Skip to content

Cargo.toml: bump version to v0.5.0#121

Merged
jlebon merged 2 commits intocoreos:mainfrom
jlebon:bump-v0.5.0
May 4, 2026
Merged

Cargo.toml: bump version to v0.5.0#121
jlebon merged 2 commits intocoreos:mainfrom
jlebon:bump-v0.5.0

Conversation

@jlebon
Copy link
Copy Markdown
Member

@jlebon jlebon commented May 4, 2026

No description provided.

Copy link
Copy Markdown

@gemini-code-assist gemini-code-assist Bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request bumps the version of chunkah from 0.4.0 to 0.5.0 across the project files and adds documentation for verifying image signatures using cosign. A security improvement was suggested to anchor the certificate identity regular expression in the README to prevent potential verification bypasses.

Comment thread README.md Outdated
jlebon added 2 commits May 3, 2026 22:51
I don't think not having this is really exploitable, but just to be safe
so we don't even have to think about it.
@jlebon jlebon merged commit b990a77 into coreos:main May 4, 2026
10 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant