Ecosyste.ms: Issues

An open API service for providing issue and pull request metadata for open source projects.

GitHub / liatrio/gh-trusted-builds-attestations issues and pull requests

#59 - Link github attestations API to opensearch to pull in data

Issue - State: open - Opened by csalt-liatrio 3 months ago - 3 comments

#58 - docs: add docker login readme for vsa

Pull Request - State: open - Opened by amber-beasley-liatrio 3 months ago

#57 - build: update actions/setup-go digest to 41dfa10

Pull Request - State: open - Opened by renovate[bot] 4 months ago

#56 - build: update actions/checkout digest to 11bd719

Pull Request - State: open - Opened by renovate[bot] 7 months ago

#55 - build: update module github.com/sigstore/cosign/v2 to v2.4.1

Pull Request - State: open - Opened by renovate[bot] 8 months ago - 1 comment

#53 - build: update module golang.org/x/oauth2 to v0.23.0

Pull Request - State: open - Opened by renovate[bot] 8 months ago - 1 comment

#52 - feat: support downloading policy from GitHub tree URLs

Pull Request - State: closed - Opened by alexashley 8 months ago

#51 - build: update module github.com/sigstore/rekor to v1.3.6

Pull Request - State: open - Opened by renovate[bot] 8 months ago

#48 - build: update module github.com/sigstore/sigstore to v1.8.10

Pull Request - State: open - Opened by renovate[bot] 8 months ago - 1 comment

#47 - build: update module github.com/open-policy-agent/opa to v0.70.0

Pull Request - State: open - Opened by renovate[bot] 8 months ago - 1 comment

#46 - Only run goreleaser if there's a new version

Issue - State: closed - Opened by alexashley 9 months ago

#45 - ci: update Sigstore scaffolding ref

Pull Request - State: closed - Opened by alexashley 9 months ago

#44 - build: update module gopkg.in/dnaeon/go-vcr.v3 to v3.2.0

Pull Request - State: closed - Opened by renovate[bot] 9 months ago - 1 comment

#44 - build: update module gopkg.in/dnaeon/go-vcr.v3 to v3.2.0

Pull Request - State: closed - Opened by renovate[bot] 9 months ago - 1 comment

#42 - build: update dependencies

Pull Request - State: closed - Opened by alexashley 9 months ago

#41 - build: update actions/checkout action to v4 - autoclosed

Pull Request - State: closed - Opened by renovate[bot] 9 months ago

#35 - build: update module github.com/google/go-containerregistry to v0.20.2

Pull Request - State: open - Opened by renovate[bot] 9 months ago - 1 comment

#32 - build: update Go version, cosign, & go-git

Pull Request - State: closed - Opened by alexashley 9 months ago

#31 - Dependency Dashboard

Issue - State: open - Opened by renovate[bot] 9 months ago

#28 - build: bump github.com/cloudflare/circl from 1.3.3 to 1.3.7

Pull Request - State: closed - Opened by dependabot[bot] 11 months ago - 2 comments
Labels: dependencies

#27 - ci: configure Renovate

Pull Request - State: closed - Opened by renovate[bot] 11 months ago

#26 - build: bump github.com/go-git/go-git/v5 from 5.6.1 to 5.11.0

Pull Request - State: closed - Opened by dependabot[bot] 11 months ago - 2 comments
Labels: dependencies

#25 - build: bump golang.org/x/crypto from 0.9.0 to 0.17.0

Pull Request - State: closed - Opened by dependabot[bot] 11 months ago - 2 comments
Labels: dependencies

#24 - build: bump github.com/go-jose/go-jose/v3 from 3.0.0 to 3.0.1

Pull Request - State: closed - Opened by dependabot[bot] about 1 year ago - 2 comments
Labels: dependencies

#23 - build: bump github.com/sigstore/cosign/v2 from 2.0.2 to 2.2.1

Pull Request - State: closed - Opened by dependabot[bot] about 1 year ago - 2 comments
Labels: dependencies

#22 - build: bump github.com/docker/docker from 23.0.3+incompatible to 24.0.7+incompatible

Pull Request - State: closed - Opened by dependabot[bot] about 1 year ago - 2 comments
Labels: dependencies

#21 - build: bump google.golang.org/grpc from 1.55.0 to 1.56.3

Pull Request - State: closed - Opened by dependabot[bot] about 1 year ago - 2 comments
Labels: dependencies

#20 - build: bump golang.org/x/net from 0.10.0 to 0.17.0

Pull Request - State: closed - Opened by dependabot[bot] about 1 year ago - 2 comments
Labels: dependencies

#19 - ci: add semantic-release

Pull Request - State: closed - Opened by alexashley over 1 year ago - 2 comments

#18 - refactor: use cobra for commands

Pull Request - State: closed - Opened by alexashley over 1 year ago

#17 - test: add integration tests for commands

Pull Request - State: closed - Opened by alexashley over 1 year ago

#16 - feat: grab signer identities from policy

Pull Request - State: closed - Opened by alexashley over 1 year ago

#15 - feat: allow policy to call into cosign attestation verification

Pull Request - State: closed - Opened by alexashley over 1 year ago

#14 - build(deps): bump github.com/sigstore/rekor from 1.1.0 to 1.2.0

Pull Request - State: closed - Opened by dependabot[bot] over 1 year ago
Labels: dependencies

#13 - feat: add version, help commands

Pull Request - State: closed - Opened by rcoy-v over 1 year ago

#12 - feat: configurable policy bundle location

Pull Request - State: closed - Opened by rcoy-v over 1 year ago

#11 - refactor: remove dead code, update docs

Pull Request - State: closed - Opened by rcoy-v over 1 year ago

#10 - fix: remove unused commit-sha flag

Pull Request - State: closed - Opened by rcoy-v over 1 year ago

#9 - feat: wip attaching ghpr to oci artifact

Pull Request - State: closed - Opened by rcoy-v over 1 year ago

#8 - fix: remove unused kms-key-uri flag

Pull Request - State: closed - Opened by alexashley over 1 year ago - 1 comment

#7 - feat: defaults for fulcio and rekor

Pull Request - State: closed - Opened by rcoy-v over 1 year ago

#6 - feat: enable three-legged keyless signing

Pull Request - State: closed - Opened by alexashley over 1 year ago

#5 - feat: write VSA predicate to file

Pull Request - State: closed - Opened by alexashley over 1 year ago

#4 - feat: take digest type from artifact digest

Pull Request - State: closed - Opened by alexashley over 1 year ago

#3 - build(deps): bump github.com/docker/distribution from 2.8.1+incompatible to 2.8.2+incompatible

Pull Request - State: closed - Opened by dependabot[bot] over 1 year ago
Labels: dependencies

#2 - build(deps): bump github.com/cloudflare/circl from 1.1.0 to 1.3.3

Pull Request - State: closed - Opened by dependabot[bot] over 1 year ago
Labels: dependencies

#1 - build(deps): bump github.com/sigstore/rekor from 1.1.0 to 1.1.1

Pull Request - State: closed - Opened by dependabot[bot] over 1 year ago - 1 comment
Labels: dependencies