Skip to content

Update module github.com/tektoncd/pipeline to v1.17.0 (release-v0.7) - #3564

Open
renovate[bot] wants to merge 1 commit into
release-v0.7from
renovate/release-v0.7-tektoncd-pipelines
Open

renovate[bot] wants to merge 1 commit into
release-v0.7from
renovate/release-v0.7-tektoncd-pipelines

Conversation

@renovate

@renovate renovate Bot commented Sep 11, 2026 •

Copy link
Copy Markdown
Contributor

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
github.com/tektoncd/pipeline v1.12.0 → v1.17.0 age adoption passing confidence

Release Notes

tektoncd/pipeline (github.com/tektoncd/pipeline)

v1.17.0: Tekton Pipeline release v1.17.0 "Egyptian Mau Robocop"

Compare Source

🎉 Clearer failures, sharper traces 🎉

Installation one-liner

kubectl apply -f https://infra.tekton.dev/tekton-releases/pipeline/previous/v1.17.0/release.yaml

Attestation

The Rekor UUID for this release is 108e9186e8c5677a431fb2e9f34a5fd5b0418cccab54d920148b79cbe5bfcd5a2075f7ae918a9cc9

Obtain the attestation:

REKOR_UUID=108e9186e8c5677a431fb2e9f34a5fd5b0418cccab54d920148b79cbe5bfcd5a2075f7ae918a9cc9
rekor-cli get --uuid $REKOR_UUID --format json | jq -r .Attestation | jq .

Verify that all container images in the attestation are in the release file:

RELEASE_FILE=https://infra.tekton.dev/tekton-releases/pipeline/previous/v1.17.0/release.yaml
REKOR_UUID=108e9186e8c5677a431fb2e9f34a5fd5b0418cccab54d920148b79cbe5bfcd5a2075f7ae918a9cc9

# Obtains the list of images with sha from the attestation
REKOR_ATTESTATION_IMAGES=$(rekor-cli get --uuid "$REKOR_UUID" --format json | jq -r .Attestation | jq -r '.subject[]|.name + ":v1.17.0@sha256:" + .digest.sha256')

# Download the release file
curl -L "$RELEASE_FILE" > release.yaml

# For each image in the attestation, match it to the release file
for image in $REKOR_ATTESTATION_IMAGES; do
  printf $image; grep -q $image release.yaml && echo " ===> ok" || echo " ===> no match";
done

Changes

Features

  • ✨ feat(tracing): record reconcile.write_intent span attribute (#​10827)

Add a reconcile.write_intent attribute (no-op, status-only, metadata-only, metadata-and-status) to PipelineRun and TaskRun reconcile spans so operators can distinguish reconciliations that intend an etcd write.

  • ✨ Feat/10373 surface pod events/srvkp 13129 (#​10690)

Surface Pod infrastructure failure reasons (from Warning events such as
FailedMount, FailedScheduling, FailedCreatePodSandBox) onto the TaskRun
status condition when a Pod is stuck pending with no useful message. Gated
behind the new surface-pod-events alpha feature flag (disabled by default).

  • ✨ feat(tracing): tag TaskRun ReconcileKind span on cancel/timeout (#​10664)
Fixes
  • 🐛 fix: use non-expandable here-string for windows script placement (#​10822)

Fixed a Windows script-injection defense-in-depth gap: placeScriptInContainer now uses a non-expandable PowerShell here-string, so a script body containing a literal "@ line can no longer terminate the generated command early.

  • 🐛 fix: add task name in error on task resolution failure (#​10800)

Before this update, when resolver fails to get any task, controller showed the error message without containing the task name which was hard to detect which one is failed or having bad resolution config. Now task name is added to the error message from template.

  • 🐛 Allow tt.params as a valid variable-reference prefix (#​10688)

Pipelines can now reference $(tt.params.<name>) in task params, when expressions, and matrix params/includes. This lets a PipelineSpec embedded by Tekton Triggers keep its tt.params.* substitutions without failing pipeline validation.

  • 🐛 Enqueue only a resolver's own ResolutionRequests (#​10548)

Resolvers no longer fail ResolutionRequests belonging to a different resolver after a leader election or a resolver pod restart.

  • 🐛 fix: correct verb in controller startup panic logs (#​10430)

Fixed controller startup panic messages that printed a malformed %!w(...) marker instead of the underlying error when an informer event handler failed to register.

  • 🐛 Fix release_names.go: update regex for Wikipedia HTML changes and fix bugs (#​10508)
Misc
  • 🔨 chore: delete dead code in test/per_feature_flags_test.go file (#​10802)

