Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

deps: bump sigstore from 1.7.0 to 2.0.0 #6722

Merged
merged 1 commit into from
Aug 18, 2023

Conversation

bdehamer
Copy link
Contributor

NOTE: This was branched from lk/npm-10-deps

Bumps sigstore to v2.0.0. The packages exports were altered in this release, so there are some minor code changes which accompany this version bump.

Also, the TUF-related functions previously exported from the sigstore package were removed. They're now exposed in the @sigstore/tuf package so the audit command was updated to import the TUF client from this new package.

@bdehamer bdehamer requested a review from a team as a code owner August 18, 2023 17:19
Copy link
Member

@wraithgar wraithgar left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good. I'll let @lukekarrys merge since it's against his PR branch

@lukekarrys lukekarrys merged commit 54a2535 into lk/npm-10-deps Aug 18, 2023
@lukekarrys lukekarrys deleted the bdehamer/sigstore-v2 branch August 18, 2023 18:31
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants