Skip to content

Releases: chainguard-dev/apko

Release v1.2.14

25 May 01:03
Immutable release. Only release title and notes can be modified.
295b115

Choose a tag to compare

Changelog

  • 9034253 build(deps): bump chainguard.dev/sdk from 0.1.54 to 0.1.55 (#2236)
  • 00304a3 build(deps): bump github/codeql-action from 4.35.4 to 4.35.5 (#2237)
  • 71f084b build(deps): bump go.step.sm/crypto from 0.78.0 to 0.81.0 (#2235)
  • 2015c63 build(deps): bump google.golang.org/api from 0.278.0 to 0.279.0 (#2234)
  • 295b115 build(deps): bump k8s.io/apimachinery from 0.36.0 to 0.36.1 (#2232)
  • 31ce42d build(deps): bump step-security/harden-runner from 2.19.1 to 2.19.3 (#2233)
  • 289d761 build(deps): bump zizmorcore/zizmor-action from 0.5.3 to 0.5.5 (#2238)

Release v1.2.13

18 May 01:01
Immutable release. Only release title and notes can be modified.
3e9c1ec

Choose a tag to compare

Changelog

  • 22c16a5 build(deps): bump github.com/go-git/go-git/v5 from 5.18.0 to 5.19.0 in the go_modules group across 1 directory (#2222)
  • 7effda4 build(deps): bump github/codeql-action from 4.35.3 to 4.35.4 (#2225)
  • de34d75 build(deps): bump go.step.sm/crypto from 0.77.9 to 0.78.0 (#2224)
  • f6032be build(deps): bump golang.org/x/sys from 0.43.0 to 0.44.0 (#2221)
  • f85efc5 build(deps): bump google.golang.org/api from 0.277.0 to 0.278.0 (#2223)
  • 2483b20 build(deps): bump gopkg.in/ini.v1 from 1.67.1 to 1.67.2 (#2218)
  • f693e82 build(deps): bump sigstore/cosign-installer from 4.1.1 to 4.1.2 (#2226)
  • 3e9c1ec cpio: add FromLayers for multi-layer CPIO archives (#2216)

Release v1.2.12

11 May 00:58
Immutable release. Only release title and notes can be modified.
b7931ba

Choose a tag to compare

Changelog

  • b7931ba build(deps): bump chainguard-dev/actions from 1.6.17 to 1.6.19 (#2219)
  • 34a7530 fix(ci): harden against template injection and credential exposure (#2217)

Release v1.2.11

06 May 08:37
Immutable release. Only release title and notes can be modified.
bfd6776

Choose a tag to compare

Changelog

  • bfd6776 Tweak solver's same-origin heuristic (#2208)
  • 1564c07 build(deps): bump chainguard-dev/actions from 1.6.15 to 1.6.17 (#2215)
  • 4700edf build(deps): bump github.com/klauspost/compress from 1.18.5 to 1.18.6 (#2211)
  • b593d2c build(deps): bump github/codeql-action from 4.35.2 to 4.35.3 (#2213)
  • 9157b1a build(deps): bump google.golang.org/api from 0.276.0 to 0.277.0 (#2212)
  • 0e4728d build(deps): bump k8s.io/apimachinery from 0.35.4 to 0.36.0 (#2189)
  • d81a5d4 build(deps): bump step-security/harden-runner from 2.19.0 to 2.19.1 (#2214)
  • 5644a41 retry package fetch+expand on transient errors (#2210)

Release v1.2.10

04 May 00:54
Immutable release. Only release title and notes can be modified.
eebbe62

Choose a tag to compare

Changelog

  • 0670f22 build(deps): bump go.step.sm/crypto from 0.77.2 to 0.77.9 (#2209)
  • eebbe62 build(deps): bump goreleaser/goreleaser-action from 7.1.0 to 7.2.1 (#2207)

Release v1.2.9

28 Apr 19:13
Immutable release. Only release title and notes can be modified.
312a150

Choose a tag to compare

Changelog

  • 8d34c75 apk: verify package data hash against .PKGINFO for completeness (#2206)
  • 312a150 build(deps): bump chainguard.dev/sdk from 0.1.52 to 0.1.54 (#2199)
  • 5f7949b build(deps): bump github.com/invopop/jsonschema from 0.13.0 to 0.14.0 (#2197)
  • e7c2fdf build(deps): bump goreleaser/goreleaser-action from 7.0.0 to 7.1.0 (#2198)
  • 0d06d1c chore(zizmor): trigger zizmor on updates to dependabot config [PSEC-871] (#2186)
  • a7f10d8 ci: bump golangci-lint to v2.11 and clear new findings (#2205)
  • 8ccb1ed testdata: refresh apko-discover lock for rotated chainguard key (#2203)

Release v1.2.8

27 Apr 00:51
Immutable release. Only release title and notes can be modified.
beb2867

Choose a tag to compare

Changelog

  • beb2867 release: fetch full history for goreleaser changelog (#2192)

Release v1.2.7

23 Apr 19:48
Immutable release. Only release title and notes can be modified.
a118c3d

Choose a tag to compare

Changelog

  • a118c3d apk: verify package control hash against signed APKINDEX (#2191)

Release v1.2.6

22 Apr 15:26
Immutable release. Only release title and notes can be modified.
09b82d6

Choose a tag to compare

Changelog

  • 09b82d6 fs: strip special mode bits in OpenFile/WriteFile (#2188)

Release v1.2.5

22 Apr 13:08
Immutable release. Only release title and notes can be modified.
f5a96e1

Choose a tag to compare

Changelog

  • f5a96e1 fs: Scope all DirFS operations through os.Root (#2187)