NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Go modules · #2390 by repository stars
Last release today
07 Oct 2026
Ships on a steady schedule
a new release about every 2 weeks
Rarely documented
notes for 13 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
7 years old
375 releases · first in 2019
kubectl apply -f https://infra.tekton.dev/tekton-releases/triggers/previous/v0.37.1/release.yaml kubectl apply -f https://infra.tekton.dev/tekton-rele
kubectl apply -f https://infra.tekton.dev/tekton-releases/triggers/previous/v0.37.1/release.yaml
kubectl apply -f https://infra.tekton.dev/tekton-releases/triggers/previous/v0.37.1/interceptors.yamlThe Rekor UUID for this release is 108e9186e8c5677ad028f84990e7f434fcb63d84486bf5505a4c7376a9efedfb1ba298536d13a88c
Obtain the attestation:
REKOR_UUID=108e9186e8c5677ad028f84990e7f434fcb63d84486bf5505a4c7376a9efedfb1ba298536d13a88c
rekor-cli get --uuid $REKOR_UUID --format json | jq -r .Attestation | jq .Verify that all container images in the attestation are in the release file:
RELEASE_FILE=https://infra.tekton.dev/tekton-releases/triggers/previous/v0.37.1/release.yaml
INTERCEPTORS_FILE=https://infra.tekton.dev/tekton-releases/triggers/previous/v0.37.1/interceptors.yaml
REKOR_UUID=108e9186e8c5677ad028f84990e7f434fcb63d84486bf5505a4c7376a9efedfb1ba298536d13a88c
# Obtains the list of images with sha from the attestation
REKOR_ATTESTATION_IMAGES=$(rekor-cli get --uuid "$REKOR_UUID" --format json | jq -r .Attestation | jq -r '.subject[]|.name + ":v0.37.1@sha256:" + .digest.sha256')
# Download the release file
curl -L "$RELEASE_FILE" > release.yaml
curl "$INTERCEPTORS_FILE" >> release.yaml
# For each image in the attestation, match it to the release file
for image in $REKOR_ATTESTATION_IMAGES; do
printf $image; grep -q $image release.yaml && echo " ===> ok" || echo " ===> no match";
doneEnforce that the Github Interceptor must be used in conjunction with secretRef, to ensure all Github payloads are verifiably signed
Action Required: Users using the Github Interceptor must ensure the interceptor uses a secretRef, as described in the documentation
Add a configmap-driven allowlist for allowed hosts by the Github Interceptors. A new feature flag interceptors.github.use-enterprise-host-allowlist controls whether or not the allow-list is enforced. The feature flag defaults to false for backwards compatiblity but in later releases it will default to true and eventually be removed
Thanks to these contributors who contributed to v0.37.1!
Extra shout-out for awesome release notes:
One column per quarter.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
kubectl apply -f https://infra.tekton.dev/tekton-releases/triggers/previous/v0.37.0/release.yaml
kubectl apply -f https://infra.tekton.dev/tekton-releases/triggers/previous/v0.37.0/release.yamlThe Rekor UUID for this release is 108e9186e8c5677a1a23009a1951f3bd03d8d05e083fa175f2559de39d752ad4f3e71db31cb030b4
Obtain the attestation:
REKOR_UUID=108e9186e8c5677a1a23009a1951f3bd03d8d05e083fa175f2559de39d752ad4f3e71db31cb030b4
rekor-cli get --uuid $REKOR_UUID --format json | jq -r .Attestation | jq .Verify that all container images in the attestation are in the release file:
RELEASE_FILE=https://infra.tekton.dev/tekton-releases/triggers/previous/v0.37.0/release.yaml
INTERCEPTORS_FILE=https://infra.tekton.dev/tekton-releases/triggers/previous/v0.37.0/interceptors.yaml
REKOR_UUID=108e9186e8c5677a1a23009a1951f3bd03d8d05e083fa175f2559de39d752ad4f3e71db31cb030b4
# Obtains the list of images with sha from the attestation
REKOR_ATTESTATION_IMAGES=$(rekor-cli get --uuid "$REKOR_UUID" --format json | jq -r .Attestation | jq -r '.subject[]|.name + ":v0.37.0@sha256:" + .digest.sha256')
# Download the release file
curl "$RELEASE_FILE" > release.yaml
curl "$INTERCEPTORS_FILE" >> release.yaml
# For each image in the attestation, match it to the release file
for image in $REKOR_ATTESTATION_IMAGES; do
printf $image; grep -q $image release.yaml && echo " ===> ok" || echo " ===> no match";
doneFix a bug where a webhook-type interceptor placed first in a trigger's
interceptor chain would receive a pre-parsed JSON body instead of the
original request body for application/x-www-form-urlencoded requests
(e.g. Slack slash commands), breaking custom interceptors that parse the
raw form-encoded payload themselves.
