Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
85 commits
Select commit Hold shift + click to select a range
c547516
fix: add .gotmpl file extension for go template (#2218) (#2222)
binbin-li May 8, 2025
746f5b9
fix: add .gotmpl to helmfile in Makefile (#2224)
binbin-li May 8, 2025
cf0c359
chore: update ratify-project to notaryproject in helmfile (#2258)
binbin-li May 27, 2025
74da2d1
exclude .md files (#2280)
vanshika622 Jun 17, 2025
340d73e
remove references to Bridge2Kubernetes from contributing guide (#2343)
shahramk64 Aug 1, 2025
710f214
Merge branch 'v1' into v1-dev
binbin-li Sep 8, 2025
c986d77
feat: Let Ratify server allow multiple tls client cacert (#2412)
RemindD Sep 26, 2025
b5ad1ff
chore: bump package and CI tool versions (#2449)
akashsinghal Oct 26, 2025
b363d2f
feat: add slsa verifier plugin to verify slsa vsa and provenance (#2442)
DahuK Nov 5, 2025
aeaff8c
fix: resolve scan-vulns and golang-lint CI failures (#2557)
YitongFeng-git Jun 4, 2026
09df44a
chore: make CRD image Trivy scan warning only (#2576)
fseldow Jun 18, 2026
d58e5e4
chore: v1-dev workflow trigger fix (#2584)
fseldow Jun 23, 2026
313fd08
chore: update Go version to 1.26.4 (#2568)
fseldow Jun 23, 2026
84e9a7c
feat: make k8Secrets auth provider secret cache TTL configurable (#2581)
ramasai1 Jun 24, 2026
4544d13
Add Xinhe Li as Ratify maintainer (#2597)
fseldow Jun 30, 2026
91f9a4a
chore: bump sigstore/rekor v1.5.1 to v1.5.2 (#2619)
fseldow Jun 30, 2026
f6151fe
chore: Bump sigstore/cosign/v3 to v3.1.1 and k8s.io (#2653)
fseldow Jul 2, 2026
e2e7630
chore: Bump oras.land/oras-go/v2 from v2.6.0 to v2.6.1
fseldow Jul 3, 2026
69940c0
fix: add emptyDir for ORAS local cache to support nonroot image build…
fseldow Jul 5, 2026
79225a5
fix: initialize registryHostGetter in MIAuthProvider to prevent nil p…
fseldow Jul 5, 2026
35c9248
Merge branch 'v1' into v1-dev
fseldow Jul 5, 2026
06398bf
test: add unit tests for SLSA verifier plugin (#2668)
fseldow Jul 5, 2026
8c58d92
chore: Bump oras.land/oras-go/v2 from v2.6.1 to v2.6.2
fseldow Jul 10, 2026
624e7a8
Merge branch 'v1' into v1-dev
fseldow Jul 13, 2026
0040284
chore: bump Go version to 1.26.5 and ignore no actionable go vuln (#2…
fseldow Jul 21, 2026
1435126
chore: Bump alpine from `4b7ce07` to `28bd5fe` (#2758)
dependabot[bot] Jul 21, 2026
8b91e60
chore: Bump actions/cache from 4.2.x to 6.1.0 (#2773)
fseldow Jul 21, 2026
fff895d
chore: Bump golangci/golangci-lint-action from 9.2.0 to 9.3.0 (#2760)
dependabot[bot] Jul 21, 2026
e5aa6af
chore: Bump sigstore/cosign-installer from 3.8.1 to 4.1.2 (#2759)
dependabot[bot] Jul 21, 2026
4864e33
chore: Bump ossf/scorecard-action from 2.4.1 to 2.4.3 (#2761)
dependabot[bot] Jul 21, 2026
4a29324
chore: Bump docker/login-action from 3.4.0 to 4.4.0 (#2762)
dependabot[bot] Jul 21, 2026
79566c5
chore: Bump github.com/aws/aws-sdk-go-v2 from 1.41.7 to 1.41.12 (#2765)
dependabot[bot] Jul 21, 2026
6ab45a0
chore: Bump github.com/notaryproject/notation-go from 1.3.1 to 1.3.2 …
dependabot[bot] Jul 21, 2026
d417499
chore: Bump github.com/sigstore/rekor from 1.5.2 to 1.5.3 (#2768)
dependabot[bot] Jul 21, 2026
017c617
chore: Bump k8s.io/api from 0.36.1 to 0.36.2 (#2769)
dependabot[bot] Jul 21, 2026
255c66d
chore: Bump github/codeql-action/init from 3.28.15 to 4.37.1 (#2775)
dependabot[bot] Jul 21, 2026
8eb6b7e
chore: Bump distroless/static from `c0f429e` to `f7f8f72` in /httpser…
dependabot[bot] Jul 21, 2026
53a464e
chore: Bump apache/skywalking-eyes/header from 0.7.0 to 0.8.0 (#2776)
dependabot[bot] Jul 21, 2026
09571de
chore: Bump actions/cache/save from 4.2.3 to 6.1.0 (#2763)
dependabot[bot] Jul 21, 2026
058d3d5
chore: Bump golang/govulncheck-action from 1.0.4 to 1.1.0 (#2777)
dependabot[bot] Jul 21, 2026
8e44440
chore: Bump azure/login from 2.2.0 to 3.0.0 (#2778)
dependabot[bot] Jul 21, 2026
475a6b1
feat(helm): add provider.mutationExcludedNamespaces for Assign webhoo…
eric-nichols-cava Jul 22, 2026
3e43f78
chore: Bump github.com/sigstore/sigstore-go from 1.2.0 to 1.2.2 (#2766)
dependabot[bot] Jul 22, 2026
86006cb
chore: Bump oras-project/setup-oras from 1.2.2 to 2.0.1 (#2785)
dependabot[bot] Jul 22, 2026
f64d1da
chore: Bump google.golang.org/grpc from v1.82.0 to v1.82.1 (#2795)
fseldow Jul 22, 2026
a175342
chore: Bump step-security/harden-runner from 2.11.1 to 2.20.0 (#2786)
dependabot[bot] Jul 22, 2026
f8c498e
chore: Bump nick-fields/retry from 3.0.2 to 4.0.0 (#2787)
dependabot[bot] Jul 23, 2026
cbe7063
chore: Bump actions/checkout from 4.2.2 to 7.0.1 (#2788)
dependabot[bot] Jul 23, 2026
00dd0ff
chore: Bump github/codeql-action/upload-sarif from 3.28.15 to 4.37.3 …
dependabot[bot] Jul 23, 2026
688d199
chore: Bump anchore/sbom-action/download-syft from 0.18.0 to 0.24.0 (…
dependabot[bot] Jul 23, 2026
78eb625
chore: Bump actions/setup-go from 5.4.0 to 7.0.0 (#2801)
dependabot[bot] Jul 23, 2026
dd77d9a
chore: Bump gaurav-nelson/github-action-markdown-link-check from 1.0.…
dependabot[bot] Jul 23, 2026
e8d0580
chore: Bump apache/skywalking-eyes/dependency from 0.7.0 to 0.8.0 (#2…
dependabot[bot] Jul 23, 2026
9497dd8
chore: Bump github.com/Azure/azure-sdk-for-go/sdk/containers/azcontai…
dependabot[bot] Jul 23, 2026
22fd6e3
chore: Bump github.com/aws/aws-sdk-go-v2/config from 1.32.20 to 1.32.…
dependabot[bot] Jul 24, 2026
1e4a556
chore: Bump github.com/carabiner-dev/signer from 0.3.2 to 0.3.7 (#2807)
dependabot[bot] Jul 24, 2026
fd7b71f
chore: Bump github.com/aws/aws-sdk-go-v2/service/ecr from 1.55.3 to 1…
dependabot[bot] Jul 24, 2026
b9a8820
chore: Bump docker/login-action from 4.4.0 to 4.5.0 (#2818)
dependabot[bot] Jul 24, 2026
f202f13
chore: Bump goreleaser/goreleaser-action from 6.3.0 to 7.2.3 (#2819)
dependabot[bot] Jul 24, 2026
9292401
chore: Bump ossf/scorecard-action from 2.4.3 to 2.4.4 (#2821)
dependabot[bot] Jul 24, 2026
019c48d
chore: Bump github/codeql-action/analyze from 3.28.15 to 4.37.3 (#2820)
dependabot[bot] Jul 26, 2026
64e43b2
chore: Bump github/codeql-action/init from 4.37.1 to 4.37.3 (#2806)
dependabot[bot] Jul 26, 2026
8605c39
chore: Bump docker/login-action from 4.5.0 to 4.5.1 (#2837)
dependabot[bot] Jul 27, 2026
109ce48
chore: Bump actions/upload-artifact from 4.6.2 to 7.0.1 (#2835)
dependabot[bot] Jul 27, 2026
fc93201
chore: Bump codecov/codecov-action from 5.4.0 to 7.0.0 (#2836)
dependabot[bot] Jul 27, 2026
52c9ac9
chore: Bump golang.org/x/text from v0.38.0 to v0.40.0
fseldow Jul 29, 2026
7552c0b
chore: Bump docker/login-action from 4.5.1 to 4.5.2 (#2845)
dependabot[bot] Jul 29, 2026
9c62f27
chore: Bump github.com/aws/aws-sdk-go-v2 from 1.43.0 to 1.43.2 (#2856)
dependabot[bot] Jul 30, 2026
b90e818
chore: Bump k8s.io/apimachinery from 0.36.2 to 0.36.3 (#2857)
dependabot[bot] Jul 30, 2026
20a3301
chore: Bump docker/login-action from 4.5.2 to 4.6.0 (#2852)
dependabot[bot] Jul 30, 2026
10d3bbe
chore: Bump github.com/sigstore/cosign/v3 from 3.1.1 to 3.1.2 (#2855)
dependabot[bot] Jul 30, 2026
3390c6d
chore: Bump github.com/aws/aws-sdk-go-v2/credentials from 1.19.30 to …
dependabot[bot] Jul 30, 2026
f766109
chore: Bump github/codeql-action/upload-sarif from 4.37.3 to 4.37.4 (…
dependabot[bot] Aug 4, 2026
b2c2f81
chore: Bump github/codeql-action/init from 4.37.3 to 4.37.4 (#2869)
dependabot[bot] Aug 4, 2026
5bbdb81
chore: Bump github/codeql-action/analyze from 4.37.3 to 4.37.4 (#2866)
dependabot[bot] Aug 4, 2026
b5da346
chore: Bump github/codeql-action/init from 4.37.4 to 4.37.5 (#2883)
dependabot[bot] Aug 6, 2026
6a3e8ce
chore: Bump github.com/aws/aws-sdk-go-v2/config from 1.32.31 to 1.32.…
dependabot[bot] Aug 6, 2026
fa4e6bf
chore: Bump github/codeql-action/analyze from 4.37.4 to 4.37.5 (#2889)
dependabot[bot] Aug 6, 2026
b02de7a
chore: Bump k8s.io/client-go from 0.36.2 to 0.36.3 (#2887)
dependabot[bot] Aug 6, 2026
6f297cc
chore: Bump github/codeql-action/upload-sarif from 4.37.4 to 4.37.5 (…
dependabot[bot] Aug 6, 2026
3fe4b3b
chore: Bump github.com/alibabacloud-go/darabonba-openapi/v2 from 2.0.…
dependabot[bot] Aug 6, 2026
ffd0cec
chore: Bump github.com/google/go-containerregistry from 0.21.7 to 0.2…
dependabot[bot] Aug 6, 2026
13995b7
chore: Bump step-security/harden-runner from 2.20.0 to 2.20.1 (#2899)
dependabot[bot] Aug 7, 2026
6f6a365
chore: Bump azure/login from 3.0.0 to 3.0.1 (#2898)
dependabot[bot] Aug 7, 2026
9de961f
chore: Bump github/codeql-action/upload-sarif from 4.37.5 to 4.37.6 (…
dependabot[bot] Aug 7, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
14 changes: 12 additions & 2 deletions .github/actions/restore_trivy_cache/action.yml
Original file line number Diff line number Diff line change
@@ -1,6 +1,11 @@
name: "Steps to restore trivy cache"
description: "Steps to restore Trivy cache under ~/.cache/trivy"

outputs:
cache-hit:
description: "Whether the trivy cache was restored"
value: ${{ steps.cache-status.outputs.cache-hit }}

runs:
using: "composite"
steps:
Expand All @@ -9,12 +14,17 @@ runs:
run: echo "date=$(date +'%Y-%m-%d')" >> $GITHUB_OUTPUT
shell: bash
- name: Restore trivy cache directory
uses: actions/cache/restore@0c907a75c2c80ebcb7f088228285e798b750cf8f # v4.2.1
uses: actions/cache/restore@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
with:
path: ${{ github.workspace }}/.cache/trivy
key: cache-trivy-${{ steps.date.outputs.date }}
- name: Set up trivy cache directory
run: |
mkdir -p ~/.cache/trivy
cp -r ${{ github.workspace }}/.cache/trivy/db ~/.cache/trivy
if [[ -d "${{ github.workspace }}/.cache/trivy/db" ]]; then
cp -r ${{ github.workspace }}/.cache/trivy/db ~/.cache/trivy
else
echo "cache-hit=false" >> $GITHUB_OUTPUT
fi
shell: bash
id: cache-status
8 changes: 4 additions & 4 deletions .github/workflows/build-pr.yml
Original file line number Diff line number Diff line change
Expand Up @@ -75,19 +75,19 @@ jobs:
environment: azure-test
steps:
- name: Harden Runner
uses: step-security/harden-runner@c6295a65d1254861815972266d5933fd6e532bdf # v2.11.1
uses: step-security/harden-runner@b09bb98e06d4d774595224525879c09bc6e98c40 # v2.20.1
with:
egress-policy: audit

- name: Check out code into the Go module directory
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- name: Set up Go 1.24
uses: actions/setup-go@0aaccfd150d50ccaeb58ebd88d36e91967a5f35b # v5.4.0
uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0
with:
go-version: "1.26"

- name: Az CLI login
uses: azure/login@a65d910e8af852a8061c627c456678983e180302 # v2.2.0
uses: azure/login@f5d393ae46f8fde4be8b75f32e3fc50e654ad0ca # v3.0.1
with:
client-id: ${{ secrets.AZURE_CLIENT_ID }}
tenant-id: ${{ secrets.AZURE_TENANT_ID }}
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/cache-cleanup.yml
Original file line number Diff line number Diff line change
Expand Up @@ -12,7 +12,7 @@ jobs:
runs-on: ubuntu-latest
steps:
- name: Harden Runner
uses: step-security/harden-runner@0634a2670c59f64b4a01f0f96f84700a4088b9f0 # v2.12.0
uses: step-security/harden-runner@b09bb98e06d4d774595224525879c09bc6e98c40 # v2.20.1
with:
egress-policy: audit

Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/clean-dev-package.yml
Original file line number Diff line number Diff line change
Expand Up @@ -13,7 +13,7 @@ jobs:
packages: write
steps:
- name: Harden Runner
uses: step-security/harden-runner@c6295a65d1254861815972266d5933fd6e532bdf # v2.11.1
uses: step-security/harden-runner@b09bb98e06d4d774595224525879c09bc6e98c40 # v2.20.1
with:
egress-policy: audit

Expand Down
10 changes: 5 additions & 5 deletions .github/workflows/codeql.yml
Original file line number Diff line number Diff line change
Expand Up @@ -28,23 +28,23 @@ jobs:

steps:
- name: Harden Runner
uses: step-security/harden-runner@c6295a65d1254861815972266d5933fd6e532bdf # v2.11.1
uses: step-security/harden-runner@b09bb98e06d4d774595224525879c09bc6e98c40 # v2.20.1
with:
egress-policy: audit

- name: Checkout repository
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # tag=3.0.2
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- name: setup go environment
uses: actions/setup-go@0aaccfd150d50ccaeb58ebd88d36e91967a5f35b # v5.4.0
uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0
with:
go-version: "1.22"
- name: Initialize CodeQL
uses: github/codeql-action/init@45775bd8235c68ba998cffa5171334d58593da47 # tag=v3.28.15
uses: github/codeql-action/init@d1ba80a13dd99fba24a470575428917156a28b43 # tag=v4.37.5
with:
languages: go
- name: Run tidy
run: go mod tidy
- name: Build CLI
run: make build
- name: Perform CodeQL Analysis
uses: github/codeql-action/analyze@45775bd8235c68ba998cffa5171334d58593da47 # tag=v3.28.15
uses: github/codeql-action/analyze@d1ba80a13dd99fba24a470575428917156a28b43 # tag=v4.37.5
10 changes: 5 additions & 5 deletions .github/workflows/e2e-aks.yml
Original file line number Diff line number Diff line change
Expand Up @@ -28,18 +28,18 @@ jobs:
contents: read
steps:
- name: Harden Runner
uses: step-security/harden-runner@c6295a65d1254861815972266d5933fd6e532bdf # v2.11.1
uses: step-security/harden-runner@b09bb98e06d4d774595224525879c09bc6e98c40 # v2.20.1
with:
egress-policy: audit

- name: Check out code into the Go module directory
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- name: Set up Go 1.24
uses: actions/setup-go@0aaccfd150d50ccaeb58ebd88d36e91967a5f35b # v5.4.0
uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0
with:
go-version: "1.24"
- name: Az CLI login
uses: azure/login@a65d910e8af852a8061c627c456678983e180302 # v2.2.0
uses: azure/login@f5d393ae46f8fde4be8b75f32e3fc50e654ad0ca # v3.0.1
with:
client-id: ${{ secrets.AZURE_CLIENT_ID }}
tenant-id: ${{ secrets.AZURE_TENANT_ID }}
Expand Down Expand Up @@ -67,7 +67,7 @@ jobs:
make e2e-aks KUBERNETES_VERSION=${{ inputs.k8s_version }} GATEKEEPER_VERSION=${{ inputs.gatekeeper_version }} TENANT_ID=${{ secrets.AZURE_TENANT_ID }} AZURE_SP_OBJECT_ID=${{ secrets.AZURE_SP_OBJECT_ID }}

- name: Upload artifacts
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
if: ${{ always() }}
with:
name: e2e-logs-aks-${{ inputs.k8s_version }}-${{ inputs.gatekeeper_version }}
Expand Down
30 changes: 15 additions & 15 deletions .github/workflows/e2e-cli.yml
Original file line number Diff line number Diff line change
Expand Up @@ -14,34 +14,34 @@ jobs:
runs-on: ubuntu-latest
steps:
- name: Harden Runner
uses: step-security/harden-runner@c6295a65d1254861815972266d5933fd6e532bdf # v2.11.1
uses: step-security/harden-runner@b09bb98e06d4d774595224525879c09bc6e98c40 # v2.20.1
with:
egress-policy: audit

- name: Checkout
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- name: Check license header
uses: apache/skywalking-eyes/header@5c5b974209f0de5d905f37deb69369068ebfc15c
uses: apache/skywalking-eyes/header@61275cc80d0798a405cb070f7d3a8aaf7cf2c2c1
with:
mode: check
config: .github/licenserc.yml
- name: Check dependencies license
uses: apache/skywalking-eyes/dependency@5c5b974209f0de5d905f37deb69369068ebfc15c
uses: apache/skywalking-eyes/dependency@61275cc80d0798a405cb070f7d3a8aaf7cf2c2c1
with:
config: .github/licenserc.yml
flags: --weak-compatible=true
build:
runs-on: ubuntu-latest
steps:
- name: Harden Runner
uses: step-security/harden-runner@c6295a65d1254861815972266d5933fd6e532bdf # v2.11.1
uses: step-security/harden-runner@b09bb98e06d4d774595224525879c09bc6e98c40 # v2.20.1
with:
egress-policy: audit

- name: Checkout
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- name: setup go environment
uses: actions/setup-go@0aaccfd150d50ccaeb58ebd88d36e91967a5f35b # v5.4.0
uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0
with:
go-version: "1.26"
- name: Run tidy
Expand All @@ -51,7 +51,7 @@ jobs:
- name: Check build
run: bin/ratify version
- name: Upload coverage to codecov.io
uses: codecov/codecov-action@0565863a31f2c772f9f0395002a31e3f06189574 # v5.4.0
uses: codecov/codecov-action@fb8b3582c8e4def4969c97caa2f19720cb33a72f # v7.0.0
with:
token: ${{ secrets.CODECOV_TOKEN }}
- name: Run helm lint
Expand All @@ -63,14 +63,14 @@ jobs:
contents: read
steps:
- name: Harden Runner
uses: step-security/harden-runner@c6295a65d1254861815972266d5933fd6e532bdf # v2.11.1
uses: step-security/harden-runner@b09bb98e06d4d774595224525879c09bc6e98c40 # v2.20.1
with:
egress-policy: audit

- name: Checkout
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- name: setup go environment
uses: actions/setup-go@0aaccfd150d50ccaeb58ebd88d36e91967a5f35b # v5.4.0
uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0
with:
go-version: "1.26"
- name: Run tidy
Expand All @@ -86,23 +86,23 @@ jobs:
make install ratify-config install-bats
make test-e2e-cli GOCOVERDIR=${GITHUB_WORKSPACE}/test/e2e/.cover
- name: Upload coverage to codecov.io
uses: codecov/codecov-action@0565863a31f2c772f9f0395002a31e3f06189574 # v5.4.0
uses: codecov/codecov-action@fb8b3582c8e4def4969c97caa2f19720cb33a72f # v7.0.0
with:
token: ${{ secrets.CODECOV_TOKEN }}
markdown-link-check:
runs-on: ubuntu-latest
steps:
- name: Harden Runner
uses: step-security/harden-runner@c6295a65d1254861815972266d5933fd6e532bdf # v2.11.1
uses: step-security/harden-runner@b09bb98e06d4d774595224525879c09bc6e98c40 # v2.20.1
with:
egress-policy: audit

- name: Checkout
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
submodules: recursive
- name: Run link check
uses: gaurav-nelson/github-action-markdown-link-check@1b916f2cf6c36510a6059943104e3c42ce6c16bc #3.10.3
uses: gaurav-nelson/github-action-markdown-link-check@3c3b66f1f7d0900e37b71eca45b63ea9eedfce31 # 1.0.17
with:
use-quiet-mode: "no"
use-verbose-mode: "yes"
Expand Down
8 changes: 4 additions & 4 deletions .github/workflows/e2e-k8s.yml
Original file line number Diff line number Diff line change
Expand Up @@ -26,14 +26,14 @@ jobs:
contents: read
steps:
- name: Harden Runner
uses: step-security/harden-runner@c6295a65d1254861815972266d5933fd6e532bdf # v2.11.1
uses: step-security/harden-runner@b09bb98e06d4d774595224525879c09bc6e98c40 # v2.20.1
with:
egress-policy: audit

- name: Check out code into the Go module directory
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- name: Set up Go 1.24
uses: actions/setup-go@0aaccfd150d50ccaeb58ebd88d36e91967a5f35b # v5.4.0
uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0
with:
go-version: "1.26"
- name: Restore Trivy cache
Expand Down Expand Up @@ -66,7 +66,7 @@ jobs:
kubectl logs -n gatekeeper-system -l app=ratify --tail=-1 > logs-ratify-preinstall-${{ matrix.KUBERNETES_VERSION }}-${{ matrix.GATEKEEPER_VERSION }}-rego-policy.json
kubectl logs -n gatekeeper-system -l app.kubernetes.io/name=ratify --tail=-1 > logs-ratify-${{ matrix.KUBERNETES_VERSION }}-${{ matrix.GATEKEEPER_VERSION }}-rego-policy.json
- name: Upload artifacts
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
if: ${{ always() }}
with:
name: e2e-logs-${{ inputs.k8s_version }}-${{ inputs.gatekeeper_version }}
Expand Down
8 changes: 4 additions & 4 deletions .github/workflows/golangci-lint.yml
Original file line number Diff line number Diff line change
Expand Up @@ -18,16 +18,16 @@ jobs:
runs-on: ubuntu-latest
steps:
- name: Harden Runner
uses: step-security/harden-runner@c6295a65d1254861815972266d5933fd6e532bdf # v2.11.1
uses: step-security/harden-runner@b09bb98e06d4d774595224525879c09bc6e98c40 # v2.20.1
with:
egress-policy: audit

- uses: actions/setup-go@0aaccfd150d50ccaeb58ebd88d36e91967a5f35b # v5.4.0
- uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0
with:
go-version: "1.26.4"
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- name: golangci-lint
uses: golangci/golangci-lint-action@1e7e51e771db61008b38414a730f564565cf7c20 # v9.2.0
uses: golangci/golangci-lint-action@ba0d7d2ec06a0ea1cb5fa41b2e4a3ab91d21278a # v9.3.0
with:
version: v2.12.2
args: --timeout=10m
8 changes: 4 additions & 4 deletions .github/workflows/high-availability.yml
Original file line number Diff line number Diff line change
Expand Up @@ -32,14 +32,14 @@ jobs:
DAPR_VERSION: ["1.14.4"]
steps:
- name: Harden Runner
uses: step-security/harden-runner@c6295a65d1254861815972266d5933fd6e532bdf # v2.11.1
uses: step-security/harden-runner@b09bb98e06d4d774595224525879c09bc6e98c40 # v2.20.1
with:
egress-policy: audit

- name: Check out code into the Go module directory
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- name: Set up Go 1.24
uses: actions/setup-go@0aaccfd150d50ccaeb58ebd88d36e91967a5f35b # v5.4.0
uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0
with:
go-version: "1.24"

Expand All @@ -62,7 +62,7 @@ jobs:
kubectl logs -n gatekeeper-system -l app=ratify --tail=-1 > logs-ratify-preinstall-${{ matrix.DAPR_VERSION }}.json
kubectl logs -n gatekeeper-system -l app.kubernetes.io/name=ratify --tail=-1 > logs-ratify-${{ matrix.DAPR_VERSION }}.json
- name: Upload artifacts
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
if: ${{ always() }}
with:
name: e2e-logs-${{ matrix.DAPR_VERSION }}
Expand Down
4 changes: 2 additions & 2 deletions .github/workflows/pr-to-main.yml
Original file line number Diff line number Diff line change
Expand Up @@ -13,12 +13,12 @@ jobs:
runs-on: ubuntu-latest
steps:
- name: Harden Runner
uses: step-security/harden-runner@c6295a65d1254861815972266d5933fd6e532bdf # v2.11.1
uses: step-security/harden-runner@b09bb98e06d4d774595224525879c09bc6e98c40 # v2.20.1
with:
egress-policy: audit

- name: git checkout
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- name: Get current date
id: date
run: echo "::set-output name=date::$(date +'%Y-%m-%d')"
Expand Down
4 changes: 2 additions & 2 deletions .github/workflows/publish-charts.yml
Original file line number Diff line number Diff line change
Expand Up @@ -13,11 +13,11 @@ jobs:
contents: write
steps:
- name: Harden Runner
uses: step-security/harden-runner@c6295a65d1254861815972266d5933fd6e532bdf # v2.11.1
uses: step-security/harden-runner@b09bb98e06d4d774595224525879c09bc6e98c40 # v2.20.1
with:
egress-policy: audit

- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- name: Publish Helm charts
uses: stefanprodan/helm-gh-pages@0ad2bb377311d61ac04ad9eb6f252fb68e207260 # v1.7.0
with:
Expand Down
6 changes: 3 additions & 3 deletions .github/workflows/publish-cosign-sample.yml
Original file line number Diff line number Diff line change
Expand Up @@ -20,12 +20,12 @@ jobs:
id-token: write
steps:
- name: Harden Runner
uses: step-security/harden-runner@c6295a65d1254861815972266d5933fd6e532bdf # v2.11.1
uses: step-security/harden-runner@b09bb98e06d4d774595224525879c09bc6e98c40 # v2.20.1
with:
egress-policy: audit

- name: Install cosign
uses: sigstore/cosign-installer@d7d6bc7722e3daa8354c50bcb52f4837da5e9b6a # v3.8.1
uses: sigstore/cosign-installer@6f9f17788090df1f26f669e9d70d6ae9567deba6 # v4.1.2

- name: Get repo
run: |
Expand All @@ -38,7 +38,7 @@ jobs:
KEY: ${{ secrets.COSIGN_PRIVATE_KEY }}

- name: Log in to GHCR
uses: docker/login-action@74a5d142397b4f367a81961eba4e8cd7edddf772 # v3.4.0
uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f # v4.6.0
with:
registry: ${{ env.REGISTRY }}
username: ${{ github.actor }}
Expand Down
10 changes: 5 additions & 5 deletions .github/workflows/publish-dev-assets.yml
Original file line number Diff line number Diff line change
Expand Up @@ -17,17 +17,17 @@ jobs:
environment: azure-publish
steps:
- name: Harden Runner
uses: step-security/harden-runner@c6295a65d1254861815972266d5933fd6e532bdf # v2.11.1
uses: step-security/harden-runner@b09bb98e06d4d774595224525879c09bc6e98c40 # v2.20.1
with:
egress-policy: audit
- name: Checkout
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- name: Install Notation
uses: notaryproject/notation-action/setup@b6fee73110795d6793253c673bd723f12bcf9bbb # v1.2.2
- name: Install cosign
uses: sigstore/cosign-installer@d7d6bc7722e3daa8354c50bcb52f4837da5e9b6a # v3.8.1
uses: sigstore/cosign-installer@6f9f17788090df1f26f669e9d70d6ae9567deba6 # v4.1.2
- name: Az CLI login
uses: azure/login@a65d910e8af852a8061c627c456678983e180302 # v2.2.0
uses: azure/login@f5d393ae46f8fde4be8b75f32e3fc50e654ad0ca # v3.0.1
with:
client-id: ${{ secrets.AZURE_CLIENT_ID }}
tenant-id: ${{ secrets.AZURE_TENANT_ID }}
Expand Down Expand Up @@ -62,7 +62,7 @@ jobs:
echo ::set-output name=baseref::${REPOSITORYBASE}
echo ::set-output name=crdref::${REPOSITORYCRD}
- name: docker login
uses: docker/login-action@74a5d142397b4f367a81961eba4e8cd7edddf772 # v3.4.0
uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f # v4.6.0
with:
registry: ghcr.io
username: ${{ github.actor }}
Expand Down
Loading
Loading