Skip to content

Releases: sigstore/rekor

v1.4.0

01 Aug 19:29
d7d31f0
Compare
Choose a tag to compare

Changelog

  • d7d31f0 changelog for v1.4.0 release (#2550)
  • 455d37b enable retries and timeouts on GCP KMS calls (#2548)
  • bfc05e0 allow configuring gRPC default service config for trillian client load balancing & timeouts (#2549)
  • 6b4e260 remove stable checkpoint feature (#2537)
  • 5d5f299 build(deps): Bump sigs.k8s.io/release-utils from 0.11.1 to 0.12.0
  • 9a34ce9 build(deps): Bump golang.org/x/net from 0.41.0 to 0.42.0 (#2544)
  • 7d62779 build(deps): Bump the all group with 3 updates (#2545)
  • e2f2f07 fix lints
  • 82d7215 bump golangci-lint to v2.2.x
  • 47a75e6 use go1.24.5 to build rekor
  • 7fec2db build(deps): Bump google.golang.org/api from 0.238.0 to 0.242.0 (#2543)
  • d5c8e57 build(deps): Bump golang.org/x/sync from 0.15.0 to 0.16.0 (#2541)
  • a7a0356 build(deps): Bump github.com/spf13/pflag in the all group (#2542)
  • 802db4d build(deps): Bump github.com/sigstore/protobuf-specs from 0.4.3 to 0.5.0
  • d920fad move context handling in trillian RPC calls to be request based and idiomatic (#2536)
  • 4b09ef5 build(deps): Bump github.com/go-viper/mapstructure/v2 (#2522)
  • 959ea43 build(deps): Bump golang from 1.24.4 to 1.24.5 in the all group (#2534)
  • 8931ff3 build(deps): Bump the all group with 2 updates (#2518)
  • df0a4ce build(deps): Bump the all group with 2 updates (#2524)
  • 2fab95a build(deps): Bump sigstore/scaffolding/trillian_log_server (#2527)
  • 4221cb8 build(deps): Bump sigstore/scaffolding/trillian_log_signer (#2526)
  • 6c27e68 build(deps): Bump github.com/go-viper/mapstructure/v2 in /hack/tools (#2523)
  • 3f8d1e6 backoff pubsub emulator to last-known good (#2535)
  • 422e8ec build(deps): Bump golang from db5d0af to 10c1318
  • c0f3b8c build(deps): Bump sigstore/cosign-installer in the all group
  • 795d4c7 build(deps): Bump google.com/cloudsdktool/google-cloud-cli
  • 3ef026f build(deps): Bump google.golang.org/api from 0.237.0 to 0.238.0
  • 18a6ae4 build(deps): Bump go.step.sm/crypto from 0.66.0 to 0.67.0
  • 1ef8b66 build(deps): Bump github/codeql-action in the all group
  • 2e5d89f build(deps): Bump google.golang.org/api from 0.236.0 to 0.237.0
  • fa87121 build(deps): Bump the all group with 7 updates
  • 20979b6 Update GoReleaser configurations (#2511)
  • 8d71b49 update builder to use go1.24.4
  • 03a2874 build(deps): Bump google.golang.org/grpc from 1.72.2 to 1.73.0
  • b0db66f build(deps): Bump golang.org/x/net from 0.40.0 to 0.41.0
  • 7dcea62 build(deps): Bump github.com/redis/go-redis/v9 from 9.9.0 to 9.10.0
  • ea15859 build(deps): Bump google.golang.org/api from 0.235.0 to 0.236.0
  • 4793920 build(deps): Bump golang from 1.24.3 to 1.24.4 in the all group
  • 0613f7f build(deps): Bump github.com/go-swagger/go-swagger
  • bce34fc build(deps): Bump github/codeql-action in the all group
  • 946bdf5 build(deps): Bump google.com/cloudsdktool/google-cloud-cli
  • 5c131cf build(deps): Bump github.com/google/rpmpack from 0.6.0 to 0.7.0
  • 4f4dbc7 build(deps): Bump github.com/redis/go-redis/v9 from 9.8.0 to 9.9.0
  • 4a3e683 build(deps): Bump google.com/cloudsdktool/google-cloud-cli
  • 6a0305e build(deps): Bump go.step.sm/crypto from 0.64.0 to 0.66.0
  • cad3eb6 build(deps): Bump google.golang.org/api from 0.234.0 to 0.235.0
  • 5097431 build(deps): Bump golang from 4c0a181 to 81bf592
  • 1a4c8e5 build(deps): Bump google.golang.org/api from 0.233.0 to 0.234.0
  • cc3b57c build(deps): Bump golang from 86b4cff to 4c0a181
  • a695663 build(deps): Bump google.com/cloudsdktool/google-cloud-cli
  • e6af2f8 build(deps): Bump google.golang.org/grpc in the all group
  • aaaa2e3 build(deps): Bump go.step.sm/crypto from 0.63.0 to 0.64.0
  • d4e59ed Don't initialize index storage with stable checkpoint publishing (#2486)
  • 255b324 build(deps): Bump golang from 39d9e7d to 86b4cff
  • c86d95f build(deps): Bump google.com/cloudsdktool/google-cloud-cli
  • 90ca4b4 build(deps): Bump the all group with 2 updates
  • 7d5b510 build(deps): Bump google.golang.org/api from 0.232.0 to 0.233.0
  • dec7ef2 build(deps): Bump the all group with 2 updates
  • 62a6617 Fix docker compose up --wait failing when Trillian server isn't healthy (#2473)
  • dedb18d build(deps): Bump golang.org/x/crypto from 0.37.0 to 0.38.0 (#2477)
  • a18b3a3 build(deps): Bump golang.org/x/net from 0.39.0 to 0.40.0 (#2475)
  • b971ec3 build(deps): Bump golang from 1.24.2 to 1.24.3 in the all group (#2480)
  • b124325 build(deps): Bump google.golang.org/api from 0.231.0 to 0.232.0
  • f067e5a build(deps): Bump google.com/cloudsdktool/google-cloud-cli (#2478)
  • 09bb61f build(deps): Bump actions/setup-go from 5.4.0 to 5.5.0 in the all group (#2474)
  • 140f622 build(deps): Bump github.com/redis/go-redis/v9 from 9.7.3 to 9.8.0 (#2470)
  • 5cbfc5f build(deps): Bump golangci/golangci-lint-action from 7.0.0 to 8.0.0 (#2471)
  • 0e0e62b build(deps): Bump google.golang.org/api from 0.230.0 to 0.231.0
  • 810385a build(deps): Bump go.step.sm/crypto from 0.61.0 to 0.63.0 (#2468)
  • 191c5a8 build(deps): Bump github/codeql-action in the all group (#2467)
  • cc70ac7 build(deps): Bump golang from d9db321 to 30baaea (#2469)
  • 7b8fd2e build(deps): Bump google.com/cloudsdktool/google-cloud-cli (#2466)
  • 09ef86a build(deps): Bump the all group with 2 updates
  • 78c929a build(deps): Bump google.golang.org/api from 0.229.0 to 0.230.0
  • 2f76aea build(deps): Bump the all group with 3 updates
  • 6ad185a build(deps): Bump google.com/cloudsdktool/google-cloud-cli (#2462)
  • fef9f71 Bump sigstore/sigstore, use shared Tink library (#2461)
  • 5361696 better mysql healthcheck (#2459)
  • 1f43fb5 build(deps): Bump sigs.k8s.io/release-utils from 0.8.4 to 0.11.1
  • 7af1f88 build(deps): Bump google.golang.org/grpc from 1.71.1 to 1.72.0
  • fd8ce28 build(deps): Bump github.com/tink-crypto/tink-go/v2 from 2.3.0 to 2.4.0
  • c571c23 build(deps): Bump google.com/cloudsdktool/google-cloud-cli
  • 578719a build(deps): Bump golang
  • 0860336 build(deps): Bump codecov/codecov-action in the all group
  • a365058 build(deps): Bump go.step.sm/crypto from 0.60.0 to 0.61.0
  • 720ba7f build(deps): Bump golang.org/x/crypto in /hack/tools
  • 456b0df update builder image to use go1.24.2
  • ce01015 build(deps): Bump golang from 991aa6a to 1ecc479
  • 46c694f build(deps): Bump ko-build/setup-ko from 0.8 to 0.9 in the all group
  • 406f08d build(deps): Bump cloud.google.com/go/pubsub from 1.47.0 to 1.49.0
  • 78161c7 build(deps): Bump github.com/prometheus/client_golang
  • 159c0f2 build(deps): Bump the all group with 7 updates
  • 61c39f0 build(deps): Bump github.com/spf13/viper from 1.19.0 to 1.20.1
  • 9d0fbc1 Add CHANGELOG for v1.3.10 (#2439)

Thanks for all contributors!

v1.3.10

11 Apr 17:20
v1.3.10
4118a64
Compare
Choose a tag to compare

v1.3.10

Note that Rekor v1 is in maintenance mode as we are actively developing
its successor, Rekor v2, designed to be easy to maintain and cheaper to operate. See the
README for more information.

Features

  • Added --client-signing-algorithms flag (#1974)

Fixes / Misc

  • emit unpopulated values when marshalling (#2438)
  • pkg/api: better logs when algorithm registry rejects a key (#2429)
  • chore: improve mysql readiness checks (#2397)

Thanks for all contributors!

v1.3.9

27 Jan 18:44
v1.3.9
Compare
Choose a tag to compare

v1.3.9

Features

  • Cache checkpoint for inactive shards (#2332)
  • Support per-shard signing keys (#2330)

v1.3.8

16 Jan 20:54
v1.3.8
88b5ce5
Compare
Choose a tag to compare

Changelog

Please see https://github.com/sigstore/rekor/blob/main/CHANGELOG.md for changes included in this release.

New Contributors

Full Changelog: v1.3.7...v1.3.8

v1.3.7

21 Nov 22:42
4caadbc
Compare
Choose a tag to compare

Changelog

Please see https://github.com/sigstore/rekor/blob/main/CHANGELOG.md for changes included in this release.

Thanks for all contributors!

v1.3.6

02 Apr 04:42
v1.3.6
a678856
Compare
Choose a tag to compare

v1.3.6

New Features

  • Add support for IEEE P1363 encoded ECDSA signatures
  • Add index performance script (#2042)
  • Add support for ed25519ph user keys in hashedrekord (#1945)
  • Add metrics for index insertion (#2015)
  • Add TLS support for Redis Client implementation (#1998)

Bug Fixes

  • fix typo in remoteIp and set full name for trace field

Full Changelog: v1.3.5...v1.3.6

v1.3.5

03 Feb 00:18
488eb97
Compare
Choose a tag to compare

Changelog

Thanks for all contributors!

What's Changed

New Contributors

Full Changelog: v1.3.4...v1.3.5

v1.3.4

03 Dec 20:11
5072901
Compare
Choose a tag to compare

Changelog

  • 5072901 changelog for v1.3.4 (#1868)
  • 9e37c19 fix: Do not check for pubsub.topics.get on initialization (#1853)
  • fb05e16 Update ranges.go (#1852)
  • a7501a6 update indexstorage interface to reduce roundtrips (#1838)
  • 212ebff add functional options for mysql implementation
  • a9de214 s/uuids/uuid
  • 014cfb1 add mysql indexstorage backend
  • 0394bf7 add s3 storage for attestations
  • 29220fb update builder image to use go1.21.4 and bump golangci-lint to v1.55.x (#1851)
  • ff9c3b9 fix optional field in cose schema
  • c3ffda6 use a single validator library in rekor-cli (#1818)
  • b681a14 Remove go-playground/validator dependency from pkg/pki (#1817)

Thanks for all contributors!

New Contributors

Full Changelog: v1.3.3...v1.3.4

v1.3.3

01 Nov 22:32
2ea1ef0
Compare
Choose a tag to compare

Changelog

Thanks for all contributors!

What's Changed

  • build(deps): Bump golang.org/x/net from 0.10.0 to 0.17.0 in /hack/tools by @dependabot in #1759
  • build(deps): Bump google/cloud-sdk from 5499d59 to 5ae0c79 by @dependabot in #1760
  • build(deps): Bump github.com/go-redis/redismock/v9 from 9.0.3 to 9.2.0 by @dependabot in #1761
  • build(deps): Bump github.com/redis/go-redis/v9 from 9.1.0 to 9.2.1 by @dependabot in #1717
  • install go at correct version for codeql by @bobcallaway in #1762
  • build(deps): Bump github.com/sigstore/sigstore/pkg/signature/kms/azure from 1.7.3 to 1.7.4 by @dependabot in #1764
  • build(deps): Bump github.com/sigstore/sigstore/pkg/signature/kms/gcp from 1.7.3 to 1.7.4 by @dependabot in #1765
  • build(deps): Bump github.com/sigstore/sigstore/pkg/signature/kms/aws from 1.7.3 to 1.7.4 by @dependabot in #1763
  • build(deps): Bump github.com/sigstore/sigstore from 1.7.3 to 1.7.4 by @dependabot in #1767
  • build(deps): Bump github.com/sigstore/sigstore/pkg/signature/kms/hashivault from 1.7.3 to 1.7.4 by @dependabot in #1769
  • build(deps): Bump google/cloud-sdk from 5ae0c79 to 0bd5508 by @dependabot in #1768
  • make e2e tests more usable with docker-compose by @bobcallaway in #1770
  • build(deps): Bump google/cloud-sdk from 0bd5508 to 66e2681 by @dependabot in #1772
  • build(deps): Bump google/cloud-sdk from 66e2681 to d2a303f by @dependabot in #1773
  • build(deps): Bump actions/checkout from 4.1.0 to 4.1.1 by @dependabot in #1774
  • build(deps): Bump google/cloud-sdk from 450.0.0 to 451.0.0 by @dependabot in #1775
  • build(deps): Bump google.golang.org/grpc from 1.58.3 to 1.59.0 by @dependabot in #1776
  • Add method to get artifact hash for an entry by @haydentherapper in #1777
  • build(deps): Bump go.step.sm/crypto from 0.36.0 to 0.36.1 by @dependabot in #1780
  • build(deps): Bump google/cloud-sdk from 4bcc272 to 1969fea by @dependabot in #1778
  • build(deps): Bump cloud.google.com/go/profiler from 0.3.1 to 0.4.0 by @dependabot in #1779
  • build(deps): Bump google/cloud-sdk from 451.0.0 to 451.0.1 by @dependabot in #1782
  • build(deps): Bump google.golang.org/api from 0.147.0 to 0.148.0 by @dependabot in #1781
  • build(deps): Bump google/cloud-sdk from d7dac1e to d01ba39 by @dependabot in #1783
  • build(deps): Bump google/cloud-sdk from d01ba39 to 7edf46b by @dependabot in #1784
  • build(deps): Bump google/cloud-sdk from 451.0.1 to 452.0.0 by @dependabot in #1785
  • build(deps): Bump go.uber.org/goleak from 1.2.1 to 1.3.0 by @dependabot in #1787
  • build(deps): Bump sigs.k8s.io/yaml from 1.3.0 to 1.4.0 by @dependabot in #1786
  • build(deps): Bump google.golang.org/grpc from 1.55.0 to 1.56.3 in /hack/tools by @dependabot in #1788
  • build(deps): Bump google/cloud-sdk from 452.0.0 to 452.0.1 by @dependabot in #1789
  • build(deps): Bump github.com/sigstore/sigstore/pkg/signature/kms/azure from 1.7.4 to 1.7.5 by @dependabot in #1790
  • build(deps): Bump google/cloud-sdk from 8b55497 to a7d9835 by @dependabot in #1795
  • build(deps): Bump github.com/sigstore/sigstore/pkg/signature/kms/gcp from 1.7.4 to 1.7.5 by @dependabot in #1792
  • build(deps): Bump sigs.k8s.io/release-utils from 0.7.5 to 0.7.6 by @dependabot in #1793
  • build(deps): Bump github.com/sigstore/sigstore/pkg/signature/kms/hashivault from 1.7.4 to 1.7.5 by @dependabot in #1791
  • build(deps): Bump github.com/sigstore/sigstore from 1.7.4 to 1.7.5 by @dependabot in #1794
  • build(deps): Bump google/cloud-sdk from a7d9835 to 96d437f by @dependabot in #1796
  • build(deps): Bump github.com/sigstore/sigstore/pkg/signature/kms/aws from 1.7.4 to 1.7.5 by @dependabot in #1797
  • feat: adds redis auth. by @ianhundere in #1627
  • build(deps): Bump google/cloud-sdk from 96d437f to b996d57 by @dependabot in #1798
  • build(deps): Bump google/cloud-sdk from 452.0.1 to 453.0.0 by @dependabot in #1800
  • build(deps): Bump github.com/redis/go-redis/v9 from 9.2.1 to 9.3.0 by @dependabot in #1801
  • build(deps): Bump google.golang.org/api from 0.148.0 to 0.149.0 by @dependabot in #1802
  • update trillian to 1.5.3 by @k4leung4 in #1803
  • Update signer flag description by @haydentherapper in #1804
  • changelog for v1.3.3 by @bobcallaway in #1806

New Contributors

Full Changelog: v1.3.2...v1.3.3

v1.3.2

11 Oct 14:09
1c2ae1c
Compare
Choose a tag to compare

Changelog

  • 1c2ae1c changelog for v1.3.2 (#1758)
  • 4d6ff8a build(deps): Bump golang.org/x/net from 0.16.0 to 0.17.0 (#1753)
  • c7647b7 build(deps): Bump github.com/google/go-cmp from 0.5.9 to 0.6.0 (#1755)
  • 5310881 build(deps): Bump google/cloud-sdk from 449.0.0 to 450.0.0 (#1757)
  • 0a110e5 build(deps): Bump google.golang.org/grpc from 1.58.2 to 1.58.3 (#1754)
  • 9310915 update Dockerfile for go 1.21.3 (#1752)
  • 8052daa update builder image to use go1.21.3 (#1751)
  • 49a291a build(deps): Bump google/cloud-sdk from 0c79a8f to 538c693 (#1750)
  • f5c00ea add CHANGELOG for v1.3.1 (#1749)

Thanks for all contributors!