Skip to content

Tekton Pipeline release v0.33.3 "Highlander HAL"

Compare
Choose a tag to compare
@tekton-robot tekton-robot released this 16 Mar 20:46

-Docs @ v0.33.3
-Examples @ v0.33.3

Installation one-liner

kubectl apply -f https://storage.googleapis.com/tekton-releases/pipeline/previous/v0.33.3/release.yaml

Attestation

The Rekor UUID for this release is 58a9cc1653c98f726dbce1683b3052d7a5d8efe967636429412d5fe8c13ce7bf

Obtain the attestation:

REKOR_UUID=58a9cc1653c98f726dbce1683b3052d7a5d8efe967636429412d5fe8c13ce7bf
rekor-cli get --uuid $REKOR_UUID --format json | jq -r .Attestation | base64 --decode | jq

Verify that all container images in the attestation are in the release file:

RELEASE_FILE=https://storage.googleapis.com/tekton-releases/pipeline/previous/v0.33.3/release.yaml 
REKOR_UUID=58a9cc1653c98f726dbce1683b3052d7a5d8efe967636429412d5fe8c13ce7bf

# Obtains the list of images with sha from the attestation
REKOR_ATTESTATION_IMAGES=$(rekor-cli get --uuid "$REKOR_UUID" --format json | jq -r .Attestation | base64 --decode | jq -r '.subject[]|.name + ":v0.33.3@sha256:" + .digest.sha256')

# Download the release file
curl "$RELEASE_FILE" > release.yaml

# For each image in the attestation, match it to the release file
for image in $REKOR_ATTESTATION_IMAGES; do 
  printf $image; grep -q $image release.yaml && echo " ===> ok" || echo " ===> no match";
done

Changes

There are no code changes in this release.
Tekton Pipeline release v0.33.3 is identical to v0.33.2, but rebuilt with golang v1.17.7.

Features

Fixes

Misc

Docs

Thanks

Thanks to these contributors who contributed to v0.33.3!

Extra shout-out for awesome release notes: