Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
134 commits
Select commit Hold shift + click to select a range
c547516
fix: add .gotmpl file extension for go template (#2218) (#2222)
binbin-li May 8, 2025
746f5b9
fix: add .gotmpl to helmfile in Makefile (#2224)
binbin-li May 8, 2025
cf0c359
chore: update ratify-project to notaryproject in helmfile (#2258)
binbin-li May 27, 2025
74da2d1
exclude .md files (#2280)
vanshika622 Jun 17, 2025
340d73e
remove references to Bridge2Kubernetes from contributing guide (#2343)
shahramk64 Aug 1, 2025
710f214
Merge branch 'v1' into v1-dev
binbin-li Sep 8, 2025
c986d77
feat: Let Ratify server allow multiple tls client cacert (#2412)
RemindD Sep 26, 2025
b5ad1ff
chore: bump package and CI tool versions (#2449)
akashsinghal Oct 26, 2025
b363d2f
feat: add slsa verifier plugin to verify slsa vsa and provenance (#2442)
DahuK Nov 5, 2025
aeaff8c
fix: resolve scan-vulns and golang-lint CI failures (#2557)
YitongFeng-git Jun 4, 2026
09df44a
chore: make CRD image Trivy scan warning only (#2576)
fseldow Jun 18, 2026
d58e5e4
chore: v1-dev workflow trigger fix (#2584)
fseldow Jun 23, 2026
313fd08
chore: update Go version to 1.26.4 (#2568)
fseldow Jun 23, 2026
84e9a7c
feat: make k8Secrets auth provider secret cache TTL configurable (#2581)
ramasai1 Jun 24, 2026
4544d13
Add Xinhe Li as Ratify maintainer (#2597)
fseldow Jun 30, 2026
91f9a4a
chore: bump sigstore/rekor v1.5.1 to v1.5.2 (#2619)
fseldow Jun 30, 2026
f6151fe
chore: Bump sigstore/cosign/v3 to v3.1.1 and k8s.io (#2653)
fseldow Jul 2, 2026
e2e7630
chore: Bump oras.land/oras-go/v2 from v2.6.0 to v2.6.1
fseldow Jul 3, 2026
69940c0
fix: add emptyDir for ORAS local cache to support nonroot image build…
fseldow Jul 5, 2026
79225a5
fix: initialize registryHostGetter in MIAuthProvider to prevent nil p…
fseldow Jul 5, 2026
35c9248
Merge branch 'v1' into v1-dev
fseldow Jul 5, 2026
06398bf
test: add unit tests for SLSA verifier plugin (#2668)
fseldow Jul 5, 2026
8c58d92
chore: Bump oras.land/oras-go/v2 from v2.6.1 to v2.6.2
fseldow Jul 10, 2026
624e7a8
Merge branch 'v1' into v1-dev
fseldow Jul 13, 2026
0040284
chore: bump Go version to 1.26.5 and ignore no actionable go vuln (#2…
fseldow Jul 21, 2026
1435126
chore: Bump alpine from `4b7ce07` to `28bd5fe` (#2758)
dependabot[bot] Jul 21, 2026
8b91e60
chore: Bump actions/cache from 4.2.x to 6.1.0 (#2773)
fseldow Jul 21, 2026
fff895d
chore: Bump golangci/golangci-lint-action from 9.2.0 to 9.3.0 (#2760)
dependabot[bot] Jul 21, 2026
e5aa6af
chore: Bump sigstore/cosign-installer from 3.8.1 to 4.1.2 (#2759)
dependabot[bot] Jul 21, 2026
4864e33
chore: Bump ossf/scorecard-action from 2.4.1 to 2.4.3 (#2761)
dependabot[bot] Jul 21, 2026
4a29324
chore: Bump docker/login-action from 3.4.0 to 4.4.0 (#2762)
dependabot[bot] Jul 21, 2026
79566c5
chore: Bump github.com/aws/aws-sdk-go-v2 from 1.41.7 to 1.41.12 (#2765)
dependabot[bot] Jul 21, 2026
6ab45a0
chore: Bump github.com/notaryproject/notation-go from 1.3.1 to 1.3.2 …
dependabot[bot] Jul 21, 2026
d417499
chore: Bump github.com/sigstore/rekor from 1.5.2 to 1.5.3 (#2768)
dependabot[bot] Jul 21, 2026
017c617
chore: Bump k8s.io/api from 0.36.1 to 0.36.2 (#2769)
dependabot[bot] Jul 21, 2026
255c66d
chore: Bump github/codeql-action/init from 3.28.15 to 4.37.1 (#2775)
dependabot[bot] Jul 21, 2026
8eb6b7e
chore: Bump distroless/static from `c0f429e` to `f7f8f72` in /httpser…
dependabot[bot] Jul 21, 2026
53a464e
chore: Bump apache/skywalking-eyes/header from 0.7.0 to 0.8.0 (#2776)
dependabot[bot] Jul 21, 2026
09571de
chore: Bump actions/cache/save from 4.2.3 to 6.1.0 (#2763)
dependabot[bot] Jul 21, 2026
058d3d5
chore: Bump golang/govulncheck-action from 1.0.4 to 1.1.0 (#2777)
dependabot[bot] Jul 21, 2026
8e44440
chore: Bump azure/login from 2.2.0 to 3.0.0 (#2778)
dependabot[bot] Jul 21, 2026
475a6b1
feat(helm): add provider.mutationExcludedNamespaces for Assign webhoo…
eric-nichols-cava Jul 22, 2026
3e43f78
chore: Bump github.com/sigstore/sigstore-go from 1.2.0 to 1.2.2 (#2766)
dependabot[bot] Jul 22, 2026
86006cb
chore: Bump oras-project/setup-oras from 1.2.2 to 2.0.1 (#2785)
dependabot[bot] Jul 22, 2026
f64d1da
chore: Bump google.golang.org/grpc from v1.82.0 to v1.82.1 (#2795)
fseldow Jul 22, 2026
a175342
chore: Bump step-security/harden-runner from 2.11.1 to 2.20.0 (#2786)
dependabot[bot] Jul 22, 2026
f8c498e
chore: Bump nick-fields/retry from 3.0.2 to 4.0.0 (#2787)
dependabot[bot] Jul 23, 2026
cbe7063
chore: Bump actions/checkout from 4.2.2 to 7.0.1 (#2788)
dependabot[bot] Jul 23, 2026
00dd0ff
chore: Bump github/codeql-action/upload-sarif from 3.28.15 to 4.37.3 …
dependabot[bot] Jul 23, 2026
688d199
chore: Bump anchore/sbom-action/download-syft from 0.18.0 to 0.24.0 (…
dependabot[bot] Jul 23, 2026
78eb625
chore: Bump actions/setup-go from 5.4.0 to 7.0.0 (#2801)
dependabot[bot] Jul 23, 2026
dd77d9a
chore: Bump gaurav-nelson/github-action-markdown-link-check from 1.0.…
dependabot[bot] Jul 23, 2026
e8d0580
chore: Bump apache/skywalking-eyes/dependency from 0.7.0 to 0.8.0 (#2…
dependabot[bot] Jul 23, 2026
9497dd8
chore: Bump github.com/Azure/azure-sdk-for-go/sdk/containers/azcontai…
dependabot[bot] Jul 23, 2026
22fd6e3
chore: Bump github.com/aws/aws-sdk-go-v2/config from 1.32.20 to 1.32.…
dependabot[bot] Jul 24, 2026
1e4a556
chore: Bump github.com/carabiner-dev/signer from 0.3.2 to 0.3.7 (#2807)
dependabot[bot] Jul 24, 2026
fd7b71f
chore: Bump github.com/aws/aws-sdk-go-v2/service/ecr from 1.55.3 to 1…
dependabot[bot] Jul 24, 2026
b9a8820
chore: Bump docker/login-action from 4.4.0 to 4.5.0 (#2818)
dependabot[bot] Jul 24, 2026
f202f13
chore: Bump goreleaser/goreleaser-action from 6.3.0 to 7.2.3 (#2819)
dependabot[bot] Jul 24, 2026
9292401
chore: Bump ossf/scorecard-action from 2.4.3 to 2.4.4 (#2821)
dependabot[bot] Jul 24, 2026
019c48d
chore: Bump github/codeql-action/analyze from 3.28.15 to 4.37.3 (#2820)
dependabot[bot] Jul 26, 2026
64e43b2
chore: Bump github/codeql-action/init from 4.37.1 to 4.37.3 (#2806)
dependabot[bot] Jul 26, 2026
8605c39
chore: Bump docker/login-action from 4.5.0 to 4.5.1 (#2837)
dependabot[bot] Jul 27, 2026
109ce48
chore: Bump actions/upload-artifact from 4.6.2 to 7.0.1 (#2835)
dependabot[bot] Jul 27, 2026
fc93201
chore: Bump codecov/codecov-action from 5.4.0 to 7.0.0 (#2836)
dependabot[bot] Jul 27, 2026
52c9ac9
chore: Bump golang.org/x/text from v0.38.0 to v0.40.0
fseldow Jul 29, 2026
7552c0b
chore: Bump docker/login-action from 4.5.1 to 4.5.2 (#2845)
dependabot[bot] Jul 29, 2026
9c62f27
chore: Bump github.com/aws/aws-sdk-go-v2 from 1.43.0 to 1.43.2 (#2856)
dependabot[bot] Jul 30, 2026
b90e818
chore: Bump k8s.io/apimachinery from 0.36.2 to 0.36.3 (#2857)
dependabot[bot] Jul 30, 2026
20a3301
chore: Bump docker/login-action from 4.5.2 to 4.6.0 (#2852)
dependabot[bot] Jul 30, 2026
10d3bbe
chore: Bump github.com/sigstore/cosign/v3 from 3.1.1 to 3.1.2 (#2855)
dependabot[bot] Jul 30, 2026
3390c6d
chore: Bump github.com/aws/aws-sdk-go-v2/credentials from 1.19.30 to …
dependabot[bot] Jul 30, 2026
f766109
chore: Bump github/codeql-action/upload-sarif from 4.37.3 to 4.37.4 (…
dependabot[bot] Aug 4, 2026
b2c2f81
chore: Bump github/codeql-action/init from 4.37.3 to 4.37.4 (#2869)
dependabot[bot] Aug 4, 2026
5bbdb81
chore: Bump github/codeql-action/analyze from 4.37.3 to 4.37.4 (#2866)
dependabot[bot] Aug 4, 2026
b5da346
chore: Bump github/codeql-action/init from 4.37.4 to 4.37.5 (#2883)
dependabot[bot] Aug 6, 2026
6a3e8ce
chore: Bump github.com/aws/aws-sdk-go-v2/config from 1.32.31 to 1.32.…
dependabot[bot] Aug 6, 2026
fa4e6bf
chore: Bump github/codeql-action/analyze from 4.37.4 to 4.37.5 (#2889)
dependabot[bot] Aug 6, 2026
b02de7a
chore: Bump k8s.io/client-go from 0.36.2 to 0.36.3 (#2887)
dependabot[bot] Aug 6, 2026
6f297cc
chore: Bump github/codeql-action/upload-sarif from 4.37.4 to 4.37.5 (…
dependabot[bot] Aug 6, 2026
3fe4b3b
chore: Bump github.com/alibabacloud-go/darabonba-openapi/v2 from 2.0.…
dependabot[bot] Aug 6, 2026
ffd0cec
chore: Bump github.com/google/go-containerregistry from 0.21.7 to 0.2…
dependabot[bot] Aug 6, 2026
13995b7
chore: Bump step-security/harden-runner from 2.20.0 to 2.20.1 (#2899)
dependabot[bot] Aug 7, 2026
6f6a365
chore: Bump azure/login from 3.0.0 to 3.0.1 (#2898)
dependabot[bot] Aug 7, 2026
9de961f
chore: Bump github/codeql-action/upload-sarif from 4.37.5 to 4.37.6 (…
dependabot[bot] Aug 7, 2026
37dd2f9
chore: Bump github/codeql-action/analyze from 4.37.5 to 4.37.6 (#2893)
dependabot[bot] Aug 10, 2026
1b53224
fix: do not compare against empty string to inject `azure.workload.id…
ramasai1 Aug 11, 2026
a8e6954
chore: Bump github.com/sigstore/cosign/v3 from 3.1.2 to 3.1.3 (#2909)
dependabot[bot] Aug 13, 2026
4a311d0
chore: Bump github.com/aliyun/credentials-go from 1.4.6 to 1.4.12 (#2…
dependabot[bot] Aug 13, 2026
1429016
chore: Bump github.com/sigstore/sigstore from 1.10.8 to 1.10.9 (#2908)
dependabot[bot] Aug 17, 2026
00f3ad0
chore: Bump github.com/alibabacloud-go/tea-utils/v2 from 2.0.7 to 2.0…
dependabot[bot] Aug 17, 2026
b5f8959
chore: bump Go Docker image to 1.26.6 (#2925)
fseldow Aug 17, 2026
84509c9
chore: Bump vulnerable dependencies [CVE-2026-56864, CVE-2026-56865, …
github-actions[bot] Aug 24, 2026
e03bc93
chore: Bump github.com/go-logr/logr from 1.4.3 to 1.4.4 (#2928)
dependabot[bot] Aug 24, 2026
ae5935d
chore: Bump github/codeql-action/upload-sarif from 4.37.6 to 4.37.8 (…
dependabot[bot] Aug 24, 2026
be6178d
chore: Bump google.golang.org/protobuf from 1.36.12-0.20260120151049-…
dependabot[bot] Aug 24, 2026
3b874a6
chore: Bump github.com/aws/aws-sdk-go-v2 from 1.43.3 to 1.43.6 (#2931)
dependabot[bot] Aug 24, 2026
814b241
chore: Bump github.com/google/go-containerregistry from 0.21.8 to 0.2…
dependabot[bot] Aug 24, 2026
07732c3
chore: Bump step-security/harden-runner from 2.20.1 to 2.21.0 (#2922)
dependabot[bot] Aug 24, 2026
be387cb
chore: Bump github/codeql-action/init from 4.37.5 to 4.37.6 (#2897)
dependabot[bot] Aug 24, 2026
3806ae2
chore: Bump github/codeql-action/analyze from 4.37.6 to 4.37.8 (#2938)
dependabot[bot] Aug 24, 2026
c8f8f3c
chore: Bump github/codeql-action/init from 4.37.6 to 4.37.8 (#2945)
dependabot[bot] Aug 25, 2026
a313144
chore: Bump github.com/aws/aws-sdk-go-v2/config from 1.32.34 to 1.32.…
dependabot[bot] Aug 29, 2026
d47ffd7
chore: Bump distroless/static from `f7f8f72` to `1c2c046` in /httpser…
dependabot[bot] Aug 29, 2026
5d75b9e
chore: Bump github.com/sigstore/rekor from 1.5.3 to 1.5.4 (#2951)
dependabot[bot] Aug 29, 2026
a40edf6
chore: Bump github.com/aliyun/credentials-go from 1.4.12 to 1.4.13 (#…
dependabot[bot] Aug 30, 2026
0a70cbf
chore: Bump github.com/aws/aws-sdk-go-v2/credentials from 1.19.37 to …
dependabot[bot] Aug 30, 2026
1d6d758
chore: Bump github/codeql-action/init from 4.37.8 to 4.37.9 (#2959)
dependabot[bot] Sep 1, 2026
a11652f
chore: Bump github/codeql-action/analyze from 4.37.8 to 4.37.9 (#2960)
dependabot[bot] Sep 1, 2026
0f7c1f4
chore: Bump azure/login from 3.0.1 to 3.0.2 (#2962)
dependabot[bot] Sep 1, 2026
b09bbcb
chore: Bump step-security/harden-runner from 2.21.0 to 2.21.1 (#2967)
dependabot[bot] Sep 2, 2026
4cca4c9
chore: Bump github/codeql-action/upload-sarif from 4.37.8 to 4.37.9 (…
dependabot[bot] Sep 2, 2026
d42d8de
chore: Bump anchore/sbom-action/download-syft from 0.24.0 to 0.24.2 (…
dependabot[bot] Sep 2, 2026
ab83ad1
chore: Bump vulnerable dependencies [CVE-2026-56855, CVE-2026-78662, …
github-actions[bot] Sep 3, 2026
61079e6
chore: Bump k8s.io/apimachinery from 0.36.3 to 0.36.4 (#2974)
dependabot[bot] Sep 7, 2026
4626c0c
chore: Bump k8s.io/api from 0.36.3 to 0.36.4 (#2973)
dependabot[bot] Sep 8, 2026
e70a948
chore: Bump k8s.io/client-go from 0.36.3 to 0.36.4 (#2986)
dependabot[bot] Sep 10, 2026
b38e29e
chore: Bump github.com/Azure/azure-sdk-for-go/sdk/azidentity from 1.1…
dependabot[bot] Sep 10, 2026
682fbed
ci: validate published image before chart publish (#2923)
fseldow Sep 11, 2026
73295ed
chore: Bump github/codeql-action/upload-sarif from 4.37.9 to 4.38.0 (…
dependabot[bot] Sep 15, 2026
63f8cc1
chore: Bump step-security/harden-runner from 2.20.1 to 2.21.1 (#2995)
dependabot[bot] Sep 15, 2026
91fd13b
chore: Bump github/codeql-action/analyze from 4.37.9 to 4.38.0 (#2990)
dependabot[bot] Sep 15, 2026
f2f587e
chore: Bump azure/login from 3.0.2 to 3.1.0 (#2988)
dependabot[bot] Sep 15, 2026
79cb204
fix: remove live schemastore.org dependency from SARIF schema validat…
fseldow Sep 17, 2026
5ba3452
chore: Bump distroless/static from `1c2c046` to `e2e927e` in /httpser…
dependabot[bot] Sep 17, 2026
b7d67e4
chore: Bump codecov/codecov-action from 7.0.0 to 7.1.0 (#3002)
dependabot[bot] Sep 20, 2026
ca37ba8
chore: Bump github/codeql-action/init from 4.37.9 to 4.38.0 (#2997)
dependabot[bot] Sep 20, 2026
7dc8767
fix: propagate e2e image repository/tag to test-e2e (backport #2999) …
fseldow Sep 20, 2026
53cdc32
fix: use propagated image vars in e2e-helm-deploy-ratify-without-tls-…
fseldow Sep 20, 2026
e24390c
chore: Bump github/codeql-action/init from 4.38.0 to 4.38.1 (#3012)
dependabot[bot] Sep 21, 2026
682649c
chore: Bump github/codeql-action/upload-sarif from 4.38.0 to 4.38.1 (…
dependabot[bot] Sep 21, 2026
9c4d388
chore: Bump github/codeql-action/analyze from 4.38.0 to 4.38.1 (#3013)
dependabot[bot] Sep 21, 2026
96b0d14
chore: Bump codecov/codecov-action from 7.1.0 to 7.1.1 (#3014)
dependabot[bot] Sep 24, 2026
4369806
chore: Bump alpine from `28bd5fe` to `294b683` (#3018)
dependabot[bot] Sep 24, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
14 changes: 12 additions & 2 deletions .github/actions/restore_trivy_cache/action.yml
Original file line number Diff line number Diff line change
@@ -1,6 +1,11 @@
name: "Steps to restore trivy cache"
description: "Steps to restore Trivy cache under ~/.cache/trivy"

outputs:
cache-hit:
description: "Whether the trivy cache was restored"
value: ${{ steps.cache-status.outputs.cache-hit }}

runs:
using: "composite"
steps:
Expand All @@ -9,12 +14,17 @@ runs:
run: echo "date=$(date +'%Y-%m-%d')" >> $GITHUB_OUTPUT
shell: bash
- name: Restore trivy cache directory
uses: actions/cache/restore@0c907a75c2c80ebcb7f088228285e798b750cf8f # v4.2.1
uses: actions/cache/restore@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
with:
path: ${{ github.workspace }}/.cache/trivy
key: cache-trivy-${{ steps.date.outputs.date }}
- name: Set up trivy cache directory
run: |
mkdir -p ~/.cache/trivy
cp -r ${{ github.workspace }}/.cache/trivy/db ~/.cache/trivy
if [[ -d "${{ github.workspace }}/.cache/trivy/db" ]]; then
cp -r ${{ github.workspace }}/.cache/trivy/db ~/.cache/trivy
else
echo "cache-hit=false" >> $GITHUB_OUTPUT
fi
shell: bash
id: cache-status
8 changes: 4 additions & 4 deletions .github/workflows/build-pr.yml
Original file line number Diff line number Diff line change
Expand Up @@ -75,19 +75,19 @@ jobs:
environment: azure-test
steps:
- name: Harden Runner
uses: step-security/harden-runner@c6295a65d1254861815972266d5933fd6e532bdf # v2.11.1
uses: step-security/harden-runner@e14015d583714f6e62063499dc959a02595150a1 # v2.21.1
with:
egress-policy: audit

- name: Check out code into the Go module directory
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- name: Set up Go 1.24
uses: actions/setup-go@0aaccfd150d50ccaeb58ebd88d36e91967a5f35b # v5.4.0
uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0
with:
go-version: "1.26"

- name: Az CLI login
uses: azure/login@a65d910e8af852a8061c627c456678983e180302 # v2.2.0
uses: azure/login@a641126d1b8aa4d1fa005f4f92df94a3a4c4c906 # v3.1.0
with:
client-id: ${{ secrets.AZURE_CLIENT_ID }}
tenant-id: ${{ secrets.AZURE_TENANT_ID }}
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/cache-cleanup.yml
Original file line number Diff line number Diff line change
Expand Up @@ -12,7 +12,7 @@ jobs:
runs-on: ubuntu-latest
steps:
- name: Harden Runner
uses: step-security/harden-runner@0634a2670c59f64b4a01f0f96f84700a4088b9f0 # v2.12.0
uses: step-security/harden-runner@e14015d583714f6e62063499dc959a02595150a1 # v2.21.1
with:
egress-policy: audit

Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/clean-dev-package.yml
Original file line number Diff line number Diff line change
Expand Up @@ -13,7 +13,7 @@ jobs:
packages: write
steps:
- name: Harden Runner
uses: step-security/harden-runner@c6295a65d1254861815972266d5933fd6e532bdf # v2.11.1
uses: step-security/harden-runner@e14015d583714f6e62063499dc959a02595150a1 # v2.21.1
with:
egress-policy: audit

Expand Down
10 changes: 5 additions & 5 deletions .github/workflows/codeql.yml
Original file line number Diff line number Diff line change
Expand Up @@ -28,23 +28,23 @@ jobs:

steps:
- name: Harden Runner
uses: step-security/harden-runner@c6295a65d1254861815972266d5933fd6e532bdf # v2.11.1
uses: step-security/harden-runner@e14015d583714f6e62063499dc959a02595150a1 # v2.21.1
with:
egress-policy: audit

- name: Checkout repository
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # tag=3.0.2
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- name: setup go environment
uses: actions/setup-go@0aaccfd150d50ccaeb58ebd88d36e91967a5f35b # v5.4.0
uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0
with:
go-version: "1.22"
- name: Initialize CodeQL
uses: github/codeql-action/init@45775bd8235c68ba998cffa5171334d58593da47 # tag=v3.28.15
uses: github/codeql-action/init@1c5b675653bb5c22dbe9b12b556ec555138e09fd # tag=v4.38.1
with:
languages: go
- name: Run tidy
run: go mod tidy
- name: Build CLI
run: make build
- name: Perform CodeQL Analysis
uses: github/codeql-action/analyze@45775bd8235c68ba998cffa5171334d58593da47 # tag=v3.28.15
uses: github/codeql-action/analyze@1c5b675653bb5c22dbe9b12b556ec555138e09fd # tag=v4.38.1
10 changes: 5 additions & 5 deletions .github/workflows/e2e-aks.yml
Original file line number Diff line number Diff line change
Expand Up @@ -28,18 +28,18 @@ jobs:
contents: read
steps:
- name: Harden Runner
uses: step-security/harden-runner@c6295a65d1254861815972266d5933fd6e532bdf # v2.11.1
uses: step-security/harden-runner@e14015d583714f6e62063499dc959a02595150a1 # v2.21.1
with:
egress-policy: audit

- name: Check out code into the Go module directory
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- name: Set up Go 1.24
uses: actions/setup-go@0aaccfd150d50ccaeb58ebd88d36e91967a5f35b # v5.4.0
uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0
with:
go-version: "1.24"
- name: Az CLI login
uses: azure/login@a65d910e8af852a8061c627c456678983e180302 # v2.2.0
uses: azure/login@a641126d1b8aa4d1fa005f4f92df94a3a4c4c906 # v3.1.0
with:
client-id: ${{ secrets.AZURE_CLIENT_ID }}
tenant-id: ${{ secrets.AZURE_TENANT_ID }}
Expand Down Expand Up @@ -67,7 +67,7 @@ jobs:
make e2e-aks KUBERNETES_VERSION=${{ inputs.k8s_version }} GATEKEEPER_VERSION=${{ inputs.gatekeeper_version }} TENANT_ID=${{ secrets.AZURE_TENANT_ID }} AZURE_SP_OBJECT_ID=${{ secrets.AZURE_SP_OBJECT_ID }}

- name: Upload artifacts
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
if: ${{ always() }}
with:
name: e2e-logs-aks-${{ inputs.k8s_version }}-${{ inputs.gatekeeper_version }}
Expand Down
30 changes: 15 additions & 15 deletions .github/workflows/e2e-cli.yml
Original file line number Diff line number Diff line change
Expand Up @@ -14,34 +14,34 @@ jobs:
runs-on: ubuntu-latest
steps:
- name: Harden Runner
uses: step-security/harden-runner@c6295a65d1254861815972266d5933fd6e532bdf # v2.11.1
uses: step-security/harden-runner@e14015d583714f6e62063499dc959a02595150a1 # v2.21.1
with:
egress-policy: audit

- name: Checkout
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- name: Check license header
uses: apache/skywalking-eyes/header@5c5b974209f0de5d905f37deb69369068ebfc15c
uses: apache/skywalking-eyes/header@61275cc80d0798a405cb070f7d3a8aaf7cf2c2c1
with:
mode: check
config: .github/licenserc.yml
- name: Check dependencies license
uses: apache/skywalking-eyes/dependency@5c5b974209f0de5d905f37deb69369068ebfc15c
uses: apache/skywalking-eyes/dependency@61275cc80d0798a405cb070f7d3a8aaf7cf2c2c1
with:
config: .github/licenserc.yml
flags: --weak-compatible=true
build:
runs-on: ubuntu-latest
steps:
- name: Harden Runner
uses: step-security/harden-runner@c6295a65d1254861815972266d5933fd6e532bdf # v2.11.1
uses: step-security/harden-runner@e14015d583714f6e62063499dc959a02595150a1 # v2.21.1
with:
egress-policy: audit

- name: Checkout
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- name: setup go environment
uses: actions/setup-go@0aaccfd150d50ccaeb58ebd88d36e91967a5f35b # v5.4.0
uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0
with:
go-version: "1.26"
- name: Run tidy
Expand All @@ -51,7 +51,7 @@ jobs:
- name: Check build
run: bin/ratify version
- name: Upload coverage to codecov.io
uses: codecov/codecov-action@0565863a31f2c772f9f0395002a31e3f06189574 # v5.4.0
uses: codecov/codecov-action@303a32d7a59b442fa8d48b6a1cc6825c09c847a5 # v7.1.1
with:
token: ${{ secrets.CODECOV_TOKEN }}
- name: Run helm lint
Expand All @@ -63,14 +63,14 @@ jobs:
contents: read
steps:
- name: Harden Runner
uses: step-security/harden-runner@c6295a65d1254861815972266d5933fd6e532bdf # v2.11.1
uses: step-security/harden-runner@e14015d583714f6e62063499dc959a02595150a1 # v2.21.1
with:
egress-policy: audit

- name: Checkout
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- name: setup go environment
uses: actions/setup-go@0aaccfd150d50ccaeb58ebd88d36e91967a5f35b # v5.4.0
uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0
with:
go-version: "1.26"
- name: Run tidy
Expand All @@ -86,23 +86,23 @@ jobs:
make install ratify-config install-bats
make test-e2e-cli GOCOVERDIR=${GITHUB_WORKSPACE}/test/e2e/.cover
- name: Upload coverage to codecov.io
uses: codecov/codecov-action@0565863a31f2c772f9f0395002a31e3f06189574 # v5.4.0
uses: codecov/codecov-action@303a32d7a59b442fa8d48b6a1cc6825c09c847a5 # v7.1.1
with:
token: ${{ secrets.CODECOV_TOKEN }}
markdown-link-check:
runs-on: ubuntu-latest
steps:
- name: Harden Runner
uses: step-security/harden-runner@c6295a65d1254861815972266d5933fd6e532bdf # v2.11.1
uses: step-security/harden-runner@e14015d583714f6e62063499dc959a02595150a1 # v2.21.1
with:
egress-policy: audit

- name: Checkout
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
submodules: recursive
- name: Run link check
uses: gaurav-nelson/github-action-markdown-link-check@1b916f2cf6c36510a6059943104e3c42ce6c16bc #3.10.3
uses: gaurav-nelson/github-action-markdown-link-check@3c3b66f1f7d0900e37b71eca45b63ea9eedfce31 # 1.0.17
with:
use-quiet-mode: "no"
use-verbose-mode: "yes"
Expand Down
63 changes: 52 additions & 11 deletions .github/workflows/e2e-k8s.yml
Original file line number Diff line number Diff line change
Expand Up @@ -4,6 +4,28 @@ permissions:
contents: read

on:
workflow_dispatch:
inputs:
k8s_version:
description: "Kubernetes version"
required: true
default: "1.31.2"
type: string
gatekeeper_version:
description: "Gatekeeper version"
required: true
default: "3.18.0"
type: string
ratify_image_repository:
description: "Ratify image repository used by the Helm chart"
required: false
default: "localbuild"
type: string
ratify_image_tag:
description: "Ratify image tag used by the Helm chart"
required: false
default: "test"
type: string
workflow_call:
inputs:
k8s_version:
Expand All @@ -16,6 +38,16 @@ on:
required: true
default: "3.18.0"
type: string
ratify_image_repository:
description: "Ratify image repository used by the Helm chart"
required: false
default: "localbuild"
type: string
ratify_image_tag:
description: "Ratify image tag used by the Helm chart"
required: false
default: "test"
type: string

jobs:
build_test_e2e:
Expand All @@ -26,14 +58,14 @@ jobs:
contents: read
steps:
- name: Harden Runner
uses: step-security/harden-runner@c6295a65d1254861815972266d5933fd6e532bdf # v2.11.1
uses: step-security/harden-runner@e14015d583714f6e62063499dc959a02595150a1 # v2.21.1
with:
egress-policy: audit

- name: Check out code into the Go module directory
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- name: Set up Go 1.24
uses: actions/setup-go@0aaccfd150d50ccaeb58ebd88d36e91967a5f35b # v5.4.0
uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0
with:
go-version: "1.26"
- name: Restore Trivy cache
Expand All @@ -47,8 +79,14 @@ jobs:
- name: Run e2e with config policy
run: |
make e2e-deploy-gatekeeper GATEKEEPER_VERSION=${{ inputs.gatekeeper_version }}
make e2e-deploy-ratify GATEKEEPER_VERSION=${{ inputs.gatekeeper_version }}
make test-e2e GATEKEEPER_VERSION=${{ inputs.gatekeeper_version }}
make e2e-deploy-ratify \
GATEKEEPER_VERSION="${{ inputs.gatekeeper_version }}" \
E2E_RATIFY_IMAGE_REPOSITORY="${{ inputs.ratify_image_repository }}" \
E2E_RATIFY_IMAGE_TAG="${{ inputs.ratify_image_tag }}"
make test-e2e \
GATEKEEPER_VERSION="${{ inputs.gatekeeper_version }}" \
E2E_RATIFY_IMAGE_REPOSITORY="${{ inputs.ratify_image_repository }}" \
E2E_RATIFY_IMAGE_TAG="${{ inputs.ratify_image_tag }}"
- name: Save logs
if: ${{ always() }}
run: |
Expand All @@ -57,16 +95,19 @@ jobs:
- name: Run e2e with Rego policy
run: |
make deploy-rego-policy
make test-e2e
make test-e2e \
GATEKEEPER_VERSION="${{ inputs.gatekeeper_version }}" \
E2E_RATIFY_IMAGE_REPOSITORY="${{ inputs.ratify_image_repository }}" \
E2E_RATIFY_IMAGE_TAG="${{ inputs.ratify_image_tag }}"
- name: Save logs
if: ${{ always() }}
run: |
kubectl logs -n gatekeeper-system -l control-plane=controller-manager --tail=-1 > logs-externaldata-controller-${{ matrix.KUBERNETES_VERSION }}-${{ matrix.GATEKEEPER_VERSION }}.json
kubectl logs -n gatekeeper-system -l control-plane=audit-controller --tail=-1 > logs-externaldata-audit-${{ matrix.KUBERNETES_VERSION }}-${{ matrix.GATEKEEPER_VERSION }}.json
kubectl logs -n gatekeeper-system -l app=ratify --tail=-1 > logs-ratify-preinstall-${{ matrix.KUBERNETES_VERSION }}-${{ matrix.GATEKEEPER_VERSION }}-rego-policy.json
kubectl logs -n gatekeeper-system -l app.kubernetes.io/name=ratify --tail=-1 > logs-ratify-${{ matrix.KUBERNETES_VERSION }}-${{ matrix.GATEKEEPER_VERSION }}-rego-policy.json
kubectl logs -n gatekeeper-system -l control-plane=controller-manager --tail=-1 > logs-externaldata-controller-${{ inputs.k8s_version }}-${{ inputs.gatekeeper_version }}.json
kubectl logs -n gatekeeper-system -l control-plane=audit-controller --tail=-1 > logs-externaldata-audit-${{ inputs.k8s_version }}-${{ inputs.gatekeeper_version }}.json
kubectl logs -n gatekeeper-system -l app=ratify --tail=-1 > logs-ratify-preinstall-${{ inputs.k8s_version }}-${{ inputs.gatekeeper_version }}-rego-policy.json
kubectl logs -n gatekeeper-system -l app.kubernetes.io/name=ratify --tail=-1 > logs-ratify-${{ inputs.k8s_version }}-${{ inputs.gatekeeper_version }}-rego-policy.json
- name: Upload artifacts
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
if: ${{ always() }}
with:
name: e2e-logs-${{ inputs.k8s_version }}-${{ inputs.gatekeeper_version }}
Expand Down
8 changes: 4 additions & 4 deletions .github/workflows/golangci-lint.yml
Original file line number Diff line number Diff line change
Expand Up @@ -18,16 +18,16 @@ jobs:
runs-on: ubuntu-latest
steps:
- name: Harden Runner
uses: step-security/harden-runner@c6295a65d1254861815972266d5933fd6e532bdf # v2.11.1
uses: step-security/harden-runner@e14015d583714f6e62063499dc959a02595150a1 # v2.21.1
with:
egress-policy: audit

- uses: actions/setup-go@0aaccfd150d50ccaeb58ebd88d36e91967a5f35b # v5.4.0
- uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0
with:
go-version: "1.26.4"
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- name: golangci-lint
uses: golangci/golangci-lint-action@1e7e51e771db61008b38414a730f564565cf7c20 # v9.2.0
uses: golangci/golangci-lint-action@ba0d7d2ec06a0ea1cb5fa41b2e4a3ab91d21278a # v9.3.0
with:
version: v2.12.2
args: --timeout=10m
8 changes: 4 additions & 4 deletions .github/workflows/high-availability.yml
Original file line number Diff line number Diff line change
Expand Up @@ -32,14 +32,14 @@ jobs:
DAPR_VERSION: ["1.14.4"]
steps:
- name: Harden Runner
uses: step-security/harden-runner@c6295a65d1254861815972266d5933fd6e532bdf # v2.11.1
uses: step-security/harden-runner@e14015d583714f6e62063499dc959a02595150a1 # v2.21.1
with:
egress-policy: audit

- name: Check out code into the Go module directory
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- name: Set up Go 1.24
uses: actions/setup-go@0aaccfd150d50ccaeb58ebd88d36e91967a5f35b # v5.4.0
uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0
with:
go-version: "1.24"

Expand All @@ -62,7 +62,7 @@ jobs:
kubectl logs -n gatekeeper-system -l app=ratify --tail=-1 > logs-ratify-preinstall-${{ matrix.DAPR_VERSION }}.json
kubectl logs -n gatekeeper-system -l app.kubernetes.io/name=ratify --tail=-1 > logs-ratify-${{ matrix.DAPR_VERSION }}.json
- name: Upload artifacts
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
if: ${{ always() }}
with:
name: e2e-logs-${{ matrix.DAPR_VERSION }}
Expand Down
Loading
Loading