Releases: chainguard-dev/melange
Releases · chainguard-dev/melange
Release v0.13.5
What's Changed
- Make installing -dev package "just work" and pull in all other dev libraries it needs by @xnox in #1522
- Improve some config parsing errors by @jonjohnsonjr in #1448
Full Changelog: v0.13.4...v0.13.5
Release v0.13.4
What's Changed
- sca: revert melange changes for naked sca by @justinvreeland in #1550
Full Changelog: v0.13.3...v0.13.4
Release v0.13.3
What's Changed
Full Changelog: v0.13.2...v0.13.3
Release v0.13.2
What's Changed
- build(deps): bump golang.org/x/time from 0.6.0 to 0.7.0 by @dependabot in #1543
- fix: pc provides by @xnox in #1547
Full Changelog: v0.13.1...v0.13.2
Release v0.13.1
What's Changed
- [Draft] sca: check if runtime dependencies are vendored by @justinvreeland in #1537
- build(deps): bump the actions group with 2 updates by @dependabot in #1538
- build(deps): bump cloud.google.com/go/storage from 1.43.0 to 1.44.0 by @dependabot in #1544
- build(deps): bump github.com/chainguard-dev/yam from 0.2.0 to 0.2.1 in the gomod group by @dependabot in #1539
- build(deps): bump golang.org/x/crypto from 0.27.0 to 0.28.0 by @dependabot in #1540
Full Changelog: v0.13.0...v0.13.1
Release v0.13.0
What's Changed
- build(deps): bump the gomod group with 5 updates by @dependabot in #1517
- Add pipeline markdown reference markdown generator. by @wlynch in #1492
- Support string replacement in ImageContents by @jonjohnsonjr in #1519
- git-checkout: support scheduled updates by @xnox in #1516
- sca: never emit libcuda.so.1 runtime dep by @xnox in #1515
- feat(melange): Add sub for output directory by @EyeCantCU in #1490
- build(deps): bump actions/checkout from 4.1.7 to 4.2.0 in the actions group by @dependabot in #1523
- build(deps): bump github.com/chainguard-dev/yam from 0.1.1 to 0.2.0 by @dependabot in #1525
- build(deps): bump google.golang.org/api from 0.198.0 to 0.199.0 by @dependabot in #1524
- Adjust an e2e-test that made a bad assumption. by @smoser in #1532
- add --cleanup flag (default true) by @imjasonh in #1529
- Added additional documentation for package version selection by @hbh7 in #1530
- Properly detect .so files as deps by @justinvreeland in #1526
- test: Fix typo by @jonjohnsonjr in #1535
- Fix typo in README by @jonjohnsonjr in #1451
New Contributors
- @hbh7 made their first contribution in #1530
- @justinvreeland made their first contribution in #1526
Full Changelog: v0.12.1...v0.13.0
Release v0.12.1
What's Changed
- build(deps): bump step-security/harden-runner from 2.9.1 to 2.10.1 in the actions group by @dependabot in #1501
- build(deps): bump go.opentelemetry.io/otel/exporters/stdout/stdouttrace from 1.29.0 to 1.30.0 by @dependabot in #1499
- build(deps): bump the gomod group with 2 updates by @dependabot in #1497
- build(deps): bump dagger.io/dagger from 0.12.7 to 0.13.0 by @dependabot in #1500
- cleanup: remove some direct imports of charm log by @imjasonh in #1495
- keygen: reject bit size < 2048 by @imjasonh in #1496
- pombump: add flag to display the dependency tree by @hectorj2f in #1502
- Only read the first line for shbang. by @smoser in #1213
- Include subpackage name in slog values by @jonjohnsonjr in #1505
- update_config: expose function to get valid schedule messages by @rawlingsj in #1507
- sca: remove set but never used variable by @xnox in #1509
- Add uses and name to slog values by @jonjohnsonjr in #1506
- build(deps): bump chainguard.dev/apko from 0.18.1 to 0.19.1 by @dependabot in #1512
- build(deps): bump the gomod group with 2 updates by @dependabot in #1510
- build(deps): bump github.com/docker/docker from 27.2.1+incompatible to 27.3.0+incompatible by @dependabot in #1511
Full Changelog: v0.12.0...v0.13.0
What's Changed
- build(deps): bump step-security/harden-runner from 2.9.1 to 2.10.1 in the actions group by @dependabot in #1501
- build(deps): bump go.opentelemetry.io/otel/exporters/stdout/stdouttrace from 1.29.0 to 1.30.0 by @dependabot in #1499
- build(deps): bump the gomod group with 2 updates by @dependabot in #1497
- build(deps): bump dagger.io/dagger from 0.12.7 to 0.13.0 by @dependabot in #1500
- cleanup: remove some direct imports of charm log by @imjasonh in #1495
- keygen: reject bit size < 2048 by @imjasonh in #1496
- pombump: add flag to display the dependency tree by @hectorj2f in #1502
- Only read the first line for shbang. by @smoser in #1213
- Include subpackage name in slog values by @jonjohnsonjr in #1505
- update_config: expose function to get valid schedule messages by @rawlingsj in #1507
- sca: remove set but never used variable by @xnox in #1509
- Add uses and name to slog values by @jonjohnsonjr in #1506
- build(deps): bump chainguard.dev/apko from 0.18.1 to 0.19.1 by @dependabot in #1512
- build(deps): bump the gomod group with 2 updates by @dependabot in #1510
- build(deps): bump github.com/docker/docker from 27.2.1+incompatible to 27.3.0+incompatible by @dependabot in #1511
- build(deps): bump github.com/docker/cli from 27.2.1+incompatible to 27.3.0+incompatible by @dependabot in #1513
Full Changelog: v0.12.0...v0.12.1
Release v0.12.0
What's Changed
- config: Whack more moles for string replacement by @jonjohnsonjr in #1479
- pipelines/ruby: remove signing_key by default by @Dentrax in #1481
- build(deps): bump golang.org/x/crypto from 0.26.0 to 0.27.0 by @dependabot in #1487
- build(deps): bump the gomod group with 2 updates by @dependabot in #1484
- build(deps): bump google.golang.org/api from 0.195.0 to 0.196.0 by @dependabot in #1488
- upgrade to golang 1.23 by @k4leung4 in #1443
- update to go1.23.1 by @cpanato in #1489
- index: stop writing APKINDEX.json by @xnox in #1491
- apko upgrade by @xnox in #1493
Full Changelog: v0.11.6...v0.12.0
Release v0.11.6
What's Changed
- adds git checkout fetch,update,test and yams the melange apkbuild yamls by @mritunjaysharma394 in #1477
New Contributors
- @mritunjaysharma394 made their first contribution in #1477
Full Changelog: v0.11.5...v0.11.6
Release v0.11.5
What's Changed
- fix(split pipelines): Don't split lib64 libraries by @EyeCantCU in #1476
Full Changelog: v0.11.4...v0.11.5