Releases: chainguard-dev/melange
Releases · chainguard-dev/melange
Release v0.30.3
What's Changed
Full Changelog: v0.30.2...v0.30.3
Release v0.30.2
What's Changed
- Use https://mirrors.ocf.berkeley.edu whenever applicable for GNU programs by @sergiodj in #2073
- build(deps): bump github.com/docker/docker from 28.3.2+incompatible to 28.3.3+incompatible in the go_modules group by @dependabot[bot] in #2108
- Don't --require-zero in CI scan by @jonjohnsonjr in #2112
- Improve SCA handling of bogus shlib dependencies by @sergiodj in #2109
- Bump apko to v0.30.2 and handle field rename by @kevinmdavis in #2111
New Contributors
- @kevinmdavis made their first contribution in #2111
Full Changelog: v0.30.1...v0.30.2
Release v0.30.1
What's Changed
- Expand check for libraries provided by the host by @murraybd in #2077
- SCA: Generate
depends
for shlibs ending in.so
by @sergiodj in #2072 - Do not require .so files to be executable by @murraybd in #2099
- sbom: populate supplier for operating system package by @imjasonh in #2101
Full Changelog: v0.30.0...v0.30.1
Release v0.30.0
What's Changed
- feat(sbom): Include the distro qualifier as part of the APK PURL by @pdeslaur in #2078
- Use session.Run instead of session.Shell by @egibs in #2100
Full Changelog: v0.29.7...v0.30.0
Release v0.29.7
What's Changed
- build(deps): bump sigs.k8s.io/release-utils from 0.11.1 to 0.12.0 by @dependabot[bot] in #2095
- Revert changes related to "avoid SSH lockups, use script for tests" by @sil2100 in #2096
Full Changelog: v0.29.6...v0.29.7
Release v0.29.6
What's Changed
- Upgrade apko to v0.29.4 by @markusthoemmes in #2084
- build(deps): bump the actions group across 1 directory with 2 updates by @dependabot[bot] in #2054
- build(deps): bump the gomod group across 1 directory with 6 updates by @dependabot[bot] in #2087
- build(deps): bump github.com/docker/docker from 28.2.2+incompatible to 28.3.2+incompatible by @dependabot[bot] in #2088
- build(deps): bump go.opentelemetry.io/otel/exporters/stdout/stdouttrace from 1.36.0 to 1.37.0 by @dependabot[bot] in #2092
- build(deps): bump sigs.k8s.io/yaml from 1.4.0 to 1.5.0 by @dependabot[bot] in #2089
- build(deps): bump github.com/moby/moby from 28.0.4+incompatible to 28.3.2+incompatible by @dependabot[bot] in #2091
- build(deps): bump mvdan.cc/sh/v3 from 3.11.0 to 3.12.0 by @dependabot[bot] in #2090
Full Changelog: v0.29.5...v0.29.6
Release v0.29.5
What's Changed
Full Changelog: v0.29.4...v0.29.5
Release v0.29.4
What's Changed
- chore(pipelines/cargo): add parallel jobs input by @maxgio92 in #2083
- Revert "Use os.DirFS over apkofs.DirFS" by @markusthoemmes in #2085
New Contributors
- @markusthoemmes made their first contribution in #2085
Full Changelog: v0.29.3...v0.29.4
Release v0.29.3
What's Changed
- config: use supplier for namespace for unknown gits by @javacruft in #2081
- Include top-level environment variables in tests by @egibs in #2080
- Use os.DirFS over apkofs.DirFS by @jonjohnsonjr in #2079
Full Changelog: v0.29.2...v0.29.3