NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Go modules · #3186 by repository stars
Last release 9 days ago
29 Sep 2026
Ships on a steady schedule
a new release about every 2 weeks
Some releases are documented
notes for 21 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
6 years old
348 releases · first in 2020
One column per quarter.
kubectl apply -f https://infra.tekton.dev/tekton-releases/chains/previous/v0.29.7/release.yaml
kubectl apply -f https://infra.tekton.dev/tekton-releases/chains/previous/v0.29.7/release.yamlThe Rekor UUID for this release is 108e9186e8c5677ad62ac78a2a3e6cdb7c221dba2b07f1cc0e261697e446637426c97e60c7cb1da1
Obtain the attestation:
REKOR_UUID=108e9186e8c5677ad62ac78a2a3e6cdb7c221dba2b07f1cc0e261697e446637426c97e60c7cb1da1
rekor-cli get --uuid $REKOR_UUID --format json | jq -r .Attestation | jq .Verify that all container images in the attestation are in the release file:
RELEASE_FILE=https://infra.tekton.dev/tekton-releases/chains/previous/v0.29.7/release.yaml
REKOR_UUID=108e9186e8c5677ad62ac78a2a3e6cdb7c221dba2b07f1cc0e261697e446637426c97e60c7cb1da1
# Obtains the list of images with sha from the attestation
REKOR_ATTESTATION_IMAGES=$(rekor-cli get --uuid "$REKOR_UUID" --format json | jq -r .Attestation | jq -r '.subject[]|.name + ":v0.29.7@sha256:" + .digest.sha256')
# Download the release file
curl -L "$RELEASE_FILE" > release.yaml
# For each image in the attestation, match it to the release file
for image in $REKOR_ATTESTATION_IMAGES; do
printf $image; grep -q $image release.yaml && echo " ===> ok" || echo " ===> no match";
doneThanks to these contributors who contributed to v0.29.7!
Extra shout-out for awesome release notes:
kubectl apply -f https://infra.tekton.dev/tekton-releases/chains/previous/v0.29.6/release.yaml
kubectl apply -f https://infra.tekton.dev/tekton-releases/chains/previous/v0.29.6/release.yamlThe Rekor UUID for this release is 108e9186e8c5677a229a9884506039d69f0a436df370b0722b70af5911cce9882a7f7e0444c4e6d5
Obtain the attestation:
REKOR_UUID=108e9186e8c5677a229a9884506039d69f0a436df370b0722b70af5911cce9882a7f7e0444c4e6d5
rekor-cli get --uuid $REKOR_UUID --format json | jq -r .Attestation | jq .Verify that all container images in the attestation are in the release file:
RELEASE_FILE=https://infra.tekton.dev/tekton-releases/chains/previous/v0.29.6/release.yaml
REKOR_UUID=108e9186e8c5677a229a9884506039d69f0a436df370b0722b70af5911cce9882a7f7e0444c4e6d5
# Obtains the list of images with sha from the attestation
REKOR_ATTESTATION_IMAGES=$(rekor-cli get --uuid "$REKOR_UUID" --format json | jq -r .Attestation | jq -r '.subject[]|.name + ":v0.29.6@sha256:" + .digest.sha256')
# Download the release file
curl -L "$RELEASE_FILE" > release.yaml
# For each image in the attestation, match it to the release file
for image in $REKOR_ATTESTATION_IMAGES; do
printf $image; grep -q $image release.yaml && echo " ===> ok" || echo " ===> no match";
doneThanks to these contributors who contributed to v0.29.6!
Extra shout-out for awesome release notes:
kubectl apply -f https://infra.tekton.dev/tekton-releases/chains/previous/v0.29.5/release.yaml
kubectl apply -f https://infra.tekton.dev/tekton-releases/chains/previous/v0.29.5/release.yamlThe Rekor UUID for this release is 108e9186e8c5677a99cecf80f685974d0059e426a4e6b2906de7cdada6502d45ad1ddacf037dde1f
Obtain the attestation:
REKOR_UUID=108e9186e8c5677a99cecf80f685974d0059e426a4e6b2906de7cdada6502d45ad1ddacf037dde1f
rekor-cli get --uuid $REKOR_UUID --format json | jq -r .Attestation | jq .Verify that all container images in the attestation are in the release file:
RELEASE_FILE=https://infra.tekton.dev/tekton-releases/chains/previous/v0.29.5/release.yaml
REKOR_UUID=108e9186e8c5677a99cecf80f685974d0059e426a4e6b2906de7cdada6502d45ad1ddacf037dde1f
# Obtains the list of images with sha from the attestation
REKOR_ATTESTATION_IMAGES=$(rekor-cli get --uuid "$REKOR_UUID" --format json | jq -r .Attestation | jq -r '.subject[]|.name + ":v0.29.5@sha256:" + .digest.sha256')
# Download the release file
curl -L "$RELEASE_FILE" > release.yaml
# For each image in the attestation, match it to the release file
for image in $REKOR_ATTESTATION_IMAGES; do
printf $image; grep -q $image release.yaml && echo " ===> ok" || echo " ===> no match";
doneThanks to these contributors who contributed to v0.29.5!
Extra shout-out for awesome release notes:
kubectl apply -f https://infra.tekton.dev/tekton-releases/chains/previous/v0.29.4/release.yaml
kubectl apply -f https://infra.tekton.dev/tekton-releases/chains/previous/v0.29.4/release.yamlThe Rekor UUID for this release is 108e9186e8c5677a644211a39f17de419f949bce6b373e5ce707ead67e30d59e43f0bd7290612c23
Obtain the attestation:
REKOR_UUID=108e9186e8c5677a644211a39f17de419f949bce6b373e5ce707ead67e30d59e43f0bd7290612c23
rekor-cli get --uuid $REKOR_UUID --format json | jq -r .Attestation | jq .Verify that all container images in the attestation are in the release file:
RELEASE_FILE=https://infra.tekton.dev/tekton-releases/chains/previous/v0.29.4/release.yaml
REKOR_UUID=108e9186e8c5677a644211a39f17de419f949bce6b373e5ce707ead67e30d59e43f0bd7290612c23
# Obtains the list of images with sha from the attestation
REKOR_ATTESTATION_IMAGES=$(rekor-cli get --uuid "$REKOR_UUID" --format json | jq -r .Attestation | jq -r '.subject[]|.name + ":v0.29.4@sha256:" + .digest.sha256')
# Download the release file
curl -L "$RELEASE_FILE" > release.yaml
# For each image in the attestation, match it to the release file
for image in $REKOR_ATTESTATION_IMAGES; do
printf $image; grep -q $image release.yaml && echo " ===> ok" || echo " ===> no match";
doneThanks to these contributors who contributed to v0.29.4!
Extra shout-out for awesome release notes:
kubectl apply -f https://infra.tekton.dev/tekton-releases/chains/previous/v0.29.3/release.yaml
kubectl apply -f https://infra.tekton.dev/tekton-releases/chains/previous/v0.29.3/release.yamlThe Rekor UUID for this release is 108e9186e8c5677af11aac195e340e8866f20b9b86bf5cb7e464b2af28f483c057eb267f33bd0b6f
Obtain the attestation:
REKOR_UUID=108e9186e8c5677af11aac195e340e8866f20b9b86bf5cb7e464b2af28f483c057eb267f33bd0b6f
rekor-cli get --uuid $REKOR_UUID --format json | jq -r .Attestation | jq .Verify that all container images in the attestation are in the release file:
RELEASE_FILE=https://infra.tekton.dev/tekton-releases/chains/previous/v0.29.3/release.yaml
REKOR_UUID=108e9186e8c5677af11aac195e340e8866f20b9b86bf5cb7e464b2af28f483c057eb267f33bd0b6f
# Obtains the list of images with sha from the attestation
REKOR_ATTESTATION_IMAGES=$(rekor-cli get --uuid "$REKOR_UUID" --format json | jq -r .Attestation | jq -r '.subject[]|.name + ":v0.29.3@sha256:" + .digest.sha256')
# Download the release file
curl -L "$RELEASE_FILE" > release.yaml
# For each image in the attestation, match it to the release file
for image in $REKOR_ATTESTATION_IMAGES; do
printf $image; grep -q $image release.yaml && echo " ===> ok" || echo " ===> no match";
doneThanks to these contributors who contributed to v0.29.3!
Extra shout-out for awesome release notes:
kubectl apply -f https://infra.tekton.dev/tekton-releases/chains/previous/v0.29.2/release.yaml
kubectl apply -f https://infra.tekton.dev/tekton-releases/chains/previous/v0.29.2/release.yamlThe Rekor UUID for this release is 108e9186e8c5677adf3b6f09e69381e572cbe7c66ffcdb4e3f8b8c121ac1f021e919ad471890a80c
Obtain the attestation:
REKOR_UUID=108e9186e8c5677adf3b6f09e69381e572cbe7c66ffcdb4e3f8b8c121ac1f021e919ad471890a80c
rekor-cli get --uuid $REKOR_UUID --format json | jq -r .Attestation | jq .Verify that all container images in the attestation are in the release file:
RELEASE_FILE=https://infra.tekton.dev/tekton-releases/chains/previous/v0.29.2/release.yaml
REKOR_UUID=108e9186e8c5677adf3b6f09e69381e572cbe7c66ffcdb4e3f8b8c121ac1f021e919ad471890a80c
# Obtains the list of images with sha from the attestation
REKOR_ATTESTATION_IMAGES=$(rekor-cli get --uuid "$REKOR_UUID" --format json | jq -r .Attestation | jq -r '.subject[]|.name + ":v0.29.2@sha256:" + .digest.sha256')
# Download the release file
curl -L "$RELEASE_FILE" > release.yaml
# For each image in the attestation, match it to the release file
for image in $REKOR_ATTESTATION_IMAGES; do
printf $image; grep -q $image release.yaml && echo " ===> ok" || echo " ===> no match";
doneThanks to these contributors who contributed to v0.29.2!
Extra shout-out for awesome release notes:
kubectl apply -f https://infra.tekton.dev/tekton-releases/chains/previous/v0.29.1/release.yaml
kubectl apply -f https://infra.tekton.dev/tekton-releases/chains/previous/v0.29.1/release.yamlThe Rekor UUID for this release is 108e9186e8c5677a85df9927c244d661ca9d8b61ba7ac58ac047b90e70618d9a2a8b23d521c9741c
Obtain the attestation:
REKOR_UUID=108e9186e8c5677a85df9927c244d661ca9d8b61ba7ac58ac047b90e70618d9a2a8b23d521c9741c
rekor-cli get --uuid $REKOR_UUID --format json | jq -r .Attestation | jq .Verify that all container images in the attestation are in the release file:
RELEASE_FILE=https://infra.tekton.dev/tekton-releases/chains/previous/v0.29.1/release.yaml
REKOR_UUID=108e9186e8c5677a85df9927c244d661ca9d8b61ba7ac58ac047b90e70618d9a2a8b23d521c9741c
# Obtains the list of images with sha from the attestation
REKOR_ATTESTATION_IMAGES=$(rekor-cli get --uuid "$REKOR_UUID" --format json | jq -r .Attestation | jq -r '.subject[]|.name + ":v0.29.1@sha256:" + .digest.sha256')
# Download the release file
curl -L "$RELEASE_FILE" > release.yaml
# For each image in the attestation, match it to the release file
for image in $REKOR_ATTESTATION_IMAGES; do
printf $image; grep -q $image release.yaml && echo " ===> ok" || echo " ===> no match";
doneThanks to these contributors who contributed to v0.29.1!
Extra shout-out for awesome release notes:
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
🔨 fix- CVE-2026-48702 -bump sigstore/rekor
kubectl apply -f https://infra.tekton.dev/tekton-releases/chains/previous/v0.29.0/release.yamlThe Rekor UUID for this release is
108e9186e8c5677a82aef8db00e95c000a21e72f54ff0b2efbee3300c0f3bdc2a30a7f9485d76641
Obtain the attestation:
REKOR_UUID=108e9186e8c5677a82aef8db00e95c000a21e72f54ff0b2efbee3300c0f3bdc2a30a7f9485d76641
rekor-cli get --uuid $REKOR_UUID --format json | jq -r .Attestation | jq .Verify that all container images in the attestation are in the release file:
RELEASE_FILE=https://infra.tekton.dev/tekton-releases/chains/previous/v0.29.0/release.yaml
REKOR_UUID=108e9186e8c5677a82aef8db00e95c000a21e72f54ff0b2efbee3300c0f3bdc2a30a7f9485d76641
# Obtains the list of images with sha from the attestation
REKOR_ATTESTATION_IMAGES=$(rekor-cli get --uuid "$REKOR_UUID" --format json | jq -r .Attestation | jq -r '.subject[]|.name + ":v0.29.0@sha256:" + .digest.sha256')
# Download the release file
curl -L "$RELEASE_FILE" > release.yaml
# For each image in the attestation, match it to the release file
for image in $REKOR_ATTESTATION_IMAGES; do
printf $image; grep -q $image release.yaml && echo " ===> ok" || echo " ===> no match";
donefeat: OCI storage now supports the OCI 1.1 Referrers API via a new config key:
Set storage.oci.encoding-format: sigstore-bundle in the chains-config ConfigMap
to store signatures and attestations as Sigstore protobuf bundles (v0.3) via the
OCI 1.1 Referrers API instead of .sig/.att tags.
