Commit Graph
619 Commits
Author SHA1 Message Date
bb5be057d7 fixed hauler containers (backport #718) (#721)
Co-authored-by: Zack Brady <zackbrady123@gmail.com>
2026-08-09 20:21:44 -04:00
Zack BradyandGitHub 8d688ccee2 fixed vuln for golang grpc (#717) v2.0.3 2026-08-07 11:38:12 -04:00
1136f3d3fd update hauler store remove to handle registry reference as part of string (backport #705) (#706)
Signed-off-by: Camryn Carter <camryn.carter@ranchergovernment.com>
Co-authored-by: Camryn Carter <camryn.carter@ranchergovernment.com>
2026-08-03 19:57:48 -04:00
Adam Martin f190939939 address helm chart verification, auth, and tls options (#601)
Signed-off-by: Adam Martin <adam.martin@ranchergovernment.com>
(cherry picked from commit 2e280f2717)
2026-08-03 06:34:04 -04:00
2475087885 fix: process helm deps before --add-images discovery (backport #703) (#704)
Co-authored-by: aeltai <ala.eltai@suse.com>
2026-07-31 14:46:43 -04:00
d7d129abc6 fix for homebrew macOS binary quarantine (backport #690) (#696)
Signed-off-by: Adam Martin <adam.martin@ranchergovernment.com>
Co-authored-by: Adam Martin <adam.martin@ranchergovernment.com>
2026-07-27 10:56:31 -04:00
a6f031f54f Bump oras.land/oras-go/v2 from 2.6.1 to 2.6.2 in the go_modules group across 1 directory (backport #691) (#693)
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-25 11:30:55 -04:00
cfd476c344 Bump k8s.io/apimachinery from 0.36.2 to 0.36.3 (backport #688) (#692)
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-25 11:24:32 -04:00
4ece589a5c fix: bump golang to 1.26.5 (backport #685) (#686)
Signed-off-by: Adam Martin <adam.martin@ranchergovernment.com>
Co-authored-by: Adam Martin <adam.martin@ranchergovernment.com>
v2.0.2
2026-07-21 14:35:09 -04:00
13512a3652 registry auth fallback bugfix (backport #672) (#684)
Signed-off-by: Adam Martin <adam.martin@ranchergovernment.com>
Co-authored-by: Adam Martin <adam.martin@ranchergovernment.com>
2026-07-21 13:16:21 -04:00
mergify[bot]andAdam Martin 43e361d022 fix for copying digest artifacts (backport #673) (#683)
Co-authored-by: Adam Martin <adam.martin@ranchergovernment.com>
2026-07-21 12:11:18 -04:00
2c4b798dd6 fix: plain-http enforces use of http on bearer token fetch (#677) (backport #678) (#680)
Co-authored-by: Jeroen van Erp <jeroen@hierynomus.com>
Co-authored-by: Adam Martin <adam.martin@ranchergovernment.com>
2026-07-20 10:47:34 -04:00
494b62b1f2 Bump github.com/sigstore/cosign/v3 from 3.1.1 to 3.1.2 (backport #674) (#679)
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-20 09:57:24 -04:00
cb324ccaec bump containerd to v2 (backport #663) (#670)
Signed-off-by: Adam Martin <adam.martin@ranchergovernment.com>
Co-authored-by: Adam Martin <adam.martin@ranchergovernment.com>
2026-07-16 11:32:08 -04:00
16076a106d fix the broken behavior for --insecure on copy (backport #668) (#669)
Signed-off-by: Adam Martin <adam.martin@ranchergovernment.com>
Co-authored-by: Adam Martin <adam.martin@ranchergovernment.com>
2026-07-16 10:58:15 -04:00
22b14c941e utilize vex for trivy scan (backport #662) (#666)
Signed-off-by: Adam Martin <adam.martin@ranchergovernment.com>
Co-authored-by: Adam Martin <adam.martin@ranchergovernment.com>
2026-07-11 00:13:16 -04:00
fcf53f0dbc bump helm.sh/helm/v4 from 4.2.2 to 4.2.3 (backport #661) (#665)
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-11 00:12:39 -04:00
decf7ed97a bump github.com/containerd/containerd from 1.7.33 to 1.7.34 (backport #659) (#664)
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-11 00:12:08 -04:00
bf88ce66d6 bump golang.org/x/sync from 0.21.0 to 0.22.0 (backport #650) (#656)
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-09 14:26:43 -04:00
581ea4c7e3 feat: extend charts resource with helm values (backport #644) (#655)
Signed-off-by: Zack Brady <zackbrady123@gmail.com>
Co-authored-by: Eric Klatzer <eric@klatzer.at>
Co-authored-by: Zack Brady <zackbrady123@gmail.com>
2026-07-09 14:25:59 -04:00
a3543f6cf0 updates for helm v4 (backport #648) (#654)
Signed-off-by: Adam Martin <adam.martin@ranchergovernment.com>
Co-authored-by: Adam Martin <adam.martin@ranchergovernment.com>
2026-07-09 10:01:13 -04:00
777d0f059f unpinned distribution/distribution dependency (backport #647) (#653)
Co-authored-by: Zack Brady <zackbrady123@gmail.com>
2026-07-09 09:57:28 -04:00
6f6a101770 digest only regression fix (backport #643) (#652)
Signed-off-by: Adam Martin <adam.martin@ranchergovernment.com>
Co-authored-by: Adam Martin <adam.martin@ranchergovernment.com>
2026-07-09 09:57:03 -04:00
25f7185ee3 add trivy to make and add new vuln GHA (backport #641) (#651)
Signed-off-by: Adam Martin <adam.martin@ranchergovernment.com>
Co-authored-by: Adam Martin <adam.martin@ranchergovernment.com>
2026-07-09 09:55:07 -04:00
Adam MartinandGitHub 4f47155d6f bump go to 1.26.4 to squash CVE noise (#640)
Signed-off-by: Adam Martin <adam.martin@ranchergovernment.com>
v2.0.1
2026-06-23 11:58:40 -04:00
Zack BradyandGitHub 2bcc74450f removed experimental warnings from a few flags (#638) v2.0.0 2026-06-22 17:11:15 -04:00
Adam MartinandGitHub ec5082df18 add v2 to module path to correct version (#637)
Signed-off-by: Adam Martin <adam.martin@ranchergovernment.com>
2026-06-22 16:40:31 -04:00
905b3e4932 fix: image detection regex to allow hyphen in image property (#604)
Signed-off-by: Eric Klatzer <eric@klatzer.at>
Co-authored-by: Zack Brady <zackbrady123@gmail.com>
v2.0.0-rc.1
2026-06-22 11:10:20 -04:00
f68969de5c Bump helm.sh/helm/v3 from 3.21.1 to 3.21.2 (#635)
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-22 08:59:48 -04:00
Zack BradyandGitHub 538a43f8ec updated git ignore (#631) 2026-06-19 12:17:46 -04:00
1baff64cc0 bump github.com/containerd/containerd from 1.7.32 to 1.7.33 (#633)
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-19 11:00:15 -04:00
Zack BradyandGitHub 9e3fda28ce bumped versions and dependencies (#630) 2026-06-18 15:14:04 -04:00
5abb42e7fc bump helm.sh/helm/v3 from 3.21.0 to 3.21.1 (#623)
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-18 11:21:28 -04:00
4c03e58024 bump k8s.io/apimachinery from 0.36.1 to 0.36.2 (#625)
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-18 10:30:00 -04:00
0c5f8252b8 bump github.com/google/go-containerregistry from 0.21.6 to 0.21.7 (#628)
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-18 10:29:18 -04:00
Camryn CarterandGitHub 65c665ce81 remove experimental notes from rewrite and remove for 2.0.0 release (#621) 2026-06-09 15:53:43 -07:00
2b31ba465e bump golang.org/x/sync from 0.20.0 to 0.21.0 (#620)
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-09 14:34:26 -04:00
Adam ToyandGitHub d043105843 411 special characters fix (#618) 2026-06-03 09:36:48 -04:00
c6c1022298 bump github.com/containerd/containerd from 1.7.31 to 1.7.32 (#616)
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-05-21 09:19:55 +02:00
69d6b6e695 bump github.com/google/go-containerregistry from 0.21.5 to 0.21.6 (#613)
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-05-21 09:15:45 +02:00
953211d308 Bump github.com/in-toto/in-toto-golang from 0.10.0 to 0.11.0 in the go_modules group across 1 directory (#612)
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-05-14 09:59:47 -04:00
Adam Martin 1e782019c3 bump go to 1.26.0
Signed-off-by: Adam Martin <adam.martin@ranchergovernment.com>
2026-05-14 09:13:56 -04:00
a7ab99b2a4 Bump helm.sh/helm/v3 from 3.20.2 to 3.21.0 (#610)
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-05-14 08:44:38 -04:00
Adam Martin cfa7ea3484 bump github.com/sigstore/cosign/v3 from 3.0.5 to 3.0.6
Signed-off-by: Adam Martin <adam.martin@ranchergovernment.com>
2026-05-13 12:14:20 -04:00
99406d6cf8 bump github.com/containerd/containerd from 1.7.30 to 1.7.31 (#596)
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-05-08 00:09:32 -04:00
820baf0ba7 bump github.com/google/go-containerregistry from 0.20.7 to 0.21.5 (#600)
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-05-08 00:09:00 -04:00
d379ffa660 bump github.com/rs/zerolog from 1.34.0 to 1.35.1 (#593)
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-05-08 00:08:12 -04:00
Adam ToyandGitHub 8b777abc8a add dependabot configuration file to track multiple release minor rel… (#585) 2026-05-05 12:52:31 -06:00
Camryn CarterandGitHub fbcbb282c3 remove cherrypick bot and add mergify details (#581)
Signed-off-by: Camryn Carter <camryn.carter@ranchergovernment.com>
2026-05-03 12:27:51 -07:00
Zack BradyandGitHub cf6e7bcc40 added makefile command for vulnerability checks (#577) 2026-05-01 09:45:06 -04:00