Releases: open-component-model/ocm
Releases · open-component-model/ocm
v0.38.0-rc.1
What's Changed
🐛 Bug Fixes
- fix(deps): Fix dependency bump by updating another deprecated dependency by @frewilhelm in #1856
⬆️ Dependencies
- chore(deps): bump github.com/cloudflare/circl from 1.6.1 to 1.6.3 by @dependabot[bot] in #1839
- chore(deps): bump go.opentelemetry.io/otel/sdk from 1.39.0 to 1.40.0 by @dependabot[bot] in #1844
- chore(deps): bump the go group with 15 updates by @dependabot[bot] in #1843
- chore(deps): bump golang from 1.25.7-alpine3.22 to 1.26.1-alpine3.22 by @dependabot[bot] in #1854
- chore(deps): update to go 1.26.1 by @matthiasbruns in #1859
🧰 Maintenance
- chore: bump VERSION to 0.38.0-dev by @ocmbot[bot] in #1837
Full Changelog: v0.37...v0.38.0
v0.37.0
What's Changed
🚀 Features
- feat: add registry client timeout attribute by @piotrjanik in #1823
🐛 Bug Fixes
- fix: the version comment on codeql is incorrect by @Skarlso in #1828
- fix: revert feat: add registry client timeout attribute (#1823) by @piotrjanik in #1835
- fix: increase token scope to create PRs or sent events in other repositories by @frewilhelm in #1834
⬆️ Dependencies
8 changes
- chore(deps): bump github.com/theupdateframework/go-tuf/v2 from 2.3.0 to 2.3.1 by @dependabot[bot] in #1788
- chore(deps): bump github.com/theupdateframework/go-tuf/v2 from 2.3.1 to 2.4.1 by @dependabot[bot] in #1798
- chore(deps): bump the go group with 11 updates by @dependabot[bot] in #1804
- chore: update Go version to 1.25.7 by @morri-son in #1811
- chore(deps): bump the go group across 1 directory with 6 updates by @Skarlso in #1817
- chore(deps): bump the go group with 10 updates by @dependabot[bot] in #1825
- chore: update mongodb for security compliance fixes by @Skarlso in #1827
- chore(deps): bump the go group with 7 updates by @dependabot[bot] in #1831
🧰 Maintenance
- chore: bump VERSION to 0.37.0-dev by @ocmbot[bot] in #1796
- chore: correct brew and readme by @morri-son in #1815
- chore: bump VERSION to 0.38.0-dev by @ocmbot[bot] in #1819
- chore: update to use create-github-app-token action instead of deprecated tibdex by @Skarlso in #1829
- chore: Revert "chore: bump VERSION to 0.38.0-dev (#1819)" by @frewilhelm in #1836
Full Changelog: v0.36...v0.37.0
latest ocm-cli
holds always the latest ocm-cli binaries
v0.37.0-rc.1
What's Changed
🚀 Features
- feat: add registry client timeout attribute by @piotrjanik in #1823
🐛 Bug Fixes
- fix: the version comment on codeql is incorrect by @Skarlso in #1828
- fix: revert feat: add registry client timeout attribute (#1823) by @piotrjanik in #1835
- fix: increase token scope to create PRs or sent events in other repositories by @frewilhelm in #1834
⬆️ Dependencies
8 changes
- chore(deps): bump github.com/theupdateframework/go-tuf/v2 from 2.3.0 to 2.3.1 by @dependabot[bot] in #1788
- chore(deps): bump github.com/theupdateframework/go-tuf/v2 from 2.3.1 to 2.4.1 by @dependabot[bot] in #1798
- chore(deps): bump the go group with 11 updates by @dependabot[bot] in #1804
- chore: update Go version to 1.25.7 by @morri-son in #1811
- chore(deps): bump the go group across 1 directory with 6 updates by @Skarlso in #1817
- chore(deps): bump the go group with 10 updates by @dependabot[bot] in #1825
- chore: update mongodb for security compliance fixes by @Skarlso in #1827
- chore(deps): bump the go group with 7 updates by @dependabot[bot] in #1831
🧰 Maintenance
- chore: bump VERSION to 0.37.0-dev by @ocmbot[bot] in #1796
- chore: correct brew and readme by @morri-son in #1815
- chore: bump VERSION to 0.38.0-dev by @ocmbot[bot] in #1819
- chore: update to use create-github-app-token action instead of deprecated tibdex by @Skarlso in #1829
- chore: Revert "chore: bump VERSION to 0.38.0-dev (#1819)" by @frewilhelm in #1836
Full Changelog: v0.36...v0.37.0
v0.36.0
What's Changed
‼️ Breaking Changes
- fix!: use Fulcio certificate instead of public key and upgrade Sigstore Cosign from v2 to v3 by @morri-son in #1726
- fix: chart access artifact set media type by @fabianburth in #1786
🚀 Features
- feat: support index based reading of OCI artifacts by @jakobmoellerdev in #1646
🐛 Bug Fixes
- fix: add --oci-layout flag for OCI Image Layout blob paths by @piotrjanik in #1723
- fix: update image reference name to use the open-component-model organization repository by @piotrjanik in #1784
- fix(1560): add more explicit errors on get cv by @matthiasbruns in #1787
⬆️ Dependencies
14 changes
- chore(deps): bump the go group with 2 updates by @dependabot[bot] in #1728
- chore(deps): bump the go group with 18 updates by @dependabot[bot] in #1734
- chore: retract 0.33.0 and 0.34.1 by @frewilhelm in #1740
- chore(deps): bump the go group with 11 updates by @dependabot[bot] in #1749
- chore(deps): bump github.com/klauspost/compress by @frewilhelm in #1752
- chore(deps): bump golang from 1.25.4-alpine3.22 to 1.25.5-alpine3.22 by @dependabot[bot] in #1718
- chore: bump sigstore/fulcio by @jakobmoellerdev in #1757
- chore(deps): bump the go group with 3 updates by @dependabot[bot] in #1764
- chore(deps): bump the go group with 12 updates by @dependabot[bot] in #1770
- chore(deps): bump github.com/sigstore/fulcio from 1.8.4 to 1.8.5 by @dependabot[bot] in #1774
- chore(deps): bump the go group with 6 updates by @dependabot[bot] in #1778
- chore(deps): bump github.com/sigstore/sigstore from 1.10.3 to 1.10.4 by @dependabot[bot] in #1792
- chore(deps): bump the go group with 7 updates by @dependabot[bot] in #1795
- chore(deps): bump golang from 1.25.5-alpine3.22 to 1.25.6-alpine3.22 by @dependabot[bot] in #1794
🧰 Maintenance
- chore: bump VERSION to 0.36.0-dev by @ocmbot[bot] in #1724
New Contributors
- @piotrjanik made their first contribution in #1723
- @matthiasbruns made their first contribution in #1787
Full Changelog: v0.35...v0.36.0
v0.36.0-rc.2
What's Changed
‼️ Breaking Changes
- fix!: use Fulcio certificate instead of public key and upgrade Sigstore Cosign from v2 to v3 by @morri-son in #1726
- fix: chart access artifact set media type by @fabianburth in #1786
📋 Migration Notices
Sigstore v3 Upgrade: Keyless Signing Changes (#1726)
What Changed:
- Cosign upgraded from v2 to v3, changing OIDC token handling
- New
sigstore-v2algorithm available for Sigstore Bundle compliance - Existing
sigstoresignatures remain fully verifiable
Required Action for GitHub Actions Workflows: Add id-token: write permission and explicit OIDC token handling before keyless signing steps. Then acquire and export the OIDC token .
Other CI/CD Platforms: No action required (always required explicit OIDC handling).
Full Migration Guide: PR #1726
🚀 Features
- feat: support index based reading of OCI artifacts by @jakobmoellerdev in #1646
🐛 Bug Fixes
- fix(deps): pin github.com/klauspost/compress to version that does not change the digest on transfer by @frewilhelm in #1738
- fix: add --oci-layout flag for OCI Image Layout blob paths by @piotrjanik in #1723
- fix: update image reference name to use the open-component-model organization repository by @piotrjanik in #1784
- fix(1560): add more explicit errors on get cv by @matthiasbruns in #1787
⬆️ Dependencies
14 changes
- chore(deps): bump the go group with 2 updates by @dependabot[bot] in #1728
- chore(deps): bump the go group with 18 updates by @dependabot[bot] in #1734
- chore: retract 0.33.0 and 0.34.1 by @frewilhelm in #1740
- chore(deps): bump the go group with 11 updates by @dependabot[bot] in #1749
- chore(deps): bump github.com/klauspost/compress by @frewilhelm in #1752
- chore(deps): bump golang from 1.25.4-alpine3.22 to 1.25.5-alpine3.22 by @dependabot[bot] in #1718
- chore: bump sigstore/fulcio by @jakobmoellerdev in #1757
- chore(deps): bump the go group with 3 updates by @dependabot[bot] in #1764
- chore(deps): bump the go group with 12 updates by @dependabot[bot] in #1770
- chore(deps): bump github.com/sigstore/fulcio from 1.8.4 to 1.8.5 by @dependabot[bot] in #1774
- chore(deps): bump the go group with 6 updates by @dependabot[bot] in #1778
- chore(deps): bump github.com/sigstore/sigstore from 1.10.3 to 1.10.4 by @dependabot[bot] in #1792
- chore(deps): bump the go group with 7 updates by @dependabot[bot] in #1795
- chore(deps): bump golang from 1.25.5-alpine3.22 to 1.25.6-alpine3.22 by @dependabot[bot] in #1794
🧰 Maintenance
- chore: bump VERSION to 0.36.0-dev by @ocmbot[bot] in #1724
New Contributors
- @piotrjanik made their first contribution in #1723
- @matthiasbruns made their first contribution in #1787
Full Changelog: v0.35...v0.36.0
v0.36.0-rc.1
What's Changed
‼️ Breaking Changes
- fix!: use Fulcio certificate instead of public key and upgrade Sigstore Cosign from v2 to v3 by @morri-son in #1726
- fix: chart access artifact set media type by @fabianburth in #1786
🚀 Features
- feat: support index based reading of OCI artifacts by @jakobmoellerdev in #1646
🐛 Bug Fixes
- fix(deps): pin github.com/klauspost/compress to version that does not change the digest on transfer by @frewilhelm in #1738
- fix: add --oci-layout flag for OCI Image Layout blob paths by @piotrjanik in #1723
- fix: update image reference name to use the open-component-model organization repository by @piotrjanik in #1784
- fix(1560): add more explicit errors on get cv by @matthiasbruns in #1787
⬆️ Dependencies
14 changes
- chore(deps): bump the go group with 2 updates by @dependabot[bot] in #1728
- chore(deps): bump the go group with 18 updates by @dependabot[bot] in #1734
- chore: retract 0.33.0 and 0.34.1 by @frewilhelm in #1740
- chore(deps): bump the go group with 11 updates by @dependabot[bot] in #1749
- chore(deps): bump github.com/klauspost/compress by @frewilhelm in #1752
- chore(deps): bump golang from 1.25.4-alpine3.22 to 1.25.5-alpine3.22 by @dependabot[bot] in #1718
- chore: bump sigstore/fulcio by @jakobmoellerdev in #1757
- chore(deps): bump the go group with 3 updates by @dependabot[bot] in #1764
- chore(deps): bump the go group with 12 updates by @dependabot[bot] in #1770
- chore(deps): bump github.com/sigstore/fulcio from 1.8.4 to 1.8.5 by @dependabot[bot] in #1774
- chore(deps): bump the go group with 6 updates by @dependabot[bot] in #1778
- chore(deps): bump github.com/sigstore/sigstore from 1.10.3 to 1.10.4 by @dependabot[bot] in #1792
- chore(deps): bump the go group with 7 updates by @dependabot[bot] in #1795
- chore(deps): bump golang from 1.25.5-alpine3.22 to 1.25.6-alpine3.22 by @dependabot[bot] in #1794
🧰 Maintenance
- chore: bump VERSION to 0.36.0-dev by @ocmbot[bot] in #1724
New Contributors
- @piotrjanik made their first contribution in #1723
- @matthiasbruns made their first contribution in #1787
Full Changelog: v0.35...v0.36.0
v0.35.0
What's Changed
🚀 Features
- feat(transfer): Optimized approach for OCM transfer by implementing a concurrent worker pool by @jakobmoellerdev in #1676
🐛 Bug Fixes
- fix: Address concurrent setting of log level for yq-lib by @dee0sap in #1690
- bugfix: Correct the usage of sync.OnceFunc by @dee0sap in #1696
⬆️ Dependencies
13 changes
- chore(deps): bump github.com/docker/docker from 28.3.2+incompatible to 28.3.3+incompatible by @dependabot[bot] in #1688
- chore(deps): bump golang.org/x/crypto from 0.44.0 to 0.45.0 by @dependabot[bot] in #1691
- chore: bump docker/docker to latest version again by @frewilhelm in #1693
- chore(deps): bump the go group across 1 directory with 11 updates by @dependabot[bot] in #1701
- chore: retract release 0.34 by @frewilhelm in #1709
- chore: revert upgrade of github.com/mikefarah/yq/v4 by @frewilhelm in #1710
- chore(deps): adjust dependabot ignore for github.com/mikefarah/yq/v4 by @frewilhelm in #1716
- chore(deps): bump the go group with 11 updates by @dependabot[bot] in #1719
- chore: [releases/0.35] cherry-pick: #1738 by @frewilhelm in #1743
- chore: [releases/0.35] cherry-pick: #1740 by @frewilhelm in #1744
- chore: [releases/0.35] cherry-pick: #1752 by @frewilhelm in #1753
- chore: [releases/0.35] cherry-pick: #1718 by @frewilhelm in #1760
- chore: [releases/0.35] cherry-pick: #1757 by @frewilhelm in #1761
🧰 Maintenance
- chore: bump VERSION to 0.35.0-dev by @ocmbot[bot] in #1685
Full Changelog: v0.34...v0.35.0
v0.35.0-rc.3
What's Changed
🚀 Features
- feat(transfer): Optimized approach for OCM transfer by implementing a concurrent worker pool by @jakobmoellerdev in #1676
🐛 Bug Fixes
- fix: Address concurrent setting of log level for yq-lib by @dee0sap in #1690
- bugfix: Correct the usage of sync.OnceFunc by @dee0sap in #1696
⬆️ Dependencies
13 changes
- chore(deps): bump github.com/docker/docker from 28.3.2+incompatible to 28.3.3+incompatible by @dependabot[bot] in #1688
- chore(deps): bump golang.org/x/crypto from 0.44.0 to 0.45.0 by @dependabot[bot] in #1691
- chore: bump docker/docker to latest version again by @frewilhelm in #1693
- chore(deps): bump the go group across 1 directory with 11 updates by @dependabot[bot] in #1701
- chore: retract release 0.34 by @frewilhelm in #1709
- chore: revert upgrade of github.com/mikefarah/yq/v4 by @frewilhelm in #1710
- chore(deps): adjust dependabot ignore for github.com/mikefarah/yq/v4 by @frewilhelm in #1716
- chore(deps): bump the go group with 11 updates by @dependabot[bot] in #1719
- chore: [releases/0.35] cherry-pick: #1738 by @frewilhelm in #1743
- chore: [releases/0.35] cherry-pick: #1740 by @frewilhelm in #1744
- chore: [releases/0.35] cherry-pick: #1752 by @frewilhelm in #1753
- chore: [releases/0.35] cherry-pick: #1718 by @frewilhelm in #1760
- chore: [releases/0.35] cherry-pick: #1757 by @frewilhelm in #1761
🧰 Maintenance
- chore: bump VERSION to 0.35.0-dev by @ocmbot[bot] in #1685
Full Changelog: v0.34...v0.35.0
v0.34.3
What's Changed
⬆️ Dependencies
- chore: [releases/0.34] cherry-pick: #1718 by @frewilhelm in #1758
- chore: [releases/0.34] cherry-pick: #1757 by @frewilhelm in #1759
🧰 Maintenance
- chore: bump VERSION to 0.34.3-dev by @ocmbot[bot] in #1747
Full Changelog: v0.34.2...v0.34.3