Skip to content

build(deps): bump azure/trusted-signing-action from 0.5 to 2 - #177

Closed
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/github_actions/azure/trusted-signing-action-2
Closed

build(deps): bump azure/trusted-signing-action from 0.5 to 2#177
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/github_actions/azure/trusted-signing-action-2

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 21, 2026

Copy link
Copy Markdown
Contributor

Bumps azure/trusted-signing-action from 0.5 to 2.

Release notes

Sourced from azure/trusted-signing-action's releases.

v2.0.0

What's Changed

Full Changelog: Azure/artifact-signing-action@v1.2.0...v2.0.0

v1.2.0

What's Changed

New Contributors

Full Changelog: Azure/artifact-signing-action@v1.1.0...v1.2.0

v1.1.0

What's Changed

Full Changelog: Azure/artifact-signing-action@v1...v1.1.0

Artifact Signing v1.0.0

Rebranding action from Trusted Signing into Artifact Signing. This will be our initial version for GA.

v0.5.11

What's Changed

Full Changelog: Azure/artifact-signing-action@v0...v0.5.11

v0.5.10

What's Changed

New Contributors

... (truncated)

Commits
  • c7ab2a8 refactor: upgrade packages to the latest versions (#135)
  • 7664cea docs: update README runtime version and action references (#139)
  • 64185d8 refactor: migrate to new artifactsigning module (#133)
  • b443cf8 Update internal actions/cache to v5.0.4 (#126)
  • 6c581eb refactor: disable az credential types by default except cli and env vars (#122)
  • dd27d98 docs: update examples to remove azps session (#123)
  • 87c2e83 feat: check runner prior to execution (#120)
  • d15bd92 chore: upgrade cache-action to version 4.3.0 (#116)
  • 2eddbb3 docs: update lack of support for win arm (#117)
  • f3a110b chore: update code owners to artifact signing team (#118)
  • Additional commits viewable in compare view

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Aug 21, 2026
@dependabot dependabot Bot changed the title chore(deps): bump azure/trusted-signing-action from 0.5 to 2 build(deps): bump azure/trusted-signing-action from 0.5 to 2 Aug 21, 2026
@dependabot
dependabot Bot force-pushed the dependabot/github_actions/azure/trusted-signing-action-2 branch 2 times, most recently from b98824d to ce4c635 Compare August 22, 2026 11:44
Bumps [azure/trusted-signing-action](https://github.com/azure/trusted-signing-action) from 0.5 to 2.
- [Release notes](https://github.com/azure/trusted-signing-action/releases)
- [Commits](Azure/artifact-signing-action@v0.5...v2)

---
updated-dependencies:
- dependency-name: azure/trusted-signing-action
  dependency-version: '2'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/github_actions/azure/trusted-signing-action-2 branch from ce4c635 to b11d473 Compare August 22, 2026 13:32
@SSC-STUDIO

Copy link
Copy Markdown
Owner

Skipping: trusted-signing-action 0.5 to 2 is a sensitive signing bump and smoke failed. Leave the current pin until a green, reviewed upgrade.

@SSC-STUDIO SSC-STUDIO closed this Aug 23, 2026
@dependabot @github

dependabot Bot commented on behalf of github Aug 23, 2026

Copy link
Copy Markdown
Contributor Author

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@dependabot
dependabot Bot deleted the dependabot/github_actions/azure/trusted-signing-action-2 branch August 23, 2026 12:22
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant