Skip to content

Bump sigstore from 3.6.4 to 3.6.7#351

Merged
ezio-melotti merged 1 commit intomainfrom
bump-sigstore-3.6.7
Mar 17, 2026
Merged

Bump sigstore from 3.6.4 to 3.6.7#351
ezio-melotti merged 1 commit intomainfrom
bump-sigstore-3.6.7

Conversation

@ezio-melotti
Copy link
Member

This PR bumps sigstore from 3.6.4 to 3.6.7.

This indirectly updates the requirements for cryptography:

  • sigstore==3.6.7 requires "cryptography >= 42, < 47"
  • sigstore==3.6.4 requires "cryptography >= 42, < 45"

Updating sigstore will allow us to update cryptography to the latest version and fix a few security issues.

@ezio-melotti ezio-melotti requested a review from hugovk March 17, 2026 00:36
@ezio-melotti ezio-melotti self-assigned this Mar 17, 2026
@ezio-melotti ezio-melotti added dependencies Pull requests that update a dependency file python Pull requests that update Python code labels Mar 17, 2026
@ezio-melotti ezio-melotti merged commit 1648672 into main Mar 17, 2026
31 checks passed
@hugovk hugovk deleted the bump-sigstore-3.6.7 branch March 17, 2026 05:16
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python Pull requests that update Python code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant