lifecycle
lifecycle copied to clipboard
Reference implementation of the Cloud Native Buildpacks lifecycle
### Summary The build plan output when passing it two buildpacks does not make it clear that order can be a problem --- ### Reproduction ##### Steps ``` $ mkdir...
Bumps the go-dependencies group with 5 updates in the / directory: | Package | From | To | | --- | --- | --- | | [github.com/GoogleContainerTools/kaniko](https://github.com/GoogleContainerTools/kaniko) | `1.23.0` |...
### Summary All buildpack builders reset the mtime of all application source files to Jan 1, 1980, even if `SOURCE_DATE_EPOCH` or the pack `--creation-time` flag is set. --- ### Reproduction...
### Summary This is still somewhat a WIP - I need to update the code comments and also add unit tests, as that's a major advantage of this refactor. ####...
Bumps [actions/download-artifact](https://github.com/actions/download-artifact) from 3 to 4.1.7. Release notes Sourced from actions/download-artifact's releases. v4.1.7 What's Changed Update @actions/artifact dependency by @bethanyj28 in actions/download-artifact#325 Full Changelog: https://github.com/actions/download-artifact/compare/v4.1.6...v4.1.7 v4.1.6 What's Changed updating @actions/artifact...
Bumps the go-dependencies group with 5 updates in the / directory: | Package | From | To | | --- | --- | --- | | [github.com/GoogleContainerTools/kaniko](https://github.com/GoogleContainerTools/kaniko) | `1.23.1` |...
Bumps [anchore/scan-action](https://github.com/anchore/scan-action) from 3 to 5. Release notes Sourced from anchore/scan-action's releases. v5.0.0 New in scan-action v5.0.0 chore(deps): update Grype to v0.82.0 (#383) [anchore-actions-token-generator] 🚀 Features feat: short-lived grype-db cache...
Bumps [appleboy/ssh-action](https://github.com/appleboy/ssh-action) from 1.0.3 to 1.1.0. Release notes Sourced from appleboy/ssh-action's releases. v1.1.0 Changelog Bug fixes 0c7561b1a30e223b97730bb8b92671995d9fb1d0: fix: switch to SSH key authentication for security (@appleboy) Enhancements 9b978f09f2587beff9c80449f57cb0f0612d3039: chore: update...
### Summary Hi, I'm using the Tekton Buildpacks task from this link: https://hub.tekton.dev/tekton/task/buildpacks I'm working with a private registry (Harbor) and followed the documentation here: https://github.com/tektoncd/catalog/blob/main/task/buildpacks/0.6/samples/dockerconfig.yaml However, I'm encountering the...
Latest lifecycle release v0.20.1 triggered CVE(s) from Grype. For further details, see: https://github.com/buildpacks/lifecycle/actions/runs/10822952717 json: { "id": "CVE-2024-34158", "severity": "High", "description": "Calling Parse on a \"// +build\" build tag line with...