Skip to content

Bump sigstore from 4.1.0 to 4.1.1 in /pulumi - #99

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/pulumi/sigstore-4.1.1
Closed

Bump sigstore from 4.1.0 to 4.1.1 in /pulumi#99
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/pulumi/sigstore-4.1.1

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 31, 2026

Copy link
Copy Markdown
Contributor

Bumps sigstore from 4.1.0 to 4.1.1.

Release notes

Sourced from sigstore's releases.

sigstore@4.1.1

Patch Changes

  • 7845532: Verification of OID certificate extensions
  • f074710: Require inclusion promise in Rekor entry when used as timestamp source
  • Updated dependencies [b5aa4f1]
  • Updated dependencies [7845532]
  • Updated dependencies [f074710]
    • @​sigstore/core@​3.2.1
    • @​sigstore/verify@​3.1.1
Commits

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Jul 31, 2026
@dependabot
dependabot Bot requested a review from minniemeierdev as a code owner July 31, 2026 21:22
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Jul 31, 2026
@github-actions

github-actions Bot commented Jul 31, 2026

Copy link
Copy Markdown

🍹 preview on andymeier/prod

Pulumi report

View in Pulumi Cloud

  Previewing update (prod)

View Live: https://app.pulumi.com/meiermade/andymeier/prod/previews/71270282-de32-4601-8341-3b7c37b9ede5

pulumi:pulumi:Stack: (same)
  [urn=urn:pulumi:prod::andymeier::pulumi:pulumi:Stack::andymeier-prod]
Resources:
  13 unchanged
  

Bumps [sigstore](https://github.com/sigstore/sigstore-js) from 4.1.0 to 4.1.1.
- [Release notes](https://github.com/sigstore/sigstore-js/releases)
- [Commits](https://github.com/sigstore/sigstore-js/compare/sigstore@4.1.0...sigstore@4.1.1)

---
updated-dependencies:
- dependency-name: sigstore
  dependency-version: 4.1.1
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/pulumi/sigstore-4.1.1 branch from c420cc7 to 4929758 Compare July 31, 2026 21:28

@minniemeierdev minniemeierdev left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed this Dependabot update and I’m comfortable approving it.

Evidence:

  • Diff is limited to pulumi/package-lock.json with 17 additions / 17 deletions.
  • The lockfile update bumps sigstore from 4.1.0 to 4.1.1, @sigstore/sign from 4.1.0 to 4.1.1, and @sigstore/tuf from 4.0.1 to 4.0.2; no application or Pulumi program source files changed.
  • Release notes describe patch-level verification hardening: OID certificate extension verification and requiring an inclusion promise when a Rekor entry is used as a timestamp source, plus related sigstore dependency updates.
  • Local validation in /pulumi: npm ci succeeded and npm run check (tsc -p tsconfig.json --noEmit) succeeded.
  • npm audit --package-lock-only improves from 23 findings on main to 22 on this branch and removes the prior sigstore finding; no new audit package names appeared.
  • GitHub checks are green: Test and Preview both completed successfully.

Recommendation: approve and allow normal merge/automerge; no blockers found.

@dependabot @github

dependabot Bot commented on behalf of github Aug 1, 2026

Copy link
Copy Markdown
Contributor Author

Looks like sigstore is up-to-date now, so this is no longer needed.

@dependabot dependabot Bot closed this Aug 1, 2026
@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/pulumi/sigstore-4.1.1 branch August 1, 2026 09:13
@minniemeierdev

Copy link
Copy Markdown

Follow-up after the Dependabot rebase banner: I rechecked the current source of truth.

  • This PR is now closed by Dependabot as no longer needed; the body no longer contains the rebase banner.
  • Head remains 492975879e630376abc8966bc985bbb8d5ce5502, and the diff remains limited to pulumi/package-lock.json.
  • The prior approval was attached to that head and still reflects the diff reviewed; Test and Preview were successful on that head.
  • The prior merge/automerge recommendation is superseded by the PR being closed. Current main already has sigstore 4.1.1, @sigstore/sign 4.1.1, and @sigstore/tuf 4.0.2 in /pulumi, so no merge action is recommended for this closed PR.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant