NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Go modules · #397 by repository stars
Last release 2 days ago
06 Oct 2026
Ships on a steady schedule
a new release about every 9 days
Some releases are documented
notes for 18 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
8 years old
1928 releases · first in 2018
Nothing published for this version
Nothing published for this version
Nothing published for this version
One column per quarter.
Nothing published for this version
🎉 Clearer failures, sharper traces 🎉
kubectl apply -f https://infra.tekton.dev/tekton-releases/pipeline/previous/v1.17.0/release.yamlThe Rekor UUID for this release is 108e9186e8c5677a431fb2e9f34a5fd5b0418cccab54d920148b79cbe5bfcd5a2075f7ae918a9cc9
Obtain the attestation:
REKOR_UUID=108e9186e8c5677a431fb2e9f34a5fd5b0418cccab54d920148b79cbe5bfcd5a2075f7ae918a9cc9
rekor-cli get --uuid $REKOR_UUID --format json | jq -r .Attestation | jq .Verify that all container images in the attestation are in the release file:
RELEASE_FILE=https://infra.tekton.dev/tekton-releases/pipeline/previous/v1.17.0/release.yaml
REKOR_UUID=108e9186e8c5677a431fb2e9f34a5fd5b0418cccab54d920148b79cbe5bfcd5a2075f7ae918a9cc9
# Obtains the list of images with sha from the attestation
REKOR_ATTESTATION_IMAGES=$(rekor-cli get --uuid "$REKOR_UUID" --format json | jq -r .Attestation | jq -r '.subject[]|.name + ":v1.17.0@sha256:" + .digest.sha256')
# Download the release file
curl -L "$RELEASE_FILE" > release.yaml
# For each image in the attestation, match it to the release file
for image in $REKOR_ATTESTATION_IMAGES; do
printf $image; grep -q $image release.yaml && echo " ===> ok" || echo " ===> no match";
doneAdd a reconcile.write_intent attribute (no-op, status-only, metadata-only, metadata-and-status) to PipelineRun and TaskRun reconcile spans so operators can distinguish reconciliations that intend an etcd write.
Surface Pod infrastructure failure reasons (from Warning events such as
FailedMount, FailedScheduling, FailedCreatePodSandBox) onto the TaskRun
status condition when a Pod is stuck pending with no useful message. Gated
behind the new surface-pod-events alpha feature flag (disabled by default).
Fixed a Windows script-injection defense-in-depth gap: placeScriptInContainer now uses a non-expandable PowerShell here-string, so a script body containing a literal "@ line can no longer terminate the generated command early.
Before this update, when resolver fails to get any task, controller showed the error message without containing the task name which was hard to detect which one is failed or having bad resolution config. Now task name is added to the error message from template.
Pipelines can now reference $(tt.params.<name>) in task params, when expressions, and matrix params/includes. This lets a PipelineSpec embedded by Tekton Triggers keep its tt.params.* substitutions without failing pipeline validation.
Resolvers no longer fail ResolutionRequests belonging to a different resolver after a leader election or a resolver pod restart.
Fixed controller startup panic messages that printed a malformed %!w(...) marker instead of the underlying error when an informer event handler failed to register.
NOT REQUIRED
Thanks to these contributors who contributed to v1.17.0!
Extra shout-out for awesome release notes:
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
🎉 Secure by default, sharper traces 🎉
-Docs @ v1.16.0
-Examples @ v1.16.0
kubectl apply -f https://infra.tekton.dev/tekton-releases/pipeline/previous/v1.16.0/release.yamlThe Rekor UUID for this release is 108e9186e8c5677a13e773b2ae0f6c52943d2b44a284030efb9b43068a9927a698b4799e13342b14
Obtain the attestation:
REKOR_UUID=108e9186e8c5677a13e773b2ae0f6c52943d2b44a284030efb9b43068a9927a698b4799e13342b14
rekor-cli get --uuid $REKOR_UUID --format json | jq -r .Attestation | jq .Verify that all container images in the attestation are in the release file:
RELEASE_FILE=https://infra.tekton.dev/tekton-releases/pipeline/previous/v1.16.0/release.yaml
REKOR_UUID=108e9186e8c5677a13e773b2ae0f6c52943d2b44a284030efb9b43068a9927a698b4799e13342b14
# Obtains the list of images with sha from the attestation
REKOR_ATTESTATION_IMAGES=$(rekor-cli get --uuid "$REKOR_UUID" --format json | jq -r .Attestation | jq -r '.subject[]|.name + ":v1.16.0@sha256:" + .digest.sha256')
# Download the release file
curl -L "$RELEASE_FILE" > release.yaml
# For each image in the attestation, match it to the release file
for image in $REKOR_ATTESTATION_IMAGES; do
printf $image; grep -q $image release.yaml && echo " ===> ok" || echo " ===> no match";
doneset-security-context enabled by defaultaction required: set-security-context now defaults to true and applies only to Tekton-injected TaskRun containers and Affinity Assistants (#9589, #10680). User-defined Steps and Sidecars must supply their own restricted-compatible security contexts. If the generated security contexts are incompatible with your images or Kubernetes implementation, set set-security-context to "false".
Add tracing spans to the task parameter and workspace substitution pipeline in the TaskRun reconciler to improve observability and performance tracking. No user-facing changes.
Update the golangci-lint installation URL
Fix root tracing span lifecycle in TaskRun and PipelineRun reconcilers to cover the full reconciliation cycle instead of ending immediately after initialization.
Thanks to these contributors who contributed to v1.16.0!
Extra shout-out for awesome release notes:
kubectl apply -f https://infra.tekton.dev/tekton-releases/pipeline/previous/v1.15.3/release.yaml
kubectl apply -f https://infra.tekton.dev/tekton-releases/pipeline/previous/v1.15.3/release.yamlThe Rekor UUID for this release is 108e9186e8c5677a1cca30d273b8c9dacc3ecea843087a7743386bf7355ef7a283afd3ed1829b921
Obtain the attestation:
REKOR_UUID=108e9186e8c5677a1cca30d273b8c9dacc3ecea843087a7743386bf7355ef7a283afd3ed1829b921
rekor-cli get --uuid $REKOR_UUID --format json | jq -r .Attestation | jq .Verify that all container images in the attestation are in the release file:
RELEASE_FILE=https://infra.tekton.dev/tekton-releases/pipeline/previous/v1.15.3/release.yaml
REKOR_UUID=108e9186e8c5677a1cca30d273b8c9dacc3ecea843087a7743386bf7355ef7a283afd3ed1829b921
# Obtains the list of images with sha from the attestation
REKOR_ATTESTATION_IMAGES=$(rekor-cli get --uuid "$REKOR_UUID" --format json | jq -r .Attestation | jq -r '.subject[]|.name + ":v1.15.3@sha256:" + .digest.sha256')
# Download the release file
curl -L "$RELEASE_FILE" > release.yaml
# For each image in the attestation, match it to the release file
for image in $REKOR_ATTESTATION_IMAGES; do
printf $image; grep -q $image release.yaml && echo " ===> ok" || echo " ===> no match";
donePipelines can now reference $(tt.params.<name>) in task params, when expressions, and matrix params/includes. This lets a PipelineSpec embedded by Tekton Triggers keep its tt.params.* substitutions without failing pipeline validation.
Thanks to these contributors who contributed to v1.15.3!
Extra shout-out for awesome release notes:
- Docs @ v1.15.2 - Examples @ v1.15.2
-Docs @ v1.15.2
-Examples @ v1.15.2
kubectl apply -f https://infra.tekton.dev/tekton-releases/pipeline/previous/v1.15.2/release.yamlThe Rekor UUID for this release is 108e9186e8c5677ad57a83fb64ccefa586efb4446b591b3a2d760972ce02657eb1929896879dbb74
Obtain the attestation:
REKOR_UUID=108e9186e8c5677ad57a83fb64ccefa586efb4446b591b3a2d760972ce02657eb1929896879dbb74
rekor-cli get --uuid $REKOR_UUID --format json | jq -r .Attestation | jq .Verify that all container images in the attestation are in the release file:
RELEASE_FILE=https://infra.tekton.dev/tekton-releases/pipeline/previous/v1.15.2/release.yaml
REKOR_UUID=108e9186e8c5677ad57a83fb64ccefa586efb4446b591b3a2d760972ce02657eb1929896879dbb74
# Obtains the list of images with sha from the attestation
REKOR_ATTESTATION_IMAGES=$(rekor-cli get --uuid "$REKOR_UUID" --format json | jq -r .Attestation | jq -r '.subject[]|.name + ":v1.15.2@sha256:" + .digest.sha256')
# Download the release file
curl -L "$RELEASE_FILE" > release.yaml
# For each image in the attestation, match it to the release file
for image in $REKOR_ATTESTATION_IMAGES; do
printf $image; grep -q $image release.yaml && echo " ===> ok" || echo " ===> no match";
doneThanks to these contributors who contributed to v1.15.2!
Extra shout-out for awesome release notes:
- Docs @ v1.15.1 - Examples @ v1.15.1
-Docs @ v1.15.1
-Examples @ v1.15.1
kubectl apply -f https://infra.tekton.dev/tekton-releases/pipeline/previous/v1.15.1/release.yamlThe Rekor UUID for this release is 108e9186e8c5677a210b81c75be73c2949e8e917e1776229b8bb68bc95b532e51d8f2bf29219a9c1
Obtain the attestation:
REKOR_UUID=108e9186e8c5677a210b81c75be73c2949e8e917e1776229b8bb68bc95b532e51d8f2bf29219a9c1
rekor-cli get --uuid $REKOR_UUID --format json | jq -r .Attestation | jq .Verify that all container images in the attestation are in the release file:
RELEASE_FILE=https://infra.tekton.dev/tekton-releases/pipeline/previous/v1.15.1/release.yaml
REKOR_UUID=108e9186e8c5677a210b81c75be73c2949e8e917e1776229b8bb68bc95b532e51d8f2bf29219a9c1
# Obtains the list of images with sha from the attestation
REKOR_ATTESTATION_IMAGES=$(rekor-cli get --uuid "$REKOR_UUID" --format json | jq -r .Attestation | jq -r '.subject[]|.name + ":v1.15.1@sha256:" + .digest.sha256')
# Download the release file
curl -L "$RELEASE_FILE" > release.yaml
# For each image in the attestation, match it to the release file
for image in $REKOR_ATTESTATION_IMAGES; do
printf $image; grep -q $image release.yaml && echo " ===> ok" || echo " ===> no match";
doneThanks to these contributors who contributed to v1.15.1!
Extra shout-out for awesome release notes:
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
🔨 Fix wrong Deprecated godoc in affinity assistant
-Docs @ v1.15.0
-Examples @ v1.15.0
kubectl apply -f https://infra.tekton.dev/tekton-releases/pipeline/previous/v1.15.0/release.yamlThe Rekor UUID for this release is 108e9186e8c5677a045c87c57225dfff98b32437f52b89e344c449bcd535b462d41fff9004b89d29
Obtain the attestation:
REKOR_UUID=108e9186e8c5677a045c87c57225dfff98b32437f52b89e344c449bcd535b462d41fff9004b89d29
rekor-cli get --uuid $REKOR_UUID --format json | jq -r .Attestation | jq .Verify that all container images in the attestation are in the release file:
RELEASE_FILE=https://infra.tekton.dev/tekton-releases/pipeline/previous/v1.15.0/release.yaml
REKOR_UUID=108e9186e8c5677a045c87c57225dfff98b32437f52b89e344c449bcd535b462d41fff9004b89d29
# Obtains the list of images with sha from the attestation
REKOR_ATTESTATION_IMAGES=$(rekor-cli get --uuid "$REKOR_UUID" --format json | jq -r .Attestation | jq -r '.subject[]|.name + ":v1.15.0@sha256:" + .digest.sha256')
# Download the release file
curl -L "$RELEASE_FILE" > release.yaml
# For each image in the attestation, match it to the release file
for image in $REKOR_ATTESTATION_IMAGES; do
printf $image; grep -q $image release.yaml && echo " ===> ok" || echo " ===> no match";
doneEnables the configuration of backoffs for git resolver requests.
Add default-create-container-error-timeout configuration option in config-defaults to provide a grace period before failing TaskRuns on transient CreateContainerError/CreateContainerConfigError with "context deadline exceeded". Default is 0 (fail fast, preserving existing behavior)
Prevent ResolutionRequest lifecycle updates from overwriting resolver-written status fields.
Fix resolver replicas processing ResolutionRequests outside their leader-election bucket.
Fixed an integer overflow in matrix combination counting that could let a very
large matrix bypass the max-matrix-combinations validation guard.
Fix PipelineRun remaining stuck in ResolvingTaskRef when a ResolutionRequest completion event is missed by periodically requeueing while remote resolution is in progress
Fixed a panic in the PipelineRun controller when a PipelineRun using an embedded (anonymous) pipeline spec sets a generateName that contains no alphanumeric characters (for example --). Such names no longer crash the reconciler.
Fix sidecar-logs result extraction dropping all TaskRun results when a single result's JSON exceeds 4096 bytes but is within the configured max-result-size. Regression since v1.9.0.
Fixed a bug where a Sidecar's restartPolicy (native Kubernetes sidecar support)
was dropped when converting a Task or TaskRun between the v1beta1 and v1 API
versions, causing a sidecar requested as a native sidecar to be created as an
ordinary sidecar.
Debug breakpoint scripts are now mounted read-only in step containers, so a step can no longer overwrite them before a user execs in to continue or fail a breakpoint.
Fix release pipeline ko resolve failure caused by ko >= v0.19.0 rejecting
the kodata/source.tar.gz symlink used to bundle vendored source.
Thanks to these contributors who contributed to v1.15.0!
Extra shout-out for awesome release notes:
Tekton Pipeline release v1.14.1 ""Chartreux Cait Sith""
Tekton Pipeline release v1.14.1 ""Chartreux Cait Sith""
-Docs @ v1.14.1
-Examples @ v1.14.1
kubectl apply -f https://infra.tekton.dev/tekton-releases/pipeline/previous/v1.14.1/release.yamlThe Rekor UUID for this release is 108e9186e8c5677a5b65d09f2d5a25a1c1cc499f6dd152f80348422ff8fbe46a84ad47c0eba03a8a
Obtain the attestation:
REKOR_UUID=108e9186e8c5677a5b65d09f2d5a25a1c1cc499f6dd152f80348422ff8fbe46a84ad47c0eba03a8a
rekor-cli get --uuid $REKOR_UUID --format json | jq -r .Attestation | jq .Verify that all container images in the attestation are in the release file:
RELEASE_FILE=https://infra.tekton.dev/tekton-releases/pipeline/previous/v1.14.1/release.yaml
REKOR_UUID=108e9186e8c5677a5b65d09f2d5a25a1c1cc499f6dd152f80348422ff8fbe46a84ad47c0eba03a8a
# Obtains the list of images with sha from the attestation
REKOR_ATTESTATION_IMAGES=$(rekor-cli get --uuid "$REKOR_UUID" --format json | jq -r .Attestation | jq -r '.subject[]|.name + ":v1.14.1@sha256:" + .digest.sha256')
# Download the release file
curl -L "$RELEASE_FILE" > release.yaml
# For each image in the attestation, match it to the release file
for image in $REKOR_ATTESTATION_IMAGES; do
printf $image; grep -q $image release.yaml && echo " ===> ok" || echo " ===> no match";
doneFix pipeline validation rejecting $(results.*) variable references in pipeline task parameters
Thanks to these contributors who contributed to v1.14.1!
Extra shout-out for awesome release notes:
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →