Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Bump github.com/tektoncd/pipeline from 0.62.2 to 0.63.0 #2391

Conversation

dependabot[bot]
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Sep 2, 2024

Bumps github.com/tektoncd/pipeline from 0.62.2 to 0.63.0.

Release notes

Sourced from github.com/tektoncd/pipeline's releases.

Tekton Pipeline release v0.63.0 "Abyssinian K-9"

-Docs @ v0.63.0 -Examples @ v0.63.0

Installation one-liner

kubectl apply -f https://storage.googleapis.com/tekton-releases/pipeline/previous/v0.63.0/release.yaml

Attestation

The Rekor UUID for this release is 108e9186e8c5677a41806e924e8c5d6a3c1e083f8c35950f0d1af7e0e6a4c0712a2eb4bf92e9538e

Obtain the attestation:

REKOR_UUID=108e9186e8c5677a41806e924e8c5d6a3c1e083f8c35950f0d1af7e0e6a4c0712a2eb4bf92e9538e
rekor-cli get --uuid $REKOR_UUID --format json | jq -r .Attestation | jq .

Verify that all container images in the attestation are in the release file:

RELEASE_FILE=https://storage.googleapis.com/tekton-releases/pipeline/previous/v0.63.0/release.yaml
REKOR_UUID=108e9186e8c5677a41806e924e8c5d6a3c1e083f8c35950f0d1af7e0e6a4c0712a2eb4bf92e9538e
Obtains the list of images with sha from the attestation
REKOR_ATTESTATION_IMAGES=$(rekor-cli get --uuid "$REKOR_UUID" --format json | jq -r .Attestation | jq -r '.subject[]|.name + ":v0.63.0@sha256:" + .digest.sha256')
Download the release file
curl "$RELEASE_FILE" > release.yaml
For each image in the attestation, match it to the release file
for image in $REKOR_ATTESTATION_IMAGES; do
printf $image; grep -q $image release.yaml && echo " ===> ok" || echo " ===> no match";
done

Changes

Features

  • ✨ cluster-reslover: add support for StepAction (#8199)

... (truncated)

Commits
  • c910594 Fix Artifact type to a pointer
  • a3bd23e build(deps): bump tj-actions/changed-files from 44.5.7 to 45.0.0
  • 504bdc8 Add UID label to PipelineRun and TaskRun
  • 78d1f11 Fixing linting issue with updates…
  • 1c0367d build(deps): bump github.com/golangci/golangci-lint in /tools
  • b4e8652 fix(taskrun): resolve issue with TaskRun not failing promptly after Pod OOM
  • 7ba0b3b build(deps): bump github.com/docker/docker
  • 4f04964 TEP-0097 breakpoint before steps for taskrun
  • c6c33e0 docs: fix links to Matrix examples
  • 086e4d6 apply default-container-resource-requirements before LimitRange transformer
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

@dependabot dependabot bot added dependencies Used by dependabot - identifies all PRs created by dependabot kind/misc Categorizes issue or PR as a miscellaneuous one. ok-to-test Indicates a non-member PR verified by an org member that is safe to test. release-note-none Denotes a PR that doesnt merit a release note. labels Sep 2, 2024
@tekton-robot
Copy link
Contributor

Hi @dependabot[bot]. Thanks for your PR.

I'm waiting for a tektoncd member to verify that this patch is reasonable to test. If it is, they should reply with /ok-to-test on its own line. Until that is done, I will not automatically test new commits in this PR, but the usual testing commands by org members will still work. Regular contributors should join the org to skip this step.

Once the patch is verified, the new status will be reflected by the ok-to-test label.

I understand the commands that are listed here.

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository.

@tekton-robot tekton-robot added the size/L Denotes a PR that changes 100-499 lines, ignoring generated files. label Sep 2, 2024
@piyush-garg
Copy link
Contributor

/hold

we will first do 0.62.3 to fix #2388 and do a patch release

@tekton-robot tekton-robot added the do-not-merge/hold Indicates that a PR should not merge because someone has issued a /hold command. label Sep 3, 2024
@vdemeester
Copy link
Member

@piyush-garg don't we have a release branch for tkn 0.38 ?

@dependabot dependabot bot force-pushed the dependabot/go_modules/github.com/tektoncd/pipeline-0.63.0 branch from 0ecd8d2 to cf02f81 Compare September 4, 2024 04:11
Bumps [github.com/tektoncd/pipeline](https://github.com/tektoncd/pipeline) from 0.62.2 to 0.63.0.
- [Release notes](https://github.com/tektoncd/pipeline/releases)
- [Changelog](https://github.com/tektoncd/pipeline/blob/main/releases.md)
- [Commits](tektoncd/pipeline@v0.62.2...v0.63.0)

---
updated-dependencies:
- dependency-name: github.com/tektoncd/pipeline
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <[email protected]>
@dependabot dependabot bot force-pushed the dependabot/go_modules/github.com/tektoncd/pipeline-0.63.0 branch from cf02f81 to c542be1 Compare September 5, 2024 11:21
@piyush-garg
Copy link
Contributor

/hold

we will first do 0.62.3 to fix #2388 and do a patch release

@piyush-garg don't we have a release branch for tkn 0.38 ?

we have release branch release-v0.38.0, so we dont cherry pick here and we cut a branch during release for new version with cherry-picking commits for patch release.

so for 0.38.1, we need the particular commit in main branch to cut a new branch release-0.38.1 which will be using base branch release-v0.38.0 and with few cherry-pick commits from main

@piyush-garg
Copy link
Contributor

/hold cancel

@tekton-robot tekton-robot removed the do-not-merge/hold Indicates that a PR should not merge because someone has issued a /hold command. label Sep 10, 2024
@piyush-garg
Copy link
Contributor

/approve
/lgtm
/retest

@tekton-robot tekton-robot added the lgtm Indicates that a PR is ready to be merged. label Sep 10, 2024
@tekton-robot
Copy link
Contributor

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: piyush-garg

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@tekton-robot tekton-robot added the approved Indicates a PR has been approved by an approver from all required OWNERS files. label Sep 10, 2024
@piyush-garg
Copy link
Contributor

/retest

1 similar comment
@piyush-garg
Copy link
Contributor

/retest

@tekton-robot tekton-robot merged commit ca3b6e9 into main Sep 10, 2024
7 of 8 checks passed
@dependabot dependabot bot deleted the dependabot/go_modules/github.com/tektoncd/pipeline-0.63.0 branch September 10, 2024 18:49
vinamra28 added a commit that referenced this pull request Nov 26, 2024
#2393 | [dependabot[bot]] Bump github.com/sigstore/sigstore from 1.8.8 to 1.8.9 | 2024/09/10-15:45
#2398 | [vinamra28] Update docs for tkn 0.38.1 | 2024/09/10-17:13
#2395 | [dependabot[bot]] Bump golang.org/x/term from 0.23.0 to 0.24.0 | 2024/09/10-18:09
#2397 | [dependabot[bot]] Bump github.com/golangci/golangci-lint from 1.60.3 to 1.61.0 in /tools | 2024/09/10-18:09
#2391 | [dependabot[bot]] Bump github.com/tektoncd/pipeline from 0.62.2 to 0.63.0 | 2024/09/10-19:49
#2399 | [dependabot[bot]] Bump the go-k8s-dependencies group with 4 updates | 2024/09/12-18:59
#2403 | [dependabot[bot]] Bump github.com/tektoncd/chains from 0.22.0 to 0.22.1 | 2024/09/19-03:13
#2401 | [Aung Baw] Fix hard link for Mac | 2024/09/20-08:22
#2404 | [dependabot[bot]] Bump the go-docker-dependencies group with 2 updates | 2024/09/21-06:14
#2405 | [dependabot[bot]] Bump the go-docker-dependencies group with 2 updates | 2024/09/23-18:44
null | [dependabot[bot]] Bump github.com/tektoncd/chains from 0.22.1 to 0.22.2 | 2024/09/30-17:18
null | [dependabot[bot]] Bump github.com/tektoncd/pipeline from 0.63.0 to 0.64.0 | 2024/09/30-17:52
null | [dependabot[bot]] Bump golang.org/x/term from 0.24.0 to 0.25.0 | 2024/10/07-15:44
null | [Piyush Garg] Bump cosign to v2.4.1 | 2024/10/15-06:20
null | [dependabot[bot]] Bump github.com/fatih/color from 1.17.0 to 1.18.0 | 2024/10/24-09:36
null | [dependabot[bot]] Bump github.com/tektoncd/pipeline from 0.64.0 to 0.65.0 | 2024/10/29-14:52
null | [dependabot[bot]] Bump github.com/creack/pty from 1.1.23 to 1.1.24 | 2024/11/04-10:08
null | [dependabot[bot]] Bump the go-k8s-dependencies group with 4 updates | 2024/11/05-09:06
null | [Chmouel Boudjnah] Set status to succeeded when the reason is Completed | 2024/11/06-08:58
null | [dependabot[bot]] Bump github.com/golang-jwt/jwt/v4 from 4.5.0 to 4.5.1 | 2024/11/06-10:26
null | [dependabot[bot]] Bump github.com/tektoncd/pipeline from 0.65.0 to 0.65.1 | 2024/11/06-17:48
null | [dependabot[bot]] Bump github.com/tektoncd/hub from 1.18.0 to 1.19.0 | 2024/11/07-08:10
null | [Chmouel Boudjnah] refactor RemoveFieldForExport function | 2024/11/07-11:22
null | [dependabot[bot]] Bump github.com/tektoncd/triggers from 0.29.1 to 0.30.0 | 2024/11/07-14:54
null | [dependabot[bot]] Bump github.com/tektoncd/chains from 0.22.2 to 0.23.0 | 2024/11/07-15:42
null | [dependabot[bot]] Bump golang.org/x/term from 0.25.0 to 0.26.0 | 2024/11/08-19:12
null | [divyansh42] Bump go to 1.22.8 and remove toolchain | 2024/11/11-10:10
null | [divyansh42] Reword variable name to fix lint issues | 2024/11/12-08:20
null | [dependabot[bot]] Bump github.com/golangci/golangci-lint from 1.61.0 to 1.62.0 in /tools | 2024/11/12-10:28
null | [dependabot[bot]] Bump github.com/tektoncd/pipeline from 0.65.1 to 0.65.2 | 2024/11/19-15:12
null | [dependabot[bot]] Bump the go-k8s-dependencies group with 4 updates | 2024/11/21-08:40
null | [dependabot[bot]] Bump github.com/golangci/golangci-lint from 1.62.0 to 1.62.2 in /tools | 2024/11/25-09:56
null | [Vincent Demeester] Use io.ReadFull to read the bundle content | 2024/11/26-01:42

Signed-off-by: vinamra28 <[email protected]>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
approved Indicates a PR has been approved by an approver from all required OWNERS files. dependencies Used by dependabot - identifies all PRs created by dependabot kind/misc Categorizes issue or PR as a miscellaneuous one. lgtm Indicates that a PR is ready to be merged. ok-to-test Indicates a non-member PR verified by an org member that is safe to test. release-note-none Denotes a PR that doesnt merit a release note. size/L Denotes a PR that changes 100-499 lines, ignoring generated files.
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants