1
0
mirror of https://github.com/goreleaser/goreleaser.git synced 2024-12-31 01:53:50 +02:00
Commit Graph

62 Commits

Author SHA1 Message Date
Carlos Alexandro Becker
84d0bfef74
fix(deps): update cosign to v1.12.1 (#3403)
Signed-off-by: Carlos A Becker <caarlos0@users.noreply.github.com>

Signed-off-by: Carlos A Becker <caarlos0@users.noreply.github.com>
2022-09-26 10:25:27 -03:00
Carlos Alexandro Becker
69e9b2b120
fix: update cosign in docker img to 1.12.0 (#3379)
fix for
https://github.com/sigstore/cosign/security/advisories/GHSA-8gw7-4j42-w388

Signed-off-by: Carlos A Becker <caarlos0@users.noreply.github.com>
2022-09-15 19:39:51 +03:00
dependabot[bot]
c7bb924e44
fix(deps): bump golang from 1.19.0-alpine to 1.19.1-alpine (#3355)
Bumps golang from 1.19.0-alpine to 1.19.1-alpine.


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=golang&package-manager=docker&previous-version=1.19.0-alpine&new-version=1.19.1-alpine)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot squash and merge` will squash and merge this PR after
your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge
and block automerging
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot close` will close this PR and stop Dependabot recreating
it. You can achieve the same result by closing it manually
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2022-09-11 15:38:45 -03:00
Carlos A Becker
4a67c765af
feat(deps): update cosign to 1.11.1
Signed-off-by: Carlos A Becker <caarlos0@users.noreply.github.com>
2022-08-28 10:55:22 -03:00
dependabot[bot]
1be5baed36
feat(deps): bump golang from f8e128f to 0eb08c8 (#3301)
Bumps golang from `f8e128f` to `0eb08c8`.

---
updated-dependencies:
- dependency-name: golang
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>

Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2022-08-10 09:40:49 -03:00
dependabot[bot]
f71230272b
feat(deps): bump golang from 0e78fc1 to f8e128f (#3288)
Bumps golang from `0e78fc1` to `f8e128f`.

---
updated-dependencies:
- dependency-name: golang
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>

Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2022-08-04 15:45:09 -03:00
dependabot[bot]
631003e1fe
feat(deps): bump golang from 1.18.5-alpine to 1.19.0-alpine (#3281)
Bumps golang from 1.18.5-alpine to 1.19.0-alpine.

---
updated-dependencies:
- dependency-name: golang
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>

Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2022-08-03 09:37:39 -03:00
dependabot[bot]
171f53218a
feat(deps): bump golang from 1.18.4-alpine to 1.18.5-alpine (#3276)
Bumps golang from 1.18.4-alpine to 1.18.5-alpine.

---
updated-dependencies:
- dependency-name: golang
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>

Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2022-08-02 09:11:20 -03:00
dependabot[bot]
daf88f6c80
feat(deps): bump golang from d84b1ff to af22f4a (#3264)
Bumps golang from `d84b1ff` to `af22f4a`.

---
updated-dependencies:
- dependency-name: golang
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>

Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2022-07-28 09:23:56 -03:00
dependabot[bot]
0a30706297
feat(deps): bump golang from c9a9074 to d84b1ff (#3253)
Bumps golang from `c9a9074` to `d84b1ff`.

---
updated-dependencies:
- dependency-name: golang
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>

Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2022-07-26 09:32:29 -03:00
Carlos Alexandro Becker
5e0f345e1b
feat(deps): update cosign to 1.10.0 (#3247)
* feat(deps): update cosign to 1.9.0

Signed-off-by: Carlos A Becker <caarlos0@users.noreply.github.com>

* fix: 1.10

Signed-off-by: Carlos A Becker <caarlos0@users.noreply.github.com>
2022-07-22 11:34:56 -03:00
dependabot[bot]
dccce660cb
feat(deps): bump golang from 1.18.3-alpine to 1.18.4-alpine (#3237)
Bumps golang from 1.18.3-alpine to 1.18.4-alpine.

---
updated-dependencies:
- dependency-name: golang
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>

Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2022-07-22 11:10:35 -03:00
dependabot[bot]
5fcc52118a
feat(deps): bump golang from 1.18.2-alpine to 1.18.3-alpine (#3142)
Bumps golang from 1.18.2-alpine to 1.18.3-alpine.

---
updated-dependencies:
- dependency-name: golang
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>

Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2022-06-02 09:02:42 -03:00
dependabot[bot]
a5ef8e3cc2
feat(deps): bump golang from 1.18.1-alpine to 1.18.2-alpine (#3097)
Bumps golang from 1.18.1-alpine to 1.18.2-alpine.

---
updated-dependencies:
- dependency-name: golang
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>

Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2022-05-11 10:17:31 -03:00
Carlos Alexandro Becker
e31c49d4f6
feat: adds openssh-client to docker images (#3077)
closes #3076

Signed-off-by: Carlos A Becker <caarlos0@gmail.com>
2022-04-29 09:32:24 -03:00
Carlos A Becker
bac1ce288b
feat(deps): update docker image cosign version
Update to v1.7.2

Signed-off-by: Carlos A Becker <caarlos0@gmail.com>
2022-04-13 23:59:15 -03:00
Naveen
09c622c226
feat: pin base docker image by sha (#3038)
Pinned dependencies reduce several security risks:

They ensure that checking and deployment are all done with the same software, reducing deployment risks, simplifying debugging, and enabling reproducibility.
They can help mitigate compromised dependencies from undermining the security of the project (in the case where you've evaluated
2022-04-13 15:38:11 -03:00
dependabot[bot]
4ab2fbfa22
feat(deps): bump golang from 1.18-alpine to 1.18.1-alpine (#3035)
Bumps golang from 1.18-alpine to 1.18.1-alpine.

---
updated-dependencies:
- dependency-name: golang
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>

Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2022-04-13 09:38:07 -03:00
Carlos Alexandro Becker
3c4e797150
feat: upgrade to go 1.18 (#2978)
* feat: upgrade to go 1.18

* chore: go mod tidy

Signed-off-by: Carlos A Becker <caarlos0@gmail.com>

* test: fix

* fix: more updates

* test: fix test
2022-03-16 21:51:48 -03:00
dependabot[bot]
31212ad87d
feat(deps): bump golang from 1.17.7-alpine to 1.17.8-alpine (#2963) 2022-03-07 07:15:56 -03:00
Carlos Alexandro Becker
27db17e9f3
feat: update docker image's cosign (#2906)
update from v1.4.1 to v1.5.1

cc/ @cpanato

Signed-off-by: Carlos A Becker <caarlos0@gmail.com>
2022-02-13 14:27:09 -03:00
Yann Hamon
9bcbaac264
feat: adds gpg to Docker image for signing of artifacts (#2905) 2022-02-13 13:37:38 -03:00
dependabot[bot]
03f8fb05be
feat(deps): bump golang from 1.17.6-alpine to 1.17.7-alpine (#2900)
Bumps golang from 1.17.6-alpine to 1.17.7-alpine.

---
updated-dependencies:
- dependency-name: golang
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>

Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2022-02-12 00:30:40 -03:00
dependabot[bot]
35b439a28a
feat(deps): bump golang from 1.17.5-alpine to 1.17.6-alpine (#2812)
Bumps golang from 1.17.5-alpine to 1.17.6-alpine.

---
updated-dependencies:
- dependency-name: golang
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>

Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2022-01-07 09:16:44 -03:00
Carlos A Becker
86a6687f9c
fix: update cosign to v1.4.1
Signed-off-by: Carlos A Becker <caarlos0@gmail.com>
2021-12-12 00:06:14 -03:00
dependabot[bot]
348d208cf3
feat(deps): bump golang from 1.17.4-alpine to 1.17.5-alpine (#2753)
Bumps golang from 1.17.4-alpine to 1.17.5-alpine.

---
updated-dependencies:
- dependency-name: golang
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>

Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2021-12-11 21:25:02 -03:00
dependabot[bot]
03e558f6e0
feat(deps): bump golang from 1.17.3-alpine to 1.17.4-alpine (#2736)
Bumps golang from 1.17.3-alpine to 1.17.4-alpine.

---
updated-dependencies:
- dependency-name: golang
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>

Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2021-12-06 09:24:55 -03:00
Carlos A Becker
0e964a134a
fix: cosign is on /ko-app
after looking into it with docker inspect, it seem the binary is actually on /ko-app instead of /bin.

build was failing on master (branches are not running the whole goreleaser process rn)

cc/ @cpanato
2021-11-18 23:34:19 -03:00
Carlos Tadeu Panato Junior
a6605ad568
feat: add cosign tool in the goreleaser image (#2542)
Signed-off-by: Carlos Panato <ctadeu@gmail.com>
2021-11-18 09:54:54 -03:00
Carlos Alexandro Becker
49b00cfbc4
fix: apk add --no-cache (#2672) 2021-11-17 15:00:10 -03:00
dependabot[bot]
a94e28b77c
feat(deps): bump golang from 1.17.2-alpine to 1.17.3-alpine (#2632)
Bumps golang from 1.17.2-alpine to 1.17.3-alpine.

---
updated-dependencies:
- dependency-name: golang
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>

Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2021-11-05 10:47:42 -03:00
dependabot[bot]
c8db72cef0
chore(deps): bump golang from 1.17.1-alpine to 1.17.2-alpine (#2568)
Bumps golang from 1.17.1-alpine to 1.17.2-alpine.

---
updated-dependencies:
- dependency-name: golang
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>

Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2021-10-08 09:41:22 -03:00
Artur Troian
de7b01eb17
feat(docker): install tini to handle Ctrl+C (#2501)
https://github.com/krallin/tini/issues/8

Signed-off-by: Artur Troian <troian.ap@gmail.com>
2021-09-21 22:17:42 -03:00
dependabot[bot]
91a8abb2e6
chore(deps): bump golang from 1.17.0-alpine to 1.17.1-alpine (#2470)
Bumps golang from 1.17.0-alpine to 1.17.1-alpine.

---
updated-dependencies:
- dependency-name: golang
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>

Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2021-09-10 10:14:11 -03:00
Carlos Alexandro Becker
dd5ccf7170
feat: use go 1.17 (#2408)
* feat: use go 1.17

Signed-off-by: Carlos Alexandro Becker <caarlos0@gmail.com>

* fix: go mod tidy

Signed-off-by: Carlos Alexandro Becker <caarlos0@gmail.com>

* test: fix failing test

Signed-off-by: Carlos Alexandro Becker <caarlos0@gmail.com>

* ci: increase lint timeout

Signed-off-by: Carlos Alexandro Becker <caarlos0@gmail.com>

* ci: increase lint timeout

Signed-off-by: Carlos Alexandro Becker <caarlos0@gmail.com>
2021-08-24 20:49:11 -03:00
dependabot[bot]
5e006eb236
chore(deps): bump golang from 1.16.7-alpine to 1.17.0-alpine (#2410)
Bumps golang from 1.16.7-alpine to 1.17.0-alpine.

---
updated-dependencies:
- dependency-name: golang
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>

Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2021-08-17 09:37:19 -03:00
dependabot[bot]
8eab9af272
chore(deps): bump golang from 1.16.6-alpine to 1.16.7-alpine (#2385)
Bumps golang from 1.16.6-alpine to 1.16.7-alpine.

---
updated-dependencies:
- dependency-name: golang
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>

Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2021-08-06 10:03:22 -03:00
msvechla
c3af58708c
feat: add docker-buildx to Docker image (#2333)
* add buildx to Docker image to support multi-arch docker builds

* add docker-cli-buildx to support multi-arch builds

Co-authored-by: Carlos Alexandro Becker <caarlos0@users.noreply.github.com>
2021-07-25 00:17:32 +00:00
dependabot[bot]
e51b6d67f5
chore(deps): bump golang from 1.16-alpine to 1.16.6-alpine (#2345)
Bumps golang from 1.16-alpine to 1.16.6-alpine.

---
updated-dependencies:
- dependency-name: golang
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>

Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2021-07-16 15:48:08 -03:00
Carlos Alexandro Becker
901af74caf fix: docker: stable image
Signed-off-by: Carlos Alexandro Becker <caarlos0@gmail.com>
2021-02-18 14:54:42 -03:00
Carlos Alexandro Becker
617bd2a24e fix: temporary use rc1 on docker image
Signed-off-by: Carlos Alexandro Becker <caarlos0@gmail.com>
2021-02-16 20:29:16 -03:00
Carlos Alexandro Becker
6b26fe4106
feat: support go 1.16 and apple silicon (#1956)
* feat: support apple silicon

Signed-off-by: Carlos Alexandro Becker <caarlos0@gmail.com>

* fix: test

Signed-off-by: Carlos Alexandro Becker <caarlos0@gmail.com>

* feat: go 1.16

Signed-off-by: Carlos Alexandro Becker <caarlos0@gmail.com>

* feat: go 1.16

Signed-off-by: Carlos Alexandro Becker <caarlos0@gmail.com>

* feat: go 1.16

Signed-off-by: Carlos Alexandro Becker <caarlos0@gmail.com>

* test: fix

Signed-off-by: Carlos Alexandro Becker <caarlos0@gmail.com>

* fix: test case

Signed-off-by: Carlos Alexandro Becker <caarlos0@gmail.com>

* Update .github/workflows/build.yml

Co-authored-by: Radek Simko <radek.simko@gmail.com>

* docs: go 1.16

Signed-off-by: Carlos Alexandro Becker <caarlos0@gmail.com>

Co-authored-by: Radek Simko <radek.simko@gmail.com>
2021-02-16 22:51:11 +00:00
Carlos Alexandro Becker
e8ea231122
feat: allow to use nfpm packages in the docker pipe (#2003)
* feat: copy nfpms to docker image too

Signed-off-by: Carlos Alexandro Becker <caarlos0@gmail.com>

* test: wip

Signed-off-by: Carlos Alexandro Becker <caarlos0@gmail.com>

* fix: logs

Signed-off-by: Carlos Alexandro Becker <caarlos0@gmail.com>

* test: fixes

Signed-off-by: Carlos Alexandro Becker <caarlos0@gmail.com>

* test: improving

Signed-off-by: Carlos Alexandro Becker <caarlos0@gmail.com>

* docs: deprecations and docker improvements

Signed-off-by: Carlos Alexandro Becker <caarlos0@gmail.com>

* fix: revert .goreleaser.yml changes

Signed-off-by: Carlos Alexandro Becker <caarlos0@gmail.com>

* test: fix

Signed-off-by: Carlos Alexandro Becker <caarlos0@gmail.com>

* docs: fix syntax

Signed-off-by: Carlos Alexandro Becker <caarlos0@gmail.com>

* docs: fixed deprecation warnings

Signed-off-by: Carlos Alexandro Becker <caarlos0@gmail.com>

* test: fix

Signed-off-by: Carlos Alexandro Becker <caarlos0@gmail.com>

* test: coverage

Signed-off-by: Carlos Alexandro Becker <caarlos0@gmail.com>

* test: add one more test case

Signed-off-by: Carlos Alexandro Becker <caarlos0@gmail.com>

* test: fix

Signed-off-by: Carlos Alexandro Becker <caarlos0@gmail.com>

* test: fix

Signed-off-by: Carlos Alexandro Becker <caarlos0@gmail.com>

Co-authored-by: kodiakhq[bot] <49736102+kodiakhq[bot]@users.noreply.github.com>
2021-01-07 19:21:12 +00:00
Carlos Alexandro Becker
93a94d1dad
chore(ci): improve dockerfile/manifest (#1974)
Signed-off-by: Carlos Alexandro Becker <caarlos0@gmail.com>
2020-12-28 17:36:57 -03:00
Carlos Alexandro Becker
3fb2366bd4
feat: install build-base on main img, drop -cgo img (#1924)
Signed-off-by: Carlos Alexandro Becker <caarlos0@gmail.com>
2020-11-28 18:04:13 -03:00
Carlos Alexandro Becker
e337fc9ca0
feat: multi-arch docker images (#1923)
* feat: multi-arch docker images

Signed-off-by: Carlos Alexandro Becker <caarlos0@gmail.com>

* feat: split files

Signed-off-by: Carlos Alexandro Becker <caarlos0@gmail.com>

* docs: manifest

Signed-off-by: Carlos Alexandro Becker <caarlos0@gmail.com>

* refactor: split files

Signed-off-by: Carlos Alexandro Becker <caarlos0@gmail.com>

* test: added some

Signed-off-by: Carlos Alexandro Becker <caarlos0@gmail.com>

* docs: flags

Signed-off-by: Carlos Alexandro Becker <caarlos0@gmail.com>

* fix: fmt

Signed-off-by: Carlos Alexandro Becker <caarlos0@gmail.com>

* fix: diff

Signed-off-by: Carlos Alexandro Becker <caarlos0@gmail.com>

* ci: enable experimental

Signed-off-by: Carlos Alexandro Becker <caarlos0@gmail.com>

* ci: multi-arch goreleaser images

Signed-off-by: Carlos Alexandro Becker <caarlos0@gmail.com>
2020-11-28 16:26:37 -03:00
Simon Jürgensmeyer
a35ab24ce6 feat: update to Go 1.15 image (#1758) 2020-08-16 11:21:56 -03:00
Igor
52e984f377
feat: Install make into docker image (#1621)
* Install make into docker image

* Whitespace
2020-06-19 10:02:01 -03:00
Carlos Alexandro Becker
fec84d9bf4
fix: docker images: bzr (#1587)
Signed-off-by: Carlos Alexandro Becker <caarlos0@gmail.com>
2020-06-04 13:38:15 +00:00
Carlos Alexandro Becker
58acbd334d
fix: cgo docker image (#1540)
Signed-off-by: Carlos Alexandro Becker <caarlos0@gmail.com>
2020-05-23 14:25:39 -03:00