Repository navigation
Update module github.com/tektoncd/pipeline to v1.17.0 (release-v0.7) - #3564
renovate[bot] wants to merge 1 commit into
Conversation
ℹ️ Artifact update noticeFile name: acceptance/go.modIn order to perform the update(s) described in the table above, Renovate ran the
Due to Go's usage of Minimal Version Selection (MVS), these packages have been updated to the minimum version available, so will still abide by Details:
File name: go.modIn order to perform the update(s) described in the table above, Renovate ran the
Due to Go's usage of Minimal Version Selection (MVS), these packages have been updated to the minimum version available, so will still abide by Details:
|
|
Important Review skippedBot user detected. To trigger a single review, invoke the ⚙️ Run configuration
You can disable this status message by setting the Use the checkbox below for a quick retry:
Comment |
|
🤖 Finished Review · ✅ Success · Started 3:05 AM UTC · Completed 3:11 AM UTC Commit: Runtime: claude · Model: opus → claude-opus-4-7 · Effort: high · Cost: $3.74 |
|
Looks good to me Previous runLooks good to me Previous run (2)Looks good to me Previous run (3)Looks good to me Previous run (4)ReviewRenovate PR bumping FindingsInfo
|
Codecov Report✅ All modified and coverable lines are covered by tests.
Flags with carried forward coverage won't be shown. Click here to find out more. 🚀 New features to boost your workflow:
|
0f8f27c to
11a6ae7
Compare
|
🤖 Finished Review · ✅ Success · Started 3:19 PM UTC · Completed 3:26 PM UTC Commit: Runtime: claude · Model: opus → claude-opus-4-7 · Effort: high · Cost: $4.20 |
11a6ae7 to
56304af
Compare
|
🤖 Finished Review · ✅ Success · Started 7:36 PM UTC · Completed 7:44 PM UTC Commit: Runtime: claude · Model: opus → claude-opus-4-7 · Effort: high · Cost: $3.76 |
|
Risk Assessment: moderate (2/5) DetailsBot-authored Renovate PR updating Tekton pipeline go.mod/go.sum across 4 dependency files; medium blast radius and 4 dependency files drive score to moderate, while bot authorship and absence of protected paths or security-sensitive changes keep it from elevating further. Previous runRisk Assessment: moderate (2/5) DetailsBot-authored routine dependency update touching only go.mod/go.sum files across main and acceptance modules; sole elevated signal is >=2 dependency files changed, offset by bot authorship, no protected paths, and no security-sensitive changes, yielding a moderate composite. Previous run (2)Risk Assessment: moderate (2/5) DetailsRenovate bot dependency-only bump (4 Go module manifests, 292 lines) with no protected paths, security-sensitive files, or CI changes; multi-file dependency updates and moderately elevated recent churn on go.mod/go.sum push the score above baseline into moderate. |
56304af to
750db29
Compare
750db29 to
813e005
Compare
|
🤖 Finished Review · ✅ Success · Started 1:33 PM UTC · Completed 1:39 PM UTC Commit: Runtime: claude · Model: opus → claude-opus-4-7 · Effort: high · Cost: $2.23 |
Superseded by updated review
813e005 to
9f4930c
Compare
|
🤖 Finished Review · ❌ Failure (ensuring provider "github-ro": provider create "github-ro" failed: exit status 1 (output: Error: × provider profile 'fullsend-github-ro' not found; import a matching profile │ before using this provid…) · Started 10:33 AM UTC · Completed 10:33 AM UTC Commit: Effort: high |
This PR contains the following updates:
v1.12.0→v1.17.0Release Notes
tektoncd/pipeline (github.com/tektoncd/pipeline)
v1.17.0: Tekton Pipeline release v1.17.0 "Egyptian Mau Robocop"Compare Source
🎉 Clearer failures, sharper traces 🎉
Installation one-liner
Attestation
The Rekor UUID for this release is
108e9186e8c5677a431fb2e9f34a5fd5b0418cccab54d920148b79cbe5bfcd5a2075f7ae918a9cc9Obtain the attestation:
Verify that all container images in the attestation are in the release file:
Changes
Features
Add a
reconcile.write_intentattribute (no-op, status-only, metadata-only, metadata-and-status) to PipelineRun and TaskRun reconcile spans so operators can distinguish reconciliations that intend an etcd write.Surface Pod infrastructure failure reasons (from Warning events such as
FailedMount, FailedScheduling, FailedCreatePodSandBox) onto the TaskRun
status condition when a Pod is stuck pending with no useful message. Gated
behind the new
surface-pod-eventsalpha feature flag (disabled by default).Fixes
Fixed a Windows script-injection defense-in-depth gap:
placeScriptInContainernow uses a non-expandable PowerShell here-string, so a script body containing a literal"@line can no longer terminate the generated command early.Before this update, when resolver fails to get any task, controller showed the error message without containing the task name which was hard to detect which one is failed or having bad resolution config. Now task name is added to the error message from template.
Pipelines can now reference
$(tt.params.<name>)in task params,whenexpressions, and matrix params/includes. This lets aPipelineSpecembedded by Tekton Triggers keep itstt.params.*substitutions without failing pipeline validation.Resolvers no longer fail ResolutionRequests belonging to a different resolver after a leader election or a resolver pod restart.
Fixed controller startup panic messages that printed a malformed
%!w(...)marker instead of the underlying error when an informer event handler failed to register.Misc
NOT REQUIRED
Docs
Thanks
Thanks to these contributors who contributed to v1.17.0!
Extra shout-out for awesome release notes:
v1.16.0: Tekton Pipeline release v1.16.0 "Manx WALL-E"Compare Source
🎉 Secure by default, sharper traces 🎉
-Docs @ v1.16.0
-Examples @ v1.16.0
Installation one-liner
Attestation
The Rekor UUID for this release is
108e9186e8c5677a13e773b2ae0f6c52943d2b44a284030efb9b43068a9927a698b4799e13342b14Obtain the attestation:
Verify that all container images in the attestation are in the release file:
Upgrade Notices
set-security-contextenabled by defaultaction required:
set-security-contextnow defaults totrueand applies only to Tekton-injected TaskRun containers and Affinity Assistants (#9589, #10680). User-defined Steps and Sidecars must supply their own restricted-compatible security contexts. If the generated security contexts are incompatible with your images or Kubernetes implementation, setset-security-contextto"false".Changes
Features
Add tracing spans to the task parameter and workspace substitution pipeline in the TaskRun reconciler to improve observability and performance tracking. No user-facing changes.
Fixes
Update the golangci-lint installation URL
Fix root tracing span lifecycle in TaskRun and PipelineRun reconcilers to cover the full reconciliation cycle instead of ending immediately after initialization.
Misc
Docs
Thanks
Thanks to these contributors who contributed to v1.16.0!
Extra shout-out for awesome release notes:
v1.15.3: Tekton Pipeline release v1.15.3 "Toyger Orisa" LTSCompare Source
Installation one-liner
Attestation
The Rekor UUID for this release is
108e9186e8c5677a1cca30d273b8c9dacc3ecea843087a7743386bf7355ef7a283afd3ed1829b921Obtain the attestation:
Verify that all container images in the attestation are in the release file:
Changes
Features
Fixes
Pipelines can now reference
$(tt.params.<name>)in task params,whenexpressions, and matrix params/includes. This lets aPipelineSpecembedded by Tekton Triggers keep itstt.params.*substitutions without failing pipeline validation.Misc
Docs
Thanks
Thanks to these contributors who contributed to v1.15.3!
Extra shout-out for awesome release notes:
v1.15.2: Tekton Pipeline release v1.15.2 "Toyger Orisa" LTSCompare Source
-Docs @ v1.15.2
-Examples @ v1.15.2
Installation one-liner
Attestation
The Rekor UUID for this release is
108e9186e8c5677ad57a83fb64ccefa586efb4446b591b3a2d760972ce02657eb1929896879dbb74Obtain the attestation:
Verify that all container images in the attestation are in the release file:
Changes
Features
Fixes
Misc
Docs
Thanks
Thanks to these contributors who contributed to v1.15.2!
Extra shout-out for awesome release notes:
v1.15.1: Tekton Pipeline release v1.15.1 "Toyger Orisa" LTSCompare Source
-Docs @ v1.15.1
-Examples @ v1.15.1
Installation one-liner
Attestation
The Rekor UUID for this release is
108e9186e8c5677a210b81c75be73c2949e8e917e1776229b8bb68bc95b532e51d8f2bf29219a9c1Obtain the attestation:
Verify that all container images in the attestation are in the release file:
Changes
Features
Fixes
Misc
Docs
Thanks
Thanks to these contributors who contributed to v1.15.1!
Extra shout-out for awesome release notes:
v1.15.0: Tekton Pipeline release v1.15.0 "Toyger Orisa" LTSCompare Source
🎉 Steady under pressure — configurable backoffs and battle-tested fixes 🎉
-Docs @ v1.15.0
-Examples @ v1.15.0
Installation one-liner
Attestation
The Rekor UUID for this release is
108e9186e8c5677a045c87c57225dfff98b32437f52b89e344c449bcd535b462d41fff9004b89d29Obtain the attestation:
Verify that all container images in the attestation are in the release file:
Changes
Features
Enables the configuration of backoffs for git resolver requests.
Add
default-create-container-error-timeoutconfiguration option inconfig-defaultsto provide a grace period before failing TaskRuns on transientCreateContainerError/CreateContainerConfigErrorwith "context deadline exceeded". Default is 0 (fail fast, preserving existing behavior)Fixes
Prevent ResolutionRequest lifecycle updates from overwriting resolver-written status fields.
Fix resolver replicas processing ResolutionRequests outside their leader-election bucket.
Fixed an integer overflow in matrix combination counting that could let a very
large matrix bypass the max-matrix-combinations validation guard.
Fix PipelineRun remaining stuck in ResolvingTaskRef when a ResolutionRequest completion event is missed by periodically requeueing while remote resolution is in progress
Fixed a panic in the PipelineRun controller when a PipelineRun using an embedded (anonymous) pipeline spec sets a
generateNamethat contains no alphanumeric characters (for example--). Such names no longer crash the reconciler.Fix sidecar-logs result extraction dropping all TaskRun results when a single result's JSON exceeds 4096 bytes but is within the configured max-result-size. Regression since v1.9.0.
Fixed a bug where a Sidecar's
restartPolicy(native Kubernetes sidecar support)was dropped when converting a Task or TaskRun between the v1beta1 and v1 API
versions, causing a sidecar requested as a native sidecar to be created as an
ordinary sidecar.
Debug breakpoint scripts are now mounted read-only in step containers, so a step can no longer overwrite them before a user execs in to continue or fail a breakpoint.
Misc
Fix release pipeline
ko resolvefailure caused byko>= v0.19.0 rejectingthe
kodata/source.tar.gzsymlink used to bundle vendored source.Configuration
📅 Schedule: (UTC)
* 0-3 * * *)🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.