about summary refs log tree commit diff
path: root/pkgs/tools/security/cosign
diff options
context:
space:
mode:
authorThomas Gerbet <thomas@gerbet.me>2022-08-05 09:01:25 +0200
committerzowoq <59103226+zowoq@users.noreply.github.com>2022-08-06 06:59:26 +1000
commit958dd9a8c7c335f7063bb0f73d02e6adb719683f (patch)
tree5e21d2b1b8491652eb7530ed9cf1cfe40f809736 /pkgs/tools/security/cosign
parenta7521391b9a944db65e3c0ce561079f12f654666 (diff)
cosign: 1.10.0 -> 1.10.1
https://github.com/sigstore/cosign/releases/tag/v1.10.1

Includes a fix for CVE-2022-35929
https://github.com/sigstore/cosign/security/advisories/GHSA-vjxv-45g9-9296
Diffstat (limited to 'pkgs/tools/security/cosign')
-rw-r--r--pkgs/tools/security/cosign/default.nix6
1 files changed, 3 insertions, 3 deletions
diff --git a/pkgs/tools/security/cosign/default.nix b/pkgs/tools/security/cosign/default.nix
index 4fe0fba4f65de..c698fa4fa9e9e 100644
--- a/pkgs/tools/security/cosign/default.nix
+++ b/pkgs/tools/security/cosign/default.nix
@@ -2,13 +2,13 @@
 
 buildGoModule rec {
   pname = "cosign";
-  version = "1.10.0";
+  version = "1.10.1";
 
   src = fetchFromGitHub {
     owner = "sigstore";
     repo = pname;
     rev = "v${version}";
-    sha256 = "sha256-EJ1NOaGLLBkEkWLWn8wfyFA6Kgsb9mctkw4G2um9cWE=";
+    sha256 = "sha256-DMNjzTor22uyTzieWsni9wvscfU7uCFuf3AXOYP4LRo=";
   };
 
   buildInputs = lib.optional (stdenv.isLinux && pivKeySupport) (lib.getDev pcsclite)
@@ -16,7 +16,7 @@ buildGoModule rec {
 
   nativeBuildInputs = [ pkg-config installShellFiles ];
 
-  vendorSha256 = "sha256-JL7bqdLrNwOQPVUhlIktRM1cAPycq0PVpB1xXXiJiKM=";
+  vendorSha256 = "sha256-onRfo3ZK/+uEa0xR7P9IlEsd2aXy9foJjZl0UBO/cbs=";
 
   subPackages = [
     "cmd/cosign"