Skip to content

Update module github.com/tektoncd/pipeline to v1.17.0 (main) - #3432

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/main-tektoncd-pipelines
Open

renovate[bot] wants to merge 1 commit into
mainfrom
renovate/main-tektoncd-pipelines

Conversation

@renovate

@renovate renovate Bot commented Jul 23, 2026 •

Copy link
Copy Markdown
Contributor

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
github.com/tektoncd/pipeline v1.12.0 → v1.17.0 age adoption passing confidence

Release Notes

tektoncd/pipeline (github.com/tektoncd/pipeline)

v1.17.0: Tekton Pipeline release v1.17.0 "Egyptian Mau Robocop"

Compare Source

🎉 Clearer failures, sharper traces 🎉
Installation one-liner
kubectl apply -f https://infra.tekton.dev/tekton-releases/pipeline/previous/v1.17.0/release.yaml
Attestation

The Rekor UUID for this release is 108e9186e8c5677a431fb2e9f34a5fd5b0418cccab54d920148b79cbe5bfcd5a2075f7ae918a9cc9

Obtain the attestation:

REKOR_UUID=108e9186e8c5677a431fb2e9f34a5fd5b0418cccab54d920148b79cbe5bfcd5a2075f7ae918a9cc9
rekor-cli get --uuid $REKOR_UUID --format json | jq -r .Attestation | jq .

Verify that all container images in the attestation are in the release file:

RELEASE_FILE=https://infra.tekton.dev/tekton-releases/pipeline/previous/v1.17.0/release.yaml
REKOR_UUID=108e9186e8c5677a431fb2e9f34a5fd5b0418cccab54d920148b79cbe5bfcd5a2075f7ae918a9cc9

# Obtains the list of images with sha from the attestation
REKOR_ATTESTATION_IMAGES=$(rekor-cli get --uuid "$REKOR_UUID" --format json | jq -r .Attestation | jq -r '.subject[]|.name + ":v1.17.0@sha256:" + .digest.sha256')

# Download the release file
curl -L "$RELEASE_FILE" > release.yaml

# For each image in the attestation, match it to the release file
for image in $REKOR_ATTESTATION_IMAGES; do
  printf $image; grep -q $image release.yaml && echo " ===> ok" || echo " ===> no match";
done
Changes
Features
  • ✨ feat(tracing): record reconcile.write_intent span attribute (#​10827)

Add a reconcile.write_intent attribute (no-op, status-only, metadata-only, metadata-and-status) to PipelineRun and TaskRun reconcile spans so operators can distinguish reconciliations that intend an etcd write.

  • ✨ Feat/10373 surface pod events/srvkp 13129 (#​10690)

Surface Pod infrastructure failure reasons (from Warning events such as
FailedMount, FailedScheduling, FailedCreatePodSandBox) onto the TaskRun
status condition when a Pod is stuck pending with no useful message. Gated
behind the new surface-pod-events alpha feature flag (disabled by default).

  • ✨ feat(tracing): tag TaskRun ReconcileKind span on cancel/timeout (#​10664)
Fixes
  • 🐛 fix: use non-expandable here-string for windows script placement (#​10822)

Fixed a Windows script-injection defense-in-depth gap: placeScriptInContainer now uses a non-expandable PowerShell here-string, so a script body containing a literal "@ line can no longer terminate the generated command early.

  • 🐛 fix: add task name in error on task resolution failure (#​10800)

Before this update, when resolver fails to get any task, controller showed the error message without containing the task name which was hard to detect which one is failed or having bad resolution config. Now task name is added to the error message from template.

  • 🐛 Allow tt.params as a valid variable-reference prefix (#​10688)

Pipelines can now reference $(tt.params.<name>) in task params, when expressions, and matrix params/includes. This lets a PipelineSpec embedded by Tekton Triggers keep its tt.params.* substitutions without failing pipeline validation.

  • 🐛 Enqueue only a resolver's own ResolutionRequests (#​10548)

Resolvers no longer fail ResolutionRequests belonging to a different resolver after a leader election or a resolver pod restart.

  • 🐛 fix: correct verb in controller startup panic logs (#​10430)

Fixed controller startup panic messages that printed a malformed %!w(...) marker instead of the underlying error when an informer event handler failed to register.

  • 🐛 Fix release_names.go: update regex for Wikipedia HTML changes and fix bugs (#​10508)
Misc
  • 🔨 chore: delete dead code in test/per_feature_flags_test.go file (#​10802)

NOT REQUIRED

  • 🔨 chore: group sigstore dependency updates in dependabot (#​10761)
  • 🔨 Eliminate discontinued gopkg.in/yaml.v3 library (#​10683)
  • 🔨 build(deps): bump the kubernetes group with 5 updates (#​10829)
  • 🔨 build(deps): bump the kubernetes group in /test/custom-task-ctrls/wait-task-beta with 3 updates (#​10828)
  • 🔨 build(deps): bump google.golang.org/grpc from 1.83.2 to 1.84.0 (#​10823)
  • 🔨 build(deps): bump chainguard-dev/actions/kind-diag from 1.6.35 to 1.6.36 (#​10821)
  • 🔨 build(deps): bump codecov/codecov-action from 7.0.0 to 7.1.1 (#​10820)
  • 🔨 build(deps): bump agilepathway/label-checker from 1.6.66 to 1.6.98 (#​10819)
  • 🔨 build(deps): bump chainguard-dev/actions/setup-kind from 1.6.35 to 1.6.36 (#​10818)
  • 🔨 build(deps): bump the all group in /tekton with 4 updates (#​10803)
  • 🔨 test: Fix tracing test to honor custom SYSTEM_NAMESPACE (#​10801)
  • 🔨 build(deps): bump github.com/spiffe/go-spiffe/v2 from 2.8.1 to 2.8.2 (#​10795)
  • 🔨 build(deps): bump the sigstore group with 5 updates (#​10791)
  • 🔨 build(deps): bump github.com/jenkins-x/go-scm from 1.16.0 to 1.16.3 (#​10783)
  • 🔨 build(deps): bump the all group in /tekton with 4 updates (#​10782)
  • 🔨 build(deps): bump agilepathway/label-checker from 1.6.65 to 1.6.66 (#​10780)
  • 🔨 build(deps): bump chainguard-dev/actions/setup-kind from 1.6.34 to 1.6.35 (#​10779)
  • 🔨 build(deps): bump chainguard-dev/actions/kind-diag from 1.6.34 to 1.6.35 (#​10778)
  • 🔨 build(deps): bump zizmorcore/zizmor-action from 0.6.3 to 0.6.4 (#​10777)
  • 🔨 build(deps): bump the codeql-action group with 3 updates (#​10776)
  • 🔨 build(deps): bump the all group in /tekton with 6 updates (#​10766)
  • 🔨 build(deps): bump github.com/jenkins-x/go-scm from 1.15.32 to 1.16.0 (#​10760)
  • 🔨 build(deps): bump golang.org/x/crypto from 0.56.0 to 0.57.0 (#​10759)
  • 🔨 build(deps): bump github.com/sigstore/sigstore/pkg/signature/kms/aws from 1.10.9 to 1.10.10 (#​10746)
  • 🔨 build(deps): bump github.com/sigstore/sigstore/pkg/signature/kms/gcp from 1.10.9 to 1.10.10 (#​10745)
  • 🔨 build(deps): bump github.com/sigstore/sigstore/pkg/signature/kms/hashivault from 1.10.9 to 1.10.10 (#​10744)
  • 🔨 build(deps): bump github.com/sigstore/sigstore from 1.10.9 to 1.10.10 (#​10743)
  • 🔨 build(deps): bump github.com/sigstore/sigstore/pkg/signature/kms/azure from 1.10.9 to 1.10.10 (#​10742)
  • 🔨 build(deps): bump step-security/harden-runner from 2.21.0 to 2.21.1 (#​10734)
  • 🔨 build(deps): bump chainguard-dev/actions/setup-kind from 1.6.32 to 1.6.34 (#​10733)
  • 🔨 build(deps): bump chainguard-dev/actions/kind-diag from 1.6.33 to 1.6.34 (#​10731)
  • 🔨 build(deps): bump zizmorcore/zizmor-action from 0.6.2 to 0.6.3 (#​10730)
  • 🔨 build(deps): bump the codeql-action group across 1 directory with 2 updates (#​10729)
  • 🔨 build(deps): bump golang.org/x/crypto from 0.55.0 to 0.56.0 (#​10723)
  • 🔨 build(deps): bump golang.org/x/sync from 0.22.0 to 0.23.0 (#​10722)
  • 🔨 build(deps): bump github.com/prometheus/common from 0.70.1 to 0.71.0 (#​10721)
  • 🔨 build(deps): bump github.com/google/go-containerregistry from 0.22.0 to 0.22.1 (#​10720)
  • 🔨 build(deps): bump github.com/tektoncd/pipeline from 1.15.1 to 1.16.0 in /test/custom-task-ctrls/wait-task-beta (#​10719)
  • 🔨 build(deps): bump chainguard-dev/actions/kind-diag from 1.6.32 to 1.6.33 (#​10712)
  • 🔨 build(deps): bump github/codeql-action/upload-sarif from 4.37.7 to 4.37.9 (#​10711)
  • 🔨 build(deps): bump the all group across 1 directory with 4 updates (#​10697)
  • 🔨 build(deps): bump github.com/prometheus/client_model from 0.6.2 to 0.6.3 (#​10693)
  • 🔨 deps: use new import path for google/cel-go lib (#​10689)
  • 🔨 build(deps): bump github.com/google/go-containerregistry from 0.21.9 to 0.22.0 (#​10682)
  • 🔨 fix(CI): group github/codeql-action/* dependabot updates (#​10661)
  • 🔨 Bump plumbing ref for github_release_oci task (#​10509)
Docs
  • 📖 docs: add v1.16.0 release to releases.md (#​10681)
  • 📖 docs: clarify config-tracing and config-observability are separate tracing paths (#​10626)
Thanks

Thanks to these contributors who contributed to v1.17.0!

Extra shout-out for awesome release notes:

v1.16.0: Tekton Pipeline release v1.16.0 "Manx WALL-E"

Compare Source

🎉 Secure by default, sharper traces 🎉

-Docs @​ v1.16.0
-Examples @​ v1.16.0

Installation one-liner
kubectl apply -f https://infra.tekton.dev/tekton-releases/pipeline/previous/v1.16.0/release.yaml
Attestation

The Rekor UUID for this release is 108e9186e8c5677a13e773b2ae0f6c52943d2b44a284030efb9b43068a9927a698b4799e13342b14

Obtain the attestation:

REKOR_UUID=108e9186e8c5677a13e773b2ae0f6c52943d2b44a284030efb9b43068a9927a698b4799e13342b14
rekor-cli get --uuid $REKOR_UUID --format json | jq -r .Attestation | jq .

Verify that all container images in the attestation are in the release file:

RELEASE_FILE=https://infra.tekton.dev/tekton-releases/pipeline/previous/v1.16.0/release.yaml
REKOR_UUID=108e9186e8c5677a13e773b2ae0f6c52943d2b44a284030efb9b43068a9927a698b4799e13342b14

# Obtains the list of images with sha from the attestation
REKOR_ATTESTATION_IMAGES=$(rekor-cli get --uuid "$REKOR_UUID" --format json | jq -r .Attestation | jq -r '.subject[]|.name + ":v1.16.0@sha256:" + .digest.sha256')

# Download the release file
curl -L "$RELEASE_FILE" > release.yaml

# For each image in the attestation, match it to the release file
for image in $REKOR_ATTESTATION_IMAGES; do
  printf $image; grep -q $image release.yaml && echo " ===> ok" || echo " ===> no match";
done
Upgrade Notices
  • 🚨 set-security-context enabled by default

action required: set-security-context now defaults to true and applies only to Tekton-injected TaskRun containers and Affinity Assistants (#​9589, #​10680). User-defined Steps and Sidecars must supply their own restricted-compatible security contexts. If the generated security contexts are incompatible with your images or Kubernetes implementation, set set-security-context to "false".

Changes
Features
  • ✨ feat(tracing): add spans for task parameter and workspace substitution #​9801 (#​10271)

Add tracing spans to the task parameter and workspace substitution pipeline in the TaskRun reconciler to improve observability and performance tracking. No user-facing changes.

  • ✨ test(notifications): cover CustomRun initTracing span propagation (#​10559)
  • ✨ feat: enable set-security-context feature flag by default (#​9589)
Fixes
  • 🐛 fix(CI): update golang-ci install URL to use main branch (#​10659)

Update the golangci-lint installation URL

  • 🐛 fix(nightlies): pass previousReleaseTag/releaseName to tkn pipeline start (#​10550)
  • 🐛 fix(ci): bump codeql-action/analyze to match init (#​10516)
  • 🐛 fix: end root tracing span at reconciliation completion (#​9699)

Fix root tracing span lifecycle in TaskRun and PipelineRun reconcilers to cover the full reconciliation cycle instead of ending immediately after initialization.

Misc
  • 🔨 Use larger GitHub-hosted runners for CI and E2E (#​10511)
  • 🔨 build(deps): bump google.golang.org/grpc from 1.83.1 to 1.83.2 (#​10674)
  • 🔨 build(deps): bump step-security/harden-runner from 2.20.1 to 2.21.0 (#​10672)
  • 🔨 build(deps): bump chainguard-dev/actions/setup-kind from 1.6.31 to 1.6.32 (#​10671)
  • 🔨 build(deps): bump chainguard-dev/actions/kind-diag from 1.6.31 to 1.6.32 (#​10669)
  • 🔨 build(deps): bump github.com/tektoncd/pipeline from 1.15.0 to 1.15.1 in /test/custom-task-ctrls/wait-task-beta (#​10666)
  • 🔨 Bump github/codeql-action to v4.37.7 (#​10660)
  • 🔨 build(deps): bump google.golang.org/grpc from 1.83.0 to 1.83.1 (#​10653)
  • 🔨 build(deps): bump the kubernetes group with 5 updates (#​10652)
  • 🔨 build(deps): bump the kubernetes group in /test/custom-task-ctrls/wait-task-beta with 3 updates (#​10650)
  • 🔨 build(deps): bump github.com/spiffe/spire-api-sdk from 1.15.2 to 1.15.3 (#​10646)
  • 🔨 build(deps): bump github.com/allegro/bigcache/v3 from 3.1.0 to 3.2.0 (#​10645)
  • 🔨 build(deps): bump github/codeql-action/init from 4.37.5 to 4.37.7 (#​10640)
  • 🔨 build(deps): bump github/codeql-action/upload-sarif from 4.37.6 to 4.37.7 (#​10638)
  • 🔨 build(deps): bump golang.org/x/crypto from 0.54.0 to 0.55.0 (#​10629)
  • 🔨 fix: exclude generated and non-library code from codecov coverage (#​10627)
  • 🔨 build(deps): bump google.golang.org/protobuf from 1.36.12-0.20260120151049-f2248ac996af to 1.36.12 (#​10622)
  • 🔨 build(deps): bump chainguard-dev/actions/kind-diag from 1.6.30 to 1.6.31 (#​10620)
  • 🔨 build(deps): bump chainguard-dev/actions/setup-kind from 1.6.30 to 1.6.31 (#​10619)
  • 🔨 build(deps): bump step-security/harden-runner from 2.20.0 to 2.20.1 (#​10615)
  • 🔨 build(deps): bump github.com/google/cel-go from 0.30.0 to 0.31.0 (#​10614)
  • 🔨 Regenerate dependabot.yml configuration (#​10611)
  • 🔨 build(deps): bump github/codeql-action/upload-sarif from 4.37.5 to 4.37.6 (#​10604)
  • 🔨 build(deps): bump chainguard-dev/actions/setup-kind from 1.6.27 to 1.6.30 (#​10596)
  • 🔨 build(deps): bump ossf/scorecard-action from 2.4.3 to 2.4.4 (#​10595)
  • 🔨 Move v1.3.x to End of Life releases (#​10585)
  • 🔨 build(deps): bump chainguard-dev/actions/kind-diag from 1.6.27 to 1.6.30 (#​10584)
  • 🔨 build(deps): bump github/codeql-action/upload-sarif from 4.37.1 to 4.37.5 (#​10583)
  • 🔨 build(deps): bump zizmorcore/zizmor-action from 0.6.0 to 0.6.2 (#​10582)
  • 🔨 build(deps): bump github/codeql-action/init from 4.37.3 to 4.37.5 (#​10581)
  • 🔨 build(deps): bump github/codeql-action/analyze from 4.37.3 to 4.37.5 (#​10576)
  • 🔨 build(deps): bump github.com/google/go-containerregistry from 0.21.8 to 0.21.9 (#​10571)
  • 🔨 Regenerate dependabot.yml configuration (#​10563)
  • 🔨 build(deps): bump github.com/tektoncd/pipeline from 1.14.1 to 1.15.0 in /test/custom-task-ctrls/wait-task-beta (#​10558)
  • 🔨 build(deps): bump github.com/sigstore/sigstore/pkg/signature/kms/hashivault from 1.10.8 to 1.10.9 (#​10544)
  • 🔨 build(deps): bump google.golang.org/grpc from 1.82.1 to 1.83.0 (#​10543)
  • 🔨 build(deps): bump github.com/sigstore/sigstore/pkg/signature/kms/aws from 1.10.8 to 1.10.9 (#​10532)
  • 🔨 build(deps): bump github.com/sigstore/sigstore/pkg/signature/kms/gcp from 1.10.8 to 1.10.9 (#​10531)
  • 🔨 build(deps): bump github.com/sigstore/sigstore from 1.10.8 to 1.10.9 (#​10530)
  • 🔨 build(deps): bump github.com/sigstore/sigstore/pkg/signature/kms/azure from 1.10.8 to 1.10.9 (#​10529)
  • 🔨 build(deps): bump github.com/jenkins-x/go-scm from 1.15.31 to 1.15.32 (#​10519)
  • 🔨 build(deps): bump github.com/google/go-containerregistry from 0.21.7 to 0.21.8 (#​10518)
  • 🔨 build(deps): bump github.com/google/cel-go from 0.29.2 to 0.30.0 (#​10517)
  • 🔨 build(deps): bump actions/download-artifact from 4.2.1 to 8.0.1 (#​10507)
  • 🔨 build(deps): bump step-security/harden-runner from 2.19.4 to 2.20.0 (#​10506)
  • 🔨 build(deps): bump actions/checkout from 7.0.0 to 7.0.1 (#​10503)
  • 🔨 build(deps): bump fgrosse/go-coverage-report from 1.3.0 to 1.3.1 (#​10499)
  • 🔨 build(deps): bump github/codeql-action/init from 4.37.0 to 4.37.3 (#​10498)
Docs
  • 📖 docs: clarify set-security-context scope and rollback (#​10680)
  • 📖 docs: include command to apply optional config to run e2e locally in development documentation (#​10553)
  • 📖 docs: add v1.15.0 release to releases.md (#​10510)
Thanks

Thanks to these contributors who contributed to v1.16.0!

Extra shout-out for awesome release notes:

v1.15.3: Tekton Pipeline release v1.15.3 "Toyger Orisa" LTS

Compare Source

Installation one-liner
kubectl apply -f https://infra.tekton.dev/tekton-releases/pipeline/previous/v1.15.3/release.yaml
Attestation

The Rekor UUID for this release is 108e9186e8c5677a1cca30d273b8c9dacc3ecea843087a7743386bf7355ef7a283afd3ed1829b921

Obtain the attestation:

REKOR_UUID=108e9186e8c5677a1cca30d273b8c9dacc3ecea843087a7743386bf7355ef7a283afd3ed1829b921
rekor-cli get --uuid $REKOR_UUID --format json | jq -r .Attestation | jq .

Verify that all container images in the attestation are in the release file:

RELEASE_FILE=https://infra.tekton.dev/tekton-releases/pipeline/previous/v1.15.3/release.yaml
REKOR_UUID=108e9186e8c5677a1cca30d273b8c9dacc3ecea843087a7743386bf7355ef7a283afd3ed1829b921

# Obtains the list of images with sha from the attestation
REKOR_ATTESTATION_IMAGES=$(rekor-cli get --uuid "$REKOR_UUID" --format json | jq -r .Attestation | jq -r '.subject[]|.name + ":v1.15.3@sha256:" + .digest.sha256')

# Download the release file
curl -L "$RELEASE_FILE" > release.yaml

# For each image in the attestation, match it to the release file
for image in $REKOR_ATTESTATION_IMAGES; do
  printf $image; grep -q $image release.yaml && echo " ===> ok" || echo " ===> no match";
done
Changes
Features
Fixes
  • 🐛 [cherry-pick: release-v1.15.x] Allow tt.params as a valid variable-reference prefix (#​10691)

Pipelines can now reference $(tt.params.<name>) in task params, when expressions, and matrix params/includes. This lets a PipelineSpec embedded by Tekton Triggers keep its tt.params.* substitutions without failing pipeline validation.

Misc
  • 🔨 [release-v1.15.x] bump github.com/sigstore/sigstore from 1.10.10 to 1.10.11 in the sigstore group (#​10792)
  • 🔨 [release-v1.15.x] bump the all group in /tekton with 4 updates (#​10787)
  • 🔨 [release-v1.15.x] bump agilepathway/label-checker from 1.6.65 to 1.6.66 (#​10769)
  • 🔨 [release-v1.15.x] bump zizmorcore/zizmor-action from 0.6.3 to 0.6.4 (#​10765)
  • 🔨 [release-v1.15.x] bump the sigstore group with 2 updates (#​10764)
  • 🔨 [release-v1.15.x] bump the all group in /tekton with 6 updates (#​10763)
  • 🔨 [release-v1.15.x] bump github.com/sigstore/sigstore from 1.10.9 to 1.10.10 (#​10755)
  • 🔨 [release-v1.15.x] bump github.com/sigstore/sigstore/pkg/signature/kms/azure from 1.10.9 to 1.10.10 (#​10753)
  • 🔨 [release-v1.15.x] bump github.com/sigstore/sigstore/pkg/signature/kms/gcp from 1.10.9 to 1.10.10 (#​10752)
  • 🔨 [release-v1.15.x] bump chainguard-dev/actions/kind-diag from 1.6.33 to 1.6.35 (#​10738)
  • 🔨 [release-v1.15.x] bump github/codeql-action/analyze from 4.37.7 to 4.37.9 in the codeql-action group across 1 directory (#​10736)
  • 🔨 [release-v1.15.x] bump zizmorcore/zizmor-action from 0.6.2 to 0.6.3 (#​10735)
  • 🔨 [release-v1.15.x] bump chainguard-dev/actions/setup-kind from 1.6.32 to 1.6.35 (#​10732)
  • 🔨 [release-v1.15.x] bump github/codeql-action/upload-sarif from 4.37.7 to 4.37.9 (#​10716)
  • 🔨 [release-v1.15.x] bump github/codeql-action/init from 4.37.7 to 4.37.9 (#​10715)
  • 🔨 [release-v1.15.x] bump github.com/prometheus/client_model from 0.6.2 to 0.6.3 (#​10709)
  • 🔨 [release-v1.15.x] bump chainguard-dev/actions/kind-diag from 1.6.32 to 1.6.33 (#​10706)
  • 🔨 [release-v1.15.x] bump the all group in /tekton with 4 updates (#​10704)
Docs
Thanks

Thanks to these contributors who contributed to v1.15.3!

Extra shout-out for awesome release notes:

v1.15.2: Tekton Pipeline release v1.15.2 "Toyger Orisa" LTS

Compare Source

-Docs @​ v1.15.2
-Examples @​ v1.15.2

Installation one-liner
kubectl apply -f https://infra.tekton.dev/tekton-releases/pipeline/previous/v1.15.2/release.yaml
Attestation

The Rekor UUID for this release is 108e9186e8c5677ad57a83fb64ccefa586efb4446b591b3a2d760972ce02657eb1929896879dbb74

Obtain the attestation:

REKOR_UUID=108e9186e8c5677ad57a83fb64ccefa586efb4446b591b3a2d760972ce02657eb1929896879dbb74
rekor-cli get --uuid $REKOR_UUID --format json | jq -r .Attestation | jq .

Verify that all container images in the attestation are in the release file:

RELEASE_FILE=https://infra.tekton.dev/tekton-releases/pipeline/previous/v1.15.2/release.yaml
REKOR_UUID=108e9186e8c5677ad57a83fb64ccefa586efb4446b591b3a2d760972ce02657eb1929896879dbb74

# Obtains the list of images with sha from the attestation
REKOR_ATTESTATION_IMAGES=$(rekor-cli get --uuid "$REKOR_UUID" --format json | jq -r .Attestation | jq -r '.subject[]|.name + ":v1.15.2@sha256:" + .digest.sha256')

# Download the release file
curl -L "$RELEASE_FILE" > release.yaml

# For each image in the attestation, match it to the release file
for image in $REKOR_ATTESTATION_IMAGES; do
  printf $image; grep -q $image release.yaml && echo " ===> ok" || echo " ===> no match";
done
Changes
Features
Fixes
Misc
  • 🔨 [release-v1.15.x] bump google.golang.org/grpc from 1.82.1 to 1.82.2 (#​10677)
  • 🔨 [release-v1.15.x] bump chainguard-dev/actions/setup-kind from 1.6.31 to 1.6.32 (#​10673)
  • 🔨 [release-v1.15.x] bump chainguard-dev/actions/kind-diag from 1.6.31 to 1.6.32 (#​10670)
  • 🔨 [release-v1.15.x] bump the kubernetes group with 5 updates (#​10656)
  • 🔨 [release-v1.15.x] bump the kubernetes group in /test/custom-task-ctrls/wait-task-beta with 3 updates (#​10654)
  • 🔨 [release-v1.15.x] bump github.com/spiffe/spire-api-sdk from 1.15.2 to 1.15.3 (#​10649)
  • 🔨 [release-v1.15.x] bump github/codeql-action/analyze from 4.37.6 to 4.37.7 (#​10641)
  • 🔨 [release-v1.15.x] bump github/codeql-action/init from 4.37.0 to 4.37.7 (#​10639)
  • 🔨 [release-v1.15.x] bump github/codeql-action/upload-sarif from 4.37.6 to 4.37.7 (#​10637)
  • 🔨 [release-v1.15.x] bump google.golang.org/protobuf from 1.36.12-0.20260120151049-f2248ac996af to 1.36.12 (#​10624)
  • 🔨 [release-v1.15.x] bump chainguard-dev/actions/kind-diag from 1.6.30 to 1.6.31 (#​10621)
  • 🔨 [release-v1.15.x] bump chainguard-dev/actions/setup-kind from 1.6.30 to 1.6.31 (#​10618)
  • 🔨 [release-v1.15.x] bump ossf/scorecard-action from 2.4.3 to 2.4.4 (#​10617)
  • 🔨 [release-v1.15.x] bump github/codeql-action/analyze from 4.37.5 to 4.37.6 (#​10616)
  • 🔨 [release-v1.15.x] bump github/codeql-action/upload-sarif from 4.37.5 to 4.37.6 (#​10603)
  • 🔨 [release-v1.15.x] bump fgrosse/go-coverage-report from 1.3.0 to 1.3.1 (#​10598)
  • 🔨 [release-v1.15.x] bump chainguard-dev/actions/kind-diag from 1.6.27 to 1.6.30 (#​10597)
  • 🔨 [release-v1.15.x] bump github.com/google/go-containerregistry from 0.21.7 to 0.21.9 (#​10587)
  • 🔨 [release-v1.15.x] bump chainguard-dev/actions/setup-kind from 1.6.27 to 1.6.30 (#​10579)
  • 🔨 [release-v1.15.x] bump github/codeql-action/analyze from 4.37.0 to 4.37.5 (#​10574)
  • 🔨 [release-v1.15.x] bump github.com/jenkins-x/go-scm from 1.15.31 to 1.15.36 (#​10572)
  • 🔨 [release-v1.15.x] bump github.com/sigstore/sigstore/pkg/signature/kms/azure from 1.10.8 to 1.10.9 (#​10570)
  • 🔨 [release-v1.15.x] bump github.com/sigstore/sigstore/pkg/signature/kms/gcp from 1.10.8 to 1.10.9 (#​10569)
  • 🔨 [release-v1.15.x] bump zizmorcore/zizmor-action from 0.6.0 to 0.6.2 (#​10567)
  • 🔨 [release-v1.15.x] bump actions/checkout from 7.0.0 to 7.0.1 (#​10566)
Docs
Thanks

Thanks to these contributors who contributed to v1.15.2!

Extra shout-out for awesome release notes:

v1.15.1: Tekton Pipeline release v1.15.1 "Toyger Orisa" LTS

Compare Source

-Docs @​ v1.15.1
-Examples @​ v1.15.1

Installation one-liner
kubectl apply -f https://infra.tekton.dev/tekton-releases/pipeline/previous/v1.15.1/release.yaml
Attestation

The Rekor UUID for this release is 108e9186e8c5677a210b81c75be73c2949e8e917e1776229b8bb68bc95b532e51d8f2bf29219a9c1

Obtain the attestation:

REKOR_UUID=108e9186e8c5677a210b81c75be73c2949e8e917e1776229b8bb68bc95b532e51d8f2bf29219a9c1
rekor-cli get --uuid $REKOR_UUID --format json | jq -r .Attestation | jq .

Verify that all container images in the attestation are in the release file:

RELEASE_FILE=https://infra.tekton.dev/tekton-releases/pipeline/previous/v1.15.1/release.yaml
REKOR_UUID=108e9186e8c5677a210b81c75be73c2949e8e917e1776229b8bb68bc95b532e51d8f2bf29219a9c1

# Obtains the list of images with sha from the attestation
REKOR_ATTESTATION_IMAGES=$(rekor-cli get --uuid "$REKOR_UUID" --format json | jq -r .Attestation | jq -r '.subject[]|.name + ":v1.15.1@sha256:" + .digest.sha256')

# Download the release file
curl -L "$RELEASE_FILE" > release.yaml

# For each image in the attestation, match it to the release file
for image in $REKOR_ATTESTATION_IMAGES; do
  printf $image; grep -q $image release.yaml && echo " ===> ok" || echo " ===> no match";
done
Changes
Features
Fixes
Misc
  • 🔨 [release-v1.15.x] bump github.com/sigstore/sigstore/pkg/signature/kms/hashivault from 1.10.8 to 1.10.9 (#​10586)
  • 🔨 [release-v1.15.x] bump github/codeql-action/upload-sarif from 4.37.1 to 4.37.5 (#​10577)
  • 🔨 [release-v1.15.x] bump github.com/sigstore/sigstore from 1.10.8 to 1.10.9 (#​10573)
  • 🔨 [release-v1.15.x] bump github.com/sigstore/sigstore/pkg/signature/kms/aws from 1.10.8 to 1.10.9 (#​10568)
Docs
Thanks

Thanks to these contributors who contributed to v1.15.1!

Extra shout-out for awesome release notes:

v1.15.0: Tekton Pipeline release v1.15.0 "Toyger Orisa" LTS

Compare Source

🎉 Steady under pressure — configurable backoffs and battle-tested fixes 🎉

-Docs @​ v1.15.0
-Examples @​ v1.15.0

Installation one-liner
kubectl apply -f https://infra.tekton.dev/tekton-releases/pipeline/previous/v1.15.0/release.yaml
Attestation

The Rekor UUID for this release is 108e9186e8c5677a045c87c57225dfff98b32437f52b89e344c449bcd535b462d41fff9004b89d29

Obtain the attestation:

REKOR_UUID=108e9186e8c5677a045c87c57225dfff98b32437f52b89e344c449bcd535b462d41fff9004b89d29
rekor-cli get --uuid $REKOR_UUID --format json | jq -r .Attestation | jq .

Verify that all container images in the attestation are in the release file:

RELEASE_FILE=https://infra.tekton.dev/tekton-releases/pipeline/previous/v1.15.0/release.yaml
REKOR_UUID=108e9186e8c5677a045c87c57225dfff98b32437f52b89e344c449bcd535b462d41fff9004b89d29

# Obtains the list of images with sha from the attestation
REKOR_ATTESTATION_IMAGES=$(rekor-cli get --uuid "$REKOR_UUID" --format json | jq -r .Attestation | jq -r '.subject[]|.name + ":v1.15.0@sha256:" + .digest.sha256')

# Download the release file
curl -L "$RELEASE_FILE" > release.yaml

# For each image in the attestation, match it to the release file
for image in $REKOR_ATTESTATION_IMAGES; do
  printf $image; grep -q $image release.yaml && echo " ===> ok" || echo " ===> no match";
done
Changes
Features
  • ✨ Add configuration for custom git resolver backoff (#​10422)

Enables the configuration of backoffs for git resolver requests.

  • ✨ feat: add configurable grace period for transient CreateContainerError (#​10326)

Add default-create-container-error-timeout configuration option in config-defaults to provide a grace period before failing TaskRuns on transient CreateContainerError/CreateContainerConfigError with "context deadline exceeded". Default is 0 (fail fast, preserving existing behavior)

Fixes
  • 🐛 fix(resolutionrequest): preserve resolver-written status fields (#​10487)

Prevent ResolutionRequest lifecycle updates from overwriting resolver-written status fields.

  • 🐛 fix(resolvers): honor leader-election bucket ownership (#​10480)

Fix resolver replicas processing ResolutionRequests outside their leader-election bucket.

  • 🐛 Prevent matrix combination count int overflow (#​10431)

Fixed an integer overflow in matrix combination counting that could let a very
large matrix bypass the max-matrix-combinations validation guard.

  • 🐛 Fix PipelineRun stuck in ResolvingTaskRef when ResolutionRequest enqueue is missed (#​10429)

Fix PipelineRun remaining stuck in ResolvingTaskRef when a ResolutionRequest completion event is missed by periodically requeueing while remote resolution is in progress

  • 🐛 Fix RestrictLength panic on all-symbol input (#​10421)

Fixed a panic in the PipelineRun controller when a PipelineRun using an embedded (anonymous) pipeline spec sets a generateName that contains no alphanumeric characters (for example --). Such names no longer crash the reconciler.

  • 🐛 Fix sidecar-logs result extraction for results exceeding 4096 bytes (#​10403)

Fix sidecar-logs result extraction dropping all TaskRun results when a single result's JSON exceeds 4096 bytes but is within the configured max-result-size. Regression since v1.9.0.

  • 🐛 Preserve Sidecar RestartPolicy on API conversion (#​10392)

Fixed a bug where a Sidecar's restartPolicy (native Kubernetes sidecar support)
was dropped when converting a Task or TaskRun between the v1beta1 and v1 API
versions, causing a sidecar requested as a native sidecar to be created as an
ordinary sidecar.

  • 🐛 Mount debug scripts read-only in step containers (#​10362)

Debug breakpoint scripts are now mounted read-only in step containers, so a step can no longer overwrite them before a user execs in to continue or fail a breakpoint.

  • 🐛 fix(nightlies): restart webhook after CEL feature-flag patch (#​10475)
  • 🐛 fix(deps): bump OTel SDK with knative.dev/pkg semconv alignment (#​10447)
  • 🐛 fix(nightlies): skip draft-release tasks when releaseMode=nightly (#​10441)
  • 🐛 Fix broken object param example links in API spec (#​10397)
  • 🐛 fix: resolve in-toto attestation UUID in wait-for-chains (#​10363)
Misc
  • 🔨 fix(release): copy vendor tarball into kodata instead of symlink (#​10418)

Fix release pipeline ko resolve failure caused by ko >= v0.19.0 rejecting
the kodata/source.tar.gz symlink used to bundle vendored source.

  • 🔨 Add branch prefix to Dependabot PR titles for release branches (#​10405)
  • 🔨 Fix wrong Deprecated godoc in affinity assistant (#​10391)
  • 🔨 build(deps): bump github.com/prometheus/common from 0.70.0 to 0.70.1 (#​10470)
  • 🔨 build(deps): bump the kubernetes group with 5 updates (#​10469)
  • 🔨 build(deps): bump the kubernetes group across 1 directory with 3 updates (#​10468)
  • 🔨 build(deps): bump github/codeql-action/upload-sarif from 4.37.0 to 4.37.1 (#​10462)
  • 🔨 build(deps): bump github.com/tektoncd/pipeline from 1.14.0 to 1.14.1 in /test/custom-task-ctrls/wait-task-beta (#​10461)
  • 🔨 build(deps): bump actions/setup-go from 6.5.0 to 7.0.0 (#​10456)
  • 🔨 build(deps): bump chainguard-dev/actions/setup-kind from 1.6.26 to 1.6.27 (#​10455)
  • 🔨 build(deps): bump chainguard-dev/actions/kind-diag from 1.6.26 to 1.6.27 (#​10454)
  • 🔨 build(deps): bump zizmorcore/zizmor-action from 0.5.7 to 0.6.0 (#​10453)
  • 🔨 Ignore otel major/minor updates in dependabot (#​10450)
  • 🔨 build(deps): bump google.golang.org/grpc from 1.82.0 to 1.82.1 (#​10446)
  • 🔨 ci(.github/workflows): enable Codecov coverage reporting (#​10440)
  • 🔨 build(deps): bump github.com/prometheus/common from 0.69.0 to 0.70.0 (#​10439)
  • 🔨 build(deps): bump github/codeql-action/upload-sarif from 4.36.3 to 4.37.0 (#​10437)
  • 🔨 build(deps): bump github/codeql-action/analyze from 4.36.3 to 4.37.0 (#​10436)
  • 🔨 build(deps): bump github/codeql-action/init from 4.36.3 to 4.37.0 (#​10435)
  • 🔨 build(deps): bump step-security/harden-runner from 2.19.4 to 2.20.0 (#​10434)
  • 🔨 build(deps): bump github.com/spiffe/spire-api-sdk from 1.15.1 to 1.15.2 (#​10433)
  • 🔨 build(deps): bump golang.org/x/crypto from 0.53.0 to 0.54.0 (#​10432)
  • 🔨 build(deps): bump github.com/google/cel-go from 0.29.1 to 0.29.2 (#​10423)
  • 🔨 build(deps): bump chainguard-dev/actions/kind-diag from 1.6.25 to 1.6.26 (#​10417)
  • 🔨 build(deps): bump ko-build/setup-ko from 0.9 to 0.10 (#​10416)
  • 🔨 build(deps): bump github.com/google/cel-go from 0.29.0 to 0.29.1 (#​10415)
  • 🔨 build(deps): bump github/codeql-action/init from 4.36.2 to 4.36.3 (#​10413)
  • 🔨 build(deps): bump github/codeql-action/analyze from 4.36.2 to 4.36.3 (#​10412)
  • 🔨 build(deps): bump golangci/golangci-lint-action from 9.2.1 to 9.3.0 (#​10411)
  • 🔨 build(deps): bump github/codeql-action/upload-sarif from 4.36.2 to 4.36.3 (#​10410)
  • 🔨 build(deps): bump github.com/google/cel-go from 0.28.1 to 0.29.0 (#​10407)
  • 🔨 build(deps): bump chainguard-dev/actions/setup-kind from 1.6.25 to 1.6.26 (#​10406)
  • 🔨 build(deps): bump golang.org/x/sync from 0.21.0 to 0.22.0 (#​10404)
  • 🔨

❗ Important

✂ PR body was truncated to here.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • Between 12:00 AM and 03:59 AM (* 0-3 * * *)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
renovate Bot enabled auto-merge July 23, 2026 02:02
@renovate

renovate Bot commented Jul 23, 2026 •

Copy link
Copy Markdown
Contributor Author

ℹ️ Artifact update notice

File name: acceptance/go.mod

In order to perform the update(s) described in the table above, Renovate ran the go get command, which resulted in the following additional change(s):

  • 32 additional dependencies were updated
  • The go directive was updated for compatibility reasons

Due to Go's usage of Minimal Version Selection (MVS), these packages have been updated to the minimum version available, so will still abide by minimumReleaseAge=5 days

Details:

Package Change
go 1.26.7 -> 1.27.0
github.com/google/go-containerregistry v0.21.7 -> v0.22.1
github.com/secure-systems-lab/go-securesystemslib v0.11.0 -> v0.11.1
github.com/sigstore/sigstore v1.10.8 -> v1.11.0
k8s.io/apimachinery v0.36.0 -> v0.37.1
github.com/coreos/go-oidc/v3 v3.19.0 -> v3.20.0
github.com/fxamacker/cbor/v2 v2.9.0 -> v2.9.1
github.com/go-jose/go-jose/v4 v4.1.4 -> v4.1.5
github.com/go-openapi/jsonpointer v0.23.1 -> v1.0.0
github.com/go-openapi/jsonreference v0.21.6 -> v1.0.0
github.com/go-openapi/swag v0.26.1 -> v0.27.1
github.com/go-openapi/swag/cmdutils v0.26.1 -> v0.27.1
github.com/go-openapi/swag/conv v0.27.0 -> v0.27.1
github.com/go-openapi/swag/fileutils v0.26.1 -> v0.27.1
github.com/go-openapi/swag/jsonutils v0.26.1 -> v0.27.1
github.com/go-openapi/swag/loading v0.26.1 -> v0.27.1
github.com/go-openapi/swag/mangling v0.26.1 -> v0.27.1
github.com/go-openapi/swag/netutils v0.26.1 -> v0.27.1
github.com/go-openapi/swag/stringutils v0.26.1 -> v0.27.1
github.com/go-openapi/swag/typeutils v0.27.0 -> v0.27.1
github.com/go-openapi/swag/yamlutils v0.26.1 -> v0.27.1
github.com/goccy/go-yaml v1.18.0 -> v1.19.2
github.com/prometheus/client_model v0.6.2 -> v0.6.3
github.com/prometheus/common v0.70.1 -> v0.71.0
github.com/sigstore/protobuf-specs v0.5.1 -> v0.5.2
github.com/sirupsen/logrus v1.10.1 -> v1.10.2
go.opentelemetry.io/otel/exporters/stdout/stdouttrace v1.43.0 -> v1.44.0
golang.org/x/oauth2 v0.36.0 -> v0.37.0
google.golang.org/genproto/googleapis/rpc v0.0.0-20260803160001-6ac0973c030d -> v0.0.0-20260819154853-08b0e4226688
google.golang.org/grpc v1.83.2 -> v1.84.0
k8s.io/kube-openapi v0.0.0-20260319004828-5883c5ee87b9 -> v0.0.0-20260821135717-be32def86098
k8s.io/utils v0.0.0-20260319190234-28399d86e0b5 -> v0.0.0-20260626114624-be93311217bd
sigs.k8s.io/structured-merge-diff/v6 v6.3.2 -> v6.4.2
File name: go.mod

In order to perform the update(s) described in the table above, Renovate ran the go get command, which resulted in the following additional change(s):

  • 58 additional dependencies were updated
  • The go directive was updated for compatibility reasons

Due to Go's usage of Minimal Version Selection (MVS), these packages have been updated to the minimum version available, so will still abide by minimumReleaseAge=5 days

Details:

Package Change
go 1.26.7 -> 1.27.0
github.com/google/go-containerregistry v0.21.7 -> v0.22.1
github.com/secure-systems-lab/go-securesystemslib v0.11.0 -> v0.11.1
github.com/sigstore/sigstore v1.10.8 -> v1.11.0
github.com/sirupsen/logrus v1.10.1 -> v1.10.2
golang.org/x/net v0.58.0 -> v0.58.0
k8s.io/apimachinery v0.36.3 -> v0.37.1
k8s.io/kube-openapi v0.0.0-20260319004828-5883c5ee87b9 -> v0.0.0-20260821135717-be32def86098
cloud.google.com/go/auth v0.20.0 -> v0.23.2
cloud.google.com/go/iam v1.11.0 -> v1.12.0
cloud.google.com/go/monitoring v1.25.0 -> v1.30.0
github.com/GoogleCloudPlatform/opentelemetry-operations-go/detectors/gcp v1.33.0 -> v1.34.0
github.com/aws/aws-sdk-go-v2 v1.43.8 -> v1.46.0
github.com/aws/aws-sdk-go-v2/config v1.32.39 -> v1.33.3
github.com/aws/aws-sdk-go-v2/credentials v1.19.38 -> v1.20.3
github.com/aws/aws-sdk-go-v2/feature/ec2/imds v1.18.39 -> v1.19.2
github.com/aws/aws-sdk-go-v2/internal/configsources v1.4.39 -> v1.5.2
github.com/aws/aws-sdk-go-v2/internal/endpoints/v2 v2.7.39 -> v2.8.2
github.com/aws/aws-sdk-go-v2/internal/v4a v1.4.40 -> v1.5.2
github.com/aws/aws-sdk-go-v2/service/internal/accept-encoding v1.13.18 -> v1.13.19
github.com/aws/aws-sdk-go-v2/service/internal/presigned-url v1.13.39 -> v1.14.2
github.com/aws/aws-sdk-go-v2/service/signin v1.5.8 -> v1.9.0
github.com/aws/aws-sdk-go-v2/service/sso v1.33.8 -> v1.37.0
github.com/aws/aws-sdk-go-v2/service/ssooidc v1.38.8 -> v1.42.0
github.com/aws/aws-sdk-go-v2/service/sts v1.45.8 -> v1.49.0
github.com/aws/smithy-go v1.27.10 -> v1.28.1
github.com/coreos/go-oidc/v3 v3.19.0 -> v3.20.0
github.com/fxamacker/cbor/v2 v2.9.0 -> v2.9.1
github.com/go-jose/go-jose/v4 v4.1.4 -> v4.1.5
github.com/go-openapi/jsonpointer v0.23.1 -> v1.0.0
github.com/go-openapi/jsonreference v0.21.6 -> v1.0.0
github.com/go-openapi/swag v0.26.1 -> v0.27.1
github.com/go-openapi/swag/cmdutils v0.26.1 -> v0.27.1
github.com/go-openapi/swag/conv v0.27.0 -> v0.27.1
github.com/go-openapi/swag/fileutils v0.26.1 -> v0.27.1
github.com/go-openapi/swag/jsonutils v0.26.1 -> v0.27.1
github.com/go-openapi/swag/loading v0.26.1 -> v0.27.1
github.com/go-openapi/swag/mangling v0.26.1 -> v0.27.1
github.com/go-openapi/swag/netutils v0.26.1 -> v0.27.1
github.com/go-openapi/swag/stringutils v0.26.1 -> v0.27.1
github.com/go-openapi/swag/typeutils v0.27.0 -> v0.27.1
github.com/go-openapi/swag/yamlutils v0.26.1 -> v0.27.1
github.com/goccy/go-yaml v1.18.0 -> v1.19.2
github.com/golang/snappy v0.0.4 -> v1.0.0
github.com/googleapis/enterprise-certificate-proxy v0.3.16 -> v0.3.20
github.com/googleapis/gax-go/v2 v2.22.0 -> v2.24.0
github.com/prometheus/client_model v0.6.2 -> v0.6.3
github.com/prometheus/common v0.70.1 -> v0.71.0
github.com/sigstore/protobuf-specs v0.5.1 -> v0.5.2
github.com/spiffe/go-spiffe/v2 v2.7.0 -> v2.8.2
go.opentelemetry.io/otel/exporters/stdout/stdouttrace v1.42.0 -> v1.44.0
golang.org/x/oauth2 v0.36.0 -> v0.37.0
google.golang.org/api v0.286.0 -> v0.295.0
google.golang.org/genproto v0.0.0-20260406210006-6f92a3bedf2d -> v0.0.0-20260715232425-e75dac1f907d
google.golang.org/genproto/googleapis/rpc v0.0.0-20260803160001-6ac0973c030d -> v0.0.0-20260819154853-08b0e4226688
google.golang.org/grpc v1.83.2 -> v1.84.0
k8s.io/utils v0.0.0-20260319190234-28399d86e0b5 -> v0.0.0-20260626114624-be93311217bd
knative.dev/pkg v0.0.0-20260318013857-98d5a706d4fd -> v0.0.0-20260622140654-39ebae2ee2dc
sigs.k8s.io/structured-merge-diff/v6 v6.3.3 -> v6.4.2

@fullsend-ai-review

fullsend-ai-review Bot commented Jul 23, 2026 •

Copy link
Copy Markdown

🤖 Finished Review · ✅ Success · Started 2:02 AM UTC · Completed 2:10 AM UTC
Commit: 87c4a29 · View workflow run →

@fullsend-ai-review

fullsend-ai-review Bot commented Jul 23, 2026 •

Copy link
Copy Markdown

Looks good to me

Previous run

Looks good to me

Previous run (2)

Review

Reason: stale-head

The review agent reviewed commit b96d32b9b53fff0debb55133e2b5f5669236d6b5 but the PR HEAD is now b35a18b9f23153e89584352d89a77cb7dc049d6c. This review was discarded to avoid approving unreviewed code.

Previous run (3)

Looks good to me

Previous run (4)

Looks good to me

Previous run (5)

Looks good to me

Previous run (6)

Looks good to me

Previous run (7)

Looks good to me

Previous run (8)

Looks good to me

Previous run (9)

Looks good to me

Previous run (10)

Looks good to me

Previous run (11)

Looks good to me

Previous run (12)

Looks good to me

Previous run (13)

Looks good to me

Previous run (14)

Review

Findings

Info

  • [provenance-warning] — Prior review context was discarded because provenance validation failed (PRIOR_REVIEW_PROVENANCE=unverifiable-wrong-app). This review treats all findings as first-time assessments; no severity anchoring was applied.
  • [dependency-bump] go.mod, go.sum, acceptance/go.mod, acceptance/go.sum — Renovate bot bump of github.com/tektoncd/pipeline from v1.12.0 to v1.16.0, plus cascading updates to transitive dependencies (sigstore, cel-go, k8s.io/apimachinery, knative.dev/pkg, etc.). Diff is purely go.mod/go.sum version changes with no source-code edits. Note: the tektoncd/pipeline v1.16.0 release enables set-security-context by default, but that flag affects the Tekton controller runtime, not consumers of the Go library types/schema (this repository).
Previous run (15)

Review

Mechanical Renovate dependency bump (github.com/tektoncd/pipeline v1.12.0 → v1.16.0) with the resulting transitive cascade across go.mod / go.sum and acceptance/go.mod / acceptance/go.sum. No source files or protected paths are touched. Automated checks (parallel review across correctness, security, style-conventions, and intent-coherence dimensions) found no blocking issues.

Findings

Info

  • [scope-authorization-implicit] — Authorization inferred from the mechanical nature of the change (dependency-manifest-only bump). No architectural review required.
  • [provenance-warning] — Prior review context discarded: provenance validation failed (PRIOR_REVIEW_PROVENANCE=unverifiable-wrong-app). This review treats all findings as first-time assessments; severity anchoring was skipped for this run.
Previous run (16)

Looks good to me

Previous run (17)

Looks good to me

Previous run (18)

Looks good to me

Previous run (19)

Looks good to me

Previous run (20)

Looks good to me

Previous run (21)

Looks good to me

Previous run (22)

Looks good to me

Previous run (23)

Looks good to me

Previous run (24)

Looks good to me


Labels: Renovate bot dependency version bump in Go module files (go.mod, go.sum)

Previous run (25)

Looks good to me

Previous run (26)

Looks good to me

Previous run (27)

Looks good to me

Previous run (28)

Looks good to me

Previous run (29)

Looks good to me

Previous run (30)

Looks good to me

Previous run (31)

Looks good to me

Previous run (32)

Looks good to me

Previous run (33)

Looks good to me

Previous run (34)

Looks good to me

Previous run (35)

Looks good to me

Previous run (36)

Looks good to me

Previous run (37)

Looks good to me

Previous run (38)

Looks good to me

Previous run (39)

Looks good to me

Previous run (40)

Looks good to me

Previous run (41)

Looks good to me

Previous run (42)

Looks good to me

Previous run (43)

Looks good to me

Previous run (44)

Looks good to me

Previous run (45)

Looks good to me

Previous run (46)

Looks good to me


Labels: Renovate bot Go module dependency update (tektoncd/pipeline v1.12.0 → v1.15.0 with transitive deps)

Previous run (47)

Looks good to me

Previous run (48)

Looks good to me

Previous run (49)

Looks good to me

Previous run (50)

Looks good to me

Previous run (51)

Looks good to me

Previous run (52)

Looks good to me

Previous run (53)

Looks good to me

Previous run (54)

Looks good to me

Previous run (55)

Looks good to me

Previous run (56)

Looks good to me


Labels: Renovate bot dependency version bump in Go modules

Previous run (57)

Looks good to me


Labels: Renovate bot dependency update modifying Go module files

Previous run (58)

Looks good to me

Previous run (59)

Looks good to me

Previous run (60)

Looks good to me


Labels: PR is a Go dependency update (go.mod/go.sum only)

fullsend-ai-review[bot]

This comment was marked as outdated.

@fullsend-ai-review fullsend-ai-review Bot added ready-for-merge All reviewers approved — ready to merge dependencies Pull requests that update a dependency file go Pull requests that update Go code labels Jul 23, 2026
@renovate
renovate Bot force-pushed the renovate/main-tektoncd-pipelines branch from 0972810 to 07721ee Compare July 24, 2026 08:21
@fullsend-ai-review

fullsend-ai-review Bot commented Jul 24, 2026 •

Copy link
Copy Markdown

🤖 Finished Review · ✅ Success · Started 8:21 AM UTC · Completed 8:26 AM UTC
Commit: 87c4a29 · View workflow run →

fullsend-ai-review[bot]

This comment was marked as outdated.

@renovate
renovate Bot force-pushed the renovate/main-tektoncd-pipelines branch from 07721ee to ff2d07b Compare July 28, 2026 07:53
@fullsend-ai-review

fullsend-ai-review Bot commented Jul 28, 2026 •

Copy link
Copy Markdown

🤖 Finished Review · ✅ Success · Started 7:54 AM UTC · Completed 8:01 AM UTC
Commit: 87c4a29 · View workflow run →

fullsend-ai-review[bot]

This comment was marked as outdated.

