- Dynamic construction of Sigstore API URLs
- Bump @sigstore/bundle from 2.3.0 to 2.3.2
- Bump @sigstore/sign from 2.3.0 to 2.3.2
- Retry request on attestation persistence failure
- Generate attestations using the v0.3 Sigstore bundle format.
- Bump @sigstore/bundle from 2.2.0 to 2.3.0.
- Bump @sigstore/sign from 2.2.3 to 2.3.0.
- Remove dependency on make-fetch-happen
- Updates the
attestProvenance
function to retrieve a token from the GitHub OIDC provider and use the token claims to populate the provenance statement.
- Initial release