diff --git a/Cargo.lock b/Cargo.lock index 84cd1a7..4f8c35f 100644 --- a/Cargo.lock +++ b/Cargo.lock @@ -181,11 +181,11 @@ dependencies = [ "serde_with", "serde_yaml", "sha2 0.11.0", - "sigstore-crypto", + "sigstore-crypto 0.6.6", "sigstore-fulcio", "sigstore-oidc", "sigstore-rekor", - "sigstore-types", + "sigstore-types 0.6.6", "subtle", "tdx_workload_attestation", "tempfile", @@ -2461,7 +2461,29 @@ dependencies = [ "rand_core 0.10.1", "sha2 0.10.9", "signature", - "sigstore-types", + "sigstore-types 0.6.6", + "spki", + "thiserror 2.0.18", + "tracing", + "x509-cert", +] + +[[package]] +name = "sigstore-crypto" +version = "0.8.0" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "9cdc66f1480e176533425cc880bc5f8a8e0d88ae1fe2701e98de4fb68984b71c" +dependencies = [ + "aws-lc-rs", + "base64", + "const-oid 0.9.6", + "der", + "digest 0.10.7", + "pem", + "rand_core 0.9.5", + "sha2 0.10.9", + "signature", + "sigstore-types 0.8.0", "spki", "thiserror 2.0.18", "tracing", @@ -2478,23 +2500,23 @@ dependencies = [ "reqwest 0.13.3", "serde", "serde_json", - "sigstore-crypto", + "sigstore-crypto 0.6.6", "sigstore-oidc", - "sigstore-types", + "sigstore-types 0.6.6", "thiserror 2.0.18", "url", ] [[package]] name = "sigstore-merkle" -version = "0.6.6" +version = "0.8.0" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "7c0d53558825c77716855c13794306fff766854c1bf92948e77d7890da3f2455" +checksum = "a4dbea5d8d5f293dfc2ed6abd06dc26a5ef017af126e53e3e36a6b2f7b7dac8c" dependencies = [ "base64", "hex", - "sigstore-crypto", - "sigstore-types", + "sigstore-crypto 0.8.0", + "sigstore-types 0.8.0", "thiserror 2.0.18", ] @@ -2510,8 +2532,8 @@ dependencies = [ "reqwest 0.13.3", "serde", "serde_json", - "sigstore-crypto", - "sigstore-types", + "sigstore-crypto 0.6.6", + "sigstore-types 0.6.6", "thiserror 2.0.18", "tokio", "url", @@ -2519,18 +2541,18 @@ dependencies = [ [[package]] name = "sigstore-rekor" -version = "0.6.6" +version = "0.8.0" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "641fdaaa40d0cd6e249cf1671c2240beff1a3ece578062cf43e750779e8db2b3" +checksum = "fbe0bf948de89bed9b3b5c9d62940264a4da60db3518006b952b107d0e71926f" dependencies = [ "base64", "hex", "reqwest 0.13.3", "serde", "serde_json", - "sigstore-crypto", + "sigstore-crypto 0.8.0", "sigstore-merkle", - "sigstore-types", + "sigstore-types 0.8.0", "thiserror 2.0.18", "url", ] @@ -2550,6 +2572,20 @@ dependencies = [ "thiserror 2.0.18", ] +[[package]] +name = "sigstore-types" +version = "0.8.0" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "7fb0334b69834c1f29757e57ade7e9bdbc42f5383cc22d003256d4d2df47af13" +dependencies = [ + "base64", + "hex", + "pem", + "serde", + "serde_json", + "thiserror 2.0.18", +] + [[package]] name = "simd-adler32" version = "0.3.9" diff --git a/Cargo.toml b/Cargo.toml index f6715ac..9b22c55 100644 --- a/Cargo.toml +++ b/Cargo.toml @@ -74,7 +74,7 @@ subtle = "2.6.1" # Sigstore sigstore-types = "0.6.5" -sigstore-rekor = { version = "0.6.5", default-features = false, features = ["rustls"] } +sigstore-rekor = { version = "0.8.0", default-features = false, features = ["rustls"] } sigstore-fulcio = { version = "0.6.5", default-features = false, features = ["rustls"] } sigstore-oidc = { version = "0.6.5", default-features = false, features = ["rustls"] } sigstore-crypto = "0.6.5"