Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

chore: bumps version for v1.4.6 release #1658

Closed
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
165 commits
Select commit Hold shift + click to select a range
5a184ae
chore: bump sigs.k8s.io/yaml from 1.3.0 to 1.4.0 in /test/e2eprovider
dependabot[bot] Oct 30, 2023
abe4833
chore: bump actions/dependency-review-action from 3.0.6 to 3.1.3
dependabot[bot] Nov 13, 2023
d0faaff
release: update manifest and helm charts for v1.4.0
aramase Nov 13, 2023
38752bb
Merge pull request #1375 from aramase/release-v1.4.0
k8s-ci-robot Nov 20, 2023
b201663
docs: update supported releases - v1.3.x and v1.4.x
aramase Nov 20, 2023
d74be15
Merge pull request #1379 from aramase/aramase/d/release_v1.4.0
k8s-ci-robot Nov 20, 2023
0117e89
chore: bump step-security/harden-runner from 2.4.0 to 2.6.1
dependabot[bot] Nov 20, 2023
6d96251
Merge pull request #1381 from kubernetes-sigs/dependabot/github_actio…
k8s-ci-robot Nov 29, 2023
97f9dec
Merge pull request #1373 from kubernetes-sigs/dependabot/github_actio…
k8s-ci-robot Dec 1, 2023
d6a0f93
Add clarify to mount action in best-practices.md
prb112 Dec 11, 2023
212b58d
ci: add script for aks windows cluster
aramase Jan 6, 2024
a54afd0
ci: remove aks-engine job templates
aramase Jan 8, 2024
261fc40
Merge pull request #1405 from aramase/aramase/f/aks_windows_testing
k8s-ci-robot Jan 8, 2024
9f4a2bb
security: bump golang.org/x/crypto to v0.17.0 to fix CVE-2023-48795
aramase Jan 8, 2024
c219f51
docs: updates security section
nilekhc Nov 17, 2023
1bbc782
Merge pull request #1378 from nilekhc/update-docs
k8s-ci-robot Jan 8, 2024
f3c1bb8
chore: bump github/codeql-action from 2.21.5 to 3.23.0
dependabot[bot] Jan 8, 2024
9f3e9ca
Merge pull request #1407 from aramase/aramase/c/security_fixes
k8s-ci-robot Jan 8, 2024
b5f9ce6
chore: bump google.golang.org/grpc in /test/e2eprovider
dependabot[bot] Jan 8, 2024
2eb0930
Merge pull request #1402 from kubernetes-sigs/dependabot/go_modules/t…
k8s-ci-robot Jan 8, 2024
839df7b
Merge pull request #1408 from kubernetes-sigs/dependabot/github_actio…
k8s-ci-robot Jan 8, 2024
e378b67
ci: remove low quota regions for aks windows job
aramase Jan 9, 2024
d390bd6
Merge pull request #1410 from aramase/aramase/c/aks_regions
k8s-ci-robot Jan 9, 2024
903314f
chore: update to go 1.21.6 in docker
dargudear-google Dec 15, 2023
16d72a3
Merge pull request #1393 from dargudear-google/go_upgrades
k8s-ci-robot Jan 10, 2024
3be4d17
chore: bump actions/upload-artifact from 3.1.2 to 4.0.0
dependabot[bot] Jan 11, 2024
10b6ad5
Merge pull request #1396 from kubernetes-sigs/dependabot/github_actio…
k8s-ci-robot Jan 11, 2024
cc87fdc
chore: bump ossf/scorecard-action from 2.2.0 to 2.3.1
dependabot[bot] Jan 12, 2024
3c190c5
docs: Make link to Reloader a link (#1413)
spottedmahn Jan 12, 2024
836339d
Merge pull request #1367 from kubernetes-sigs/dependabot/go_modules/t…
k8s-ci-robot Jan 13, 2024
97c39a0
Merge pull request #1384 from kubernetes-sigs/dependabot/github_actio…
k8s-ci-robot Jan 13, 2024
4fefeb8
chore: bump actions/dependency-review-action from 3.1.3 to 3.1.5
dependabot[bot] Jan 15, 2024
b1a67fd
release: update manifest and helm charts for v1.4.1
aramase Jan 16, 2024
a42d96f
Merge pull request #1423 from aramase/aramase/r/release_v1.4.1
k8s-ci-robot Jan 16, 2024
b14c525
Merge pull request #1419 from kubernetes-sigs/dependabot/github_actio…
k8s-ci-robot Jan 22, 2024
0a5d00e
chore: bump actions/checkout
dependabot[bot] Jan 22, 2024
0af3027
chore: bump k8s.io/klog/v2 from 2.100.1 to 2.120.1 in /test/e2eprovider
dependabot[bot] Jan 22, 2024
07c7f49
chore: bump actions/upload-artifact from 4.0.0 to 4.2.0
dependabot[bot] Jan 22, 2024
ffb313d
Merge pull request #1418 from kubernetes-sigs/dependabot/github_actio…
k8s-ci-robot Jan 22, 2024
b91661f
chore: bump github/codeql-action from 3.23.0 to 3.23.1
dependabot[bot] Jan 22, 2024
ebc3039
Merge pull request #1427 from kubernetes-sigs/dependabot/github_actio…
k8s-ci-robot Jan 23, 2024
17aeb6b
Merge pull request #1426 from kubernetes-sigs/dependabot/github_actio…
k8s-ci-robot Jan 25, 2024
299d438
Merge pull request #1425 from kubernetes-sigs/dependabot/go_modules/t…
k8s-ci-robot Jan 27, 2024
91e5453
chore: bump codecov/codecov-action from 3.1.4 to 3.1.5
dependabot[bot] Jan 29, 2024
d8daac9
chore: bump actions/dependency-review-action from 3.1.5 to 4.0.0
dependabot[bot] Jan 29, 2024
ddecf45
Merge pull request #1431 from kubernetes-sigs/dependabot/github_actio…
k8s-ci-robot Jan 30, 2024
7a13f0d
Merge pull request #1429 from kubernetes-sigs/dependabot/github_actio…
k8s-ci-robot Feb 1, 2024
6cbaa7c
chore: bump actions/upload-artifact from 4.2.0 to 4.3.1
dependabot[bot] Feb 12, 2024
4400ec5
docs: add Akeyless to supported providers (#1306)
akljph Feb 15, 2024
5231a5e
Merge pull request #1386 from prb112/patch-1
k8s-ci-robot Feb 15, 2024
608fae1
Merge pull request #1439 from kubernetes-sigs/dependabot/github_actio…
k8s-ci-robot Feb 15, 2024
275cf5f
chore: bump github/codeql-action from 3.23.1 to 3.24.3
dependabot[bot] Feb 19, 2024
c697863
Merge pull request #1448 from kubernetes-sigs/dependabot/github_actio…
k8s-ci-robot Feb 25, 2024
10e8b27
chore: update debian-base to bookworm-v1.0.1
aramase Mar 6, 2024
d52c27f
Merge pull request #1457 from aramase/aramase/c/debian_base_bookworm_…
k8s-ci-robot Mar 11, 2024
ab9df20
chore: update node-driver-registrar:v2.10.0, livenessprobe:v2.12.0
aramase Mar 11, 2024
f0741f9
Merge pull request #1459 from aramase/aramase/c/node_driver_registrar…
k8s-ci-robot Mar 11, 2024
5c8a085
release: update manifest and helm charts for v1.4.2
aramase Mar 11, 2024
f2aea5b
Merge pull request #1463 from aramase/aramase/c/release_driver_v1.4.2
k8s-ci-robot Mar 11, 2024
d308d13
CVE-2024-24786: bump google.golang.org/protobuf to v1.33.0
dobsonj Mar 12, 2024
050f986
Merge pull request #1467 from dobsonj/CVE-2024-24786-origin-main
k8s-ci-robot Mar 12, 2024
987599f
chore: bump google.golang.org/grpc in /test/e2eprovider
dependabot[bot] Mar 12, 2024
173a7bd
Merge pull request #1462 from kubernetes-sigs/dependabot/go_modules/t…
k8s-ci-robot Mar 15, 2024
b54143d
security: bump kubectl to v1.29.3 in driver-crds for CVE-2024-24786
aramase Mar 18, 2024
6ec3680
Merge pull request #1472 from aramase/aramase/c/bump_kubectl_version_…
k8s-ci-robot Mar 18, 2024
78e1995
chore: bump github/codeql-action from 3.24.3 to 3.24.8
dependabot[bot] Mar 18, 2024
c7fa95e
Merge pull request #1475 from kubernetes-sigs/dependabot/github_actio…
k8s-ci-robot Mar 19, 2024
d84a7a1
fix: support more than one linux.crds.annotations
stephaniemanning Mar 22, 2024
57b289b
Merge pull request #1478 from stephaniemanning/fix/support-multiple-l…
k8s-ci-robot Mar 22, 2024
8f1c32e
chore: bump actions/checkout from 4.1.1 to 4.1.2
dependabot[bot] Mar 25, 2024
0779c12
Merge pull request #1481 from kubernetes-sigs/dependabot/github_actio…
k8s-ci-robot Mar 25, 2024
dfd7ff6
chore: bump actions/dependency-review-action from 4.0.0 to 4.2.4
dependabot[bot] Mar 25, 2024
bf86dbf
Merge pull request #1480 from kubernetes-sigs/dependabot/github_actio…
k8s-ci-robot Mar 26, 2024
3fa13ad
chore: bump github/codeql-action from 3.24.8 to 3.24.10
dependabot[bot] Apr 8, 2024
d3c3968
chore: bump codecov/codecov-action from 3.1.5 to 4.2.0
dependabot[bot] Apr 8, 2024
8356051
Merge pull request #1489 from kubernetes-sigs/dependabot/github_actio…
k8s-ci-robot Apr 9, 2024
c1b0d9c
chore: update debian-base to bookworm-v1.0.2
aramase Apr 9, 2024
185a8a4
Merge pull request #1491 from aramase/aramase/c/bookworm_v1.0.2
k8s-ci-robot Apr 9, 2024
3040148
Merge pull request #1488 from kubernetes-sigs/dependabot/github_actio…
k8s-ci-robot Apr 10, 2024
22da0cc
chore: bump github/codeql-action from 3.24.10 to 3.25.0
dependabot[bot] Apr 15, 2024
347030e
ci: add govulncheck
aramase Apr 15, 2024
8a596d2
Merge pull request #1494 from kubernetes-sigs/dependabot/github_actio…
k8s-ci-robot Apr 15, 2024
0abfaa3
security: bump golang.org/x/net to v0.23.0+ to fix GO-2024-2687
aramase Apr 15, 2024
205bb9e
Merge pull request #1496 from aramase/aramase/ci/add_govuln_check
k8s-ci-robot Apr 16, 2024
c4aa5d1
release: update manifest and helm charts for v1.4.3
aramase Apr 17, 2024
1c2a612
chore: bump kubectl to v1.29.4 in driver-crds for CVE-2023-45288
aramase Apr 17, 2024
9e4b229
Merge pull request #1500 from aramase/aramase/c/release_driver_v1.4.3
k8s-ci-robot Apr 17, 2024
46041f3
Merge pull request #1502 from aramase/aramase/c/bump_kubectl_version_…
k8s-ci-robot Apr 17, 2024
f43e0b6
chore: bump actions/checkout from 4.1.2 to 4.1.4
dependabot[bot] Apr 29, 2024
897cae9
Merge pull request #1510 from kubernetes-sigs/dependabot/github_actio…
k8s-ci-robot Apr 30, 2024
c970d0e
chore: bump actions/dependency-review-action from 4.2.4 to 4.3.2
dependabot[bot] May 6, 2024
f627940
Merge pull request #1513 from kubernetes-sigs/dependabot/github_actio…
k8s-ci-robot May 7, 2024
c49351a
chore: bump actions/checkout from 4.1.4 to 4.1.5
dependabot[bot] May 7, 2024
5f6daa0
Merge pull request #1512 from kubernetes-sigs/dependabot/github_actio…
k8s-ci-robot May 7, 2024
87f51ec
docs: Add Conjur provider
imheresamir May 16, 2024
9eedbee
Add conjur e2e bats tests
gl-johnson May 23, 2024
f95f32d
Merge pull request #1498 from gl-johnson/conjur-e2e
k8s-ci-robot May 24, 2024
5672b8d
chore: update debian-base to bookworm-v1.0.3
aramase May 28, 2024
df34f89
docs: adds troubleshooting guide for kubeletRootDir
nilekhc May 28, 2024
7ce293a
Merge pull request #1531 from nilekhc/nilekh/d/document-kubelet-dir
k8s-ci-robot May 29, 2024
19177a1
Merge pull request #1530 from aramase/aramase/c/bump_debian_base_v1.0.3
k8s-ci-robot May 29, 2024
549a1de
chore: bump github/codeql-action from 3.25.0 to 3.25.8
dependabot[bot] Jun 10, 2024
c99911f
test: remove target path check in fake provider server
aramase Jun 11, 2024
097f92a
Merge pull request #1543 from aramase/aramase/f/rm_target_path_fake_s…
k8s-ci-robot Jun 12, 2024
05ef279
Merge pull request #1541 from kubernetes-sigs/dependabot/github_actio…
k8s-ci-robot Jun 13, 2024
c9a07a0
Merge pull request #1521 from imheresamir/main
k8s-ci-robot Jun 13, 2024
9548c23
refactor: cleanup unused err check
aramase Jun 14, 2024
de09479
release: update manifest and helm charts for v1.4.4
aramase Jun 17, 2024
0363ede
chore: bump codecov/codecov-action from 4.2.0 to 4.5.0
dependabot[bot] Jun 17, 2024
31bbe92
ci: use `--clean` instead of `--rm-dist`
aramase Jun 18, 2024
6e2f3f3
Merge pull request #1555 from aramase/aramase/c/goreleaser_rm_dist
k8s-ci-robot Jun 18, 2024
9c89ae1
ci: use `--verbose` instead of `--debug` in goreleaser
aramase Jun 18, 2024
2873d70
Merge pull request #1557 from aramase/aramase/c/goreleaser_rm_debug
k8s-ci-robot Jun 18, 2024
aa8e88d
Merge pull request #1548 from aramase/aramase/c/release_driver_v1.4.4
k8s-ci-robot Jun 18, 2024
08ceeb9
ci: use v2 for goreleaser
aramase Jun 19, 2024
e6da463
Akeyless now provides Rotation
akljph Jun 23, 2024
91025bd
Merge pull request #1561 from akljph/main
k8s-ci-robot Jun 24, 2024
18619d1
feat: handles sha string in tag
nilekhc Jun 27, 2024
f49f22f
Merge pull request #1565 from nilekhc/nilekh/c/update-semvar-check
k8s-ci-robot Jun 28, 2024
09e9b3b
chore: bump actions/setup-go from 4.0.1 to 5.0.2
dependabot[bot] Jul 15, 2024
fd1821b
test: use e2e-provider for manifest tests
aramase Jul 16, 2024
555135f
Merge pull request #1573 from aramase/aramase/t/yaml_test
k8s-ci-robot Jul 16, 2024
8feeb00
test: delete metrics ns in e2e for upgrade tests
aramase Jul 17, 2024
92bbbbd
Merge pull request #1574 from aramase/aramase/c/e2e_metrics
k8s-ci-robot Jul 17, 2024
1bfd728
ci: migrate azure job to eks prow cluster
aramase Jul 22, 2024
a30bc3c
Merge pull request #1578 from aramase/aramase/t/migrate_azure_jobs
k8s-ci-robot Jul 26, 2024
71fdb54
test: reset rotation response in mock server for upgrade tests
aramase Jul 29, 2024
f486ae5
Merge pull request #1585 from aramase/aramase/t/reset_rotated_secret_e2e
k8s-ci-robot Jul 29, 2024
0c90683
chore: bump ossf/scorecard-action from 2.3.1 to 2.4.0
dependabot[bot] Jul 29, 2024
57a12f1
Merge pull request #1586 from kubernetes-sigs/dependabot/github_actio…
k8s-ci-robot Jul 29, 2024
c807dca
chore: bump node-driver-registrar to v2.11.1
aramase Aug 2, 2024
36c6a8d
chore: bump livenessprobe to v2.13.1
aramase Aug 2, 2024
0a0ed48
chore: bump kind version and k8s version in test matrix
aramase Aug 2, 2024
b3ee654
Merge pull request #1593 from aramase/aramase/c/bump_kind_version_v0.…
k8s-ci-robot Aug 9, 2024
5e3935b
chore: bump step-security/harden-runner from 2.6.1 to 2.9.1
dependabot[bot] Aug 9, 2024
e1ba223
bump kubectl version to v1.30.2
aramase Aug 9, 2024
f81c8ec
add namespace to all kubectl commands in azure.bats
aramase Aug 9, 2024
a3d7b87
Merge pull request #1597 from aramase/aramase/t/debug_ci
k8s-ci-robot Aug 10, 2024
3a4d581
Merge pull request #1592 from aramase/aramase/c/bump_sidecars
k8s-ci-robot Aug 10, 2024
dae0961
chore: bump actions/upload-artifact from 4.3.1 to 4.3.6
dependabot[bot] Aug 12, 2024
d3b857e
Merge pull request #1559 from aramase/aramase/ci/goreleaser_v2
k8s-ci-robot Aug 20, 2024
093828b
release: update manifest and helm charts for v1.4.5
aramase Aug 20, 2024
71a81ca
Merge pull request #1608 from aramase/aramase/c/release_driver_v1.4.5
k8s-ci-robot Aug 20, 2024
65a69f6
Merge pull request #1596 from kubernetes-sigs/dependabot/github_actio…
k8s-ci-robot Aug 22, 2024
c683164
ci: update goreleaser config for v2
aramase Aug 21, 2024
824efb1
Merge pull request #1612 from aramase/aramase/ci/update_goreleaser_co…
k8s-ci-robot Aug 22, 2024
3193ce4
Merge pull request #1600 from kubernetes-sigs/dependabot/github_actio…
k8s-ci-robot Aug 23, 2024
6c0cdde
ci: skip builds goreleaser config
aramase Aug 23, 2024
1967382
Merge pull request #1614 from aramase/aramase/ci/skip_builds_goreleaser
k8s-ci-robot Aug 23, 2024
15c0654
Merge pull request #1546 from aramase/aramase/f/cleanup_err
k8s-ci-robot Aug 23, 2024
9f2de3f
Merge pull request #1552 from kubernetes-sigs/dependabot/github_actio…
k8s-ci-robot Aug 26, 2024
7e524a7
Merge pull request #1571 from kubernetes-sigs/dependabot/github_actio…
k8s-ci-robot Aug 26, 2024
f09e97c
chore: bump github/codeql-action from 3.25.8 to 3.26.5
dependabot[bot] Aug 26, 2024
6fe8bd5
chore: bump actions/checkout from 4.1.5 to 4.1.7
dependabot[bot] Aug 26, 2024
5e1d34f
chore: bump golang/govulncheck-action from 1.0.2 to 1.0.3
dependabot[bot] Aug 26, 2024
09eed10
Merge pull request #1618 from kubernetes-sigs/dependabot/github_actio…
k8s-ci-robot Aug 26, 2024
d41dbff
Merge pull request #1615 from kubernetes-sigs/dependabot/github_actio…
k8s-ci-robot Aug 29, 2024
d344c22
Merge pull request #1616 from kubernetes-sigs/dependabot/github_actio…
k8s-ci-robot Aug 29, 2024
7710922
chore: bump actions/dependency-review-action from 4.3.2 to 4.3.4
dependabot[bot] Aug 29, 2024
ccd4672
Merge pull request #1617 from kubernetes-sigs/dependabot/github_actio…
k8s-ci-robot Sep 1, 2024
92c73a0
chore: bump github/codeql-action from 3.26.5 to 3.26.6
dependabot[bot] Sep 2, 2024
2f6e7d0
chore: bump actions/upload-artifact from 4.3.6 to 4.4.0
dependabot[bot] Sep 2, 2024
3b60c21
Merge pull request #1628 from kubernetes-sigs/dependabot/github_actio…
k8s-ci-robot Sep 3, 2024
981b21a
Merge pull request #1627 from kubernetes-sigs/dependabot/github_actio…
k8s-ci-robot Sep 3, 2024
85ac324
chore: bumps version for v1.4.6 release
nilekhc Oct 8, 2024
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 2 additions & 2 deletions .github/workflows/chart.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -19,10 +19,10 @@ jobs:
runs-on: ubuntu-20.04
steps:
- name: Harden Runner
uses: step-security/harden-runner@128a63446a954579617e875aaab7d2978154e969 # v2.4.0
uses: step-security/harden-runner@5c7944e73c4c2a096b17a9cb74d65b6c2bbafbde # v2.9.1
with:
egress-policy: audit
- uses: actions/checkout@3df4ab11eba7bda6032a0b82a6bb43b11571feac # v4.0.0
- uses: actions/checkout@692973e3d937129bcbf40652eb9f2f61becf3332 # v4.0.0
with:
submodules: true
fetch-depth: 0
Expand Down
8 changes: 4 additions & 4 deletions .github/workflows/codecov.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -14,16 +14,16 @@ jobs:
runs-on: ubuntu-latest
steps:
- name: Harden Runner
uses: step-security/harden-runner@128a63446a954579617e875aaab7d2978154e969 # v2.4.0
uses: step-security/harden-runner@5c7944e73c4c2a096b17a9cb74d65b6c2bbafbde # v2.9.1
with:
egress-policy: audit

- uses: actions/checkout@3df4ab11eba7bda6032a0b82a6bb43b11571feac # v4.0.0
- uses: actions/setup-go@fac708d6674e30b6ba41289acaab6d4b75aa0753 # v4.0.1
- uses: actions/checkout@692973e3d937129bcbf40652eb9f2f61becf3332 # v4.0.0
- uses: actions/setup-go@0a12ed9d6a96ab950c8f026ed9f722fe0da7ef32 # v5.0.2
with:
go-version: "^1.20"
- name: Run tests
run: make go-test
- uses: codecov/codecov-action@eaaf4bedf32dbdc6b720b63067d99c4d77d6047d
- uses: codecov/codecov-action@e28ff129e5465c2c0dcc6f003fc735cb6ae0c673
with:
files: ./cover.out
10 changes: 5 additions & 5 deletions .github/workflows/codeql.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -21,20 +21,20 @@ jobs:

steps:
- name: Harden Runner
uses: step-security/harden-runner@128a63446a954579617e875aaab7d2978154e969 # v2.4.0
uses: step-security/harden-runner@5c7944e73c4c2a096b17a9cb74d65b6c2bbafbde # v2.9.1
with:
egress-policy: audit

- name: Checkout repository
uses: actions/checkout@3df4ab11eba7bda6032a0b82a6bb43b11571feac # v4.0.0
uses: actions/checkout@692973e3d937129bcbf40652eb9f2f61becf3332 # v4.0.0

- name: Initialize CodeQL
uses: github/codeql-action/init@00e563ead9f72a8461b24876bee2d0c2e8bd2ee8 # v2.21.5
uses: github/codeql-action/init@4dd16135b69a43b6c8efb853346f8437d92d3c93 # v3.26.6
with:
languages: go

- name: Autobuild
uses: github/codeql-action/autobuild@00e563ead9f72a8461b24876bee2d0c2e8bd2ee8 # v2.21.5
uses: github/codeql-action/autobuild@4dd16135b69a43b6c8efb853346f8437d92d3c93 # v3.26.6

- name: Perform CodeQL Analysis
uses: github/codeql-action/analyze@00e563ead9f72a8461b24876bee2d0c2e8bd2ee8 # v2.21.5
uses: github/codeql-action/analyze@4dd16135b69a43b6c8efb853346f8437d92d3c93 # v3.26.6
8 changes: 4 additions & 4 deletions .github/workflows/create-release.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -12,18 +12,18 @@ jobs:
runs-on: ubuntu-20.04
steps:
- name: Harden Runner
uses: step-security/harden-runner@128a63446a954579617e875aaab7d2978154e969 # v2.4.0
uses: step-security/harden-runner@5c7944e73c4c2a096b17a9cb74d65b6c2bbafbde # v2.9.1
with:
egress-policy: audit

- name: Checkout
uses: actions/checkout@3df4ab11eba7bda6032a0b82a6bb43b11571feac # v4.0.0
uses: actions/checkout@692973e3d937129bcbf40652eb9f2f61becf3332 # v4.0.0
with:
fetch-depth: 0
- name: Goreleaser
uses: goreleaser/goreleaser-action@336e29918d653399e599bfca99fadc1d7ffbc9f7 # v4.3.0
with:
version: latest
args: release --rm-dist --timeout 60m --debug
version: "~> v2"
args: release --clean --fail-fast --timeout 60m --verbose
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
6 changes: 3 additions & 3 deletions .github/workflows/dependency-review.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -17,11 +17,11 @@ jobs:
runs-on: ubuntu-latest
steps:
- name: Harden Runner
uses: step-security/harden-runner@128a63446a954579617e875aaab7d2978154e969 # v2.4.0
uses: step-security/harden-runner@5c7944e73c4c2a096b17a9cb74d65b6c2bbafbde # v2.9.1
with:
egress-policy: audit

- name: 'Checkout Repository'
uses: actions/checkout@3df4ab11eba7bda6032a0b82a6bb43b11571feac # v4.0.0
uses: actions/checkout@692973e3d937129bcbf40652eb9f2f61becf3332 # v4.0.0
- name: 'Dependency Review'
uses: actions/dependency-review-action@1360a344ccb0ab6e9475edef90ad2f46bf8003b1 # v3.0.6
uses: actions/dependency-review-action@5a2ce3f5b92ee19cbb1541a4984c76d921601d7c # v4.3.4
8 changes: 4 additions & 4 deletions .github/workflows/e2e.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -29,14 +29,14 @@ jobs:
timeout-minutes: 20
strategy:
matrix:
KUBERNETES_VERSION: ["v1.24.12", "v1.25.8", "v1.26.3", "v1.27.1"]
KUBERNETES_VERSION: ["v1.28.9", "v1.29.4", "v1.30.2"]
steps:
- name: Harden Runner
uses: step-security/harden-runner@128a63446a954579617e875aaab7d2978154e969 # v2.4.0
uses: step-security/harden-runner@5c7944e73c4c2a096b17a9cb74d65b6c2bbafbde # v2.9.1
with:
egress-policy: audit
- name: Checkout
uses: actions/checkout@3df4ab11eba7bda6032a0b82a6bb43b11571feac # v4.0.0
uses: actions/checkout@692973e3d937129bcbf40652eb9f2f61becf3332 # v4.0.0
with:
submodules: true
fetch-depth: 0
Expand All @@ -47,7 +47,7 @@ jobs:
- name: Setup Kind
uses: engineerd/setup-kind@aa272fe2a7309878ffc2a81c56cfe3ef108ae7d0 # v0.5.0
with:
version: "v0.18.0"
version: "v0.23.0"
image: "kindest/node:${{ matrix.KUBERNETES_VERSION }}"
- name: Test
run: |
Expand Down
4 changes: 2 additions & 2 deletions .github/workflows/markdown-link-check.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -22,10 +22,10 @@ jobs:
runs-on: ubuntu-latest
steps:
- name: Harden Runner
uses: step-security/harden-runner@128a63446a954579617e875aaab7d2978154e969 # v2.4.0
uses: step-security/harden-runner@5c7944e73c4c2a096b17a9cb74d65b6c2bbafbde # v2.9.1
with:
egress-policy: audit
- uses: actions/checkout@3df4ab11eba7bda6032a0b82a6bb43b11571feac # v4.0.0
- uses: actions/checkout@692973e3d937129bcbf40652eb9f2f61becf3332 # v4.0.0
- uses: gaurav-nelson/github-action-markdown-link-check@d53a906aa6b22b8979d33bc86170567e619495ec # v1.0.15
with:
# this will only show errors in the output
Expand Down
30 changes: 30 additions & 0 deletions .github/workflows/scan-vulns.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,30 @@
name: scan_vulns

on:
push:
paths-ignore:
- "docs/**"
- "**.md"
pull_request:
paths-ignore:
- "docs/**"
- "**.md"

permissions: read-all

jobs:
govulncheck:
name: "Run govulncheck"
runs-on: ubuntu-22.04
timeout-minutes: 15
steps:
- name: Harden Runner
uses: step-security/harden-runner@5c7944e73c4c2a096b17a9cb74d65b6c2bbafbde # v2.9.1
with:
egress-policy: audit

- uses: actions/setup-go@0a12ed9d6a96ab950c8f026ed9f722fe0da7ef32 # v5.0.2
with:
go-version: "1.21"
check-latest: true
- uses: golang/govulncheck-action@dd0578b371c987f96d1185abb54344b44352bd58 # v1.0.3
10 changes: 5 additions & 5 deletions .github/workflows/scorecards.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -31,17 +31,17 @@ jobs:

steps:
- name: Harden Runner
uses: step-security/harden-runner@128a63446a954579617e875aaab7d2978154e969 # v2.4.0
uses: step-security/harden-runner@5c7944e73c4c2a096b17a9cb74d65b6c2bbafbde # v2.9.1
with:
egress-policy: audit

- name: "Checkout code"
uses: actions/checkout@3df4ab11eba7bda6032a0b82a6bb43b11571feac # v4.0.0
uses: actions/checkout@692973e3d937129bcbf40652eb9f2f61becf3332 # v4.0.0
with:
persist-credentials: false

- name: "Run analysis"
uses: ossf/scorecard-action@08b4669551908b1024bb425080c797723083c031 # v2.2.0
uses: ossf/scorecard-action@62b2cac7ed8198b15735ed49ab1e5cf35480ba46 # v2.4.0
with:
results_file: results.sarif
results_format: sarif
Expand All @@ -63,14 +63,14 @@ jobs:
# Upload the results as artifacts (optional). Commenting out will disable uploads of run results in SARIF
# format to the repository Actions tab.
- name: "Upload artifact"
uses: actions/upload-artifact@0b7f8abb1508181956e8e162db84b466c27e18ce # v3.1.2
uses: actions/upload-artifact@50769540e7f4bd5e21e526ee35c689e35e0d6874 # v4.4.0
with:
name: SARIF file
path: results.sarif
retention-days: 5

# Upload the results to GitHub's code scanning dashboard.
- name: "Upload to code-scanning"
uses: github/codeql-action/upload-sarif@00e563ead9f72a8461b24876bee2d0c2e8bd2ee8 # v2.21.5
uses: github/codeql-action/upload-sarif@4dd16135b69a43b6c8efb853346f8437d92d3c93 # v3.26.6
with:
sarif_file: results.sarif
7 changes: 4 additions & 3 deletions .goreleaser.yml
Original file line number Diff line number Diff line change
@@ -1,14 +1,15 @@
# refer to https://goreleaser.com for more options
build:
skip: true
version: 2
builds:
- skip: true
release:
prerelease: auto
header: |
## {{.Tag}} - {{ time "2006-01-02" }}
extra_files:
- glob: deploy/*.yaml
changelog:
skip: false
disable: false
groups:
- title: Bug Fixes 🐞
regexp: ^.*fix[(\\w)]*:+.*$
Expand Down
2 changes: 1 addition & 1 deletion .local/Dockerfile
Original file line number Diff line number Diff line change
@@ -1,4 +1,4 @@
FROM golang:1.21-alpine@sha256:eeaab088668869c65a2ee0c2c4df7f8c9920140ede7fba3b777cf5b7e9fdbb69
FROM golang:1.21-alpine@sha256:2523a6f68a0f515fe251aad40b18545155135ca6a5b2e61da8254df9153e3648

ENV CGO_ENABLED=0
ENV GOROOT=/usr/local/go
Expand Down
56 changes: 30 additions & 26 deletions Makefile
Original file line number Diff line number Diff line change
Expand Up @@ -29,12 +29,12 @@ E2E_PROVIDER_IMAGE_NAME ?= e2e-provider

# Release version is the current supported release for the driver
# Update this version when the helm chart is being updated for release
RELEASE_VERSION := v1.3.4
IMAGE_VERSION ?= v1.3.4
RELEASE_VERSION := v1.4.6
IMAGE_VERSION ?= v1.4.6

# Use a custom version for E2E tests if we are testing in CI
ifdef CI
override IMAGE_VERSION := v1.3.0-e2e-$(BUILD_COMMIT)
override IMAGE_VERSION := v1.5.0-e2e-$(BUILD_COMMIT)
endif

IMAGE_TAG=$(REGISTRY)/$(IMAGE_NAME):$(IMAGE_VERSION)
Expand All @@ -61,12 +61,12 @@ export GOPATH GOBIN GO111MODULE DOCKER_CLI_EXPERIMENTAL

# Generate all combination of all OS, ARCH, and OSVERSIONS for iteration
ALL_OS = linux windows
ALL_ARCH.linux = amd64 arm64
ALL_OS_ARCH.linux = $(foreach arch, ${ALL_ARCH.linux}, linux-$(arch))
ALL_ARCH.windows = amd64
ALL_OSVERSIONS.windows := 1809 ltsc2022
ALL_OS_ARCH.windows = $(foreach arch, $(ALL_ARCH.windows), $(foreach osversion, ${ALL_OSVERSIONS.windows}, windows-${osversion}-${arch}))
ALL_OS_ARCH = $(foreach os, $(ALL_OS), ${ALL_OS_ARCH.${os}})
ALL_ARCH_linux ?= amd64 arm64
ALL_OS_ARCH_linux = $(foreach arch, ${ALL_ARCH_linux}, linux-$(arch))
ALL_ARCH_windows = amd64
ALL_OSVERSIONS_windows := 1809 ltsc2022
ALL_OS_ARCH_windows = $(foreach arch, $(ALL_ARCH_windows), $(foreach osversion, ${ALL_OSVERSIONS_windows}, windows-${osversion}-${arch}))
ALL_OS_ARCH = $(foreach os, $(ALL_OS), ${ALL_OS_ARCH_${os}})

# The current context of image building
# The architecture of the image
Expand Down Expand Up @@ -99,9 +99,9 @@ EKSCTL := eksctl
YQ := yq

# Test variables
KIND_VERSION ?= 0.18.0
KUBERNETES_VERSION ?= 1.24.0
KUBECTL_VERSION ?= 1.25.3
KIND_VERSION ?= 0.23.0
KUBERNETES_VERSION ?= 1.30.2
KUBECTL_VERSION ?= 1.30.2
BATS_VERSION ?= 1.4.1
TRIVY_VERSION ?= 0.39.1
PROTOC_VERSION ?= 3.20.1
Expand Down Expand Up @@ -328,24 +328,24 @@ docker-buildx-builder:

.PHONY: container-all
container-all: docker-buildx-builder
for arch in $(ALL_ARCH.linux); do \
for arch in $(ALL_ARCH_linux); do \
ARCH=$${arch} $(MAKE) container-linux; \
ARCH=$${arch} $(MAKE) crd-container-linux; \
done
for osversion in $(ALL_OSVERSIONS.windows); do \
for osversion in $(ALL_OSVERSIONS_windows); do \
OSVERSION=$${osversion} $(MAKE) container-windows; \
done

.PHONY: push-manifest
push-manifest:
docker manifest create --amend $(IMAGE_TAG) $(foreach osarch, $(ALL_OS_ARCH), $(IMAGE_TAG)-${osarch})
docker manifest create --amend $(CRD_IMAGE_TAG) $(foreach osarch, $(ALL_OS_ARCH.linux), $(CRD_IMAGE_TAG)-${osarch})
docker manifest create --amend $(CRD_IMAGE_TAG) $(foreach osarch, $(ALL_OS_ARCH_linux), $(CRD_IMAGE_TAG)-${osarch})
# add "os.version" field to windows images (based on https://github.com/kubernetes/kubernetes/blob/master/build/pause/Makefile)
set -x; \
registry_prefix=$(shell (echo ${REGISTRY} | grep -Eq ".*[\/\.].*") && echo "" || echo "docker.io/"); \
manifest_image_folder=`echo "$${registry_prefix}${IMAGE_TAG}" | sed "s|/|_|g" | sed "s/:/-/"`; \
for arch in $(ALL_ARCH.windows); do \
for osversion in $(ALL_OSVERSIONS.windows); do \
for arch in $(ALL_ARCH_windows); do \
for osversion in $(ALL_OSVERSIONS_windows); do \
BASEIMAGE=mcr.microsoft.com/windows/nanoserver:$${osversion}; \
full_version=`docker manifest inspect $${BASEIMAGE} | jq -r '.manifests[0].platform["os.version"]'`; \
sed -i -r "s/(\"os\"\:\"windows\")/\0,\"os.version\":\"$${full_version}\"/" "${HOME}/.docker/manifests/$${manifest_image_folder}/$${manifest_image_folder}-windows-$${osversion}-$${arch}"; \
Expand All @@ -359,11 +359,12 @@ push-manifest:
## --------------------------------------
## E2E Testing
## --------------------------------------
.PHONY: e2e-install-prerequisites
e2e-install-prerequisites: $(HELM) $(BATS) $(KIND) $(KUBECTL) $(ENVSUBST) $(YQ)

.PHONY: e2e-bootstrap
e2e-bootstrap: $(HELM) $(BATS) $(KIND) $(KUBECTL) $(ENVSUBST) $(YQ) #setup all required binaries and kind cluster for testing
ifndef TEST_WINDOWS
e2e-bootstrap: e2e-install-prerequisites #setup all required binaries and kind cluster for testing
$(MAKE) setup-kind
endif
docker pull $(IMAGE_TAG) || $(MAKE) e2e-container

.PHONY: setup-kind
Expand All @@ -378,12 +379,8 @@ setup-eks-cluster: $(HELM) $(EKSCTL) $(BATS) $(ENVSUBST) $(YQ)

.PHONY: e2e-container
e2e-container:
ifdef TEST_WINDOWS
$(MAKE) container-all push-manifest
else
$(MAKE) container
kind load docker-image --name kind $(IMAGE_TAG) $(CRD_IMAGE_TAG)
endif

.PHONY: e2e-mock-provider-container
e2e-mock-provider-container:
Expand Down Expand Up @@ -437,7 +434,9 @@ e2e-helm-deploy:
--set enableSecretRotation=true \
--set rotationPollInterval=30s \
--set tokenRequests[0].audience="aud1" \
--set tokenRequests[1].audience="aud2"
--set tokenRequests[1].audience="aud2" \
--set tokenRequests[2].audience="conjur" \
--set tokenRequests[3].audience="api://AzureADTokenExchange"

.PHONY: e2e-helm-upgrade
e2e-helm-upgrade:
Expand All @@ -460,7 +459,8 @@ e2e-helm-deploy-release:
--set linux.enabled=true \
--set syncSecret.enabled=true \
--set enableSecretRotation=true \
--set rotationPollInterval=30s
--set rotationPollInterval=30s \
--set tokenRequests[0].audience="api://AzureADTokenExchange"

.PHONY: e2e-kind-cleanup
e2e-kind-cleanup:
Expand Down Expand Up @@ -494,6 +494,10 @@ e2e-gcp:
e2e-aws:
bats -t test/bats/aws.bats

.PHONY: e2e-conjur
e2e-conjur:
bats -t test/bats/conjur.bats

## --------------------------------------
## Generate
## --------------------------------------
Expand Down
2 changes: 1 addition & 1 deletion README.md
Original file line number Diff line number Diff line change
Expand Up @@ -15,7 +15,7 @@ The Secrets Store CSI Driver `secrets-store.csi.k8s.io` allows Kubernetes to mou
| Test | Status |
| ---------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| periodic/image-scan | [![sig-auth-secrets-store-csi-driver-periodic/secrets-store-csi-driver-image-scan](https://testgrid.k8s.io/q/summary/sig-auth-secrets-store-csi-driver-periodic/secrets-store-csi-driver-image-scan/tests_status?style=svg)](https://testgrid.k8s.io/sig-auth-secrets-store-csi-driver-periodic#secrets-store-csi-driver-image-scan) |
| periodic/azure-upgrade | [![sig-auth-secrets-store-csi-driver-periodic/secrets-store-csi-driver-upgrade-test-azure](https://testgrid.k8s.io/q/summary/sig-auth-secrets-store-csi-driver-periodic/secrets-store-csi-driver-upgrade-test-azure/tests_status?style=svg)](https://testgrid.k8s.io/sig-auth-secrets-store-csi-driver-periodic#secrets-store-csi-driver-upgrade-test-azure) |
| periodic/e2e-provider-upgrade | [![sig-auth-secrets-store-csi-driver-periodic/secrets-store-csi-driver-upgrade-test-e2e-provider](https://testgrid.k8s.io/q/summary/sig-auth-secrets-store-csi-driver-periodic/secrets-store-csi-driver-upgrade-test-e2e-provider/tests_status?style=svg)](https://testgrid.k8s.io/sig-auth-secrets-store-csi-driver-periodic#secrets-store-csi-driver-upgrade-test-e2e-provider) |
| postsubmit/aws | [![sig-auth-secrets-store-csi-driver-postsubmit/secrets-store-csi-driver-e2e-aws-postsubmit](https://testgrid.k8s.io/q/summary/sig-auth-secrets-store-csi-driver-postsubmit/secrets-store-csi-driver-e2e-aws-postsubmit/tests_status?style=svg)](https://testgrid.k8s.io/sig-auth-secrets-store-csi-driver-postsubmit#secrets-store-csi-driver-e2e-aws-postsubmit) |
| postsubmit/azure | [![sig-auth-secrets-store-csi-driver-postsubmit/secrets-store-csi-driver-e2e-azure-postsubmit](https://testgrid.k8s.io/q/summary/sig-auth-secrets-store-csi-driver-postsubmit/secrets-store-csi-driver-e2e-azure-postsubmit/tests_status?style=svg)](https://testgrid.k8s.io/sig-auth-secrets-store-csi-driver-postsubmit#secrets-store-csi-driver-e2e-azure-postsubmit) |
| postsubmit/gcp | [![sig-auth-secrets-store-csi-driver-postsubmit/secrets-store-csi-driver-e2e-gcp-postsubmit](https://testgrid.k8s.io/q/summary/sig-auth-secrets-store-csi-driver-postsubmit/secrets-store-csi-driver-e2e-gcp-postsubmit/tests_status?style=svg)](https://testgrid.k8s.io/sig-auth-secrets-store-csi-driver-postsubmit#secrets-store-csi-driver-e2e-gcp-postsubmit) |
Expand Down
4 changes: 2 additions & 2 deletions charts/secrets-store-csi-driver/Chart.yaml
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
apiVersion: v2
name: secrets-store-csi-driver
version: 1.3.4
appVersion: 1.3.4
version: 1.4.5
appVersion: 1.4.5
kubeVersion: ">=1.16.0-0"
description: A Helm chart to install the SecretsStore CSI Driver inside a Kubernetes cluster.
icon: https://github.com/kubernetes/kubernetes/blob/master/logo/logo.png
Expand Down
Loading
Loading