Skip to content

chore(deps): bump github.com/tektoncd/pipeline from 1.3.5 to 1.3.6#3606

Merged
tekton-robot merged 1 commit into
release-v0.77.xfrom
dependabot/go_modules/release-v0.77.x/github.com/tektoncd/pipeline-1.3.6
Jul 2, 2026
Merged

chore(deps): bump github.com/tektoncd/pipeline from 1.3.5 to 1.3.6#3606
tekton-robot merged 1 commit into
release-v0.77.xfrom
dependabot/go_modules/release-v0.77.x/github.com/tektoncd/pipeline-1.3.6

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jun 29, 2026

Copy link
Copy Markdown
Contributor

Bumps github.com/tektoncd/pipeline from 1.3.5 to 1.3.6.

Release notes

Sourced from github.com/tektoncd/pipeline's releases.

Tekton Pipeline release v1.3.6 "Maine Coon Melfina"

-Docs @ v1.3.6 -Examples @ v1.3.6

Installation one-liner

kubectl apply -f https://infra.tekton.dev/tekton-releases/pipeline/previous/v1.3.6/release.yaml

Attestation

The Rekor UUID for this release is 108e9186e8c5677abb2dede359568d236b4fb17593f0860b984278b4f333fd917d06c7f5d407853e

Obtain the attestation:

REKOR_UUID=108e9186e8c5677abb2dede359568d236b4fb17593f0860b984278b4f333fd917d06c7f5d407853e
rekor-cli get --uuid $REKOR_UUID --format json | jq -r .Attestation | jq .

Verify that all container images in the attestation are in the release file:

RELEASE_FILE=https://infra.tekton.dev/tekton-releases/pipeline/previous/v1.3.6/release.yaml
REKOR_UUID=108e9186e8c5677abb2dede359568d236b4fb17593f0860b984278b4f333fd917d06c7f5d407853e
Obtains the list of images with sha from the attestation
REKOR_ATTESTATION_IMAGES=$(rekor-cli get --uuid "$REKOR_UUID" --format json | jq -r .Attestation | jq -r '.subject[]|.name + ":v1.3.6@sha256:" + .digest.sha256')
Download the release file
curl -L "$RELEASE_FILE" > release.yaml
For each image in the attestation, match it to the release file
for image in $REKOR_ATTESTATION_IMAGES; do
printf $image; grep -q $image release.yaml && echo " ===> ok" || echo " ===> no match";
done

Changes

Features

... (truncated)

Commits
  • 6827e77 build(deps): bump the all group in /tekton with 3 updates
  • 5fff819 build(deps): bump the all group in /tekton with 4 updates
  • See full diff in compare view

@dependabot dependabot Bot added dependencies Used by dependabot - identifies all PRs created by dependabot kind/misc Categorizes issue or PR as a miscellaneuous one. ok-to-test Indicates a non-member PR verified by an org member that is safe to test. release-note-none Denotes a PR that doesnt merit a release note. labels Jun 29, 2026
@tekton-robot tekton-robot added the size/XS Denotes a PR that changes 0-9 lines, ignoring generated files. label Jun 29, 2026
@vdemeester

Copy link
Copy Markdown
Member

/retest

@vdemeester

Copy link
Copy Markdown
Member

@dependabot rebase

Bumps [github.com/tektoncd/pipeline](https://github.com/tektoncd/pipeline) from 1.3.5 to 1.3.6.
- [Release notes](https://github.com/tektoncd/pipeline/releases)
- [Changelog](https://github.com/tektoncd/pipeline/blob/main/releases.md)
- [Commits](tektoncd/pipeline@v1.3.5...v1.3.6)

---
updated-dependencies:
- dependency-name: github.com/tektoncd/pipeline
  dependency-version: 1.3.6
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot force-pushed the dependabot/go_modules/release-v0.77.x/github.com/tektoncd/pipeline-1.3.6 branch from 68f5292 to 6f22c13 Compare July 1, 2026 12:36
@jkhelil

jkhelil commented Jul 2, 2026

Copy link
Copy Markdown
Member

/approve

@jkhelil

jkhelil commented Jul 2, 2026

Copy link
Copy Markdown
Member

/lgtm

@tekton-robot

Copy link
Copy Markdown
Contributor

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: jkhelil

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@tekton-robot tekton-robot added the approved Indicates a PR has been approved by an approver from all required OWNERS files. label Jul 2, 2026
@tekton-robot tekton-robot added the lgtm Indicates that a PR is ready to be merged. label Jul 2, 2026
@tekton-robot tekton-robot merged commit 7804120 into release-v0.77.x Jul 2, 2026
12 checks passed
@dependabot dependabot Bot deleted the dependabot/go_modules/release-v0.77.x/github.com/tektoncd/pipeline-1.3.6 branch July 2, 2026 07:32
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

approved Indicates a PR has been approved by an approver from all required OWNERS files. dependencies Used by dependabot - identifies all PRs created by dependabot kind/misc Categorizes issue or PR as a miscellaneuous one. lgtm Indicates that a PR is ready to be merged. ok-to-test Indicates a non-member PR verified by an org member that is safe to test. release-note-none Denotes a PR that doesnt merit a release note. size/XS Denotes a PR that changes 0-9 lines, ignoring generated files.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants