Skip to content

Releases: yves-vogl/aws-eks-helm-deploy

v3.0.0

Choose a tag to compare

@github-actions github-actions released this 19 Aug 17:17
Immutable release. Only release title and notes can be modified.
v3.0.0
b4a6dca

What's Changed

  • fix(release): smoke-test must ignore SLSA attestation-manifest entries (R2) by @yves-vogl in #50
  • fix(release): drop cosign --bundle flag (removed in cosign 2.x) by @yves-vogl in #51
  • docs(admin): runbook §9 — actual working v1-snapshot procedure by @yves-vogl in #52
  • fix(release): benchmark resolve tag input on workflow_dispatch (IMAGE-06) by @yves-vogl in #53
  • fix(release): benchmark needs packages:read + GHCR login (IMAGE-06) by @yves-vogl in #54
  • fix(release): benchmark must strip 'v' prefix to match GHCR tag scheme by @yves-vogl in #55
  • chore(security): freeze v1.x EOS date — 2026-12-23 by @yves-vogl in #56
  • docs(state): v2.0.0 RELEASED — ceremony complete except web-UI steps by @yves-vogl in #57
  • fix(security): scorecard publish, trivy-secret false-positives on .venv by @yves-vogl in #58
  • docs(security): v1.x is NOT maintained — drop misleading 6-month window claim by @yves-vogl in #60
  • docs(readme): rewrite for v2.0 — OIDC-first, GHCR image, supply-chain verification by @yves-vogl in #59
  • docs(oidc): polish v1 → v2 setup guide — Terraform + migration walkthrough by @yves-vogl in #61
  • docs(site): exclude docs/admin/ from public docs site + fix v1 banner by @yves-vogl in #62
  • docs: move quickstart SsoT into docs/quickstart/overview.md by @yves-vogl in #63
  • fix(meta-01): use --set-json for bitbucket metadata to preserve curly braces by @yves-vogl in #65
  • fix(ci): honour trivy ignores + correct chart-fixture skip-dirs + bump pipe.yml to 2.0.0 by @yves-vogl in #66
  • feat(helm)!: bump helm 3.21.2 → 4.2.2; migrate --atomic → --rollback-on-failure by @yves-vogl in #71
  • chore(ci): wire release-please to dot-prefixed config + sync manifest to 2.0.0 by @yves-vogl in #73
  • chore(ci): set release-please bootstrap-sha to v2.0.0 commit by @yves-vogl in #74
  • chore(ci): release-as: 3.0.0 one-shot override to unblock v3.0.0 Release PR by @yves-vogl in #76
  • chore: fix LICENSE detection + SVG logo + version matrix correctness by @yves-vogl in #78
  • chore(security): hoist write-token-perms to job level per OpenSSF Scorecard by @yves-vogl in #80
  • chore(sec): bump requests 2.32.5 → 2.34.2 (CVE-2026-25645 / GHSA-gc5v-m9x4-r6x2) by @yves-vogl in #83
  • docs(planning): pickup note for August 2026 v3.0.0 launch resume by @yves-vogl in #84
  • chore(sec): bump gitpython, cryptography, pymdown-extensions (fresh advisories) by @yves-vogl in #95
  • chore(main): release 3.0.0 by @yves-vogl in #77

Full Changelog: v2.0.0...v3.0.0

v2.1.0

Choose a tag to compare

@github-actions github-actions released this 24 Jun 11:26
Immutable release. Only release title and notes can be modified.
v2.1.0
c90fd45

Full Changelog: v2.0.0...v2.1.0

v2.0.0

Choose a tag to compare

@github-actions github-actions released this 23 Jun 00:58
v2.0.0
30e6d09

What's Changed

  • Add helm timeout configurable by @Babbleshack in #15
  • docs: profile-visibility pass — badges, version matrix, v2 roadmap by @yves-vogl in #18
  • chore(planning): initialize GSD planning for v2.0 modernization by @yves-vogl in #19
  • plan(phase-01): toolchain & spine — 4 plans + validation by @yves-vogl in #20
  • chore: migrate v2.0 to ghcr.io + enable GitHub Sponsors by @yves-vogl in #21
  • plan: add continuous image vulnerability monitoring (SEC-07/08/09) by @yves-vogl in #22
  • plan: add OpenSSF Scorecard (SEC-10) to Phase 6 by @yves-vogl in #23
  • chore: Tier-1 OpenSSF Scorecard community-health files (LICENSE rename, SECURITY, CONTRIBUTING, CoC, CODEOWNERS, Dependabot) by @yves-vogl in #26
  • phase(01): toolchain & spine — uv/ruff/mypy/pytest + src layout + base Dockerfile + structured logging by @yves-vogl in #24
  • plan(02): research + 4 plans + validation for AWS Layer & Auth Foundation by @yves-vogl in #31
  • chore: Tier-2 OpenSSF Scorecard hardening — CodeQL, Scorecard workflow, base-image digest pin, awscli test by @yves-vogl in #32
  • docs(planning): add CII / OpenSSF Best Practices crib sheet by @yves-vogl in #33
  • phase(02): AWS Layer & Auth Foundation — AuthStrategy Protocol + pure-boto3 EKS token by @yves-vogl in #34
  • phase(03): Helm Core & Upgrade Action — HelmClient + kubeconfig + UpgradeAction + HISTORY_MAX (closes #17) by @yves-vogl in #35
  • docs(planning): paste-ready CII Best Practices answer sheet by @yves-vogl in #36
  • Phase 4: OIDC & Chart Source Extensions by @yves-vogl in #37
  • Phase 5: Log Masking, Diff, Rollback & Metadata Flip by @yves-vogl in #38
  • chore(state): mark Phase 5 complete in STATE.md by @yves-vogl in #39
  • Phase 6: Release Pipeline & Supply Chain by @yves-vogl in #40
  • chore(deps): update structlog requirement from ~=26.0 to ~=26.1 by @dependabot[bot] in #41
  • chore(state): mark Phase 6 complete in STATE.md by @yves-vogl in #44
  • Phase 7: Documentation Site & Migration Guide (FINAL v2.0) by @yves-vogl in #45
  • chore(state): mark v2.0 feature-complete after Phase 7 merge by @yves-vogl in #46
  • chore: ruff format + E501 fix on Phase 6 helper scripts by @yves-vogl in #47
  • chore(deps-dev): update pre-commit requirement from ~=4.0 to ~=4.6 by @dependabot[bot] in #42
  • chore(deps): bump the actions group across 1 directory with 4 updates by @dependabot[bot] in #43
  • docs(admin): restore Phase 6 sections in repo-settings.md (Project Board + Labels + Sanity-Check) by @yves-vogl in #48
  • docs(07): mark Phase 7 deferred-items resolved + carry Phase 6 follow-ups by @yves-vogl in #49

New Contributors

Full Changelog: 1.2.0...v2.0.0

Supply chain artifacts

  • Manifest: ghcr.io/yves-vogl/aws-eks-helm-deploy@sha256:40c0bd035893eab852cc28cf3ad5d7156e52e1f31136dfc7d5cf5b549ad06b65
  • Cosign verify: cosign verify --certificate-identity-regexp '^https://github.com/yves-vogl/aws-eks-helm-deploy/' --certificate-oidc-issuer https://token.actions.githubusercontent.com ghcr.io/yves-vogl/aws-eks-helm-deploy@sha256:40c0bd035893eab852cc28cf3ad5d7156e52e1f31136dfc7d5cf5b549ad06b65
  • SBOM (SPDX): cosign verify-attestation --type spdxjson ghcr.io/yves-vogl/aws-eks-helm-deploy@sha256:40c0bd035893eab852cc28cf3ad5d7156e52e1f31136dfc7d5cf5b549ad06b65
  • SBOM (CycloneDX): cosign verify-attestation --type cyclonedx ghcr.io/yves-vogl/aws-eks-helm-deploy@sha256:40c0bd035893eab852cc28cf3ad5d7156e52e1f31136dfc7d5cf5b549ad06b65

Supply chain artifacts

  • Manifest: ghcr.io/yves-vogl/aws-eks-helm-deploy@sha256:0a3db94545c3da80e389f85c37c0d1edf73ec499dcd195990cfc135c141d8e74
  • Cosign verify: cosign verify --certificate-identity-regexp '^https://github.com/yves-vogl/aws-eks-helm-deploy/' --certificate-oidc-issuer https://token.actions.githubusercontent.com ghcr.io/yves-vogl/aws-eks-helm-deploy@sha256:0a3db94545c3da80e389f85c37c0d1edf73ec499dcd195990cfc135c141d8e74
  • SBOM (SPDX): cosign verify-attestation --type spdxjson ghcr.io/yves-vogl/aws-eks-helm-deploy@sha256:0a3db94545c3da80e389f85c37c0d1edf73ec499dcd195990cfc135c141d8e74
  • SBOM (CycloneDX): cosign verify-attestation --type cyclonedx ghcr.io/yves-vogl/aws-eks-helm-deploy@sha256:0a3db94545c3da80e389f85c37c0d1edf73ec499dcd195990cfc135c141d8e74

Supply chain artifacts

  • Manifest: ghcr.io/yves-vogl/aws-eks-helm-deploy@sha256:0c8189a70b86528680bf2148b61bd6df3529b68ebae29d3db4c4f05b4bb15cce
  • Cosign verify: cosign verify --certificate-identity-regexp '^https://github.com/yves-vogl/aws-eks-helm-deploy/' --certificate-oidc-issuer https://token.actions.githubusercontent.com ghcr.io/yves-vogl/aws-eks-helm-deploy@sha256:0c8189a70b86528680bf2148b61bd6df3529b68ebae29d3db4c4f05b4bb15cce
  • SBOM (SPDX): cosign verify-attestation --type spdxjson ghcr.io/yves-vogl/aws-eks-helm-deploy@sha256:0c8189a70b86528680bf2148b61bd6df3529b68ebae29d3db4c4f05b4bb15cce
  • SBOM (CycloneDX): cosign verify-attestation --type cyclonedx ghcr.io/yves-vogl/aws-eks-helm-deploy@sha256:0c8189a70b86528680bf2148b61bd6df3529b68ebae29d3db4c4f05b4bb15cce