What's Changed
- Update CHANGELOG for 1.10.1 release by @priyawadhwa in #2130
- Bump github/codeql-action from 2.1.17 to 2.1.18 by @dependabot in #2129
- Bump github.com/go-piv/piv-go from 1.9.0 to 1.10.0 by @dependabot in #2135
- Bump actions/cache from 3.0.5 to 3.0.6 by @dependabot in #2136
- Bump github.com/xanzy/go-gitlab from 0.70.0 to 0.71.0 by @dependabot in #2142
- Bump github.com/go-openapi/swag from 0.21.1 to 0.22.0 by @dependabot in #2140
- Bump github.com/hashicorp/go-secure-stdlib/parseutil from 0.1.6 to 0.1.7 by @dependabot in #2141
- Verify the certificate chain against the Fulcio root trust by default by @wata727 in #2139
- Add notes to clarify registry use. by @bendory in #2145
- Use TUF from scaffolding for validating cosign. by @vaikas in #2146
- Bump actions/cache from 3.0.6 to 3.0.7 by @dependabot in #2151
- Bump google.golang.org/api from 0.91.0 to 0.92.0 by @dependabot in #2150
- Bump tests to use scaffolding-0.4.3. by @vaikas in #2153
- docs: clarify wording in spec about usage of certificate chain by @asraa in #2152
- Bump github.com/xanzy/go-gitlab from 0.71.0 to 0.72.0 by @dependabot in #2148
- Bump go.uber.org/atomic from 1.9.0 to 1.10.0 by @dependabot in #2155
- Bump actions/github-script from 6.1.0 to 6.1.1 by @dependabot in #2156
- fix: fix blob verification output with sharded rekor tlogs by @asraa in #2157
- Run tests using Go 1.18 by @imjasonh in #2093
- Bump sigs.k8s.io/release-utils from 0.6.0 to 0.7.3 by @dependabot in #2102
- fix: adds envelope hash to in-toto entries in tlog entry creation by @nkreiger in #2118
- fix handling of verify-attestation types for URIs by @otms61 in #2159
- bump to scaffolding v0.4.4 by @vaikas in #2165
- fix oidc post-merge job by @cpanato in #2164
- Remove third_party by @imjasonh in #2166
- use updated device flow logic with PKCE by @bobcallaway in #2163
- fix: rekor get tlog entry with uuid by @asraa in #2058
- update e2e job to run only when push to main by @cpanato in #2169
- Bump sigstore/cosign-installer from 2.5.0 to 2.5.1 by @dependabot in #2168
- fix: add env cmd to root by @developer-guy in #2171
- Bump github.com/go-openapi/swag from 0.22.0 to 0.22.1 by @dependabot in #2167
- fix panic when os.Stat returns an error besides ErrNotExists by @dsa0x in #2162
- add changelog for v1.11.0 by @cpanato in #2173
- update builder image by @cpanato in #2174
New Contributors
- @wata727 made their first contribution in #2139
- @bendory made their first contribution in #2145
- @nkreiger made their first contribution in #2118
- @dsa0x made their first contribution in #2162
Full Changelog: v1.10.1...v1.11.0