What's Changed
- build(deps): bump github/codeql-action from 3.27.9 to 3.28.14 by @dependabot in #1603
- build(deps): bump golang.org/x/sync from 0.12.0 to 0.13.0 by @dependabot in #1602
- build(deps): bump step-security/harden-runner from 2.11.0 to 2.11.1 by @dependabot in #1599
- build(deps): bump goreleaser/goreleaser-action from 6.2.1 to 6.3.0 by @dependabot in #1597
- build(deps): bump sigs.k8s.io/release-utils from 0.11.0 to 0.11.1 by @dependabot in #1594
- build(deps): bump google.golang.org/api from 0.225.0 to 0.228.0 by @dependabot in #1591
- build(deps): bump golang.org/x/sys from 0.31.0 to 0.32.0 by @dependabot in #1601
- build(deps): bump go.step.sm/crypto from 0.59.1 to 0.60.0 by @dependabot in #1592
- Pass through ReadAt to tarfs by @jonjohnsonjr in #1607
- Un-abstract the tarball package by @jonjohnsonjr in #1609
- Drop pkg/apk/tarball by @jonjohnsonjr in #1613
- refactor: slim down interface requirements for fetching packages by @luhring in #1614
- Consider deps resolved if other resolved deps already provide them by @dannf in #1606
- For multi-layer images, include all layers in sbom by @jonjohnsonjr in #1611
- Rewrite writeTar in terms of iterators by @jonjohnsonjr in #1615
- Use a lazy layerWriter for writing tar files by @jonjohnsonjr in #1616
- apk: fix cached APKINDEX to be world readable by @xnox in #1621
New Contributors
Full Changelog: v0.25.6...v0.25.7