Thanks to these contributors who contributed to v0.37.0!
Extra shout-out for awesome release notes:
kubectl apply -f https://infra.tekton.dev/tekton-releases/triggers/previous/v0.36.1/release.yaml kubectl apply -f https://infra.tekton.dev/tekton-rele
kubectl apply -f https://infra.tekton.dev/tekton-releases/triggers/previous/v0.36.1/release.yaml
kubectl apply -f https://infra.tekton.dev/tekton-releases/triggers/previous/v0.36.1/interceptors.yamlThe Rekor UUID for this release is 108e9186e8c5677a657a035abaa26626fb70696b986e9a50cab171d2e2fa7047a72e03f050c5f135
Obtain the attestation:
REKOR_UUID=108e9186e8c5677a657a035abaa26626fb70696b986e9a50cab171d2e2fa7047a72e03f050c5f135
rekor-cli get --uuid $REKOR_UUID --format json | jq -r .Attestation | jq .Verify that all container images in the attestation are in the release file:
RELEASE_FILE=https://infra.tekton.dev/tekton-releases/triggers/previous/v0.36.1/release.yaml
INTERCEPTORS_FILE=https://infra.tekton.dev/tekton-releases/triggers/previous/v0.36.1/interceptors.yaml
REKOR_UUID=108e9186e8c5677a657a035abaa26626fb70696b986e9a50cab171d2e2fa7047a72e03f050c5f135
REKOR_ATTESTATION_IMAGES=$(rekor-cli get --uuid "$REKOR_UUID" --format json | jq -r .Attestation | jq -r '.subject[]|.name + ":v0.36.1@sha256:" + .digest.sha256')
curl -L "$RELEASE_FILE" > release.yaml
curl "$INTERCEPTORS_FILE" >> release.yaml
for image in $REKOR_ATTESTATION_IMAGES; do
printf $image; grep -q $image release.yaml && echo " ===> ok" || echo " ===> no match";
donePatch release on top of v0.36.0.
This release was created manually; automated GitHub draft release creation for triggers is being added in #2171.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Tekton Triggers release v0.36.0 "Tekton Triggers"
Tekton Triggers release v0.36.0 "Tekton Triggers"
-Docs @ v0.36.0
-Examples @ v0.36.0
kubectl apply -f https://infra.tekton.dev/tekton-releases/triggers/previous/v0.36.0/release.yamlThe Rekor UUID for this release is 108e9186e8c5677a6b2a69794ca92fea0d3bb45b80f923817fd184a39c84987cd53cee88dcf9dc5f
Obtain the attestation:
REKOR_UUID=108e9186e8c5677a6b2a69794ca92fea0d3bb45b80f923817fd184a39c84987cd53cee88dcf9dc5f
rekor-cli get --uuid $REKOR_UUID --format json | jq -r .Attestation | jq .Verify that all container images in the attestation are in the release file:
RELEASE_FILE=https://infra.tekton.dev/tekton-releases/triggers/previous/v0.36.0/release.yaml
INTERCEPTORS_FILE=https://infra.tekton.dev/tekton-releases/triggers/previous/${VERSION_TAG}/interceptors.yaml
REKOR_UUID=108e9186e8c5677a6b2a69794ca92fea0d3bb45b80f923817fd184a39c84987cd53cee88dcf9dc5f
# Obtains the list of images with sha from the attestation
REKOR_ATTESTATION_IMAGES=$(rekor-cli get --uuid "$REKOR_UUID" --format json | jq -r .Attestation | jq -r '.subject[]|.name + ":v0.36.0@sha256:" + .digest.sha256')
# Download the release file
curl -L "$RELEASE_FILE" > release.yaml
curl -L "$INTERCEPTORS_FILE" >> release.yaml
# For each image in the attestation, match it to the release file
for image in $REKOR_ATTESTATION_IMAGES; do
printf $image; grep -q $image release.yaml && echo " ===> ok" || echo " ===> no match";
doneCore interceptors now honor the TLS security profile injected by the Tekton operator via TLS_MIN_VERSION, TLS_CIPHER_SUITES, and TLS_CURVE_PREFERENCES environment variables, allowing cluster-wide TLS policy enforcement on OpenShift.
Migrated metrics from OpenCensus to OpenTelemetry.
ACTION REQUIRED:
Configuration key change
Replace metrics.backend-destination with metrics-protocol in your config-observability-triggers ConfigMap.
Prometheus export remains the default — no change needed if you were not customizing observability.
Infrastructure metric renaming
Infrastructure metrics (workqueue, K8s client) have been renamed from the
tekton_triggers_controller_ prefix to standard Knative/OpenTelemetry namespaces.
┌──────────────────────────────────────────────────────────┬───────────────────────────────────────────────────┐
│ Old Metric Name (OpenCensus) │ New Metric Name (OpenTelemetry) │
├──────────────────────────────────────────────────────────┼───────────────────────────────────────────────────┤
│ tekton_triggers_controller_workqueue_depth │ kn_workqueue_depth │
│ tekton_triggers_controller_workqueue_adds_total │ kn_workqueue_adds_total │
│ tekton_triggers_controller_workqueue_queue_latency_* │ kn_workqueue_queue_duration_seconds_* │
│ tekton_triggers_controller_workqueue_work_duration_* │ kn_workqueue_process_duration_seconds_* │
│ tekton_triggers_controller_workqueue_unfinished_work_* │ kn_workqueue_unfinished_work_seconds │
│ tekton_triggers_controller_workqueue_retries_total │ kn_workqueue_retries_total │
│ tekton_triggers_controller_client_latency │ http_client_request_duration_seconds_* │
│ tekton_triggers_controller_client_results │ kn_k8s_client_http_response_status_code_total │
└──────────────────────────────────────────────────────────┴───────────────────────────────────────────────────┘
Sink counter metrics renamed
┌──────────────────────────────────────────┬────────────────────────────────────────────┐
│ Old Metric Name (OpenCensus) │ New Metric Name (OpenTelemetry) │
├──────────────────────────────────────────┼────────────────────────────────────────────┤
│ eventlistener_event_received_count │ eventlistener_event_received_total │
│ eventlistener_triggered_resources │ eventlistener_triggered_resources_total │
└──────────────────────────────────────────┴────────────────────────────────────────────┘
All other metric names are unchanged
controller_eventlistener_count, controller_triggerbinding_count,
controller_triggertemplate_count, controller_clustertriggerbinding_count,
controller_clusterinterceptor_count, eventlistener_http_duration_seconds
Thanks to these contributors who contributed to v0.36.0!
Extra shout-out for awesome release notes:
kubectl apply -f https://infra.tekton.dev/tekton-releases/triggers/previous/v0.35.1/release.yaml kubectl apply -f https://infra.tekton.dev/tekton-rele
kubectl apply -f https://infra.tekton.dev/tekton-releases/triggers/previous/v0.35.1/release.yaml
kubectl apply -f https://infra.tekton.dev/tekton-releases/triggers/previous/v0.35.1/interceptors.yamlThe Rekor UUID for this release is 108e9186e8c5677afcbbd2fbbeb11137aa3b20516853ad8927ca19f4009f533f8669a1749ef4221b
Obtain the attestation:
REKOR_UUID=108e9186e8c5677afcbbd2fbbeb11137aa3b20516853ad8927ca19f4009f533f8669a1749ef4221b
rekor-cli get --uuid $REKOR_UUID --format json | jq -r .Attestation | jq .Verify that all container images in the attestation are in the release file:
RELEASE_FILE=https://infra.tekton.dev/tekton-releases/triggers/previous/v0.35.1/release.yaml
INTERCEPTORS_FILE=https://infra.tekton.dev/tekton-releases/triggers/previous/v0.35.1/interceptors.yaml
REKOR_UUID=108e9186e8c5677afcbbd2fbbeb11137aa3b20516853ad8927ca19f4009f533f8669a1749ef4221b
REKOR_ATTESTATION_IMAGES=$(rekor-cli get --uuid "$REKOR_UUID" --format json | jq -r .Attestation | jq -r '.subject[]|.name + ":v0.35.1@sha256:" + .digest.sha256')
curl -L "$RELEASE_FILE" > release.yaml
curl "$INTERCEPTORS_FILE" >> release.yaml
for image in $REKOR_ATTESTATION_IMAGES; do
printf $image; grep -q $image release.yaml && echo " ===> ok" || echo " ===> no match";
donePatch release on top of v0.35.0.
This release was created manually; automated GitHub draft release creation for triggers is being added in #2171.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
- Docs @ v0.35.0 - Examples @ v0.35.0
-Docs @ v0.35.0
-Examples @ v0.35.0
kubectl apply -f https://infra.tekton.dev/tekton-releases/triggers/previous/v0.35.0/release.yaml
kubectl apply -f https://infra.tekton.dev/tekton-releases/triggers/previous/v0.35.0/interceptors.yamlThe Rekor UUID for this release is 108e9186e8c5677a45203936a8966245d4ee1bb04114c3c9a7a8ed99eae1e452c4e75cd00bfe19eb
Obtain the attestation:
REKOR_UUID=108e9186e8c5677a45203936a8966245d4ee1bb04114c3c9a7a8ed99eae1e452c4e75cd00bfe19eb
rekor-cli get --uuid $REKOR_UUID --format json | jq -r .Attestation | jq .Verify that all container images in the attestation are in the release file:
RELEASE_FILE=https://infra.tekton.dev/tekton-releases/triggers/previous/${VERSION_TAG}/release.yaml
INTERCEPTORS_FILE=https://infra.tekton.dev/tekton-releases/triggers/previous/${VERSION_TAG}/interceptors.yaml
REKOR_UUID=108e9186e8c5677a45203936a8966245d4ee1bb04114c3c9a7a8ed99eae1e452c4e75cd00bfe19eb
# Obtains the list of images with sha from the attestation
REKOR_ATTESTATION_IMAGES=$(rekor-cli get --uuid "$REKOR_UUID" --format json | jq -r .Attestation | jq -r '.subject[]|.name + ":v0.35.0@sha256:" + .digest.sha256')
# Download the release file
curl -L "$RELEASE_FILE" > release.yaml
curl -L "$INTERCEPTORS_FILE" >> release.yaml
# For each image in the attestation, match it to the release file
for image in $REKOR_ATTESTATION_IMAGES; do
printf $image; grep -q $image release.yaml && echo " ===> ok" || echo " ===> no match";
doneThanks to these contributors who contributed to v0.35.0!
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
- Docs @ v0.34.0 - Examples @ v0.34.0
-Docs @ v0.34.0
-Examples @ v0.34.0
kubectl apply -f https://infra.tekton.dev/tekton-releases/triggers/previous/v0.34.0/release.yaml
kubectl apply -f https://infra.tekton.dev/tekton-releases/triggers/previous/v0.34.0/interceptors.yamlThe Rekor UUID for this release is 108e9186e8c5677af5fc7b3c5466e79e0ce84af7fbea9da03d09fcf1f91c05e1d34c23b20af28f3f
Obtain the attestation:
REKOR_UUID=108e9186e8c5677af5fc7b3c5466e79e0ce84af7fbea9da03d09fcf1f91c05e1d34c23b20af28f3f
rekor-cli get --uuid $REKOR_UUID --format json | jq -r .Attestation | jq .Verify that all container images in the attestation are in the release file:
RELEASE_FILE=https://infra.tekton.dev/tekton-releases/triggers/previous/v0.34.0/release.yaml
REKOR_UUID=108e9186e8c5677af5fc7b3c5466e79e0ce84af7fbea9da03d09fcf1f91c05e1d34c23b20af28f3f
# Obtains the list of images with sha from the attestation
REKOR_ATTESTATION_IMAGES=$(rekor-cli get --uuid "$REKOR_UUID" --format json | jq -r .Attestation | jq -r '.subject[]|.name + ":v0.34.0@sha256:" + .digest.sha256')
# Download the release file
curl -LO "$RELEASE_FILE" > release.yaml
# For each image in the attestation, match it to the release file
for image in $REKOR_ATTESTATION_IMAGES; do
printf $image; grep -q $image release.yaml && echo " ===> ok" || echo " ===> no match";
donefeat: auto fill http request content length for binding and cel eval tools
The GitHub interceptor now only accepts SHA-256 signatures via the X-Hub-Signature-256 header and no longer supports SHA-1 signatures via X-Hub-Signature. Standard GitHub webhooks are unaffected as GitHub sends both headers by default, but custom webhook implementations must update their HMAC signature generation from SHA-1 to SHA-256 or they will receive "no X-Hub-Signature-256 header set" errors.
Bugfix: escape Tekton variable syntax in trigger parameters (e.g. when $() are found in pr.body.description)
Thanks to these contributors who contributed to v0.34.0!
Extra shout-out for awesome release notes:
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →