fix(deps): update module github.com/shipwright-io/build to v0.20.13 - #480
Conversation
ℹ️ Artifact update noticeFile name: go.modIn order to perform the update(s) described in the table above, Renovate ran the
Details:
|
52d9824 to
aad44b4
Compare
Automated Review SummaryPR: Checks performed:
Assessment: 🔴 Do not merge as-is. Part of a cluster requiring a coordinated k8s minor version upgrade (see also #482, #484, #485). Recommend closing these four PRs and opening a single, deliberate k8s 0.36.x upgrade PR. |
c3cdd47 to
c97683c
Compare
bde5e1e to
509bf9f
Compare
a1bdb29 to
901efe9
Compare
1846836 to
5e31492
Compare
f0de0d8 to
5cfda67
Compare
0c16667 to
fc1974e
Compare
Signed-off-by: red-hat-konflux-kflux-prd-rh02 <190377777+red-hat-konflux-kflux-prd-rh02[bot]@users.noreply.github.com>
fc1974e to
ec744f7
Compare
This PR contains the following updates:
v0.18.3→v0.20.13Warning
Some dependencies could not be looked up. Check the warning logs for more information.
Release Notes
shipwright-io/build (github.com/shipwright-io/build)
v0.20.13: Shipwright Build release v0.20.13Compare Source
Release changes since v0.20.12
None. This is a rebuild of all components to address vulnerabilities in the base images.
To see a list of addressed vulnerabilities, please refer to #2296
Features
Fixes
API Changes
Docs
Misc
v0.20.12: Shipwright Build release v0.20.12Compare Source
Release changes since v0.20.11
None. This is a rebuild of all components to address vulnerabilities in the base images and in Go libraries.
To see a list of addressed vulnerabilities, please refer to #2296
Features
Fixes
API Changes
Docs
Misc
#2297 by @SaschaSchwarze0: Update github.com/go-git/go-git/v5 from v5.19.1 to v5.19.2 / Update github.com/google/cel-go from v0.28.0 to v0.30.0
v0.20.11: Shipwright Build release v0.20.11Compare Source
Release changes since v0.20.10
None. This is a rebuild of all components to address vulnerabilities in the base images.
To see a list of addressed vulnerabilities, please refer to #2291
Features
Fixes
API Changes
Docs
Misc
v0.20.10: Shipwright Build release v0.20.10Compare Source
Release changes since v0.20.9
None. This is a rebuild of all components to address vulnerabilities in the Go standard libraries.
To see a list of addressed vulnerabilities, please refer to #2289
Features
Fixes
API Changes
Docs
Misc
v0.20.9: Shipwright Build release v0.20.9Compare Source
Release changes since v0.20.8
None. This is a rebuild of all components to address vulnerabilities in the base images.
To see a list of addressed vulnerabilities, please refer to #2287
Features
Fixes
API Changes
Docs
Misc
v0.20.8: Shipwright Build release v0.20.8Compare Source
Release changes since v0.20.7
None. This is a rebuild of all components to address vulnerabilities in the base images.
To see a list of addressed vulnerabilities, please refer to #2281
Features
Fixes
API Changes
Docs
Misc
v0.20.7: Shipwright Build release v0.20.7Compare Source
Release changes since v0.20.6
None. This is a rebuild of all components to address vulnerabilities in the base images and Go dependencies.
To see a list of addressed vulnerabilities, please refer to #2267
Features
Fixes
API Changes
Docs
Misc
#2272 by @SaschaSchwarze0: Update github.com/klauspost/compress from v1.18.5 to v1.18.7 to address GHSA-259r-337f-4rfw
#2269 by @SaschaSchwarze0: Update go.opentelemetry.io/otel from v1.43.0 to v1.44.0
v0.20.6: Shipwright Build release v0.20.6Compare Source
Release changes since v0.20.5
None. This is a rebuild of all components to address vulnerabilities in the base images and Go dependencies.
To see a list of addressed vulnerabilities, please refer to #2260
Features
Fixes
API Changes
Docs
Misc
#2262 by @SaschaSchwarze0: Update golang.org/x/net from v0.55.0 to v0.56.0 to address CVE-2026-46600 / Update golang.org/x/text from v0.37.0 to v0.39.0 to address CVE-2026-56852
v0.20.5: Shipwright Build release v0.20.5Compare Source
Release changes since v0.20.4
None. This is a rebuild of all components to address vulnerabilities in the base images.
To see a list of addressed vulnerabilities, please refer to #2253
Features
Fixes
API Changes
Docs
Misc
v0.20.4: Shipwright Build release v0.20.4Compare Source
Release changes since v0.20.3
None. This is a rebuild of all components to address vulnerabilities in the Go standard libraries.
To see a list of addressed vulnerabilities, please refer to #2251
Features
Fixes
API Changes
Docs
Misc
v0.20.3: Shipwright Build release v0.20.3Compare Source
Release changes since v0.20.2
None. This is a rebuild of all components to address vulnerabilities in the base images.
To see a list of addressed vulnerabilities, please refer to #2247
Features
Fixes
API Changes
Docs
Misc
v0.20.2: Shipwright Build release v0.20.2Compare Source
Release changes since v0.20.1
None. This is a rebuild of all components to address vulnerabilities in the base images.
To see a list of addressed vulnerabilities, please refer to #2240
Features
Fixes
API Changes
Docs
Misc
v0.20.1: Shipwright Build release v0.20.1Compare Source
Release changes since v0.20.0
None. This is a rebuild of all components to address vulnerabilities in the base images.
To see a list of addressed vulnerabilities, please refer to #2240
Features
Fixes
API Changes
Docs
Misc
v0.20.0: Shipwright Build release v0.20.0Compare Source
Release changes since v0.19.0
Features
#2159 by @sgaist: The buildpacks sample build strategies now allow the configuration of insecure registries in a fashion similar to buildah and source-to-image.
#2150 by @officialasishkumar: Improved experience of
kubectl patchfor build strategies and cluster build strategies by using step name as identifierFixes
API Changes
Docs
#2175 by @kaizakin: You are not anymore required to use the
build.shipwright.io/referenced.secret=trueannotation on Secrets to cause related Builds to be reconciled on Secret changesMisc
#2223 by @psrvere: The minimum supported Tekton version is now v1.3. The minimum supported Kubernetes version is now v1.34.
#2213 by @SaschaSchwarze0: Update golang.org/x/crypto and golang.org/x/net to address CVE-2026-25680, CVE-2026-25681, CVE-2026-27136, CVE-2026-39821, CVE-2026-39827, CVE-2026-39828, CVE-2026-39829, CVE-2026-39830, CVE-2026-39831, CVE-2026-39832, CVE-2026-39833, CVE-2026-39834, CVE-2026-39835, CVE-2026-42502, CVE-2026-42506, CVE-2026-42508, CVE-2026-46595, CVE-2026-46597, CVE-2026-46598
#2183 by @SaschaSchwarze0: Update to the new latest Tekton LTS release v1.12.0
#2167 by @shipwright-ci-bot: Update to the new latest Tekton LTS release v1.9.3
#2149 by @officialasishkumar: Increase ko build strategy requests and limits to meet most real world use cases
#2137 by @shipwright-ci-bot: Update to the new latest Tekton LTS release v1.9.2
#2131 by @kaizakin: Added gingkgo labels support to differentiate PipelineRun and TaskRun tests
#2127 by @anchi205: Added spec.output.platforms field to Build and BuildRun APIs, allowing users to define target OS/architecture combinations for multi-arch image builds.
v0.19.8: Shipwright Build release v0.19.8Compare Source
Release changes since v0.19.7
None. This is a rebuild of all components to address vulnerabilities in the base images.
To see a list of addressed vulnerabilities, please refer to #2225
Features
Fixes
API Changes
Docs
Misc
v0.19.7: Shipwright Build release v0.19.7Compare Source
Release changes since v0.19.6
None. This is a rebuild of all components to address vulnerabilities in the base images and in Golang.
To see a list of addressed vulnerabilities, please refer to #2217
Features
Fixes
API Changes
Docs
Misc
v0.19.6: Shipwright Build release v0.19.6Compare Source
Release changes since v0.19.5
To see a list of addressed vulnerabilities, please refer to #2212
Features
Fixes
API Changes
Docs
Misc
#2214 by @SaschaSchwarze0: Update golang.org/x/crypto and golang.org/x/net to address CVE-2026-25680, CVE-2026-25681, CVE-2026-27136, CVE-2026-39821, CVE-2026-39827, CVE-2026-39828, CVE-2026-39829, CVE-2026-39830, CVE-2026-39831, CVE-2026-39832, CVE-2026-39833, CVE-2026-39834, CVE-2026-39835, CVE-2026-42502, CVE-2026-42506, CVE-2026-42508, CVE-2026-46595, CVE-2026-46597, CVE-2026-46598
v0.19.5: Shipwright Build release v0.19.5Compare Source
Release changes since v0.19.4
None. This is a rebuild of all components to address vulnerabilities in the base images.
To see a list of addressed vulnerabilities, please refer to #2196
Features
Fixes
API Changes
Docs
Misc
v0.19.4: Shipwright Build release v0.19.4Compare Source
Release changes since v0.19.3
To see a list of addressed vulnerabilities, please refer to #2190
Features
Fixes
API Changes
Docs
Misc
#2191 by @SaschaSchwarze0: Update golang.org/x/net from v0.51.0 to v0.53.0 to fix CVE-2026-33814
v0.19.3: Shipwright Build release v0.19.3Compare Source
Release changes since v0.19.2
To see a list of addressed vulnerabilities, please refer to #2141
Features
Fixes
API Changes
Docs
Misc
#2162 by @SaschaSchwarze0: Update github.com/tektoncd/pipeline from v1.9.1 to v1.9.2, update google.golang.org/grpc from v1.77.0 to v1.79.3, update github.com/go-git/go-git/v5 from v5.17.0 to v5.17.1
v0.19.2: Shipwright Build release v0.19.2Compare Source
Release changes since v0.19.1
None. This is a rebuild of all components to address vulnerabilities in the base images.
To see a list of addressed vulnerabilities, please refer to #2138
Features
Fixes
API Changes
Docs
Misc
v0.19.1: Shipwright Build release v0.19.1Compare Source
Release changes since v0.19.0
None. This is a rebuild of all components to address vulnerabilities in the base images.
To see a list of addressed vulnerabilities, please refer to #2124
Features
Fixes
API Changes
Docs
Misc
v0.19.0: Shipwright Build release v0.19.0Compare Source
Release changes since v0.18.0
Features
#2108 by @anchi205: You can now define
stepResourcesin a Build or BuildRun APIs to override the resources of steps defined in the BuildStrategy or ClusterBuildStrategy.#2079 by @IrvingMg: You can now specify a
runtimeClassNameon a Build and BuildRun to use alternative container runtimes.Fixes
#2101 by @adambkaplan: Update Tekton manifests URL to
infra.tekton.dev#2082 by @SaschaSchwarze0: The ko build strategy is fixed for Go modules that have dependencies but no vendoring.
API Changes
#2108 by @anchi205: You can now define
stepResourcesin a Build or BuildRun APIs to override the resources of steps defined in the BuildStrategy or ClusterBuildStrategy.#2079 by @IrvingMg: You can now specify a
runtimeClassNameon a Build and BuildRun to use alternative container runtimes.Docs
Misc
#2113 by @SaschaSchwarze0: The minimum supported Kubernetes version is now v1.33. The minimum supported Tekton version is v1.0.
#2109 by @shipwright-ci-bot: Update to the new latest Tekton LTS release v1.9.1
#2105 by @SaschaSchwarze0: We are scanning our images during our regular scans now with Grype in addition to Trivy as Trivy is not yet capable to find vulnerabilities in RedHat UBI 10 which we are using as our base image.
#2098 by @shipwright-ci-bot: Update to the new latest Tekton LTS release v1.9.0
#2056 by @ayushsatyam146: Added PipelineRun execution mode as an alternative to TaskRun for multi-pod build execution with PVC-based workspace storage, laying the foundation for future multi-architecture build support.
v0.18.4: Shipwright Build release v0.18.4Compare Source
Release changes since v0.18.3
To see a list of addressed vulnerabilities, please refer to #2110
Features
Fixes
API Changes
Docs
Misc
#2112 by @SaschaSchwarze0: Update github.com/go-git/go-git/v5 from v5.16.3 to v5.16.5 to address GO-2026-4473
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
To execute skipped test pipelines write comment
/ok-to-test.Documentation
Find out how to configure dependency updates in MintMaker documentation or see all available configuration options in Renovate documentation.