github chainguard-dev/apko v0.25.2
Release v0.25.2

one day ago

What's Changed

  • build(deps): bump github.com/spf13/cobra from 1.8.1 to 1.9.1 by @dependabot in #1531
  • build(deps): bump step-security/harden-runner from 2.10.4 to 2.11.0 by @dependabot in #1533
  • build(deps): bump google.golang.org/api from 0.220.0 to 0.222.0 by @dependabot in #1534
  • build(deps): bump github.com/sigstore/cosign/v2 from 2.4.2 to 2.4.3 by @dependabot in #1535
  • build(deps): bump github.com/klauspost/compress from 1.17.11 to 1.18.0 by @dependabot in #1536
  • build(deps): bump k8s.io/apimachinery from 0.32.1 to 0.32.2 by @dependabot in #1527
  • build(deps): bump golangci/golangci-lint-action from 6.3.2 to 6.5.0 by @dependabot in #1532
  • build(deps): bump github.com/go-jose/go-jose/v4 from 4.0.4 to 4.0.5 in the go_modules group by @dependabot in #1539
  • build(deps): bump github.com/google/go-cmp from 0.6.0 to 0.7.0 by @dependabot in #1542
  • build(deps): bump sigstore/cosign-installer from 3.8.0 to 3.8.1 by @dependabot in #1537
  • Make LockImageConfiguration incorporate options by @jonjohnsonjr in #1540
  • build(deps): bump docker/setup-qemu-action from 3.4.0 to 3.5.0 by @dependabot in #1549
  • build(deps): bump github.com/go-jose/go-jose/v3 from 3.0.3 to 3.0.4 in the go_modules group by @dependabot in #1547
  • build(deps): bump github.com/go-git/go-git/v5 from 5.13.2 to 5.14.0 by @dependabot in #1548
  • build(deps): bump google.golang.org/api from 0.222.0 to 0.223.0 by @dependabot in #1545
  • apk/signature: remove support for creating new SHA1 signatures by @xnox in #1496
  • dot: Do a slightly better job by @jonjohnsonjr in #1553
  • spdx: add attributionText field by @xnox in #1554
  • build(deps): bump github.com/chainguard-dev/clog from 1.6.1 to 1.7.0 by @dependabot in #1555
  • build(deps): bump docker/setup-qemu-action from 3.5.0 to 3.6.0 by @dependabot in #1552
  • apko: make apk cache safer for multi-writers by @tcnghia in #1564

Full Changelog: v0.25.1...v0.25.2

Don't miss a new apko release

NewReleases is sending notifications on new releases.