NOT REQUIRED

  • 🔨 chore: group sigstore dependency updates in dependabot (#​10761)
  • 🔨 Eliminate discontinued gopkg.in/yaml.v3 library (#​10683)
  • 🔨 build(deps): bump the kubernetes group with 5 updates (#​10829)
  • 🔨 build(deps): bump the kubernetes group in /test/custom-task-ctrls/wait-task-beta with 3 updates (#​10828)
  • 🔨 build(deps): bump google.golang.org/grpc from 1.83.2 to 1.84.0 (#​10823)
  • 🔨 build(deps): bump chainguard-dev/actions/kind-diag from 1.6.35 to 1.6.36 (#​10821)
  • 🔨 build(deps): bump codecov/codecov-action from 7.0.0 to 7.1.1 (#​10820)
  • 🔨 build(deps): bump agilepathway/label-checker from 1.6.66 to 1.6.98 (#​10819)
  • 🔨 build(deps): bump chainguard-dev/actions/setup-kind from 1.6.35 to 1.6.36 (#​10818)
  • 🔨 build(deps): bump the all group in /tekton with 4 updates (#​10803)
  • 🔨 test: Fix tracing test to honor custom SYSTEM_NAMESPACE (#​10801)
  • 🔨 build(deps): bump github.com/spiffe/go-spiffe/v2 from 2.8.1 to 2.8.2 (#​10795)
  • 🔨 build(deps): bump the sigstore group with 5 updates (#​10791)
  • 🔨 build(deps): bump github.com/jenkins-x/go-scm from 1.16.0 to 1.16.3 (#​10783)
  • 🔨 build(deps): bump the all group in /tekton with 4 updates (#​10782)
  • 🔨 build(deps): bump agilepathway/label-checker from 1.6.65 to 1.6.66 (#​10780)
  • 🔨 build(deps): bump chainguard-dev/actions/setup-kind from 1.6.34 to 1.6.35 (#​10779)
  • 🔨 build(deps): bump chainguard-dev/actions/kind-diag from 1.6.34 to 1.6.35 (#​10778)
  • 🔨 build(deps): bump zizmorcore/zizmor-action from 0.6.3 to 0.6.4 (#​10777)
  • 🔨 build(deps): bump the codeql-action group with 3 updates (#​10776)
  • 🔨 build(deps): bump the all group in /tekton with 6 updates (#​10766)
  • 🔨 build(deps): bump github.com/jenkins-x/go-scm from 1.15.32 to 1.16.0 (#​10760)
  • 🔨 build(deps): bump golang.org/x/crypto from 0.56.0 to 0.57.0 (#​10759)
  • 🔨 build(deps): bump github.com/sigstore/sigstore/pkg/signature/kms/aws from 1.10.9 to 1.10.10 (#​10746)
  • 🔨 build(deps): bump github.com/sigstore/sigstore/pkg/signature/kms/gcp from 1.10.9 to 1.10.10 (#​10745)
  • 🔨 build(deps): bump github.com/sigstore/sigstore/pkg/signature/kms/hashivault from 1.10.9 to 1.10.10 (#​10744)
  • 🔨 build(deps): bump github.com/sigstore/sigstore from 1.10.9 to 1.10.10 (#​10743)
  • 🔨 build(deps): bump github.com/sigstore/sigstore/pkg/signature/kms/azure from 1.10.9 to 1.10.10 (#​10742)
  • 🔨 build(deps): bump step-security/harden-runner from 2.21.0 to 2.21.1 (#​10734)
  • 🔨 build(deps): bump chainguard-dev/actions/setup-kind from 1.6.32 to 1.6.34 (#​10733)
  • 🔨 build(deps): bump chainguard-dev/actions/kind-diag from 1.6.33 to 1.6.34 (#​10731)
  • 🔨 build(deps): bump zizmorcore/zizmor-action from 0.6.2 to 0.6.3 (#​10730)
  • 🔨 build(deps): bump the codeql-action group across 1 directory with 2 updates (#​10729)
  • 🔨 build(deps): bump golang.org/x/crypto from 0.55.0 to 0.56.0 (#​10723)
  • 🔨 build(deps): bump golang.org/x/sync from 0.22.0 to 0.23.0 (#​10722)
  • 🔨 build(deps): bump github.com/prometheus/common from 0.70.1 to 0.71.0 (#​10721)
  • 🔨 build(deps): bump github.com/google/go-containerregistry from 0.22.0 to 0.22.1 (#​10720)
  • 🔨 build(deps): bump github.com/tektoncd/pipeline from 1.15.1 to 1.16.0 in /test/custom-task-ctrls/wait-task-beta (#​10719)
  • 🔨 build(deps): bump chainguard-dev/actions/kind-diag from 1.6.32 to 1.6.33 (#​10712)
  • 🔨 build(deps): bump github/codeql-action/upload-sarif from 4.37.7 to 4.37.9 (#​10711)
  • 🔨 build(deps): bump the all group across 1 directory with 4 updates (#​10697)
  • 🔨 build(deps): bump github.com/prometheus/client_model from 0.6.2 to 0.6.3 (#​10693)
  • 🔨 deps: use new import path for google/cel-go lib (#​10689)
  • 🔨 build(deps): bump github.com/google/go-containerregistry from 0.21.9 to 0.22.0 (#​10682)
  • 🔨 fix(CI): group github/codeql-action/* dependabot updates (#​10661)
  • 🔨 Bump plumbing ref for github_release_oci task (#​10509)
Docs
  • 📖 docs: add v1.16.0 release to releases.md (#​10681)
  • 📖 docs: clarify config-tracing and config-observability are separate tracing paths (#​10626)

Thanks

Thanks to these contributors who contributed to v1.17.0!

Extra shout-out for awesome release notes:

v1.16.0: Tekton Pipeline release v1.16.0 "Manx WALL-E"

Compare Source

🎉 Secure by default, sharper traces 🎉

-Docs @​ v1.16.0
-Examples @​ v1.16.0

Installation one-liner
kubectl apply -f https://infra.tekton.dev/tekton-releases/pipeline/previous/v1.16.0/release.yaml
Attestation

The Rekor UUID for this release is 108e9186e8c5677a13e773b2ae0f6c52943d2b44a284030efb9b43068a9927a698b4799e13342b14

Obtain the attestation:

REKOR_UUID=108e9186e8c5677a13e773b2ae0f6c52943d2b44a284030efb9b43068a9927a698b4799e13342b14
rekor-cli get --uuid $REKOR_UUID --format json | jq -r .Attestation | jq .

Verify that all container images in the attestation are in the release file:

RELEASE_FILE=https://infra.tekton.dev/tekton-releases/pipeline/previous/v1.16.0/release.yaml
REKOR_UUID=108e9186e8c5677a13e773b2ae0f6c52943d2b44a284030efb9b43068a9927a698b4799e13342b14

# Obtains the list of images with sha from the attestation
REKOR_ATTESTATION_IMAGES=$(rekor-cli get --uuid "$REKOR_UUID" --format json | jq -r .Attestation | jq -r '.subject[]|.name + ":v1.16.0@sha256:" + .digest.sha256')

# Download the release file
curl -L "$RELEASE_FILE" > release.yaml

# For each image in the attestation, match it to the release file
for image in $REKOR_ATTESTATION_IMAGES; do
  printf $image; grep -q $image release.yaml && echo " ===> ok" || echo " ===> no match";
done
Upgrade Notices
  • 🚨 set-security-context enabled by default

action required: set-security-context now defaults to true and applies only to Tekton-injected TaskRun containers and Affinity Assistants (#​9589, #​10680). User-defined Steps and Sidecars must supply their own restricted-compatible security contexts. If the generated security contexts are incompatible with your images or Kubernetes implementation, set set-security-context to "false".

Changes
Features
  • ✨ feat(tracing): add spans for task parameter and workspace substitution #​9801 (#​10271)

Add tracing spans to the task parameter and workspace substitution pipeline in the TaskRun reconciler to improve observability and performance tracking. No user-facing changes.

  • ✨ test(notifications): cover CustomRun initTracing span propagation (#​10559)
  • ✨ feat: enable set-security-context feature flag by default (#​9589)
Fixes
  • 🐛 fix(CI): update golang-ci install URL to use main branch (#​10659)

Update the golangci-lint installation URL

  • 🐛 fix(nightlies): pass previousReleaseTag/releaseName to tkn pipeline start (#​10550)
  • 🐛 fix(ci): bump codeql-action/analyze to match init (#​10516)
  • 🐛 fix: end root tracing span at reconciliation completion (#​9699)

Fix root tracing span lifecycle in TaskRun and PipelineRun reconcilers to cover the full reconciliation cycle instead of ending immediately after initialization.

Misc
  • 🔨 Use larger GitHub-hosted runners for CI and E2E (#​10511)
  • 🔨 build(deps): bump google.golang.org/grpc from 1.83.1 to 1.83.2 (#​10674)
  • 🔨 build(deps): bump step-security/harden-runner from 2.20.1 to 2.21.0 (#​10672)
  • 🔨 build(deps): bump chainguard-dev/actions/setup-kind from 1.6.31 to 1.6.32 (#​10671)
  • 🔨 build(deps): bump chainguard-dev/actions/kind-diag from 1.6.31 to 1.6.32 (#​10669)
  • 🔨 build(deps): bump github.com/tektoncd/pipeline from 1.15.0 to 1.15.1 in /test/custom-task-ctrls/wait-task-beta (#​10666)
  • 🔨 Bump github/codeql-action to v4.37.7 (#​10660)
  • 🔨 build(deps): bump google.golang.org/grpc from 1.83.0 to 1.83.1 (#​10653)
  • 🔨 build(deps): bump the kubernetes group with 5 updates (#​10652)
  • 🔨 build(deps): bump the kubernetes group in /test/custom-task-ctrls/wait-task-beta with 3 updates (#​10650)
  • 🔨 build(deps): bump github.com/spiffe/spire-api-sdk from 1.15.2 to 1.15.3 (#​10646)
  • 🔨 build(deps): bump github.com/allegro/bigcache/v3 from 3.1.0 to 3.2.0 (#​10645)
  • 🔨 build(deps): bump github/codeql-action/init from 4.37.5 to 4.37.7 (#​10640)
  • 🔨 build(deps): bump github/codeql-action/upload-sarif from 4.37.6 to 4.37.7 (#​10638)
  • 🔨 build(deps): bump golang.org/x/crypto from 0.54.0 to 0.55.0 (#​10629)
  • 🔨 fix: exclude generated and non-library code from codecov coverage (#​10627)
  • 🔨 build(deps): bump google.golang.org/protobuf from 1.36.12-0.20260120151049-f2248ac996af to 1.36.12 (#​10622)
  • 🔨 build(deps): bump chainguard-dev/actions/kind-diag from 1.6.30 to 1.6.31 (#​10620)
  • 🔨 build(deps): bump chainguard-dev/actions/setup-kind from 1.6.30 to 1.6.31 (#​10619)
  • 🔨 build(deps): bump step-security/harden-runner from 2.20.0 to 2.20.1 (#​10615)
  • 🔨 build(deps): bump github.com/google/cel-go from 0.30.0 to 0.31.0 (#​10614)
  • 🔨 Regenerate dependabot.yml configuration (#​10611)
  • 🔨 build(deps): bump github/codeql-action/upload-sarif from 4.37.5 to 4.37.6 (#​10604)
  • 🔨 build(deps): bump chainguard-dev/actions/setup-kind from 1.6.27 to 1.6.30 (#​10596)
  • 🔨 build(deps): bump ossf/scorecard-action from 2.4.3 to 2.4.4 (#​10595)
  • 🔨 Move v1.3.x to End of Life releases (#​10585)
  • 🔨 build(deps): bump chainguard-dev/actions/kind-diag from 1.6.27 to 1.6.30 (#​10584)
  • 🔨 build(deps): bump github/codeql-action/upload-sarif from 4.37.1 to 4.37.5 (#​10583)
  • 🔨 build(deps): bump zizmorcore/zizmor-action from 0.6.0 to 0.6.2 (#​10582)
  • 🔨 build(deps): bump github/codeql-action/init from 4.37.3 to 4.37.5 (#​10581)
  • 🔨 build(deps): bump github/codeql-action/analyze from 4.37.3 to 4.37.5 (#​10576)
  • 🔨 build(deps): bump github.com/google/go-containerregistry from 0.21.8 to 0.21.9 (#​10571)
  • 🔨 Regenerate dependabot.yml configuration (#​10563)
  • 🔨 build(deps): bump github.com/tektoncd/pipeline from 1.14.1 to 1.15.0 in /test/custom-task-ctrls/wait-task-beta (#​10558)
  • 🔨 build(deps): bump github.com/sigstore/sigstore/pkg/signature/kms/hashivault from 1.10.8 to 1.10.9 (#​10544)
  • 🔨 build(deps): bump google.golang.org/grpc from 1.82.1 to 1.83.0 (#​10543)
  • 🔨 build(deps): bump github.com/sigstore/sigstore/pkg/signature/kms/aws from 1.10.8 to 1.10.9 (#​10532)
  • 🔨 build(deps): bump github.com/sigstore/sigstore/pkg/signature/kms/gcp from 1.10.8 to 1.10.9 (#​10531)
  • 🔨 build(deps): bump github.com/sigstore/sigstore from 1.10.8 to 1.10.9 (#​10530)
  • 🔨 build(deps): bump github.com/sigstore/sigstore/pkg/signature/kms/azure from 1.10.8 to 1.10.9 (#​10529)
  • 🔨 build(deps): bump github.com/jenkins-x/go-scm from 1.15.31 to 1.15.32 (#​10519)
  • 🔨 build(deps): bump github.com/google/go-containerregistry from 0.21.7 to 0.21.8 (#​10518)
  • 🔨 build(deps): bump github.com/google/cel-go from 0.29.2 to 0.30.0 (#​10517)
  • 🔨 build(deps): bump actions/download-artifact from 4.2.1 to 8.0.1 (#​10507)
  • 🔨 build(deps): bump step-security/harden-runner from 2.19.4 to 2.20.0 (#​10506)
  • 🔨 build(deps): bump actions/checkout from 7.0.0 to 7.0.1 (#​10503)
  • 🔨 build(deps): bump fgrosse/go-coverage-report from 1.3.0 to 1.3.1 (#​10499)
  • 🔨 build(deps): bump github/codeql-action/init from 4.37.0 to 4.37.3 (#​10498)
Docs
  • 📖 docs: clarify set-security-context scope and rollback (#​10680)
  • 📖 docs: include command to apply optional config to run e2e locally in development documentation (#​10553)
  • 📖 docs: add v1.15.0 release to releases.md (#​10510)
Thanks

Thanks to these contributors who contributed to v1.16.0!

Extra shout-out for awesome release notes:

v1.15.3: Tekton Pipeline release v1.15.3 "Toyger Orisa" LTS

Compare Source

Installation one-liner
kubectl apply -f https://infra.tekton.dev/tekton-releases/pipeline/previous/v1.15.3/release.yaml
Attestation

The Rekor UUID for this release is 108e9186e8c5677a1cca30d273b8c9dacc3ecea843087a7743386bf7355ef7a283afd3ed1829b921

Obtain the attestation:

REKOR_UUID=108e9186e8c5677a1cca30d273b8c9dacc3ecea843087a7743386bf7355ef7a283afd3ed1829b921
rekor-cli get --uuid $REKOR_UUID --format json | jq -r .Attestation | jq .

Verify that all container images in the attestation are in the release file:

RELEASE_FILE=https://infra.tekton.dev/tekton-releases/pipeline/previous/v1.15.3/release.yaml
REKOR_UUID=108e9186e8c5677a1cca30d273b8c9dacc3ecea843087a7743386bf7355ef7a283afd3ed1829b921

# Obtains the list of images with sha from the attestation
REKOR_ATTESTATION_IMAGES=$(rekor-cli get --uuid "$REKOR_UUID" --format json | jq -r .Attestation | jq -r '.subject[]|.name + ":v1.15.3@sha256:" + .digest.sha256')

# Download the release file
curl -L "$RELEASE_FILE" > release.yaml

# For each image in the attestation, match it to the release file
for image in $REKOR_ATTESTATION_IMAGES; do
  printf $image; grep -q $image release.yaml && echo " ===> ok" || echo " ===> no match";
done
Changes
Features
Fixes
  • 🐛 [cherry-pick: release-v1.15.x] Allow tt.params as a valid variable-reference prefix (#​10691)

Pipelines can now reference $(tt.params.<name>) in task params, when expressions, and matrix params/includes. This lets a PipelineSpec embedded by Tekton Triggers keep its tt.params.* substitutions without failing pipeline validation.

