NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
npm · #3035 most downloaded on npm
Sigstore bundle type
Last release 4 months ago
01 Jun 2026
Release timing varies
gaps range from 3 weeks to 10 months
Nearly every release is documented
notes for 13 of 13 stable releases
Nothing withdrawn
no release was ever pulled
3 years old
13 releases · first in 2023
One column per quarter.
46c00b3: Drop support for Node 20
tuf-js from 4.x to 5.0.1tuf-js from 5.0.1 to 6.0.046c00b3: Drop support for Node 20
74cc6c5: Bump @sigstore/protobuf-specs from 0.3.2 to 0.4.0
383e200: Drop support for node 18
tuf-js from 2.2.1 to 3.0.0DSSEBundleBuilder to generating v0.3 bundlesRekorWitness to generating "dsse" entries instead of "intoto"toDSSEBundle and toMessageSignatureBundle generate v0.3 bundles by defaultcf0c3ef: Bump @sigstore/protobuf-specs from 0.3.1 to 0.3.2
9d300e8: Bump make-fetch-happen from 13.0.0 to 13.0.1
require instead of require.resolve77e9e17: Updates the DSSEBundleBuilder with a new singleCertificate option which will trigger the creation of v0.3 Sigstore bundles
DSSEBundleBuilder with a new singleCertificate option which will trigger the creation of v0.3 Sigstore bundlesforceCache option for TUF client555dd8e: Support for validating v0.3 bundles
entryType option on RekorWitness constructorforce option to force re-initialization of local TUF cache620c30c: Fix to use verified timestamp when selecting which certificate authority chains should be used from the trusted root to verify Fulcio-issued
bundleFromJSON to perform full bundle validation74cc6c5: Bump @sigstore/protobuf-specs from 0.3.2 to 0.4.0
f89faed: Drop support for node 16
hash function in core packagetuf-js to v2.0.0make-fetch-happen from 11.0.0 to 13.0.046caed8: Update createPublicKey to support both "spki" and "pkcs1" key types
createPublicKey to support both "spki" and "pkcs1" key types@sigstore/bundle package.tufMirrorURL and tufRootPath options to the verify functionf05be96: Update Rekor verification to handle checkpoint values which do no include timestamps ( )
MessageBundleBuilder class to MessageSignatureBundleBuilder@sigstore/bundle package.SerializedTLogEntry typeenvelopeToJSON/envelopeFromJSON functions for serialization/deserialization of DSSE envelopesThe 1.0.0 release 🎉
Your coding agent can read these notes before it upgrades. Set up the MCP server →