Skip to content

Commit d434dcc

Browse files
committed
Update after 2.0.0-rc2 release
Signed-off-by: Appu Goundan <[email protected]>
1 parent 93e444a commit d434dcc

File tree

8 files changed

+19
-34
lines changed

8 files changed

+19
-34
lines changed

CHANGELOG.md

Lines changed: 10 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -9,6 +9,16 @@ All versions prior to 1.0.0 are untracked
99

1010
## [Unreleased]
1111

12+
# [2.0.0-rc2] - 2025-10-21
13+
14+
## Fixed
15+
- Fix TUF snapshot version rollback case: https://github.com/sigstore/sigstore-java/pull/1061
16+
- Fix userAgent string in requests: https://github.com/sigstore/sigstore-java/pull/1066
17+
- Handle parsing/format failures: https://github.com/sigstore/sigstore-java/pull/1063, https://github.com/sigstore/sigstore-java/pull/1064, https://github.com/sigstore/sigstore-java/pull/1073, https://github.com/sigstore/sigstore-java/pull/1074, https://github.com/sigstore/sigstore-java/pull/1075
18+
19+
## Changed
20+
- Remove oidc config from gradle plugin: https://github.com/sigstore/sigstore-java/pull/1076
21+
1222
# [2.0.0-rc1] - 2025-08-14
1323

1424
## Added

build-logic/publishing/build.gradle.kts

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -11,7 +11,7 @@ dependencies {
1111
implementation(project(":basics"))
1212
implementation(project(":jvm"))
1313
implementation("dev.sigstore.build-logic:gradle-plugin")
14-
implementation("dev.sigstore:sigstore-gradle-sign-plugin:2.0.0-rc1")
14+
implementation("dev.sigstore:sigstore-gradle-sign-plugin:2.0.0-rc2")
1515
implementation("com.gradle.plugin-publish:com.gradle.plugin-publish.gradle.plugin:1.3.1")
1616
implementation("com.gradleup.nmcp:com.gradleup.nmcp.gradle.plugin:1.0.3")
1717
}

examples/hello-world/build.gradle.kts

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
plugins {
22
`java-library`
33
`maven-publish`
4-
val sigstoreVersion = System.getProperty("sigstore.version") ?: "2.0.0-rc1"
4+
val sigstoreVersion = System.getProperty("sigstore.version") ?: "2.0.0-rc2"
55
id("dev.sigstore.sign") version "$sigstoreVersion"
66
signing
77
}

examples/hello-world/pom.xml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -16,7 +16,7 @@
1616
<project.build.sourceEncoding>UTF-8</project.build.sourceEncoding>
1717
<project.reporting.outputEncoding>UTF-8</project.reporting.outputEncoding>
1818
<maven.compiler.release>11</maven.compiler.release>
19-
<sigstore.version>2.0.0-rc1</sigstore.version>
19+
<sigstore.version>2.0.0-rc2</sigstore.version>
2020
</properties>
2121

2222
<build>

gradle.properties

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -4,7 +4,7 @@ org.gradle.jvmargs=-XX:MaxMetaspaceSize=768m
44
group=dev.sigstore
55

66
# use the ./scripts/update_version.sh script to update all versions
7-
version=2.0.0-rc2
7+
version=2.0.0-rc3
88

99
# Kotlin Dokka is experemental, and we want silence the build warning
1010
org.jetbrains.dokka.experimental.gradle.pluginMode=V2Enabled

sigstore-gradle/README.md

Lines changed: 3 additions & 28 deletions
Original file line numberDiff line numberDiff line change
@@ -15,7 +15,7 @@ Signature format uses [Sigstore bundle](https://github.com/sigstore/protobuf-spe
1515

1616
```kotlin
1717
plugins {
18-
id("dev.sigstore.sign") version "2.0.0-rc1"
18+
id("dev.sigstore.sign") version "2.0.0-rc2"
1919
}
2020

2121
// Automatically sign all Maven publications, using GitHub Actions OIDC when available,
@@ -47,28 +47,9 @@ plugins {
4747
}
4848

4949
dependencies {
50-
// Override sigstore-java clients
50+
// Override sigstore-java clients, this may lead to unexpected behavior
5151
sigstoreClient("dev.sigstore:sigstore-java:<alternate-version>")
5252
}
53-
54-
sigstoreSign {
55-
oidcClient {
56-
// oidcClient configuration should very rarely be configured, it should be
57-
// inferred from a sigstore deployment's config obtained from a TUF repository
58-
// with a default set of ambient credential providers
59-
gitHub {
60-
audience.set("sigstore")
61-
}
62-
web {
63-
clientId.set("sigstore")
64-
issuer.set("https://oauth2.sigstore.dev/auth")
65-
}
66-
// override the client config to a specific provider
67-
client.set(web)
68-
// or
69-
client(web)
70-
}
71-
}
7253
```
7354

7455
## How to
@@ -147,13 +128,7 @@ Properties:
147128
Extensions:
148129
* `sigstoreSign`: `dev.sigstore.sign.SigstoreSignExtension`
149130

150-
Configures signing parameters
151-
152-
* `oidcClient`: `dev.sigstore.sign.OidcClientExtension`
153-
154-
Configures OIDC token source.
155-
156-
Supported sources: web browser, GitHub Actions.
131+
An empty extension that may support configuration in the feature
157132

158133
Configurations:
159134
* `sigstoreClient`

sigstore-gradle/sigstore-gradle-sign-base-plugin/src/main/kotlin/dev/sigstore/sign/SigstoreSignExtension.kt

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -46,7 +46,7 @@ abstract class SigstoreSignExtension(private val project: Project) {
4646
abstract val sigstoreJavaVersion : Property<String>
4747

4848
init {
49-
sigstoreJavaVersion.convention("2.0.0-rc2")
49+
sigstoreJavaVersion.convention("2.0.0-rc3")
5050
}
5151

5252
fun sign(publications: DomainObjectCollection<Publication>) {

sigstore-maven-plugin/README.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -17,7 +17,7 @@ Signature format uses [Sigstore bundle](https://github.com/sigstore/protobuf-spe
1717
<plugin>
1818
<groupId>dev.sigstore</groupId>
1919
<artifactId>sigstore-maven-plugin</artifactId>
20-
<version>2.0.0-rc1</version>
20+
<version>2.0.0-rc2</version>
2121
<executions>
2222
<execution>
2323
<id>sign</id>

0 commit comments

Comments
 (0)