Skip to content

Commit 671f1b5

Browse files
authored
Merge pull request #1206 from sigstore/post-2.2.0
Update after 2.2.0 release
2 parents 55eec24 + 8b727e2 commit 671f1b5

9 files changed

Lines changed: 22 additions & 7 deletions

File tree

CHANGELOG.md

Lines changed: 9 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -10,6 +10,15 @@ All versions prior to 1.0.0 are untracked
1010

1111
## [Unreleased]
1212

13+
# [2.2.0] - 2026-06-10
14+
15+
## Added
16+
- Users can now use environment variable `SIGSTORE_JAVA_ID_TOKEN` to pass in a raw token to the signer: https://github.com/sigstore/sigstore-java/pull/1204
17+
- Support more signing algorithms from the registry: https://github.com/sigstore/sigstore-java/pull/1197, https://github.com/sigstore/sigstore-java/pull/1198
18+
19+
## Changed
20+
- DSSE types logged with rekor v2 will use `hashedrekord` as the log entry type, the `dsse` log type is no longer in use for rekor v2: https://github.com/sigstore/sigstore-java/pull/1202
21+
1322
# [2.1.0] - 2026-05-21
1423

1524
## Added

README.md

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -33,6 +33,12 @@ Bundle result = signer.signFile(testArtifact);
3333
String bundleJson = result.toJson();
3434
```
3535

36+
##### ID Token
37+
Signing will use identity tokens from these sources in the following order of priority:
38+
- `SIGSTORE_JAVA_ID_TOKEN`: a raw token provided as an environment variable
39+
- GitHub Actions: a token from github actions when the permission `idtoken: write` is set
40+
- Interactive Web Flow: an broswer based oidc flow requiring user input
41+
3642
#### Artifact Verification
3743

3844
##### Get artifact and bundle

build-logic/publishing/build.gradle.kts

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -11,7 +11,7 @@ dependencies {
1111
implementation(project(":basics"))
1212
implementation(project(":jvm"))
1313
implementation("dev.sigstore.build-logic:gradle-plugin")
14-
implementation("dev.sigstore:sigstore-gradle-sign-plugin:2.1.0")
14+
implementation("dev.sigstore:sigstore-gradle-sign-plugin:2.2.0")
1515
implementation("com.gradle.plugin-publish:com.gradle.plugin-publish.gradle.plugin:2.0.0")
1616
implementation("com.gradleup.nmcp:com.gradleup.nmcp.gradle.plugin:1.4.0")
1717
}

examples/hello-world/build.gradle.kts

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
plugins {
22
`java-library`
33
`maven-publish`
4-
val sigstoreVersion = System.getProperty("sigstore.version") ?: "2.1.0"
4+
val sigstoreVersion = System.getProperty("sigstore.version") ?: "2.2.0"
55
id("dev.sigstore.sign") version "$sigstoreVersion"
66
signing
77
}

examples/hello-world/pom.xml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -16,7 +16,7 @@
1616
<project.build.sourceEncoding>UTF-8</project.build.sourceEncoding>
1717
<project.reporting.outputEncoding>UTF-8</project.reporting.outputEncoding>
1818
<maven.compiler.release>11</maven.compiler.release>
19-
<sigstore.version>2.1.0</sigstore.version>
19+
<sigstore.version>2.2.0</sigstore.version>
2020
</properties>
2121

2222
<build>

gradle.properties

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -4,7 +4,7 @@ org.gradle.jvmargs=-XX:MaxMetaspaceSize=768m
44
group=dev.sigstore
55

66
# use the ./scripts/update_version.sh script to update all versions
7-
version=2.2.0
7+
version=2.3.0
88

99
# Kotlin Dokka is experemental, and we want silence the build warning
1010
org.jetbrains.dokka.experimental.gradle.pluginMode=V2Enabled

sigstore-gradle/README.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -15,7 +15,7 @@ Signature format uses [Sigstore bundle](https://github.com/sigstore/protobuf-spe
1515

1616
```kotlin
1717
plugins {
18-
id("dev.sigstore.sign") version "2.1.0"
18+
id("dev.sigstore.sign") version "2.2.0"
1919
}
2020

2121
// Automatically sign all Maven publications, using GitHub Actions OIDC when available,

sigstore-gradle/sigstore-gradle-sign-base-plugin/src/main/kotlin/dev/sigstore/sign/SigstoreSignExtension.kt

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -46,7 +46,7 @@ abstract class SigstoreSignExtension(private val project: Project) {
4646
abstract val sigstoreJavaVersion : Property<String>
4747

4848
init {
49-
sigstoreJavaVersion.convention("2.2.0")
49+
sigstoreJavaVersion.convention("2.3.0")
5050
}
5151

5252
fun sign(publications: DomainObjectCollection<Publication>) {

sigstore-maven-plugin/README.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -17,7 +17,7 @@ Signature format uses [Sigstore bundle](https://github.com/sigstore/protobuf-spe
1717
<plugin>
1818
<groupId>dev.sigstore</groupId>
1919
<artifactId>sigstore-maven-plugin</artifactId>
20-
<version>2.1.0</version>
20+
<version>2.2.0</version>
2121
<executions>
2222
<execution>
2323
<id>sign</id>

0 commit comments

Comments
 (0)