diff --git a/actions/setup-sigstore-env/Dockerfile.cosign b/actions/setup-sigstore-env/Dockerfile.cosign index 7830a91dc..aaec3fa2c 100644 --- a/actions/setup-sigstore-env/Dockerfile.cosign +++ b/actions/setup-sigstore-env/Dockerfile.cosign @@ -13,6 +13,6 @@ # limitations under the License. # Use Cosign from a container so that Dependabot will keep the dependency up to date -FROM ghcr.io/sigstore/cosign/cosign:v3.0.6@sha256:de9c65609e6bde17e6b48de485ee788407c9502fa08b8f4459f595b21f56cd00 +FROM ghcr.io/sigstore/cosign/cosign:v3.1.3@sha256:9e5c2f2edc34351160407ca3416c61855bdf9403c3c5936e0f0be7fc261611b8 ENTRYPOINT [ "cosign" ] diff --git a/config/fulcio/fulcio/300-fulcio.yaml b/config/fulcio/fulcio/300-fulcio.yaml index 96f8362e3..dd450313b 100644 --- a/config/fulcio/fulcio/300-fulcio.yaml +++ b/config/fulcio/fulcio/300-fulcio.yaml @@ -20,7 +20,7 @@ spec: # This doesn't actually use Kubernetes credentials, so don't mount them in. automountServiceAccountToken: false containers: - - image: gcr.io/projectsigstore/fulcio:v1.8.5@sha256:b51ed0cb6761070d632bf81d28894ef1827b2c18da2535689ca8e98d91d3a015 + - image: gcr.io/projectsigstore/fulcio:v1.8.8@sha256:ef72cf56c64b7455ceda5268d1cc801b92992e7ce36b744b40b7761684d60753 name: fulcio ports: - containerPort: 5555 @@ -90,7 +90,7 @@ spec: # This doesn't actually use Kubernetes credentials, so don't mount them in. automountServiceAccountToken: false containers: - - image: gcr.io/projectsigstore/fulcio:v1.8.5@sha256:b51ed0cb6761070d632bf81d28894ef1827b2c18da2535689ca8e98d91d3a015 + - image: gcr.io/projectsigstore/fulcio:v1.8.8@sha256:ef72cf56c64b7455ceda5268d1cc801b92992e7ce36b744b40b7761684d60753 name: fulcio-grpc ports: - containerPort: 5554 diff --git a/config/rekor-tiles/rekor-tiles/300-rekor.yaml b/config/rekor-tiles/rekor-tiles/300-rekor.yaml index ef1d02d41..8bd6c1660 100644 --- a/config/rekor-tiles/rekor-tiles/300-rekor.yaml +++ b/config/rekor-tiles/rekor-tiles/300-rekor.yaml @@ -19,7 +19,7 @@ spec: serviceAccountName: rekor containers: - name: rekor-tiles-posix - image: ghcr.io/sigstore/rekor-tiles/posix:v2.2.1@sha256:627422bf9da146d1d9ff4e1c1e8301a1780ab6ad9b32bccff51ecd9f8c820e41 + image: ghcr.io/sigstore/rekor-tiles/posix:v2.3.0@sha256:a5ceeff41b2468f965f7259685a9553c6dbba6870108ffebfa6584df5ae22504 ports: - containerPort: 3000 args: [ diff --git a/config/tsa/tsa/300-tsa.yaml b/config/tsa/tsa/300-tsa.yaml index 8379cea1d..ab22bcb68 100644 --- a/config/tsa/tsa/300-tsa.yaml +++ b/config/tsa/tsa/300-tsa.yaml @@ -19,7 +19,7 @@ spec: serviceAccountName: tsa containers: - name: tsa - image: ghcr.io/sigstore/timestamp-server:v2.0.6@sha256:bb2e57fe86ba114663ed7cf98291add3c4131115169abf2929ec870c09d2493f + image: ghcr.io/sigstore/timestamp-server:v2.1.3@sha256:21b32b43cf51e4f1bcb76518727ddaecd58b16a7cab57bbd7e7bedea5696933b ports: - containerPort: 3000 args: [