Skip to content

chore(deps): update sigstore/cosign-installer action to v4.1.1#240

Merged
renovate[bot] merged 1 commit intomainfrom
renovate/sigstore-cosign-installer-4.x
Mar 30, 2026
Merged

chore(deps): update sigstore/cosign-installer action to v4.1.1#240
renovate[bot] merged 1 commit intomainfrom
renovate/sigstore-cosign-installer-4.x

Conversation

@renovate
Copy link
Copy Markdown

@renovate renovate bot commented Mar 30, 2026

This PR contains the following updates:

Package Type Update Change OpenSSF
sigstore/cosign-installer action patch v4.1.0v4.1.1 OpenSSF Scorecard

Release Notes

sigstore/cosign-installer (sigstore/cosign-installer)

v4.1.1

Compare Source

What's Changed
  • chore: update default cosign-release to v3.0.5 in #​223

Full Changelog: sigstore/cosign-installer@v4.1.0...v4.1.1


Configuration

📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate bot added dependencies Pull requests that update a dependency file deps-patch github_actions Pull requests that update GitHub Actions code labels Mar 30, 2026
@renovate renovate bot merged commit 4ce25e5 into main Mar 30, 2026
11 checks passed
@renovate renovate bot deleted the renovate/sigstore-cosign-installer-4.x branch March 30, 2026 20:45
github-actions bot pushed a commit that referenced this pull request Apr 7, 2026
## [6.5.0](v6.4.1...v6.5.0) (2026-04-07)

### Features

* **ci:** switch to RenovateBot ([#194](#194)) ([4cd71a4](4cd71a4))

### Bug Fixes

* add issues write permission to Docker Security Scan workflow ([fe21b44](fe21b44))
* **ci:** Fix docker scan reference issues ([d737cd4](d737cd4))
* **ci:** Fix yaml indentation ([d3a47fd](d3a47fd))
* **ci:** handle missing Docker images in security scan workflow ([#191](#191)) ([c97ab2e](c97ab2e))
* replace pkg_resources with importlib.resources for Python 3.14 compat ([f9f6f22](f9f6f22))

### Tests

* add smoke test for app entrypoint imports ([c55316c](c55316c))

### Continuous Integration

* change release workflow to manual trigger ([069149e](069149e))

### Chores

* **ci:** add package rules for dependency update types ([8696a3e](8696a3e))
* **ci:** change label to addLabels for GitHub Actions ([9b6e57f](9b6e57f))
* **ci:** change matchDatasources to matchManagers in renovate.json ([df59e8c](df59e8c))
* **deps:** bump actions/checkout from 5 to 6 ([a9e3017](a9e3017))
* **deps:** bump actions/download-artifact from 4 to 6 ([17c2932](17c2932))
* **deps:** bump actions/download-artifact from 6 to 7 ([4e1bf45](4e1bf45))
* **deps:** bump actions/download-artifact from 7 to 8 ([9a78b38](9a78b38))
* **deps:** bump actions/github-script from 7 to 8 ([99adb09](99adb09))
* **deps:** bump actions/setup-python from 5 to 6 ([7d3977c](7d3977c))
* **deps:** bump actions/upload-artifact from 4 to 5 ([d6c0f14](d6c0f14))
* **deps:** bump actions/upload-artifact from 5 to 6 ([63c464f](63c464f))
* **deps:** bump actions/upload-artifact from 6 to 7 ([9bb3285](9bb3285))
* **deps:** bump cycjimmy/semantic-release-action from 4 to 5 ([a9871be](a9871be))
* **deps:** bump cycjimmy/semantic-release-action from 5.0.2 to 6.0.0 ([6dd5941](6dd5941))
* **deps:** bump docker/build-push-action from 6 to 7 ([82c78ce](82c78ce))
* **deps:** bump docker/login-action from 3 to 4 ([6a941e4](6a941e4))
* **deps:** bump docker/metadata-action from 5 to 6 ([b909f83](b909f83))
* **deps:** bump docker/setup-buildx-action from 3 to 4 ([8e39072](8e39072))
* **deps:** bump github/codeql-action from 3 to 4 ([16744b2](16744b2))
* **deps:** bump pygments from 2.19.2 to 2.20.0 ([3ef539a](3ef539a))
* **deps:** bump requests from 2.32.5 to 2.33.0 ([3e8bcd8](3e8bcd8))
* **deps:** bump tornado from 6.5.2 to 6.5.5 ([b22a963](b22a963))
* **deps:** bump urllib3 from 2.5.0 to 2.6.3 ([576ca3f](576ca3f))
* **deps:** pin dependencies ([6082802](6082802))
* **deps:** renovate config — semantic commits, labels, pin github-actions, automerge minor+ ([5faf6d6](5faf6d6))
* **deps:** update actions/checkout action to v5 ([48154fb](48154fb))
* **deps:** update actions/checkout action to v5.0.1 ([#207](#207)) ([d224efb](d224efb))
* **deps:** update actions/dependency-review-action action to v4.8.2 ([#196](#196)) ([9af1de5](9af1de5))
* **deps:** update actions/dependency-review-action action to v4.8.3 ([#222](#222)) ([ba60e44](ba60e44))
* **deps:** update actions/dependency-review-action action to v4.9.0 ([#227](#227)) ([994fcaf](994fcaf))
* **deps:** update actions/setup-node action to v6 ([e6af6dd](e6af6dd))
* **deps:** update amannn/action-semantic-pull-request action to v6 ([af4a16c](af4a16c))
* **deps:** update astral-sh/setup-uv action to v7 ([96797d7](96797d7))
* **deps:** update cycjimmy/semantic-release-action action to v5.0.2 ([#206](#206)) ([8c8347f](8c8347f))
* **deps:** update dependency node to v24 ([3dc2802](3dc2802))
* **deps:** update dependency node to v24.12.0 ([#214](#214)) ([d31a06e](d31a06e))
* **deps:** update dependency node to v24.13.0 ([#216](#216)) ([2b2e97c](2b2e97c))
* **deps:** update dependency node to v24.13.1 ([#220](#220)) ([1d79820](1d79820))
* **deps:** update dependency node to v24.14.0 ([#223](#223)) ([3c8deb2](3c8deb2))
* **deps:** update dependency node to v24.14.1 ([#238](#238)) ([ded2b6d](ded2b6d))
* **deps:** update dependency python to v3.14.1 ([#210](#210)) ([e32b494](e32b494))
* **deps:** update dependency python to v3.14.2 ([#211](#211)) ([4528ffa](4528ffa))
* **deps:** update dependency python to v3.14.3 ([#219](#219)) ([f1e8640](f1e8640))
* **deps:** update sigstore/cosign-installer action to v4.1.0 ([#235](#235)) ([e7ca0a9](e7ca0a9))
* **deps:** update sigstore/cosign-installer action to v4.1.1 ([#240](#240)) ([4ce25e5](4ce25e5))
@github-actions
Copy link
Copy Markdown

github-actions bot commented Apr 7, 2026

🎉 This PR is included in version 6.5.0 🎉

The release is available on GitHub release

Your semantic-release bot 📦🚀

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file deps-patch github_actions Pull requests that update GitHub Actions code released

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants