chore(deps): bump sigstore/scaffolding from 0.7.24 to 0.7.29
Bumps sigstore/scaffolding from 0.7.24 to 0.7.29.
Release notes
Sourced from sigstore/scaffolding's releases.
v0.7.29
What's Changed
This release reverts a previous change to the prober to allow for insecure gRPC connections, in favor of allowing for gRPC testing to be disabled.
- Allow disabling Fulcio gRPC testing via flag in sigstore/scaffolding#1787
Full Changelog: https://github.com/sigstore/scaffolding/compare/v0.7.28...v0.7.29
v0.7.28
What's Changed
- Allow insecure transport for Fulcio gRPC requests to be configured by flag in sigstore/scaffolding#1786
Full Changelog: https://github.com/sigstore/scaffolding/compare/v0.7.27...v0.7.28
v0.7.27
What's Changed
- fix: Adjust Fulcio gRPC URL handling for internal services in sigstore/scaffolding#1774
Full Changelog: https://github.com/sigstore/scaffolding/compare/v0.7.26...v0.7.27
v0.7.26
What's Changed
- Build GCP omniwitness on release in sigstore/scaffolding#1775
Full Changelog: https://github.com/sigstore/scaffolding/compare/v0.7.25...v0.7.26
v0.7.25
What's Changed
- Bump github.com/go-viper/mapstructure/v2 from 2.2.1 to 2.3.0 by
@dependabot[bot] in sigstore/scaffolding#1617- update docs and clean up scripts by
@cpanatoin sigstore/scaffolding#1624- Parallelize service setup by
@cmurphyin sigstore/scaffolding#1618- Bump github/codeql-action from 3.29.0 to 3.29.2 by
@dependabot[bot] in sigstore/scaffolding#1626- Bump golang.org/x/net from 0.41.0 to 0.42.0 by
@dependabot[bot] in sigstore/scaffolding#1629- Bump github.com/letsencrypt/boulder from 0.0.0-20240620165639-de9c06129bec to 0.20250707.0 by
@dependabot[bot] in sigstore/scaffolding#1630- Bump cloud-sql-connectors/cloud-sql-proxy from 2.17.1-alpine to 2.18.0-alpine by
@dependabot[bot] in sigstore/scaffolding#1632- Bump github.com/go-jose/go-jose/v4 from 4.1.0 to 4.1.1 by
@dependabot[bot] in sigstore/scaffolding#1622- Clean up GHAs using zizmor by
@haydentherapperin sigstore/scaffolding#1633- Bump chainguard-dev/actions from 1.4.5 to 1.4.7 by
@dependabot[bot] in sigstore/scaffolding#1644- Bump google.golang.org/grpc from 1.73.0 to 1.74.2 by
@dependabot[bot] in sigstore/scaffolding#1646- Bump github/codeql-action from 3.29.2 to 3.29.4 by
@dependabot[bot] in sigstore/scaffolding#1645- Bump github.com/letsencrypt/boulder from 0.20250707.0 to 0.20250721.0 by
@dependabot[bot] in sigstore/scaffolding#1647- Create utility for generating Tink keysets by
@haydentherapperin sigstore/scaffolding#1627- Bump github/codeql-action from 3.29.4 to 3.29.5 by
@dependabot[bot] in sigstore/scaffolding#1652- Bump chainguard-dev/actions from 1.4.7 to 1.4.8 by
@dependabot[bot] in sigstore/scaffolding#1651- Bump go.step.sm/crypto from 0.67.0 to 0.68.0 by
@dependabot[bot] in sigstore/scaffolding#1650- Bump github.com/go-jose/go-jose/v4 from 4.1.1 to 4.1.2 by
@dependabot[bot] in sigstore/scaffolding#1648
... (truncated)
Commits
-
a3728aeAllow disabling Fulcio gRPC testing via flag (#1787) -
3f50591Allow insecure transport to be configured by flag (#1786) -
927ecadfix path to Dockerfile.deps file in automation (#1785) -
214bb8ffix: Adjust Fulcio gRPC URL handling for internal services (#1774) -
d0a102bBump trillian-opensource-ci/db_server in /config/trillian/mysql (#1784) -
d0e7459Bump github.com/letsencrypt/boulder from 0.20251021.0 to 0.20251103.0 (#1781) -
b85681cBump go.step.sm/crypto from 0.73.0 to 0.74.0 (#1779) -
390af4fBump chainguard-dev/actions from 1.5.7 to 1.5.8 (#1776) -
6b5656aBump github.com/go-openapi/strfmt from 0.24.0 to 0.25.0 (#1778) -
7f8b4fcBump golangci/golangci-lint-action from 8.0.0 to 9.0.0 (#1777) - Additional commits viewable in compare view
You can trigger a rebase of this PR by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
-
@dependabot rebasewill rebase this PR -
@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it -
@dependabot mergewill merge this PR after your CI passes on it -
@dependabot squash and mergewill squash and merge this PR after your CI passes on it -
@dependabot cancel mergewill cancel a previously requested merge and block automerging -
@dependabot reopenwill reopen this PR if it is closed -
@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually -
@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency -
@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) -
@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) -
@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)