Skip to content

Releases: chainloop-dev/chainloop

v0.85.1

Choose a tag to compare

@github-actions github-actions released this 03 May 11:24
aee5e72

What's Changed

  • Bump Helm Chart Version => v0.84.0 by @github-actions in #700
  • feat(ci): Adds chainloop to scorecards pipeline by @javirln in #710
  • feat(docs-deploy): Bump version of chainloop action to perform checkout before init by @javirln in #708
  • fix(scorecards): Move env variable to individual steps by @javirln in #713
  • fix(ci): Bump version of chainloop action by @javirln in #714
  • fix(ci): Use chainloop action on scorecard pipeline by @javirln in #715
  • feat(package): attest container images in helm package gh action by @jiparis in #701
  • feat(chainloop): add EVIDENCE material type by @jiparis in #702
  • feat(referrer): store backlinks unconditionally by @migmartri in #712
  • feat(ci): Adds chainloop to codeql pipeline by @javirln in #711
  • fix(ci): do not add materials on pull_request by @migmartri in #722
  • fix(cli): Send pagination message to stderr by @jiparis in #721
  • feat(cli): Workflow run can receive a status flag by @javirln in #723
  • feat(apitoken): Adds workflow run list policy to default apitoken policies by @javirln in #724
  • fix(cli): sanitize remote url by @migmartri in #729
  • feat(cli): Allow to pass --output flag to artifact download by @javirln in #726
  • feat(cli): add json output to attestation push by @migmartri in #730
  • feat(backend): ATTESTATION material type by @jiparis in #727
  • feat(ci): Declarative Chainloop contracts by @javirln in #731
  • feat(controlplane): verify that dependent attestations exist by @migmartri in #732
  • Bump Helm Chart Version => v0.85.0 by @github-actions in #734
  • feat(ci): Add README.md to contracts and fix helm package contract by @javirln in #733
  • feat(ci): Use reusable workflow for sync contracts by @javirln in #737
  • fix(ci): Only run contract sync on changes in contracts path by @javirln in #738
  • fix(ci): Fixes level of indentation by @javirln in #739
  • feat(ci): Update bedrock releases contract to add missing binaries by @javirln in #741
  • feat(ci): Update release pipeline to include all architecture binaries by @javirln in #742
  • feat(ci): Updatees contracts' README file by @javirln in #743
  • feat(ci): Update contract names by @javirln in #744
  • chore: validate dependent attestation in referrer endpoint by @migmartri in #745

Full Changelog: v0.84.0...v0.85.1

v0.85.0

Choose a tag to compare

@github-actions github-actions released this 30 Apr 10:57
a5af520

The new core contributors @javirln and @jiparis have been busy preparing this new release 🚀

Highlights

New Material types

You can now attest two new kinds of material types, EVIDENCE and ATTESTATION.

  • To differentiate between software artifacts and pieces of evidence, we have introduced an Evidence type. It allows you to provide arbitrary information that can be attached to your attestations
  • The ATTESTATION type can be used to connect different attestations generated by chainloop and in practice is a mechanism to represent dependencies.

What's Changed

  • Bump Helm Chart Version => v0.84.0 by @github-actions in #700
  • feat(ci): Adds chainloop to scorecards pipeline by @javirln in #710
  • feat(docs-deploy): Bump version of chainloop action to perform checkout before init by @javirln in #708
  • fix(scorecards): Move env variable to individual steps by @javirln in #713
  • fix(ci): Bump version of chainloop action by @javirln in #714
  • fix(ci): Use chainloop action on scorecard pipeline by @javirln in #715
  • feat(package): attest container images in helm package gh action by @jiparis in #701
  • feat(chainloop): add EVIDENCE material type by @jiparis in #702
  • feat(referrer): store backlinks unconditionally by @migmartri in #712
  • feat(ci): Adds chainloop to codeql pipeline by @javirln in #711
  • fix(ci): do not add materials on pull_request by @migmartri in #722
  • fix(cli): Send pagination message to stderr by @jiparis in #721
  • feat(cli): Workflow run can receive a status flag by @javirln in #723
  • feat(apitoken): Adds workflow run list policy to default apitoken policies by @javirln in #724
  • fix(cli): sanitize remote url by @migmartri in #729
  • feat(cli): Allow to pass --output flag to artifact download by @javirln in #726
  • feat(cli): add json output to attestation push by @migmartri in #730
  • feat(backend): ATTESTATION material type by @jiparis in #727
  • feat(ci): Declarative Chainloop contracts by @javirln in #731
  • feat(controlplane): verify that dependent attestations exist by @migmartri in #732

Full Changelog: v0.84.0...v0.85.0

v0.84.0

Choose a tag to compare

@github-actions github-actions released this 25 Apr 16:25
0958403

Changelog

  • 0958403 feat(docs): Update contracts' examples to include HELM_CHART material (#694)
  • b66bd42 feat(ci): Attest Chainloop Helm Chart on every release (#696)
  • a2e5cc2 Bump Helm Chart Version => v0.83.0 (#692)

v0.83.0

Choose a tag to compare

@github-actions github-actions released this 24 Apr 10:51
e8d43fa

And with this release we welcome to new Chainloop core maintainers @javirln and @jiparis 🚀

Highlights

Helm Chart Support

You can now provide Helm Charts as a piece of evidence in your attestations, where they will get validated and uploaded to the content addressable storage.

What's Changed

  • Bump Helm Chart Version => v0.82.0 by @github-actions in #676
  • docs: document API tokens by @migmartri in #675
  • chore(deps): Bump golang.org/x/net from 0.22.0 to 0.23.0 by @dependabot in #679
  • fix(makefile): fixes atlas installation by using its own install script by @jiparis in #688
  • feat(materials): Helm Chart material support by @javirln in #689
  • feat(docs): Update documentation to reflect the HELM_CHART material type by @javirln in #691
  • fix(controlplane): return Notfound errror if robot account doesn't exist by @jiparis in #690

Full Changelog: v0.82.0...v0.83.0

v0.82.0

Choose a tag to compare

@github-actions github-actions released this 16 Apr 13:18
ba8b595

What's Changed

Full Changelog: v0.81.2...v0.82.0

v0.81.2

Choose a tag to compare

@github-actions github-actions released this 04 Apr 18:55
66b5dae

What's Changed

  • Bump Helm Chart Version => v0.80.1 by @github-actions in #614
  • Improving documentation deployment + adding Chainloop by @danlishka in #610
  • Updating references after documentation migration by @danlishka in #611
  • chore(deps): Bump google.golang.org/protobuf from 1.31.0 to 1.33.0 by @dependabot in #615
  • docs: add dagger demo by @migmartri in #616
  • fix(authz): add read permissions in workflow.View by @migmartri in #617
  • chore(deps): Bump github.com/jackc/pgx/v5 from 5.4.3 to 5.5.4 by @dependabot in #619
  • fix(docs-release) Fixed docs release and chainloop integration by @danlishka in #621
  • chore(deps): Bump follow-redirects from 1.15.4 to 1.15.6 in /docs by @dependabot in #620
  • fix(docs-release) Fixed docs release and chainloop integration by @danlishka in #623
  • chore(api): handle context.Canceled error by @migmartri in #628
  • chore(deps): Bump webpack-dev-middleware from 5.3.3 to 5.3.4 in /docs by @dependabot in #631
  • chore(deps): Bump github.com/docker/docker from 24.0.7+incompatible to 24.0.9+incompatible by @dependabot in #626
  • chore: upgrade dependencies by @migmartri in #630
  • chore(ci): bump actions by @migmartri in #632
  • fix(cli): allow updating only the contract description by @migmartri in #633
  • docs: dependency track parentID field by @sedan07 in #637
  • fix(controlplane): handle not-found contract on update by @migmartri in #638
  • feat(controlplane): always store the digest of the attestation by @migmartri in #639
  • chore(deps): Bump express from 4.18.2 to 4.19.2 in /docs by @dependabot in #634
  • fix(cli): send digest to stderr by @migmartri in #642
  • feat(controlplane): add extra info to discovery endpoint by @migmartri in #641
  • feat(api): support set workflow visibility on creation by @migmartri in #640
  • feat(controlplane): add unique name to registered integrations by @migmartri in #643
  • chore(ci): bump cosign version on release process by @migmartri in #644
  • feat: add contract selection on workflow update by @migmartri in #646
  • Bump Helm Chart Version => v0.81.0 by @github-actions in #647
  • chore: upgrade aws-sdk by @migmartri in #648
  • Bump Helm Chart Version => v0.81.1 by @github-actions in #650
  • dagger: upgrade module to v0.81.1 by @migmartri in #651
  • ci: update module by @migmartri in #652
  • chore: remove unused generated typescript files by @migmartri in #649
  • fix(api): validate material type by @migmartri in #653
  • chore: upgrade golang 1.22.2 by @migmartri in #654
  • fix(api); validate runner type by @migmartri in #655

Full Changelog: v0.80.1...v0.81.2

v0.81.1

Choose a tag to compare

@github-actions github-actions released this 02 Apr 14:06
1e15cad

What's Changed

  • Bump Helm Chart Version => v0.80.1 by @github-actions in #614
  • Improving documentation deployment + adding Chainloop by @danlishka in #610
  • Updating references after documentation migration by @danlishka in #611
  • chore(deps): Bump google.golang.org/protobuf from 1.31.0 to 1.33.0 by @dependabot in #615
  • docs: add dagger demo by @migmartri in #616
  • fix(authz): add read permissions in workflow.View by @migmartri in #617
  • chore(deps): Bump github.com/jackc/pgx/v5 from 5.4.3 to 5.5.4 by @dependabot in #619
  • fix(docs-release) Fixed docs release and chainloop integration by @danlishka in #621
  • chore(deps): Bump follow-redirects from 1.15.4 to 1.15.6 in /docs by @dependabot in #620
  • fix(docs-release) Fixed docs release and chainloop integration by @danlishka in #623
  • chore(api): handle context.Canceled error by @migmartri in #628
  • chore(deps): Bump webpack-dev-middleware from 5.3.3 to 5.3.4 in /docs by @dependabot in #631
  • chore(deps): Bump github.com/docker/docker from 24.0.7+incompatible to 24.0.9+incompatible by @dependabot in #626
  • chore: upgrade dependencies by @migmartri in #630
  • chore(ci): bump actions by @migmartri in #632
  • fix(cli): allow updating only the contract description by @migmartri in #633
  • docs: dependency track parentID field by @sedan07 in #637
  • fix(controlplane): handle not-found contract on update by @migmartri in #638
  • feat(controlplane): always store the digest of the attestation by @migmartri in #639
  • chore(deps): Bump express from 4.18.2 to 4.19.2 in /docs by @dependabot in #634
  • fix(cli): send digest to stderr by @migmartri in #642
  • feat(controlplane): add extra info to discovery endpoint by @migmartri in #641
  • feat(api): support set workflow visibility on creation by @migmartri in #640
  • feat(controlplane): add unique name to registered integrations by @migmartri in #643
  • chore(ci): bump cosign version on release process by @migmartri in #644
  • feat: add contract selection on workflow update by @migmartri in #646
  • Bump Helm Chart Version => v0.81.0 by @github-actions in #647
  • chore: upgrade aws-sdk by @migmartri in #648

Full Changelog: v0.80.1...v0.81.1

v0.81.0

Choose a tag to compare

@github-actions github-actions released this 02 Apr 10:59
b972089

What's Changed

  • Bump Helm Chart Version => v0.80.1 by @github-actions in #614
  • Improving documentation deployment + adding Chainloop by @danlishka in #610
  • Updating references after documentation migration by @danlishka in #611
  • chore(deps): Bump google.golang.org/protobuf from 1.31.0 to 1.33.0 by @dependabot in #615
  • docs: add dagger demo by @migmartri in #616
  • fix(authz): add read permissions in workflow.View by @migmartri in #617
  • chore(deps): Bump github.com/jackc/pgx/v5 from 5.4.3 to 5.5.4 by @dependabot in #619
  • fix(docs-release) Fixed docs release and chainloop integration by @danlishka in #621
  • chore(deps): Bump follow-redirects from 1.15.4 to 1.15.6 in /docs by @dependabot in #620
  • fix(docs-release) Fixed docs release and chainloop integration by @danlishka in #623
  • chore(api): handle context.Canceled error by @migmartri in #628
  • chore(deps): Bump webpack-dev-middleware from 5.3.3 to 5.3.4 in /docs by @dependabot in #631
  • chore(deps): Bump github.com/docker/docker from 24.0.7+incompatible to 24.0.9+incompatible by @dependabot in #626
  • chore: upgrade dependencies by @migmartri in #630
  • chore(ci): bump actions by @migmartri in #632
  • fix(cli): allow updating only the contract description by @migmartri in #633
  • docs: dependency track parentID field by @sedan07 in #637
  • fix(controlplane): handle not-found contract on update by @migmartri in #638
  • feat(controlplane): always store the digest of the attestation by @migmartri in #639
  • chore(deps): Bump express from 4.18.2 to 4.19.2 in /docs by @dependabot in #634
  • fix(cli): send digest to stderr by @migmartri in #642
  • feat(controlplane): add extra info to discovery endpoint by @migmartri in #641
  • feat(api): support set workflow visibility on creation by @migmartri in #640
  • feat(controlplane): add unique name to registered integrations by @migmartri in #643
  • chore(ci): bump cosign version on release process by @migmartri in #644
  • feat: add contract selection on workflow update by @migmartri in #646

Full Changelog: v0.80.1...v0.81.0

v0.80.1

Choose a tag to compare

@github-actions github-actions released this 13 Mar 12:44
09ebb28

What's Changed

  • Bump Helm Chart Version => v0.75.2 by @github-actions in #575
  • chore: upgrade Dagger module for Chainloop v0.72.2 by @migmartri in #576
  • chore(deps): Bump gopkg.in/go-jose/go-jose.v2 from 2.6.1 to 2.6.3 by @dependabot in #579
  • chore(deps): Bump github.com/go-jose/go-jose/v3 from 3.0.1 to 3.0.3 by @dependabot in #580
  • feat(api): add workflow run describe API endpoint by @migmartri in #577
  • Let's take the Dagger module to the next level :) by @shykes in #581
  • chore(ci): disable dagger linter by @migmartri in #583
  • feat(metrics): add runs by day and update returned types by @migmartri in #584
  • chore: rename pagination options by @migmartri in #585
  • chore(docs): migrate Chainloop docs to the main repo by @danlishka in #568
  • feat(controlplane): support providing connection string by @migmartri in #592
  • chore(docs): upgrading docusaurus by @migmartri in #594
  • chore(dagger module): minor follow-up items for dagger module by @migmartri in #586
  • chore(deps): Bump the npm_and_yarn group group in /docs with 1 update by @dependabot in #597
  • fix(dagger): container authentication by @migmartri in #598
  • feat(dagger): sync method by @migmartri in #599
  • chore(ci): fix dagger linter by @migmartri in #604
  • feat(controlplane): make contract-names unique and DNS1123 compatible by @migmartri in #601
  • chore(deps): Bump github.com/jackc/pgx/v4 from 4.18.1 to 4.18.2 by @dependabot in #606
  • feat(controlplane): unique workflow name and formatted project by @migmartri in #605
  • docs: document dagger module and runner by @migmartri in #607
  • feat(controlplane): workflow contract description support by @migmartri in #608
  • Bump Helm Chart Version => v0.80.0 by @github-actions in #609
  • fix(controlplane): support soft-deleted items on name constraint by @migmartri in #613

New Contributors

Full Changelog: v0.75.2...v0.80.1

v0.80.0

Choose a tag to compare

@github-actions github-actions released this 13 Mar 09:49
134a1d9

What's Changed

  • Bump Helm Chart Version => v0.75.2 by @github-actions in #575
  • chore: upgrade Dagger module for Chainloop v0.72.2 by @migmartri in #576
  • chore(deps): Bump gopkg.in/go-jose/go-jose.v2 from 2.6.1 to 2.6.3 by @dependabot in #579
  • chore(deps): Bump github.com/go-jose/go-jose/v3 from 3.0.1 to 3.0.3 by @dependabot in #580
  • feat(api): add workflow run describe API endpoint by @migmartri in #577
  • Let's take the Dagger module to the next level :) by @shykes in #581
  • chore(ci): disable dagger linter by @migmartri in #583
  • feat(metrics): add runs by day and update returned types by @migmartri in #584
  • chore: rename pagination options by @migmartri in #585
  • chore(docs): migrate Chainloop docs to the main repo by @danlishka in #568
  • feat(controlplane): support providing connection string by @migmartri in #592
  • chore(docs): upgrading docusaurus by @migmartri in #594
  • chore(dagger module): minor follow-up items for dagger module by @migmartri in #586
  • chore(deps): Bump the npm_and_yarn group group in /docs with 1 update by @dependabot in #597
  • fix(dagger): container authentication by @migmartri in #598
  • feat(dagger): sync method by @migmartri in #599
  • chore(ci): fix dagger linter by @migmartri in #604
  • feat(controlplane): make contract-names unique and DNS1123 compatible by @migmartri in #601
  • chore(deps): Bump github.com/jackc/pgx/v4 from 4.18.1 to 4.18.2 by @dependabot in #606
  • feat(controlplane): unique workflow name and formatted project by @migmartri in #605
  • docs: document dagger module and runner by @migmartri in #607
  • feat(controlplane): workflow contract description support by @migmartri in #608

New Contributors

Full Changelog: v0.75.2...v0.80.0