83 Commits

Author SHA1 Message Date
dependabot[bot]
329e85366b chore: bump actions/dependency-review-action from 4.3.5 to 4.4.0
Some checks failed
Helm Release / Release Chart (push) Has been cancelled
Release Drafter / update_release_draft (push) Has been cancelled
build_test / Lint (push) Has been cancelled
build_test / [Helm] Build and Test (push) Has been cancelled
Bumps [actions/dependency-review-action](https://github.com/actions/dependency-review-action) from 4.3.5 to 4.4.0.
- [Release notes](https://github.com/actions/dependency-review-action/releases)
- [Commits](a6993e2c61...4081bf99e2)

---
updated-dependencies:
- dependency-name: actions/dependency-review-action
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2024-11-04 09:14:12 +00:00
Joel Kamp
edaf7eaa6a Merge branch 'main' into dependabot/github_actions/actions/dependency-review-action-4.3.5 2024-10-28 08:31:33 -05:00
dependabot[bot]
6a8358e0d0 chore: bump actions/dependency-review-action from 4.3.4 to 4.3.5
Bumps [actions/dependency-review-action](https://github.com/actions/dependency-review-action) from 4.3.4 to 4.3.5.
- [Release notes](https://github.com/actions/dependency-review-action/releases)
- [Commits](5a2ce3f5b9...a6993e2c61)

---
updated-dependencies:
- dependency-name: actions/dependency-review-action
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2024-10-28 01:30:57 +00:00
dependabot[bot]
1f19cb823d chore: bump actions/setup-go from 5.0.2 to 5.1.0
Bumps [actions/setup-go](https://github.com/actions/setup-go) from 5.0.2 to 5.1.0.
- [Release notes](https://github.com/actions/setup-go/releases)
- [Commits](0a12ed9d6a...41dfa10bad)

---
updated-dependencies:
- dependency-name: actions/setup-go
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2024-10-28 01:30:54 +00:00
Jonny Stoten
c5ece432ed Remove scorecards workflow
This was disabled anyway
2024-10-23 12:44:53 +01:00
Jonny Stoten
b014017b9a Skip DCO requirement for org members
Signed-off-by: Jonny Stoten <jonny.stoten@docker.com>
2024-10-23 10:35:50 +01:00
Jonny Stoten
56874d0b3a Remove GitHub app usage now that attest is public
Signed-off-by: Jonny Stoten <jonny.stoten@docker.com>
2024-10-23 10:29:43 +01:00
James Carnegie
395b5fe114 feat: add support for policy parameters 2024-10-16 14:52:11 +01:00
dependabot[bot]
1aa89f25f0 chore: bump github/codeql-action from 3.26.10 to 3.26.13
Bumps [github/codeql-action](https://github.com/github/codeql-action) from 3.26.10 to 3.26.13.
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](e2b3eafc8d...f779452ac5)

---
updated-dependencies:
- dependency-name: github/codeql-action
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2024-10-15 13:36:41 +00:00
Joel Kamp
ccb74b9fb7 Merge branch 'main' into dependabot/github_actions/actions/upload-artifact-4.4.3 2024-10-15 08:30:59 -05:00
dependabot[bot]
cee30c25dd chore: bump actions/upload-artifact from 4.4.0 to 4.4.3
Bumps [actions/upload-artifact](https://github.com/actions/upload-artifact) from 4.4.0 to 4.4.3.
- [Release notes](https://github.com/actions/upload-artifact/releases)
- [Commits](50769540e7...b4b15b8c7c)

---
updated-dependencies:
- dependency-name: actions/upload-artifact
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2024-10-14 02:02:21 +00:00
dependabot[bot]
14f0adcaeb chore: bump golangci/golangci-lint-action from 6.1.0 to 6.1.1
Bumps [golangci/golangci-lint-action](https://github.com/golangci/golangci-lint-action) from 6.1.0 to 6.1.1.
- [Release notes](https://github.com/golangci/golangci-lint-action/releases)
- [Commits](aaa42aa062...971e284b60)

---
updated-dependencies:
- dependency-name: golangci/golangci-lint-action
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2024-10-07 01:17:18 +00:00
Joel Kamp
7d33fc6e40 Merge branch 'main' into dependabot/github_actions/github/codeql-action-3.26.10 2024-10-01 16:00:52 -05:00
dependabot[bot]
2bfd8b6229 chore: bump github/codeql-action from 3.26.6 to 3.26.10
Bumps [github/codeql-action](https://github.com/github/codeql-action) from 3.26.6 to 3.26.10.
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](4dd16135b6...e2b3eafc8d)

---
updated-dependencies:
- dependency-name: github/codeql-action
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2024-10-01 20:57:01 +00:00
Joel Kamp
d043f700cf Merge branch 'main' into dependabot/github_actions/actions/create-github-app-token-1.11.0 2024-10-01 15:56:08 -05:00
dependabot[bot]
947c9a8cb4 chore: bump actions/create-github-app-token from 1.10.3 to 1.11.0
Bumps [actions/create-github-app-token](https://github.com/actions/create-github-app-token) from 1.10.3 to 1.11.0.
- [Release notes](https://github.com/actions/create-github-app-token/releases)
- [Commits](31c86eb3b3...5d869da34e)

---
updated-dependencies:
- dependency-name: actions/create-github-app-token
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2024-09-17 10:15:41 +00:00
dependabot[bot]
c30fa57d5c chore: bump step-security/harden-runner from 2.9.1 to 2.10.1
Bumps [step-security/harden-runner](https://github.com/step-security/harden-runner) from 2.9.1 to 2.10.1.
- [Release notes](https://github.com/step-security/harden-runner/releases)
- [Commits](5c7944e73c...91182cccc0)

---
updated-dependencies:
- dependency-name: step-security/harden-runner
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2024-09-16 01:14:55 +00:00
dependabot[bot]
367c3c8fa4 chore: bump actions/upload-artifact from 4.3.6 to 4.4.0
Bumps [actions/upload-artifact](https://github.com/actions/upload-artifact) from 4.3.6 to 4.4.0.
- [Release notes](https://github.com/actions/upload-artifact/releases)
- [Commits](834a144ee9...50769540e7)

---
updated-dependencies:
- dependency-name: actions/upload-artifact
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2024-09-02 10:04:18 +00:00
dependabot[bot]
cd2679a04a chore: bump github/codeql-action from 3.26.5 to 3.26.6
Bumps [github/codeql-action](https://github.com/github/codeql-action) from 3.26.5 to 3.26.6.
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](2c779ab0d0...4dd16135b6)

---
updated-dependencies:
- dependency-name: github/codeql-action
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2024-09-02 09:43:04 +00:00
James Carnegie
e39de4a1bc Merge branch 'main' into dependabot/github_actions/step-security/harden-runner-2.9.1 2024-08-28 10:10:55 +01:00
James Carnegie
62ada11e35 Merge branch 'main' into dependabot/github_actions/step-security/harden-runner-2.9.1 2024-08-28 10:02:58 +01:00
James Carnegie
cc4b2a3506 Merge branch 'main' into dependabot/github_actions/actions/upload-artifact-4.3.6 2024-08-28 10:02:24 +01:00
dependabot[bot]
65a4578504 chore: bump github/codeql-action from 3.25.15 to 3.26.5
Bumps [github/codeql-action](https://github.com/github/codeql-action) from 3.25.15 to 3.26.5.
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](afb54ba388...2c779ab0d0)

---
updated-dependencies:
- dependency-name: github/codeql-action
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2024-08-26 01:57:04 +00:00
dependabot[bot]
0a60e5fdd5 chore: bump actions/upload-artifact from 4.3.5 to 4.3.6
Bumps [actions/upload-artifact](https://github.com/actions/upload-artifact) from 4.3.5 to 4.3.6.
- [Release notes](https://github.com/actions/upload-artifact/releases)
- [Commits](89ef406dd8...834a144ee9)

---
updated-dependencies:
- dependency-name: actions/upload-artifact
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2024-08-12 02:06:29 +00:00
dependabot[bot]
f1a940310f chore: bump step-security/harden-runner from 2.9.0 to 2.9.1
Bumps [step-security/harden-runner](https://github.com/step-security/harden-runner) from 2.9.0 to 2.9.1.
- [Release notes](https://github.com/step-security/harden-runner/releases)
- [Commits](0d381219dd...5c7944e73c)

---
updated-dependencies:
- dependency-name: step-security/harden-runner
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2024-08-12 02:06:26 +00:00
Joel Kamp
62297ee17e Merge branch 'main' into dependabot/github_actions/actions/upload-artifact-4.3.5 2024-08-08 16:51:15 -05:00
dependabot[bot]
90f036816f chore: bump actions/upload-artifact from 4.3.4 to 4.3.5
Bumps [actions/upload-artifact](https://github.com/actions/upload-artifact) from 4.3.4 to 4.3.5.
- [Release notes](https://github.com/actions/upload-artifact/releases)
- [Commits](0b2256b8c0...89ef406dd8)

---
updated-dependencies:
- dependency-name: actions/upload-artifact
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2024-08-05 01:17:57 +00:00
dependabot[bot]
ebdc385d1e chore: bump golangci/golangci-lint-action from 6.0.1 to 6.1.0
Bumps [golangci/golangci-lint-action](https://github.com/golangci/golangci-lint-action) from 6.0.1 to 6.1.0.
- [Release notes](https://github.com/golangci/golangci-lint-action/releases)
- [Commits](a4f60bb28d...aaa42aa062)

---
updated-dependencies:
- dependency-name: golangci/golangci-lint-action
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2024-08-05 01:17:53 +00:00
dependabot[bot]
724aaca38e chore: bump ossf/scorecard-action from 2.3.3 to 2.4.0
Bumps [ossf/scorecard-action](https://github.com/ossf/scorecard-action) from 2.3.3 to 2.4.0.
- [Release notes](https://github.com/ossf/scorecard-action/releases)
- [Changelog](https://github.com/ossf/scorecard-action/blob/main/RELEASE.md)
- [Commits](dc50aa9510...62b2cac7ed)

---
updated-dependencies:
- dependency-name: ossf/scorecard-action
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2024-07-30 09:32:20 +00:00
dependabot[bot]
68e1b78984 chore: bump github/codeql-action from 3.25.13 to 3.25.15
Bumps [github/codeql-action](https://github.com/github/codeql-action) from 3.25.13 to 3.25.15.
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](2d790406f5...afb54ba388)

---
updated-dependencies:
- dependency-name: github/codeql-action
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2024-07-30 08:27:25 +00:00
dependabot[bot]
f4a8e239eb chore: bump github/codeql-action from 3.25.12 to 3.25.13 (#50) 2024-07-24 19:26:47 +00:00
dependabot[bot]
e02e91db86 chore: bump step-security/harden-runner from 2.8.1 to 2.9.0 (#49) 2024-07-24 19:22:06 +00:00
dependabot[bot]
383c35a114 chore: bump actions/setup-go from 5.0.1 to 5.0.2
Bumps [actions/setup-go](https://github.com/actions/setup-go) from 5.0.1 to 5.0.2.
- [Release notes](https://github.com/actions/setup-go/releases)
- [Commits](cdcb360436...0a12ed9d6a)

---
updated-dependencies:
- dependency-name: actions/setup-go
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2024-07-16 10:43:13 +00:00
Jonny Stoten
e6cfbadd08 Merge pull request #45 from docker/dependabot/github_actions/github/codeql-action-3.25.12
chore: bump github/codeql-action from 3.25.11 to 3.25.12
2024-07-16 11:42:09 +01:00
dependabot[bot]
1939496f6b chore: bump github/codeql-action from 3.25.11 to 3.25.12
Bumps [github/codeql-action](https://github.com/github/codeql-action) from 3.25.11 to 3.25.12.
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](b611370bb5...4fa2a79536)

---
updated-dependencies:
- dependency-name: github/codeql-action
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2024-07-15 01:17:33 +00:00
dependabot[bot]
bc8350122d chore: bump actions/dependency-review-action from 4.3.3 to 4.3.4
Bumps [actions/dependency-review-action](https://github.com/actions/dependency-review-action) from 4.3.3 to 4.3.4.
- [Release notes](https://github.com/actions/dependency-review-action/releases)
- [Commits](72eb03d02c...5a2ce3f5b9)

---
updated-dependencies:
- dependency-name: actions/dependency-review-action
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2024-07-15 01:17:27 +00:00
mrjoelkamp
84a7b26e2c feat: add production tuf root 2024-07-10 10:06:59 -05:00
dependabot[bot]
372982c90e chore: bump actions/create-github-app-token from 1.10.2 to 1.10.3 (#38) 2024-07-08 18:16:24 +00:00
dependabot[bot]
2ed9e72456 chore: bump actions/upload-artifact from 4.3.3 to 4.3.4 (#39) 2024-07-08 18:16:05 +00:00
Jonny Stoten
fb5bd79775 Merge pull request #33 from docker/update-chart-version
Update chart version to 0.0.2
2024-07-03 10:51:50 +01:00
dependabot[bot]
8a90c456e8 chore: bump actions/create-github-app-token from 1.10.1 to 1.10.2
Bumps [actions/create-github-app-token](https://github.com/actions/create-github-app-token) from 1.10.1 to 1.10.2.
- [Release notes](https://github.com/actions/create-github-app-token/releases)
- [Commits](c8f55efbd4...ad38cffc07)

---
updated-dependencies:
- dependency-name: actions/create-github-app-token
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2024-07-02 20:07:01 +00:00
dependabot[bot]
54534194ad chore: bump github/codeql-action from 3.25.10 to 3.25.11
Bumps [github/codeql-action](https://github.com/github/codeql-action) from 3.25.10 to 3.25.11.
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](23acc5c183...b611370bb5)

---
updated-dependencies:
- dependency-name: github/codeql-action
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2024-07-02 19:05:53 +00:00
Jonny Stoten
a37c181b97 Fix workflow 2024-07-02 16:50:31 +01:00
Jonny Stoten
318fd2e904 Fix path 2024-07-02 16:09:55 +01:00
Joel Kamp
d410c759e3 Merge branch 'main' into feat-add-helm-releaser 2024-07-02 09:27:12 -05:00
Jonny Stoten
9f1db587b3 Add this repo to github token scope 2024-07-02 09:15:51 +01:00
mrjoelkamp
1617823dee revert: test trigger 2024-07-01 16:05:28 -05:00
mrjoelkamp
1436232891 feat: add helm release workflow 2024-07-01 16:00:29 -05:00
Jonny Stoten
e2d4b0b5f6 Add release-drafter config 2024-07-01 15:19:28 +01:00
Jonny Stoten
dbb42b4d2b Add release workflow 2024-07-01 15:19:28 +01:00