Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

chore: automated PR to main 2024-09-22 #250

Closed
wants to merge 428 commits into from
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
428 commits
Select commit Hold shift + click to select a range
27ca126
chore: Bump alpine from `77726ef` to `b89d9c9`
dependabot[bot] Jun 24, 2024
e4c58e2
Merge pull request #1590 from ratify-project/dependabot/docker/alpine…
binbin-li Jun 24, 2024
cca0a13
Merge branch 'dev' into dependabot/docker/httpserver/golang-b405b62
binbin-li Jun 24, 2024
47b3331
Merge pull request #1589 from ratify-project/dependabot/docker/httpse…
binbin-li Jun 24, 2024
efe84cf
ci: switch region from eastus to westus2 (#1591)
binbin-li Jun 25, 2024
9bf9232
Merge pull request #1585 from ratify-project/dev
susanshi Jun 25, 2024
ae4385b
feat: Support more trust store types (#1538)
junczhu Jun 25, 2024
374d187
chore: Bump github.com/aws/aws-sdk-go-v2/config from 1.27.18 to 1.27.…
dependabot[bot] Jun 26, 2024
cf7a111
chore: Bump github.com/hashicorp/go-retryablehttp from 0.7.5 to 0.7.7…
dependabot[bot] Jun 26, 2024
45430c7
chore: Bump github.com/aws/aws-sdk-go-v2/service/ecr from 1.28.5 to 1…
dependabot[bot] Jun 26, 2024
aeceddc
chore: Bump github.com/aws/aws-sdk-go-v2/credentials from 1.17.21 to …
dependabot[bot] Jun 26, 2024
8af013d
chore: Bump github.com/aws/aws-sdk-go-v2/credentials from 1.17.22 to …
dependabot[bot] Jul 1, 2024
54e92a4
chore: Bump github.com/aws/aws-sdk-go-v2/config from 1.27.21 to 1.27.…
dependabot[bot] Jul 1, 2024
d862e04
chore: Bump github/codeql-action from 3.25.10 to 3.25.11 (#1598)
dependabot[bot] Jul 1, 2024
e033cb2
build: add SBOM & provenance docker build attestations (#1596)
akashsinghal Jul 1, 2024
0a1198a
chore: upgrade to go 1.22 (#1605)
akashsinghal Jul 2, 2024
bcd0f39
chore: Bump github.com/spdx/tools-golang from 0.5.4 to 0.5.5 (#1601)
dependabot[bot] Jul 2, 2024
48c8015
chore: Bump github.com/sigstore/sigstore from 1.8.4 to 1.8.6 (#1599)
dependabot[bot] Jul 3, 2024
89b0a9c
chore: fix linting issues (#1606)
akashsinghal Jul 3, 2024
db3b86f
Merge pull request #1597 from ratify-project/dev
susanshi Jul 4, 2024
0ee96d8
Create ratify-weekly-notes-2023-Jun-2024-Jun.md
susanshi Jul 5, 2024
e911c59
chore: prepare release 1.2.1 charts update (#1610)
junczhu Jul 5, 2024
4fc08ce
chore: prepare release 1.2.1 charts update 2 (#1612)
junczhu Jul 5, 2024
efa4295
chore: prepare release 1.2.1 helmfile update
junczhu Jul 5, 2024
357eb51
Merge pull request #1613 from ZAFT-Armored-Keeper-of-Unity/helmfile-u…
binbin-li Jul 5, 2024
0b58daf
Merge branch 'dev' into notes
binbin-li Jul 8, 2024
7f1ecfb
Merge pull request #1608 from susanshi/notes
binbin-li Jul 8, 2024
94457a7
chore: Bump actions/upload-artifact from 4.3.3 to 4.3.4
dependabot[bot] Jul 8, 2024
b7fa5e1
chore: Bump google.golang.org/grpc from 1.64.0 to 1.64.1 (#1615)
dependabot[bot] Jul 8, 2024
6cf38fd
chore: Bump google.golang.org/protobuf from 1.34.1 to 1.34.2 (#1616)
dependabot[bot] Jul 8, 2024
3829c79
chore: Bump github.com/aws/aws-sdk-go-v2/credentials from 1.17.23 to …
dependabot[bot] Jul 8, 2024
c4dc680
chore: Bump github.com/aws/aws-sdk-go-v2/config from 1.27.23 to 1.27.…
dependabot[bot] Jul 8, 2024
34eeced
chore: Bump github.com/owenrumney/go-sarif/v2 from 2.3.1 to 2.3.2 (#1…
dependabot[bot] Jul 8, 2024
d8f86fb
chore: Bump distroless/static from `e9ac71e` to `8dd8d3c` in /httpser…
dependabot[bot] Jul 9, 2024
c9f2c0a
chore: Bump golang from `a66eda6` to `fcae9e0` in /httpserver
dependabot[bot] Jul 9, 2024
61e0fed
Merge pull request #1621 from ratify-project/dependabot/docker/httpse…
binbin-li Jul 9, 2024
db7e6ee
Merge pull request #1614 from ratify-project/dev
binbin-li Jul 9, 2024
72025fb
Merge branch 'dev' into dependabot/github_actions/actions/upload-arti…
binbin-li Jul 9, 2024
e62cd8e
Merge pull request #1622 from ratify-project/dependabot/github_action…
binbin-li Jul 9, 2024
6010b4f
chore: ignore pb.go files under experimental
binbin-li Jul 10, 2024
7e74e12
Merge branch 'dev' into ignore-experimental-test
binbin-li Jul 10, 2024
9551205
Merge pull request #1624 from binbin-li/ignore-experimental-test
binbin-li Jul 10, 2024
5d992c3
chore: Bump actions/setup-go from 5.0.1 to 5.0.2
dependabot[bot] Jul 11, 2024
03216af
Merge pull request #1628 from ratify-project/dependabot/github_action…
binbin-li Jul 11, 2024
449cdf3
chore: bump CRD controller + conversion gen binaries to be compatible…
akashsinghal Jul 11, 2024
db07f8f
docs: remove CLA section from CONTRIBUTING (#1626)
akashsinghal Jul 11, 2024
b2535b9
fix: validate plugin version for ratify cli (#1604)
susanshi Jul 15, 2024
444d8cc
chore: Bump github.com/owenrumney/go-sarif/v2 from 2.3.2 to 2.3.3
dependabot[bot] Jul 15, 2024
f9720b1
chore: Bump github.com/aws/aws-sdk-go-v2/credentials
dependabot[bot] Jul 15, 2024
dca6b77
chore: Bump vscode/devcontainers/go in /.devcontainer
dependabot[bot] Jul 15, 2024
9c9cb05
Merge pull request #1636 from ratify-project/dependabot/go_modules/gi…
binbin-li Jul 15, 2024
6ebd6f1
Merge branch 'dev' into dependabot/go_modules/github.com/owenrumney/g…
binbin-li Jul 15, 2024
643e98a
Merge pull request #1632 from ratify-project/dependabot/go_modules/gi…
binbin-li Jul 15, 2024
e0c8da6
chore: Bump github.com/sigstore/sigstore from 1.8.6 to 1.8.7
dependabot[bot] Jul 15, 2024
e7aa02a
Merge pull request #1634 from ratify-project/dependabot/go_modules/gi…
binbin-li Jul 15, 2024
ee5bad7
chore: Bump github.com/aws/aws-sdk-go-v2/config from 1.27.24 to 1.27.26
dependabot[bot] Jul 15, 2024
9549d66
Merge pull request #1635 from ratify-project/dependabot/go_modules/gi…
binbin-li Jul 15, 2024
bd2f5ca
Merge branch 'dev' into dependabot/docker/dot-devcontainer/vscode/dev…
binbin-li Jul 15, 2024
1d6e824
Merge pull request #1637 from ratify-project/dependabot/docker/dot-de…
binbin-li Jul 15, 2024
fbeb67e
chore: Bump golang from `fcae9e0` to `829eff9` in /httpserver (#1639)
dependabot[bot] Jul 15, 2024
48a1565
chore: Bump github/codeql-action from 3.25.11 to 3.25.12 (#1638)
dependabot[bot] Jul 15, 2024
60c9b85
build: add workflow for publishing cosign sample image (#1640)
akashsinghal Jul 19, 2024
7e6f99f
chore: Bump step-security/harden-runner from 2.8.1 to 2.9.0 (#1642)
dependabot[bot] Jul 19, 2024
4122be7
chore: Bump k8s.io/api from 0.28.11 to 0.28.12 (#1644)
dependabot[bot] Jul 22, 2024
6f78679
chore: Bump github.com/aws/aws-sdk-go-v2/credentials from 1.17.26 to …
dependabot[bot] Jul 22, 2024
5e9f3a4
chore: Bump github.com/aws/aws-sdk-go-v2/config from 1.27.26 to 1.27.27
dependabot[bot] Jul 22, 2024
dfe9d0a
Merge pull request #1647 from ratify-project/dependabot/go_modules/gi…
binbin-li Jul 22, 2024
a63adcc
chore: Bump github.com/google/go-containerregistry from 0.20.0 to 0.2…
dependabot[bot] Jul 22, 2024
5b0f3e1
chore: Bump github/codeql-action from 3.25.12 to 3.25.13 (#1649)
dependabot[bot] Jul 22, 2024
07f3f79
chore: Bump docker/login-action from 3.2.0 to 3.3.0
dependabot[bot] Jul 23, 2024
9db35b0
Merge pull request #1651 from ratify-project/dependabot/github_action…
binbin-li Jul 23, 2024
fc3ddbb
chore: rephrase failure result in constraint template
binbin-li Jul 23, 2024
c10fab6
docs: design doc for KMP periodic retrieval (#1583)
duffney Jul 23, 2024
6f92077
Merge branch 'dev' into template-result
binbin-li Jul 24, 2024
b8f0e29
Merge pull request #1656 from binbin-li/template-result
binbin-li Jul 26, 2024
2000c11
doc: proposal for error message improvements
yizha1 Jul 28, 2024
9dc9e82
update
yizha1 Jul 28, 2024
70ba627
update
yizha1 Jul 28, 2024
f5694f7
chore: Bump github/codeql-action from 3.25.13 to 3.25.14 (#1659)
dependabot[bot] Jul 29, 2024
14624cc
chore: Bump alpine from `b89d9c9` to `0a4eaa0`
dependabot[bot] Jul 29, 2024
2188f95
chore: Bump k8s.io/client-go from 0.28.11 to 0.28.12 (#1663)
dependabot[bot] Jul 29, 2024
7ffb697
chore: Bump ossf/scorecard-action from 2.3.3 to 2.4.0 (#1664)
dependabot[bot] Jul 29, 2024
537c823
chore: Bump github/codeql-action from 3.25.14 to 3.25.15
dependabot[bot] Jul 29, 2024
3c28fd4
Merge pull request #1665 from ratify-project/dependabot/github_action…
binbin-li Jul 29, 2024
581be1e
Merge branch 'dev' into dependabot/docker/alpine-0a4eaa0eecf5f8c050e5…
binbin-li Jul 29, 2024
1d12f7f
update
yizha1 Jul 29, 2024
d442fad
Merge pull request #1666 from ratify-project/dependabot/docker/alpine…
binbin-li Jul 29, 2024
4ae4332
update
yizha1 Jul 29, 2024
0bbd60e
chore: Bump golang from `829eff9` to `86a3c48` in /httpserver (#1667)
dependabot[bot] Jul 30, 2024
8f2f716
chore: Bump golangci/golangci-lint-action from 6.0.1 to 6.1.0
dependabot[bot] Jul 30, 2024
182b567
docs: Archive ratify error handling scenario doc
binbin-li Jul 29, 2024
b0d8a2d
Merge pull request #1672 from ratify-project/dependabot/github_action…
binbin-li Jul 30, 2024
3578e05
chore: Bump github.com/docker/docker
dependabot[bot] Jul 30, 2024
bd87979
Merge pull request #1674 from ratify-project/dependabot/go_modules/gi…
binbin-li Jul 31, 2024
060c5a5
Merge branch 'dev' into ratify-err-doc
binbin-li Jul 31, 2024
bd97bc2
docs: add proposal for producing supply chain metadata for all ratify…
akashsinghal Jul 31, 2024
17f829a
build: add image signing for dev images and add release sbom (#1629)
akashsinghal Jul 31, 2024
7294999
fix: warning message is printed to stdout by CLI (#1650)
susanshi Aug 1, 2024
8549d91
Merge branch 'dev' into ratify-err-doc
susanshi Aug 1, 2024
90367de
Merge pull request #1668 from binbin-li/ratify-err-doc
binbin-li Aug 1, 2024
9d5acaf
fix: pass CODECOV_TOKEN to reusable workflow
binbin-li Aug 1, 2024
ba5638e
Merge pull request #1676 from binbin-li/fix-codecov
binbin-li Aug 1, 2024
f0cdcfe
fix: remove duplicate $
binbin-li Aug 1, 2024
18f071a
Merge branch 'dev' into fix-codecov
binbin-li Aug 1, 2024
a494009
update per comments
yizha1 Aug 1, 2024
b652e00
Merge pull request #1677 from binbin-li/fix-codecov
binbin-li Aug 2, 2024
05a8cbe
fix: fix typo in notation verifier (#1678)
junczhu Aug 2, 2024
b12b038
fix: bump-up docker dependency (#1679)
junczhu Aug 2, 2024
1401080
update per comments
yizha1 Aug 2, 2024
3bb4224
chore: Bump actions/upload-artifact from 4.3.4 to 4.3.5
dependabot[bot] Aug 5, 2024
e222c72
Merge pull request #1684 from ratify-project/dependabot/github_action…
binbin-li Aug 5, 2024
8b17053
feat: add verifierName, verifierType and errorReason fields to verifi…
binbin-li Jul 25, 2024
af1a0d8
feat: refactor error message format
binbin-li Jul 31, 2024
9eccff6
chore: remove unused code path
binbin-li Aug 6, 2024
aedb222
chore: Bump step-security/harden-runner from 2.9.0 to 2.9.1
dependabot[bot] Aug 6, 2024
300401c
Merge pull request #1689 from ratify-project/dependabot/github_action…
binbin-li Aug 6, 2024
e757310
Merge branch 'dev' into verification-response
binbin-li Aug 6, 2024
294a715
Merge pull request #1671 from binbin-li/verification-response
binbin-li Aug 6, 2024
451390b
Merge branch 'dev' into error-log-message
binbin-li Aug 6, 2024
92ce84f
chore: update scorecards action (#1687)
junczhu Aug 6, 2024
220dfce
Merge branch 'dev' into error-log-message
binbin-li Aug 6, 2024
51c5402
chore: rename WithLinkToDoc to WithRemediation
binbin-li Aug 6, 2024
46280e0
chore: Bump actions/upload-artifact from 4.3.5 to 4.3.6
dependabot[bot] Aug 7, 2024
f347f6a
chore: Bump github/codeql-action from 3.25.15 to 3.26.0
dependabot[bot] Aug 7, 2024
e6f031b
Merge pull request #1692 from ratify-project/dependabot/github_action…
binbin-li Aug 7, 2024
bb8d7f0
Merge branch 'dev' into dependabot/github_actions/actions/upload-arti…
binbin-li Aug 7, 2024
c83f3f8
Merge pull request #1691 from ratify-project/dependabot/github_action…
binbin-li Aug 7, 2024
4bbd9f1
Merge branch 'dev' into proposal_errorimprovements
binbin-li Aug 8, 2024
1ecd579
Merge pull request #1662 from yizha1/proposal_errorimprovements
binbin-li Aug 8, 2024
742ccc0
chore: Bump sigstore/cosign-installer from 3.5.0 to 3.6.0
dependabot[bot] Aug 8, 2024
8a8192d
Merge pull request #1695 from ratify-project/dependabot/github_action…
binbin-li Aug 8, 2024
5b7c4e0
Merge branch 'dev' into error-log-message
binbin-li Aug 9, 2024
e8f8000
Merge pull request #1675 from binbin-li/error-log-message
binbin-li Aug 9, 2024
f510dd9
Merge branch 'dev' into remove-autorest-adal
binbin-li Aug 9, 2024
23092c6
feat: add open ssf best practices badge (#1696)
susanshi Aug 9, 2024
518ad3d
Merge branch 'dev' into remove-autorest-adal
binbin-li Aug 9, 2024
56ffab4
Merge pull request #1688 from binbin-li/remove-autorest-adal
binbin-li Aug 9, 2024
c2f5c3a
chore: Bump github.com/sigstore/sigstore from 1.8.7 to 1.8.8
dependabot[bot] Aug 12, 2024
341c545
chore: Bump github.com/google/go-containerregistry from 0.20.1 to 0.20.2
dependabot[bot] Aug 12, 2024
2389aa6
chore: Bump vscode/devcontainers/go in /.devcontainer
dependabot[bot] Aug 12, 2024
730c48b
chore: Bump golang from `86a3c48` to `2bd56f0` in /httpserver
dependabot[bot] Aug 12, 2024
6ba1c32
Merge pull request #1706 from ratify-project/dependabot/docker/httpse…
binbin-li Aug 12, 2024
7e387db
Merge branch 'dev' into dependabot/docker/dot-devcontainer/vscode/dev…
binbin-li Aug 12, 2024
956109c
Merge pull request #1705 from ratify-project/dependabot/docker/dot-de…
binbin-li Aug 12, 2024
e353f38
Merge branch 'dev' into dependabot/go_modules/github.com/google/go-co…
binbin-li Aug 12, 2024
f78f69d
Merge pull request #1704 from ratify-project/dependabot/go_modules/gi…
binbin-li Aug 12, 2024
bb8516e
Merge branch 'dev' into dependabot/go_modules/github.com/sigstore/sig…
binbin-li Aug 12, 2024
9862c66
Update go.mod
binbin-li Aug 13, 2024
e1cf41e
Merge pull request #1703 from ratify-project/dependabot/go_modules/gi…
binbin-li Aug 13, 2024
9804ad7
chore: Bump github/codeql-action from 3.26.0 to 3.26.1
dependabot[bot] Aug 14, 2024
60a21cd
chore: Bump anchore/sbom-action from 0.17.0 to 0.17.1
dependabot[bot] Aug 14, 2024
c098e93
Merge pull request #1708 from ratify-project/dependabot/github_action…
binbin-li Aug 14, 2024
0447079
Merge branch 'dev' into dependabot/github_actions/anchore/sbom-action…
binbin-li Aug 14, 2024
2b270c3
Merge pull request #1709 from ratify-project/dependabot/github_action…
binbin-li Aug 14, 2024
365d843
chore: update helm charts (#1702)
junczhu Aug 15, 2024
3e04cb5
feat: add timestamp and traceId to verification response (#1697)
binbin-li Aug 15, 2024
486a308
chore: Bump github/codeql-action from 3.26.1 to 3.26.2
dependabot[bot] Aug 15, 2024
1ddf2f9
Merge pull request #1714 from ratify-project/dependabot/github_action…
binbin-li Aug 15, 2024
f2ed26e
chore: add the governance doc link to readme.md (#1713)
yizha1 Aug 15, 2024
a5f6f59
chore: Bump github.com/aws/aws-sdk-go-v2/config from 1.27.27 to 1.27.…
dependabot[bot] Aug 19, 2024
4e02c39
chore: Bump k8s.io/client-go from 0.28.12 to 0.28.13 (#1722)
dependabot[bot] Aug 19, 2024
2b08e26
chore: Bump golang from `2bd56f0` to `367bb52` in /httpserver (#1725)
dependabot[bot] Aug 19, 2024
f495934
feat: KMP periodic retrieval with k8s requeue (#1727)
duffney Aug 20, 2024
be3adc1
chore: stop printing out error stack trace (#1711)
binbin-li Aug 20, 2024
d0c04e4
chore: Bump github/codeql-action from 3.26.2 to 3.26.3 (#1728)
dependabot[bot] Aug 20, 2024
0b6aa67
feat: fill ErrorReason and Remediation during verifierReport generati…
binbin-li Aug 21, 2024
7500f96
test: add tests to akv provider (#1729)
binbin-li Aug 21, 2024
796c8c3
docs: update the contributing guide for a successful cli debugging (#…
shahramk64 Aug 21, 2024
9afbbf9
fix: Enforce validation on notation signature blob number (#1726)
binbin-li Aug 22, 2024
d83a7de
chore: Bump github/codeql-action from 3.26.3 to 3.26.4 (#1736)
dependabot[bot] Aug 22, 2024
c8c9c0e
chore: Bump anchore/sbom-action from 0.17.1 to 0.17.2 (#1737)
dependabot[bot] Aug 22, 2024
494bcf3
docs: update contributing guide for enhancement (#1715)
susanshi Aug 22, 2024
9b96175
feat: save reconcile error for KMP/CertStore (#1710)
binbin-li Aug 23, 2024
fb5692e
chore: Bump vscode/devcontainers/go from `8cb4ef6` to `fdc107c` in /.…
dependabot[bot] Aug 26, 2024
f9569e4
chore: Bump github.com/docker/cli from 27.1.1+incompatible to 27.1.2+…
dependabot[bot] Aug 26, 2024
6c2fb71
chore: Bump github.com/aws/aws-sdk-go-v2/credentials from 1.17.28 to …
dependabot[bot] Aug 26, 2024
c62c142
chore: Bump github.com/aws/aws-sdk-go-v2/config from 1.27.28 to 1.27.…
dependabot[bot] Aug 26, 2024
5199eae
chore: Bump github/codeql-action from 3.26.4 to 3.26.5 (#1748)
dependabot[bot] Aug 26, 2024
d1e810b
chore: update local dev charts to the latest version (#1749)
junczhu Aug 27, 2024
8632ea5
fix: remove nonexistent KMP from verifier sample (#1753)
binbin-li Aug 27, 2024
269d176
fix: remove critical cache failure in oras `GetBlobContent` (#1740)
binbin-li Aug 28, 2024
6474b4d
fix: make notation verifier installation optional on ratify installat…
shahramk64 Aug 29, 2024
b2e5bfa
chore: Bump github/codeql-action from 3.26.5 to 3.26.6 (#1763)
dependabot[bot] Aug 30, 2024
e7655fe
feat: enhance CR status with clearer brief error message (#1734)
binbin-li Sep 2, 2024
64d5f33
chore: Bump github.com/aws/aws-sdk-go-v2/config from 1.27.30 to 1.27.…
dependabot[bot] Sep 2, 2024
f204e9d
chore: update aks version (#1768)
junczhu Sep 2, 2024
2b1c461
chore: Bump actions/upload-artifact from 4.3.6 to 4.4.0 (#1771)
dependabot[bot] Sep 2, 2024
0cae6c7
feat: timestamping feature (#1758)
junczhu Sep 3, 2024
4a44d3a
feat: Add refreshInterval to the helm chart Values (#1773)
shahramk64 Sep 3, 2024
1c52df8
test: e2e tests for kmp refresh logic (#1742)
duffney Sep 4, 2024
f548082
chore: add description for notation.enabled in the helm charts readme…
shahramk64 Sep 4, 2024
7519519
chore: add codecov badge (#1777)
binbin-li Sep 4, 2024
6487002
chore: update default templates (#1776)
junczhu Sep 5, 2024
7208f98
chore: update err-msg with notation (#1775)
junczhu Sep 5, 2024
23f6ac8
chore: Bump github.com/aws/aws-sdk-go-v2/config from 1.27.31 to 1.27.…
dependabot[bot] Sep 9, 2024
2534b33
chore: Bump github.com/sigstore/sigstore from 1.8.8 to 1.8.9 (#1782)
dependabot[bot] Sep 9, 2024
1a8f598
chore: Bump github.com/notaryproject/notation-go from 1.2.0 to 1.2.1 …
dependabot[bot] Sep 9, 2024
f6743d0
chore: Bump alpine from `0a4eaa0` to `beefdbd` (#1786)
dependabot[bot] Sep 9, 2024
ab77d70
chore: Bump distroless/static from `8dd8d3c` to `42d15c6` in /httpser…
dependabot[bot] Sep 9, 2024
a73822c
chore: Bump golang from `367bb52` to `192683d` in /httpserver (#1788)
dependabot[bot] Sep 9, 2024
d89400e
fix: remove unused trust store from sample verifier config (#1790)
binbin-li Sep 9, 2024
ab8d001
chore: Refactor error messages for Notation signature verification (#…
binbin-li Sep 9, 2024
4d4d00c
feat: refactor cosign verification error messages (#1750)
binbin-li Sep 10, 2024
7657a3f
chore: update CRD and related code to enable `type` field (#1779)
junczhu Sep 10, 2024
acf60d1
chore: Bump step-security/harden-runner from 2.9.1 to 2.10.0 (#1794)
dependabot[bot] Sep 11, 2024
5381e0c
fix: showing verifier config parse detail in err log (#1791)
junczhu Sep 11, 2024
b7cab88
chore: update error messages for cosign validation (#1792)
binbin-li Sep 11, 2024
4b04c08
chore: bump support GK version matrix to include v3.17.0 (#1795)
akashsinghal Sep 12, 2024
630a2bd
chore: Bump step-security/harden-runner from 2.10.0 to 2.10.1 (#1796)
dependabot[bot] Sep 12, 2024
b32db85
fix: missing status update in KMP controller (#1761)
duffney Sep 12, 2024
482aee7
chore: update helm charts for v1.3.0 (#1805)
junczhu Sep 13, 2024
ff3d824
docs: add config path arg to launch.json, update instructions (#1800)
shahramk64 Sep 14, 2024
95e6c4e
chore: update go reference badge to the new path (#1806)
binbin-li Sep 14, 2024
ae0a9f9
chore: Bump golang from `192683d` to `4594271` in /httpserver (#1808)
dependabot[bot] Sep 16, 2024
8cb5343
chore: Bump vscode/devcontainers/go from `fdc107c` to `44c273a` in /.…
dependabot[bot] Sep 16, 2024
0542598
chore: Bump github/codeql-action from 3.26.6 to 3.26.7 (#1810)
dependabot[bot] Sep 16, 2024
161fd6b
chore: Bump k8s.io/client-go from 0.28.13 to 0.28.14 (#1813)
dependabot[bot] Sep 17, 2024
9100119
chore: Bump github.com/open-policy-agent/opa from 0.63.0 to 0.68.0 (#…
dependabot[bot] Sep 19, 2024
a08976e
chore: Bump azure/login from 2.1.1 to 2.2.0 (#1816)
dependabot[bot] Sep 20, 2024
fb69af0
chore: Bump github/codeql-action from 3.26.7 to 3.26.8 (#1820)
dependabot[bot] Sep 20, 2024
79aac85
chore: Bump github.com/aws/aws-sdk-go-v2/credentials from 1.17.32 to …
dependabot[bot] Sep 23, 2024
4cd6ba2
chore: Bump distroless/static from `42d15c6` to `dcd3f1f` in /httpser…
dependabot[bot] Sep 23, 2024
aa28620
chore: Bump github.com/aws/aws-sdk-go-v2/config from 1.27.33 to 1.27.…
dependabot[bot] Sep 23, 2024
4032cc1
chore: Bump github.com/prometheus/client_golang from 1.20.2 to 1.20.4…
dependabot[bot] Sep 23, 2024
f1ca1c1
chore: Bump google.golang.org/grpc from 1.66.0 to 1.66.2 (#1825)
dependabot[bot] Sep 24, 2024
ac85e25
docs: some improvement in release instructions (#1815)
junczhu Sep 24, 2024
d3e49d2
chore: update the roadmap after v1.3.0 release (#1817)
yizha1 Sep 25, 2024
77fbbaf
chore: Bump github/codeql-action from 3.26.8 to 3.26.9 (#1828)
dependabot[bot] Sep 25, 2024
8d72736
chore: Bump vscode/devcontainers/go from `44c273a` to `68e6bd3` in /.…
dependabot[bot] Sep 25, 2024
2a7ec4d
chore: Bump actions/checkout from 4.1.7 to 4.2.0 (#1830)
dependabot[bot] Sep 27, 2024
aea7688
chore: Bump notaryproject/notation-action from 1.1.0 to 1.2.0 (#1832)
dependabot[bot] Sep 30, 2024
c260f3b
chore: Bump github.com/aws/aws-sdk-go-v2/credentials from 1.17.34 to …
dependabot[bot] Sep 30, 2024
70e4744
chore: Bump vscode/devcontainers/go from `68e6bd3` to `d638d11` in /.…
dependabot[bot] Sep 30, 2024
d72b0d7
chore: Bump golang from `4594271` to `ddad330` in /httpserver (#1837)
dependabot[bot] Oct 1, 2024
8786419
chore: Bump distroless/static from `dcd3f1f` to `26f9b99` in /httpser…
dependabot[bot] Oct 1, 2024
036beb9
chore: Bump github/codeql-action from 3.26.9 to 3.26.10 (#1840)
dependabot[bot] Oct 1, 2024
6bf96b0
chore: Bump golang/govulncheck-action from 1.0.3 to 1.0.4 (#1841)
dependabot[bot] Oct 2, 2024
ad5cdcf
chore: Bump codecov/codecov-action from 4.5.0 to 4.6.0 (#1842)
dependabot[bot] Oct 2, 2024
b94c067
chore: Bump golangci/golangci-lint-action from 6.1.0 to 6.1.1 (#1845)
dependabot[bot] Oct 3, 2024
5327afe
docs: add commits doc to contributing guide (#1844)
susanshi Oct 7, 2024
6fd804f
chore: Bump github/codeql-action from 3.26.10 to 3.26.11 (#1846)
dependabot[bot] Oct 7, 2024
8162d6a
chore: Bump golang from `ddad330` to `628529a` in /httpserver (#1847)
dependabot[bot] Oct 7, 2024
1af7001
chore: Bump vscode/devcontainers/go from `d638d11` to `bdecb4c` in /.…
dependabot[bot] Oct 7, 2024
b41acf8
chore: Bump github.com/aws/aws-sdk-go-v2/config from 1.27.36 to 1.27.…
dependabot[bot] Oct 7, 2024
96fb63d
chore: Bump google.golang.org/grpc from 1.66.2 to 1.66.3 (#1850)
dependabot[bot] Oct 7, 2024
7ce62b7
chore: Bump sigstore/cosign-installer from 3.6.0 to 3.7.0 (#1851)
dependabot[bot] Oct 7, 2024
2b1890b
chore: Bump actions/upload-artifact from 4.4.0 to 4.4.1 (#1855)
dependabot[bot] Oct 8, 2024
f6fae7e
chore: Bump actions/checkout from 4.2.0 to 4.2.1 (#1857)
dependabot[bot] Oct 8, 2024
1ecd21f
chore: Bump github/codeql-action from 3.26.11 to 3.26.12 (#1856)
dependabot[bot] Oct 9, 2024
f62dddf
Update scan-vulns.yaml
binbin-li Oct 15, 2024
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
11 changes: 5 additions & 6 deletions .devcontainer/Dockerfile
Original file line number Diff line number Diff line change
Expand Up @@ -13,9 +13,8 @@

# See here for image contents: https://github.com/microsoft/vscode-dev-containers/tree/v0.245.2/containers/go/.devcontainer/base.Dockerfile

# [Choice] Go version (use -bullseye variants on local arm64/Apple Silicon): 1.21-bullseye, 1, 1.19, 1.18, 1-bullseye, 1.19-bullseye, 1.18-bullseye, 1-buster, 1.19-buster, 1.18-buster
ARG VARIANT="1.21-bullseye"
FROM mcr.microsoft.com/vscode/devcontainers/go:${VARIANT}
# [Choice] Go version (use -bullseye variants on local arm64/Apple Silicon): 1.22-bullseye, 1.21-bullseye, 1, 1.19, 1.18, 1-bullseye, 1.19-bullseye, 1.18-bullseye, 1-buster, 1.19-buster, 1.18-buster
FROM mcr.microsoft.com/vscode/devcontainers/go:1.22-bullseye@sha256:bdecb4ca0d168e7bd73b01e475d017aac0888ee22c7d4998a09858ab95157669

# [Choice] Node.js version: none, lts/*, 18, 16, 14
ARG NODE_VERSION="none"
Expand All @@ -31,7 +30,7 @@ RUN curl -Lo bats.tar.gz https://github.com/bats-core/bats-core/archive/v${BATS_
&& bash ./bats-core-${BATS_VERSION}/install.sh /usr/local \
&& rm -rf bats.tar.gz ./bats-core-${BATS_VERSION}

ARG NOTATION_VERSION="1.0.0-rc.1"
ARG NOTATION_VERSION="1.2.0"
RUN curl -Lo notation.tar.gz https://github.com/notaryproject/notation/releases/download/v${NOTATION_VERSION}/notation_${NOTATION_VERSION}_linux_amd64.tar.gz \
&& tar -zxf notation.tar.gz \
&& mv ./notation /usr/local/bin/notation \
Expand All @@ -54,8 +53,8 @@ RUN apt-get update && export DEBIAN_FRONTEND=noninteractive \

# [Optional] Uncomment the next lines to use go get to install anything else you need
USER vscode
RUN go install google.golang.org/protobuf/cmd/[email protected] \
&& go install google.golang.org/grpc/cmd/[email protected] \
RUN go install google.golang.org/protobuf/cmd/[email protected].1 \
&& go install google.golang.org/grpc/cmd/[email protected].0 \
&& chmod a+w -R /go/pkg

# [Optional] Uncomment this line to install global node packages.
Expand Down
4 changes: 2 additions & 2 deletions .devcontainer/devcontainer.json
Original file line number Diff line number Diff line change
Expand Up @@ -5,10 +5,10 @@
"build": {
"dockerfile": "Dockerfile",
"args": {
// Update the VARIANT arg to pick a version of Go: 1.21, 1.20, 1.19, 1.18
// Update the VARIANT arg to pick a version of Go: 1.22, 1.21, 1.20, 1.19, 1.18
// Append -bullseye or -buster to pin to an OS version.
// Use -bullseye variants on local arm64/Apple Silicon.
"VARIANT": "1.21-bullseye",
"VARIANT": "1.22-bullseye",
// Options
"NODE_VERSION": "none",
// Ratify-specific devcontainer options
Expand Down
8 changes: 7 additions & 1 deletion .github/codecov.yml
Original file line number Diff line number Diff line change
@@ -1,2 +1,8 @@
ignore:
- "./api" # ignore folders and all its contents
- "./api" # ignore folders and all its contents
- "./experimental/proto/v1"
coverage:
status:
patch:
default:
target: 80%
32 changes: 29 additions & 3 deletions .github/dependabot.yml
Original file line number Diff line number Diff line change
Expand Up @@ -17,6 +17,32 @@ updates:
ignore:
- dependency-name: "*"
update-types:
- "version-update:semver-major"
- "version-update:semver-minor"

- "version-update:semver-major"
- "version-update:semver-minor"

- package-ecosystem: "docker"
directory: "/"
schedule:
interval: "weekly"
commit-message:
prefix: "chore"

- package-ecosystem: "docker"
directory: "/httpserver"
schedule:
interval: "weekly"
ignore:
- dependency-name: "golang"
versions: '> 1.22'
commit-message:
prefix: "chore"

- package-ecosystem: "docker"
directory: "/.devcontainer"
schedule:
interval: "weekly"
ignore:
- dependency-name: "vscode/devcontainers/go"
versions: '> 1.22'
commit-message:
prefix: "chore"
4 changes: 2 additions & 2 deletions .github/licenserc.yml
Original file line number Diff line number Diff line change
Expand Up @@ -29,7 +29,7 @@ header:
limitations under the License.

paths-ignore:
- "**/*.{md,svg,yaml,crt,json,pub,yml,pb.go,proto}"
- "**/*.{md,svg,yaml,crt,cer,json,pub,yml,pb.go,proto}"
- "CODEOWNERS"
- "PROJECT"
- "NOTICE"
Expand All @@ -49,7 +49,7 @@ dependency:
- go.mod
licenses:
- name: github.com/spdx/tools-golang
version: v0.5.3
version: v0.5.5
license: Apache-2.0
- name: github.com/alibabacloud-go/cr-20160607 # TODO: remove this when library is upgraded to v2.0.0
version: v1.0.1
Expand Down
55 changes: 31 additions & 24 deletions .github/workflows/build-pr.yml
Original file line number Diff line number Diff line change
Expand Up @@ -5,25 +5,28 @@ on:
types: [labeled]
pull_request:
branches:
- staging
- dev
workflow_dispatch:

permissions: read-all

jobs:
call_test_cli:
uses: ./.github/workflows/e2e-cli.yml

secrets:
CODECOV_TOKEN: ${{ secrets.CODECOV_TOKEN }}

call_test_e2e_basic:
name: "run e2e on basic matrix"
if: ${{ ! (contains(github.event.pull_request.labels.*.name, 'safe to test') || github.event_name == 'workflow_dispatch') }}
permissions:
contents: read
strategy:
fail-fast: false
matrix:
KUBERNETES_VERSION: ["1.27.7"]
GATEKEEPER_VERSION: ["3.15.0"]
uses: ./.github/workflows/e2e-k8s.yml
KUBERNETES_VERSION: ["1.29.2"]
GATEKEEPER_VERSION: ["3.17.0"]
uses: ./.github/workflows/e2e-k8s.yml
with:
k8s_version: ${{ matrix.KUBERNETES_VERSION }}
gatekeeper_version: ${{ matrix.GATEKEEPER_VERSION }}
Expand All @@ -34,12 +37,12 @@ jobs:
strategy:
fail-fast: false
matrix:
KUBERNETES_VERSION: ["1.26.10", "1.27.7"]
GATEKEEPER_VERSION: ["3.13.0", "3.14.0", "3.15.0"]
uses: ./.github/workflows/e2e-k8s.yml
KUBERNETES_VERSION: ["1.28.12", "1.29.2"]
GATEKEEPER_VERSION: ["3.15.0", "3.16.0", "3.17.0"]
uses: ./.github/workflows/e2e-k8s.yml
with:
k8s_version: ${{ matrix.KUBERNETES_VERSION }}
gatekeeper_version: ${{ matrix.GATEKEEPER_VERSION }}
gatekeeper_version: ${{ matrix.GATEKEEPER_VERSION }}

build_test_aks_e2e_conditional:
name: "Build and run e2e Test on AKS with conditions"
Expand All @@ -50,37 +53,41 @@ jobs:
strategy:
fail-fast: false
matrix:
KUBERNETES_VERSION: ["1.26.10", "1.27.7"]
GATEKEEPER_VERSION: ["3.13.0", "3.14.0", "3.15.0"]
KUBERNETES_VERSION: ["1.28.12", "1.29.2"]
GATEKEEPER_VERSION: ["3.15.0", "3.16.0", "3.17.0"]
uses: ./.github/workflows/e2e-aks.yml
with:
k8s_version: ${{ matrix.KUBERNETES_VERSION }}
gatekeeper_version: ${{ matrix.GATEKEEPER_VERSION }}
secrets: inherit

aks-test-cleanup:
env:
AZURE_SUBSCRIPTION_ID: daae1e1a-63dc-454f-825d-b39289070f79
AZURE_CLIENT_ID: 814e6e97-120c-4534-b8a9-f1645bc99500
AZURE_TENANT_ID: 72f988bf-86f1-41af-91ab-2d7cd011db47
needs: ['build_test_aks_e2e_conditional']
needs: ["build_test_aks_e2e_conditional"]
runs-on: ubuntu-latest
permissions:
id-token: write
contents: read
environment: azure-test
steps:
- name: Harden Runner
uses: step-security/harden-runner@91182cccc01eb5e619899d80e4e971d6181294a7 # v2.10.1
with:
egress-policy: audit

- name: Check out code into the Go module directory
uses: actions/checkout@9bb56186c3b09b4f86b1c65136769dd318469633 # v4.1.2
- name: Set up Go 1.21
uses: actions/setup-go@0c52d547c9bc32b1aa3301fd7a9cb496313a4491 # v5.0.0
uses: actions/checkout@eef61447b9ff4aafe5dcd4e0bbf5d482be7e7871 # v4.2.1
- name: Set up Go 1.22
uses: actions/setup-go@0a12ed9d6a96ab950c8f026ed9f722fe0da7ef32 # v5.0.2
with:
go-version: '1.21'
go-version: "1.22"

- name: Az CLI login
uses: azure/login@8c334a195cbb38e46038007b304988d888bf676a # v2.0.0
uses: azure/login@a65d910e8af852a8061c627c456678983e180302 # v2.2.0
with:
creds: '{"clientId":"${{ env.AZURE_CLIENT_ID }}","clientSecret":"${{ secrets.AZURE_CLIENT_SECRET }}","subscriptionId":"${{ env.AZURE_SUBSCRIPTION_ID }}","tenantId":"${{ env.AZURE_TENANT_ID }}"}'
client-id: ${{ secrets.AZURE_CLIENT_ID }}
tenant-id: ${{ secrets.AZURE_TENANT_ID }}
subscription-id: ${{ secrets.AZURE_SUBSCRIPTION_ID }}

- name: clean up
run: |
make e2e-cleanup AZURE_SUBSCRIPTION_ID=${{ env.AZURE_SUBSCRIPTION_ID }}
make e2e-cleanup AZURE_SUBSCRIPTION_ID=${{ secrets.AZURE_SUBSCRIPTION_ID }}
14 changes: 11 additions & 3 deletions .github/workflows/cache-cleanup.yml
Original file line number Diff line number Diff line change
Expand Up @@ -4,14 +4,22 @@ on:
types:
- closed

permissions:
contents: read

jobs:
cleanup:
runs-on: ubuntu-latest
steps:
steps:
- name: Harden Runner
uses: step-security/harden-runner@91182cccc01eb5e619899d80e4e971d6181294a7 # v2.10.1
with:
egress-policy: audit

- name: Cleanup
run: |
gh extension install actions/gh-actions-cache

echo "Fetching list of cache key"
cacheKeysForPR=$(gh actions-cache list -R $REPO -B $BRANCH -L 100 | cut -f 1 )

Expand All @@ -26,4 +34,4 @@ jobs:
env:
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
REPO: ${{ github.repository }}
BRANCH: refs/pull/${{ github.event.pull_request.number }}/merge
BRANCH: refs/pull/${{ github.event.pull_request.number }}/merge
33 changes: 33 additions & 0 deletions .github/workflows/clean-dev-package.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,33 @@
name: clean-dev-package

on:
workflow_dispatch:

permissions:
contents: read

jobs:
cleanup-packages:
runs-on: ubuntu-latest
permissions:
packages: write
steps:
- name: Harden Runner
uses: step-security/harden-runner@91182cccc01eb5e619899d80e4e971d6181294a7 # v2.10.1
with:
egress-policy: audit

- name: Clean up ratify-crds-dev
uses: actions/delete-package-versions@e5bc658cc4c965c472efe991f8beea3981499c55 # v5.0.0
with:
package-name: "ratify-crds-dev"
package-type: "container"
min-versions-to-keep: 7
delete-only-pre-release-versions: "true"
- name: Clean up ratify-dev
uses: actions/delete-package-versions@e5bc658cc4c965c472efe991f8beea3981499c55 # v5.0.0
with:
package-name: "ratify-dev"
package-type: "container"
min-versions-to-keep: 7
delete-only-pre-release-versions: "true"
24 changes: 15 additions & 9 deletions .github/workflows/codeql.yml
Original file line number Diff line number Diff line change
@@ -1,17 +1,18 @@

name: "CodeQL Scan"

on:
push:
branches:
branches:
- main
- dev
- 1.0.0*
pull_request:
branches:
branches:
- main
- dev
- 1.0.0*
schedule:
- cron: '30 1 * * 0'
- cron: "30 1 * * 0"
workflow_dispatch:

permissions: read-all
Expand All @@ -24,19 +25,24 @@ jobs:
security-events: write

steps:
- name: Harden Runner
uses: step-security/harden-runner@91182cccc01eb5e619899d80e4e971d6181294a7 # v2.10.1
with:
egress-policy: audit

- name: Checkout repository
uses: actions/checkout@9bb56186c3b09b4f86b1c65136769dd318469633 # tag=3.0.2
uses: actions/checkout@eef61447b9ff4aafe5dcd4e0bbf5d482be7e7871 # tag=3.0.2
- name: setup go environment
uses: actions/setup-go@0c52d547c9bc32b1aa3301fd7a9cb496313a4491 # v5.0.0
uses: actions/setup-go@0a12ed9d6a96ab950c8f026ed9f722fe0da7ef32 # v5.0.2
with:
go-version: "1.21"
go-version: "1.22"
- name: Initialize CodeQL
uses: github/codeql-action/init@cdcdbb579706841c47f7063dda365e292e5cad7a # tag=v2.13.4
uses: github/codeql-action/init@c36620d31ac7c881962c3d9dd939c40ec9434f2b # tag=v3.26.12
with:
languages: go
- name: Run tidy
run: go mod tidy
- name: Build CLI
run: make build
- name: Perform CodeQL Analysis
uses: github/codeql-action/analyze@cdcdbb579706841c47f7063dda365e292e5cad7a # tag=v2.13.4
uses: github/codeql-action/analyze@c36620d31ac7c881962c3d9dd939c40ec9434f2b # tag=v3.26.12
Loading
Loading