Releases: sigstore/scaffolding
Releases · sigstore/scaffolding
v0.5.2
Changelog
Thanks to all contributors!
What's Changed
- Bump github.com/sigstore/sigstore from 1.4.5 to 1.4.6 by @dependabot in #486
- Exercise TSA in action/release tests. by @vaikas in #484
- Fix secret update by @vaikas in #487
Full Changelog: v0.5.1...v0.5.2
v0.5.1
v0.5.0
What's Changed
- Issue 450 2 by @vaikas in #467
- export FULCIO_GRPC_URL when installing scaffolding using GHA by @bobcallaway in #466
- Add initial release documentationl by @tstromberg in #403
- Remove meaningless tests. Test with k8s 1.25 by @vaikas in #468
- Bump golang.org/x/crypto from 0.1.0 to 0.2.0 by @dependabot in #471
- Bump k8s.io/api from 0.25.3 to 0.25.4 by @dependabot in #470
- Bump github.com/sigstore/rekor from 1.0.0 to 1.0.1 by @dependabot in #469
- Bump k8s.io/code-generator from 0.25.3 to 0.25.4 by @dependabot in #475
- Bump github.com/sigstore/timestamp-authority from 0.1.1 to 0.1.2 by @dependabot in #474
- Bump k8s.io/client-go from 0.25.3 to 0.25.4 by @dependabot in #472
- Add TSA certs to TUF root. by @vaikas in #477
- Update README diagram and add TSA. by @vaikas in #478
- Bump golang.org/x/crypto from 0.2.0 to 0.3.0 by @dependabot in #479
- Bump google.golang.org/grpc from 1.50.1 to 1.51.0 by @dependabot in #480
- increase trillian timeout to 5 min. by @vaikas in #481
- Install TSA if release > 0.5.0. Remove old cruft. by @vaikas in #482
New Contributors
- @tstromberg made their first contribution in #403
Full Changelog: v0.4.13...v0.5.0
v0.4.13
Changelog
- a4fbf80 Add tsa to scaffolding. (#464)
- e09d7b3 Delete unused github actions service account provisioning. (#428)
- 7b3c867 add fulcio-grpc as knative service (#463)
- 226db88 unpin setup-kind to stop using (#461)
- fc9e9e7 Bump github.com/prometheus/client_golang from 1.13.0 to 1.13.1 (#460)
- 0aef55f Terraform configuration for timestamp authority module (#455)
- f4b16c5 change redis to match version used in production (#456)
- c3445ab increase redis memory to prevent OOM errors in Rekor prod (#453)
- fb58c35 Revert "Terraform configuration for timestamp authority module (#449)" (#452)
- e644b1e Terraform configuration for timestamp authority module (#449)
- 5b82657 plumb ways to add metadata about targets. (#437)
- e8aff7a create gcp secret for mysql user and database name (#447)
- 24e5b33 drop 1.22.x usage (#448)
- c6847c6 Bump github.com/sigstore/fulcio from 0.6.0 to 1.0.0 (#443)
- 625efa4 Bump github.com/sigstore/sigstore from 1.4.4 to 1.4.5 (#444)
- e81fda3 Bump github.com/sigstore/rekor from 0.12.2 to 1.0.0 (#442)
- 616b7ab Bump github.com/sigstore/cosign from 1.13.0 to 1.13.1 (#445)
- abd8899 Bump github.com/google/certificate-transparency-go from 1.1.3 to 1.1.4 (#446)
- dc4f9e1 add var for ctlog shard mysql db name (#436)
- 0aadec7 allow specifying max resources available to node autoscaling for sigs… (#434)
- 755ce04 Fix another typo in metrics: oneof -> one_of (#433)
- 3099716 Fix typo in prober alerts. (#432)
- 846b655 pin knative version (#431)
- 7052248 Add in defaults for node pool autoscaling (#430)
Thanks to all contributors!
v0.4.12
What's Changed
- Update k8s log alert policy filters by @malancas in #400
- Create alert for prober verification failures by @codysoyland in #402
- Update alert name and condition name by @malancas in #404
- Define basic ctlog and dex availability SLOs. by @var-sdk in #405
- Alert on SLO burn rate by @var-sdk in #408
- use retryablehttp client for prober by @bobcallaway in #415
- Remove api.sigstore.dev CNAME record by @haydentherapper in #417
- Add explicit dependency on project_roles for all modules. by @var-sdk in #416
- Write the repository into secret, test air-gap mode. by @vaikas in #382
- add explicit dependencies on the associated metrics by @malancas in #407
- Add ctlog shards that create their own Cloud SQL instances. by @vaikas in #370
- Add allow lists for probed methods. by @var-sdk in #406
- Use GITHUB_OUTPUT instead of deprecated set-output by @cpanato in #418
- Configure cluster autoscaling from sigstore module by @priyawadhwa in #427
- add support for pre-existing secrets for CTLog. by @vaikas in #429
Full Changelog: v0.4.11...v0.4.12
v0.4.11
What's Changed
Full Changelog: v0.4.10...v0.4.11
v0.4.10
What's Changed
- Fix typo in config var name by @codysoyland in #392
- Create K8s pod metric based logs and alerts by @malancas in #391
- Remove broken probe by UUID and add probing for fulcio v2 read endpoints. by @var-sdk in #394
- Add availability. SLO definitions to terraform for Fulcio and Rekor by @var-sdk in #393
- Missed this one last time around. google-beta => google by @vaikas in #396
- Add prober flags for passing extra requests. by @var-sdk in #395
Full Changelog: v0.4.9...v0.4.10
v0.4.9
v0.4.8
What's Changed
- Add back support for RSA for legacy deployed CTLogs. by @vaikas in #341
- Remove /api/v1/index/retrieve endpoint from prober checks since it's experimental by @priyawadhwa in #340
- do not use setup-kind action from the head. by @vaikas in #345
- Wire missing oslogin parameter to oslogin module. by @var-sdk in #346
- Add kind support for v1.25.x by @vaikas in #343
- Update prober alerts to accept 201s on write APIs. by @var-sdk in #350
- Fix prober alerts. by @var-sdk in #353
- Correct a link in README.md. by @var-sdk in #355
- Use file based signer now that Rekor supports it. by @vaikas in #358
- Close the httpresponse.Body by @vaikas in #357
- Make tuf generic in prep for more fulcio / ctlog certs/keys. by @vaikas in #356
- Stop testing way older versions. build/test with go1.19 by @vaikas in #366
- add dns resources to service-level terraform by @bobcallaway in #336
- Use ctlog.config for creating certs, add managecaroots job, tests. by @vaikas in #352
- Trillian v0.12.1, Rekor v0.12.1, update go deps. by @vaikas in #367
- refactor signing release images by @cpanato in #368
- fix shellcheck by @cpanato in #376
Full Changelog: v0.4.7...v0.4.8
v0.4.6
What's Changed
- Disable noisy rekor alert by @priyawadhwa in #303
- Bump github.com/go-openapi/swag from 0.22.0 to 0.22.3 by @dependabot in #310
- Bump github.com/sigstore/cosign from 1.10.1 to 1.11.0 by @dependabot in #306
- Bump github/codeql-action from 2.1.18 to 2.1.19 by @dependabot in #305
- Bump sigstore/cosign-installer from 2.5.0 to 2.5.1 by @dependabot in #304
- Bump github.com/google/trillian from 1.4.2 to 1.5.0 by @dependabot in #309
- Bump github.com/sigstore/rekor from 0.10.0 to 0.11.0 by @dependabot in #311
- Bump all sigstore components. Use GODEBUG=netdns=go for fulcio. by @vaikas in #316
Full Changelog: v0.4.5...v0.4.6