NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Go modules · #2350 by repository stars
Last release 2 days ago
07 Oct 2026
Ships fairly regularly
a new release about every 2 weeks
Rarely documented
notes for 10 of 59 stable releases
Nothing withdrawn
no release was ever pulled
7 years old
528 releases · first in 2019
kubectl apply -f https://infra.tekton.dev/tekton-releases/operator/previous/v0.81.1/release.yaml
kubectl apply -f https://infra.tekton.dev/tekton-releases/operator/previous/v0.81.1/release.yamlThe Rekor UUID for this release is 108e9186e8c5677a830ae08bf3254c27e80b45a4284961c5f586310b61ce2ff1e5a27b6516d17c55
Obtain the attestation:
REKOR_UUID=108e9186e8c5677a830ae08bf3254c27e80b45a4284961c5f586310b61ce2ff1e5a27b6516d17c55
rekor-cli get --uuid $REKOR_UUID --format json | jq -r .Attestation | jq .Verify that all container images in the attestation are in the release file:
RELEASE_FILE=https://infra.tekton.dev/tekton-releases/operator/previous/v0.81.1/release.yaml
REKOR_UUID=108e9186e8c5677a830ae08bf3254c27e80b45a4284961c5f586310b61ce2ff1e5a27b6516d17c55
# Obtains the list of images with sha from the attestation
REKOR_ATTESTATION_IMAGES=$(rekor-cli get --uuid "$REKOR_UUID" --format json | jq -r .Attestation | jq -r '.subject[]|.name + ":v0.81.1@sha256:" + .digest.sha256')
# Download the release file
curl -L "$RELEASE_FILE" > release.yaml
# For each image in the attestation, match it to the release file
for image in $REKOR_ATTESTATION_IMAGES; do
printf $image; grep -q $image release.yaml && echo " ===> ok" || echo " ===> no match";
doneThanks to these contributors who contributed to v0.81.1!
Extra shout-out for awesome release notes:
One column per quarter.
kubectl apply -f https://infra.tekton.dev/tekton-releases/operator/previous/v0.81.0/release.yaml
kubectl apply -f https://infra.tekton.dev/tekton-releases/operator/previous/v0.81.0/release.yamlThe Rekor UUID for this release is 108e9186e8c5677a00472a306f2eb6c7553ee43b383c3e96be02812532438ff4bc0e5ddb86bedfac
Obtain the attestation:
REKOR_UUID=108e9186e8c5677a00472a306f2eb6c7553ee43b383c3e96be02812532438ff4bc0e5ddb86bedfac
rekor-cli get --uuid $REKOR_UUID --format json | jq -r .Attestation | jq .Verify that all container images in the attestation are in the release file:
RELEASE_FILE=https://infra.tekton.dev/tekton-releases/operator/previous/v0.81.0/release.yaml
REKOR_UUID=108e9186e8c5677a00472a306f2eb6c7553ee43b383c3e96be02812532438ff4bc0e5ddb86bedfac
# Obtains the list of images with sha from the attestation
REKOR_ATTESTATION_IMAGES=$(rekor-cli get --uuid "$REKOR_UUID" --format json | jq -r .Attestation | jq -r '.subject[]|.name + ":v0.81.0@sha256:" + .digest.sha256')
# Download the release file
curl -L "$RELEASE_FILE" > release.yaml
# For each image in the attestation, match it to the release file
for image in $REKOR_ATTESTATION_IMAGES; do
printf $image; grep -q $image release.yaml && echo " ===> ok" || echo " ===> no match";
doneexpose storage.oci.encoding-format config key in TektonChain and TektonConfig CRDs — allows configuring OCI 1.1 Referrers API storage via the operator
options now applies deployments[].spec.strategy and
statefulSets[].spec.updateStrategy to the generated workloads instead of
ignoring them. This makes it possible to set, for example,
rollingUpdate.maxSurge: 0 on a component whose replicas are pinned
one-per-node by anti-affinity, where the default surge-based rollout cannot
schedule the extra pod.
TektonPruner gains a spec.networkPolicy field so its controller and webhook default-deny and allow policies can be reconciled, overridden, or disabled per component. The field is propagated from TektonConfig.
TektonPipeline now ships default NetworkPolicy resources for pipeline-controller, pipeline-webhook, pipeline-events-controller, and pipeline-resolvers pods, restricting network access to
only DNS, API server, Prometheus metrics, and webhook traffic. Resolvers additionally allow HTTP/HTTPS and SSH egress for git, bundle, hub, and http resolver types.
Tekton Operator now ships default NetworkPolicy resources restricting network access for its own controller and proxy-webhook pods to only DNS, Kubernetes API server, Prometheus metrics, and webhook traffic. TektonPipeline also gains a spec.networkPolicy field (mirroring TektonTrigger) so its proxy-webhook's default-deny and allow policies can be reconciled, overridden, or disabled per component.
TektonConfig and TektonResult now support spec.result.watcher to configure Tekton Results Watcher behavior (for example completed_run_grace_period, check_owner, store_deadline, and disable_storing_incomplete_runs) without manually editing the tekton-results-watcher Deployment.
Fix patch release pipeline failures caused by Go 1.26.5 requirement
mismatch in pinned ko/koparse images.
Fix missing RBAC permissions in the Kubernetes Helm chart and install
manifests that prevented the operator from installing Pipelines-as-Code
on Kubernetes.
Fix StatefulSet pods (used when statefulset-ordinals is enabled) not
inheriting cluster-wide proxy environment variables.
Add NetworkPolicy support for TektonScheduler, TektonMulticlusterProxyAAE, and SyncerService components, giving each a default-deny policy plus targeted allow rules for required traffic.
Add NetworkPolicy support for Tekton Results. Default policies for Results API, watcher, retention-policy-agent, and postgres are reconciled from TektonConfig.spec.networkPolicy (enabled by default; set disabled: true to remove them).
ManualApprovalGate now creates default NetworkPolicies that restrict ingress/egress for its controller and webhook pods. These are enabled by default. To opt out, set spec.networkPolicy.disabled: true on the ManualApprovalGate CR.
TektonPruner gains a spec.networkPolicy field so its controller and webhook default-deny and allow policies can be reconciled, overridden, or disabled per component. The field is propagated from TektonConfig.
The OpenShift Pipelines console plugin now ships default NetworkPolicy resources restricting ingress to only the OpenShift Console on port 8443. The plugin is a static file server with no
egress required.
Thanks to these contributors who contributed to v0.81.0!
Extra shout-out for awesome release notes:
Nothing published for this version
Nothing published for this version
Tekton Operator release v0.79.2 "Release v0.79.2"
Tekton Operator release v0.79.2 "Release v0.79.2"
-Docs @ v0.79.2
-Examples @ v0.79.2
kubectl apply -f https://infra.tekton.dev/tekton-releases/operator/previous/v0.79.2/release.yamlThe Rekor UUID for this release is 108e9186e8c5677a8e16233d95b40c454dc247ce2ebfbb5fac46cab1e9be27961087fa0a28a52a87
Obtain the attestation:
REKOR_UUID=108e9186e8c5677a8e16233d95b40c454dc247ce2ebfbb5fac46cab1e9be27961087fa0a28a52a87
rekor-cli get --uuid $REKOR_UUID --format json | jq -r .Attestation | jq .Verify that all container images in the attestation are in the release file:
RELEASE_FILE=https://infra.tekton.dev/tekton-releases/operator/previous/v0.79.2/release.yaml
REKOR_UUID=108e9186e8c5677a8e16233d95b40c454dc247ce2ebfbb5fac46cab1e9be27961087fa0a28a52a87
# Obtains the list of images with sha from the attestation
REKOR_ATTESTATION_IMAGES=$(rekor-cli get --uuid "$REKOR_UUID" --format json | jq -r .Attestation | jq -r '.subject[]|.name + ":v0.79.2@sha256:" + .digest.sha256')
# Download the release file
curl -L "$RELEASE_FILE" > release.yaml
# For each image in the attestation, match it to the release file
for image in $REKOR_ATTESTATION_IMAGES; do
printf $image; grep -q $image release.yaml && echo " ===> ok" || echo " ===> no match";
doneTekton Results API route now uses passthrough TLS termination by default, enabling end-to-end encryption between clients and the Results API service.
Thanks to these contributors who contributed to v0.79.2!
Extra shout-out for awesome release notes:
Nothing published for this version
Nothing published for this version
Tekton Operator release v0.78.2 "Release v0.78.2"
Tekton Operator release v0.78.2 "Release v0.78.2"
-Docs @ v0.78.2
-Examples @ v0.78.2
kubectl apply -f https://infra.tekton.dev/tekton-releases/operator/previous/v0.78.2/release.yamlThe Rekor UUID for this release is 108e9186e8c5677a941d80cffbb6afc06ec28aa339d7ef2f5d81e4a3f676c9e9d99a5d650f6ca9b1
Obtain the attestation:
REKOR_UUID=108e9186e8c5677a941d80cffbb6afc06ec28aa339d7ef2f5d81e4a3f676c9e9d99a5d650f6ca9b1
rekor-cli get --uuid $REKOR_UUID --format json | jq -r .Attestation | jq .Verify that all container images in the attestation are in the release file:
RELEASE_FILE=https://infra.tekton.dev/tekton-releases/operator/previous/v0.78.2/release.yaml
REKOR_UUID=108e9186e8c5677a941d80cffbb6afc06ec28aa339d7ef2f5d81e4a3f676c9e9d99a5d650f6ca9b1
# Obtains the list of images with sha from the attestation
REKOR_ATTESTATION_IMAGES=$(rekor-cli get --uuid "$REKOR_UUID" --format json | jq -r .Attestation | jq -r '.subject[]|.name + ":v0.78.2@sha256:" + .digest.sha256')
# Download the release file
curl -L "$RELEASE_FILE" > release.yaml
# For each image in the attestation, match it to the release file
for image in $REKOR_ATTESTATION_IMAGES; do
printf $image; grep -q $image release.yaml && echo " ===> ok" || echo " ===> no match";
doneThanks to these contributors who contributed to v0.78.2!
Extra shout-out for awesome release notes:
Nothing published for this version
Nothing published for this version
kubectl apply -f https://infra.tekton.dev/tekton-releases/operator/previous/v0.77.2/release.yaml
kubectl apply -f https://infra.tekton.dev/tekton-releases/operator/previous/v0.77.2/release.yamlThe Rekor UUID for this release is 108e9186e8c5677a7455dc08d6c3d0e8b37276af97a174fbf6a149c86af71e0fc950773499d29234
Obtain the attestation:
REKOR_UUID=108e9186e8c5677a7455dc08d6c3d0e8b37276af97a174fbf6a149c86af71e0fc950773499d29234
rekor-cli get --uuid $REKOR_UUID --format json | jq -r .Attestation | jq .Verify that all container images in the attestation are in the release file:
RELEASE_FILE=https://infra.tekton.dev/tekton-releases/operator/previous/v0.77.2/release.yaml
REKOR_UUID=108e9186e8c5677a7455dc08d6c3d0e8b37276af97a174fbf6a149c86af71e0fc950773499d29234
# Obtains the list of images with sha from the attestation
REKOR_ATTESTATION_IMAGES=$(rekor-cli get --uuid "$REKOR_UUID" --format json | jq -r .Attestation | jq -r '.subject[]|.name + ":v0.77.2@sha256:" + .digest.sha256')
# Download the release file
curl -L "$RELEASE_FILE" > release.yaml
# For each image in the attestation, match it to the release file
for image in $REKOR_ATTESTATION_IMAGES; do
printf $image; grep -q $image release.yaml && echo " ===> ok" || echo " ===> no match";
doneThanks to these contributors who contributed to v0.77.2!
Extra shout-out for awesome release notes:
Tekton Operator release v0.77.1 "Release v0.77.1"
Tekton Operator release v0.77.1 "Release v0.77.1"
-Docs @ v0.77.1
-Examples @ v0.77.1
kubectl apply -f https://infra.tekton.dev/tekton-releases/operator/previous/v0.77.1/release.yamlThe Rekor UUID for this release is 108e9186e8c5677a47dea07c7b48970998c0421a867d751b6748b98ebd87b540c06c7e231b40e0c4
Obtain the attestation:
REKOR_UUID=108e9186e8c5677a47dea07c7b48970998c0421a867d751b6748b98ebd87b540c06c7e231b40e0c4
rekor-cli get --uuid $REKOR_UUID --format json | jq -r .Attestation | jq .Verify that all container images in the attestation are in the release file:
RELEASE_FILE=https://infra.tekton.dev/tekton-releases/operator/previous/v0.77.1/release.yaml
REKOR_UUID=108e9186e8c5677a47dea07c7b48970998c0421a867d751b6748b98ebd87b540c06c7e231b40e0c4
# Obtains the list of images with sha from the attestation
REKOR_ATTESTATION_IMAGES=$(rekor-cli get --uuid "$REKOR_UUID" --format json | jq -r .Attestation | jq -r '.subject[]|.name + ":v0.77.1@sha256:" + .digest.sha256')
# Download the release file
curl -L "$RELEASE_FILE" > release.yaml
# For each image in the attestation, match it to the release file
for image in $REKOR_ATTESTATION_IMAGES; do
printf $image; grep -q $image release.yaml && echo " ===> ok" || echo " ===> no match";
doneThanks to these contributors who contributed to v0.77.1!
Extra shout-out for awesome release notes:
Nothing published for this version
kubectl apply -f https://infra.tekton.dev/tekton-releases/operator/previous/v0.76.3/release.yaml
kubectl apply -f https://infra.tekton.dev/tekton-releases/operator/previous/v0.76.3/release.yamlThe Rekor UUID for this release is 108e9186e8c5677a0c039fb63c196c60609946b5d04fdeadcd09485b0066bb0a4d3f6c2d1a44878d
Obtain the attestation:
REKOR_UUID=108e9186e8c5677a0c039fb63c196c60609946b5d04fdeadcd09485b0066bb0a4d3f6c2d1a44878d
rekor-cli get --uuid $REKOR_UUID --format json | jq -r .Attestation | jq .Verify that all container images in the attestation are in the release file:
RELEASE_FILE=https://infra.tekton.dev/tekton-releases/operator/previous/v0.76.3/release.yaml
REKOR_UUID=108e9186e8c5677a0c039fb63c196c60609946b5d04fdeadcd09485b0066bb0a4d3f6c2d1a44878d
# Obtains the list of images with sha from the attestation
REKOR_ATTESTATION_IMAGES=$(rekor-cli get --uuid "$REKOR_UUID" --format json | jq -r .Attestation | jq -r '.subject[]|.name + ":v0.76.3@sha256:" + .digest.sha256')
# Download the release file
curl -L "$RELEASE_FILE" > release.yaml
# For each image in the attestation, match it to the release file
for image in $REKOR_ATTESTATION_IMAGES; do
printf $image; grep -q $image release.yaml && echo " ===> ok" || echo " ===> no match";
doneThanks to these contributors who contributed to v0.76.3!
Extra shout-out for awesome release notes:
kubectl apply -f https://infra.tekton.dev/tekton-releases/operator/previous/v0.76.2/release.yaml
kubectl apply -f https://infra.tekton.dev/tekton-releases/operator/previous/v0.76.2/release.yamlThe Rekor UUID for this release is 108e9186e8c5677a96a2811fe2b271dd2eb032706397c69dc680694079b55678a18aa778286738ba
Obtain the attestation:
REKOR_UUID=108e9186e8c5677a96a2811fe2b271dd2eb032706397c69dc680694079b55678a18aa778286738ba
rekor-cli get --uuid $REKOR_UUID --format json | jq -r .Attestation | jq .Verify that all container images in the attestation are in the release file:
RELEASE_FILE=https://infra.tekton.dev/tekton-releases/operator/previous/v0.76.2/release.yaml
REKOR_UUID=108e9186e8c5677a96a2811fe2b271dd2eb032706397c69dc680694079b55678a18aa778286738ba
# Obtains the list of images with sha from the attestation
REKOR_ATTESTATION_IMAGES=$(rekor-cli get --uuid "$REKOR_UUID" --format json | jq -r .Attestation | jq -r '.subject[]|.name + ":v0.76.2@sha256:" + .digest.sha256')
# Download the release file
curl -L "$RELEASE_FILE" > release.yaml
# For each image in the attestation, match it to the release file
for image in $REKOR_ATTESTATION_IMAGES; do
printf $image; grep -q $image release.yaml && echo " ===> ok" || echo " ===> no match";
doneThanks to these contributors who contributed to v0.76.2!
Extra shout-out for awesome release notes:
Nothing published for this version
Nothing published for this version
kubectl apply -f https://infra.tekton.dev/tekton-releases/operator/previous/v0.75.3/release.yaml
kubectl apply -f https://infra.tekton.dev/tekton-releases/operator/previous/v0.75.3/release.yamlThe Rekor UUID for this release is 108e9186e8c5677aab3c8127312ed8b467d4ac6eff34d4a3ef842e3718a5479b37877dbd6874dc60
Obtain the attestation:
REKOR_UUID=108e9186e8c5677aab3c8127312ed8b467d4ac6eff34d4a3ef842e3718a5479b37877dbd6874dc60
rekor-cli get --uuid $REKOR_UUID --format json | jq -r .Attestation | jq .Verify that all container images in the attestation are in the release file:
RELEASE_FILE=https://infra.tekton.dev/tekton-releases/operator/previous/v0.75.3/release.yaml
REKOR_UUID=108e9186e8c5677aab3c8127312ed8b467d4ac6eff34d4a3ef842e3718a5479b37877dbd6874dc60
# Obtains the list of images with sha from the attestation
REKOR_ATTESTATION_IMAGES=$(rekor-cli get --uuid "$REKOR_UUID" --format json | jq -r .Attestation | jq -r '.subject[]|.name + ":v0.75.3@sha256:" + .digest.sha256')
# Download the release file
curl -L "$RELEASE_FILE" > release.yaml
# For each image in the attestation, match it to the release file
for image in $REKOR_ATTESTATION_IMAGES; do
printf $image; grep -q $image release.yaml && echo " ===> ok" || echo " ===> no match";
doneThanks to these contributors who contributed to v0.75.3!
Extra shout-out for awesome release notes:
Tekton Operator release v0.75.2 "Release v0.75.2"
Tekton Operator release v0.75.2 "Release v0.75.2"
-Docs @ v0.75.2
-Examples @ v0.75.2
kubectl apply -f https://infra.tekton.dev/tekton-releases/operator/previous/v0.75.2/release.yamlThe Rekor UUID for this release is 108e9186e8c5677a625dbf777f9c6214feb8141733249f6dccee2ac5104168185f229a464c4c8d52
Obtain the attestation:
REKOR_UUID=108e9186e8c5677a625dbf777f9c6214feb8141733249f6dccee2ac5104168185f229a464c4c8d52
rekor-cli get --uuid $REKOR_UUID --format json | jq -r .Attestation | jq .Verify that all container images in the attestation are in the release file:
RELEASE_FILE=https://infra.tekton.dev/tekton-releases/operator/previous/v0.75.2/release.yaml
REKOR_UUID=108e9186e8c5677a625dbf777f9c6214feb8141733249f6dccee2ac5104168185f229a464c4c8d52
# Obtains the list of images with sha from the attestation
REKOR_ATTESTATION_IMAGES=$(rekor-cli get --uuid "$REKOR_UUID" --format json | jq -r .Attestation | jq -r '.subject[]|.name + ":v0.75.2@sha256:" + .digest.sha256')
# Download the release file
curl -L "$RELEASE_FILE" > release.yaml
# For each image in the attestation, match it to the release file
for image in $REKOR_ATTESTATION_IMAGES; do
printf $image; grep -q $image release.yaml && echo " ===> ok" || echo " ===> no match";
doneThanks to these contributors who contributed to v0.75.2!
Extra shout-out for awesome release notes:
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →