Skip to content

fix(deps): update module github.com/shipwright-io/build to v0.20.13 - #480

Open
red-hat-konflux-kflux-prd-rh02[bot] wants to merge 1 commit into
mainfrom
konflux/mintmaker/main/github.com-shipwright-io-build-0.x
Open

fix(deps): update module github.com/shipwright-io/build to v0.20.13#480
red-hat-konflux-kflux-prd-rh02[bot] wants to merge 1 commit into
mainfrom
konflux/mintmaker/main/github.com-shipwright-io-build-0.x

Conversation

@red-hat-konflux-kflux-prd-rh02

@red-hat-konflux-kflux-prd-rh02 red-hat-konflux-kflux-prd-rh02 Bot commented Aug 5, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
github.com/shipwright-io/build v0.18.3v0.20.13 age confidence

Warning

Some dependencies could not be looked up. Check the warning logs for more information.


Release Notes

shipwright-io/build (github.com/shipwright-io/build)

v0.20.13: Shipwright Build release v0.20.13

Compare Source

Release changes since v0.20.12

None. This is a rebuild of all components to address vulnerabilities in the base images.

To see a list of addressed vulnerabilities, please refer to #​2296

Features

Fixes

API Changes

Docs

Misc

v0.20.12: Shipwright Build release v0.20.12

Compare Source

Release changes since v0.20.11

None. This is a rebuild of all components to address vulnerabilities in the base images and in Go libraries.

To see a list of addressed vulnerabilities, please refer to #​2296

Features

Fixes

API Changes

Docs

Misc

#​2297 by @​SaschaSchwarze0: Update github.com/go-git/go-git/v5 from v5.19.1 to v5.19.2 / Update github.com/google/cel-go from v0.28.0 to v0.30.0

v0.20.11: Shipwright Build release v0.20.11

Compare Source

Release changes since v0.20.10

None. This is a rebuild of all components to address vulnerabilities in the base images.

To see a list of addressed vulnerabilities, please refer to #​2291

Features

Fixes

API Changes

Docs

Misc

v0.20.10: Shipwright Build release v0.20.10

Compare Source

Release changes since v0.20.9

None. This is a rebuild of all components to address vulnerabilities in the Go standard libraries.

To see a list of addressed vulnerabilities, please refer to #​2289

Features

Fixes

API Changes

Docs

Misc

v0.20.9: Shipwright Build release v0.20.9

Compare Source

Release changes since v0.20.8

None. This is a rebuild of all components to address vulnerabilities in the base images.

To see a list of addressed vulnerabilities, please refer to #​2287

Features

Fixes

API Changes

Docs

Misc

v0.20.8: Shipwright Build release v0.20.8

Compare Source

Release changes since v0.20.7

None. This is a rebuild of all components to address vulnerabilities in the base images.

To see a list of addressed vulnerabilities, please refer to #​2281

Features

Fixes

API Changes

Docs

Misc

v0.20.7: Shipwright Build release v0.20.7

Compare Source

Release changes since v0.20.6

None. This is a rebuild of all components to address vulnerabilities in the base images and Go dependencies.

To see a list of addressed vulnerabilities, please refer to #​2267

Features

Fixes

API Changes

Docs

Misc

#​2272 by @​SaschaSchwarze0: Update github.com/klauspost/compress from v1.18.5 to v1.18.7 to address GHSA-259r-337f-4rfw

#​2269 by @​SaschaSchwarze0: Update go.opentelemetry.io/otel from v1.43.0 to v1.44.0

v0.20.6: Shipwright Build release v0.20.6

Compare Source

Release changes since v0.20.5

None. This is a rebuild of all components to address vulnerabilities in the base images and Go dependencies.

To see a list of addressed vulnerabilities, please refer to #​2260

Features

Fixes

API Changes

Docs

Misc

#​2262 by @​SaschaSchwarze0: Update golang.org/x/net from v0.55.0 to v0.56.0 to address CVE-2026-46600 / Update golang.org/x/text from v0.37.0 to v0.39.0 to address CVE-2026-56852

v0.20.5: Shipwright Build release v0.20.5

Compare Source

Release changes since v0.20.4

None. This is a rebuild of all components to address vulnerabilities in the base images.

To see a list of addressed vulnerabilities, please refer to #​2253

Features

Fixes

API Changes

Docs

Misc

v0.20.4: Shipwright Build release v0.20.4

Compare Source

Release changes since v0.20.3

None. This is a rebuild of all components to address vulnerabilities in the Go standard libraries.

To see a list of addressed vulnerabilities, please refer to #​2251

Features

Fixes

API Changes

Docs

Misc

v0.20.3: Shipwright Build release v0.20.3

Compare Source

Release changes since v0.20.2

None. This is a rebuild of all components to address vulnerabilities in the base images.

To see a list of addressed vulnerabilities, please refer to #​2247

Features

Fixes

API Changes

Docs

Misc

v0.20.2: Shipwright Build release v0.20.2

Compare Source

Release changes since v0.20.1

None. This is a rebuild of all components to address vulnerabilities in the base images.

To see a list of addressed vulnerabilities, please refer to #​2240

Features

Fixes

API Changes

Docs

Misc

v0.20.1: Shipwright Build release v0.20.1

Compare Source

Release changes since v0.20.0

None. This is a rebuild of all components to address vulnerabilities in the base images.

To see a list of addressed vulnerabilities, please refer to #​2240

Features

Fixes

API Changes

Docs

Misc

v0.20.0: Shipwright Build release v0.20.0

Compare Source

Release changes since v0.19.0

Features

#​2159 by @​sgaist: The buildpacks sample build strategies now allow the configuration of insecure registries in a fashion similar to buildah and source-to-image.

#​2150 by @​officialasishkumar: Improved experience of kubectl patch for build strategies and cluster build strategies by using step name as identifier

Fixes

API Changes

Docs

#​2175 by @​kaizakin: You are not anymore required to use the build.shipwright.io/referenced.secret=true annotation on Secrets to cause related Builds to be reconciled on Secret changes

Misc

#​2223 by @​psrvere: The minimum supported Tekton version is now v1.3. The minimum supported Kubernetes version is now v1.34.

#​2213 by @​SaschaSchwarze0: Update golang.org/x/crypto and golang.org/x/net to address CVE-2026-25680, CVE-2026-25681, CVE-2026-27136, CVE-2026-39821, CVE-2026-39827, CVE-2026-39828, CVE-2026-39829, CVE-2026-39830, CVE-2026-39831, CVE-2026-39832, CVE-2026-39833, CVE-2026-39834, CVE-2026-39835, CVE-2026-42502, CVE-2026-42506, CVE-2026-42508, CVE-2026-46595, CVE-2026-46597, CVE-2026-46598

#​2183 by @​SaschaSchwarze0: Update to the new latest Tekton LTS release v1.12.0

#​2167 by @​shipwright-ci-bot: Update to the new latest Tekton LTS release v1.9.3

#​2149 by @​officialasishkumar: Increase ko build strategy requests and limits to meet most real world use cases

#​2137 by @​shipwright-ci-bot: Update to the new latest Tekton LTS release v1.9.2

#​2131 by @​kaizakin: Added gingkgo labels support to differentiate PipelineRun and TaskRun tests

#​2127 by @​anchi205: Added spec.output.platforms field to Build and BuildRun APIs, allowing users to define target OS/architecture combinations for multi-arch image builds.

v0.19.8: Shipwright Build release v0.19.8

Compare Source

Release changes since v0.19.7

None. This is a rebuild of all components to address vulnerabilities in the base images.

To see a list of addressed vulnerabilities, please refer to #​2225

Features

Fixes

API Changes

Docs

Misc

v0.19.7: Shipwright Build release v0.19.7

Compare Source

Release changes since v0.19.6

None. This is a rebuild of all components to address vulnerabilities in the base images and in Golang.

To see a list of addressed vulnerabilities, please refer to #​2217

Features

Fixes

API Changes

Docs

Misc

v0.19.6: Shipwright Build release v0.19.6

Compare Source

Release changes since v0.19.5

To see a list of addressed vulnerabilities, please refer to #​2212

Features

Fixes

API Changes

Docs

Misc

#​2214 by @​SaschaSchwarze0: Update golang.org/x/crypto and golang.org/x/net to address CVE-2026-25680, CVE-2026-25681, CVE-2026-27136, CVE-2026-39821, CVE-2026-39827, CVE-2026-39828, CVE-2026-39829, CVE-2026-39830, CVE-2026-39831, CVE-2026-39832, CVE-2026-39833, CVE-2026-39834, CVE-2026-39835, CVE-2026-42502, CVE-2026-42506, CVE-2026-42508, CVE-2026-46595, CVE-2026-46597, CVE-2026-46598

v0.19.5: Shipwright Build release v0.19.5

Compare Source

Release changes since v0.19.4

None. This is a rebuild of all components to address vulnerabilities in the base images.

To see a list of addressed vulnerabilities, please refer to #​2196

Features

Fixes

API Changes

Docs

Misc

v0.19.4: Shipwright Build release v0.19.4

Compare Source

Release changes since v0.19.3

To see a list of addressed vulnerabilities, please refer to #​2190

Features

Fixes

API Changes

Docs

Misc

#​2191 by @​SaschaSchwarze0: Update golang.org/x/net from v0.51.0 to v0.53.0 to fix CVE-2026-33814

v0.19.3: Shipwright Build release v0.19.3

Compare Source

Release changes since v0.19.2

To see a list of addressed vulnerabilities, please refer to #​2141

Features

Fixes

API Changes

Docs

Misc

#​2162 by @​SaschaSchwarze0: Update github.com/tektoncd/pipeline from v1.9.1 to v1.9.2, update google.golang.org/grpc from v1.77.0 to v1.79.3, update github.com/go-git/go-git/v5 from v5.17.0 to v5.17.1

v0.19.2: Shipwright Build release v0.19.2

Compare Source

Release changes since v0.19.1

None. This is a rebuild of all components to address vulnerabilities in the base images.

To see a list of addressed vulnerabilities, please refer to #​2138

Features

Fixes

API Changes

Docs

Misc

v0.19.1: Shipwright Build release v0.19.1

Compare Source

Release changes since v0.19.0

None. This is a rebuild of all components to address vulnerabilities in the base images.

To see a list of addressed vulnerabilities, please refer to #​2124

Features

Fixes

API Changes

Docs

Misc

v0.19.0: Shipwright Build release v0.19.0

Compare Source

Release changes since v0.18.0

Features

#​2108 by @​anchi205: You can now define stepResources in a Build or BuildRun APIs to override the resources of steps defined in the BuildStrategy or ClusterBuildStrategy.

#​2079 by @​IrvingMg: You can now specify a runtimeClassName on a Build and BuildRun to use alternative container runtimes.

Fixes

#​2101 by @​adambkaplan: Update Tekton manifests URL to infra.tekton.dev

#​2082 by @​SaschaSchwarze0: The ko build strategy is fixed for Go modules that have dependencies but no vendoring.

API Changes

#​2108 by @​anchi205: You can now define stepResources in a Build or BuildRun APIs to override the resources of steps defined in the BuildStrategy or ClusterBuildStrategy.

#​2079 by @​IrvingMg: You can now specify a runtimeClassName on a Build and BuildRun to use alternative container runtimes.

Docs

Misc

#​2113 by @​SaschaSchwarze0: The minimum supported Kubernetes version is now v1.33. The minimum supported Tekton version is v1.0.

#​2109 by @​shipwright-ci-bot: Update to the new latest Tekton LTS release v1.9.1

#​2105 by @​SaschaSchwarze0: We are scanning our images during our regular scans now with Grype in addition to Trivy as Trivy is not yet capable to find vulnerabilities in RedHat UBI 10 which we are using as our base image.

#​2098 by @​shipwright-ci-bot: Update to the new latest Tekton LTS release v1.9.0

#​2056 by @​ayushsatyam146: Added PipelineRun execution mode as an alternative to TaskRun for multi-pod build execution with PVC-based workspace storage, laying the foundation for future multi-architecture build support.

v0.18.4: Shipwright Build release v0.18.4

Compare Source

Release changes since v0.18.3

To see a list of addressed vulnerabilities, please refer to #​2110

Features

Fixes

API Changes

Docs

Misc

#​2112 by @​SaschaSchwarze0: Update github.com/go-git/go-git/v5 from v5.16.3 to v5.16.5 to address GO-2026-4473


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

To execute skipped test pipelines write comment /ok-to-test.


Documentation

Find out how to configure dependency updates in MintMaker documentation or see all available configuration options in Renovate documentation.

@red-hat-konflux-kflux-prd-rh02

red-hat-konflux-kflux-prd-rh02 Bot commented Aug 5, 2026

Copy link
Copy Markdown
Contributor Author

ℹ️ Artifact update notice

File name: go.mod

In order to perform the update(s) described in the table above, Renovate ran the go get command, which resulted in the following additional change(s):

  • 3 additional dependencies were updated

Details:

Package Change
k8s.io/apiserver v0.36.0 -> v0.36.1
k8s.io/apiextensions-apiserver v0.36.0 -> v0.36.1
k8s.io/component-base v0.36.0 -> v0.36.1

@red-hat-konflux-kflux-prd-rh02
red-hat-konflux-kflux-prd-rh02 Bot force-pushed the konflux/mintmaker/main/github.com-shipwright-io-build-0.x branch 3 times, most recently from 52d9824 to aad44b4 Compare August 6, 2026 08:13
@ambient-code

ambient-code Bot commented Aug 6, 2026

Copy link
Copy Markdown

Automated Review Summary

PR: fix(deps): update module github.com/shipwright-io/build to v0.20.8

Checks performed:

  1. go.mod modification? Yes — updates shipwright-io/build from v0.18.3 to v0.20.8 and transitive deps. This is the only Go module in the repo tree, no other sub-project go.mod updates needed.

  2. CI status: ❌ All checks failing. Root cause: shipwright v0.20.8 transitively requires k8s.io/* v0.36.x and sets go 1.26.3 in go.mod, but CI uses Go 1.25 (GOTOOLCHAIN=local):

    Error: can't load config: the Go language version (go1.25) used to build golangci-lint is lower than the targeted Go version (1.26.3)
    
  3. k8s version bump? ⚠️ YES — k8s bump via shipwright transitive dependency: This PR brings in k8s.io/api v0.36.1 and k8s.io/apimachinery v0.36.1 (Kubernetes 1.32), up from our current v0.35.7. This is the same k8s 0.36.x bump pattern seen in PRs fix(deps): update module github.com/sigstore/cosign/v3 to v3.1.3 #482, fix(deps): update module github.com/tektoncd/pipeline to v1.15.0 #484, and fix(deps): update module sigs.k8s.io/controller-runtime to v0.24.1 - autoclosed #485.

    @bennyz @bkhizgiy — This is the fourth PR in this batch that independently forces a k8s 0.35.x → 0.36.x jump:

    These should be handled as a single coordinated k8s 0.36.x upgrade, not four separate PRs. Questions:

    • Is shipwright v0.18.x compatible with k8s 0.35.x still maintained?
    • Are there CVEs in shipwright v0.18.3 that make v0.20.8 urgent?
    • Should we do a deliberate k8s 1.32 upgrade and pull all these in together?

Assessment: 🔴 Do not merge as-is. Part of a cluster requiring a coordinated k8s minor version upgrade (see also #482, #484, #485). Recommend closing these four PRs and opening a single, deliberate k8s 0.36.x upgrade PR.

@red-hat-konflux-kflux-prd-rh02
red-hat-konflux-kflux-prd-rh02 Bot force-pushed the konflux/mintmaker/main/github.com-shipwright-io-build-0.x branch 15 times, most recently from c3cdd47 to c97683c Compare August 11, 2026 20:10
@red-hat-konflux-kflux-prd-rh02 red-hat-konflux-kflux-prd-rh02 Bot changed the title fix(deps): update module github.com/shipwright-io/build to v0.20.8 fix(deps): update module github.com/shipwright-io/build to v0.20.9 Aug 12, 2026
@red-hat-konflux-kflux-prd-rh02
red-hat-konflux-kflux-prd-rh02 Bot force-pushed the konflux/mintmaker/main/github.com-shipwright-io-build-0.x branch 3 times, most recently from bde5e1e to 509bf9f Compare August 14, 2026 08:13
@red-hat-konflux-kflux-prd-rh02 red-hat-konflux-kflux-prd-rh02 Bot changed the title fix(deps): update module github.com/shipwright-io/build to v0.20.9 fix(deps): update module github.com/shipwright-io/build to v0.20.10 Aug 14, 2026
@red-hat-konflux-kflux-prd-rh02
red-hat-konflux-kflux-prd-rh02 Bot force-pushed the konflux/mintmaker/main/github.com-shipwright-io-build-0.x branch 4 times, most recently from a1bdb29 to 901efe9 Compare August 15, 2026 12:12
@red-hat-konflux-kflux-prd-rh02
red-hat-konflux-kflux-prd-rh02 Bot force-pushed the konflux/mintmaker/main/github.com-shipwright-io-build-0.x branch 7 times, most recently from 1846836 to 5e31492 Compare August 17, 2026 12:06
@red-hat-konflux-kflux-prd-rh02 red-hat-konflux-kflux-prd-rh02 Bot changed the title fix(deps): update module github.com/shipwright-io/build to v0.20.10 fix(deps): update module github.com/shipwright-io/build to v0.20.11 Aug 17, 2026
@red-hat-konflux-kflux-prd-rh02
red-hat-konflux-kflux-prd-rh02 Bot force-pushed the konflux/mintmaker/main/github.com-shipwright-io-build-0.x branch 7 times, most recently from f0de0d8 to 5cfda67 Compare August 22, 2026 12:11
@red-hat-konflux-kflux-prd-rh02 red-hat-konflux-kflux-prd-rh02 Bot changed the title fix(deps): update module github.com/shipwright-io/build to v0.20.11 fix(deps): update module github.com/shipwright-io/build to v0.20.13 Aug 22, 2026
@red-hat-konflux-kflux-prd-rh02
red-hat-konflux-kflux-prd-rh02 Bot force-pushed the konflux/mintmaker/main/github.com-shipwright-io-build-0.x branch 8 times, most recently from 0c16667 to fc1974e Compare August 26, 2026 16:11
@bennyz
bennyz enabled auto-merge August 26, 2026 16:30
@bennyz
bennyz added this pull request to the merge queue Aug 26, 2026
@github-merge-queue
github-merge-queue Bot removed this pull request from the merge queue due to a conflict with the base branch Aug 26, 2026
Signed-off-by: red-hat-konflux-kflux-prd-rh02 <190377777+red-hat-konflux-kflux-prd-rh02[bot]@users.noreply.github.com>
@red-hat-konflux-kflux-prd-rh02
red-hat-konflux-kflux-prd-rh02 Bot force-pushed the konflux/mintmaker/main/github.com-shipwright-io-build-0.x branch from fc1974e to ec744f7 Compare August 26, 2026 20:13
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant