This repository has been archived by the owner on Oct 27, 2023. It is now read-only.
-
Notifications
You must be signed in to change notification settings - Fork 4
chore(deps): update dependency aquaproj/aqua to v1.38.0 (.github/workflows) #142
Open
renovate
wants to merge
1
commit into
main
Choose a base branch
from
renovate/github/workflows-aquaproj-aqua-1.x
base: main
Could not load branches
Branch not found: {{ refName }}
Loading
Could not load tags
Nothing to show
Loading
Are you sure you want to change the base?
Some commits from the old base branch may be removed from the timeline,
and old review comments may become outdated.
Conversation
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
renovate
bot
force-pushed
the
renovate/github/workflows-aquaproj-aqua-1.x
branch
from
December 26, 2022 13:45
6b54eaf
to
e784078
Compare
renovate
bot
changed the title
chore(deps): update dependency aquaproj/aqua to v1.25.2 (.github/workflows)
chore(deps): update dependency aquaproj/aqua to v1.26.0 (.github/workflows)
Dec 26, 2022
renovate
bot
changed the title
chore(deps): update dependency aquaproj/aqua to v1.26.0 (.github/workflows)
chore(deps): update dependency aquaproj/aqua to v1.26.1 (.github/workflows)
Dec 26, 2022
renovate
bot
force-pushed
the
renovate/github/workflows-aquaproj-aqua-1.x
branch
2 times, most recently
from
December 27, 2022 07:39
1c9ff1c
to
e990703
Compare
renovate
bot
changed the title
chore(deps): update dependency aquaproj/aqua to v1.26.1 (.github/workflows)
chore(deps): update dependency aquaproj/aqua to v1.26.2 (.github/workflows)
Dec 27, 2022
renovate
bot
force-pushed
the
renovate/github/workflows-aquaproj-aqua-1.x
branch
from
December 29, 2022 06:48
e990703
to
fa7cc8f
Compare
renovate
bot
changed the title
chore(deps): update dependency aquaproj/aqua to v1.26.2 (.github/workflows)
chore(deps): update dependency aquaproj/aqua to v1.27.0 (.github/workflows)
Dec 29, 2022
renovate
bot
force-pushed
the
renovate/github/workflows-aquaproj-aqua-1.x
branch
from
December 30, 2022 00:23
fa7cc8f
to
14f632c
Compare
renovate
bot
changed the title
chore(deps): update dependency aquaproj/aqua to v1.27.0 (.github/workflows)
chore(deps): update dependency aquaproj/aqua to v1.28.0 (.github/workflows)
Dec 30, 2022
renovate
bot
force-pushed
the
renovate/github/workflows-aquaproj-aqua-1.x
branch
from
January 2, 2023 08:13
14f632c
to
8037c85
Compare
renovate
bot
changed the title
chore(deps): update dependency aquaproj/aqua to v1.28.0 (.github/workflows)
chore(deps): update dependency aquaproj/aqua to v1.29.0 (.github/workflows)
Jan 2, 2023
renovate
bot
force-pushed
the
renovate/github/workflows-aquaproj-aqua-1.x
branch
from
January 3, 2023 18:30
8037c85
to
c83dd5d
Compare
renovate
bot
changed the title
chore(deps): update dependency aquaproj/aqua to v1.29.0 (.github/workflows)
chore(deps): update dependency aquaproj/aqua to v1.30.0 (.github/workflows)
Jan 3, 2023
renovate
bot
force-pushed
the
renovate/github/workflows-aquaproj-aqua-1.x
branch
from
January 5, 2023 13:39
c83dd5d
to
75ec716
Compare
renovate
bot
changed the title
chore(deps): update dependency aquaproj/aqua to v1.30.0 (.github/workflows)
chore(deps): update dependency aquaproj/aqua to v1.30.1 (.github/workflows)
Jan 5, 2023
renovate
bot
force-pushed
the
renovate/github/workflows-aquaproj-aqua-1.x
branch
from
January 6, 2023 04:36
75ec716
to
f4e556a
Compare
renovate
bot
changed the title
chore(deps): update dependency aquaproj/aqua to v1.30.1 (.github/workflows)
chore(deps): update dependency aquaproj/aqua to v1.30.2 (.github/workflows)
Jan 6, 2023
renovate
bot
force-pushed
the
renovate/github/workflows-aquaproj-aqua-1.x
branch
from
January 8, 2023 08:14
f4e556a
to
1e7e8d6
Compare
renovate
bot
changed the title
chore(deps): update dependency aquaproj/aqua to v1.30.2 (.github/workflows)
chore(deps): update dependency aquaproj/aqua to v1.30.3 (.github/workflows)
Jan 8, 2023
renovate
bot
force-pushed
the
renovate/github/workflows-aquaproj-aqua-1.x
branch
from
January 10, 2023 04:07
1e7e8d6
to
6016cd7
Compare
renovate
bot
changed the title
chore(deps): update dependency aquaproj/aqua to v1.30.3 (.github/workflows)
chore(deps): update dependency aquaproj/aqua to v1.30.4 (.github/workflows)
Jan 10, 2023
renovate
bot
force-pushed
the
renovate/github/workflows-aquaproj-aqua-1.x
branch
from
January 13, 2023 11:39
6016cd7
to
37c9a9b
Compare
renovate
bot
changed the title
chore(deps): update dependency aquaproj/aqua to v1.30.4 (.github/workflows)
chore(deps): update dependency aquaproj/aqua to v1.31.0 (.github/workflows)
Jan 13, 2023
renovate
bot
force-pushed
the
renovate/github/workflows-aquaproj-aqua-1.x
branch
from
January 15, 2023 14:53
37c9a9b
to
6937454
Compare
renovate
bot
changed the title
chore(deps): update dependency aquaproj/aqua to v1.31.0 (.github/workflows)
chore(deps): update dependency aquaproj/aqua to v1.32.0 (.github/workflows)
Jan 15, 2023
renovate
bot
force-pushed
the
renovate/github/workflows-aquaproj-aqua-1.x
branch
from
January 28, 2023 11:38
6937454
to
fb3dd0a
Compare
renovate
bot
changed the title
chore(deps): update dependency aquaproj/aqua to v1.32.0 (.github/workflows)
chore(deps): update dependency aquaproj/aqua to v1.32.1 (.github/workflows)
Jan 28, 2023
renovate
bot
force-pushed
the
renovate/github/workflows-aquaproj-aqua-1.x
branch
from
January 31, 2023 17:07
fb3dd0a
to
9dcb082
Compare
renovate
bot
changed the title
chore(deps): update dependency aquaproj/aqua to v1.32.1 (.github/workflows)
chore(deps): update dependency aquaproj/aqua to v1.32.2 (.github/workflows)
Jan 31, 2023
renovate
bot
force-pushed
the
renovate/github/workflows-aquaproj-aqua-1.x
branch
from
February 2, 2023 06:45
9dcb082
to
e7d009a
Compare
renovate
bot
changed the title
chore(deps): update dependency aquaproj/aqua to v1.32.2 (.github/workflows)
chore(deps): update dependency aquaproj/aqua to v1.32.3 (.github/workflows)
Feb 2, 2023
renovate
bot
force-pushed
the
renovate/github/workflows-aquaproj-aqua-1.x
branch
from
February 6, 2023 09:48
e7d009a
to
59ec445
Compare
renovate
bot
changed the title
chore(deps): update dependency aquaproj/aqua to v1.32.3 (.github/workflows)
chore(deps): update dependency aquaproj/aqua to v1.33.0 (.github/workflows)
Feb 6, 2023
renovate
bot
force-pushed
the
renovate/github/workflows-aquaproj-aqua-1.x
branch
from
March 17, 2023 06:04
59ec445
to
f890647
Compare
renovate
bot
changed the title
chore(deps): update dependency aquaproj/aqua to v1.33.0 (.github/workflows)
chore(deps): update dependency aquaproj/aqua to v1.36.1 (.github/workflows)
Mar 17, 2023
renovate
bot
changed the title
chore(deps): update dependency aquaproj/aqua to v1.36.1 (.github/workflows)
chore(deps): update dependency aquaproj/aqua to v1.38.0 (.github/workflows)
Mar 24, 2023
renovate
bot
force-pushed
the
renovate/github/workflows-aquaproj-aqua-1.x
branch
from
March 24, 2023 13:39
f890647
to
7abc40a
Compare
Sign up for free
to subscribe to this conversation on GitHub.
Already have an account?
Sign in.
Labels
None yet
0 participants
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
v1.25.0
->v1.38.0
Release Notes
aquaproj/aqua (aquaproj/aqua)
v1.38.0
Compare Source
Pull Requests | Issues | aquaproj/aqua@v1.37.2...v1.38.0
Features
#1781 #1783 Support configuring
require_checksum
by the environment variableIf
require_checksum
is configured in a configuration file, the environment variable is ignored.If
checksum
isn't enabled in a configuration file, the environment variable is ignored.Why is the feature needed?
To combine security and convenience.
In CI we would like to enable
require_checksum
for security.On the other hand, we don't want to enable
require_checksum
in your laptops for convenience.If
require_checksum
is enabled, you have to runaqua update-checksum
when you change the package version.Otherwise, it fails to run the package. This is a bad experience.
v1.37.2
Compare Source
Pull Requests | Issues | aquaproj/aqua@v1.37.1...v1.37.2
Fixes
#1777 init, init-policy: remove broken links
aqua.yaml
andaqua-policy.yaml
generated byaqua init
andaqua init-policy
commands contained broken links.So we removed them.
v1.37.1
Compare Source
Pull Requests | Issues | aquaproj/aqua@v1.37.0...v1.37.1
Bug Fixes
#1771 #1772 Fixed a bug that
update-checksum --deep
command fails ifgo_install
package is usedv1.37.0
Compare Source
Pull Requests | Issues | aquaproj/aqua@v1.36.1...v1.37.0
Features
#1762 Support default checksum parser
aqua supported two checksum file format
raw
andregexp
and the file format is mandatory.This pull request supports a default file format and the file format becomes optional.
If a checksum file contains only one line and doesn't contain a space
, a file content is treated as checksum.
e.g.
Each line is split by a space
.
The first element is treated as a checksum
The second element is treated as a file path, and the base name is treated as the asset name.
e.g.
Why this feature is needed
This feature works well flexibly and we don't have to fix checksum configuration when the checksum file format is changed.
We don't have to write complicated regular expressions.
This feature improves the maintainability of checksum configuration.
Others
#1764 Update Go from v1.20.1 to v1.20.2
v1.36.1
Compare Source
Pull Requests | Issues | aquaproj/aqua@v1.36.0...v1.36.1
Bug Fixes
#1742 #1752 install: install command succeeded unexpectedly even if unknown packages are included
This bug was caused by aquaproj/aqua@40154d3 v1.19.5 (2022-10-01).
#1746 #1757 Clear unrelated fields if package type is changed by
overrides
orversion_overrides
Others
#1718 #1721 #1755 #1756 Use slsa-verifier as CLI instead of Go library to separate slsa-verifier from aqua itself
#1753 update google/go-github from v45 to v50
Use slsa-verifier as CLI instead of Go library to separate slsa-verifier from aqua itself
#1718 #1721
From aqua v1.26.0, aqua has supported verifing packages by slsa-verifier. aqua used slsa-verifier as a Go library, but then some issues occured because slsa-verifier is so large.
go mod tidy
andgo get
Especially, #1717 was critical.
To solve these issues, we decided to use slsa-verifer as CLI instead of Go library.
v1.36.0
Compare Source
Pull Requests | Issues | aquaproj/aqua@v1.35.0...v1.36.0
Features
#1668 #1710 Show files in a package if an executable file isn't found
#1704 #1705 Output HTTP status code when it fails to install a
http
packageShow files in a package if an executable file isn't found
#1668 #1710
e.g.
v1.35.0
Compare Source
Pull Requests | Issues | aquaproj/aqua@v1.34.2...v1.35.0
Features
#1692 #1699 Output the content of a checksum file when it fails to parse a checksum file
#1684 #1687 Support outputting error messages when a package is installed
#1693 #1695 Add a field
no_asset
to package configuration for returing an error because there is no assetOutput the content of a checksum file when it fails to parse a checksum file
#1692 #1699
This is useful to fix the package's checksum configuration.
e.g.
Support outputting error messages when a package is installed
#1684 #1687
e.g.
registry.yaml
Add a field
no_asset
to package configuration for returing an error because there is no asset#1693 #1695
e.g.
registry.yaml
Fixes
#1700 #1701 Remove
exe_path
from logexe_path
isn't helpful in many cases.exe_path
is long, so this is a bit noisy.v1.34.2
Compare Source
Pull Requests | Issues | aquaproj/aqua@v1.34.1...v1.34.2
Bug Fixes
#1682 #1685 generate-registry: Fix
--deep
option to handle GitHub Releases not conforming to semantic versioningv1.34.1
Compare Source
Pull Requests | Issues | aquaproj/aqua@v1.34.0...v1.34.1
Bug Fixes
#1092 #1675 #1677 #1678 generate-registry: Refactoring and fix some bugs
v1.34.0
Compare Source
Pull Requests | Issues | aquaproj/aqua@v1.33.0...v1.34.0
Features
#1655 #1662 generate-registry: Support generating
version_overrides
and testdatahttps://aquaproj.github.io/docs/reference/scaffold-registry/#generate-version_overrides-by---deep-option
Add command line options
--deep
and--out-testdata
toaqua gr
command.--deep
: Generateversion_overrides
--out-testdata
: Output testdata to a file--deep
option calls GitHub API per GitHub Release. So if there are a lot of GitHub Releases, many GitHub API are called and GitHub API rate limiting may occur.Fixes
#1639 generate-registry: Support md5 and sha1
#1640 generate-registry: Fix checksum asset names
#1611 Use the default configuration if the package version doesn't match any
version_constraint
Others
#1638 generate-registry: Refactoring
v1.33.0
Compare Source
Pull Requests | Issues | aquaproj/aqua@v1.32.3...v1.33.0
Features
#1595 #1615 #1626 Support keeping configuration files in one directory
https://aquaproj.github.io/docs/tutorial-extras/keep-in-one-dir
aqua has several configuration files such as
aqua.yaml
, aqua-checksums.json, policy file, and imported files.e.g.
From aqua v1.33.0, aqua supports keeping configuration files in one directory.
e.g.
This is useful to keep the working directory clean.
How to migrate
v1.32.3
Compare Source
Pull Requests | Issues | aquaproj/aqua@v1.32.2...v1.32.3
Bug Fixes
#1610 fix a bug Registry's checksums are compared without normalization
This bug occurs when a Registry is installed and the Registry's checksum in
aqua-checksums.json
is uppercase,because the calculated checksum is lowercase.
This bug raised by https://github.com/aquaproj/aqua/releases/tag/v1.32.2 , because the release made checksums uppercase.
e.g.
v1.32.2
Compare Source
Pull Requests | Issues | aquaproj/aqua@v1.32.1...v1.32.2
Bug Fixes
#1599 #1600 Skip setting checksum if the key already exists
Fixes
#1601 Normalize checksum when a newly added
v1.32.1
Compare Source
Pull Requests | Issues | aquaproj/aqua@v1.32.0...v1.32.1
Fixes
#1585 #1588 Retry slsa-verifier when slsa-verifier failed due to timeout
v1.32.0
Compare Source
Pull Requests | Issues | aquaproj/aqua@v1.31.0...v1.32.0
Features
generate-registry: Support specifying version
e.g.
$ aqua gr suzuki-shunsuke/[email protected]
v1.31.0
Compare Source
Pull Requests | Issues | aquaproj/aqua@v1.30.4...v1.31.0
Features
#1545 #1552 Add the attribute
version_prefix
to Registry Configurationversion_prefix
to Registry ConfigurationSemVer
to expr expressions and template variablesversion_filter
toversion_prefix
in many casesVersion
, the parameterSemver
is used in the functionsemver
You can filter versions with a specific prefix and trim the prefix from versions by
version_prefix
.For example, kubernetes-sigs/kustomize has a prefix
kustomize/
.Bug Fixes
Fixed bugs regarding to Cosign.
#1554 #1557 Retry the verification by Cosign
#1555 #1558 Get a lock before executing Cosign to prevent Cosign from being executing in parallel
#1559 Get a Lock before installing Cosign
#1559 Fix a bug that options of Cosign could be wrong if the same package's multiple versions are installed at the same time
v1.30.4
Compare Source
Pull Requests | Issues | aquaproj/aqua@v1.30.3...v1.30.4
Bug Fixes
#1541 generate: remove a newline
From aqua v1.25.2, a newline was inserted unnecessarily.
e.g.
By this release, the newline is removed.
#1548 #1549 Return error if version doesn't match with all version_constraints
v1.30.3
Compare Source
Pull Requests | Issues | aquaproj/aqua@v1.30.2...v1.30.3
Features
#1539 Verify checksums of aqua-proxy to prevent aqua-proxy from being tampered. Checksums are hardcoded to aqua.
Others
#1540 Update aqua-proxy from v1.1.2 to v1.1.4
v1.30.2
Compare Source
Pull Requests | Issues | aquaproj/aqua@v1.30.2-1...v1.30.2
Bug Fixes
#1528 #1530 Fix a bug that Cosign isn't installed properly if
AQUA_GOOS
andAQUA_GOARCH
are setOthers
#1391 #1526 Sign checksum files by Cosign
v1.30.1
Compare Source
Pull Requests | Issues | aquaproj/aqua@v1.30.0...v1.30.1
Bug Fixes
#1521 #1523 update-checksum: Fix a bug that registries' checksums are removed by
-prune
optionv1.30.0
Compare Source
Pull Requests | Issues | aquaproj/aqua@v1.29.0...v1.30.0
Features
#1490 #1511 Install cosign lazily to avoid installing Cosign unnecessarily
#1510 Prevent Cosign from being tampered by hardcoding checksums of Cosign
#1491 #1508 Support verifying Registries' checksums
#1512 #1514 Add
darwin/arm64
tosupported_envs
ifrosetta2
is enabledSupport verifying Registries' checksums
#1491 #1508
aqua verifies checksums of Registries if Checksum Verification is enabled.
aqua.yaml
aqua-checksums.json
If the checksum is invalid, it would fail to install Registries.
Others
#1509 init: add
.checksum.supported_envs
toaqua init
's templatev1.29.0
Compare Source
Pull Requests | Issues | aquaproj/aqua@v1.28.0...v1.29.0
Features
#1230 #1498 checksum: Support excluding unneeded os/arch checksum from aqua-checksums.json
#1216 #1500 checksum: Support an algorithm
sha1
Support excluding unneeded os/arch checksum from aqua-checksums.json
#1230 #1498
Make
aqua-checksums.json
slim and avoid unneeded API call and failure.Prevent
aqua update-checksum -deep
from downloading unused platform's assets.e.g. Exclude Windows
aqua.yaml
Support an algorithm
sha1
#1216 #1500
v1.28.0
Compare Source
Pull Requests | Issues | aquaproj/aqua@v1.27.0...v1.28.0
Features
Improved
aqua update-checksum
command. https://aquaproj.github.io/docs/tutorial-extras/checksum/#1489 #1492 Ignore unrelated files' checksums in checksum files
#1257 #1495 Support pruning unused checksums in
aqua-checksums.json
Ignore unrelated files' checksums in checksum files
#1489 #1492
aqua update-checksum
added all checksums in checksum files.But some checksum files include unrelated checksums.
For example, gh_2.21.1_checksums.txt includes a checksum of Debian package, which is unneeded for aqua.
From aqua v1.28.0, aqua ignores these unrelated checksums.
Support pruning unused checksums in
aqua-checksums.json
#1257 #1495
When tools are updated, checksums for old versions are basically unneeded.
Or when we remove some tools from
aqua.yaml
, checksums for those tools would be unneeded.You can remove unused checksums by setting
-prune
option.v1.27.0
Compare Source
Pull Requests | Issues | aquaproj/aqua@v1.26.2...v1.27.0
Features
#1466 #1468 #1486 Support a new field
private
for private packages and registriesYou can set
private: true
to private packages and registries.By default,
private
isfalse
.If
private
is true, aqua skips sending HTTP requests to download assets, because the requests always fail.Even if the value of
private
attribute is wrong, you can install the registry and package.e.g. aqua.yaml
e.g. registry.yaml
#1084 #1487 Support template in
go_install
package'spath
attributeGo Module path includes the major version.
We have ever had to define version_constraint per major version.
Using template, you can define the package more simply.
e.g.
Bug Fixes
#1482 generate-registry: Remove
slsa_provenance: null
from the output ofaqua gr
v1.26.2
Compare Source
Pull Requests | Issues | aquaproj/aqua@v1.26.1...v1.26.2
Bug Fixes
#1477 Install and execute Cosign with correct runtime
Fixed a bug that when
AQUA_GOOS
orAQUA_GOARCH
were set Cosign for wrong runtime was installed.v1.26.1
Compare Source
Pull Requests | Issues | aquaproj/aqua@v1.26.0...v1.26.1
Bug Fixes
#1471 Skip installing Cosign and verify with Cosign in windows/arm64
#1473 Check if Cosign is supported
Others
#1474 Update Go to 1.19.4
v1.26.0
Compare Source
Pull Requests | Issues | aquaproj/aqua@v1.25.2...v1.26.0
Features
#1449 #1454 Support package verification by Cosign and slsa-verifier
We provide aqua's SLSA Provenance multiple.intoto.jsonl.
v1.25.2
Compare Source
Pull Requests | Issues | aquaproj/aqua@v1.25.0...v1.25.2
📝 It failed to release v1.25.1 by CI, so we released v1.25.2. This is why the release v1.25.1 doesn't exist.
Fixes
#1462 #1463 generate: fix a bug of
--pin
optionConfiguration
📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR has been generated by Mend Renovate. View repository job log here.