Skip to content

tf-version-bump v1.0.0-rc.12

Pre-release
Pre-release

Choose a tag to compare

@github-actions github-actions released this 11 Sep 06:35
· 112 commits to main since this release

Installation

To install tf-version-bump, download one of the pre-built binaries provided for your platform from the artifacts attached to this release.

Pre-built binaries are provided for Linux, macOS, and Windows (amd64 and arm64 architectures).

Quick Install (Linux amd64)

# Download the binary
curl -LO https://github.com/yesdevnull/tf-version-bump/releases/download/v1.0.0-rc.12/tf-version-bump_1.0.0-rc.12_linux_x86_64.tar.gz

# Extract
tar -xzf tf-version-bump_1.0.0-rc.12_linux_x86_64.tar.gz

# Move to PATH
sudo mv tf-version-bump /usr/local/bin/

# Make executable
sudo chmod +x /usr/local/bin/tf-version-bump

Verify binary integrity

To verify the integrity of the downloaded binary, you can utilize the checksums file:

# Download checksums
curl -LO https://github.com/yesdevnull/tf-version-bump/releases/download/v1.0.0-rc.12/tf-version-bump-v1.0.0-rc.12.checksums.txt

# Verify the binary using the checksums file
sha256sum -c tf-version-bump-v1.0.0-rc.12.checksums.txt --ignore-missing

Verify artifact provenance

This release includes SLSA Level 3 provenance attestations for supply chain security. The SLSA provenance of the binaries and packages can be found within the artifacts associated with this release. It is presented through an in-toto link metadata file named tf-version-bump-v1.0.0-rc.12.intoto.jsonl.

To verify the provenance of an artifact, you can utilize the slsa-verifier tool:

# Install slsa-verifier (if not already installed)
go install github.com/slsa-framework/slsa-verifier/v2/cli/slsa-verifier@latest

# Download the metadata file
curl -LO https://github.com/yesdevnull/tf-version-bump/releases/download/v1.0.0-rc.12/tf-version-bump-v1.0.0-rc.12.intoto.jsonl

# Verify the provenance of the artifact
slsa-verifier verify-artifact tf-version-bump_1.0.0-rc.12_linux_x86_64.tar.gz \
  --provenance-path tf-version-bump-v1.0.0-rc.12.intoto.jsonl \
  --source-uri github.com/yesdevnull/tf-version-bump \
  --source-tag v1.0.0-rc.12

All Available Binaries

See the Assets section below for binaries for all supported platforms:

  • Linux: tf-version-bump_1.0.0-rc.12_linux_x86_64.tar.gz, tf-version-bump_1.0.0-rc.12_linux_arm64.tar.gz
  • macOS: tf-version-bump_1.0.0-rc.12_darwin_x86_64.tar.gz, tf-version-bump_1.0.0-rc.12_darwin_arm64.tar.gz
  • Windows: tf-version-bump_1.0.0-rc.12_windows_x86_64.zip, tf-version-bump_1.0.0-rc.12_windows_arm64.zip
  • Linux Packages: .deb and .rpm packages for Debian/Ubuntu and RHEL/Fedora

Alternative: Install via Go

go install github.com/yesdevnull/tf-version-bump@v1.0.0-rc.12

What's Changed

  • build(deps): bump the github-actions-backward-compatible group across 1 directory with 3 updates by @dependabot[bot] in #133
  • build(deps): bump google.golang.org/grpc from 1.82.1 to 1.83.1 in /examples/github-actions/test-fixtures/test-provider in the go_modules group across 1 directory by @dependabot[bot] in #134
  • build: pin the GitHub Actions example to v1.0.0-rc.11 by @yesdevnull in #136
  • fix: close obsolete Terraform update pull requests by @yesdevnull in #137
  • feat: make Terraform init upgrades opt-in by @yesdevnull in #138
  • refactor: simplify Terraform GitHub Actions automation by @yesdevnull in #139
  • fix: check remote state before reconciling GitHub records by @yesdevnull in #140
  • feat: visible Actions failures, Terraform environments, run summaries and linting by @yesdevnull in #141
  • feat: add -audit-file for read-only config comparison by @yesdevnull in #143

Full Changelog: v1.0.0-rc.11...v1.0.0-rc.12