Skip to content

Releases: sigstore/fulcio

v1.4.3

11 Oct 23:49
99cb25d
Compare
Choose a tag to compare

v1.4.3

Bug Fixes

  • Bump golang.org/x/net from 0.15.0 to 0.17.0 in /hack/tools (#1409)
  • Bump golang.org/x/net from 0.15.0 to 0.17.0 (#1410)

Contributors

  • dependabot

Thanks for all contributors!

v1.4.2

11 Oct 14:10
c5f47ca
Compare
Choose a tag to compare

Changelog

Thanks for all contributors!

v1.4.1

09 Oct 23:28
v1.4.1
5873bc8
Compare
Choose a tag to compare

v1.4.1

v1.4.1 disables CGO for released binaries and containers. If you need support
for an HSM-backed CA, compile Fulcio with CGO_ENABLED=1.

The Distroless base image of the released containers has been updated to Debian 12,
gcr.io/distroless/static-debian12:nonroot.

Features

  • Do not block startup if OIDC provider cannot be created (#1389)
  • Gracefully shutdown HTTP, gRPC, and Prom servers (#1342)
  • Create interface for GRPC server which encompasses the GRPC HealthServer (#1334)

Release

  • update builder image to use go1.21.2 (#1397)
  • Disable CGO on release builds (#1368)

Contributors

  • Appu
  • Hayden B
  • Jon Johnson
  • Jussi Kukkonen
  • Priya Wadhwa
  • William Woodruff

Full Changelog: v1.4.0...v1.4.1

v1.4.0

19 Jul 21:28
v1.4.0
9bd68ba
Compare
Choose a tag to compare

v1.4.0

Features

  • Add "Source Repository Visibility At Signing" ext (#1279)
  • Expose SkipExpiryCheck OIDC Config Option in Verifier (#1271)

Documentation

  • Update loadtest instructions (#1284)

Contributors

  • Hayden B
  • Philip Harrison
  • Priya Wadhwa

Full Changelog: v1.3.4...v1.4.0

v1.3.4

11 Jul 16:29
b55b6ba
Compare
Choose a tag to compare

Changelog

  • b55b6ba changelog for v1.3.4 (#1270)
  • a4b3e12 Update GitLab claim mappings for build configs (#1206)
  • 07f0ac4 add container builds for each push to main (#1269)
  • dcfd044 always use non-TLS credentials to connect over unix domain socket (#1268)

Thanks for all contributors!

v1.3.3

08 Jul 11:12
3815318
Compare
Choose a tag to compare

Changelog

  • 3815318 changelog for v1.3.3 release (#1266)
  • 1923fa1 add HTTP and GRPC health check endpoints (#1258)
  • 489d73a add fsnotify-backed cache for reading TLS PKI material (#1256)
  • 12aa925 Bump protocolbuffers/protobuf from 23.3 to 23.4 (#1264)
  • 3ce99aa Bump google.golang.org/grpc from 1.56.1 to 1.56.2 (#1265)
  • 2b8e2dc Bump google.golang.org/api from 0.129.0 to 0.130.0 (#1260)
  • 6debe57 Bump github.com/googleapis/api-linter in /hack/tools (#1261)
  • e626775 Bump golang from 7925d69 to fd9306e (#1262)
  • a3fea01 Bump golang from 344193a to 7925d69 (#1259)
  • a5b774d Bump github.com/googleapis/api-linter in /hack/tools (#1255)

Thanks for all contributors!

v1.3.2

28 Jun 19:37
v1.3.2
2454717
Compare
Choose a tag to compare

v1.3.2

Features

  • configure server-side TLS on grpc listener (#1252)

Bug fixes

  • gitlab: remove build config URI. (#1183)

Documentation

  • Update OID info (#1188)
  • Fix spellings, update protoc (#1184)
  • docs/oid-info: clarify source of issuer extensions (#1158)

Contributors

  • Billy Lynch
  • Bob Callaway
  • Carlos Tadeu Panato Junior
  • Hayden B
  • Kristian Klausen
  • William Woodruff

Full Changelog: v1.3.1...v1.3.2

v1.3.1

03 May 21:38
v1.3.1
ea02258
Compare
Choose a tag to compare

v1.3.1

Bug Fixes

  • fix cert.URIs for GitLab CI (#1144)

Contributors

  • Carlos Tadeu Panato Junior

v1.3.0

01 May 20:50
v1.3.0
d8fe6bd
Compare
Choose a tag to compare

v1.3.0

Fulcio 1.3.0 adds support for GitLab CI.

Enhancements

  • Add GitLab.com OIDC to Fulcio (#983)
  • Change ParseDerString to Public Function (#1119)
  • Support enterprise-unique GitHub Actions OIDC issuer URLs (#1088)

Documentation

  • Map GitLab OIDC token claims to Fulcio OIDs (#1097)
  • Mark GitLab JWT claim fields that are still WIP. (#1139)
  • oidc.md: Add section for how to select SANs. (#1127)
  • oid-info: Drop Build Signer Digest requirement from MUST -> SHOULD (#1126)
  • update docs to use CDN-backed TUF endpoint (#1108)

Contributors

  • Alishan Ladhani
  • Billy Lynch
  • Bob Callaway
  • Carlos Tadeu Panato Junior
  • Hayden B
  • James Ma
  • Paul Welch
  • Reed Loden
  • Sandipan Panda

Full Changelog: v1.2.0...v1.3.0

v1.2.0

27 Mar 22:52
v1.2.0
8e222e9
Compare
Choose a tag to compare

v1.2.0

Fulcio 1.2.0 adds support for additional extensions in certificates issued for
CI platforms, starting with GitHub Actions.

Deprecation warning: OIDs 1.3.6.1.4.1.57264.1.1 through 1.3.6.1.4.1.57264.1.6 have been deprecated,
but are still present in the issued certificates. The new extensions 1.3.6.1.4.1.57264.1.8
through 1.3.6.1.4.1.57264.1.21 are correctly formatted as DER-encoded strings.

Enhancements

  • Implement standardized CI extensions for GitHub (#1073)
  • Allow specifying ChallengeClaim for an Issuer in the Fulcio config (#1007)
  • Support custom OIDC issuers
    • Begin implementing Issuer interface for email and github identities (#1005)
    • Implement Issuer interface for spiffe and kubernetes types (#1033)
    • Implement Issuer interface for username and uri Issuer types (#1035)
    • implement Issuer interface for buildkite (#1037)
    • Create BaseIssuer type to implement Match for all Issuers (#1039)
    • Use Issuer interface to allow for custom issuers (#1008)

Bug Fixes

  • Don't add nil issuers to issuer pool (#1053)

Documentation

  • Standardizing Fulcio Certificate Extensions (#945)
  • Add documentation for adding a new OIDC issuer (#1042)
  • Update TUF instructions in README (#1079)

Contributors

  • Carlos Tadeu Panato Junior
  • Hayden B
  • Philip Harrison
  • priyawadhwa

Full Changelog: v1.1.0...v1.2.0