From 37518d23b99a988d27317775bf0382dc84f9a4da Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Mon, 16 Mar 2026 23:41:51 +0000 Subject: [PATCH] chore(deps): bump sigstore/cosign-installer from 3.8.2 to 4.1.0 Bumps [sigstore/cosign-installer](https://github.com/sigstore/cosign-installer) from 3.8.2 to 4.1.0. - [Release notes](https://github.com/sigstore/cosign-installer/releases) - [Commits](https://github.com/sigstore/cosign-installer/compare/3454372f43399081ed03b604cb2d021dabca52bb...ba7bc0a3fef59531c69a25acd34668d6d3fe6f22) --- updated-dependencies: - dependency-name: sigstore/cosign-installer dependency-version: 4.1.0 dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] --- .github/workflows/release-skill.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/release-skill.yml b/.github/workflows/release-skill.yml index 918e132..8d9e84b 100644 --- a/.github/workflows/release-skill.yml +++ b/.github/workflows/release-skill.yml @@ -51,7 +51,7 @@ jobs: uses: aquasecurity/setup-trivy@3fb12ec12f41e471780db15c232d5dd185dcb514 - name: Install Cosign - uses: sigstore/cosign-installer@3454372f43399081ed03b604cb2d021dabca52bb + uses: sigstore/cosign-installer@ba7bc0a3fef59531c69a25acd34668d6d3fe6f22 - name: Generate SPDX SBOM run: syft dir:./dist -o spdx-json > dist/sbom.spdx.json