dsse preserves existing tag-based behavior (backward compatible).sigstore-bundle mode: both signatures and attestations are pushed as OCI 1.1 referrers with artifactType: application/vnd.dev.sigstore.bundle.v0.3+json, discoverable via oras discover or cosign download.transparency.enabled: "true".cosign verify and cosign verify-attestation work with both modes.sigstore-bundle mode accumulates referrers (one per signing invocation) because ECDSA is non-deterministic; the dedup only coalesces exact crash-recovery retries.storage.oci.encoding-format are rejected by the controller at config-load time; the last valid config continues to be used.🐛 fix(release): stop duplicating GitHub release title (#1851)
🐛 fix(storage): skip docdb watcher reconfiguration on empty file read (#1769)
🐛 fix(signing): make KMS OIDC fallback test environment-independent (#1765)
🔨 chore(deps): bump github.com/tektoncd/pipeline from v1.14.1 to v1.15.0 (#1854)
🔨 Ignore otel major/minor updates in dependabot (#1817)
🔨 fix-CVE-2026-48702 -bump sigstore/rekor (#1793)
🔨 chore(deps): bump the all group with 8 updates (#1849)
🔨 chore(deps): bump github.com/sigstore/sigstore-go from 1.1.4 to 1.2.1 (#1844)
🔨 chore(deps): bump the all group across 1 directory with 6 updates (#1840)
🔨 chore(deps): bump github.com/google/cel-go from 0.28.1 to 0.29.0 (#1839)
🔨 chore(deps): bump the all group with 4 updates (#1833)
🔨 chore(deps): bump google.golang.org/grpc from 1.82.0 to 1.82.1 (#1825)
🔨 chore(deps): bump the all group with 3 updates (#1824)
🔨 chore(deps): bump the all group with 5 updates (#1808)
🔨 chore(deps): bump the all group with 3 updates (#1788)
🔨 chore(deps): bump the all group across 1 directory with 21 updates (#1768)
🔨 chore(deps): bump the all group with 2 updates (#1763)
Thanks to these contributors who contributed to v0.29.0!
Extra shout-out for awesome release notes:
kubectl apply -f https://infra.tekton.dev/tekton-releases/chains/previous/v0.28.8/release.yaml
kubectl apply -f https://infra.tekton.dev/tekton-releases/chains/previous/v0.28.8/release.yamlThe Rekor UUID for this release is 108e9186e8c5677aeac80fffa32f71af1eac491d44b029bb301302c0a92be74399ef340aeaf51322
Obtain the attestation:
REKOR_UUID=108e9186e8c5677aeac80fffa32f71af1eac491d44b029bb301302c0a92be74399ef340aeaf51322
rekor-cli get --uuid $REKOR_UUID --format json | jq -r .Attestation | jq .Verify that all container images in the attestation are in the release file:
RELEASE_FILE=https://infra.tekton.dev/tekton-releases/chains/previous/v0.28.8/release.yaml
REKOR_UUID=108e9186e8c5677aeac80fffa32f71af1eac491d44b029bb301302c0a92be74399ef340aeaf51322
# Obtains the list of images with sha from the attestation
REKOR_ATTESTATION_IMAGES=$(rekor-cli get --uuid "$REKOR_UUID" --format json | jq -r .Attestation | jq -r '.subject[]|.name + ":v0.28.8@sha256:" + .digest.sha256')
# Download the release file
curl -L "$RELEASE_FILE" > release.yaml
# For each image in the attestation, match it to the release file
for image in $REKOR_ATTESTATION_IMAGES; do
printf $image; grep -q $image release.yaml && echo " ===> ok" || echo " ===> no match";
doneThanks to these contributors who contributed to v0.28.8!
Extra shout-out for awesome release notes:
kubectl apply -f https://infra.tekton.dev/tekton-releases/chains/previous/v0.28.7/release.yaml
kubectl apply -f https://infra.tekton.dev/tekton-releases/chains/previous/v0.28.7/release.yamlThe Rekor UUID for this release is 108e9186e8c5677addfadac75b30314184fcbb06cbc52974043448a89adf354a46727c387f5a023c
Obtain the attestation:
REKOR_UUID=108e9186e8c5677addfadac75b30314184fcbb06cbc52974043448a89adf354a46727c387f5a023c
rekor-cli get --uuid $REKOR_UUID --format json | jq -r .Attestation | jq .Verify that all container images in the attestation are in the release file:
RELEASE_FILE=https://infra.tekton.dev/tekton-releases/chains/previous/v0.28.7/release.yaml
REKOR_UUID=108e9186e8c5677addfadac75b30314184fcbb06cbc52974043448a89adf354a46727c387f5a023c
# Obtains the list of images with sha from the attestation
REKOR_ATTESTATION_IMAGES=$(rekor-cli get --uuid "$REKOR_UUID" --format json | jq -r .Attestation | jq -r '.subject[]|.name + ":v0.28.7@sha256:" + .digest.sha256')
# Download the release file
curl -L "$RELEASE_FILE" > release.yaml
# For each image in the attestation, match it to the release file
for image in $REKOR_ATTESTATION_IMAGES; do
printf $image; grep -q $image release.yaml && echo " ===> ok" || echo " ===> no match";
doneThanks to these contributors who contributed to v0.28.7!
Extra shout-out for awesome release notes:
kubectl apply -f https://infra.tekton.dev/tekton-releases/chains/previous/v0.28.6/release.yaml
kubectl apply -f https://infra.tekton.dev/tekton-releases/chains/previous/v0.28.6/release.yamlThe Rekor UUID for this release is 108e9186e8c5677a4f350e4b99c697a2cd6b27256beb40bb3d46468bb978621c35ae0d60dd2667cc
Obtain the attestation:
REKOR_UUID=108e9186e8c5677a4f350e4b99c697a2cd6b27256beb40bb3d46468bb978621c35ae0d60dd2667cc
rekor-cli get --uuid $REKOR_UUID --format json | jq -r .Attestation | jq .Verify that all container images in the attestation are in the release file:
RELEASE_FILE=https://infra.tekton.dev/tekton-releases/chains/previous/v0.28.6/release.yaml
REKOR_UUID=108e9186e8c5677a4f350e4b99c697a2cd6b27256beb40bb3d46468bb978621c35ae0d60dd2667cc
# Obtains the list of images with sha from the attestation
REKOR_ATTESTATION_IMAGES=$(rekor-cli get --uuid "$REKOR_UUID" --format json | jq -r .Attestation | jq -r '.subject[]|.name + ":v0.28.6@sha256:" + .digest.sha256')
# Download the release file
curl -L "$RELEASE_FILE" > release.yaml
# For each image in the attestation, match it to the release file
for image in $REKOR_ATTESTATION_IMAGES; do
printf $image; grep -q $image release.yaml && echo " ===> ok" || echo " ===> no match";
doneThanks to these contributors who contributed to v0.28.6!
Extra shout-out for awesome release notes:
kubectl apply -f https://infra.tekton.dev/tekton-releases/chains/previous/v0.28.5/release.yaml
kubectl apply -f https://infra.tekton.dev/tekton-releases/chains/previous/v0.28.5/release.yamlThe Rekor UUID for this release is 108e9186e8c5677aed373b38213f2fbae0d15230b7f0692822d7aafd14990b4d1e94c73aecf789d8
Obtain the attestation:
REKOR_UUID=108e9186e8c5677aed373b38213f2fbae0d15230b7f0692822d7aafd14990b4d1e94c73aecf789d8
rekor-cli get --uuid $REKOR_UUID --format json | jq -r .Attestation | jq .Verify that all container images in the attestation are in the release file:
RELEASE_FILE=https://infra.tekton.dev/tekton-releases/chains/previous/v0.28.5/release.yaml
REKOR_UUID=108e9186e8c5677aed373b38213f2fbae0d15230b7f0692822d7aafd14990b4d1e94c73aecf789d8
# Obtains the list of images with sha from the attestation
REKOR_ATTESTATION_IMAGES=$(rekor-cli get --uuid "$REKOR_UUID" --format json | jq -r .Attestation | jq -r '.subject[]|.name + ":v0.28.5@sha256:" + .digest.sha256')
# Download the release file
curl -L "$RELEASE_FILE" > release.yaml
# For each image in the attestation, match it to the release file
for image in $REKOR_ATTESTATION_IMAGES; do
printf $image; grep -q $image release.yaml && echo " ===> ok" || echo " ===> no match";
doneThanks to these contributors who contributed to v0.28.5!
Extra shout-out for awesome release notes:
kubectl apply -f https://infra.tekton.dev/tekton-releases/chains/previous/v0.28.4/release.yaml
kubectl apply -f https://infra.tekton.dev/tekton-releases/chains/previous/v0.28.4/release.yamlThe Rekor UUID for this release is 108e9186e8c5677a25ed60de9e802ab7a8a9befaaa34d4a85f9e1e94ab03247c2e45884a3958fe29
Obtain the attestation:
REKOR_UUID=108e9186e8c5677a25ed60de9e802ab7a8a9befaaa34d4a85f9e1e94ab03247c2e45884a3958fe29
rekor-cli get --uuid $REKOR_UUID --format json | jq -r .Attestation | jq .Verify that all container images in the attestation are in the release file:
RELEASE_FILE=https://infra.tekton.dev/tekton-releases/chains/previous/v0.28.4/release.yaml
REKOR_UUID=108e9186e8c5677a25ed60de9e802ab7a8a9befaaa34d4a85f9e1e94ab03247c2e45884a3958fe29
# Obtains the list of images with sha from the attestation
REKOR_ATTESTATION_IMAGES=$(rekor-cli get --uuid "$REKOR_UUID" --format json | jq -r .Attestation | jq -r '.subject[]|.name + ":v0.28.4@sha256:" + .digest.sha256')
# Download the release file
curl -L "$RELEASE_FILE" > release.yaml
# For each image in the attestation, match it to the release file
for image in $REKOR_ATTESTATION_IMAGES; do
printf $image; grep -q $image release.yaml && echo " ===> ok" || echo " ===> no match";
doneThanks to these contributors who contributed to v0.28.4!
Extra shout-out for awesome release notes:
kubectl apply -f https://infra.tekton.dev/tekton-releases/chains/previous/v0.28.3/release.yaml
kubectl apply -f https://infra.tekton.dev/tekton-releases/chains/previous/v0.28.3/release.yamlThe Rekor UUID for this release is 108e9186e8c5677a79af7852f53742717d3cc543da30421cee2bfb7cd6e01f336ce8a724f254c723
Obtain the attestation:
REKOR_UUID=108e9186e8c5677a79af7852f53742717d3cc543da30421cee2bfb7cd6e01f336ce8a724f254c723
rekor-cli get --uuid $REKOR_UUID --format json | jq -r .Attestation | jq .Verify that all container images in the attestation are in the release file:
RELEASE_FILE=https://infra.tekton.dev/tekton-releases/chains/previous/v0.28.3/release.yaml
REKOR_UUID=108e9186e8c5677a79af7852f53742717d3cc543da30421cee2bfb7cd6e01f336ce8a724f254c723
# Obtains the list of images with sha from the attestation
REKOR_ATTESTATION_IMAGES=$(rekor-cli get --uuid "$REKOR_UUID" --format json | jq -r .Attestation | jq -r '.subject[]|.name + ":v0.28.3@sha256:" + .digest.sha256')
# Download the release file
curl -L "$RELEASE_FILE" > release.yaml
# For each image in the attestation, match it to the release file
for image in $REKOR_ATTESTATION_IMAGES; do
printf $image; grep -q $image release.yaml && echo " ===> ok" || echo " ===> no match";
doneThanks to these contributors who contributed to v0.28.3!
Extra shout-out for awesome release notes:
kubectl apply -f https://infra.tekton.dev/tekton-releases/chains/previous/v0.28.2/release.yaml
kubectl apply -f https://infra.tekton.dev/tekton-releases/chains/previous/v0.28.2/release.yamlThe Rekor UUID for this release is 108e9186e8c5677a44d1ba000f12caf9ef979748d70bf0519cdd5db8791da8a43064b4fe8e6f3521
Obtain the attestation:
REKOR_UUID=108e9186e8c5677a44d1ba000f12caf9ef979748d70bf0519cdd5db8791da8a43064b4fe8e6f3521
rekor-cli get --uuid $REKOR_UUID --format json | jq -r .Attestation | jq .Verify that all container images in the attestation are in the release file:
RELEASE_FILE=https://infra.tekton.dev/tekton-releases/chains/previous/v0.28.2/release.yaml
REKOR_UUID=108e9186e8c5677a44d1ba000f12caf9ef979748d70bf0519cdd5db8791da8a43064b4fe8e6f3521
# Obtains the list of images with sha from the attestation
REKOR_ATTESTATION_IMAGES=$(rekor-cli get --uuid "$REKOR_UUID" --format json | jq -r .Attestation | jq -r '.subject[]|.name + ":v0.28.2@sha256:" + .digest.sha256')
# Download the release file
curl -L "$RELEASE_FILE" > release.yaml
# For each image in the attestation, match it to the release file
for image in $REKOR_ATTESTATION_IMAGES; do
printf $image; grep -q $image release.yaml && echo " ===> ok" || echo " ===> no match";
doneThanks to these contributors who contributed to v0.28.2!
Extra shout-out for awesome release notes:
Tekton Chains release v0.28.1 "Release v0.28.1"
Tekton Chains release v0.28.1 "Release v0.28.1"
-Docs @ v0.28.1
-Examples @ v0.28.1
kubectl apply -f https://infra.tekton.dev/tekton-releases/chains/previous/v0.28.1/release.yamlThe Rekor UUID for this release is 108e9186e8c5677a6e885c752c61a6e3bc899f7b45150eb9e2c98cf8143bb5170747fa6dfd277f9f
Obtain the attestation:
REKOR_UUID=108e9186e8c5677a6e885c752c61a6e3bc899f7b45150eb9e2c98cf8143bb5170747fa6dfd277f9f
rekor-cli get --uuid $REKOR_UUID --format json | jq -r .Attestation | jq .Verify that all container images in the attestation are in the release file:
RELEASE_FILE=https://infra.tekton.dev/tekton-releases/chains/previous/v0.28.1/release.yaml
REKOR_UUID=108e9186e8c5677a6e885c752c61a6e3bc899f7b45150eb9e2c98cf8143bb5170747fa6dfd277f9f
# Obtains the list of images with sha from the attestation
REKOR_ATTESTATION_IMAGES=$(rekor-cli get --uuid "$REKOR_UUID" --format json | jq -r .Attestation | jq -r '.subject[]|.name + ":v0.28.1@sha256:" + .digest.sha256')
# Download the release file
curl -L "$RELEASE_FILE" > release.yaml
# For each image in the attestation, match it to the release file
for image in $REKOR_ATTESTATION_IMAGES; do
printf $image; grep -q $image release.yaml && echo " ===> ok" || echo " ===> no match";
doneThanks to these contributors who contributed to v0.28.1!
Extra shout-out for awesome release notes:
Nothing published for this version
Tekton Chains release v0.27.6 "Release v0.27.6"
Tekton Chains release v0.27.6 "Release v0.27.6"
-Docs @ v0.27.6
-Examples @ v0.27.6
kubectl apply -f https://infra.tekton.dev/tekton-releases/chains/previous/v0.27.6/release.yamlThe Rekor UUID for this release is 108e9186e8c5677a9db3c6e6d9b630fd76e7aa682bf1a0a8693a2435cf41c61afce1149e6ec13ab7
Obtain the attestation:
REKOR_UUID=108e9186e8c5677a9db3c6e6d9b630fd76e7aa682bf1a0a8693a2435cf41c61afce1149e6ec13ab7
rekor-cli get --uuid $REKOR_UUID --format json | jq -r .Attestation | jq .Verify that all container images in the attestation are in the release file:
RELEASE_FILE=https://infra.tekton.dev/tekton-releases/chains/previous/v0.27.6/release.yaml
REKOR_UUID=108e9186e8c5677a9db3c6e6d9b630fd76e7aa682bf1a0a8693a2435cf41c61afce1149e6ec13ab7
# Obtains the list of images with sha from the attestation
REKOR_ATTESTATION_IMAGES=$(rekor-cli get --uuid "$REKOR_UUID" --format json | jq -r .Attestation | jq -r '.subject[]|.name + ":v0.27.6@sha256:" + .digest.sha256')
# Download the release file
curl -L "$RELEASE_FILE" > release.yaml
# For each image in the attestation, match it to the release file
for image in $REKOR_ATTESTATION_IMAGES; do
printf $image; grep -q $image release.yaml && echo " ===> ok" || echo " ===> no match";
doneThanks to these contributors who contributed to v0.27.6!
Extra shout-out for awesome release notes:
Tekton Chains "Release v0.27.5"
Tekton Chains "Release v0.27.5"
-Docs @ v0.27.5
-Examples @ v0.27.5
kubectl apply -f https://infra.tekton.dev/tekton-releases/chains/previous/v0.27.5/release.yamlThe Rekor UUID for this release is
108e9186e8c5677ac62881930cba2e52a43acd4fdee65e9d2c840210f9a86db3f12722307a5cf0f6
Obtain the attestation:
REKOR_UUID=108e9186e8c5677ac62881930cba2e52a43acd4fdee65e9d2c840210f9a86db3f12722307a5cf0f6
rekor-cli get --uuid $REKOR_UUID --format json | jq -r .Attestation | jq .Verify that all container images in the attestation are in the release file:
RELEASE_FILE=https://infra.tekton.dev/tekton-releases/chains/previous/v0.27.5/release.yaml
REKOR_UUID=108e9186e8c5677ac62881930cba2e52a43acd4fdee65e9d2c840210f9a86db3f12722307a5cf0f6
# Obtains the list of images with sha from the attestation
REKOR_ATTESTATION_IMAGES=$(rekor-cli get --uuid "$REKOR_UUID" --format json | jq -r .Attestation | jq -r '.subject[]|.name + ":v0.27.5@sha256:" + .digest.sha256')
# Download the release file
curl -L "$RELEASE_FILE" > release.yaml
# For each image in the attestation, match it to the release file
for image in $REKOR_ATTESTATION_IMAGES; do
printf $image; grep -q $image release.yaml && echo " ===> ok" || echo " ===> no match";
doneThanks to these contributors who contributed to v0.27.5!
Extra shout-out for awesome release notes:
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
kubectl apply -f https://infra.tekton.dev/tekton-releases/chains/previous/v0.26.9/release.yaml
kubectl apply -f https://infra.tekton.dev/tekton-releases/chains/previous/v0.26.9/release.yamlThe Rekor UUID for this release is 108e9186e8c5677a9be065f521117233096593bc64a7419eea1647e468ad275d48d8f7592282ff69
Obtain the attestation:
REKOR_UUID=108e9186e8c5677a9be065f521117233096593bc64a7419eea1647e468ad275d48d8f7592282ff69
rekor-cli get --uuid $REKOR_UUID --format json | jq -r .Attestation | jq .Verify that all container images in the attestation are in the release file:
RELEASE_FILE=https://infra.tekton.dev/tekton-releases/chains/previous/v0.26.9/release.yaml
REKOR_UUID=108e9186e8c5677a9be065f521117233096593bc64a7419eea1647e468ad275d48d8f7592282ff69
# Obtains the list of images with sha from the attestation
REKOR_ATTESTATION_IMAGES=$(rekor-cli get --uuid "$REKOR_UUID" --format json | jq -r .Attestation | jq -r '.subject[]|.name + ":v0.26.9@sha256:" + .digest.sha256')
# Download the release file
curl -L "$RELEASE_FILE" > release.yaml
# For each image in the attestation, match it to the release file
for image in $REKOR_ATTESTATION_IMAGES; do
printf $image; grep -q $image release.yaml && echo " ===> ok" || echo " ===> no match";
doneThanks to these contributors who contributed to v0.26.9!
Extra shout-out for awesome release notes:
Tekton Chains release v0.26.8 "Release v0.26.8"
Tekton Chains release v0.26.8 "Release v0.26.8"
-Docs @ v0.26.8
-Examples @ v0.26.8
kubectl apply -f https://infra.tekton.dev/tekton-releases/chains/previous/v0.26.8/release.yamlThe Rekor UUID for this release is 108e9186e8c5677a9395f9f057d95f07be1c614f3e459d16f00ad07648f4e78de6c4aa62ff0bf98d
Obtain the attestation:
REKOR_UUID=108e9186e8c5677a9395f9f057d95f07be1c614f3e459d16f00ad07648f4e78de6c4aa62ff0bf98d
rekor-cli get --uuid $REKOR_UUID --format json | jq -r .Attestation | jq .Verify that all container images in the attestation are in the release file:
RELEASE_FILE=https://infra.tekton.dev/tekton-releases/chains/previous/v0.26.8/release.yaml
REKOR_UUID=108e9186e8c5677a9395f9f057d95f07be1c614f3e459d16f00ad07648f4e78de6c4aa62ff0bf98d
# Obtains the list of images with sha from the attestation
REKOR_ATTESTATION_IMAGES=$(rekor-cli get --uuid "$REKOR_UUID" --format json | jq -r .Attestation | jq -r '.subject[]|.name + ":v0.26.8@sha256:" + .digest.sha256')
# Download the release file
curl -L "$RELEASE_FILE" > release.yaml
# For each image in the attestation, match it to the release file
for image in $REKOR_ATTESTATION_IMAGES; do
printf $image; grep -q $image release.yaml && echo " ===> ok" || echo " ===> no match";
doneThanks to these contributors who contributed to v0.26.8!
Extra shout-out for awesome release notes:
Tekton Chains "Release v0.26.7"
Tekton Chains "Release v0.26.7"
-Docs @ v0.26.7
-Examples @ v0.26.7
kubectl apply -f https://infra.tekton.dev/tekton-releases/chains/previous/v0.26.7/release.yamlThe Rekor UUID for this release is 108e9186e8c5677a40d0a42a05fb5a94465d14cfd90ef06403eb7ed300ba6402c4f38d8b70978d33
Obtain the attestation:
REKOR_UUID=108e9186e8c5677a40d0a42a05fb5a94465d14cfd90ef06403eb7ed300ba6402c4f38d8b70978d33
rekor-cli get --uuid $REKOR_UUID --format json | jq -r .Attestation | jq .Verify that all container images in the attestation are in the release file:
RELEASE_FILE=https://infra.tekton.dev/tekton-releases/chains/previous/v0.26.7/release.yaml
REKOR_UUID=108e9186e8c5677a40d0a42a05fb5a94465d14cfd90ef06403eb7ed300ba6402c4f38d8b70978d33
# Obtains the list of images with sha from the attestation
REKOR_ATTESTATION_IMAGES=$(rekor-cli get --uuid "$REKOR_UUID" --format json | jq -r .Attestation | jq -r '.subject[]|.name + ":v0.26.7@sha256:" + .digest.sha256')
# Download the release file
curl -L "$RELEASE_FILE" > release.yaml
# For each image in the attestation, match it to the release file
for image in $REKOR_ATTESTATION_IMAGES; do
printf $image; grep -q $image release.yaml && echo " ===> ok" || echo " ===> no match";
doneThanks to these contributors who contributed to v0.26.7!
Extra shout-out for awesome release notes:
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →