<feed xmlns='http://www.w3.org/2005/Atom'>
<title>linux/meta-virtualization.git/recipes-containers/cosign/go-mod-cache.inc, branch master-next</title>
<subtitle>Mirror of git.yoctoproject.org/meta-virtualization</subtitle>
<id>https://git.enea.com/cgit/linux/meta-virtualization.git/atom?h=master-next</id>
<link rel='self' href='https://git.enea.com/cgit/linux/meta-virtualization.git/atom?h=master-next'/>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/meta-virtualization.git/'/>
<updated>2026-05-29T18:28:29+00:00</updated>
<entry>
<title>cosign: regen go-mod-licenses.inc with module-path encoding fix</title>
<updated>2026-05-29T18:28:29+00:00</updated>
<author>
<name>Bruce Ashfield</name>
<email>bruce.ashfield@gmail.com</email>
</author>
<published>2026-05-29T18:28:29+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/meta-virtualization.git/commit/?id=8dfaf821a861971be8f9a9c25aeaa90bfa0b60bb'/>
<id>urn:sha1:8dfaf821a861971be8f9a9c25aeaa90bfa0b60bb</id>
<content type='text'>
Picks up 16 entries that the previous writer silently dropped because
their canonical module paths contained ASCII uppercase letters and the
filter comparison was against the filesystem-encoded form. The added
modules are Azure SDK-for-Go components, Aliyun container service,
Azure-AD MSAL, and Azure/go-autorest — all present in cosign's
imported set but missing from the committed licenses.inc.

Also picks up a 1-line vcs_ref hint shift in go-mod-cache.inc for
honnef.co/go/tools (v0.1.2 → v0.9.0). Metadata only — bitbake's
fetcher uses the hash, not the ref hint, so the build is unchanged.

Root cause fix: 2f15273a "oe-go-mod-fetcher: encode Go module paths
in LIC_FILES_CHKSUM URIs".

Signed-off-by: Bruce Ashfield &lt;bruce.ashfield@gmail.com&gt;
</content>
</entry>
<entry>
<title>cosign: update to v3.0.6-tip</title>
<updated>2026-05-28T02:23:10+00:00</updated>
<author>
<name>Bruce Ashfield</name>
<email>bruce.ashfield@gmail.com</email>
</author>
<published>2026-05-27T19:03:35+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/meta-virtualization.git/commit/?id=63c82fc8dfb89a829cf05ef8666a9d8dab7b4168'/>
<id>urn:sha1:63c82fc8dfb89a829cf05ef8666a9d8dab7b4168</id>
<content type='text'>
Bumping cosign to version v3.0.6-44-g55f4d9e2, which comprises the following commits:

    55f4d9e2 Enable initialize command output in conformance (#4892)
    9146e3fd Fix Ed25519ph check to respect custom signing configs in sign-blob (#4880)
    0bfb59e0 chore(deps): bump github.com/jackc/pgx/v5 from 5.8.0 to 5.9.2 (#4833)
    3384f6a2 chore(deps): bump the actions group with 4 updates (#4890)
    f3177523 chore(deps): bump actions/github-script from 8.0.0 to 9.0.0 (#4891)
    074c598a chore(deps): bump k8s.io/apimachinery from 0.35.3 to 0.36.1 (#4859)
    ca9906d1 chore(deps): bump github.com/buildkite/agent/v3 from 3.118.0 to 3.127.0 (#4861)
    5b603990 update go-github to v88 (#4887)
    29dc88b8 bump static-debian to static-debian13 (#4888)
    74650550 update builder to use go1.26.3 (#4885)
    cb68b297 bump golangci-lint (#4886)
    da174ac4 Fix unsafe type assertion in Rego policy evaluation (#4882)
    b4e1761f fix: check HTTP status code in LoadFileOrURL (#4877)
    a01e484b Use the configured Target Repository more consistently. (#4836)
    d3f481eb Deprecate Flags for v4: OCI Referrers (#4804)
    6ea2f187 Fix crash verifying timestamps when no timestamp was verified (#4881)
    7993b350 Undo skip setcap for HashiCorp Vault (#4879)
    cd402b41 Fix impossible status code checks in GitHub provider PutSecret (#4876)
    f02ee6f5 chore(deps): bump github.com/open-policy-agent/opa from 1.14.1 to 1.16.2 (#4862)
    cca05a3f chore(deps): bump github.com/go-piv/piv-go/v2 from 2.5.0 to 2.6.0 (#4863)
    2d3bebf1 chore(deps): bump github.com/in-toto/attestation from 1.1.2 to 1.2.0 (#4798)
    4df4c13c chore(deps): bump golang from 1.25.6 to 1.25.7 in the all group (#4690)
    b2cc7950 chore(deps): bump codecov/codecov-action from 5.5.2 to 6.0.0 (#4800)
    e5871155 chore(deps): bump github.com/in-toto/in-toto-golang (#4855)
    4df629ef chore(deps): bump the actions group across 1 directory with 6 updates (#4864)
    bf57b898 feat(cli): add Rekor v2 flag to cosign signing-config create (#4868)
    8a86a7cf fix: use Header.Set to prevent duplicate Authorization on retry (#4870)
    b33aaacb fix: close file descriptor leaked in WriteSignedImageIndexImages loop (#4869)
    d5891a86 deprecate private-infrastructure and record-creation-timestamp flags (#4854)
    a1ec0737 Add bundle upgrade command (#4820)
    6a80f22c Fix typo in map of verify fields unsupported for new bundle format (#4853)
    f15ac759 Deprecate flags bundle (#4838)
    08952e2c Deprecate flags signing config (#4844)
    f5373b06 Switch from cosign copy to oras copy (#4819)
    5fff8869 Deprecate Flags for v4: Certificates (#4822)
    39940de0 chore(deps): bump the gomod group across 1 directory with 10 updates (#4840)
    394ab4da fix: honor --digestAlg when hashing a blob in verify-blob-attestation (#4813)
    f02250eb fix(load): pass NameOptions to name.ParseReference (#4786)
    032c0ea4 Update conformance to latest (#4843)
    13a3d79e Require bundle output or registry upload (#4785)
    040443cf bundle create: Prevent IgnoreTlog when bundle contains SET (#4829)
    b7462fb6 ci: Skip setcap for HashiCorp Vault
    1d5c7a6d Sign exclusively via sigstore-go (#4618)
    a6bd85fc fix(pkcs11-tool): GetKeysInfo not initializing YKCS11 correctly (#4803)
    f1ad3ee9 Fix DSSE predicate check (GHSA-w6c6-c85g-mmv6) (#4801)

Signed-off-by: Bruce Ashfield &lt;bruce.ashfield@gmail.com&gt;
</content>
</entry>
<entry>
<title>cosign: convert to go-mod-vcs hybrid fetch</title>
<updated>2026-04-28T14:16:28+00:00</updated>
<author>
<name>Bruce Ashfield</name>
<email>bruce.ashfield@gmail.com</email>
</author>
<published>2026-04-28T14:16:28+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/meta-virtualization.git/commit/?id=3b721edc4d86ef2d5188311c41ca4d184f0b6943'/>
<id>urn:sha1:3b721edc4d86ef2d5188311c41ca4d184f0b6943</id>
<content type='text'>
Convert from go-mod + go-mod-update-modules to go-mod-vcs hybrid
fetch mode, consistent with other Go recipes in the layer (k3s,
nerdctl, docker-compose, etc.).

- Replace cosign-go-mods.inc (gomod:// only) with generated
  go-mod-hybrid-{gomod,git,cache}.inc and go-mod-{git,cache}.inc
- Keep cosign-licenses.inc for dependency license tracking (our
  go-mod-vcs tooling does not yet generate license metadata)
- Add GO_MOD_VCS_EXCLUDE for buf.build (no git repo) and
  software.sslmate.com/src/go-pkcs12 (unreachable commit)
- Set GO_MOD_DISCOVERY_SRCDIR to match go.bbclass source layout

Signed-off-by: Bruce Ashfield &lt;bruce.ashfield@gmail.com&gt;
</content>
</entry>
</feed>
