github sigstore/cosign v1.12.1

latest releases: v2.4.1, v2.4.0, v2.3.0...
2 years ago

Highlights

fix: Pulls Fulcio root and intermediate when --certificate-chain is not passed into verify-blob command. The v1.12.0 release introduced a regression: when COSIGN_EXPERIMENTAL was not set, cosign verify-blob would check a --certificate (without a --certificate-chain provided) against the operating system root CA bundle. In this release, Cosign checks the certificate against Fulcio's CA root instead (restoring the earlier behavior).

What's Changed

New Contributors

Full Changelog: v1.12.0...v1.12.1

Don't miss a new cosign release

NewReleases is sending notifications on new releases.