Skip to content

v1.12.1

Compare
Choose a tag to compare
@sigstore-bot sigstore-bot released this 21 Sep 13:39
· 1094 commits to main since this release
0baa044

Highlights

fix: Pulls Fulcio root and intermediate when --certificate-chain is not passed into verify-blob command. The v1.12.0 release introduced a regression: when COSIGN_EXPERIMENTAL was not set, cosign verify-blob would check a --certificate (without a --certificate-chain provided) against the operating system root CA bundle. In this release, Cosign checks the certificate against Fulcio's CA root instead (restoring the earlier behavior).

What's Changed

New Contributors

Full Changelog: v1.12.0...v1.12.1