Script 'mail_helper' called by obssrc Hello community, here is the log from the commit of package rekor for openSUSE:Factory checked in at 2022-06-20 15:38:21 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Comparing /work/SRC/openSUSE:Factory/rekor (Old) and /work/SRC/openSUSE:Factory/.rekor.new.1548 (New) ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "rekor" Mon Jun 20 15:38:21 2022 rev:6 rq:983855 version:0.8.1 Changes: -------- --- /work/SRC/openSUSE:Factory/rekor/rekor.changes 2022-04-26 20:17:36.656749242 +0200 +++ /work/SRC/openSUSE:Factory/.rekor.new.1548/rekor.changes 2022-06-20 15:39:11.939028278 +0200 @@ -1,0 +2,29 @@ +Mon Jun 20 06:54:51 UTC 2022 - Marcus Meissner <meiss...@suse.com> + +- Updated to rekor 0.8.1 + - Fix indexing bug for intoto attestations by @priyawadhwa in #870 + - Allow an expired certificate chain to be uploaded and verified by @haydentherapper in #873 +- Updated to rekor 0.8.0 + - Update go-tuf and sigstore/sigstore to non-vulnerable go-tuf version. by @dhaus67 in #847 + - Configure rekor server in e2e tests via env variable by @priyawadhwa in #850 + - update cross-builder image to use go1.17.11 and dockerfile base image by @cpanato in #860 + - update go.mod to go1.17 by @cpanato in #861 + - Improve error message when using ED25519 with HashedRekord type by @haydentherapper in #862 + - Allow retrieving entryIDs or UUIDs via /api/v1/log/entries/retrieve endpoint by @priyawadhwa in #859 + - Print total tree size, including inactive shards in rekor-cli loginfo by @priyawadhwa in #864 +- Updated to rekor 0.7.0 + - remove URL fetch of keys/artifacts server-side by @bobcallaway in #735 + - intoto: add index on materials digest of slsa provenance by @asraa in #793 + - chore(deps): Included dependency review by @naveensrinivasan in #788 + - Check if intoto hash is available before accessing it as an index key by @priyawadhwa in #800 + - Move deprecated dependency: google/trillian/merkle to transparency-dev by @asraa in #807 + - Retrieve shard tree length if it isn't provided in the config by @priyawadhwa in #810 + - update release builder images to use go 1.17.10 and cosign image to 1.8.0 by @cpanato in #820 + - update go to 1.17.10 in the dockerfile by @cpanato in #819 + - Limit the number of certificates parsed in a chain by @haydentherapper in #823 + - Breaking change: Remove timestamping authority by @haydentherapper in #813 + - Add back owners for rfc3161 package type by @haydentherapper in #833 + - all: remove dependency on deprecated github.com/pkg/errors by @zchee in #834 + - name stored attestations by digest instead of UUID by @bobcallaway in #769 + +------------------------------------------------------------------- Old: ---- rekor-0.6.0.tar.gz New: ---- rekor-0.8.1.tar.gz ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Other differences: ------------------ ++++++ rekor.spec ++++++ --- /var/tmp/diff_new_pack.sC0uEH/_old 2022-06-20 15:39:12.771029495 +0200 +++ /var/tmp/diff_new_pack.sC0uEH/_new 2022-06-20 15:39:12.779029507 +0200 @@ -19,9 +19,9 @@ %define apps cli server Name: rekor -Version: 0.6.0 +Version: 0.8.1 Release: 0 -%define revision 5c52ad228cb698ea4320dada5cd0a7cd31a5eb9a +%define revision e981811726530c70ec707902022c336d1f1c37b4 Summary: Supply Chain Transparency Log License: Apache-2.0 URL: https://github.com/sigstore/rekor ++++++ rekor-0.6.0.tar.gz -> rekor-0.8.1.tar.gz ++++++ ++++ 13620 lines of diff (skipped) ++++++ vendor.tar.xz ++++++ ++++ 870377 lines of diff (skipped)