Skip to content

pipeline

v1.9.6 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

Published 18d Pipelines
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Topics

cdf kubernetes pipeline tekton

Affected surfaces

deps

Summary

AI summary

Bump Go, golang.org/x/crypto, and golang.org/x/net to remediate CVEs.

Full changelog

-Docs @ v1.9.6
-Examples @ v1.9.6

Installation one-liner

kubectl apply -f https://infra.tekton.dev/tekton-releases/pipeline/previous/v1.9.6/release.yaml

Attestation

The Rekor UUID for this release is 108e9186e8c5677acf3e338c239faf5a2afc67e49eec5d5d5166654363563c81b57d51d4bd910d27

Obtain the attestation:

REKOR_UUID=108e9186e8c5677acf3e338c239faf5a2afc67e49eec5d5d5166654363563c81b57d51d4bd910d27
rekor-cli get --uuid $REKOR_UUID --format json | jq -r .Attestation | jq .

Verify that all container images in the attestation are in the release file:

RELEASE_FILE=https://infra.tekton.dev/tekton-releases/pipeline/previous/v1.9.6/release.yaml
REKOR_UUID=108e9186e8c5677acf3e338c239faf5a2afc67e49eec5d5d5166654363563c81b57d51d4bd910d27

# Obtains the list of images with sha from the attestation
REKOR_ATTESTATION_IMAGES=$(rekor-cli get --uuid "$REKOR_UUID" --format json | jq -r .Attestation | jq -r '.subject[]|.name + ":v1.9.6@sha256:" + .digest.sha256')

# Download the release file
curl -L "$RELEASE_FILE" > release.yaml

# For each image in the attestation, match it to the release file
for image in $REKOR_ATTESTATION_IMAGES; do
  printf $image; grep -q $image release.yaml && echo " ===> ok" || echo " ===> no match";
done

Changes

Features

Fixes

  • :bug: [release-v1.9.x] fix: bump Go and x deps for CVEs (#10337)

Bump Go to 1.25.10, golang.org/x/crypto to v0.52.0, and golang.org/x/net to v0.55.0 for CVE remediation.

Misc

  • :hammer: [cherry-pick: release-v1.9.x] fix: replace kodata LICENSE symlinks with actual files (#10388)

Docs

Thanks

Thanks to these contributors who contributed to v1.9.6!

  • :heart: @tekton-robot
  • :heart: @waveywaves

Extra shout-out for awesome release notes:

  • :heart_eyes: @waveywaves

Security Fixes

  • Bump Go to 1.25.10, golang.org/x/crypto to v0.52.0, and golang.org/x/net to v0.55.0 for CVE remediation.

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track pipeline

Get notified when new releases ship.

Sign up free

About pipeline

A cloud-native Pipeline resource.

All releases →

Related context

Earlier breaking changes

  • v1.13.1 Tekton no longer applies default resource requests or limits to internal containers when `default-container-resource-requirements` is unset.
  • v1.9.4 Tekton Resolvers now only resolve StepActions, Tasks, and Pipelines; custom resolvers for other types will fail.
  • v1.6.3 Restrict Tekton Resolvers to resolve only StepActions, Tasks, and Pipelines; custom resolvers for other types now fail.

Beta — feedback welcome: [email protected]