Skip to content

release: upgrade to latest cosign v3#421

Merged
mathieu-benoit merged 2 commits intomainfrom
cosign-v3
Feb 8, 2026
Merged

release: upgrade to latest cosign v3#421
mathieu-benoit merged 2 commits intomainfrom
cosign-v3

Conversation

@mathieu-benoit
Copy link
Copy Markdown
Contributor

@mathieu-benoit mathieu-benoit commented Feb 8, 2026

Follow up on #361, use new cosign bundle v3.

Removed cosign-release version specification from workflow.

Signed-off-by: Mathieu Benoit <mathieu-benoit@hotmail.fr>
@github-actions
Copy link
Copy Markdown
Contributor

github-actions bot commented Feb 8, 2026

Overview

Image reference score-compose:latest score-compose:latest
- digest 29f4e9270809 b7bc03784ac6
- tag latest latest
- provenance 7b52ede 8b5eeca
- vulnerabilities critical: 0 high: 0 medium: 0 low: 0 critical: 0 high: 0 medium: 0 low: 0
- platform linux/amd64 linux/amd64
- size 5.8 MB 5.8 MB (-6 B)
- packages 54 54
Policies (0 improved, 0 worsened)
Policy Name score-compose:latest score-compose:latest Change Standing
Default non-root user No Change
No AGPL v3 licenses No Change
No fixable critical or high vulnerabilities No Change
No high-profile vulnerabilities No Change
No outdated base images No Change
No unapproved base images No Change
Supply chain attestations No Change
Valid Docker Hardened Image (DHI) or DHI base image ⚠️ 2 ⚠️ 2 No Change
Packages and Vulnerabilities (1 package changes and 0 vulnerability changes)
  • ♾️ 1 packages changed
  • 53 packages unchanged
Changes for packages of type golang (1 changes)
Package Version
score-compose:latest
Version
score-compose:latest
♾️ github.com/score-spec/score-compose 0.0.0-20260207193827-7b52edeea3fe+dirty 0.0.0-20260208151002-8b5eecabdd96+dirty

Signed-off-by: Mathieu Benoit <mathieu-benoit@hotmail.fr>
@mathieu-benoit mathieu-benoit changed the title Upgrade to latest cosign v3 release: upgrade to latest cosign v3 Feb 8, 2026
@mathieu-benoit mathieu-benoit merged commit 3f42c0f into main Feb 8, 2026
11 checks passed
@mathieu-benoit mathieu-benoit deleted the cosign-v3 branch February 8, 2026 15:20
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant