github tektoncd/pipeline v1.17.0
Tekton Pipeline release v1.17.0 "Egyptian Mau Robocop"

3 hours ago

🎉 Clearer failures, sharper traces 🎉

Installation one-liner

kubectl apply -f https://infra.tekton.dev/tekton-releases/pipeline/previous/v1.17.0/release.yaml

Attestation

The Rekor UUID for this release is 108e9186e8c5677a431fb2e9f34a5fd5b0418cccab54d920148b79cbe5bfcd5a2075f7ae918a9cc9

Obtain the attestation:

REKOR_UUID=108e9186e8c5677a431fb2e9f34a5fd5b0418cccab54d920148b79cbe5bfcd5a2075f7ae918a9cc9
rekor-cli get --uuid $REKOR_UUID --format json | jq -r .Attestation | jq .

Verify that all container images in the attestation are in the release file:

RELEASE_FILE=https://infra.tekton.dev/tekton-releases/pipeline/previous/v1.17.0/release.yaml
REKOR_UUID=108e9186e8c5677a431fb2e9f34a5fd5b0418cccab54d920148b79cbe5bfcd5a2075f7ae918a9cc9

# Obtains the list of images with sha from the attestation
REKOR_ATTESTATION_IMAGES=$(rekor-cli get --uuid "$REKOR_UUID" --format json | jq -r .Attestation | jq -r '.subject[]|.name + ":v1.17.0@sha256:" + .digest.sha256')

# Download the release file
curl -L "$RELEASE_FILE" > release.yaml

# For each image in the attestation, match it to the release file
for image in $REKOR_ATTESTATION_IMAGES; do
  printf $image; grep -q $image release.yaml && echo " ===> ok" || echo " ===> no match";
done

Changes

Features

  • ✨ feat(tracing): record reconcile.write_intent span attribute (#10827)

Add a reconcile.write_intent attribute (no-op, status-only, metadata-only, metadata-and-status) to PipelineRun and TaskRun reconcile spans so operators can distinguish reconciliations that intend an etcd write.

  • ✨ Feat/10373 surface pod events/srvkp 13129 (#10690)

Surface Pod infrastructure failure reasons (from Warning events such as
FailedMount, FailedScheduling, FailedCreatePodSandBox) onto the TaskRun
status condition when a Pod is stuck pending with no useful message. Gated
behind the new surface-pod-events alpha feature flag (disabled by default).

  • ✨ feat(tracing): tag TaskRun ReconcileKind span on cancel/timeout (#10664)

Fixes

  • 🐛 fix: use non-expandable here-string for windows script placement (#10822)

Fixed a Windows script-injection defense-in-depth gap: placeScriptInContainer now uses a non-expandable PowerShell here-string, so a script body containing a literal "@ line can no longer terminate the generated command early.

  • 🐛 fix: add task name in error on task resolution failure (#10800)

Before this update, when resolver fails to get any task, controller showed the error message without containing the task name which was hard to detect which one is failed or having bad resolution config. Now task name is added to the error message from template.

  • 🐛 Allow tt.params as a valid variable-reference prefix (#10688)

Pipelines can now reference $(tt.params.<name>) in task params, when expressions, and matrix params/includes. This lets a PipelineSpec embedded by Tekton Triggers keep its tt.params.* substitutions without failing pipeline validation.

  • 🐛 Enqueue only a resolver's own ResolutionRequests (#10548)

Resolvers no longer fail ResolutionRequests belonging to a different resolver after a leader election or a resolver pod restart.

  • 🐛 fix: correct verb in controller startup panic logs (#10430)

Fixed controller startup panic messages that printed a malformed %!w(...) marker instead of the underlying error when an informer event handler failed to register.

  • 🐛 Fix release_names.go: update regex for Wikipedia HTML changes and fix bugs (#10508)

Misc

  • 🔨 chore: delete dead code in test/per_feature_flags_test.go file (#10802)

NOT REQUIRED

  • 🔨 chore: group sigstore dependency updates in dependabot (#10761)
  • 🔨 Eliminate discontinued gopkg.in/yaml.v3 library (#10683)
  • 🔨 build(deps): bump the kubernetes group with 5 updates (#10829)
  • 🔨 build(deps): bump the kubernetes group in /test/custom-task-ctrls/wait-task-beta with 3 updates (#10828)
  • 🔨 build(deps): bump google.golang.org/grpc from 1.83.2 to 1.84.0 (#10823)
  • 🔨 build(deps): bump chainguard-dev/actions/kind-diag from 1.6.35 to 1.6.36 (#10821)
  • 🔨 build(deps): bump codecov/codecov-action from 7.0.0 to 7.1.1 (#10820)
  • 🔨 build(deps): bump agilepathway/label-checker from 1.6.66 to 1.6.98 (#10819)
  • 🔨 build(deps): bump chainguard-dev/actions/setup-kind from 1.6.35 to 1.6.36 (#10818)
  • 🔨 build(deps): bump the all group in /tekton with 4 updates (#10803)
  • 🔨 test: Fix tracing test to honor custom SYSTEM_NAMESPACE (#10801)
  • 🔨 build(deps): bump github.com/spiffe/go-spiffe/v2 from 2.8.1 to 2.8.2 (#10795)
  • 🔨 build(deps): bump the sigstore group with 5 updates (#10791)
  • 🔨 build(deps): bump github.com/jenkins-x/go-scm from 1.16.0 to 1.16.3 (#10783)
  • 🔨 build(deps): bump the all group in /tekton with 4 updates (#10782)
  • 🔨 build(deps): bump agilepathway/label-checker from 1.6.65 to 1.6.66 (#10780)
  • 🔨 build(deps): bump chainguard-dev/actions/setup-kind from 1.6.34 to 1.6.35 (#10779)
  • 🔨 build(deps): bump chainguard-dev/actions/kind-diag from 1.6.34 to 1.6.35 (#10778)
  • 🔨 build(deps): bump zizmorcore/zizmor-action from 0.6.3 to 0.6.4 (#10777)
  • 🔨 build(deps): bump the codeql-action group with 3 updates (#10776)
  • 🔨 build(deps): bump the all group in /tekton with 6 updates (#10766)
  • 🔨 build(deps): bump github.com/jenkins-x/go-scm from 1.15.32 to 1.16.0 (#10760)
  • 🔨 build(deps): bump golang.org/x/crypto from 0.56.0 to 0.57.0 (#10759)
  • 🔨 build(deps): bump github.com/sigstore/sigstore/pkg/signature/kms/aws from 1.10.9 to 1.10.10 (#10746)
  • 🔨 build(deps): bump github.com/sigstore/sigstore/pkg/signature/kms/gcp from 1.10.9 to 1.10.10 (#10745)
  • 🔨 build(deps): bump github.com/sigstore/sigstore/pkg/signature/kms/hashivault from 1.10.9 to 1.10.10 (#10744)
  • 🔨 build(deps): bump github.com/sigstore/sigstore from 1.10.9 to 1.10.10 (#10743)
  • 🔨 build(deps): bump github.com/sigstore/sigstore/pkg/signature/kms/azure from 1.10.9 to 1.10.10 (#10742)
  • 🔨 build(deps): bump step-security/harden-runner from 2.21.0 to 2.21.1 (#10734)
  • 🔨 build(deps): bump chainguard-dev/actions/setup-kind from 1.6.32 to 1.6.34 (#10733)
  • 🔨 build(deps): bump chainguard-dev/actions/kind-diag from 1.6.33 to 1.6.34 (#10731)
  • 🔨 build(deps): bump zizmorcore/zizmor-action from 0.6.2 to 0.6.3 (#10730)
  • 🔨 build(deps): bump the codeql-action group across 1 directory with 2 updates (#10729)
  • 🔨 build(deps): bump golang.org/x/crypto from 0.55.0 to 0.56.0 (#10723)
  • 🔨 build(deps): bump golang.org/x/sync from 0.22.0 to 0.23.0 (#10722)
  • 🔨 build(deps): bump github.com/prometheus/common from 0.70.1 to 0.71.0 (#10721)
  • 🔨 build(deps): bump github.com/google/go-containerregistry from 0.22.0 to 0.22.1 (#10720)
  • 🔨 build(deps): bump github.com/tektoncd/pipeline from 1.15.1 to 1.16.0 in /test/custom-task-ctrls/wait-task-beta (#10719)
  • 🔨 build(deps): bump chainguard-dev/actions/kind-diag from 1.6.32 to 1.6.33 (#10712)
  • 🔨 build(deps): bump github/codeql-action/upload-sarif from 4.37.7 to 4.37.9 (#10711)
  • 🔨 build(deps): bump the all group across 1 directory with 4 updates (#10697)
  • 🔨 build(deps): bump github.com/prometheus/client_model from 0.6.2 to 0.6.3 (#10693)
  • 🔨 deps: use new import path for google/cel-go lib (#10689)
  • 🔨 build(deps): bump github.com/google/go-containerregistry from 0.21.9 to 0.22.0 (#10682)
  • 🔨 fix(CI): group github/codeql-action/* dependabot updates (#10661)
  • 🔨 Bump plumbing ref for github_release_oci task (#10509)

Docs

  • 📖 docs: add v1.16.0 release to releases.md (#10681)
  • 📖 docs: clarify config-tracing and config-observability are separate tracing paths (#10626)

Thanks

Thanks to these contributors who contributed to v1.17.0!

Extra shout-out for awesome release notes:

Don't miss a new pipeline release

NewReleases is sending notifications on new releases.