Skip to content

chore: sign checksum with cosign, add govulncheck tool and job, bump deps#46

Merged
idebeijer merged 4 commits intomainfrom
chore/security-improvements
Feb 13, 2026
Merged

chore: sign checksum with cosign, add govulncheck tool and job, bump deps#46
idebeijer merged 4 commits intomainfrom
chore/security-improvements

Conversation

@idebeijer
Copy link
Owner

@idebeijer idebeijer commented Feb 13, 2026

  • Add govulncheck tool and as Makefile command.
  • Add govulncheck ci job.
  • Bump go to v1.25.7.
  • Bump k8s deps to v0.35.1.
  • Pin github actions to digests.
  • Sign release checksum with cosign

Only sign the checksum since it contains the hashes which should be compared against the downloaded binaries.

Signed-off-by: Igor de Beijer <71566757+idebeijer@users.noreply.github.com>
Signed-off-by: Igor de Beijer <71566757+idebeijer@users.noreply.github.com>
Signed-off-by: Igor de Beijer <71566757+idebeijer@users.noreply.github.com>
@idebeijer idebeijer changed the title chore: add govulncheck tool and ci job chore: sign checksum with cosign, add govulncheck tool and job, bump deps Feb 13, 2026
@idebeijer idebeijer merged commit 08c3343 into main Feb 13, 2026
4 checks passed
@idebeijer idebeijer deleted the chore/security-improvements branch February 13, 2026 16:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant