Skip to content

chore(deps): update sigstore/cosign-installer action to v4.1.0#235

Merged
renovate[bot] merged 1 commit intomainfrom
renovate/sigstore-cosign-installer-4.x
Mar 14, 2026
Merged

chore(deps): update sigstore/cosign-installer action to v4.1.0#235
renovate[bot] merged 1 commit intomainfrom
renovate/sigstore-cosign-installer-4.x

Conversation

@renovate
Copy link

@renovate renovate bot commented Mar 13, 2026

This PR contains the following updates:

Package Type Update Change OpenSSF
sigstore/cosign-installer action minor v4.0.0v4.1.0 OpenSSF Scorecard

Release Notes

sigstore/cosign-installer (sigstore/cosign-installer)

v4.1.0

Compare Source

What's Changed

We recommend updating as soon as possible as this includes bug fixes for Cosign. We also recommend removing with: cosign-release and strongly discourage using cosign-release unless you have a specific reason to use an older version of Cosign.

  • Bump cosign to 3.0.5 in #​220
  • fix: add retry to curl downloads for transient network failures in #​210

Full Changelog: sigstore/cosign-installer@v4.0.0...v4.1.0


Configuration

📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate bot added dependencies Pull requests that update a dependency file deps-minor github_actions Pull requests that update GitHub Actions code labels Mar 13, 2026
@renovate renovate bot merged commit e7ca0a9 into main Mar 14, 2026
11 checks passed
@renovate renovate bot deleted the renovate/sigstore-cosign-installer-4.x branch March 14, 2026 01:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file deps-minor github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants