Skip to content

Bump sigstore and ls-engines - #1448

Open
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/npm_and_yarn/multi-3313064c28
Open

Bump sigstore and ls-engines#1448
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/npm_and_yarn/multi-3313064c28

Conversation

@dependabot

@dependabotdependabotBot commented on behalf of githubJul 2, 2026

Copy link
Copy Markdown
Contributor

Bumps sigstore to 4.1.1 and updates ancestor dependency ls-engines. These dependencies need to be updated together.

Updates sigstore from 1.9.0 to 4.1.1

Release notes

Sourced from sigstore's releases.

sigstore@4.1.1

Patch Changes

  • 7845532: Verification of OID certificate extensions
  • f074710: Require inclusion promise in Rekor entry when used as timestamp source
  • Updated dependencies [b5aa4f1]
  • Updated dependencies [7845532]
  • Updated dependencies [f074710]
    • @​sigstore/core@​3.2.1
    • @​sigstore/verify@​3.1.1

sigstore@4.1.0

Minor Changes

  • eba6a52: verify(bundle[, payload][, options]) now returns a Signer object containing the public key and identity information from the verification.

Patch Changes

  • Updated dependencies [cee51c0]
  • Updated dependencies [2042aad]
  • Updated dependencies [018974e]
  • Updated dependencies [dea916f]
  • Updated dependencies [61a4f9e]
  • Updated dependencies [5ffadc0]
  • Updated dependencies [5ffadc0]
  • Updated dependencies [1663b3e]
    • @​sigstore/tuf@​4.0.1
    • @​sigstore/verify@​3.1.0
    • @​sigstore/sign@​4.1.0
    • @​sigstore/core@​3.1.0

sigstore@4.0.0

Major Changes

  • 383e200: Drop support for node 18

Patch Changes

  • Updated dependencies [40395f5]
  • Updated dependencies [383e200]
  • Updated dependencies [383e200]
  • Updated dependencies [383e200]
    • @​sigstore/tuf@​4.0.0
    • @​sigstore/sign@​4.0.0
    • @​sigstore/bundle@​4.0.0
    • @​sigstore/verify@​3.0.0
    • @​sigstore/core@​3.0.0

sigstore@3.1.0

Minor Changes

... (truncated)

Commits
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for sigstore since your current version.


Updates ls-engines from 0.9.4 to 0.10.1

Changelog

Sourced from ls-engines's changelog.

v0.10.1 - 2026-06-19

Commits

  • [New] add types 13ff435
  • [Tests] update fixtures 0b249a1
  • [eslint] some cleanup c5046f7
  • [actions] update workflows 0ceb848
  • [Deps] update pargs12170a9
  • [Robustness] avoid .push, use void79e28f2
  • [Dev Deps] update auto-changelog, eslint, npmignore, tape27c9468
  • [meta] exclude some files from the publish ae9bf18
  • [Refactor] store valid engines in an importable file c2cee45
  • [Fix] use valid subpath imports specifier for node <24 301a113
  • [eslint] fix errors 523e825
  • [Deps] update pargs, semverafa5e63
  • [Tests] update tape7366498
  • [Dev Deps] update eslint3c8a241
  • [Deps] update pargs7c4b17d
  • [readme] replace runkit CI badge with shields.io check-runs badge 46608fe
  • [eslint] fix linting dd08850

v0.10.0 - 2025-12-22

Commits

  • [Dev Deps] update eslint, @ljharb/eslint-config9bdfde1
  • [Refactor] switch from yargs to pargs 52031da
  • [Refactor] extract fulfilled result processing into separate module 6621295
  • [Deps] remove unused and no-longer-needed deps 04c90fb
  • [Refactor] use util.styleText instead of colorsb77a164
  • [Tests] add regression test for --save flag modifying package.json fb74dd9
  • [Refactor] convert CLI entrypoint to ESM f5f4084
  • [Breaking] require node 22 9d4fbbc
  • [Fix] correctly extract save function from fulfilled result value 4d04d3c
  • [Deps] update @npmcli/arborist, json-file-plus, pacotea6f1e0e
  • [Dev Deps] update nyc1569183
  • [Dev Deps] update npmignoreb1342bb
  • [Deps] update json-file-plusfa28493
  • [Deps] update get-dep-tree53f3cfa
  • [Dev Deps] update @ljharb/eslint-configdb2c528
Commits

Note
Automatic rebases have been disabled on this pull request as it has been open for over 30 days.

@dependabotdependabotBot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Jul 2, 2026
@socket-security

socket-securityBot commented Jul 2, 2026

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

DiffPackageSupply Chain
Security
VulnerabilityQualityMaintenanceLicense
Updatedls-engines@​0.9.4 ⏵ 0.10.192+11008488+7100

View full report

@dependabot
dependabotBotforce-pushed the dependabot/npm_and_yarn/multi-3313064c28 branch from 7af60fc to 966275aCompareJuly 5, 2026 05:43
@dependabot
dependabotBotforce-pushed the dependabot/npm_and_yarn/multi-3313064c28 branch from 966275a to a3f7c7cCompareJuly 13, 2026 02:13
@dependabot
dependabotBotforce-pushed the dependabot/npm_and_yarn/multi-3313064c28 branch 2 times, most recently from 178905d to 068bd6eCompareJuly 26, 2026 04:51
Bumps [sigstore](https://github.com/sigstore/sigstore-js) to 4.1.1 and updates ancestor dependency [ls-engines](https://github.com/ljharb/ls-engines). These dependencies need to be updated together.
Updates `sigstore` from 1.9.0 to 4.1.1
- [Release notes](https://github.com/sigstore/sigstore-js/releases)
- [Commits](https://github.com/sigstore/sigstore-js/compare/sigstore@1.9.0...sigstore@4.1.1)
Updates `ls-engines` from 0.9.4 to 0.10.1
- [Changelog](https://github.com/ljharb/ls-engines/blob/main/CHANGELOG.md)
- [Commits](ljharb/ls-engines@v0.9.4...v0.10.1)
---
updated-dependencies:
- dependency-name: ls-engines
dependency-version: 0.10.1
dependency-type: direct:development
- dependency-name: sigstore
dependency-version: 4.1.1
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabotBotforce-pushed the dependabot/npm_and_yarn/multi-3313064c28 branch from 068bd6e to b60e2cbCompareJuly 31, 2026 21:53
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependenciesPull requests that update a dependency filejavascriptPull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants