Access Sigstore changelog updates through our uniform API. Same JSON structure across all sources — no adapter-specific parsing needed.
GET https://watchchangelog.com/api/v1/entries?source=cosign.releases{
"source": "cosign.releases",
"vendor": "Sigstore",
"id": "tag:github.com,2008:Repository/335952417/v3.1.3",
"published_at": "2026-08-06T01:09:23.000Z",
"title": "v3.1.3",
"url": "https://github.com/sigstore/cosign/releases/tag/v3.1.3",
"summary": "What's Changed This release resolves GHSA-fx35-mq7g-6g98 , a verification bypass using an unexpected public key in a legacy bundle. Auto-detect default digest algorithm for public keys in #5019 fix(pkcs11key): return an error instead of panicking when no key pair matches in #5022 Supporting OCI Signing with X.509 Certificate Chain in #4614 test(inspect): replace mock TSA client usage with local timestamp response generator in #5021 fix: prevent shell completions for various options not taking filenames in #5032 fix(blob): compare file checksums case-insensitively in #5036 Verification bypass via public key in legacy bundle ( GHSA-fx35-mq7g-6g98 ) in #5040 Full Changelog : v3.1.2...v3.1.3",
"tags": [
"Sigstore",
"cosign.releases",
"security",
"signing",
"supply-chain"
]
}Sign up to access the full changelog API. All public sources are free — no credit card required.
Sign Up Free →+2 more
+2 more
+2 more
+2 more
+2 more