@renovate
renovate Bot force-pushed the renovate/main-tektoncd-pipelines branch from ff2d07b to c216db6 Compare July 28, 2026 15:01
@fullsend-ai-review

fullsend-ai-review Bot commented Jul 28, 2026 •

Copy link
Copy Markdown

🤖 Finished Review · ✅ Success · Started 3:02 PM UTC · Completed 3:09 PM UTC
Commit: 87c4a29 · View workflow run →

fullsend-ai-review[bot]

This comment was marked as outdated.

@renovate
renovate Bot force-pushed the renovate/main-tektoncd-pipelines branch from c216db6 to 8fede4b Compare July 28, 2026 20:03
@fullsend-ai-review

fullsend-ai-review Bot commented Jul 28, 2026 •

Copy link
Copy Markdown

🤖 Finished Review · ✅ Success · Started 8:04 PM UTC · Completed 8:11 PM UTC
Commit: 87c4a29 · View workflow run →

fullsend-ai-review[bot]

This comment was marked as outdated.

@renovate
renovate Bot force-pushed the renovate/main-tektoncd-pipelines branch from 8fede4b to dcb00e9 Compare July 29, 2026 13:32
@fullsend-ai-review

fullsend-ai-review Bot commented Jul 29, 2026 •

Copy link
Copy Markdown

🤖 Finished Review · ✅ Success · Started 1:33 PM UTC · Completed 1:39 PM UTC
Commit: 87c4a29 · View workflow run →

fullsend-ai-review[bot]

This comment was marked as outdated.

@renovate
renovate Bot force-pushed the renovate/main-tektoncd-pipelines branch from dcb00e9 to 64fd9cb Compare July 30, 2026 22:15
@github-actions github-actions Bot added size: M and removed size: L labels Jul 30, 2026
@fullsend-ai-review

fullsend-ai-review Bot commented Jul 30, 2026 •

Copy link
Copy Markdown

🤖 Finished Review · ✅ Success · Started 10:16 PM UTC · Completed 10:23 PM UTC
Commit: 87c4a29 · View workflow run →

@renovate
renovate Bot force-pushed the renovate/main-tektoncd-pipelines branch from da4b03e to 2002579 Compare September 15, 2026 13:07
@fullsend-ai-review

fullsend-ai-review Bot commented Sep 15, 2026 •

Copy link
Copy Markdown

🤖 Finished Review · ✅ Success · Started 1:08 PM UTC · Completed 1:15 PM UTC

Commit: cd01138 · View workflow run →

Runtime: claude · Model: opus → claude-opus-4-7 · Effort: high · Cost: $2.98

fullsend-ai-review[bot]

This comment was marked as outdated.

@renovate
renovate Bot force-pushed the renovate/main-tektoncd-pipelines branch from 2002579 to 379b405 Compare September 15, 2026 13:25
@fullsend-ai-review

fullsend-ai-review Bot commented Sep 15, 2026 •

Copy link
Copy Markdown

🤖 Finished Review · ✅ Success · Started 1:27 PM UTC · Completed 1:34 PM UTC

Commit: cd01138 · View workflow run →

Runtime: claude · Model: opus → claude-opus-4-7 · Effort: high · Cost: $3.73

fullsend-ai-review[bot]

This comment was marked as outdated.

@renovate
renovate Bot force-pushed the renovate/main-tektoncd-pipelines branch from 379b405 to e59d612 Compare September 15, 2026 15:49
@fullsend-ai-review

fullsend-ai-review Bot commented Sep 15, 2026 •

Copy link
Copy Markdown

🤖 Finished Review · ✅ Success · Started 3:50 PM UTC · Completed 3:59 PM UTC

Commit: e8f0a9f · View workflow run →

Runtime: claude · Model: opus → claude-opus-4-7 · Effort: high · Cost: $3.84

fullsend-ai-review[bot]

This comment was marked as outdated.

@renovate
renovate Bot force-pushed the renovate/main-tektoncd-pipelines branch from e59d612 to d5fe6cb Compare September 15, 2026 19:21
@fullsend-ai-review

fullsend-ai-review Bot commented Sep 15, 2026 •

Copy link
Copy Markdown

🤖 Finished Review · ✅ Success · Started 7:23 PM UTC · Completed 7:29 PM UTC

Commit: e8f0a9f · View workflow run →

Runtime: claude · Model: opus → claude-opus-4-7 · Effort: high · Cost: $2.97

fullsend-ai-review[bot]

This comment was marked as outdated.

@renovate
renovate Bot force-pushed the renovate/main-tektoncd-pipelines branch from d5fe6cb to aa20c45 Compare September 16, 2026 10:09
@fullsend-ai-review

fullsend-ai-review Bot commented Sep 16, 2026 •

Copy link
Copy Markdown

🤖 Finished Review · ✅ Success · Started 10:11 AM UTC · Completed 10:18 AM UTC

Commit: e8f0a9f · View workflow run →

Runtime: claude · Model: opus → claude-opus-4-7 · Effort: high · Cost: $3.61

fullsend-ai-review[bot]

This comment was marked as outdated.

fullsend-ai-review[bot]

This comment was marked as outdated.

fullsend-ai-review[bot]

This comment was marked as outdated.

fullsend-ai-review[bot]

This comment was marked as outdated.

fullsend-ai-review[bot]

This comment was marked as outdated.

fullsend-ai-review[bot]

This comment was marked as outdated.

fullsend-ai-review[bot]

This comment was marked as outdated.

@fullsend-ai-review

Copy link
Copy Markdown

🤖 Finished Review · ❌ Failure (ensuring provider "github-ro": provider create "github-ro" failed: exit status 1 (output: Error: × code: 'Client specified an invalid argument', message: "provider │ credentials are not declared by pr…) · Started 10:08 AM UTC · Completed 10:08 AM UTC

Commit: 4c2f633 · View workflow run →

Effort: high

@fullsend-ai-review

Copy link
Copy Markdown

🤖 Finished Review · ❌ Failure (ensuring provider "github-ro": provider create "github-ro" failed: exit status 1 (output: Error: × code: 'Client specified an invalid argument', message: "provider │ credentials are not declared by pr…) · Started 11:42 AM UTC · Completed 11:42 AM UTC

Commit: 3d7d755 · View workflow run →

Effort: high

@fullsend-ai-review

Copy link
Copy Markdown

🤖 Finished Review · ❌ Failure (ensuring provider "vertex-ai": provider create "vertex-ai" failed: exit status 1 (output: Error: × code: 'Client specified an invalid argument', message: "provider │ credentials are not declared by pr…) · Started 9:27 PM UTC · Completed 9:27 PM UTC

Commit: 1d0751e · View workflow run →

Effort: high

@fullsend-ai-review

Copy link
Copy Markdown

🤖 Finished Review · ❌ Failure (ensuring provider "vertex-ai": provider create "vertex-ai" failed: exit status 1 (output: Error: × code: 'Client specified an invalid argument', message: "provider │ credentials are not declared by pr…) · Started 10:32 AM UTC · Completed 10:32 AM UTC

Commit: 0355acb · View workflow run →

Effort: high

@fullsend-ai-review

Copy link
Copy Markdown

🤖 Finished Review · ❌ Failure (ensuring provider "github-ro": provider create "github-ro" failed: exit status 1 (output: Error: × code: 'Client specified an invalid argument', message: "provider │ credentials are not declared by pr…) · Started 2:10 PM UTC · Completed 2:11 PM UTC

Commit: e50b438 · View workflow run →

Effort: high

@fullsend-ai-review

Copy link
Copy Markdown

/fs-review

fullsend-ai-review[bot]

This comment was marked as outdated.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file go Pull requests that update Go code main ready-for-merge All reviewers approved — ready to merge renovate risk/moderate PR risk: moderate size: XXL

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants