ce3c3cd8c006 chore(deps): bump github.com/secure-systems-lab/go-securesystemslib from 0.10.0 to 0.11.0 (#533)
  • aca2a0253cc9daec2664d9b19c9311ee3d17f919 chore(deps): bump the terraform group across 1 directory with 2 updates (#531)
  • 4329c52cf38784dc303a7c3b857d35bffc85955b chore(deps): bump github.com/in-toto/attestation from 1.1.2 to 1.2.0 (#528)
  • e2a00f71f4dbe5070d96c2df82e2906c29b1e63a chore(deps): bump github.com/sigstore/protobuf-specs from 0.5.0 to 0.5.1 (#527)
  • 92bcae171e037f30b6074a34af64926de9910d7c chore(deps): bump goreleaser/goreleaser-action from 7.1.0 to 7.2.1 (#532)
  • af758564404a87d4d4c7bc8a4bde27de97427792 chore(deps): bump step-security/ghaction-import-gpg from 6.3.1 to 7.0.0 (#529)
  • 2b646bb3d95c6e5786ce13a8cf3b2fd2d642aadb chore(deps): bump github.com/sigstore/cosign/v3 from 3.0.5 to 3.0.6 (#526)
  • bbefb5990ca097173b249e8d1c58be9a32720d3e chore(deps): bump github.com/sigstore/policy-controller from 0.14.1-0.20260320111758-65ad92569d69 to 0.15.1 (#525)
Commits
  • 4b882cb Raise attest predicate size limit from 10 MiB to 32 MiB (#537)
  • fd1f489 chore(deps): bump step-security/harden-runner from 2.19.0 to 2.19.1 (#536)
  • 2d8192a chore(deps): bump github.com/chainguard-dev/terraform-provider-oci from 0.1.3...
  • 518ee99 chore(deps): bump github.com/secure-systems-lab/go-securesystemslib from 0.10...
  • aca2a02 chore(deps): bump the terraform group across 1 directory with 2 updates (#531)
  • 4329c52 chore(deps): bump github.com/in-toto/attestation from 1.1.2 to 1.2.0 (#528)
  • e2a00f7 chore(deps): bump github.com/sigstore/protobuf-specs from 0.5.0 to 0.5.1 (#527)
  • 92bcae1 chore(deps): bump goreleaser/goreleaser-action from 7.1.0 to 7.2.1 (#532)
  • af75856 chore(deps): bump step-security/ghaction-import-gpg from 6.3.1 to 7.0.0 (#529)
  • 2b646bb chore(deps): bump github.com/sigstore/cosign/v3 from 3.0.5 to 3.0.6 (#526)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [chainguard-dev/cosign](https://github.com/chainguard-dev/terraform-provider-cosign) from 0.4.2 to 0.4.3.
- [Release notes](https://github.com/chainguard-dev/terraform-provider-cosign/releases)
- [Commits](chainguard-dev/terraform-provider-cosign@v0.4.2...v0.4.3)

---
updated-dependencies:
- dependency-name: chainguard-dev/cosign
  dependency-version: 0.4.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file terraform Pull requests that update Terraform code labels May 8, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file terraform Pull requests that update Terraform code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants