Sourced from sigstore/gh-action-sigstore-python's releases.
v3.1.0
gh-action-sigstore-pythonis now compatible with Rekor v2 transparency log (but produced signature bundles still contain Rekor v1 entries by default).Changed
- The action now uses sigstore-python 4.1. All other dependencies are also updated (#220)
Fixed
- Fixed incompatibility with Python 3.14 by upgrading dependencies (#225)
Added
rekor-versionargument was added to control the Rekor transparency log version when signing. The default version in the gh-action-sigstore-python 3.x series will remain 1 (except when usingstaging: true). (#228)
Sourced from sigstore/gh-action-sigstore-python's changelog.
[3.1.0]
gh-action-sigstore-pythonis now compatible with Rekor v2 transparency log (but produced signature bundles still contain Rekor v1 entries by default).Changed
- The action now uses sigstore-python 4.1. All other dependencies are also updated (#220)
Fixed
- Fixed incompatibility with Python 3.14 by upgrading dependencies (#225)
Added
rekor-versionargument was added to control the Rekor transparency log version when signing. The default version in the gh-action-sigstore-python 3.x series will remain 1 (except when usingstaging: true). (#228)
f832326
Prepare 3.1.0 release (#230)3385d3a
build(deps): bump astral-sh/setup-uv in the actions group (#232)35fff1e
Add rekor-version argument (#228)be60bbe
build(deps): bump github/codeql-action in the actions group (#231)72e7431
Actually upgrade dependencies (#225)ccdc279
ci, action: address zizmor findings, bump versions (#222)709f8a4
build(deps): bump sigstore from 3.6.3 to 4.0.0 (#220)5ce4031
requirements: Include main.in contents within dev.in (#221)ea888ad
build(deps): bump the actions group with 3 updates (#218)17565e2
build(deps): bump the python-dependencies group with 6 updates (#219)