Skip to content

[DEPENDENCY] Bump sigstore and pacote - #880

Open
dependabot[bot] wants to merge 1 commit into
v4from
dependabot/npm_and_yarn/multi-525b793c4e
Open

[DEPENDENCY] Bump sigstore and pacote#880
dependabot[bot] wants to merge 1 commit into
v4from
dependabot/npm_and_yarn/multi-525b793c4e

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 2, 2026

Copy link
Copy Markdown
Contributor

Bumps sigstore to 5.0.0 and updates ancestor dependency pacote. These dependencies need to be updated together.

Updates sigstore from 3.1.0 to 5.0.0

Release notes

Sourced from sigstore's releases.

sigstore@5.0.0

Major Changes

  • 46c00b3: Drop support for Node 20

Patch Changes

  • Updated dependencies [7db2666]
  • Updated dependencies [74eda7a]
  • Updated dependencies [46c00b3]
  • Updated dependencies [46c00b3]
  • Updated dependencies [46c00b3]
  • Updated dependencies [46c00b3]
    • @​sigstore/tuf@​5.0.0
    • @​sigstore/bundle@​5.0.0
    • @​sigstore/verify@​4.0.0
    • @​sigstore/core@​4.0.0
    • @​sigstore/sign@​5.0.0

sigstore@4.1.1

Patch Changes

  • 7845532: Verification of OID certificate extensions
  • f074710: Require inclusion promise in Rekor entry when used as timestamp source
  • Updated dependencies [b5aa4f1]
  • Updated dependencies [7845532]
  • Updated dependencies [f074710]
    • @​sigstore/core@​3.2.1
    • @​sigstore/verify@​3.1.1

sigstore@4.1.0

Minor Changes

  • eba6a52: verify(bundle[, payload][, options]) now returns a Signer object containing the public key and identity information from the verification.

Patch Changes

  • Updated dependencies [cee51c0]
  • Updated dependencies [2042aad]
  • Updated dependencies [018974e]
  • Updated dependencies [dea916f]
  • Updated dependencies [61a4f9e]
  • Updated dependencies [5ffadc0]
  • Updated dependencies [5ffadc0]
  • Updated dependencies [1663b3e]
    • @​sigstore/tuf@​4.0.1
    • @​sigstore/verify@​3.1.0
    • @​sigstore/sign@​4.1.0
    • @​sigstore/core@​3.1.0

... (truncated)

Commits
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for sigstore since your current version.


Updates pacote from 19.0.2 to 22.0.0

Release notes

Sourced from pacote's releases.

v22.0.0

22.0.0 (2026-06-15)

⚠️ BREAKING CHANGES

  • pacote now supports node ^22.22.2 || ^24.15.0 || >=26.0.0
  • git specs using the https or git+https protocol now resolve to git+https URLs instead of being switched to git+ssh. Shortcut specs (e.g. github:user/repo, user/repo) and git+ssh/git:// specs are unchanged.

Features

Bug Fixes

Dependencies

Chores

v21.5.1

21.5.1 (2026-06-09)

Bug Fixes

Chores

v21.5.0

21.5.0 (2026-03-09)

... (truncated)

Changelog

Sourced from pacote's changelog.

22.0.0 (2026-06-15)

⚠️ BREAKING CHANGES

  • pacote now supports node ^22.22.2 || ^24.15.0 || >=26.0.0
  • git specs using the https or git+https protocol now resolve to git+https URLs instead of being switched to git+ssh. Shortcut specs (e.g. github:user/repo, user/repo) and git+ssh/git:// specs are unchanged.

Features

Bug Fixes

Dependencies

Chores

21.5.0 (2026-03-09)

Features

Chores

21.4.0 (2026-02-24)

Features

Bug Fixes

... (truncated)

Commits

Note
Automatic rebases have been disabled on this pull request as it has been open for over 30 days.

@dependabot dependabot Bot added dependencies javascript Pull requests that update Javascript code labels Jul 2, 2026
Bumps [sigstore](https://github.com/sigstore/sigstore-js) to 5.0.0 and updates ancestor dependency [pacote](https://github.com/npm/pacote). These dependencies need to be updated together.


Updates `sigstore` from 3.1.0 to 5.0.0
- [Release notes](https://github.com/sigstore/sigstore-js/releases)
- [Commits](https://github.com/sigstore/sigstore-js/compare/sigstore@3.1.0...sigstore@5.0.0)

Updates `pacote` from 19.0.2 to 22.0.0
- [Release notes](https://github.com/npm/pacote/releases)
- [Changelog](https://github.com/npm/pacote/blob/main/CHANGELOG.md)
- [Commits](npm/pacote@v19.0.2...v22.0.0)

---
updated-dependencies:
- dependency-name: pacote
  dependency-version: 22.0.0
  dependency-type: direct:production
- dependency-name: sigstore
  dependency-version: 5.0.0
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/multi-525b793c4e branch from 669c358 to 61181c3 Compare July 26, 2026 02:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies javascript Pull requests that update Javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants