Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
…-project#1876) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> chore: Bump github.com/prometheus/client_golang from 1.20.4 to 1.20.5 (ratify-project#1877) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> chore: Bump vscode/devcontainers/go from `bdecb4c` to `46f85d1` in /.devcontainer (ratify-project#1879) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> feat: crl cache Signed-off-by: Juncheng Zhu <junczhu@microsoft.com> feat: crl cache 2 Signed-off-by: Juncheng Zhu <junczhu@microsoft.com> feat: crl provider Signed-off-by: Juncheng Zhu <junczhu@microsoft.com> feat: added interfaces Signed-off-by: Juncheng Zhu <junczhu@microsoft.com> feat: crl refactor Signed-off-by: Juncheng Zhu <junczhu@microsoft.com> feat: crl refactor Signed-off-by: Juncheng Zhu <junczhu@microsoft.com> feat: crl refactor Signed-off-by: Juncheng Zhu <junczhu@microsoft.com> feat: crl refactor Signed-off-by: Juncheng Zhu <junczhu@microsoft.com> feat: integrate crl to verifier Signed-off-by: Juncheng Zhu <junczhu@microsoft.com> feat: kmp revocationfactory refactor Signed-off-by: Juncheng Zhu <junczhu@microsoft.com> chore: bump up go version to 1.22.8 (ratify-project#1880) Signed-off-by: Binbin Li <libinbin@microsoft.com> Signed-off-by: Binbin Li <libinbin050215@gmail.com> chore: Bump github.com/sigstore/sigstore from 1.8.9 to 1.8.10 (ratify-project#1878) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> docs: design proposal for tag and digest co-existing [ISSUE 1657] (ratify-project#1793) docs: add CRL Design (ratify-project#1789) Signed-off-by: Juncheng Zhu <junczhu@microsoft.com> docs: Create proposal for verifying 'last-n' artifacts only. (ratify-project#1797) Signed-off-by: Susan Shi <huish@microsoft.com> docs: nVersionCount support for KMP design doc (ratify-project#1831) Signed-off-by: Joshua Duffney <jduffney@microsoft.com> ci: retry trivy db update upon failure (ratify-project#1881) Signed-off-by: Binbin Li <libinbin@microsoft.com> chore: Bump anchore/sbom-action from 0.17.4 to 0.17.5 (ratify-project#1882) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> ci: fix tagging in publish-ghcr workflow (ratify-project#1884) Signed-off-by: Binbin Li <libinbin@microsoft.com> ci: retry trivy download-db on failure (ratify-project#1883) Signed-off-by: Binbin Li <libinbin@microsoft.com> chore: migrate azure-sdk-for-go/containerregistry to the latest release (ratify-project#1829) Signed-off-by: Shahram Kalantari <shahramk@gmail.com> chore: Bump github/codeql-action from 3.26.13 to 3.27.0 (ratify-project#1887) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> feat: crl fetcher Signed-off-by: Juncheng Zhu <junczhu@microsoft.com> feat: crl fetcher Signed-off-by: Juncheng Zhu <junczhu@microsoft.com> feat: update bytesFetcher Signed-off-by: Juncheng Zhu <junczhu@microsoft.com> feat: crl provider Signed-off-by: Juncheng Zhu <junczhu@microsoft.com> feat: refactor the interface Signed-off-by: Juncheng Zhu <junczhu@microsoft.com> feat: integrate crl to verifier 2 Signed-off-by: Juncheng Zhu <junczhu@microsoft.com> feat: integrate crl to verifier 2 Signed-off-by: Juncheng Zhu <junczhu@microsoft.com> chore: update charts (ratify-project#1892) Signed-off-by: Juncheng Zhu <junczhu@microsoft.com> chore: Bump actions/checkout from 4.2.1 to 4.2.2 (ratify-project#1893) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> chore: Bump actions/setup-go from 5.0.2 to 5.1.0 (ratify-project#1894) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> chore: Bump k8s.io/apimachinery from 0.28.14 to 0.28.15 (ratify-project#1896) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> chore: Bump distroless/static from `26f9b99` to `3a03fc0` in /httpserver (ratify-project#1899) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> chore: Bump k8s.io/client-go from 0.28.14 to 0.28.15 (ratify-project#1897) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> chore: Bump anchore/sbom-action from 0.17.5 to 0.17.6 (ratify-project#1903) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> feat: allow service account annotations (ratify-project#1907) Signed-off-by: Maneesh Singh <mann.biher@yahoo.co.in> feat: add interface for testing Signed-off-by: Juncheng Zhu <junczhu@microsoft.com> feat: implemented interface Signed-off-by: Juncheng Zhu <junczhu@microsoft.com> feat: implemented interface Signed-off-by: Juncheng Zhu <junczhu@microsoft.com> test: working on test cases Signed-off-by: Juncheng Zhu <junczhu@microsoft.com> test: working on test cases 2 Signed-off-by: Juncheng Zhu <junczhu@microsoft.com> test: working on test cases 3 Signed-off-by: Juncheng Zhu <junczhu@microsoft.com> refactor: add cache constructor into fetcher constructor Signed-off-by: Juncheng Zhu <junczhu@microsoft.com> refactor: add cache constructor into fetcher constructor 2 Signed-off-by: Juncheng Zhu <junczhu@microsoft.com> refactor: add cache constructor into fetcher constructor 3 Signed-off-by: Juncheng Zhu <junczhu@microsoft.com> test: add cache constructor into fetcher constructor Signed-off-by: Juncheng Zhu <junczhu@microsoft.com> test: add cache constructor into fetcher constructor 2 Signed-off-by: Juncheng Zhu <junczhu@microsoft.com> feat: kmprevocationfactory impl 1 Signed-off-by: Juncheng Zhu <junczhu@microsoft.com> chore: Bump github.com/aws/aws-sdk-go-v2 from 1.32.2 to 1.32.3 (ratify-project#1912) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> chore: Bump github.com/aws/aws-sdk-go-v2/credentials from 1.17.41 to 1.17.42 (ratify-project#1911) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> chore: Bump github.com/AzureAD/microsoft-authentication-library-for-go from 1.2.2 to 1.2.3 (ratify-project#1910) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> chore: Bump anchore/sbom-action from 0.17.6 to 0.17.7 (ratify-project#1915) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> chore: Bump github.com/golang-jwt/jwt/v4 from 4.5.0 to 4.5.1 (ratify-project#1916) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> feat: support enabled status for kmp keys/certs (ratify-project#1874) Signed-off-by: Joshua Duffney <jduffney@microsoft.com> ci: add cron job to cache trivy db (ratify-project#1918) Signed-off-by: Binbin Li <libinbin@microsoft.com> fix: fix the conditional check on update-trivy-cache job (ratify-project#1919) Signed-off-by: Binbin Li <libinbin@microsoft.com> feat: add support for crl basic functionality with built-in cache (ratify-project#1890) Signed-off-by: Juncheng Zhu <junczhu@microsoft.com> Co-authored-by: Binbin Li <libinbin@microsoft.com> chore: Bump goreleaser/goreleaser-action from 6.0.0 to 6.1.0 (ratify-project#1920) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> chore: Bump github/codeql-action from 3.27.0 to 3.27.1 (ratify-project#1922) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> chore: Bump github.com/aws/aws-sdk-go-v2/credentials from 1.17.42 to 1.17.44 (ratify-project#1923) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> chore: Bump golang from `0ca97f4` to `4cfe4a9` in /httpserver (ratify-project#1925) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> chore: Bump github/codeql-action from 3.27.1 to 3.27.3 (ratify-project#1926) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> feat: support alibaba cloud rrsa store auth provider (ratify-project#1909) Signed-off-by: dahu.kdh <dahu.kdh@alibaba-inc.com> feat: kmprevocationfactory impl 3 Signed-off-by: Juncheng Zhu <junczhu@microsoft.com> feat: kmprevocationfactory impl Signed-off-by: Juncheng Zhu <junczhu@microsoft.com> feat: kmprevocationfactory impl 2 Signed-off-by: Juncheng Zhu <junczhu@microsoft.com> feat: kmprevocationfactory impl 3 Signed-off-by: Juncheng Zhu <junczhu@microsoft.com> feat: kmprevocationfactory impl 4 Signed-off-by: Juncheng Zhu <junczhu@microsoft.com> feat: kmprevocationfactory impl 5 Signed-off-by: Juncheng Zhu <junczhu@microsoft.com> chore: kmprevocationfactory reform Signed-off-by: Juncheng Zhu <junczhu@microsoft.com> feat: update implementations Signed-off-by: Juncheng Zhu <junczhu@microsoft.com> feat: update implementations 2 Signed-off-by: Juncheng Zhu <junczhu@microsoft.com> feat: update implementations 3 Signed-off-by: Juncheng Zhu <junczhu@microsoft.com> feat: update implementations 4 Signed-off-by: Juncheng Zhu <junczhu@microsoft.com> feat: update implementations 5 Signed-off-by: Juncheng Zhu <junczhu@microsoft.com> feat: update implementations 6 Signed-off-by: Juncheng Zhu <junczhu@microsoft.com> feat: update implementations 7 Signed-off-by: Juncheng Zhu <junczhu@microsoft.com> feat: update implementations 8 Signed-off-by: Juncheng Zhu <junczhu@microsoft.com> chore: Bump github/codeql-action from 3.27.3 to 3.27.4 (ratify-project#1929) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> chore: Bump alpine from `beefdbd` to `1e42bbe` (ratify-project#1937) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> chore: Bump golang from `4cfe4a9` to `147f428` in /httpserver (ratify-project#1936) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> chore: Bump distroless/static from `3a03fc0` to `d71f4b2` in /httpserver (ratify-project#1935) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> chore: Bump github.com/aliyun/credentials-go from 1.3.10 to 1.3.11 (ratify-project#1934) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> chore: Bump github.com/aws/aws-sdk-go-v2/credentials from 1.17.44 to 1.17.45 (ratify-project#1933) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> chore: Bump codecov/codecov-action from 4.6.0 to 5.0.2 (ratify-project#1932) Signed-off-by: dependabot[bot] <support@github.com> chore: Replace deprecated autorest SDK with azidentity (ratify-project#1904) Signed-off-by: Shahram Kalantari <shahramk@gmail.com> chore: Bump step-security/harden-runner from 2.10.1 to 2.10.2 (ratify-project#1938) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> chore: Bump codecov/codecov-action from 5.0.2 to 5.0.4 (ratify-project#1939) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> chore: Bump codecov/codecov-action from 5.0.4 to 5.0.7 (ratify-project#1946) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> chore: Bump github/codeql-action from 3.27.4 to 3.27.5 (ratify-project#1945) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> chore: Bump anchore/sbom-action from 0.17.7 to 0.17.8 (ratify-project#1948) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> chore: Bump github.com/aws/aws-sdk-go-v2/credentials from 1.17.45 to 1.17.46 (ratify-project#1953) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> fix: add missing pod annotations and labels to deployment spec (ratify-project#1949) Signed-off-by: akashsinghal <akashsinghal@microsoft.com> chore: revert changes in AKV KMP provider Signed-off-by: Juncheng Zhu <junczhu@microsoft.com> chore: add more comments Signed-off-by: Juncheng Zhu <junczhu@microsoft.com> chore: add more comments and fix Signed-off-by: Juncheng Zhu <junczhu@microsoft.com> chore: update logging Signed-off-by: Juncheng Zhu <junczhu@microsoft.com> chore: update test Signed-off-by: Juncheng Zhu <junczhu@microsoft.com> chore: update test 2 Signed-off-by: Juncheng Zhu <junczhu@microsoft.com> chore: limited changes 3 Signed-off-by: Juncheng Zhu <junczhu@microsoft.com> chore: more changes applied Signed-off-by: Juncheng Zhu <junczhu@microsoft.com> chore: Bump github.com/sigstore/rekor from 1.3.6 to 1.3.7 (ratify-project#1952) Signed-off-by: dependabot[bot] <support@github.com> Signed-off-by: Susan Shi <huish@microsoft.com> Signed-off-by: Binbin Li <libinbin@microsoft.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> chore: bump up golangci-lint version (ratify-project#1961) Signed-off-by: Binbin Li <libinbin050215@gmail.com> fix(tls): allowing TLS when crd-manager disabled (ratify-project#1954) Signed-off-by: Jordan Langue <jordan.langue@doctolib.com> chore: Bump github.com/aws/aws-sdk-go-v2/config from 1.28.3 to 1.28.6 (ratify-project#1957) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> chore: Bump distroless/static from `d71f4b2` to `6cd937e` in /httpserver (ratify-project#1960) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> chore: fix go-lint Signed-off-by: Juncheng Zhu <junczhu@microsoft.com> chore: improve codecov Signed-off-by: Juncheng Zhu <junczhu@microsoft.com> chore: fix golint Signed-off-by: Juncheng Zhu <junczhu@microsoft.com> chore: remove the CRL Cache in truststore Signed-off-by: Juncheng Zhu <junczhu@microsoft.com> chore: renaming func Signed-off-by: Juncheng Zhu <junczhu@microsoft.com> chore: fix 1 Signed-off-by: Juncheng Zhu <junczhu@microsoft.com> chore: fix 2 Signed-off-by: Juncheng Zhu <junczhu@microsoft.com> chore: Bump github/codeql-action from 3.27.5 to 3.27.6 (ratify-project#1963) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> chore: add more test case Signed-off-by: Juncheng Zhu <junczhu@microsoft.com> chore: fix golint Signed-off-by: Juncheng Zhu <junczhu@microsoft.com> chore: fix codecov Signed-off-by: Juncheng Zhu <junczhu@microsoft.com> chore: fix context reference Signed-off-by: Juncheng Zhu <junczhu@microsoft.com> chore: fix golint Signed-off-by: Juncheng Zhu <junczhu@microsoft.com> build: add image signing for all release images (ratify-project#1947) Signed-off-by: Akash Singhal <akashsinghal@microsoft.com> chore: Bump golang from `73f06be` to `574185e` in /httpserver (ratify-project#1973) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
- Loading branch information