Commit Graph
604 Commits
Author SHA1 Message Date
Zack BradyandGitHub b9069d57c6 added audit log functionality (#632)
Signed-off-by: Zack Brady <zackbrady123@gmail.com>
2026-07-10 13:52:24 -04:00
9d04bbdd64 bump helm.sh/helm/v4 from 4.2.2 to 4.2.3 (#661)
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-10 08:41:10 -04:00
c38ba852b3 bump github.com/containerd/containerd from 1.7.33 to 1.7.34 (#659)
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-10 08:40:35 -04:00
f1dad651db bump golang.org/x/sync from 0.21.0 to 0.22.0 (#650)
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-09 01:49:06 -04:00
d93167185f feat: extend charts resource with helm values (#644)
Signed-off-by: Eric Klatzer <eric@klatzer.at>
Co-authored-by: Zack Brady <zackbrady123@gmail.com>
2026-07-08 13:24:01 -04:00
Adam MartinandGitHub cbf07f07d9 updates for helm v4 (#648)
Signed-off-by: Adam Martin <adam.martin@ranchergovernment.com>
2026-07-04 14:11:03 -04:00
Zack BradyandGitHub 32c30ac28a unpinned distribution/distribution dependency (#647) 2026-07-04 09:31:47 -04:00
Adam MartinandGitHub d912cfa85f digest only regression fix (#643)
Signed-off-by: Adam Martin <adam.martin@ranchergovernment.com>
2026-06-26 09:55:51 -04:00
Adam MartinandGitHub 7d00a53c94 add trivy to make and add new vuln GHA (#641)
Signed-off-by: Adam Martin <adam.martin@ranchergovernment.com>
2026-06-24 09:53:23 -04:00
Adam MartinandGitHub 4f47155d6f bump go to 1.26.4 to squash CVE noise (#640)
Signed-off-by: Adam Martin <adam.martin@ranchergovernment.com>
v2.0.1
2026-06-23 11:58:40 -04:00
Zack BradyandGitHub 2bcc74450f removed experimental warnings from a few flags (#638) v2.0.0 2026-06-22 17:11:15 -04:00
Adam MartinandGitHub ec5082df18 add v2 to module path to correct version (#637)
Signed-off-by: Adam Martin <adam.martin@ranchergovernment.com>
2026-06-22 16:40:31 -04:00
905b3e4932 fix: image detection regex to allow hyphen in image property (#604)
Signed-off-by: Eric Klatzer <eric@klatzer.at>
Co-authored-by: Zack Brady <zackbrady123@gmail.com>
v2.0.0-rc.1
2026-06-22 11:10:20 -04:00
f68969de5c Bump helm.sh/helm/v3 from 3.21.1 to 3.21.2 (#635)
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-22 08:59:48 -04:00
Zack BradyandGitHub 538a43f8ec updated git ignore (#631) 2026-06-19 12:17:46 -04:00
1baff64cc0 bump github.com/containerd/containerd from 1.7.32 to 1.7.33 (#633)
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-19 11:00:15 -04:00
Zack BradyandGitHub 9e3fda28ce bumped versions and dependencies (#630) 2026-06-18 15:14:04 -04:00
5abb42e7fc bump helm.sh/helm/v3 from 3.21.0 to 3.21.1 (#623)
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-18 11:21:28 -04:00
4c03e58024 bump k8s.io/apimachinery from 0.36.1 to 0.36.2 (#625)
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-18 10:30:00 -04:00
0c5f8252b8 bump github.com/google/go-containerregistry from 0.21.6 to 0.21.7 (#628)
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-18 10:29:18 -04:00
Camryn CarterandGitHub 65c665ce81 remove experimental notes from rewrite and remove for 2.0.0 release (#621) 2026-06-09 15:53:43 -07:00
2b31ba465e bump golang.org/x/sync from 0.20.0 to 0.21.0 (#620)
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-09 14:34:26 -04:00
Adam ToyandGitHub d043105843 411 special characters fix (#618) 2026-06-03 09:36:48 -04:00
c6c1022298 bump github.com/containerd/containerd from 1.7.31 to 1.7.32 (#616)
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-05-21 09:19:55 +02:00
69d6b6e695 bump github.com/google/go-containerregistry from 0.21.5 to 0.21.6 (#613)
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-05-21 09:15:45 +02:00
953211d308 Bump github.com/in-toto/in-toto-golang from 0.10.0 to 0.11.0 in the go_modules group across 1 directory (#612)
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-05-14 09:59:47 -04:00
Adam Martin 1e782019c3 bump go to 1.26.0
Signed-off-by: Adam Martin <adam.martin@ranchergovernment.com>
2026-05-14 09:13:56 -04:00
a7ab99b2a4 Bump helm.sh/helm/v3 from 3.20.2 to 3.21.0 (#610)
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-05-14 08:44:38 -04:00
Adam Martin cfa7ea3484 bump github.com/sigstore/cosign/v3 from 3.0.5 to 3.0.6
Signed-off-by: Adam Martin <adam.martin@ranchergovernment.com>
2026-05-13 12:14:20 -04:00
99406d6cf8 bump github.com/containerd/containerd from 1.7.30 to 1.7.31 (#596)
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-05-08 00:09:32 -04:00
820baf0ba7 bump github.com/google/go-containerregistry from 0.20.7 to 0.21.5 (#600)
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-05-08 00:09:00 -04:00
d379ffa660 bump github.com/rs/zerolog from 1.34.0 to 1.35.1 (#593)
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-05-08 00:08:12 -04:00
Adam ToyandGitHub 8b777abc8a add dependabot configuration file to track multiple release minor rel… (#585) 2026-05-05 12:52:31 -06:00
Camryn CarterandGitHub fbcbb282c3 remove cherrypick bot and add mergify details (#581)
Signed-off-by: Camryn Carter <camryn.carter@ranchergovernment.com>
2026-05-03 12:27:51 -07:00
Zack BradyandGitHub cf6e7bcc40 added makefile command for vulnerability checks (#577) 2026-05-01 09:45:06 -04:00
Zack BradyandGitHub 6677f10d7b fixed github workflows (tests and cherrypicker) (#574) 2026-04-22 17:01:16 -04:00
Adam MartinandGitHub eca35ecb92 adjust logging for extracting oci artifacts with cosign bits (#575)
Signed-off-by: Adam Martin <adam.martin@ranchergovernment.com>
2026-04-22 12:57:51 -04:00
Camryn CarterandGitHub 2bf284e183 removed unnecessary rewrite flag from sync (#572) 2026-04-21 16:53:01 -04:00
c3cd3c0379 bump github.com/sigstore/timestamp-authority/v2 (#557)
bumps the go_modules group with 1 update in the / directory: [github.com/sigstore/timestamp-authority/v2](https://github.com/sigstore/timestamp-authority).


updates `github.com/sigstore/timestamp-authority/v2` from 2.0.4 to 2.0.6
- [Release notes](https://github.com/sigstore/timestamp-authority/releases)
- [Changelog](https://github.com/sigstore/timestamp-authority/blob/main/CHANGELOG.md)
- [Commits](https://github.com/sigstore/timestamp-authority/compare/v2.0.4...v2.0.6)

---
updated-dependencies:
- dependency-name: github.com/sigstore/timestamp-authority/v2
  dependency-version: 2.0.6
  dependency-type: indirect
  dependency-group: go_modules
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-04-19 18:24:01 -05:00
Adam MartinandGitHub 40c4fdded4 add ability to add images from local docker daemon (#551)
signed-off-by: Adam Martin <adam.martin@ranchergovernment.com>
2026-04-19 17:51:36 -05:00
Adam MartinandGitHub b2d0f9f01e add dry-run flag for sync --products (#547)
signed-off-by: Adam Martin <adam.martin@ranchergovernment.com>
2026-04-14 16:27:59 -04:00
Camryn CarterandGitHub 57d45f136e handle large diff passed to gh api (#553) 2026-04-11 20:26:29 -04:00
8560d02a6d bump helm.sh/helm/v3 in the go_modules group across 1 directory (#552)
bumps the go_modules group with 1 update in the / directory: [helm.sh/helm/v3](https://github.com/helm/helm).

updates `helm.sh/helm/v3` from 3.19.0 to 3.20.2
- [Release notes](https://github.com/helm/helm/releases)
- [Commits](https://github.com/helm/helm/compare/v3.19.0...v3.20.2)

---
updated-dependencies:
- dependency-name: helm.sh/helm/v3
  dependency-version: 3.20.2
  dependency-type: direct:production
  dependency-group: go_modules
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-04-11 10:39:49 -04:00
Camryn CarterandGitHub a8d6e2e527 verified commits and better messges (#550) 2026-04-08 20:23:05 -04:00
7319874ea8 bump go.opentelemetry.io/otel/sdk (#548)
bumps the go_modules group with 1 update in the / directory: [go.opentelemetry.io/otel/sdk](https://github.com/open-telemetry/opentelemetry-go).

updates `go.opentelemetry.io/otel/sdk` from 1.40.0 to 1.43.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-go/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-go/blob/main/CHANGELOG.md)
- [Commits](https://github.com/open-telemetry/opentelemetry-go/compare/v1.40.0...v1.43.0)

---
updated-dependencies:
- dependency-name: go.opentelemetry.io/otel/sdk
  dependency-version: 1.43.0
  dependency-type: indirect
  dependency-group: go_modules
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-04-08 17:30:16 -04:00
Adam MartinandGitHub f059a135da add optional flag for excluding extra artifacts when pulling from a registry (#541)
* add optional flag for excluding extra artifacts when pulling from a registry

Signed-off-by: Adam Martin <adam.martin@ranchergovernment.com>

* add optional flag to charts for excluding extra artifacts when pulling from a registry

Signed-off-by: Adam Martin <adam.martin@ranchergovernment.com>

---------

Signed-off-by: Adam Martin <adam.martin@ranchergovernment.com>
2026-04-07 12:48:05 -04:00
Zack BradyandGitHub b3e21806fe allow multiple prefix references (#532)
* allow multiple prefix references
* fixed some duplications
2026-04-07 07:51:25 -04:00
93938d1acb bump github.com/go-jose/go-jose/v4 (#542)
bumps the go_modules group with 1 update in the / directory: [github.com/go-jose/go-jose/v4](https://github.com/go-jose/go-jose).


updates `github.com/go-jose/go-jose/v4` from 4.1.3 to 4.1.4

- [Release notes](https://github.com/go-jose/go-jose/releases)
- [Commits](https://github.com/go-jose/go-jose/compare/v4.1.3...v4.1.4)

---

updated-dependencies:
- dependency-name: github.com/go-jose/go-jose/v4
  dependency-version: 4.1.4
  dependency-type: indirect
  dependency-group: go_modules

...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-04-03 08:41:54 -04:00
Camryn CarterandGitHub 641b9db8fd chunk the haul (#519)
* chunk the haul
* validate numeric suffix on join
* enforce valid chunk size
* containerd warning
* updated test.go files
2026-03-25 10:59:51 -04:00
Camryn CarterandGitHub c68e72df1c option to sync images.txt files natively (#538)
* sync images.txt files
* test worklflow sync w image list
* images.txt
2026-03-25 10:53:54 -04:00