Releases: project-copacetic/copacetic
Releases · project-copacetic/copacetic
v0.9.0
Notable Changes
- 🐧 Copa now supports patching Azure Linux 3 based images!
Changelog
- ec1921f chore: bump k8s.io/apimachinery from 0.31.1 to 0.31.2 (#817)
- fcf1f10 chore: bump the all group with 7 updates (#816)
- cdee476 feat: azure linux 3 support (#815)
- 6dd5b5e chore: Replaced apt with apt-get (#804)
- ee516e0 chore: bump http-proxy-middleware from 2.0.6 to 2.0.7 in /website (#814)
- e5f901b chore: bump anchore/sbom-action from 0.17.3 to 0.17.4 in the all group (#811)
- 05401b8 chore: bump @mdx-js/react from 3.0.1 to 3.1.0 in /website in the all group (#812)
- 973c6d2 chore: bump the all group with 4 updates (#805)
- aec1c59 chore: bump github.com/aquasecurity/trivy from 0.56.1 to 0.56.2 (#808)
- ce0e1dd chore: bump typescript from 5.6.2 to 5.6.3 in /website in the all group (#807)
- 2315670 docs: add documentation for dependabot and copa (#801)
- d8de178 docs: Add doc for scanners that report individual layers (#803)
- 68e61c0 chore: bump github.com/quay/claircore from 1.5.31 to 1.5.32 (#798)
- c4d6e82 chore: bump the all group across 1 directory with 8 updates (#800)
- b15487e chore: bump google.golang.org/grpc from 1.67.0 to 1.67.1 (#797)
- d475e6b chore: bump github.com/aquasecurity/trivy from 0.55.2 to 0.56.1 (#796)
- 41249bb chore: bump the all group across 1 directory with 4 updates (#792)
- 1b18be6 chore: bump github.com/aquasecurity/trivy from 0.55.1 to 0.55.2 (#785)
- 40a6847 chore: bump github.com/cpuguy83/dockercfg from 0.3.1 to 0.3.2 (#789)
- cb59080 chore: bump google.golang.org/grpc from 1.66.2 to 1.67.0 (#784)
- ad0f004 chore: bump github.com/quay/claircore from 1.5.30 to 1.5.31 (#783)
- b496255 chore: bump github.com/docker/cli from 27.2.2-0.20240913085431-48a2cdff970d+incompatible to 27.3.1+incompatible (#782)
- 616bccf chore: bump github.com/open-policy-agent/opa from 0.67.1 to 0.68.0 (#781)
- b561d78 chore: bump k8s.io/apimachinery from 0.31.0 to 0.31.1 (#779)
- 2688695 chore: bump google.golang.org/grpc from 1.66.0 to 1.66.2 (#778)
- fa4cdcc chore: bump github.com/aquasecurity/trivy from 0.55.0 to 0.55.1 (#777)
- c10027d chore: bump github.com/docker/buildx from 0.16.2 to 0.17.1 (#776)
- 68ed18a chore: bump typescript from 5.5.4 to 5.6.2 in /website in the all group (#775)
- aafd39a chore: bump the all group with 3 updates (#774)
- d3ec17e fix: copa extension release img tag (#772)
- deba107 chore: bump express from 4.19.2 to 4.21.0 in /website (#771)
- 5cc37ee chore: bump peter-evans/create-pull-request from 6.1.0 to 7.0.1 in the all group (#768)
- 4387e24 chore: Generate v0.8.x docs (#770)
v0.8.0
Notable Changes
- 🪡 Copa now creates a single patch layer on subsequent patches of an already patched image instead of appending a patch layer for each patch! See FAQ for more information.
- 🔮 Oracle Linux is now supported for updating without vulnerability scanner reports. This will update all dependencies, including vulnerable packages. See documentation for more information.
Shoutouts ❤️
- 🎉 Shoutout to @thelinuxfoundation intern @MiahaCybersec for many contributions to Copa!
- 🎊 Shoutout to @microsoft intern @jgrer for contributing Copa Docker Desktop extension!
Changelog
- 06eefb9 chore: bump github.com/docker/cli from 27.2.0+incompatible to 27.2.1+incompatible (#767)
- 88a81ba chore: bump github.com/quay/claircore from 1.5.29 to 1.5.30 (#765)
- a055b43 chore: bump github.com/aquasecurity/trivy from 0.54.1 to 0.55.0 (#766)
- f32017a chore: bump google.golang.org/grpc from 1.65.0 to 1.66.0 (#760)
- 84b1f92 chore: bump github.com/docker/cli from 27.1.2+incompatible to 27.2.0+incompatible (#759)
- 380087f chore: bump prism-react-renderer from 2.3.1 to 2.4.0 in /website in the all group (#758)
- dd52ce1 chore: bump the all group with 2 updates (#757)
- b827cb9 feat: skip install tools cmd (#741)
- 5f61ade chore: bump webpack from 5.91.0 to 5.94.0 in /website (#755)
- 7b26e85 ci: build and push copa-extension image on release (#726)
- e353f70 docs: remove broken FOSSA status link (#742)
- 9e31777 chore: bump micromatch from 4.0.5 to 4.0.8 in /website (#754)
- bc2ca54 chore: bump the all group with 2 updates (#753)
- 77290f4 chore: bump github.com/quay/claircore from 1.5.25 to 1.5.29 (#752)
- 894500c docs: Add additional way to signoff commits (#751)
- 0990908 docs: add tooling image versioning docs (#736)
- a284d8b ci: Unblock trivy dependency updates (#750)
- 10fd0c7 chore: bump github/codeql-action from 3.26.1 to 3.26.3 in the all group across 1 directory (#749)
- e396f6b chore: bump github.com/moby/buildkit from 0.15.1 to 0.15.2 (#746)
- b702238 chore: bump github.com/docker/cli from 27.1.1+incompatible to 27.1.2+incompatible (#748)
- d118daa chore: bump k8s.io/apimachinery from 0.30.3 to 0.31.0 (#747)
- 9e83f83 docs: remove outdated todo comments (#743)
- f0cb34a test: increase code coverage (#704)
- 44cc2ad chore: bump the all group across 1 directory with 4 updates (#740)
- bd7f980 chore: bump the all group across 1 directory with 3 updates (#739)
- 3c38005 chore: bump github.com/docker/docker from 27.1.0+incompatible to 27.1.1+incompatible (#737)
- d441937 chore: bump github.com/google/go-containerregistry from 0.20.1 to 0.20.2 (#733)
- 9401e88 chore: bump golang.org/x/sync from 0.7.0 to 0.8.0 (#730)
- d453ba9 chore: bump the all group with 2 updates (#728)
- c5f3260 chore: bump github.com/docker/docker from 27.0.3+incompatible to 27.1.0+incompatible (#727)
- 839ffa5 feat: discard patch layer (#689)
- 358a7ff feat: add oracle support (#706)
- 0d0f2f3 docs: clarify copa does not support wolfi-based images (#724)
- 473202f fix: microdnf update (#721)
- da90152 chore: bump the all group across 1 directory with 3 updates (#722)
- bbffa29 chore: bump typescript from 5.5.3 to 5.5.4 in /website in the all group (#719)
- f696308 chore: bump github.com/docker/buildx from 0.16.0 to 0.16.2 (#717)
- da8fe8e chore: bump github.com/docker/cli from 27.1.0+incompatible to 27.1.1+incompatible (#716)
- beb8c86 fix: docker repository format checks (#707)
- 6d91446 chore: bump the all group with 6 updates (#711)
- f730aa9 chore: bump github.com/google/go-containerregistry from 0.19.2 to 0.20.1 (#710)
- 75b8bac chore: bump k8s.io/apimachinery from 0.30.2 to 0.30.3 (#709)
- 1cd9abe chore: bump github.com/docker/cli from 27.0.3+incompatible to 27.1.0+incompatible (#708)
- 9da1246 chore: bump github.com/docker/buildx from 0.15.1 to 0.16.0 (#701)
- 3f3a9a2 chore: bump the all group with 5 updates (#700)
- 1ea24b7 test: buildkit with defaults (#682)
- 4953f10 docs: add function to be included when using buildkit.SolveToDocker (#698)
- 1fcc6e0 chore: bump the all group across 1 directory with 6 updates (#696)
- ded40bd chore: bump typescript from 5.5.2 to 5.5.3 in /website in the all group (#695)
- abce88c chore: bump github.com/containerd/containerd from 1.7.18 to 1.7.19 (#694)
- 456bf08 chore: bump google.golang.org/grpc from 1.64.0 to 1.65.0 (#693)
- a8ede19 docs: 0.7.0 release docs (#692)
- 5920993 fix: update NODE_VERSION (#691)
v0.7.0
Notable changes
- 🚀 Support for upgrading all outdated packages without a scanner report. See quick start to get started!
Changelog
- b1df0e9 docs: update all documentation (#688)
- 9d5c9cc ci: remove centos eol img (#686)
- eb7cdcd feat: update all - check for upgradable packages (#644)
- 8987230 ci: add CODECOV_TOKEN field to upload coverage (#641)
- 275dd5b chore: bump typescript from 5.4.5 to 5.5.2 in /website in the all group (#677)
- 8d7125a chore: bump peter-evans/create-pull-request from 6.0.5 to 6.1.0 in the all group (#676)
- 2366c37 feat: allow change to BINS_OUT_DIR in makefile (#678)
- 938c98b feat: Add error validation for update all (#618)
- 962b773 chore: bump github.com/google/go-containerregistry from 0.19.1 to 0.19.2 (#675)
- 2335453 chore: bump github.com/docker/buildx from 0.15.0 to 0.15.1 (#673)
- 73eff67 chore: bump ws from 7.5.9 to 7.5.10 in /website (#668)
- 975aab2 chore: bump github.com/docker/buildx from 0.14.1 to 0.15.0 (#665)
- d18efa7 chore: bump k8s.io/apimachinery from 0.30.1 to 0.30.2 (#664)
- 1b50013 chore: bump github.com/spf13/cobra from 1.8.0 to 1.8.1 (#663)
- 8e30c21 chore: bump the all group with 3 updates (#662)
- 394526a docs: update contributor docs (#633)
- d3f88fe chore: bump braces from 3.0.2 to 3.0.3 in /website (#658)
- 7808b18 chore: bump the all group with 5 updates (#657)
- d7817b8 chore: bump github.com/docker/cli from 26.1.3+incompatible to 26.1.4+incompatible (#656)
- 88bf14b chore: bump github.com/containerd/containerd from 1.7.17 to 1.7.18 (#654)
- f3ecc42 chore: bump github.com/spf13/viper from 1.18.2 to 1.19.0 (#648)
- 99c4fb2 chore: bump the all group in /website with 3 updates (#646)
- dfd844c chore: bump the all group with 2 updates (#645)
- afbf823 docs: added helmper to adopters list (#640)
- 475d3d6 chore: bump github.com/docker/buildx from 0.13.1 to 0.14.1 (#637)
- a194881 ci: updated trivy dependency to v0.51.4 (#635)
- 409f13d chore: bump github.com/containerd/containerd from 1.7.16 to 1.7.17 (#636)
- a0235c4 chore: bump the all group with 4 updates (#638)
- c9a5fb7 feat: add rpm package verification (#632)
- 6d04228 chore: bump google.golang.org/grpc from 1.63.2 to 1.64.0 (#630)
- d22df93 chore: bump the all group with 3 updates (#629)
- b73910e docs: patching with digest (#626)
- 2087808 chore: bump github.com/containerd/containerd from 1.7.13 to 1.7.16 (#623)
- e280d5e fix: added context to error (#620)
- 2ee07aa chore: bump the all group with 5 updates (#622)
- d85fba7 feat: handle distroless for upgrade all packages (#570)
- a8c073e feat: add rocky linux support (#605)
- 64a71e9 fix: flakey custom unix test (#615)
- 569ab03 docs: add buildkit mtls-over-tcp docs (#612)
- e35fa4e chore: bump github.com/docker/cli from 26.1.0+incompatible to 26.1.2+incompatible (#617)
- 55f809a docs: update slack to cncf (#614)
- 3956236 chore: bump the all group in /website with 3 updates (#607)
- 0eabd04 chore: bump the all group with 5 updates (#606)
- 04473ab chore: bump the all group across 1 directory with 3 updates (#590)
- 59110b2 chore: bump the all group in /website with 2 updates (#588)
- fadd7c6 chore: bump github.com/moby/buildkit from 0.13.1 to 0.13.2 (#586)
- a27c3f6 docs: add source policy docs for debian 12 (#583)
- eee6147 ci: mark golangci-lint as blocking (#582)
- c6890cc fix: added ignore cache to apk update (#581)
- d648155 ci: add prefix to ci runs (#580)
- 58c3faf docs: add mention of support for containers without package managers to versioned_docs (#579)
- dca7fdc chore: bump the all group across 1 directory with 9 updates (#576)
- 7f23656 chore: bump github.com/docker/cli from 26.0.0-rc1+incompatible to 26.1.0+incompatible (#575)
- 937ac47 chore: bump google.golang.org/grpc from 1.62.1 to 1.63.2 (#561)
- b25af66 chore: bump github.com/distribution/reference from 0.5.0 to 0.6.0 (#549)
- 61f7e9a chore: bump the all group in /website with 10 updates (#577)
- f132c22 chore: update node version to 18.x (#571)
- b06b977 chore: bump golang.org/x/net from 0.21.0 to 0.23.0 (#566)
- 13f0238 docs: add mention of support for containers without package managers (#572)
- 250ab33 chore: remove ignored cves (#560)
- c213334 chore: bump golang.org/x/sync from 0.6.0 to 0.7.0 (#558)
- ea84eaf docs: add copa patch command to quick start guide (#554)
- ebd8811 feat: Add option to update all packages without scanner input. (#548)
- d1075c7 chore: update codeowners (#553)
- cd8ea80 chore: bump the all group with 3 updates (#550)
- 7ff64bc chore: bump github.com/google/go-containerregistry from 0.19.0 to 0.19.1 (#542)
- d33de48 chore: bump express from 4.18.2 to 4.19.2 in /website (#545)
- d580749 chore: bump k8s.io/apimachinery from 0.29.2 to 0.29.3 (#541)
- 4606bea chore: bump webpack-dev-middleware from 5.3.3 to 5.3.4 in /website (#537)
- 3c67465 chore: bump the all group with 3 updates (#539)
- 5d23d64 chore: bump github.com/docker/docker from 26.0.0-rc1+incompatible to 26.0.0-rc3+incompatible (#536)
- 86363e0 ci: bump to go 1.22 (#535)
- 0cbc0ab chore: bump google.golang.org/protobuf from 1.32.0 to 1.33.0 (#529)
- 70c6858 chore: bump google.golang.org/grpc from 1.62.0 to 1.62.1 (#526)
- 5f7819a chore: bump the all group with 6 updates (#534)
- fbf53a3 chore: bump follow-redirects from 1.15.4 to 1.15.6 in /website (#533)
- 6210452 chore: update buildkit to 1.13.1 (#532)
- b20d078 feat: ignore unpatchable packages and add GetUniqueLatestUpdates test (#531)
- ac50842 test: replace mariner 1.0 test images (#530)
- 19fbcad chore: bump the all group with 6 updates (#520)
- e887eac chore: bump github.com/stretchr/testify from 1.8.4 to 1.9.0 (#519)
v0.6.2
This is a routine maintenance and security patch release.
Changelog
- a4c1e1d docs: add adopters file (#514)
- 9fd1c8d chore: bump google.golang.org/grpc from 1.61.1 to 1.62.0 (#516)
- ebed3c6 chore: bump github.com/opencontainers/image-spec from 1.1.0-rc6 to 1.1.0 (#517)
- 70e5465 chore: bump the all group with 4 updates (#515)
- e702650 chore: bump k8s.io/apimachinery from 0.29.1 to 0.29.2 (#512)
- 2b57c05 docs: include Copa logo in README (#507)
- 56adade chore: bump the all group with 7 updates (#510)
- 5fde875 chore: bump github.com/containerd/console from 1.0.3 to 1.0.4 (#500)
- b1760b6 chore: bump google.golang.org/grpc from 1.61.0 to 1.61.1 (#511)
v0.6.1
This is a routine maintenance and security patch release.
Changelog
- 0b98f33 fix: Copa hangs when InstallUpdates fails (#508)
- 5274edf ci: ignore CVE-2024-0567 and CVE-2023-5981 to fix ci (#506)
- 2f621d1 chore: bump github.com/docker/cli from 24.0.8+incompatible to 24.0.9+incompatible (#494)
- 59bb1b3 docs: update missed tagging guidelines page (#498)
- 8a9264f docs: add best practices for patching and tagging (#497)
- aa823e1 test: add plugin e2e tests (#391)
- cd1dbee chore: bump github.com/google/go-containerregistry from 0.18.0 to 0.19.0 (#495)
- 629d0ee chore: bump the all group with 5 updates (#493)
- 2602d59 chore: bump google.golang.org/grpc from 1.60.1 to 1.61.0 (#486)
- 1017994 fix: validate patched image tag (#492)
- bbd8563 chore: bump github.com/moby/buildkit from 0.12.4 to 0.12.5 (#491)
- 23dfd85 chore: bump github.com/google/go-containerregistry from 0.17.0 to 0.18.0 (#477)
- f586ceb chore: bump github.com/docker/cli from 24.0.7+incompatible to 24.0.8+incompatible (#487)
- 9a9fda4 chore: bump the all group with 4 updates (#485)
- 8d6e4aa docs: add website categories (#483)
- fc6b96b docs: revamp quick start (#482)
- 4708cce chore: bump github.com/opencontainers/image-spec from 1.1.0-rc5 to 1.1.0-rc.6 (#479)
- c6fa385 chore: bump the all group with 5 updates (#480)
- 3cb4b2d chore: bump k8s.io/apimachinery from 0.29.0 to 0.29.1 (#478)
- 45e40f5 chore: use trivy code (#475)
- 86dded1 chore: bump the all group with 5 updates (#470)
- a15c13e fix: do not upgrade held packages (#457)
- 29397a0 chore: bump follow-redirects from 1.15.2 to 1.15.4 in /website (#466)
- 5ddc6bc chore: bump github.com/spf13/viper from 1.18.1 to 1.18.2 (#464)
- 789384e chore: bump golang.org/x/sync from 0.5.0 to 0.6.0 (#463)
- b91c45d chore: bump the all group with 2 updates (#461)
- 163d92c docs: fix docs issues (#460)
- 3a973c5 ci: docs pr auto signoff (#459)
- 6433c4d chore: Generate v0.6.x docs (#458)
v0.6.0
Notable changes
- 📦 Support for patching local images using containerd image store. See quick start to get started!
Changelog
- 251e637 chore: bump k8s.io/apimachinery from 0.28.4 to 0.29.0 (#448)
- d484f34 chore: bump github.com/containerd/containerd from 1.7.8 to 1.7.11 (#451)
- 955e89c chore: bump google.golang.org/grpc from 1.59.0 to 1.60.1 (#455)
- 0364b12 chore: bump the all group with 6 updates (#454)
- 162b15a chore: bump golang.org/x/crypto from 0.16.0 to 0.17.0 (#450)
- d49fe1d chore: bump github.com/spf13/viper from 1.17.0 to 1.18.1 (#442)
- b1f6e30 chore: bump github.com/moby/buildkit from 0.12.3 to 0.12.4 (#432)
- 27865b5 chore: bump k8s.io/apimachinery from 0.28.1 to 0.28.4 (#431)
- d98d03f ci: fix go version in govulncheck (#444)
- decda59 chore: bump github.com/google/go-containerregistry from 0.16.1 to 0.17.0 (#433)
- e168e25 chore: bump the all group with 1 update (#435)
- 69fe90a chore: bump golang.org/x/sync from 0.4.0 to 0.5.0 (#411)
- b9a418b chore: bump the all group with 4 updates (#428)
- 45b7b87 chore: bump github.com/cpuguy83/go-docker from 0.2.1 to 0.3.0 (#417)
- e5288e8 feat: Prefer local image (#381)
- 24e86a2 chore: bump github.com/spf13/cobra from 1.7.0 to 1.8.0 (#410)
- 2b9f177 docs: update MIT license headers to Apache 2 (#403)
- 5eea421 chore: bump github.com/docker/docker from 24.0.5+incompatible to 24.0.7+incompatible (#402)
- 4d74f58 chore: bump the all group with 3 updates (#401)
- bf9331f chore: bump github.com/containerd/containerd from 1.7.7 to 1.7.8 (#400)
- d591b69 chore: bump github.com/docker/cli from 24.0.6+incompatible to 24.0.7+incompatible (#398)
- 7587c54 fix: release copa-action push (#393)
- 6ad6a75 chore: Generate v0.5.x docs (#392)
New Contributors
- @pmengelbert made their first contribution in #381
Full Changelog: v0.5.0...v0.6.0
v0.5.1
v0.5.0
Notable changes
- 🔧 Adds support for scanner integrations via plugins. Please see scanner plugin template for a quick start template.
- 📤 Adds support for VEX output.
- 📝 Support for buildkit source policies for replacing tooling image.
- 🔐 Support for remote buildkit mTLS-over-TCP.
- 🗜️ Support for Azure Linux RPM zstd compression switch.
Changelog
- 67c7e29 chore: bump github.com/moby/buildkit from 0.12.2 to 0.12.3 (#386)
- b592060 chore: bump google.golang.org/grpc from 1.58.3 to 1.59.0 (#385)
- d67c582 chore: bump the all group with 2 updates (#384)
- f8af3e9 docs: update issue template with contribution details (#379)
- 89eddc6 ci: add govulncheck (#382)
- dd45fe1 docs: add plugin docs (#360)
- 013c118 chore: bump the all group with 1 update (#371)
- 5bca058 chore: bump @babel/traverse from 7.20.12 to 7.23.2 in /website (#378)
- c42fa8f chore: bump google.golang.org/grpc from 1.58.2 to 1.58.3 (#374)
- f14392d chore: bump github.com/containerd/containerd from 1.7.6 to 1.7.7 (#372)
- 4eacf06 feat: add modular scanners (#261)
- d514256 chore: bump golang.org/x/net from 0.15.0 to 0.17.0 (#367)
- f893559 fix: move openvex packages as subcomponents (#366)
- 1a7c070 fix: migrate to yumdownloader (#377)
- ff4fb01 ci: ignore centos CVE-2020-22218 and CVE-2023-3341 (#369)
- ed77375 fix: ignore cache for "apt update" (#364)
- 949d6c2 docs: update versioned docs faq (#363)
- b840d42 chore: bump the all group with 2 updates (#362)
- 912b3a4 chore: bump github.com/spf13/viper from 1.16.0 to 1.17.0 (#356)
- e87aec9 docs: update faq with not patch (#347)
- 462fb5a chore: remove qualys parser (#350)
- 9aa25ec ci: add gha and npm groups (#359)
- 0237956 chore: bump github/codeql-action from 2.21.9 to 2.22.0 (#353)
- 7be1028 chore: bump golang.org/x/sync from 0.3.0 to 0.4.0 (#348)
- 7e2dca5 chore: bump github.com/distribution/distribution from 2.8.2+incompatible to 2.8.3+incompatible (#345)
- 4dd928e feat: add source policy (#341)
- d3082c5 chore: bump postcss from 8.4.21 to 8.4.31 in /website (#344)
- 76efad1 chore: bump step-security/harden-runner from 2.5.1 to 2.6.0 (#343)
- f587cbb chore: bump github.com/distribution/distribution from 2.8.2+incompatible to 2.8.3+incompatible (#342)
- 35b54ca chore: bump prism-react-renderer from 2.0.6 to 2.1.0 in /website (#340)
- 3ba01ef fix: add release and github action pages to sidebar (#338)
- dff7b28 docs: document copa github action (#334)
- fbad7d1 docs: add release doc (#333)
- d2b0447 chore: bump github/codeql-action from 2.21.8 to 2.21.9 (#331)
- 58c4020 docs: add fossa badge (#328)
- 28191f1 docs: Fix typo in quick-start.md (#327)
- e6a6b76 docs(website): add logo (#319)
- ed7d690 chore: bump @docusaurus/module-type-aliases from 2.4.1 to 2.4.3 in /website (#325)
- bf2f197 chore: bump @docusaurus/core from 2.4.1 to 2.4.3 in /website (#324)
- 0eea4ea chore: bump actions/checkout from 4.0.0 to 4.1.0 (#326)
- b124fa8 chore: bump @docusaurus/preset-classic from 2.4.1 to 2.4.3 in /website (#323)
- e8b5e13 chore: bump github.com/antchfx/xmlquery from 1.3.17 to 1.3.18 (#322)
- eba1ba5 fix: add package permissions (#317)
- 3886cb8 docs: cncf onboarding items (#312)
- 141363d chore: bump google.golang.org/grpc from 1.58.1 to 1.58.2 (#313)
- 22f060a docs(website): update favicon (#311)
- 6396212 chore: bump github/codeql-action from 2.21.7 to 2.21.8 (#310)
- a4c4abe feat: mTLS-over-TCP buildkit (#284)
- 6a8afc2 chore: bump @tsconfig/docusaurus from 2.0.0 to 2.0.1 in /website (#309)
- b376b87 chore: bump github.com/aquasecurity/trivy from 0.45.0 to 0.45.1 (#308)
- deeae56 docs: switch to apache license for CNCF compliance (#304)
- 751ebf9 chore: bump github/codeql-action from 2.21.6 to 2.21.7 (#307)
- 13e3b39 chore: bump github.com/opencontainers/image-spec from 1.1.0-rc4 to 1.1.0-rc5 (#306)
- 10fb6ef chore: bump google.golang.org/grpc from 1.58.0 to 1.58.1 (#305)
- 62c9adf chore: bump github/codeql-action from 2.21.5 to 2.21.6 (#303)
- 2df832f chore: bump github.com/containerd/containerd from 1.7.3 to 1.7.6 (#302)
- da9de7a chore: bump goreleaser/goreleaser-action from 4.6.0 to 5.0.0 (#301)
- 0040674 chore: bump docker/setup-qemu-action from 2.2.0 to 3.0.0 (#300)
- 8c24605 chore: bump docker/setup-buildx-action from 2.10.0 to 3.0.0 (#299)
- 466ac55 chore: bump actions/cache from 3.3.1 to 3.3.2 (#297)
- 075d4eb chore: bump actions/dependency-review-action from 3.0.8 to 3.1.0 (#296)
- 72a2b81 chore: bump github.com/aquasecurity/trivy from 0.44.1 to 0.45.0 (#280)
- 9632d7d chore: bump github.com/docker/cli from 24.0.5+incompatible to 24.0.6+incompatible (#286)
- 9703f57 chore: bump google.golang.org/grpc from 1.57.0 to 1.58.0 (#290)
- a0605d3 chore: bump github.com/cyphar/filepath-securejoin from 0.2.3 to 0.2.4 (#292)
- 45604af chore: bump goreleaser/goreleaser-action from 4.4.0 to 4.6.0 (#287)
- 1b26c46 chore: bump actions/checkout from 3.6.0 to 4.0.0 (#282)
- 5a9cdf3 chore: bump actions/upload-artifact from 3.1.2 to 3.1.3 (#291)
- edcf49e docs: add slack and meeting info (#289)
- d89e401 fix: handle mariner zstd compression (#295)
- 013f758 docs: add faq section to docs (#281)
- 88b36ca docs: use dockerhub instead of mcr (#267)
- 4182a4c chore: bump github/codeql-action from 2.21.4 to 2.21.5 (#279)
- dee4ad6 chore: bump github.com/moby/buildkit from 0.12.1 to 0.12.2 (#271)
- aa80538 chore: bump actions/checkout from 3.5.3 to 3.6.0 (#274)
- a72c494 feat: vex output (#272)
- 67e8932 chore: bump docker/setup-buildx-action from 2.9.1 to 2.10.0 (#277)
- 4b79dfe chore: bump typescript from 5.1.6 to 5.2.2 in /website (#278)
- dbdcbfa docs: generate v0.4.x docs and fix doc gen (#265)
New Contributors
- @RealHarshThakur made their first contribution in #284
- @tomdev made their first contribution in #327
Full Changelog: v0.4.0...v0.5.0
v0.4.1
v0.4.0
Notable changes
- 🐳 Copa now allows to use buildkit from Docker.
- 🚫 Added
--ignore-errors
flag to produce an image regardless of any errors. Users can also filter vulnerabilities and packages in scanners to skip any package updates. - Introducting Copa Github Action to easily integrate Copa into GitHub Actions.
Changelog
- e9cba83 ci: fix release action (#264)
- ac5c027 feat: add ignore errors flags (#247)
- fa9ead6 ci: validate docs (#263)
- ad8085c docs: update demo with buildkit changes (#259)
- fc01b26 chore: bump actions/setup-node from 3.8.0 to 3.8.1 (#260)
- ae0b05b docs: filtering vulnerabilities with trivy (#251)
- cbf4117 docs: Update docs for new connection methods (#258)
- 69206e5 chore: bump google.golang.org/grpc from 1.55.0 to 1.57.0 (#256)
- d6022a8 chore: bump actions/dependency-review-action from 3.0.7 to 3.0.8 (#252)
- 621c63c chore: bump golangci/golangci-lint-action from 3.6.0 to 3.7.0 (#253)
- 9078a6b chore: bump github/codeql-action from 2.21.3 to 2.21.4 (#254)
- 120bfa8 chore: bump github.com/cpuguy83/go-docker from 0.1.2 to 0.2.1 (#255)
- 69603ae chore: bump actions/setup-node from 3.7.0 to 3.8.0 (#248)
- 3dec6b7 feat: Allow copa to use buildkit from dockerd (#233)
- 6e08cb6 chore: bump to go 1.21 (#246)
- 7b6ddb1 chore: bump docker/setup-buildx-action from 2.7.0 to 2.9.1 (#244)
- 45b0be1 chore: bump github.com/aquasecurity/trivy from 0.44.0 to 0.44.1 (#240)
- f2f6d22 chore: bump actions/dependency-review-action from 3.0.6 to 3.0.7 (#241)
- a0199b8 chore: bump step-security/harden-runner from 2.5.0 to 2.5.1 (#242)
- 47e2e79 chore: bump github/codeql-action from 2.21.2 to 2.21.3 (#238)
- dacc74e chore: bump goreleaser/goreleaser-action from 4.3.0 to 4.4.0 (#243)
- 0914713 chore: bump actions/setup-go from 4.0.1 to 4.1.0 (#236)
- 0cc348f feat: push new copa-action image on release (#237)
- a8a0e82 ci: remove dev container (#239)
- 8acdd9e chore: bump github.com/google/go-containerregistry from 0.15.2 to 0.16.1 (#234)
- 3e22d49 chore: bump github.com/moby/buildkit from 0.12.0 to 0.12.1 (#232)
- 499a752 chore: bump github.com/aquasecurity/trivy from 0.43.1 to 0.44.0 (#231)
- 5659b81 chore: bump github/codeql-action from 2.21.1 to 2.21.2 (#229)
- ff244d1 chore: bump github.com/containerd/containerd from 1.7.2 to 1.7.3 (#228)
- 2bc3def chore: bump github.com/docker/cli from 24.0.2+incompatible to 24.0.5+incompatible (#227)
- a339a16 chore: bump step-security/harden-runner from 2.4.0 to 2.5.0 (#226)
- fe06e35 chore: bump github/codeql-action from 2.21.0 to 2.21.1 (#225)
- db03558 chore: Generate v0.3.x docs (#222)
- 42b29fe chore: downgrade mdx-js/react (#223)
- b4ac2e8 fix: release docs (#220)
- 049b07e chore: bump buildkit 0.12.0 and trivy 0.43.0 (#221)
- b86106d chore: bump ossf/scorecard-action from 2.1.3 to 2.2.0 (#218)
- a38bc93 chore: bump actions/setup-node from 3.6.0 to 3.7.0 (#217)
- 290122f chore: bump anchore/sbom-action from 0.14.2 to 0.14.3 (#216)
- 642a359 chore: bump step-security/harden-runner from 2.4.0 to 2.5.0 (#215)
- 3528d85 chore: bump typescript from 4.9.4 to 5.1.6 in /website (#212)
- dda8528 chore: bump @docusaurus/preset-classic from 2.2.0 to 2.4.1 in /website (#211)
- 9db7432 chore: bump clsx from 1.2.1 to 2.0.0 in /website (#210)
- fda1668 chore: bump github.com/antchfx/xmlquery from 1.3.15 to 1.3.17 (#191)
- 9987d9f build: fix release version (#213)
New Contributors
- @cpuguy83 made their first contribution in #233
- @anubhav06 made their first contribution in #251
Full Changelog: v0.3.0...v0.4.0