Skip to content

chains

v0.27.4 Maintenance

This release keeps dependencies and maintenance posture current for teams operating this tool.

Published 9d Pipelines
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →

✓ No known CVEs patched in this version

ReleasePort's take

Moderate signal
editorial:auto 9d

Tekton Chains v0.27.4 resolves CVE-2026-48702.

Why it matters: CVE severity is high (90); patch immediately to mitigate risk.

Summary

AI summary

Minor fixes and improvements.

Changes in this release

Security Critical

Fixes CVE-2026-48702 vulnerability.

Fixes CVE-2026-48702 vulnerability.

Source: llm_adapter@2026-07-17

Confidence: high

Full changelog

Tekton Chains release v0.27.4 "Release v0.27.4"

-Docs @ v0.27.4
-Examples @ v0.27.4

Installation one-liner

kubectl apply -f https://infra.tekton.dev/tekton-releases/chains/previous/v0.27.4/release.yaml

Attestation

The Rekor UUID for this release is 108e9186e8c5677a52dd0e301f02cab5288b6398948c404712fe81a9ae0cfa05e6fa338eddcb9697

Obtain the attestation:

REKOR_UUID=108e9186e8c5677a52dd0e301f02cab5288b6398948c404712fe81a9ae0cfa05e6fa338eddcb9697
rekor-cli get --uuid $REKOR_UUID --format json | jq -r .Attestation | jq .

Verify that all container images in the attestation are in the release file:

RELEASE_FILE=https://infra.tekton.dev/tekton-releases/chains/previous/v0.27.4/release.yaml
REKOR_UUID=108e9186e8c5677a52dd0e301f02cab5288b6398948c404712fe81a9ae0cfa05e6fa338eddcb9697

# Obtains the list of images with sha from the attestation
REKOR_ATTESTATION_IMAGES=$(rekor-cli get --uuid "$REKOR_UUID" --format json | jq -r .Attestation | jq -r '.subject[]|.name + ":v0.27.4@sha256:" + .digest.sha256')

# Download the release file
curl -L "$RELEASE_FILE" > release.yaml

# For each image in the attestation, match it to the release file
for image in $REKOR_ATTESTATION_IMAGES; do
  printf $image; grep -q $image release.yaml && echo " ===> ok" || echo " ===> no match";
done

Changes

Features

Fixes

Misc

Docs

Thanks

Thanks to these contributors who contributed to v0.27.4!

  • :heart: @ngelman1

Extra shout-out for awesome release notes:

  • :heart_eyes: @ngelman1

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track chains

Get notified when new releases ship.

Sign up free

About chains

Supply Chain Security in Tekton Pipelines

All releases →

Related context

Related CVEs

Beta — feedback welcome: [email protected]