Skip to content

v0.51.0

Latest

Choose a tag to compare

@tekton-pac-bot tekton-pac-bot released this 10 Sep 10:01
· 33 commits to main since this release
Immutable release. Only release title and notes can be modified.

Pipelines as Code version v0.51.0

Tekton Pipelines as Code v0.51.0 has been released 🥳

✨ Major changes and Features

  • Add provider API retries for transient failures: Allow administrators to opt in to retrying temporary GitHub and GitLab API failures, preventing short rate-limit windows and provider outages from immediately dropping webhook work that could succeed moments later. #2854

  • Query commit statuses in Bitbucket Cloud for /retest: Implement GetCommitStatuses for Bitbucket Cloud so /retest skips pipelines that already succeeded, even when PipelineRun objects have been pruned. #2879

  • Enforce PipelineRun create permission on Repository CR creation: Prevent privilege escalation by validating that users creating a Repository CR also have permission to create PipelineRuns in the same namespace. ac1ff23

🐛 Bug Fixes

  • Retry GitLab fork completion and GitHub check-run 404s: Retry brief 404s on check-run updates when the check-run ID came from the PipelineRun annotation, and wait for GitLab to finish importing repository forks before returning the project. #2922

  • Fix event-id for Bitbucket Cloud and GitLab in detect: Correct the event headers to use the right values for each provider, ensuring proper event-id logging context. #2971

  • Skip redundant spec.status patch on already-started PipelineRuns: Avoid sending no-op spec updates to the Kubernetes API once a PipelineRun is already running, preventing admission webhook rejections. #2916

  • Bitbucket Data Center: support on-comment annotation for non-gitops comments: Allow non-gitops comments to pass through the Detect handler in Bitbucket Data Center provider. #2911

  • Improve log message on invalid regexp in on-comment: Provide clearer error messages when an invalid regexp is found in the on-comment annotation. #2907

📚 Documentation Updates

  • Add missing fields to Repository CR complete examples: Include incoming, params, github_app_token_scope_repos, gitops_command_prefix, gitlab, forgejo, and AI settings in documentation examples. #2925

  • Remove comment from copiable kubectl command block: Removed comment from the copiable block containing kubectl command to create secrets so that copying it doesn't include non-executable comments. #2917

⚙️ Chores

  • Restrict credentials to trusted hosts: Add an administrator-owned trusted-provider-hostnames allowlist to prevent Repository resources from redirecting inherited global credentials to attacker-selected hosts. #2871

  • Fix Go standard library CVEs: Update Go from 1.26.5 to 1.26.6 to address six reachable Go standard library vulnerabilities (CVE-2026-56860, CVE-2026-56858, CVE-2026-56862, CVE-2026-56853, CVE-2026-33818, CVE-2026-39821). #2927

  • Fix Go SSH crypto vulnerabilities: Update golang.org/x/crypto from v0.55.0 to v0.56.0 to fix GO-2026-6354 and GO-2026-6355 DoS vulnerabilities in the SSH package. #2962

  • Test: disambiguate same-SHA runs by event type: Filter pipeline runs by target event type in test wait helpers to prevent premature resolution from different webhook deliveries. #2859

  • Export ControllerConfigMap and reuse in bootstrap: Refactor the controllerConfigMap helper to reduce duplication between packages. #2932

  • Use new path for cel-go library: Update to the new cel.dev/cel-go import path (v0.32.0). #2961

  • Update golangci-lint to 2.13 and apply fixes: Update linter configuration to the new schema options and adjust function signatures accordingly. #2963

  • Fix CEL expression in CI documentation task: Correct the CEL expression in doc.yaml that required push events. #2921

  • Dependency updates: Update Go dependencies including gobwas/glob, jenkins-x/go-scm, Tekton Pipeline to v1.16.0, Kubernetes API/client-go, golang.org/x/net, google.golang.org/grpc, and prometheus packages. #2966

Installation

To install this version you can install the release.yaml with kubectl for your platform :

Openshift

kubectl apply -f https://github.com/tektoncd/pipelines-as-code/releases/download/v0.51.0/release.yaml

Kubernetes

kubectl apply -f https://github.com/tektoncd/pipelines-as-code/releases/download/v0.51.0/release.k8s.yaml

Documentation

The documentation for this release is available here :

https://docs.pipelinesascode.com/v0.51.0

What's Changed

  • feat(bitbucket): query commit statuses for /retest by @theakshaypant in #2879
  • fix: improve log message on invalid regexp in on-comment by @zakisk in #2907
  • docs: remove comment from copiable block by @zakisk in #2917
  • ci: fix CEL expression of doc.yaml by @zakisk in #2921
  • feat: add gitlab/github provider API retries by @chmouel in #2854
  • docs: Add symlink for GitHub Copilot review by @chmouel in #2924
  • ci: bump the go-dependencies group with 9 updates by @dependabot[bot] in #2912
  • docs: add missing fields to Repository CR complete examples by @zakisk in #2925
  • fix(reconciler): skip redundant spec.status patch on already-started PipelineRuns by @pujitha24 in #2916
  • fix(cve): bump Go to 1.26.6 — fix 6 stdlib CVEs (crypto/tls, net/http, net/url, html/template, encoding/asn1) by @theakshaypant in #2927
  • test: disambiguate same-SHA runs by event type and reduce concurrency flakiness by @chmouel in #2859
  • fix: exclude generated and non-library code from codecov coverage by @khrm in #2929
  • feat: pin GitHub host on first authenticated webhook by @chmouel in #2871
  • ci: Bump golang.org/x/net from 0.57.0 to 0.58.0 in the go-dependencies group by @dependabot[bot] in #2935
  • fix(bitbucketdatacenter): support on-comment annotation for non-gitops comments by @tricktron in #2911
  • ci: Bump the go-dependencies group with 4 updates by @dependabot[bot] in #2942
  • refactor: export ControllerConfigMap and reuse in bootstrap by @chmouel in #2932
  • dep: use new path for cel-go lib by @zakisk in #2961
  • fix: update golangci to golangci-2.13 and fixes by @chmouel in #2963
  • Security: Fix GO-2026-6354/GO-2026-6355 - update golang.org/x/crypto v0.55.0 → v0.56.0 by @theakshaypant in #2962
  • ci: Bump google.golang.org/grpc from 1.83.0 to 1.83.1 by @dependabot[bot] in #2959
  • ci: Bump the go-dependencies group with 8 updates by @dependabot[bot] in #2966
  • deps: Update all dependencies by @zakisk in #2967
  • docs(release-process): fix git remote in tagging step by @theakshaypant in #2968
  • fix: retry gh transient 404 on check-run update by @chmouel in #2922
  • fix: wait for gitlab repository fork to finish importing by @chmouel in #2969
  • fix: use correct event-id for bb cloud and gitlab in detect by @zakisk in #2971

New Contributors

Full Changelog: v0.50.0...v0.51.0