NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Go modules · #2232 by repository stars
Last release 4 days ago
03 Oct 2026
Ships fairly regularly
a new release about every 9 days
Some releases are documented
notes for 19 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
6 years old
811 releases · first in 2020
One column per quarter.
None. This is a rebuild of all components to address vulnerabilities in the base images.
None. This is a rebuild of all components to address vulnerabilities in the base images.
To see a list of addressed vulnerabilities, please refer to #2379
None. This is a rebuild of all components to address vulnerabilities in the base images.
None. This is a rebuild of all components to address vulnerabilities in the base images.
To see a list of addressed vulnerabilities, please refer to #2374
None. This is a rebuild of all components to address vulnerabilities in the base images.
None. This is a rebuild of all components to address vulnerabilities in the base images.
To see a list of addressed vulnerabilities, please refer to #2369
None. This is a rebuild of all components to address vulnerabilities in the base images.
None. This is a rebuild of all components to address vulnerabilities in the base images.
To see a list of addressed vulnerabilities, please refer to #2363
None. This is a rebuild of all components to address vulnerabilities in the base images.
None. This is a rebuild of all components to address vulnerabilities in the base images.
To see a list of addressed vulnerabilities, please refer to #2355
None. This is a rebuild of all components to address vulnerabilities in the base images.
None. This is a rebuild of all components to address vulnerabilities in the base images.
To see a list of addressed vulnerabilities, please refer to #2346
None. This is a rebuild of all components to address vulnerabilities in the base images and in Go libraries.
None. This is a rebuild of all components to address vulnerabilities in the base images and in Go libraries.
To see a list of addressed vulnerabilities, please refer to #2346
#2337 by @openshift-cherrypick-robot: Update golang.org/x/crypto from v0.55.0 to v0.56.0 to address CVE-2026-56855 and CVE-2026-78662
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Release changes since v0.20.0 Features #2275 by @anchi205 : Shipwright now rejects a list of environment variables when creating a Build or BuildRun.
#2275 by @anchi205: Shipwright now rejects a list of environment variables when creating a Build or BuildRun. The list can be customized.
#2187 by @avinal: action required: metric changes with new metrics (build_buildrun_result_total, build_buildrun_failure_reason_total, build_buildruns_active, build_buildstrategy_count), new labels (strategy_kind, executor, result, source_type; opt-in via PROMETHEUS_ENABLED_LABELS), deprecation (build_buildruns_completed_total in favor of build_buildrun_result_total), changes (build_builds_registered_total now counts both successful and failed registrations)
#2305 by @Ryntak94: Fixed BuildRun conversion silently dropping .spec.output.insecure and .spec.output.timestamp. Both fields are now preserved when a BuildRun is converted between v1alpha1 and v1beta1, matching the existing Build conversion behaviour.
#2292 by @SaschaSchwarze0: You can no longer create Builds and BuildRuns that have an empty annotation or label key for the output object. Also, keys are validated to not contain the = character which is actually a limitation Shipwright enforces due to how it handles this data in its processing.
#2252 by @kaizakin: SetOwnerReferenceFailed updates buildrun status instead of build and stops reconciliation instead of continuing to build
#2314 by @SaschaSchwarze0: Kubernetes 1.37 is now supported
#2313 by @shipwright-ci-bot: Update to the new latest Tekton LTS release v1.15.1
#2302 by @IrvingMg: The buildpacks-v3 sample build strategies now pin the Paketo builder image to a specific tag instead of using the floating latest tag.
#2294 by @SaschaSchwarze0: The minimum supported Tekton version is now v1.6
#2293 by @psrvere: Unset optional build parameter value fields are now omitted from serialized output instead of appearing as null.
#2228 by @shipwright-ci-bot: Update to the new latest Tekton LTS release v1.15.0
None. This is a rebuild of all components to address vulnerabilities in the base images.
None. This is a rebuild of all components to address vulnerabilities in the base images.
To see a list of addressed vulnerabilities, please refer to #2310
None. This is a rebuild of all components to address vulnerabilities in the base images.
None. This is a rebuild of all components to address vulnerabilities in the base images.
To see a list of addressed vulnerabilities, please refer to #2296
None. This is a rebuild of all components to address vulnerabilities in the base images and in Go libraries.
None. This is a rebuild of all components to address vulnerabilities in the base images and in Go libraries.
To see a list of addressed vulnerabilities, please refer to #2296
#2297 by @SaschaSchwarze0: Update github.com/go-git/go-git/v5 from v5.19.1 to v5.19.2 / Update github.com/google/cel-go from v0.28.0 to v0.30.0
None. This is a rebuild of all components to address vulnerabilities in the base images.
None. This is a rebuild of all components to address vulnerabilities in the base images.
To see a list of addressed vulnerabilities, please refer to #2291
None. This is a rebuild of all components to address vulnerabilities in the Go standard libraries.
None. This is a rebuild of all components to address vulnerabilities in the Go standard libraries.
To see a list of addressed vulnerabilities, please refer to #2289
None. This is a rebuild of all components to address vulnerabilities in the base images.
None. This is a rebuild of all components to address vulnerabilities in the base images.
To see a list of addressed vulnerabilities, please refer to #2287
None. This is a rebuild of all components to address vulnerabilities in the base images.
None. This is a rebuild of all components to address vulnerabilities in the base images.
To see a list of addressed vulnerabilities, please refer to #2281
None. This is a rebuild of all components to address vulnerabilities in the base images and Go dependencies.
None. This is a rebuild of all components to address vulnerabilities in the base images and Go dependencies.
To see a list of addressed vulnerabilities, please refer to #2267
#2272 by @SaschaSchwarze0: Update github.com/klauspost/compress from v1.18.5 to v1.18.7 to address GHSA-259r-337f-4rfw
#2269 by @SaschaSchwarze0: Update go.opentelemetry.io/otel from v1.43.0 to v1.44.0
None. This is a rebuild of all components to address vulnerabilities in the base images and Go dependencies.
None. This is a rebuild of all components to address vulnerabilities in the base images and Go dependencies.
To see a list of addressed vulnerabilities, please refer to #2260
#2262 by @SaschaSchwarze0: Update golang.org/x/net from v0.55.0 to v0.56.0 to address CVE-2026-46600 / Update golang.org/x/text from v0.37.0 to v0.39.0 to address CVE-2026-56852
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →