Skip to content

chore(deps): bump github.com/tektoncd/pipeline from 1.12.1 to 1.12.2#3609

Merged
tekton-robot merged 1 commit into
release-v0.80.xfrom
dependabot/go_modules/release-v0.80.x/github.com/tektoncd/pipeline-1.12.2
Jul 1, 2026
Merged

chore(deps): bump github.com/tektoncd/pipeline from 1.12.1 to 1.12.2#3609
tekton-robot merged 1 commit into
release-v0.80.xfrom
dependabot/go_modules/release-v0.80.x/github.com/tektoncd/pipeline-1.12.2

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jun 29, 2026

Copy link
Copy Markdown
Contributor

Bumps github.com/tektoncd/pipeline from 1.12.1 to 1.12.2.

Release notes

Sourced from github.com/tektoncd/pipeline's releases.

Tekton Pipeline release v1.12.2 "Exotic Shorthair Elektrobots LTS"

-Docs @ v1.12.2 -Examples @ v1.12.2

Installation one-liner

kubectl apply -f https://infra.tekton.dev/tekton-releases/pipeline/previous/v1.12.2/release.yaml

Attestation

The Rekor UUID for this release is cb0a4d44223cf8dd164d8eec84c25d204f7a37a023c2d28f1f8dcde79ca3c187

Obtain the attestation:

REKOR_UUID=cb0a4d44223cf8dd164d8eec84c25d204f7a37a023c2d28f1f8dcde79ca3c187
rekor-cli get --uuid $REKOR_UUID --format json | jq -r .Attestation | jq .

Verify that all container images in the attestation are in the release file:

RELEASE_FILE=https://infra.tekton.dev/tekton-releases/pipeline/previous/v1.12.2/release.yaml
REKOR_UUID=cb0a4d44223cf8dd164d8eec84c25d204f7a37a023c2d28f1f8dcde79ca3c187
Obtains the list of images with sha from the attestation
REKOR_ATTESTATION_IMAGES=$(rekor-cli get --uuid "$REKOR_UUID" --format json | jq -r .Attestation | jq -r '.subject[]|.name + ":v1.12.2@sha256:" + .digest.sha256')
Download the release file
curl -L "$RELEASE_FILE" > release.yaml
For each image in the attestation, match it to the release file
for image in $REKOR_ATTESTATION_IMAGES; do
printf $image; grep -q $image release.yaml && echo " ===> ok" || echo " ===> no match";
done

Changes

Features

... (truncated)

Commits
  • a1fc405 build(deps): bump k8s.io/client-go from 0.35.5 to 0.35.6
  • See full diff in compare view

@dependabot dependabot Bot added dependencies Used by dependabot - identifies all PRs created by dependabot kind/misc Categorizes issue or PR as a miscellaneuous one. ok-to-test Indicates a non-member PR verified by an org member that is safe to test. release-note-none Denotes a PR that doesnt merit a release note. labels Jun 29, 2026
@tekton-robot tekton-robot added the size/XS Denotes a PR that changes 0-9 lines, ignoring generated files. label Jun 29, 2026
@jkhelil

jkhelil commented Jun 30, 2026

Copy link
Copy Markdown
Member

/retest

1 similar comment
@jkhelil

jkhelil commented Jun 30, 2026

Copy link
Copy Markdown
Member

/retest

@jkhelil

jkhelil commented Jun 30, 2026

Copy link
Copy Markdown
Member

@dependabot rebase

Bumps [github.com/tektoncd/pipeline](https://github.com/tektoncd/pipeline) from 1.12.1 to 1.12.2.
- [Release notes](https://github.com/tektoncd/pipeline/releases)
- [Changelog](https://github.com/tektoncd/pipeline/blob/main/releases.md)
- [Commits](tektoncd/pipeline@v1.12.1...v1.12.2)

---
updated-dependencies:
- dependency-name: github.com/tektoncd/pipeline
  dependency-version: 1.12.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot force-pushed the dependabot/go_modules/release-v0.80.x/github.com/tektoncd/pipeline-1.12.2 branch from 90f42b0 to 3a984ad Compare June 30, 2026 15:30
@jkhelil

jkhelil commented Jul 1, 2026

Copy link
Copy Markdown
Member

/approve

@jkhelil

jkhelil commented Jul 1, 2026

Copy link
Copy Markdown
Member

/lgtm

@tekton-robot

Copy link
Copy Markdown
Contributor

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: jkhelil

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@tekton-robot tekton-robot added the approved Indicates a PR has been approved by an approver from all required OWNERS files. label Jul 1, 2026
@tekton-robot tekton-robot added the lgtm Indicates that a PR is ready to be merged. label Jul 1, 2026
@tekton-robot tekton-robot merged commit 59ed373 into release-v0.80.x Jul 1, 2026
13 checks passed
@dependabot dependabot Bot deleted the dependabot/go_modules/release-v0.80.x/github.com/tektoncd/pipeline-1.12.2 branch July 1, 2026 06:08
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

approved Indicates a PR has been approved by an approver from all required OWNERS files. dependencies Used by dependabot - identifies all PRs created by dependabot kind/misc Categorizes issue or PR as a miscellaneuous one. lgtm Indicates that a PR is ready to be merged. ok-to-test Indicates a non-member PR verified by an org member that is safe to test. release-note-none Denotes a PR that doesnt merit a release note. size/XS Denotes a PR that changes 0-9 lines, ignoring generated files.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants