-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Thu, 02 Apr 2026 08:38:43 +0200
Source: golang-github-sigstore-cosign-v2
Binary: golang-github-sigstore-cosign-v2-dev
Architecture: source all
Version: 2.6.2-1
Distribution: unstable
Urgency: medium
Maintainer: Debian Go Packaging Team <team+pkg-go@tracker.debian.org>
Changed-By: Simon Josefsson <simon@josefsson.org>
Description:
golang-github-sigstore-cosign-v2-dev - Code signing/transparency for containers and binaries (library)
Changes:
golang-github-sigstore-cosign-v2 (2.6.2-1) unstable; urgency=medium
.
* Forked from golang-github-sigstore-cosign v2.6.2-1
- The v2 branch is needed by the go-witness eco-system
- Dropped binary 'cosign'
Checksums-Sha1:
825eaf947862bc891b2975e0e8dc4a525a0eb1db 4557 golang-github-sigstore-cosign-v2_2.6.2-1.dsc
08c4168de06766283f98dba14273365f354881f2 938153 golang-github-sigstore-cosign-v2_2.6.2.orig.tar.gz
71096e054629a8e420bf359f59afaee6bf23492e 4988 golang-github-sigstore-cosign-v2_2.6.2-1.debian.tar.xz
b86362fa86c0e889b64d82a804866cb4efcad7fd 351016 golang-github-sigstore-cosign-v2-dev_2.6.2-1_all.deb
66b959e9d4887dc8e3c967734789d65725d54026 38337 golang-github-sigstore-cosign-v2_2.6.2-1_amd64.buildinfo
Checksums-Sha256:
af4e8fca31a4f5b12fc0b6dea781ca7ad09f355b79d0ca37ad5e6314cab0f57a 4557 golang-github-sigstore-cosign-v2_2.6.2-1.dsc
ccd19e5f55f8168de8ec8e16fc0b32fa6b55b294dc93184f61bfd2b23f8429ff 938153 golang-github-sigstore-cosign-v2_2.6.2.orig.tar.gz
2c97bf40cd069bd7c921a02f893e9d3ffced4f537c33569f03aa874d731e195e 4988 golang-github-sigstore-cosign-v2_2.6.2-1.debian.tar.xz
7fdb5ef2bf9596b28ea2d3778afbeed6e08d87b2ffe893ba16800291719d5cf5 351016 golang-github-sigstore-cosign-v2-dev_2.6.2-1_all.deb
cae7f9b6e0c9a35bbe231e1dde5f1186aea1c79d84b3a582811ad14561671049 38337 golang-github-sigstore-cosign-v2_2.6.2-1_amd64.buildinfo
Files:
4cddd43edb95388781f748ff4b0e7786 4557 golang optional golang-github-sigstore-cosign-v2_2.6.2-1.dsc
50fdcce9b866fe86505158c7fcadd5fd 938153 golang optional golang-github-sigstore-cosign-v2_2.6.2.orig.tar.gz
8a3ae7eb1733e26bce370f9290f722cf 4988 golang optional golang-github-sigstore-cosign-v2_2.6.2-1.debian.tar.xz
533758c2796150b89fb77b53d52d2de6 351016 golang optional golang-github-sigstore-cosign-v2-dev_2.6.2-1_all.deb
6171ec5ed49df82e1b41a72e880e15d7 38337 golang optional golang-github-sigstore-cosign-v2_2.6.2-1_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----
iQNoBAEWCgMQFiEEo8ychwudMQq61M8vUXIrCP5HRaIFAmnOHcgUHHNpbW9uQGpv
c2Vmc3Nvbi5vcmfCHCYAmDMEXJLOtBYJKwYBBAHaRw8BAQdACIcrZIvhrxDBkK9f
V+QlTmXxo2naObDuGtw58YaxlOu0JVNpbW9uIEpvc2Vmc3NvbiA8c2ltb25Aam9z
ZWZzc29uLm9yZz6IlgQTFggAPgIbAwULCQgHAgYVCAkKCwIEFgIDAQIeAQIXgBYh
BLHSvRN1vst4TPT4xNc89jjFPAa+BQJn0XQkBQkNZGbwAAoJENc89jjFPAa+BtIA
/iR73CfBurG9y8pASh3cbGOMHpDZfMAtosu6jbpO69GHAP4p7l57d+iVty2VQMsx
+3TCSAvZkpr4P/FuTzZ8JZe8BrgzBFySz4EWCSsGAQQB2kcPAQEHQOxTCIOaeXAx
I2hIX4HK9bQTpNVei708oNr1Klm8qCGKiPUEGBYIACYCGwIWIQSx0r0Tdb7LeEz0
+MTXPPY4xTwGvgUCZ9F0SgUJDWRmSQCBdiAEGRYIAB0WIQSjzJyHC50xCrrUzy9R
cisI/kdFogUCXJLPgQAKCRBRcisI/kdFoqdMAQCgH45aseZgIrwKOvUOA9QfsmeE
8GZHYNuFHmM9FEQS6AD6A4x5aYvoY6lo98pgtw2HPDhmcCXFItjXCrV4A0GmJA4J
ENc89jjFPAa+wUUBAO64fbZek6FPlRK0DrlWsrjCXuLi6PUxyzCAY6lG2nhUAQC6
qobB9mkZlZ0qihy1x4JRtflqFcqqT9n7iUZkCDIiDbg4BFySz2oSCisGAQQBl1UB
BQEBB0AxlRumDW6nZY7A+VCfek9VpEx6PJmdJyYPt3lNHMd6HAMBCAeIfgQYFggA
JgIbDBYhBLHSvRN1vst4TPT4xNc89jjFPAa+BQJn0XTSBQkNZGboAAoJENc89jjF
PAa+0M0BAPPRq73kLnHYNDMniVBOzUdi2XeF32idjEWWfjvyIJUOAP4wZ+ALxIeh
is3Uw2BzGZE6ttXQ2Q+DeCJO3TPpIqaXDAAKCRBRcisI/kdForRpAP9uUgOUZfdL
jFkRiOYCj6cEG1Q5qBg4MSayXrMYIwqPsQEA0WEi/AEsG9ErzdXs2bbDol4ROy1n
8fmqBUKfjzwSQwM=
=3zfU
-----END PGP SIGNATURE-----