Commit Graph
562 Commits
Author SHA1 Message Date
CrazyMax b7061891c5 vendor: k8s v0.35.4
Signed-off-by: CrazyMax <1951866+crazy-max@users.noreply.github.com>
2026-04-21 11:18:40 +02:00
CrazyMax 4f89a2407a gitutil: use BuildKit urlutil.RedactCredentials for remote URLs
Signed-off-by: CrazyMax <1951866+crazy-max@users.noreply.github.com>
2026-04-09 15:04:37 +02:00
CrazyMax 3124b3c839 vendor: update buildkit to a243ce438aee
Signed-off-by: CrazyMax <1951866+crazy-max@users.noreply.github.com>
2026-04-09 14:40:14 +02:00
Sebastiaan van Stijn 0b0843233b vendor: github.com/docker/cli v29.4.0
full diff: https://github.com/docker/cli/compare/v29.3.1...v29.4.0

Signed-off-by: Sebastiaan van Stijn <github@gone.nl>
2026-04-07 11:52:07 +02:00
Sebastiaan van Stijn 2da27cedb5 vendor: github.com/mattn/go-runewidth v0.0.22
Signed-off-by: Sebastiaan van Stijn <github@gone.nl>
2026-04-04 01:41:02 +02:00
Sebastiaan van Stijn eaac97ea66 vendor: golang.org/x/net v0.52.0
full diff: https://cs.opensource.google/go/x/net/+/refs/tags/v0.50.0...refs/tags/v0.52.0

Signed-off-by: Sebastiaan van Stijn <github@gone.nl>
2026-04-04 01:41:02 +02:00
Sebastiaan van Stijn df41850e26 vendor: golang.org/x/time v0.15.0
full diff: https://cs.opensource.google/go/x/time/+/refs/tags/v0.14.0...refs/tags/v0.15.0

Signed-off-by: Sebastiaan van Stijn <github@gone.nl>
2026-04-04 01:41:02 +02:00
Sebastiaan van Stijn db4fa7c158 vendor: golang.org/x/text v0.35.0
full diff: https://cs.opensource.google/go/x/text/+/refs/tags/v0.34.0...refs/tags/v0.35.0

Signed-off-by: Sebastiaan van Stijn <github@gone.nl>
2026-04-04 01:41:02 +02:00
Sebastiaan van Stijn 2700871d66 vendor: golang.org/x/mod v0.34.0
Signed-off-by: Sebastiaan van Stijn <github@gone.nl>
2026-04-04 01:41:02 +02:00
Sebastiaan van Stijn 3ad8f0891a vendor: golang.org/x/sync v0.20.0
full diff: https://cs.opensource.google/go/x/sync/+/refs/tags/v0.19.0...refs/tags/v0.20.0

Signed-off-by: Sebastiaan van Stijn <github@gone.nl>
2026-04-04 01:41:02 +02:00
Sebastiaan van Stijn 63b4d001aa vendor: go.opentelemetry.io/otel v1.42.0, otel/contrib v1.67.0
Signed-off-by: Sebastiaan van Stijn <github@gone.nl>
2026-04-04 01:41:01 +02:00
Tõnis TiigiandGitHub b180175396 Merge pull request #3779 from thaJeztah/bump_moby
vendor: moby/client v0.4.0, moby/api v1.54.1
2026-04-03 11:36:47 -07:00
Jonathan A. Sternberg d781c83cec commands: micro optimization for source date epoch
Avoids the call to `os.Getenv` when it is unnecessary because it would
be overwritten anyway.

Removes the comments about moving environment variable parsing to a
method for use by library consumers. That method exists in containerd
and this set of code doesn't actually perform any parsing since the
parsing of this time is done within buildkit and not on the client.

Signed-off-by: Jonathan A. Sternberg <jonathan.sternberg@docker.com>
2026-04-03 10:02:50 -05:00
Sebastiaan van Stijn 3b630c6437 vendor: moby/client v0.4.0, moby/api v1.54.1
Signed-off-by: Sebastiaan van Stijn <github@gone.nl>
2026-04-03 16:05:48 +02:00
Guillaume Lours 8a01076b67 bump compose-go to version v2.10.2
Signed-off-by: Guillaume Lours <glours@users.noreply.github.com>
2026-04-03 12:15:27 +02:00
CrazyMax fdef3304af vendor: update buildkit to v0.29.0
Signed-off-by: CrazyMax <1951866+crazy-max@users.noreply.github.com>
2026-03-31 14:52:21 +02:00
Tonis Tiigi eba72a35e4 vendor: update buildkit to v0.29.0-rc1
Signed-off-by: Tonis Tiigi <tonistiigi@gmail.com>
2026-03-25 15:47:08 -07:00
Tonis Tiigi 7c4703614d vendor: k8s v0.35.2
Drops the gogo-proto XXX_* methods.

Signed-off-by: Tonis Tiigi <tonistiigi@gmail.com>
2026-03-06 17:32:09 -08:00
Tonis Tiigi 5a7f7c286f kubernetes: trim client-go dependency surface
Replace the full generated clientset and global Kubernetes scheme
with a small local REST client layer and minimal scheme registration.

This keeps the existing kubeconfig/auth and remote exec behavior while
significantly reducing the linked and vendored Kubernetes dependency set.

Signed-off-by: Tonis Tiigi <tonistiigi@gmail.com>
2026-03-06 16:44:18 -08:00
Sebastiaan van Stijn c06971965f vendor: docker/cli v29.3.0, moby/api v1.54.0, moby/client v0.3.0
This also allows the client to connect with API v1.40 and up (Docker 19.03),
which previously was API v1.43 and up (Docker 25.0 and up).

Signed-off-by: Sebastiaan van Stijn <github@gone.nl>
2026-03-05 16:38:27 +01:00
Tonis Tiigi 55bef8178d vendor: update buildkit to v0.28.0
Signed-off-by: Tonis Tiigi <tonistiigi@gmail.com>
2026-03-03 12:17:01 -08:00
Sebastiaan van Stijn f1f38d34ad vendor: github.com/golang/snappy v1.0.0
Ensure arm64 frame sizes are 8 (mod 16)

fixes: "Weird failure when building on Raspbian / Debian 10.11"

full diff: https://github.com/golang/snappy/compare/v0.0.4...v1.0.0

Signed-off-by: Sebastiaan van Stijn <github@gone.nl>
2026-03-03 16:28:00 +01:00
CrazyMax 7346c1f0dc vendor: update buildkit to v0.28.0-rc2
Signed-off-by: CrazyMax <1951866+crazy-max@users.noreply.github.com>
2026-02-27 16:51:40 +01:00
Tonis Tiigi 73ea669465 vendor: update buildkit to ecde33610015
Signed-off-by: Tonis Tiigi <tonistiigi@gmail.com>
2026-02-26 17:06:30 -08:00
Tonis Tiigi 4880756a0f policy: simplify recursive material resolution
Unify root/material unknown resolution with recursive Input traversal.

Signed-off-by: Tonis Tiigi <tonistiigi@gmail.com>
2026-02-26 09:14:25 -08:00
Tonis Tiigi dd2a620465 vendor: update buildkit to v0.28.0-rc1
Signed-off-by: Tonis Tiigi <tonistiigi@gmail.com>
2026-02-24 14:19:34 -08:00
Tonis Tiigi 5c3551beeb policy: add GitHub attestation verification
Add github_attestation and github_release_attestation policy support.
Fetch GitHub attestation bundles (including bundle_url .json.sn decode)
and verify against input.http.checksum.

Wire source metadata resolver progress through resolver options and add
ResolveState support for policy HTTP attestation fetches.

Signed-off-by: Tonis Tiigi <tonistiigi@gmail.com>
2026-02-20 08:56:40 -08:00
Tonis Tiigi 9d803b0d87 vendor: update buildkit to v0.28-dev-9836771d0c5b
Signed-off-by: Tonis Tiigi <tonistiigi@gmail.com>
2026-02-10 11:59:30 -08:00
Sebastiaan van Stijn 79b14eaeab vendor: github.com/docker/cli v29.2.1
full diff: https://github.com/docker/cli/compare/v29.2.0...v29.2.1

Signed-off-by: Sebastiaan van Stijn <github@gone.nl>
2026-02-04 11:03:56 +01:00
Sebastiaan van Stijn 8bd5bd4983 vendor: github.com/docker/cli v29.2.0
full diff: https://github.com/docker/cli/compare/v29.1.5...v29.2.0

Signed-off-by: Sebastiaan van Stijn <github@gone.nl>
2026-02-04 11:03:56 +01:00
Sebastiaan van Stijn 9aa7e1578a vendor: moby/api v1.53.0, moby/client v0.2.2
full diff:

- api: https://github.com/moby/moby/compare/api/v1.52.0...api/v1.53.0
- client: https://github.com/moby/moby/compare/client/v0.2.1...client/v0.2.2

Signed-off-by: Sebastiaan van Stijn <github@gone.nl>
2026-02-04 11:03:56 +01:00
Sebastiaan van Stijn 6b71de00a0 vendor: github.com/go-viper/mapstructure/v2 v2.5.0
full diff: https://github.com/go-viper/mapstructure/compare/v2.4.0...v2.5.0

Signed-off-by: Sebastiaan van Stijn <github@gone.nl>
2026-02-04 11:03:55 +01:00
Sebastiaan van Stijn eaf81b65d9 vendor: github.com/klauspost/compress v1.18.3
no changes in vendored code

- fixes / downstream CVE-2025-61728

full diff: https://github.com/klauspost/compress/compare/v1.18.2...v1.18.3

Signed-off-by: Sebastiaan van Stijn <github@gone.nl>
2026-02-04 11:03:53 +01:00
CrazyMaxandGitHub c1a52c4060 Merge pull request #3628 from thaJeztah/bump_x_deps
vendor: update golang.org/x dependencies
2026-02-04 10:31:22 +01:00
Sebastiaan van Stijn efe1aa593e vendor: golang.org/x/mod v0.32.0
full diffs:

- https://cs.opensource.google/go/x/tools/+/refs/tags/v0.39.0...refs/tags/v0.41.0
- https://cs.opensource.google/go/x/mod/+/refs/tags/v0.31.0...refs/tags/v0.32.0

Signed-off-by: Sebastiaan van Stijn <github@gone.nl>
2026-01-27 10:05:18 +01:00
Sebastiaan van Stijn 5d44afbda4 vendor: golang.org/x/crypto v0.47.0
full diffs:

- https://cs.opensource.google/go/x/crypto/+/refs/tags/v0.46.0...refs/tags/v0.47.0
- https://cs.opensource.google/go/x/net/+/refs/tags/v0.48.0...refs/tags/v0.49.0

Signed-off-by: Sebastiaan van Stijn <github@gone.nl>
2026-01-27 10:02:48 +01:00
Sebastiaan van Stijn 746c343d18 vendor: golang.org/x/text v0.33.0
full diff: https://cs.opensource.google/go/x/text/+/refs/tags/v0.32.0...refs/tags/v0.33.0

Signed-off-by: Sebastiaan van Stijn <github@gone.nl>
2026-01-27 10:02:48 +01:00
Sebastiaan van Stijn 95a1cb94b3 vendor: golang.org/x/tools v0.40.0
full diff: https://cs.opensource.google/go/x/tools/+/refs/tags/v0.39.0...refs/tags/v0.40.0

Signed-off-by: Sebastiaan van Stijn <github@gone.nl>
2026-01-27 10:02:48 +01:00
Sebastiaan van Stijn 214ebd8434 vendor: golang.org/x/term v0.39.0
full diff: https://cs.opensource.google/go/x/term/+/refs/tags/v0.38.0...refs/tags/v0.39.0

Signed-off-by: Sebastiaan van Stijn <github@gone.nl>
2026-01-27 10:02:48 +01:00
Sebastiaan van Stijn 40d068e12c vendor: golang.org/x/sys v0.40.0
full diff: https://cs.opensource.google/go/x/sys/+/refs/tags/v0.39.0...refs/tags/v0.40.0

Signed-off-by: Sebastiaan van Stijn <github@gone.nl>
2026-01-27 10:02:48 +01:00
Sebastiaan van Stijn 39ee64df71 commands/history: rewrite with stdlib multi-errors
Signed-off-by: Sebastiaan van Stijn <github@gone.nl>
2026-01-26 12:53:33 +01:00
Tonis Tiigi 08e5e8ebf2 vendor: update buildkit to v0.27.0
Signed-off-by: Tonis Tiigi <tonistiigi@gmail.com>
2026-01-21 14:32:32 -08:00
Sebastiaan van Stijn 0d343eff2d vendor: github.com/docker/cli v29.1.5
no changes in code

full diff: https://github.com/docker/cli/compare/v29.1.4...v29.1.5

Signed-off-by: Sebastiaan van Stijn <github@gone.nl>
2026-01-19 13:08:21 +01:00
Tonis Tiigi 3fd58dff71 vendor: update buildkit to v0.27.0-rc2
Signed-off-by: Tonis Tiigi <tonistiigi@gmail.com>
2026-01-16 13:56:16 -08:00
Sebastiaan van Stijn 99b8143e28 vendor: github.com/sirupsen/logrus v1.9.4
full diff: https://github.com/sirupsen/logrus/compare/dd1b4c2e81af...v1.9.4

Signed-off-by: Sebastiaan van Stijn <github@gone.nl>
2026-01-15 11:23:56 +01:00
Tonis Tiigi d54f398c5d vendor: update buildkit to v0.27.0-rc1
Signed-off-by: Tonis Tiigi <tonistiigi@gmail.com>
2026-01-14 13:36:15 -08:00
Tonis Tiigi 4b4f2aa682 tests: add http policy integration tests
Signed-off-by: Tonis Tiigi <tonistiigi@gmail.com>
2026-01-14 09:33:49 -08:00
Tonis Tiigi 87d4189039 policy: image signature verification support
Signed-off-by: Tonis Tiigi <tonistiigi@gmail.com>
2026-01-14 09:03:42 -08:00
Tonis Tiigi b2697ae933 policy: add git signature verification support
Signed-off-by: Tonis Tiigi <tonistiigi@gmail.com>
2026-01-14 09:03:42 -08:00
Tonis Tiigi 93341aaeee add rego integration to source policies
Signed-off-by: Tonis Tiigi <tonistiigi@gmail.com>
2026-01-14 09:03:40 -08:00