Skip to content

Releases: crossplane-contrib/provider-upjet-harbor

v1.3.1

Choose a tag to compare

@jonasz-lasut jonasz-lasut released this 09 Oct 09:17
0703212

What's Changed

  • Update module sigs.k8s.io/controller-runtime to v0.25.2
  • Update go module directive to v1.27.2
  • Update module golang.org/x/net to v0.60.0
  • Keep _wo fields at runtime schema as status-only fields as provider-harbor reads them unconditionally

Full Changelog: v1.3.0...v1.3.1

v1.3.0

Choose a tag to compare

@jonasz-lasut jonasz-lasut released this 30 Sep 08:03
d471dd3

What's new since v1.2.1

  • fix: suppress case-only schedule diffs for garbage collection and config (#85)
  • fix: build issues in cluster and namespaced robot account resources (#78)
  • feat: update Terraform provider to v3.12.5 (#79)
  • security: update google.golang.org/grpc to v1.83.2 (#73)
  • chore: dependency and CI updates (Kubernetes patches, distroless runtime image, buildx, golangci-lint, GitHub Actions)

v1.2.1

Choose a tag to compare

@jonasz-lasut jonasz-lasut released this 14 Sep 06:40

Security patch release. Remediates: GHSA-2v4p-qf9q-27wj (gRPC-Go xDS servers DoS via crash from missing :authority and Host headers) via google.golang.org/grpc v1.83.1 -> v1.83.2.

v1.2.0

Choose a tag to compare

@jonasz-lasut jonasz-lasut released this 08 Sep 06:14
f061693

What's Changed since v1.1.2

  • perf: upgrade to crossplane-runtime v2.4.0
  • feat: bump terraform-provider-harbor to v3.12.4
  • Update module google.golang.org/grpc to v1.83.1 [SECURITY]
  • Update module sigs.k8s.io/controller-runtime to v0.25.0
  • Update module sigs.k8s.io/controller-tools to v0.22.0
  • fix(apis): replace deprecated scheme.Builder with runtime.NewSchemeBuilder
  • ci: derive Go version from go.mod in workflows
  • chore: digest-pin distroless base image in Dockerfile
  • Update go module directive to v1.27.1
  • Various Renovate dependency and CI tooling updates (docker/buildx, docker/setup-qemu-action, golangci-lint, kind, kubernetes monorepo/patches, github actions)

Full Changelog: v1.1.2...v1.2.0

v1.1.2

Choose a tag to compare

@jonasz-lasut jonasz-lasut released this 17 Aug 07:24

Security patch release. Remediates: GO-2026-6179, GO-2026-6180 (golang.org/x/mod), GO-2026-6091, GO-2026-6218, GO-2026-5942/CVE-2026-46600, GO-2026-5972, GO-2026-6090, GO-2026-6088, GO-2026-6089, GO-2026-5026 (Go stdlib/toolchain, go1.26.5 -> go1.26.6).

v1.1.1

Choose a tag to compare

@jonasz-lasut jonasz-lasut released this 10 Aug 09:00
f2128f1

Security patch release. Remediates two high-severity code-scanning alerts against v1.1.0:

  • GO-2026-5942 — panic parsing an invalid SVCB or HTTPS RR in golang.org/x/net/dns/dnsmessage; golang.org/x/net bumped v0.55.0 → v0.56.0.
  • GO-2026-5970 — infinite loop on invalid input in golang.org/x/text; golang.org/x/text bumped v0.37.0 → v0.40.0.

No API or resource changes — dependency updates only.

v1.1.0

Choose a tag to compare

@jonasz-lasut jonasz-lasut released this 10 Aug 08:28
b7172f3

What's new since v1.0.2

Features

  • Bump terraform-provider-harbor to v3.12.3 (adds disabledAuditLogEventTypes to ConfigSystem)
  • Update crossplane-runtime to v2.3.3 and upjet to main

Security

  • Bump OpenTelemetry to v1.44.0, fixing GO-2026-5158 (baggage parsing)

CI & tooling

  • Update crossplane to v2.3.4 in CI
  • Fix supply-chain workflow ordering for xpkg.upbound.io signing/attestation
  • Extract certs dir resolution from main

Docs

  • Add CVE remediation and release-cutting skills

v1.0.2

Choose a tag to compare

@jonasz-lasut jonasz-lasut released this 23 Jul 08:54
69eb2a4

Security patch release. Remediates: GHSA-hrxh-6v49-42gf (google.golang.org/grpc, high), GO-2026-5942 (golang.org/x/net, low), GO-2026-5970 (golang.org/x/text, low).

v1.0.1

Choose a tag to compare

@jonasz-lasut jonasz-lasut released this 22 Jul 06:46
c7a80d3

What's Changed

Full Changelog: v1.0.0...v1.0.1

v1.0.0

Choose a tag to compare

@jonasz-lasut jonasz-lasut released this 21 Jul 18:47
43c44f9

Highlights

  • Upstream Harbor Terraform provider updated v3.12.0 → v3.12.1, adding a new Project field and dropping two fields that can't be represented as Crossplane state.
  • Supply-chain hardening: released images are now signed and attested (SBOM + SLSA provenance) via Cosign, and a weekly Grype scan checks the latest release for new CVEs.
  • Go toolchain bumped to 1.26.5 and CI dependencies (golangci-lint, GitHub Actions, kind, docker buildx) refreshed via Renovate.

Upstream provider update

  • Harbor Terraform provider bumped to v3.12.1 (TERRAFORM_PROVIDER_VERSION).
  • Project: added proxyCacheLocalOnNotFound — serve images from the local cache when they've been removed from the upstream registry (requires Harbor v2.15.1+).
  • Config (Auth): dropped oidc_client_secret_wo / oidc_client_secret_wo_version from the generated schema. These are Terraform write-only fields with no state to read back, so they can't be represented as a Crossplane resource field.
  • internal/clients: updated the buildHarborSetup call site for the new upstream client constructor signature.

Supply chain / release hardening

  • Image signing & attestation — publish-provider-package.yml now signs both the GHCR image and the Upbound registry mirror with Cosign, generates an SPDX SBOM with Syft, and attests both the SBOM and SLSA provenance to each image.
  • Registry mirroring enabled — provider packages are now also mirrored to xpkg.upbound.io (mirror: true), gated behind new id-token / packages / attestations workflow permissions.
  • Marketplace packaging — a new attach-extensions job appends the README, an icon, and the release notes to the published xpkg as Upbound Marketplace extensions.
  • Scheduled vulnerability scanning — a new weekly Grype scan (grype-scan.yaml, Mondays 05:00 UTC) scans the latest published release image and uploads results to GitHub code scanning.

CI / tooling maintenance

  • Go toolchain: 1.25.9 → 1.26.5.
  • golangci-lint: v2.12.1 → v2.12.2.
  • GitHub Actions: actions/checkout → v7, actions/setup-go → v7, actions/cache → v6, codecov/codecov-action → v7, plus digest bumps for docker/setup-buildx-action and docker/setup-qemu-action.
  • docker/buildx → v0.35.0, kubernetes-sigs/kind → v0.32.0, k8s.io/utils digest bump.
  • Removed the ad hoc publish-artifacts job from ci.yml — artifact building/publishing is now handled entirely by the dedicated, signed publish-provider-package.yml workflow.
  • Removed the unused backport.yml workflow.

Compatibility / upgrade notes

  • Backward compatible — no breaking API changes. proxyCacheLocalOnNotFound is purely additive; the two dropped write-only Auth fields were never populated in Crossplane state, so no existing Config resources reference them.
  • Requires Harbor v2.15.1+ to make use of the new proxyCacheLocalOnNotFound field on Project.
  • Building from source now requires Go ≥ 1.26.5.

Full Changelog: v0.2.1...v1.0.0