Misc
  • 🔨 [release-v1.15.x] bump github.com/sigstore/sigstore from 1.10.10 to 1.10.11 in the sigstore group (#​10792)
  • 🔨 [release-v1.15.x] bump the all group in /tekton with 4 updates (#​10787)
  • 🔨 [release-v1.15.x] bump agilepathway/label-checker from 1.6.65 to 1.6.66 (#​10769)
  • 🔨 [release-v1.15.x] bump zizmorcore/zizmor-action from 0.6.3 to 0.6.4 (#​10765)
  • 🔨 [release-v1.15.x] bump the sigstore group with 2 updates (#​10764)
  • 🔨 [release-v1.15.x] bump the all group in /tekton with 6 updates (#​10763)
  • 🔨 [release-v1.15.x] bump github.com/sigstore/sigstore from 1.10.9 to 1.10.10 (#​10755)
  • 🔨 [release-v1.15.x] bump github.com/sigstore/sigstore/pkg/signature/kms/azure from 1.10.9 to 1.10.10 (#​10753)
  • 🔨 [release-v1.15.x] bump github.com/sigstore/sigstore/pkg/signature/kms/gcp from 1.10.9 to 1.10.10 (#​10752)
  • 🔨 [release-v1.15.x] bump chainguard-dev/actions/kind-diag from 1.6.33 to 1.6.35 (#​10738)
  • 🔨 [release-v1.15.x] bump github/codeql-action/analyze from 4.37.7 to 4.37.9 in the codeql-action group across 1 directory (#​10736)
  • 🔨 [release-v1.15.x] bump zizmorcore/zizmor-action from 0.6.2 to 0.6.3 (#​10735)
  • 🔨 [release-v1.15.x] bump chainguard-dev/actions/setup-kind from 1.6.32 to 1.6.35 (#​10732)
  • 🔨 [release-v1.15.x] bump github/codeql-action/upload-sarif from 4.37.7 to 4.37.9 (#​10716)
  • 🔨 [release-v1.15.x] bump github/codeql-action/init from 4.37.7 to 4.37.9 (#​10715)
  • 🔨 [release-v1.15.x] bump github.com/prometheus/client_model from 0.6.2 to 0.6.3 (#​10709)
  • 🔨 [release-v1.15.x] bump chainguard-dev/actions/kind-diag from 1.6.32 to 1.6.33 (#​10706)
  • 🔨 [release-v1.15.x] bump the all group in /tekton with 4 updates (#​10704)
Docs
Thanks

Thanks to these contributors who contributed to v1.15.3!

Extra shout-out for awesome release notes:

v1.15.2: Tekton Pipeline release v1.15.2 "Toyger Orisa" LTS

Compare Source

-Docs @​ v1.15.2
-Examples @​ v1.15.2

Installation one-liner
kubectl apply -f https://infra.tekton.dev/tekton-releases/pipeline/previous/v1.15.2/release.yaml
Attestation

The Rekor UUID for this release is 108e9186e8c5677ad57a83fb64ccefa586efb4446b591b3a2d760972ce02657eb1929896879dbb74

Obtain the attestation:

REKOR_UUID=108e9186e8c5677ad57a83fb64ccefa586efb4446b591b3a2d760972ce02657eb1929896879dbb74
rekor-cli get --uuid $REKOR_UUID --format json | jq -r .Attestation | jq .

Verify that all container images in the attestation are in the release file:

RELEASE_FILE=https://infra.tekton.dev/tekton-releases/pipeline/previous/v1.15.2/release.yaml
REKOR_UUID=108e9186e8c5677ad57a83fb64ccefa586efb4446b591b3a2d760972ce02657eb1929896879dbb74

# Obtains the list of images with sha from the attestation
REKOR_ATTESTATION_IMAGES=$(rekor-cli get --uuid "$REKOR_UUID" --format json | jq -r .Attestation | jq -r '.subject[]|.name + ":v1.15.2@sha256:" + .digest.sha256')

# Download the release file
curl -L "$RELEASE_FILE" > release.yaml

# For each image in the attestation, match it to the release file
for image in $REKOR_ATTESTATION_IMAGES; do
  printf $image; grep -q $image release.yaml && echo " ===> ok" || echo " ===> no match";
done
Changes
Features
Fixes
Misc
  • 🔨 [release-v1.15.x] bump google.golang.org/grpc from 1.82.1 to 1.82.2 (#​10677)
  • 🔨 [release-v1.15.x] bump chainguard-dev/actions/setup-kind from 1.6.31 to 1.6.32 (#​10673)
  • 🔨 [release-v1.15.x] bump chainguard-dev/actions/kind-diag from 1.6.31 to 1.6.32 (#​10670)
  • 🔨 [release-v1.15.x] bump the kubernetes group with 5 updates (#​10656)
  • 🔨 [release-v1.15.x] bump the kubernetes group in /test/custom-task-ctrls/wait-task-beta with 3 updates (#​10654)
  • 🔨 [release-v1.15.x] bump github.com/spiffe/spire-api-sdk from 1.15.2 to 1.15.3 (#​10649)
  • 🔨 [release-v1.15.x] bump github/codeql-action/analyze from 4.37.6 to 4.37.7 (#​10641)
  • 🔨 [release-v1.15.x] bump github/codeql-action/init from 4.37.0 to 4.37.7 (#​10639)
  • 🔨 [release-v1.15.x] bump github/codeql-action/upload-sarif from 4.37.6 to 4.37.7 (#​10637)
  • 🔨 [release-v1.15.x] bump google.golang.org/protobuf from 1.36.12-0.20260120151049-f2248ac996af to 1.36.12 (#​10624)
  • 🔨 [release-v1.15.x] bump chainguard-dev/actions/kind-diag from 1.6.30 to 1.6.31 (#​10621)
  • 🔨 [release-v1.15.x] bump chainguard-dev/actions/setup-kind from 1.6.30 to 1.6.31 (#​10618)
  • 🔨 [release-v1.15.x] bump ossf/scorecard-action from 2.4.3 to 2.4.4 (#​10617)
  • 🔨 [release-v1.15.x] bump github/codeql-action/analyze from 4.37.5 to 4.37.6 (#​10616)
  • 🔨 [release-v1.15.x] bump github/codeql-action/upload-sarif from 4.37.5 to 4.37.6 (#​10603)
  • 🔨 [release-v1.15.x] bump fgrosse/go-coverage-report from 1.3.0 to 1.3.1 (#​10598)
  • 🔨 [release-v1.15.x] bump chainguard-dev/actions/kind-diag from 1.6.27 to 1.6.30 (#​10597)
  • 🔨 [release-v1.15.x] bump github.com/google/go-containerregistry from 0.21.7 to 0.21.9 (#​10587)
  • 🔨 [release-v1.15.x] bump chainguard-dev/actions/setup-kind from 1.6.27 to 1.6.30 (#​10579)
  • 🔨 [release-v1.15.x] bump github/codeql-action/analyze from 4.37.0 to 4.37.5 (#​10574)
  • 🔨 [release-v1.15.x] bump github.com/jenkins-x/go-scm from 1.15.31 to 1.15.36 (#​10572)
  • 🔨 [release-v1.15.x] bump github.com/sigstore/sigstore/pkg/signature/kms/azure from 1.10.8 to 1.10.9 (#​10570)
  • 🔨 [release-v1.15.x] bump github.com/sigstore/sigstore/pkg/signature/kms/gcp from 1.10.8 to 1.10.9 (#​10569)
  • 🔨 [release-v1.15.x] bump zizmorcore/zizmor-action from 0.6.0 to 0.6.2 (#​10567)
  • 🔨 [release-v1.15.x] bump actions/checkout from 7.0.0 to 7.0.1 (#​10566)
Docs
Thanks

Thanks to these contributors who contributed to v1.15.2!

Extra shout-out for awesome release notes:

v1.15.1: Tekton Pipeline release v1.15.1 "Toyger Orisa" LTS

Compare Source

-Docs @​ v1.15.1
-Examples @​ v1.15.1

Installation one-liner
kubectl apply -f https://infra.tekton.dev/tekton-releases/pipeline/previous/v1.15.1/release.yaml
Attestation

The Rekor UUID for this release is 108e9186e8c5677a210b81c75be73c2949e8e917e1776229b8bb68bc95b532e51d8f2bf29219a9c1

Obtain the attestation:

REKOR_UUID=108e9186e8c5677a210b81c75be73c2949e8e917e1776229b8bb68bc95b532e51d8f2bf29219a9c1
rekor-cli get --uuid $REKOR_UUID --format json | jq -r .Attestation | jq .

Verify that all container images in the attestation are in the release file:

RELEASE_FILE=https://infra.tekton.dev/tekton-releases/pipeline/previous/v1.15.1/release.yaml
REKOR_UUID=108e9186e8c5677a210b81c75be73c2949e8e917e1776229b8bb68bc95b532e51d8f2bf29219a9c1

# Obtains the list of images with sha from the attestation
REKOR_ATTESTATION_IMAGES=$(rekor-cli get --uuid "$REKOR_UUID" --format json | jq -r .Attestation | jq -r '.subject[]|.name + ":v1.15.1@sha256:" + .digest.sha256')

# Download the release file
curl -L "$RELEASE_FILE" > release.yaml

# For each image in the attestation, match it to the release file
for image in $REKOR_ATTESTATION_IMAGES; do
  printf $image; grep -q $image release.yaml && echo " ===> ok" || echo " ===> no match";
done
Changes
Features
Fixes
Misc
  • 🔨 [release-v1.15.x] bump github.com/sigstore/sigstore/pkg/signature/kms/hashivault from 1.10.8 to 1.10.9 (#​10586)
  • 🔨 [release-v1.15.x] bump github/codeql-action/upload-sarif from 4.37.1 to 4.37.5 (#​10577)
  • 🔨 [release-v1.15.x] bump github.com/sigstore/sigstore from 1.10.8 to 1.10.9 (#​10573)
  • 🔨 [release-v1.15.x] bump github.com/sigstore/sigstore/pkg/signature/kms/aws from 1.10.8 to 1.10.9 (#​10568)
Docs
Thanks

Thanks to these contributors who contributed to v1.15.1!

Extra shout-out for awesome release notes:

v1.15.0: Tekton Pipeline release v1.15.0 "Toyger Orisa" LTS

Compare Source

🎉 Steady under pressure — configurable backoffs and battle-tested fixes 🎉

-Docs @​ v1.15.0
-Examples @​ v1.15.0

Installation one-liner
kubectl apply -f https://infra.tekton.dev/tekton-releases/pipeline/previous/v1.15.0/release.yaml
Attestation

The Rekor UUID for this release is 108e9186e8c5677a045c87c57225dfff98b32437f52b89e344c449bcd535b462d41fff9004b89d29

Obtain the attestation:

REKOR_UUID=108e9186e8c5677a045c87c57225dfff98b32437f52b89e344c449bcd535b462d41fff9004b89d29
rekor-cli get --uuid $REKOR_UUID --format json | jq -r .Attestation | jq .

Verify that all container images in the attestation are in the release file:

RELEASE_FILE=https://infra.tekton.dev/tekton-releases/pipeline/previous/v1.15.0/release.yaml
REKOR_UUID=108e9186e8c5677a045c87c57225dfff98b32437f52b89e344c449bcd535b462d41fff9004b89d29

# Obtains the list of images with sha from the attestation
REKOR_ATTESTATION_IMAGES=$(rekor-cli get --uuid "$REKOR_UUID" --format json | jq -r .Attestation | jq -r '.subject[]|.name + ":v1.15.0@sha256:" + .digest.sha256')

# Download the release file
curl -L "$RELEASE_FILE" > release.yaml

# For each image in the attestation, match it to the release file
for image in $REKOR_ATTESTATION_IMAGES; do
  printf $image; grep -q $image release.yaml && echo " ===> ok" || echo " ===> no match";
done
Changes
Features
  • ✨ Add configuration for custom git resolver backoff (#​10422)

Enables the configuration of backoffs for git resolver requests.

  • ✨ feat: add configurable grace period for transient CreateContainerError (#​10326)

Add default-create-container-error-timeout configuration option in config-defaults to provide a grace period before failing TaskRuns on transient CreateContainerError/CreateContainerConfigError with "context deadline exceeded". Default is 0 (fail fast, preserving existing behavior)

Fixes
  • 🐛 fix(resolutionrequest): preserve resolver-written status fields (#​10487)

Prevent ResolutionRequest lifecycle updates from overwriting resolver-written status fields.

  • 🐛 fix(resolvers): honor leader-election bucket ownership (#​10480)

Fix resolver replicas processing ResolutionRequests outside their leader-election bucket.

  • 🐛 Prevent matrix combination count int overflow (#​10431)

Fixed an integer overflow in matrix combination counting that could let a very
large matrix bypass the max-matrix-combinations validation guard.

  • 🐛 Fix PipelineRun stuck in ResolvingTaskRef when ResolutionRequest enqueue is missed (#​10429)

Fix PipelineRun remaining stuck in ResolvingTaskRef when a ResolutionRequest completion event is missed by periodically requeueing while remote resolution is in progress

  • 🐛 Fix RestrictLength panic on all-symbol input (#​10421)

Fixed a panic in the PipelineRun controller when a PipelineRun using an embedded (anonymous) pipeline spec sets a generateName that contains no alphanumeric characters (for example --). Such names no longer crash the reconciler.

  • 🐛 Fix sidecar-logs result extraction for results exceeding 4096 bytes (#​10403)

Fix sidecar-logs result extraction dropping all TaskRun results when a single result's JSON exceeds 4096 bytes but is within the configured max-result-size. Regression since v1.9.0.

  • 🐛 Preserve Sidecar RestartPolicy on API conversion (#​10392)

Fixed a bug where a Sidecar's restartPolicy (native Kubernetes sidecar support)
was dropped when converting a Task or TaskRun between the v1beta1 and v1 API
versions, causing a sidecar requested as a native sidecar to be created as an
ordinary sidecar.

  • 🐛 Mount debug scripts read-only in step containers (#​10362)

Debug breakpoint scripts are now mounted read-only in step containers, so a step can no longer overwrite them before a user execs in to continue or fail a breakpoint.

  • 🐛 fix(nightlies): restart webhook after CEL feature-flag patch (#​10475)
  • 🐛 fix(deps): bump OTel SDK with knative.dev/pkg semconv alignment (#​10447)
  • 🐛 fix(nightlies): skip draft-release tasks when releaseMode=nightly (#​10441)
  • 🐛 Fix broken object param example links in API spec (#​10397)
  • 🐛 fix: resolve in-toto attestation UUID in wait-for-chains (#​10363)
Misc
  • 🔨 fix(release): copy vendor tarball into kodata instead of symlink (#​10418)

Fix release pipeline ko resolve failure caused by ko >= v0.19.0 rejecting
the kodata/source.tar.gz symlink used to bundle vendored source.

  • 🔨 Add branch prefix to Dependabot PR titles for release branches (#​10405)
  • 🔨 Fix wrong Deprecated godoc in affinity assistant (#​10391)
  • 🔨 build(deps): bump github.com/prometheus/common from 0.70.0 to 0.70.1 (#​10470)
  • 🔨 build(deps): bump the kubernetes group with 5 updates (#​10469)
  • 🔨 build(deps): bump the kubernetes group across 1 directory with 3 updates (#​10468)
  • 🔨 build(deps): bump github/codeql-action/upload-sarif from 4.37.0 to 4.37.1 (#​10462)
  • 🔨 build(deps): bump github.com/tektoncd/pipeline from 1.14.0 to 1.14.1 in /test/custom-task-ctrls/wait-task-beta (#​10461)
  • 🔨 build(deps): bump actions/setup-go from 6.5.0 to 7.0.0 (#​10456)
  • 🔨 build(deps): bump chainguard-dev/actions/setup-kind from 1.6.26 to 1.6.27 (#​10455)
  • 🔨 build(deps): bump chainguard-dev/actions/kind-diag from 1.6.26 to 1.6.27 (#​10454)
  • 🔨 build(deps): bump zizmorcore/zizmor-action from 0.5.7 to 0.6.0 (#​10453)
  • 🔨 Ignore otel major/minor updates in dependabot (#​10450)
  • 🔨 build(deps): bump google.golang.org/grpc from 1.82.0 to 1.82.1 (#​10446)
  • 🔨 ci(.github/workflows): enable Codecov coverage reporting (#​10440)
  • 🔨 build(deps): bump github.com/prometheus/common from 0.69.0 to 0.70.0 (#​10439)
  • 🔨 build(deps): bump github/codeql-action/upload-sarif from 4.36.3 to 4.37.0 (#​10437)
  • 🔨 build(deps): bump github/codeql-action/analyze from 4.36.3 to 4.37.0 (#​10436)
  • 🔨 build(deps): bump github/codeql-action/init from 4.36.3 to 4.37.0 (#​10435)
  • 🔨 build(deps): bump step-security/harden-runner from 2.19.4 to 2.20.0 (#​10434)
  • 🔨 build(deps): bump github.com/spiffe/spire-api-sdk from 1.15.1 to 1.15.2 (#​10433)
  • 🔨 build(deps): bump golang.org/x/crypto from 0.53.0 to 0.54.0 (#​10432)
  • 🔨 build(deps): bump github.com/google/cel-go from 0.29.1 to 0.29.2 (#​10423)
  • 🔨 build(deps): bump chainguard-dev/actions/kind-diag from 1.6.25 to 1.6.26 (#​10417)
  • 🔨 build(deps): bump ko-build/setup-ko from 0.9 to 0.10 (#​10416)
  • 🔨 build(deps): bump github.com/google/cel-go from 0.29.0 to 0.29.1 (#​10415)
  • 🔨 build(deps): bump github/codeql-action/init from 4.36.2 to 4.36.3 (#​10413)
  • 🔨 build(deps): bump github/codeql-action/analyze from 4.36.2 to 4.36.3 (#​10412)
  • 🔨 build(deps): bump golangci/golangci-lint-action from 9.2.1 to 9.3.0 (#​10411)
  • 🔨 build(deps): bump github/codeql-action/upload-sarif from 4.36.2 to 4.36.3 (#​10410)
  • 🔨 build(deps): bump github.com/google/cel-go from 0.28.1 to 0.29.0 (#​10407)
  • 🔨 build(deps): bump chainguard-dev/actions/setup-kind from 1.6.25 to 1.6.26 (#​10406)
  • 🔨 build(deps): bump golang.org/x/sync from 0.21.0 to 0.22.0 (#​10404)
  • :ha

❗ Important

✂ PR body was truncated to here.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • Between 12:00 AM and 03:59 AM (* 0-3 * * *)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate

renovate Bot commented Sep 11, 2026 •

Copy link
Copy Markdown
Contributor Author

ℹ️ Artifact update notice

File name: acceptance/go.mod

In order to perform the update(s) described in the table above, Renovate ran the go get command, which resulted in the following additional change(s):

  • 33 additional dependencies were updated
  • The go directive was updated for compatibility reasons

Due to Go's usage of Minimal Version Selection (MVS), these packages have been updated to the minimum version available, so will still abide by minimumReleaseAge=5 days

Details:

Package Change
go 1.26.7 -> 1.27.0
github.com/google/go-containerregistry v0.21.7 -> v0.22.1
github.com/secure-systems-lab/go-securesystemslib v0.11.0 -> v0.11.1
github.com/sigstore/sigstore v1.10.8 -> v1.11.0
k8s.io/apimachinery v0.36.0 -> v0.37.1
github.com/coreos/go-oidc/v3 v3.19.0 -> v3.20.0
github.com/fxamacker/cbor/v2 v2.9.0 -> v2.9.1
github.com/go-jose/go-jose/v4 v4.1.4 -> v4.1.5
github.com/go-openapi/jsonpointer v0.23.1 -> v1.0.0
github.com/go-openapi/jsonreference v0.21.6 -> v1.0.0
github.com/go-openapi/swag v0.26.1 -> v0.27.1
github.com/go-openapi/swag/cmdutils v0.26.1 -> v0.27.1
github.com/go-openapi/swag/conv v0.27.0 -> v0.27.1
github.com/go-openapi/swag/fileutils v0.26.1 -> v0.27.1
github.com/go-openapi/swag/jsonutils v0.26.1 -> v0.27.1
github.com/go-openapi/swag/loading v0.26.1 -> v0.27.1
github.com/go-openapi/swag/mangling v0.26.1 -> v0.27.1
github.com/go-openapi/swag/netutils v0.26.1 -> v0.27.1
github.com/go-openapi/swag/stringutils v0.26.1 -> v0.27.1
github.com/go-openapi/swag/typeutils v0.27.0 -> v0.27.1
github.com/go-openapi/swag/yamlutils v0.26.1 -> v0.27.1
github.com/goccy/go-yaml v1.18.0 -> v1.19.2
github.com/prometheus/client_model v0.6.2 -> v0.6.3
github.com/prometheus/common v0.70.1 -> v0.71.0
github.com/sigstore/protobuf-specs v0.5.1 -> v0.5.2
github.com/sirupsen/logrus v1.10.1 -> v1.10.2
go.opentelemetry.io/otel/exporters/stdout/stdouttrace v1.43.0 -> v1.44.0
golang.org/x/oauth2 v0.36.0 -> v0.37.0
google.golang.org/genproto/googleapis/rpc v0.0.0-20260803160001-6ac0973c030d -> v0.0.0-20260819154853-08b0e4226688
google.golang.org/grpc v1.83.2 -> v1.84.0
k8s.io/apiextensions-apiserver v0.35.4 -> v0.35.9
k8s.io/kube-openapi v0.0.0-20260319004828-5883c5ee87b9 -> v0.0.0-20260821135717-be32def86098
k8s.io/utils v0.0.0-20260319190234-28399d86e0b5 -> v0.0.0-20260626114624-be93311217bd
sigs.k8s.io/structured-merge-diff/v6 v6.3.2 -> v6.4.2
File name: go.mod

In order to perform the update(s) described in the table above, Renovate ran the go get command, which resulted in the following additional change(s):

  • 58 additional dependencies were updated
  • The go directive was updated for compatibility reasons

Due to Go's usage of Minimal Version Selection (MVS), these packages have been updated to the minimum version available, so will still abide by minimumReleaseAge=5 days

Details:

Package Change
go 1.26.7 -> 1.27.0
github.com/google/go-containerregistry v0.21.7 -> v0.22.1
github.com/secure-systems-lab/go-securesystemslib v0.11.0 -> v0.11.1
github.com/sigstore/sigstore v1.10.8 -> v1.11.0
github.com/sirupsen/logrus v1.10.1 -> v1.10.2
k8s.io/apiextensions-apiserver v0.35.4 -> v0.35.9
k8s.io/apimachinery v0.36.3 -> v0.37.1
k8s.io/kube-openapi v0.0.0-20260319004828-5883c5ee87b9 -> v0.0.0-20260821135717-be32def86098
cloud.google.com/go/auth v0.20.0 -> v0.23.2
cloud.google.com/go/iam v1.11.0 -> v1.12.0
cloud.google.com/go/monitoring v1.25.0 -> v1.30.0
github.com/GoogleCloudPlatform/opentelemetry-operations-go/detectors/gcp v1.33.0 -> v1.34.0
github.com/aws/aws-sdk-go-v2 v1.43.8 -> v1.46.0
github.com/aws/aws-sdk-go-v2/config v1.32.39 -> v1.33.3
github.com/aws/aws-sdk-go-v2/credentials v1.19.38 -> v1.20.3
github.com/aws/aws-sdk-go-v2/feature/ec2/imds v1.18.39 -> v1.19.2
github.com/aws/aws-sdk-go-v2/internal/configsources v1.4.39 -> v1.5.2
github.com/aws/aws-sdk-go-v2/internal/endpoints/v2 v2.7.39 -> v2.8.2
github.com/aws/aws-sdk-go-v2/internal/v4a v1.4.40 -> v1.5.2
github.com/aws/aws-sdk-go-v2/service/internal/accept-encoding v1.13.18 -> v1.13.19
github.com/aws/aws-sdk-go-v2/service/internal/presigned-url v1.13.39 -> v1.14.2
github.com/aws/aws-sdk-go-v2/service/signin v1.5.8 -> v1.9.0
github.com/aws/aws-sdk-go-v2/service/sso v1.33.8 -> v1.37.0
github.com/aws/aws-sdk-go-v2/service/ssooidc v1.38.8 -> v1.42.0
github.com/aws/aws-sdk-go-v2/service/sts v1.45.8 -> v1.49.0
github.com/aws/smithy-go v1.27.10 -> v1.28.1
github.com/coreos/go-oidc/v3 v3.19.0 -> v3.20.0
github.com/fxamacker/cbor/v2 v2.9.0 -> v2.9.1
github.com/go-jose/go-jose/v4 v4.1.4 -> v4.1.5
github.com/go-openapi/jsonpointer v0.23.1 -> v1.0.0
github.com/go-openapi/jsonreference v0.21.6 -> v1.0.0
github.com/go-openapi/swag v0.26.1 -> v0.27.1
github.com/go-openapi/swag/cmdutils v0.26.1 -> v0.27.1
github.com/go-openapi/swag/conv v0.27.0 -> v0.27.1
github.com/go-openapi/swag/fileutils v0.26.1 -> v0.27.1
github.com/go-openapi/swag/jsonutils v0.26.1 -> v0.27.1
github.com/go-openapi/swag/loading v0.26.1 -> v0.27.1
github.com/go-openapi/swag/mangling v0.26.1 -> v0.27.1
github.com/go-openapi/swag/netutils v0.26.1 -> v0.27.1
github.com/go-openapi/swag/stringutils v0.26.1 -> v0.27.1
github.com/go-openapi/swag/typeutils v0.27.0 -> v0.27.1
github.com/go-openapi/swag/yamlutils v0.26.1 -> v0.27.1
github.com/goccy/go-yaml v1.18.0 -> v1.19.2
github.com/golang/snappy v0.0.4 -> v1.0.0
github.com/googleapis/enterprise-certificate-proxy v0.3.16 -> v0.3.20
github.com/googleapis/gax-go/v2 v2.22.0 -> v2.24.0
github.com/prometheus/client_model v0.6.2 -> v0.6.3
github.com/prometheus/common v0.70.1 -> v0.71.0
github.com/sigstore/protobuf-specs v0.5.1 -> v0.5.2
github.com/spiffe/go-spiffe/v2 v2.7.0 -> v2.8.2
go.opentelemetry.io/otel/exporters/stdout/stdouttrace v1.42.0 -> v1.44.0
golang.org/x/oauth2 v0.36.0 -> v0.37.0
google.golang.org/api v0.286.0 -> v0.295.0
google.golang.org/genproto v0.0.0-20260406210006-6f92a3bedf2d -> v0.0.0-20260715232425-e75dac1f907d
google.golang.org/genproto/googleapis/rpc v0.0.0-20260803160001-6ac0973c030d -> v0.0.0-20260819154853-08b0e4226688
google.golang.org/grpc v1.83.2 -> v1.84.0
k8s.io/utils v0.0.0-20260319190234-28399d86e0b5 -> v0.0.0-20260626114624-be93311217bd
knative.dev/pkg v0.0.0-20260318013857-98d5a706d4fd -> v0.0.0-20260622140654-39ebae2ee2dc
sigs.k8s.io/structured-merge-diff/v6 v6.3.3 -> v6.4.2

@coderabbitai

coderabbitai Bot commented Sep 11, 2026 •

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: c690a7fe-5a41-4521-b03b-b1f5c446e18b

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Comment @coderabbitai help to get the list of available commands.

@fullsend-ai-review

fullsend-ai-review Bot commented Sep 11, 2026 •

Copy link
Copy Markdown

🤖 Finished Review · ✅ Success · Started 3:05 AM UTC · Completed 3:11 AM UTC

Commit: cd01138 · View workflow run →

Runtime: claude · Model: opus → claude-opus-4-7 · Effort: high · Cost: $3.74

@fullsend-ai-review

fullsend-ai-review Bot commented Sep 11, 2026 •

Copy link
Copy Markdown

Looks good to me

Previous run

Looks good to me

Previous run (2)

Looks good to me

Previous run (3)

Looks good to me

Previous run (4)

Review

Renovate PR bumping github.com/tektoncd/pipeline v1.12.0 → v1.16.0 in the release-v0.7 branch, along with matched patch bumps of sigstore/sigstore, google/go-containerregistry, k8s.io/apimachinery, k8s.io/apiextensions-apiserver, and various transitive dependencies. Changes are confined to go.mod / go.sum in both the root and acceptance modules.

Findings

Info

  • [scope-authorization-implicit] N/A — Authorization inferred from the mechanical nature of the change (Renovate-generated dependency version bumps confined to go.mod/go.sum lockfile equivalents). No architectural review required.
  • [correctness-verified] go.mod — Traced the repo's tektoncd/pipeline consumption to three call sites: internal/tracker/client.go (oci.NewResolver().Get()), internal/tracker/bundle_info.go (oci.KindAnnotation constant), and internal/documentation/asciidoc/tekton/tekton.go (v1.Task struct type). All are stable API surfaces across v1.12–v1.16. The v1.16 set-security-context default flip is a reconciler-only behavior change and does not affect this CLI consumer.
  • [dependency-hygiene] go.mod — sigstore/sigstore v1.10.8 → v1.10.9 with matched KMS provider modules (aws/azure/gcp/hashivault) is a routine patch bump on the signing/verification stack. coreos/go-oidc v3.19.0 → v3.20.0, spiffe/go-spiffe/v2 v2.7.0 → v2.8.1, hashicorp/vault/api v1.22.0 → v1.23.0, tink-crypto/tink-go/v2 v2.6.0 → v2.7.0, and google/cel-go v0.28.0 → v0.31.0 are all minor bumps on canonical upstream module paths. No typosquats or unexpected module additions detected. Removed indirect deps in acceptance/go.mod (letsencrypt/boulder, titanous/rocacheck, jmhodges/clock) reduce attack surface.
  • [scope-vs-branch-policy] go.mod — Base branch release-v0.7 is a maintenance branch, yet the primary bump tektoncd/pipeline v1.12.0 → v1.16.0 crosses four minor versions. This is worth confirming aligns with the project's backport / maintenance policy for release-v0.7 (e.g., intentional catch-up vs. Renovate config being applied uniformly across branches). Not a defect in the PR itself — a policy question for maintainers.

fullsend-ai-review[bot]

This comment was marked as outdated.

@fullsend-ai-review fullsend-ai-review Bot added the ready-for-merge All reviewers approved — ready to merge label Sep 11, 2026
@codecov

codecov Bot commented Sep 11, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.

Flag Coverage Δ
generative 69.55% <ø> (ø)
integration 69.55% <ø> (ø)
unit 69.55% <ø> (ø)

Flags with carried forward coverage won't be shown. Click here to find out more.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@renovate
renovate Bot force-pushed the renovate/release-v0.7-tektoncd-pipelines branch from 0f8f27c to 11a6ae7 Compare September 11, 2026 15:18
@fullsend-ai-review

fullsend-ai-review Bot commented Sep 11, 2026 •

Copy link
Copy Markdown

🤖 Finished Review · ✅ Success · Started 3:19 PM UTC · Completed 3:26 PM UTC

Commit: cd01138 · View workflow run →

Runtime: claude · Model: opus → claude-opus-4-7 · Effort: high · Cost: $4.20

fullsend-ai-review[bot]

This comment was marked as outdated.

@renovate
renovate Bot force-pushed the renovate/release-v0.7-tektoncd-pipelines branch from 11a6ae7 to 56304af Compare September 15, 2026 19:35
@fullsend-ai-review

fullsend-ai-review Bot commented Sep 15, 2026 •

Copy link
Copy Markdown

🤖 Finished Review · ✅ Success · Started 7:36 PM UTC · Completed 7:44 PM UTC

Commit: e8f0a9f · View workflow run →

Runtime: claude · Model: opus → claude-opus-4-7 · Effort: high · Cost: $3.76

@fullsend-ai-review fullsend-ai-review Bot added the risk/moderate PR risk: moderate label Sep 15, 2026
@fullsend-ai-review

fullsend-ai-review Bot commented Sep 15, 2026 •

Copy link
Copy Markdown

Risk Assessment: moderate (2/5)

Details

Bot-authored Renovate PR updating Tekton pipeline go.mod/go.sum across 4 dependency files; medium blast radius and 4 dependency files drive score to moderate, while bot authorship and absence of protected paths or security-sensitive changes keep it from elevating further.

Previous run

Risk Assessment: moderate (2/5)

Details

Bot-authored routine dependency update touching only go.mod/go.sum files across main and acceptance modules; sole elevated signal is >=2 dependency files changed, offset by bot authorship, no protected paths, and no security-sensitive changes, yielding a moderate composite.

Previous run (2)

Risk Assessment: moderate (2/5)

Details

Renovate bot dependency-only bump (4 Go module manifests, 292 lines) with no protected paths, security-sensitive files, or CI changes; multi-file dependency updates and moderately elevated recent churn on go.mod/go.sum push the score above baseline into moderate.

fullsend-ai-review[bot]

This comment was marked as outdated.

@renovate
renovate Bot force-pushed the renovate/release-v0.7-tektoncd-pipelines branch from 56304af to 750db29 Compare September 22, 2026 14:55
fullsend-ai-review[bot]

This comment was marked as outdated.

@renovate
renovate Bot force-pushed the renovate/release-v0.7-tektoncd-pipelines branch from 750db29 to 813e005 Compare September 28, 2026 13:31
@fullsend-ai-review

fullsend-ai-review Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

🤖 Finished Review · ✅ Success · Started 1:33 PM UTC · Completed 1:39 PM UTC

Commit: 813e005 · View workflow run →

Runtime: claude · Model: opus → claude-opus-4-7 · Effort: high · Cost: $2.23

@fullsend-ai-review
fullsend-ai-review Bot dismissed stale reviews from themself September 28, 2026 13:39

Superseded by updated review

@renovate
renovate Bot force-pushed the renovate/release-v0.7-tektoncd-pipelines branch from 813e005 to 9f4930c Compare October 6, 2026 10:31
@renovate renovate Bot changed the title Update module github.com/tektoncd/pipeline to v1.16.0 (release-v0.7) Update module github.com/tektoncd/pipeline to v1.17.0 (release-v0.7) Oct 6, 2026
@fullsend-ai-review

fullsend-ai-review Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

🤖 Finished Review · ❌ Failure (ensuring provider "github-ro": provider create "github-ro" failed: exit status 1 (output: Error: × provider profile 'fullsend-github-ro' not found; import a matching profile │ before using this provid…) · Started 10:33 AM UTC · Completed 10:33 AM UTC

Commit: 9f4930c · View workflow run →

Effort: high

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

ready-for-merge All reviewers approved — ready to merge release-v0.7 renovate risk/moderate PR risk: moderate size: XXL

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants