✓ No known CVEs patched
✓ No known CVEs patched in this version
Topics
cdf
kubernetes
pipeline
tekton
Affected surfaces
deps
Summary
AI summaryMinor fixes and improvements.
Full changelog
-Docs @ v1.6.4
-Examples @ v1.6.4
Installation one-liner
kubectl apply -f https://infra.tekton.dev/tekton-releases/pipeline/previous/v1.6.4/release.yaml
Attestation
The Rekor UUID for this release is 108e9186e8c5677acb83d45b8aa456f143d85612fab55c350630e7c858ecf3a3ec4b61343464a5b3
Obtain the attestation:
REKOR_UUID=108e9186e8c5677acb83d45b8aa456f143d85612fab55c350630e7c858ecf3a3ec4b61343464a5b3
rekor-cli get --uuid $REKOR_UUID --format json | jq -r .Attestation | jq .
Verify that all container images in the attestation are in the release file:
RELEASE_FILE=https://infra.tekton.dev/tekton-releases/pipeline/previous/v1.6.4/release.yaml
REKOR_UUID=108e9186e8c5677acb83d45b8aa456f143d85612fab55c350630e7c858ecf3a3ec4b61343464a5b3
# Obtains the list of images with sha from the attestation
REKOR_ATTESTATION_IMAGES=$(rekor-cli get --uuid "$REKOR_UUID" --format json | jq -r .Attestation | jq -r '.subject[]|.name + ":v1.6.4@sha256:" + .digest.sha256')
# Download the release file
curl -L "$RELEASE_FILE" > release.yaml
# For each image in the attestation, match it to the release file
for image in $REKOR_ATTESTATION_IMAGES; do
printf $image; grep -q $image release.yaml && echo " ===> ok" || echo " ===> no match";
done
Changes
Features
Fixes
Misc
- :hammer: build: bump go directive to 1.25 (#10028)
- :hammer: build(deps): bump the all group across 1 directory with 4 updates (#10311)
- :hammer: build(deps): bump github.com/google/go-containerregistry from 0.20.6 to 0.20.8 (#9875)
Docs
Thanks
Thanks to these contributors who contributed to v1.6.4!
- :heart: @app/dependabot
- :heart: @vdemeester
Extra shout-out for awesome release notes:
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Related context
Related tools
Earlier breaking changes
- v1.13.1 Tekton no longer applies default resource requests or limits to internal containers when `default-container-resource-requirements` is unset.
- v1.9.4 Tekton Resolvers now only resolve StepActions, Tasks, and Pipelines; custom resolvers for other types will fail.
- v1.6.3 Restrict Tekton Resolvers to resolve only StepActions, Tasks, and Pipelines; custom resolvers for other types now fail.
Beta — feedback welcome: [email protected]