Index index by Group index by Distribution index by Vendor index by creation date index by Name Mirrors Help Search

slsa-verifier-2.7.1-1.1 RPM for riscv64

From OpenSuSE Ports Tumbleweed for riscv64

Name: slsa-verifier Distribution: openSUSE Tumbleweed
Version: 2.7.1 Vendor: openSUSE
Release: 1.1 Build date: Mon Jun 30 07:58:01 2025
Group: System/Management Build host: reproducible
Size: 24914846 Source RPM: slsa-verifier-2.7.1-1.1.src.rpm
Packager: https://bugs.opensuse.org
Url: https://github.com/slsa-framework/slsa-verifier
Summary: Verify provenance from SLSA compliant builders
slsa-verifier is a tool for verifying SLSA provenance that was generated by
CI/CD builders. slsa-verifier verifies the provenance by verifying the
cryptographic signatures on provenance to make sure it was created by the
expected builder. It then verifies that various values such as the builder id,
source code repository, ref (branch or tag) matches the expected values.

Provides

Requires

License

Apache-2.0

Changelog

* Mon Jun 30 2025 Johannes Kastl <opensuse_buildservice@ojkastl.de>
  - update to 2.7.1:
    * chore: Update docs for v2.7.0 by @ramonpetgrave64 in #829
    * docs(npm): "exmaple" spelling fix by @scop in #832
    * chore: update test files for v2.1.0 by @ramonpetgrave64 in #836
    * feat: verify provenance for bcr modules produced by trusted
      reusable workflows by @loosebazooka in #840
    * chore(deps): update golang:1.23 docker digest to cc458d7 by
      @renovate-bot in #838
    * fix: less parallelism in tests by @ramonpetgrave64 in #851
    * chore(deps): bump @octokit/request-error from 5.0.1 to 5.1.1 in
      /actions/installer in the npm_and_yarn group across 1 directory
      by @dependabot in #833
    * chore(deps): bump github.com/go-jose/go-jose/v4 from 4.0.4 to
      4.0.5 in the go_modules group by @dependabot in #835
    * chore(deps): bump the go_modules group across 1 directory with
      2 updates by @dependabot in #853
    * fix(deps): update npm by @renovate-bot in #843
    * fix(deps): update golang.org/x/exp digest to dcc06ee by
      @renovate-bot in #839
    * fix: no parallel regression tests by @ramonpetgrave64 in #855
    * chore(deps): update golang:1.23 docker digest to dd5cc4b by
      @renovate-bot in #847
    * chore(deps): update gcr.io/distroless/base:nonroot docker
      digest to 0a0dc20 by @renovate-bot in #844
    * chore(deps): bump the npm_and_yarn group across 2 directories
      with 5 updates by @dependabot in #854
    * feat: Bazel not experimental by @ramonpetgrave64 in #850
    * docs: add section for verify-github-attestation by
      @loosebazooka in #858
* Sat Feb 08 2025 Johannes Kastl <opensuse_buildservice@ojkastl.de>
  - update to 2.7.0:
    * chore: v2.6.0: update docs by @ramonpetgrave64 in #789
    * chore: Update CODEOWNERS to use teams by @haydentherapper in
      [#793]
    * chore(deps): bump github.com/docker/docker from
      24.0.9+incompatible to 26.1.4+incompatible in the go_modules
      group by @dependabot in #794
    * feat: support npm cli provenance v1 attestations by
      @ramonpetgrave64 in #776
    * chore: pin yamllint, golangci-lint by @ramonpetgrave64 in #783
    * feat: refactor: use sigstore-go for fetching TrustedRoot by
      @ramonpetgrave64 in #791
    * chore(deps): update golang:1.21 docker digest to f2eb989 by
      @renovate-bot in #796
    * chore(deps): bump github.com/docker/docker from
      26.1.4+incompatible to 26.1.5+incompatible in the go_modules
      group by @dependabot in #798
    * chore: fix vuln: override autolinker ^4.0.0 by @ramonpetgrave64
      in #785
    * chore(config): migrate renovate config by @renovate-bot in #800
    * feat: set user-agent header on Rekor requests by @bobcallaway
      in #801
    * feat: handle dssev001 tlog entry types by @ramonpetgrave64 in
      [#799]
    * fix(deps): update golang.org/x/exp digest to 225e2ab by
      @renovate-bot in #803
    * chore(deps): update dependency pyyaml to v6.0.2 by
      @renovate-bot in #808
    * chore(deps): update golang:1.21 docker digest to 4746d26 by
      @renovate-bot in #802
    * fix(deps): update dependency org.apache.maven:maven-plugin-api
      to v3.9.9 by @renovate-bot in #809
    * chore: update go and golanci lint by @ramonpetgrave64 in #810
    * feat(action): Updating to Node20 by @IAreKyleW00t in #811
    * fix(deps): update module github.com/sigstore/sigstore-go to
      v0.6.1 [security] by @renovate-bot in #805
    * chore(deps): update gcr.io/distroless/base:nonroot docker
      digest to e5260be by @renovate-bot in #795
    * chore(deps): bump github.com/sigstore/sigstore-go from 0.6.1 to
      0.6.2 in the go_modules group across 1 directory by @dependabot
      in #812
    * fix: fix method for getting leaf certs in Bundle v0.3 by
      @ramonpetgrave64 in #813
    * chore(deps): update github-actions by @renovate-bot in #817
    * chore(deps): update golang docker tag to v1.23 by @renovate-bot
      in #818
    * fix(deps): update dependency @actions/core to v1.11.1 by
      @renovate-bot in #819
    * chore(deps): bump github.com/theupdateframework/go-tuf/v2 from
      2.0.0 to 2.0.1 in the go_modules group by @dependabot in #820
    * chore(deps): bump golang.org/x/crypto from 0.27.0 to 0.31.0 in
      the go_modules group by @dependabot in #821
    * fix(deps): update dependency org.apache.maven:maven-core to
      v3.9.9 by @renovate-bot in #816
    * fix(deps): update dependency
      org.apache.maven.plugin-tools:maven-plugin-annotations to
      v3.15.1 by @renovate-bot in #824
    * chore(deps): update github-actions by @renovate-bot in #823
    * chore(deps): bump golang.org/x/net from 0.27.0 to 0.33.0 in the
      go_modules group by @dependabot in #826
    * fix(deps): update go by @renovate-bot in #825
    * chore(deps): update golang:1.23 docker digest to 51a6466 by
      @renovate-bot in #822
    * fix(deps): update golang.org/x/exp digest to 3edf0e9 by
      @renovate-bot in #815
    * chore(deps): update gcr.io/distroless/base:nonroot docker
      digest to 97d1521 by @renovate-bot in #814
    * chore(deps): bump undici from 5.28.4 to 5.28.5 in
      /actions/installer in the npm_and_yarn group across 1 directory
      by @dependabot in #827
* Fri Aug 16 2024 Johannes Kastl <opensuse_buildservice@ojkastl.de>
  - update to 2.6.0:
    * chore: Update doc and digests for v2.5.1 by @laurentsimon in
      [#748]
    * fix(deps): update module google.golang.org/protobuf to v1.33.0
      [security] by @renovate-bot in #743
    * fix(deps): update dependency org.apache.maven:maven-core to
      v3.9.6 by @renovate-bot in #718
    * chore: Update @actions/github v6 by @laurentsimon in #749
    * fix: use sigstore/pkg/fulcioroots to lessen deps by
      @ramonpetgrave64 in #746
    * feat: add ramonpetgrave64 as CODEOWNER by @ramonpetgrave64 in
      [#750]
    * chore(deps): update gcr.io/distroless/base:nonroot docker
      digest to 1a8ece8 by @renovate-bot in #701
    * chore(deps): update github-actions (major) by @renovate-bot in
      [#719]
    * fix(deps): update dependency org.apache.maven:maven-plugin-api
      to v3.9.6 by @renovate-bot in #751
    * chore(deps): update npm dev (major) by @ramonpetgrave64 in #753
    * fix(deps): update dependency
      org.apache.maven.plugin-tools:maven-plugin-annotations to
      v3.11.0 by @renovate-bot in #752
    * feat: fixes #547: add npm sigstore-tuf suport by
      @ramonpetgrave64 in #731
    * fix(deps): update module github.com/sigstore/cosign/v2 to
      v2.2.4 [security] by @renovate-bot in #723
    * chore(deps): update golang:1.21 docker digest to 81811f8 by
      @renovate-bot in #693
    * chore: slsa-framework/slsa-github-generator@v2.0.0: add
      testdata by @ramonpetgrave64 in #758
    * chore(deps): update golang:1.21 docker digest to d83472f by
      @renovate-bot in #764
    * chore(deps): update gcr.io/distroless/base:nonroot docker
      digest to 53745e9 by @renovate-bot in #763
    * feat: workflow to update actions dist by @ramonpetgrave64 in
      [#760]
    * fix(deps): update dependency @actions/core to v1.10.1 by
      @renovate-bot in #717
    * chore: fix pr-title-checker by @ianlewis in #770
    * chore: Update Renovate config by @ianlewis in #769
    * fix: use pr_number as env variable by @ramonpetgrave64 in #771
    * fix: signoff commit by @ramonpetgrave64 in #767
    * chore(deps): bump golang.org/x/net from 0.22.0 to 0.23.0 by
      @dependabot in #781
    * chore(deps): bump github.com/hashicorp/go-retryablehttp from
      0.7.5 to 0.7.7 by @dependabot in #782
    * chore(deps): bump undici from 5.28.3 to 5.28.4 in
      /actions/installer by @dependabot in #779
    * chore(deps-dev): bump braces from 3.0.2 to 3.0.3 in
      /actions/installer by @dependabot in #780
    * chore(deps): bump the npm_and_yarn group across 2 directories
      with 2 updates by @dependabot in #784
    * fix(deps): update golang.org/x/exp digest to 7f521ea by
      @renovate-bot in #775
    * fix: make download-artifacts.sh more flexible by
      @ramonpetgrave64 in #761
    * chore(deps): update golang:1.21 docker digest to b405b62 by
      @renovate-bot in #774
    * chore(deps): update npm dev by @renovate-bot in #650
    * fix(deps): update dependency org.apache.maven:maven-core to
      v3.9.8 by @renovate-bot in #787
    * chore(deps): update github-actions by @renovate-bot in #786
    * feat: vsa support by @ramonpetgrave64 in #777
    * fix: use tag for the builder in the release workflow by
      @ramonpetgrave64 in #788
* Thu Jun 13 2024 Dirk Müller <dmueller@suse.com>
  - update to 2.5.1:
    * feat: Add cosign registry opts for provenance registry
    * feat: Add support for DSSE Rekor type
* Mon Mar 18 2024 Dirk Müller <dmueller@suse.com>
  - Initial packaging (2.4.1)

Files

/usr/bin/slsa-verifier
/usr/share/doc/packages/slsa-verifier
/usr/share/doc/packages/slsa-verifier/README.md
/usr/share/licenses/slsa-verifier
/usr/share/licenses/slsa-verifier/LICENSE


Generated by rpm2html 1.8.1

Fabrice Bellet, Wed Oct 8 23:32:53 2025