Commit Graph
904 Commits
Author SHA1 Message Date
dependabot[bot] e9988e48fb Bump github.com/sigstore/cosign/v2 from 2.1.0 to 2.1.1
Bumps [github.com/sigstore/cosign/v2](https://github.com/sigstore/cosign) from 2.1.0 to 2.1.1.
- [Release notes](https://github.com/sigstore/cosign/releases)
- [Changelog](https://github.com/sigstore/cosign/blob/main/CHANGELOG.md)
- [Commits](https://github.com/sigstore/cosign/compare/v2.1.0...v2.1.1)

---
updated-dependencies:
- dependency-name: github.com/sigstore/cosign/v2
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2023-07-03 01:13:20 +00:00
dependabot[bot] 8adc093bb0 Bump sigstore/cosign-installer from 3.1.0 to 3.1.1
Bumps [sigstore/cosign-installer](https://github.com/sigstore/cosign-installer) from 3.1.0 to 3.1.1.
- [Release notes](https://github.com/sigstore/cosign-installer/releases)
- [Commits](https://github.com/sigstore/cosign-installer/compare/d13028333d784fcc802b67ec924bcebe75aa0a5f...6e04d228eb30da1757ee4e1dd75a0ec73a653e06)

---
updated-dependencies:
- dependency-name: sigstore/cosign-installer
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2023-07-03 01:08:32 +00:00
Carlos Tadeu Panato Junior 1586ee4292 Merge pull request #1084 from ko-build/dependabot/github_actions/sigstore/cosign-installer-3.1.0
Bump sigstore/cosign-installer from 3.0.5 to 3.1.0
2023-06-26 08:43:16 +02:00
Carlos Tadeu Panato Junior 8d6741b01f Merge pull request #1083 from ko-build/dependabot/github_actions/reviewdog/action-misspell-1.13.1 2023-06-26 07:28:15 +02:00
Carlos Tadeu Panato Junior 851dbdd969 Merge pull request #1085 from ko-build/dependabot/go_modules/github.com/sigstore/cosign/v2-2.1.0 2023-06-26 07:27:47 +02:00
dependabot[bot] 7d678ca5ff Bump github.com/sigstore/cosign/v2
Bumps [github.com/sigstore/cosign/v2](https://github.com/sigstore/cosign) from 2.0.3-0.20230523133326-0544abd8fc8a to 2.1.0.
- [Release notes](https://github.com/sigstore/cosign/releases)
- [Changelog](https://github.com/sigstore/cosign/blob/main/CHANGELOG.md)
- [Commits](https://github.com/sigstore/cosign/commits/v2.1.0)

---
updated-dependencies:
- dependency-name: github.com/sigstore/cosign/v2
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2023-06-26 01:31:56 +00:00
dependabot[bot] a2179e3c82 Bump sigstore/cosign-installer from 3.0.5 to 3.1.0
Bumps [sigstore/cosign-installer](https://github.com/sigstore/cosign-installer) from 3.0.5 to 3.1.0.
- [Release notes](https://github.com/sigstore/cosign-installer/releases)
- [Commits](https://github.com/sigstore/cosign-installer/compare/dd6b2e2b610a11fd73dd187a43d57cc1394e35f9...d13028333d784fcc802b67ec924bcebe75aa0a5f)

---
updated-dependencies:
- dependency-name: sigstore/cosign-installer
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2023-06-26 01:30:43 +00:00
dependabot[bot] f9ad156928 Bump reviewdog/action-misspell from 1.12.4 to 1.13.1
Bumps [reviewdog/action-misspell](https://github.com/reviewdog/action-misspell) from 1.12.4 to 1.13.1.
- [Release notes](https://github.com/reviewdog/action-misspell/releases)
- [Commits](https://github.com/reviewdog/action-misspell/compare/ccb0441a34ac2a3ece1206c63d7b6dd757ffde4d...9257f108197b44e37995c98bea6ee4a5b9ffc3b0)

---
updated-dependencies:
- dependency-name: reviewdog/action-misspell
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2023-06-26 01:30:37 +00:00
Jon Johnson 200db7243f Pin setup-ko to previous release (#1082) v0.14.1 2023-06-20 15:13:15 -04:00
Carlos Tadeu Panato Junior 4366ded82c Merge pull request #1079 from ko-build/dependabot/github_actions/slsa-framework/slsa-github-generator-1.7.0
Bump slsa-framework/slsa-github-generator from 1.6.0 to 1.7.0
v0.14.0
2023-06-20 19:52:17 +02:00
Carlos Tadeu Panato Junior adbea950c1 Merge pull request #1078 from ko-build/dependabot/github_actions/goreleaser/goreleaser-action-4.3.0
Bump goreleaser/goreleaser-action from 4.2.0 to 4.3.0
2023-06-20 19:51:55 +02:00
Carlos Tadeu Panato Junior 6175237fe6 Merge pull request #1077 from ko-build/dependabot/go_modules/github.com/spf13/viper-1.16.0
Bump github.com/spf13/viper from 1.15.0 to 1.16.0
2023-06-20 19:51:37 +02:00
Carlos Tadeu Panato Junior 5e5fe2e703 Merge pull request #1076 from ko-build/dependabot/github_actions/aws-actions/configure-aws-credentials-2.2.0
Bump aws-actions/configure-aws-credentials from 2.1.0 to 2.2.0
2023-06-20 19:51:02 +02:00
dependabot[bot] dc9b3eebef Bump github.com/spf13/viper from 1.15.0 to 1.16.0
Bumps [github.com/spf13/viper](https://github.com/spf13/viper) from 1.15.0 to 1.16.0.
- [Release notes](https://github.com/spf13/viper/releases)
- [Commits](https://github.com/spf13/viper/compare/v1.15.0...v1.16.0)

---
updated-dependencies:
- dependency-name: github.com/spf13/viper
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2023-06-20 17:15:34 +00:00
dependabot[bot] ed445128e2 Bump golang.org/x/tools from 0.9.3 to 0.10.0 (#1080)
Bumps [golang.org/x/tools](https://github.com/golang/tools) from 0.9.3 to 0.10.0.
- [Release notes](https://github.com/golang/tools/releases)
- [Commits](https://github.com/golang/tools/compare/v0.9.3...v0.10.0)

---
updated-dependencies:
- dependency-name: golang.org/x/tools
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-06-20 10:07:47 -07:00
dependabot[bot] fcd95ec958 Bump slsa-framework/slsa-github-generator from 1.6.0 to 1.7.0
Bumps [slsa-framework/slsa-github-generator](https://github.com/slsa-framework/slsa-github-generator) from 1.6.0 to 1.7.0.
- [Release notes](https://github.com/slsa-framework/slsa-github-generator/releases)
- [Changelog](https://github.com/slsa-framework/slsa-github-generator/blob/main/CHANGELOG.md)
- [Commits](https://github.com/slsa-framework/slsa-github-generator/compare/v1.6.0...v1.7.0)

---
updated-dependencies:
- dependency-name: slsa-framework/slsa-github-generator
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2023-06-19 02:00:16 +00:00
dependabot[bot] 974f09cdea Bump goreleaser/goreleaser-action from 4.2.0 to 4.3.0
Bumps [goreleaser/goreleaser-action](https://github.com/goreleaser/goreleaser-action) from 4.2.0 to 4.3.0.
- [Release notes](https://github.com/goreleaser/goreleaser-action/releases)
- [Commits](https://github.com/goreleaser/goreleaser-action/compare/f82d6c1c344bcacabba2c841718984797f664a6b...336e29918d653399e599bfca99fadc1d7ffbc9f7)

---
updated-dependencies:
- dependency-name: goreleaser/goreleaser-action
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2023-06-19 02:00:04 +00:00
dependabot[bot] 893f6e877f Bump aws-actions/configure-aws-credentials from 2.1.0 to 2.2.0
Bumps [aws-actions/configure-aws-credentials](https://github.com/aws-actions/configure-aws-credentials) from 2.1.0 to 2.2.0.
- [Release notes](https://github.com/aws-actions/configure-aws-credentials/releases)
- [Changelog](https://github.com/aws-actions/configure-aws-credentials/blob/main/CHANGELOG.md)
- [Commits](https://github.com/aws-actions/configure-aws-credentials/compare/5727f247b64f324ec403ac56ae05e220fd02b65f...5fd3084fc36e372ff1fff382a39b10d03659f355)

---
updated-dependencies:
- dependency-name: aws-actions/configure-aws-credentials
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2023-06-19 01:59:56 +00:00
Carlos Tadeu Panato Junior b4ee3f399a Merge pull request #1075 from ko-build/dependabot/go_modules/sigs.k8s.io/kind-0.20.0
Bump sigs.k8s.io/kind from 0.18.0 to 0.20.0
2023-06-16 16:57:07 +02:00
dependabot[bot] d43ae39985 Bump sigs.k8s.io/kind from 0.18.0 to 0.20.0
Bumps [sigs.k8s.io/kind](https://github.com/kubernetes-sigs/kind) from 0.18.0 to 0.20.0.
- [Release notes](https://github.com/kubernetes-sigs/kind/releases)
- [Commits](https://github.com/kubernetes-sigs/kind/compare/v0.18.0...v0.20.0)

---
updated-dependencies:
- dependency-name: sigs.k8s.io/kind
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2023-06-16 14:39:36 +00:00
Carlos Tadeu Panato Junior cb65a2db8e Merge pull request #1074 from ko-build/dependabot/go_modules/k8s.io/apimachinery-0.27.3
Bump k8s.io/apimachinery from 0.27.1 to 0.27.3
2023-06-16 16:38:22 +02:00
dependabot[bot] 737e8c50c3 Bump k8s.io/apimachinery from 0.27.1 to 0.27.3
Bumps [k8s.io/apimachinery](https://github.com/kubernetes/apimachinery) from 0.27.1 to 0.27.3.
- [Commits](https://github.com/kubernetes/apimachinery/compare/v0.27.1...v0.27.3)

---
updated-dependencies:
- dependency-name: k8s.io/apimachinery
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2023-06-16 14:19:53 +00:00
Carlos Tadeu Panato Junior d5ae2beb7c Merge pull request #1067 from ko-build/dependabot/github_actions/aws-actions/configure-aws-credentials-2.1.0
Bump aws-actions/configure-aws-credentials from 2.0.0 to 2.1.0
2023-06-16 16:18:02 +02:00
Carlos Tadeu Panato Junior 3bc31c3c7d Merge pull request #1064 from ko-build/dependabot/go_modules/github.com/docker/docker-24.0.2incompatible
Bump github.com/docker/docker from 23.0.5+incompatible to 24.0.2+incompatible
2023-06-16 16:17:15 +02:00
Carlos Tadeu Panato Junior ebd9622d7b Merge pull request #1059 from ko-build/dependabot/github_actions/codecov/codecov-action-3.1.4
Bump codecov/codecov-action from 3.1.3 to 3.1.4
2023-06-16 16:16:11 +02:00
dependabot[bot] e4cc398651 Bump codecov/codecov-action from 3.1.3 to 3.1.4
Bumps [codecov/codecov-action](https://github.com/codecov/codecov-action) from 3.1.3 to 3.1.4.
- [Release notes](https://github.com/codecov/codecov-action/releases)
- [Changelog](https://github.com/codecov/codecov-action/blob/main/CHANGELOG.md)
- [Commits](https://github.com/codecov/codecov-action/compare/894ff025c7b54547a9a2a1e9f228beae737ad3c2...eaaf4bedf32dbdc6b720b63067d99c4d77d6047d)

---
updated-dependencies:
- dependency-name: codecov/codecov-action
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2023-06-16 14:00:58 +00:00
Carlos Tadeu Panato Junior 4f5f0771a9 Merge pull request #1069 from ko-build/dependabot/go_modules/golang.org/x/tools-0.9.3
Bump golang.org/x/tools from 0.8.0 to 0.9.3
2023-06-16 15:51:38 +02:00
Carlos Tadeu Panato Junior 6571bb7f03 Merge pull request #1070 from ko-build/dependabot/github_actions/actions/checkout-3.5.3
Bump actions/checkout from 3.5.2 to 3.5.3
2023-06-16 15:46:23 +02:00
Carlos Tadeu Panato Junior 4f56dd2dd0 Merge pull request #1071 from ko-build/dependabot/github_actions/github/codeql-action-2.13.4
Bump github/codeql-action from 2.3.3 to 2.13.4
2023-06-16 15:42:44 +02:00
Dan Luhring fe567ef66d Bump rekor module to mitigate vulnerability (#1073)
Signed-off-by: Dan Luhring <dluhring@chainguard.dev>
2023-06-15 19:22:12 +00:00
dependabot[bot] 5b728d3dcf Bump github/codeql-action from 2.3.3 to 2.13.4
Bumps [github/codeql-action](https://github.com/github/codeql-action) from 2.3.3 to 2.13.4.
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](https://github.com/github/codeql-action/compare/29b1f65c5e92e24fe6b6647da1eaabe529cec70f...cdcdbb579706841c47f7063dda365e292e5cad7a)

---
updated-dependencies:
- dependency-name: github/codeql-action
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2023-06-12 01:59:20 +00:00
dependabot[bot] 16e535ef37 Bump actions/checkout from 3.5.2 to 3.5.3
Bumps [actions/checkout](https://github.com/actions/checkout) from 3.5.2 to 3.5.3.
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](https://github.com/actions/checkout/compare/8e5e7e5ab8b370d6c329ec480221332ada57f0ab...c85c95e3d7251135ab7dc9ce3241c5835cc595a9)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2023-06-12 01:59:14 +00:00
Carlos Tadeu Panato Junior 2b8ee98d2d update boilerplate file to be KO Build Authors (#1056) 2023-06-09 10:48:00 -04:00
dependabot[bot] 19e90d8d88 Bump golang.org/x/tools from 0.8.0 to 0.9.3
Bumps [golang.org/x/tools](https://github.com/golang/tools) from 0.8.0 to 0.9.3.
- [Release notes](https://github.com/golang/tools/releases)
- [Commits](https://github.com/golang/tools/compare/v0.8.0...v0.9.3)

---
updated-dependencies:
- dependency-name: golang.org/x/tools
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2023-06-05 02:02:31 +00:00
dependabot[bot] f238017d50 Bump aws-actions/configure-aws-credentials from 2.0.0 to 2.1.0
Bumps [aws-actions/configure-aws-credentials](https://github.com/aws-actions/configure-aws-credentials) from 2.0.0 to 2.1.0.
- [Release notes](https://github.com/aws-actions/configure-aws-credentials/releases)
- [Changelog](https://github.com/aws-actions/configure-aws-credentials/blob/main/CHANGELOG.md)
- [Commits](https://github.com/aws-actions/configure-aws-credentials/compare/e1e17a757e536f70e52b5a12b2e8d1d1c60e04ef...5727f247b64f324ec403ac56ae05e220fd02b65f)

---
updated-dependencies:
- dependency-name: aws-actions/configure-aws-credentials
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2023-06-05 02:00:34 +00:00
dependabot[bot] eb647c05d4 Bump actions/setup-python from 4.6.0 to 4.6.1 (#1061)
Bumps [actions/setup-python](https://github.com/actions/setup-python) from 4.6.0 to 4.6.1.
- [Release notes](https://github.com/actions/setup-python/releases)
- [Commits](https://github.com/actions/setup-python/compare/57ded4d7d5e986d7296eab16560982c6dd7c923b...bd6b4b6205c4dbad673328db7b31b7fab9e241c0)

---
updated-dependencies:
- dependency-name: actions/setup-python
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-05-30 15:21:13 -04:00
dependabot[bot] a258d6a581 Bump github.com/docker/docker
Bumps [github.com/docker/docker](https://github.com/docker/docker) from 23.0.5+incompatible to 24.0.2+incompatible.
- [Release notes](https://github.com/docker/docker/releases)
- [Commits](https://github.com/docker/docker/compare/v23.0.5...v24.0.2)

---
updated-dependencies:
- dependency-name: github.com/docker/docker
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
2023-05-29 02:05:39 +00:00
dependabot[bot] ccc06273a1 Bump slsa-framework/slsa-github-generator from 1.5.0 to 1.6.0 (#1046)
Bumps [slsa-framework/slsa-github-generator](https://github.com/slsa-framework/slsa-github-generator) from 1.5.0 to 1.6.0.
- [Release notes](https://github.com/slsa-framework/slsa-github-generator/releases)
- [Changelog](https://github.com/slsa-framework/slsa-github-generator/blob/main/CHANGELOG.md)
- [Commits](https://github.com/slsa-framework/slsa-github-generator/compare/v1.5.0...v1.6.0)

---
updated-dependencies:
- dependency-name: slsa-framework/slsa-github-generator
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-05-23 15:46:13 -04:00
dependabot[bot] 77e6ce1cbb Bump github/codeql-action from 2.3.2 to 2.3.3 (#1041)
Bumps [github/codeql-action](https://github.com/github/codeql-action) from 2.3.2 to 2.3.3.
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](https://github.com/github/codeql-action/compare/f3feb00acb00f31a6f60280e6ace9ca31d91c76a...29b1f65c5e92e24fe6b6647da1eaabe529cec70f)

---
updated-dependencies:
- dependency-name: github/codeql-action
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-05-23 15:45:50 -04:00
Jason Hall 938893aedb bump ggcr dependency, and cosign dep (#1053)
Signed-off-by: Jason Hall <jason@chainguard.dev>
2023-05-23 09:26:47 -07:00
Jason Hall 27ca485d0b Revert "Fix kind image loading for MacOS (#1026)" (#1054)
This reverts commit a46638e296.
2023-05-23 08:14:15 -07:00
Adrian Lai a46638e296 Fix kind image loading for MacOS (#1026)
See: https://github.com/kubernetes-sigs/kind/pull/2957
2023-05-23 14:43:14 +00:00
dependabot[bot] 86787bdf54 Bump actions/setup-go from 4.0.0 to 4.0.1 (#1050)
Bumps [actions/setup-go](https://github.com/actions/setup-go) from 4.0.0 to 4.0.1.
- [Release notes](https://github.com/actions/setup-go/releases)
- [Commits](https://github.com/actions/setup-go/compare/4d34df0c2316fe8122ab82dc22947d607c0c91f9...fac708d6674e30b6ba41289acaab6d4b75aa0753)

---
updated-dependencies:
- dependency-name: actions/setup-go
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-05-23 10:23:44 -04:00
dependabot[bot] b1d84c6222 Bump sigstore/cosign-installer from 3.0.3 to 3.0.5 (#1051)
Bumps [sigstore/cosign-installer](https://github.com/sigstore/cosign-installer) from 3.0.3 to 3.0.5.
- [Release notes](https://github.com/sigstore/cosign-installer/releases)
- [Commits](https://github.com/sigstore/cosign-installer/compare/204a51a57a74d190b284a0ce69b44bc37201f343...dd6b2e2b610a11fd73dd187a43d57cc1394e35f9)

---
updated-dependencies:
- dependency-name: sigstore/cosign-installer
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-05-23 10:23:32 -04:00
dependabot[bot] 7b62c26380 Bump reviewdog/action-misspell from 1.12.3 to 1.12.4 (#1047)
Bumps [reviewdog/action-misspell](https://github.com/reviewdog/action-misspell) from 1.12.3 to 1.12.4.
- [Release notes](https://github.com/reviewdog/action-misspell/releases)
- [Commits](https://github.com/reviewdog/action-misspell/compare/fe8d5c98c3761ef40755a7bb95460b2a33f6b346...ccb0441a34ac2a3ece1206c63d7b6dd757ffde4d)

---
updated-dependencies:
- dependency-name: reviewdog/action-misspell
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-05-23 10:23:23 -04:00
Jason Hall d59ec624fb Update community.md (#1037) 2023-05-20 08:12:05 -04:00
Jason Hall cbb93deee1 mention ko tekton task (#1039) 2023-05-08 11:03:31 -07:00
Jason Hall 175820e4c5 Update community.md (#1035)
* Update community.md

* Update community.md

* Update community.md

* Update community.md
2023-05-03 16:14:14 -04:00
dependabot[bot] 8f1ea0b20f Bump github.com/opencontainers/image-spec from 1.1.0-rc2 to 1.1.0-rc.3 (#1034)
Bumps [github.com/opencontainers/image-spec](https://github.com/opencontainers/image-spec) from 1.1.0-rc2 to 1.1.0-rc.3.
- [Release notes](https://github.com/opencontainers/image-spec/releases)
- [Changelog](https://github.com/opencontainers/image-spec/blob/main/RELEASES.md)
- [Commits](https://github.com/opencontainers/image-spec/compare/v1.1.0-rc2...v1.1.0-rc3)

---
updated-dependencies:
- dependency-name: github.com/opencontainers/image-spec
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-05-03 13:24:16 -04:00
Matt Moore c6dc504a60 Fix: Incorporate platform architecture (#1029)
🐛 Right now `--sbom-dir` with a multi-arch build just writes the same file over and over.

This loosely follows the lead of apko which uses the form `sbom-{arch}.{form}.json`, but we are going with: `{app}-{platform}.{form}.json`.

It is notable that `{platform}` is a superset of `{arch}` and we sanitize the string encoding replacing the `/` and `:` characters with `-`.

/kind bug
2023-05-01 10:32:09 -04:00