💥 Breaking Changes
- chore: rename CRD group
ratify.devtoratify.shby @fseldow in #2822 - chore: drop leftover
config.ratify.deislabs.ioClusterRole rules by @fseldow in #2832
🚀 Features
- feat: support multi-tenancy via namespaced Executor CRD by @fseldow in #2862
- feat(cosign): allow key-based verification without a timestamp by @charleswool in #2753
- feat(helm): add
provider.mutationExcludedNamespacesfor Assign mutation webhook exclusions by @eric-nichols-cava in #2755 - feat: add liveness and readiness probes to gatekeeper provider by @charleswool in #2772
- feat: gate readiness on the executor being loaded by @charleswool in #2840
- feat: set container resource requests and limits by @charleswool in #2841
- feat: make log level configurable by @charleswool in #2846
- feat: expose provider metrics in the Helm chart by @charleswool in #2848
🐛 Bug Fixes
- fix(notation): reject leaf cert trust anchors by @fseldow in #2723
- fix(cosign): honor
ignoreCTLoginstead of forcing it for key-based policies by @charleswool in #2838
🔐 Security
- fix: bump google.golang.org/grpc to v1.82.1 to fix GHSA-hrxh-6v49-42gf (gRPC-Go xDS RBAC & HTTP/2 vulnerabilities) by @charleswool in #2791
- chore: bump sigstore-go to 1.2.2 to fix CVE-2026-54787 (signature timestamp not checked against signing key validity) by @dependabot in #2764
🎉 New Contributors
- @eric-nichols-cava made their first contribution in #2755
Full Changelog: v2.0.0-alpha.2...v2.0.0-beta.1