Repository navigation
Releases: crossplane-contrib/provider-upjet-harbor
Release list
v1.3.1
What's Changed
- Update module sigs.k8s.io/controller-runtime to v0.25.2
- Update go module directive to v1.27.2
- Update module golang.org/x/net to v0.60.0
- Keep
_wofields at runtime schema as status-only fields as provider-harbor reads them unconditionally
Full Changelog: v1.3.0...v1.3.1
v1.3.0
What's new since v1.2.1
- fix: suppress case-only schedule diffs for garbage collection and config (#85)
- fix: build issues in cluster and namespaced robot account resources (#78)
- feat: update Terraform provider to v3.12.5 (#79)
- security: update google.golang.org/grpc to v1.83.2 (#73)
- chore: dependency and CI updates (Kubernetes patches, distroless runtime image, buildx, golangci-lint, GitHub Actions)
v1.2.1
Security patch release. Remediates: GHSA-2v4p-qf9q-27wj (gRPC-Go xDS servers DoS via crash from missing :authority and Host headers) via google.golang.org/grpc v1.83.1 -> v1.83.2.
v1.2.0
What's Changed since v1.1.2
- perf: upgrade to crossplane-runtime v2.4.0
- feat: bump terraform-provider-harbor to v3.12.4
- Update module google.golang.org/grpc to v1.83.1 [SECURITY]
- Update module sigs.k8s.io/controller-runtime to v0.25.0
- Update module sigs.k8s.io/controller-tools to v0.22.0
- fix(apis): replace deprecated scheme.Builder with runtime.NewSchemeBuilder
- ci: derive Go version from go.mod in workflows
- chore: digest-pin distroless base image in Dockerfile
- Update go module directive to v1.27.1
- Various Renovate dependency and CI tooling updates (docker/buildx, docker/setup-qemu-action, golangci-lint, kind, kubernetes monorepo/patches, github actions)
Full Changelog: v1.1.2...v1.2.0
v1.1.2
Security patch release. Remediates: GO-2026-6179, GO-2026-6180 (golang.org/x/mod), GO-2026-6091, GO-2026-6218, GO-2026-5942/CVE-2026-46600, GO-2026-5972, GO-2026-6090, GO-2026-6088, GO-2026-6089, GO-2026-5026 (Go stdlib/toolchain, go1.26.5 -> go1.26.6).
v1.1.1
Security patch release. Remediates two high-severity code-scanning alerts against v1.1.0:
- GO-2026-5942 — panic parsing an invalid SVCB or HTTPS RR in
golang.org/x/net/dns/dnsmessage;golang.org/x/netbumped v0.55.0 → v0.56.0. - GO-2026-5970 — infinite loop on invalid input in
golang.org/x/text;golang.org/x/textbumped v0.37.0 → v0.40.0.
No API or resource changes — dependency updates only.
v1.1.0
What's new since v1.0.2
Features
- Bump terraform-provider-harbor to v3.12.3 (adds
disabledAuditLogEventTypestoConfigSystem) - Update crossplane-runtime to v2.3.3 and upjet to main
Security
- Bump OpenTelemetry to v1.44.0, fixing GO-2026-5158 (baggage parsing)
CI & tooling
- Update crossplane to v2.3.4 in CI
- Fix supply-chain workflow ordering for xpkg.upbound.io signing/attestation
- Extract certs dir resolution from main
Docs
- Add CVE remediation and release-cutting skills
v1.0.2
Security patch release. Remediates: GHSA-hrxh-6v49-42gf (google.golang.org/grpc, high), GO-2026-5942 (golang.org/x/net, low), GO-2026-5970 (golang.org/x/text, low).
v1.0.1
What's Changed
- Separate signing and attestation from image builds by @jonasz-lasut in #34 to achieve stable certificate identity - https://github.com/jonasz-lasut/provider-upjet-harbor/.github/workflows/supplychain.yaml@refs/heads/main
Full Changelog: v1.0.0...v1.0.1
v1.0.0
Highlights
- Upstream Harbor Terraform provider updated v3.12.0 → v3.12.1, adding a new
Projectfield and dropping two fields that can't be represented as Crossplane state. - Supply-chain hardening: released images are now signed and attested (SBOM + SLSA provenance) via Cosign, and a weekly Grype scan checks the latest release for new CVEs.
- Go toolchain bumped to 1.26.5 and CI dependencies (
golangci-lint, GitHub Actions,kind,docker buildx) refreshed via Renovate.
Upstream provider update
- Harbor Terraform provider bumped to v3.12.1 (
TERRAFORM_PROVIDER_VERSION). Project: addedproxyCacheLocalOnNotFound— serve images from the local cache when they've been removed from the upstream registry (requires Harbor v2.15.1+).Config(Auth): droppedoidc_client_secret_wo/oidc_client_secret_wo_versionfrom the generated schema. These are Terraform write-only fields with no state to read back, so they can't be represented as a Crossplane resource field.internal/clients: updated thebuildHarborSetupcall site for the new upstream client constructor signature.
Supply chain / release hardening
- Image signing & attestation —
publish-provider-package.ymlnow signs both the GHCR image and the Upbound registry mirror with Cosign, generates an SPDX SBOM with Syft, and attests both the SBOM and SLSA provenance to each image. - Registry mirroring enabled — provider packages are now also mirrored to
xpkg.upbound.io(mirror: true), gated behind newid-token/packages/attestationsworkflow permissions. - Marketplace packaging — a new
attach-extensionsjob appends the README, an icon, and the release notes to the published xpkg as Upbound Marketplace extensions. - Scheduled vulnerability scanning — a new weekly Grype scan (
grype-scan.yaml, Mondays 05:00 UTC) scans the latest published release image and uploads results to GitHub code scanning.
CI / tooling maintenance
- Go toolchain: 1.25.9 → 1.26.5.
golangci-lint: v2.12.1 → v2.12.2.- GitHub Actions:
actions/checkout→ v7,actions/setup-go→ v7,actions/cache→ v6,codecov/codecov-action→ v7, plus digest bumps fordocker/setup-buildx-actionanddocker/setup-qemu-action. docker/buildx→ v0.35.0,kubernetes-sigs/kind→ v0.32.0,k8s.io/utilsdigest bump.- Removed the ad hoc
publish-artifactsjob fromci.yml— artifact building/publishing is now handled entirely by the dedicated, signedpublish-provider-package.ymlworkflow. - Removed the unused
backport.ymlworkflow.
Compatibility / upgrade notes
- Backward compatible — no breaking API changes.
proxyCacheLocalOnNotFoundis purely additive; the two dropped write-only Auth fields were never populated in Crossplane state, so no existingConfigresources reference them. - Requires Harbor v2.15.1+ to make use of the new
proxyCacheLocalOnNotFoundfield onProject. - Building from source now requires Go ≥ 1.26.5.
Full Changelog: v0.2.1...v1.0.0