Releases: tektoncd/cli
Release list
v0.37.7
v0.37.7 Release 🎉
This patch release addresses the following CVEs: CVE-2026-33811, CVE-2026-39833, CVE-2026-42505, CVE-2026-39830, CVE-2026-25680, CVE-2026-22772, and CVE-2026-49835. It also updates the Go version to 1.25.12, which includes fixes for Go standard library vulnerabilities.
Changelog
- 05822dd New version v0.37.
What's Changed
- [release-v0.37.x] CI: Use goinstall mode for golangci-lint action by @vdemeester in #2990
- [release-v0.37.x] cherry-pick: OWNERS, CI summary, Dockerfile fix by @divyansh42 in #3013
- chore(deps): bump the all group across 1 directory with 3 updates by @dependabot[bot] in #3001
- [release-v0.37.x] cherry-pick: fix alibabacloud-go/cr-20160607 license by @divyansh42 in #3018
- [release-v0.37.x] bump github.com/docker/cli from 29.0.3+incompatible to 29.0.4+incompatible in the go-docker-dependencies group across 1 directory by @dependabot[bot] in #2946
- [release-v0.37.x] fix: resolve golangci-lint errors (cherry-pick from main) by @divyansh42 in #3024
- fix(cve): CVE-2026-42499, CVE-2026-39820 - update Go 1.25.9 to 1.25.10 [release-v0.37.x] by @divyansh42 in #2922
- fix(cve): CVE-2026-39828, CVE-2026-39829, CVE-2026-39830 - update golang.org/x/crypto to v0.52.0 [release-v0.37.x] by @divyansh42 in #2909
- fix(cve): CVE-2026-33811, CVE-2026-39833 - update Go stdlib and x/crypto [release-v0.37.x] by @divyansh42 in #2923
- [release-v0.37.x] bump github.com/sigstore/cosign/v2 from 2.6.2 to 2.6.3 by @dependabot[bot] in #2975
- [release-v0.37.x] bump github.com/creack/pty from 1.1.21 to 1.1.24 by @dependabot[bot] in #2963
- [release-v0.37.x] bump the go-k8s-dependencies group across 1 directory with 3 updates by @dependabot[bot] in #2957
- [release-v0.37.x] bump github.com/google/go-containerregistry from 0.20.7 to 0.20.8 by @dependabot[bot] in #2969
- [release-v0.37.x] bump github.com/tektoncd/hub from 1.17.0 to 1.17.3 by @dependabot[bot] in #3032
- [release-v0.37.x] bump github.com/tektoncd/pipeline from 0.59.5 to 0.59.6 by @dependabot[bot] in #3033
- [release-v0.37.x] bump github.com/sigstore/sigstore from 1.10.3 to 1.10.8 by @dependabot[bot] in #3035
- [release-v0.37.x] bump github.com/sigstore/cosign/v2 from 2.6.3 to 2.6.4 by @dependabot[bot] in #3050
- [release-v0.37.x] bump chainguard-dev/actions/kind-diag from 1.6.26 to 1.6.27 in the all group by @dependabot[bot] in #3053
- [release-v0.37.x] Security: Fix CVE-2026-42505 - update Go to 1.25.12 (crypto/tls ECH privacy leak) by @divyansh42 in #3067
- fix(cve): fix few critical CVEs by @pratap0007 in #3058
- [release-v0.37.x] bump the go-k8s-dependencies group with 3 updates by @dependabot[bot] in #3082
- [release-v0.37.x] bump chainguard-dev/actions/kind-diag from 1.6.27 to 1.6.28 in the all group by @dependabot[bot] in #3076
Full Changelog: v0.37.6...v0.37.7
v0.45.1
v0.45.1 Release 🎉
This patch release addresses the following CVEs: CVE-2026-48702, CVE-2026-49835, CVE-2026-39395, CVE-2026-49835. It also upgrades Go to v1.25.6 to remediate vulnerabilities in the Go standard library.
Changelog
- 4b7251b New version v0.45.1
What's Changed
- Bump the go-k8s-dependencies group with 3 updates by @dependabot[bot] in #2942
- Bump step-security/harden-runner from 2.19.1 to 2.19.4 by @dependabot[bot] in #2935
- Bump actions/checkout from 6.0.2 to 6.0.3 by @dependabot[bot] in #2936
- Bump chainguard-dev/actions/kind-diag from 1.6.19 to 1.6.25 by @dependabot[bot] in #2937
- Bump github/codeql-action/analyze from 4.35.3 to 4.35.5 by @dependabot[bot] in #2965
- [release-v0.45.x] CI: Use goinstall mode for golangci-lint action by @vdemeester in #2986
- chore(deps): bump github.com/sigstore/sigstore from 1.10.5 to 1.10.8 by @dependabot[bot] in #2993
- chore(deps): bump the all group across 1 directory with 2 updates by @dependabot[bot] in #3004
- chore(deps): bump github.com/tektoncd/pipeline from 1.12.0 to 1.12.2 by @dependabot[bot] in #2973
- chore(deps): bump github.com/tektoncd/chains from 0.26.3 to 0.26.5 by @dependabot[bot] in #2958
- chore(deps): bump google.golang.org/grpc from 1.81.0 to 1.81.1 by @dependabot[bot] in #2944
- chore(deps): bump github.com/google/go-containerregistry from 0.21.6 to 0.21.7 by @dependabot[bot] in #2964
- [release-v0.45.x] bump github.com/tektoncd/chains from 0.26.5 to 0.26.6 by @dependabot[bot] in #3034
- [release-v0.45.x] bump chainguard-dev/actions/kind-diag from 1.6.26 to 1.6.27 in the all group by @dependabot[bot] in #3047
- [release-v0.45.x] bump github.com/sigstore/cosign/v2 from 2.6.3 to 2.6.4 by @dependabot[bot] in #3051
- [release-v0.45.x] chore(deps): remove unused tektoncd/chains dependency by @pratap0007 in #3061
- fix(cve): fix few critical CVEs by @pratap0007 in #3063
Full Changelog: v0.45.0...v0.45.1
v0.44.2
v0.44.2 Release 🎉
This patch release addresses the following CVEs: CVE-2026-40938, CVE-2026-40161, CVE-2026-24051, CVE-2026-24051 and CVE-2026-34986.
Changelog
- 17a7599 New version v0.44.2
Full Changelog: v0.44.1...v0.44.2
v0.43.2
v0.43.2 Release 🎉
This patch release addresses the following CVEs: GHSA-78h2-9frx-2jm8, GHSA-mh2q-q3fh-2475, GHSA-hfvc-g4fc-pqhx, GHSA-w2q5-6q6x-x959, GHSA-m9x8-m34x-fj9q, GHSA-w9p8-pvxh-rxpj, GHSA-wrh2-89vg-4j9g
GHSA-4279-q6mj-392r, GHSA-h524-452v-82p9, GHSA-h3gm-q7m7-mp28
Changelog
- db2b9a1 New version v0.43.2
Full Changelog: v0.43.1...v0.43.2
v0.45.0
v0.45.0 Release 🎉
This release adds the describe subcommand for customrun, migrates tracing from OpenCensus to OpenTelemetry, removes the deprecated chains command, adds support for Pipelines v1.12.0, and includes dependency updates to address multiple critical CVEs.
Changelog 📋
- ce6edf3 New version v0.45.0
What's Changed
- Bump chainguard-dev/actions from 1.6.1 to 1.6.3 by @dependabot[bot] in #2742
- Bump go.opentelemetry.io/otel/sdk from 1.39.0 to 1.40.0 by @dependabot[bot] in #2753
- chore: referencing the setup-kind script from the plumbing repo instead of copying it by @infernus01 in #2590
- Nominate divyansh42 as cli approver by @vdemeester in #2761
- Move piyush-garg to alumni by @vdemeester in #2760
- docs: Update CLI docs for v0.44.0 release by @pratap0007 in #2748
- Bump github/codeql-action from 4.32.3 to 4.32.5 by @dependabot[bot] in #2755
- Bump step-security/harden-runner from 2.14.2 to 2.15.0 by @dependabot[bot] in #2757
- Bump actions/setup-go from 6.2.0 to 6.3.0 by @dependabot[bot] in #2754
- Bump github.com/google/go-containerregistry from 0.21.0 to 0.21.2 by @dependabot[bot] in #2759
- Bump github.com/docker/cli from 29.2.1+incompatible to 29.3.0+incompatible in the go-docker-dependencies group by @dependabot[bot] in #2763
- Bump golang.org/x/term from 0.40.0 to 0.41.0 by @dependabot[bot] in #2766
- Bump github.com/golangci/golangci-lint/v2 from 2.10.1 to 2.11.3 in /tools by @dependabot[bot] in #2765
- Add CI summary fan-in job to presubmit CI by @vdemeester in #2741
- feat: add cherry-pick command workflow by @vdemeester in #2682
- Bump chainguard-dev/actions from 1.6.3 to 1.6.5 by @dependabot[bot] in #2756
- Bump actions/upload-artifact from 6.0.0 to 7.0.0 by @dependabot[bot] in #2758
- Bump the go-k8s-dependencies group with 3 updates by @dependabot[bot] in #2752
- Change all occurences of GCS buckets with OCI buckets by @adityavshinde in #2768
- Add long flag --display-name to display the log of pipelinerun by @icloudnote in #2450
- feat: add describe subcommand in customrun command by @pratap0007 in #2712
- Cleanup/remove deprecate chains cmd by @adityavshinde in #2769
- Bump google.golang.org/grpc from 1.78.0 to 1.79.3 by @dependabot[bot] in #2775
- Bump github.com/tektoncd/pipeline from 1.9.1 to 1.9.2 by @dependabot[bot] in #2781
- Bump github.com/go-jose/go-jose/v4 from 4.1.3 to 4.1.4 by @dependabot[bot] in #2789
- Bump knative and components version by @khrm in #2788
- Migrate tracing from OpenCensus to OpenTelemetry by @khrm in #2799
- Bump go.opentelemetry.io/otel/sdk from 1.42.0 to 1.43.0 by @dependabot[bot] in #2800
- Bump github.com/docker/cli from 29.3.0+incompatible to 29.3.1+incompatible in the go-docker-dependencies group across 1 directory by @dependabot[bot] in #2783
- Bump go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp from 1.42.0 to 1.43.0 by @dependabot[bot] in #2801
- Bump github.com/letsencrypt/boulder from 0.20251110.0 to 0.20260406.0 by @dependabot[bot] in #2796
- (deps) Bump go version to 1.25.8 to fix CVE-2026-25679 by @divyansh42 in #2803
- Bump github.com/google/go-containerregistry from 0.21.3 to 0.21.4 by @dependabot[bot] in #2797
- Bump github.com/sigstore/cosign/v2 from 2.6.2 to 2.6.3 by @dependabot[bot] in #2798
- Bump step-security/harden-runner from 2.15.0 to 2.17.0 by @dependabot[bot] in #2808
- Bump github.com/fatih/color from 1.18.0 to 1.19.0 by @dependabot[bot] in #2777
- Bump github.com/golangci/golangci-lint/v2 from 2.11.3 to 2.11.4 in /tools by @dependabot[bot] in #2778
- Bump github/codeql-action from 4.32.5 to 4.35.1 by @dependabot[bot] in #2784
- Bump actions/setup-go from 6.3.0 to 6.4.0 by @dependabot[bot] in #2786
- Bump github.com/sigstore/sigstore from 1.10.4 to 1.10.5 by @dependabot[bot] in #2805
- Bump github.com/sigstore/timestamp-authority/v2 from 2.0.3 to 2.0.6 by @dependabot[bot] in #2809
- Bump go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetrichttp from 1.42.0 to 1.43.0 by @dependabot[bot] in #2802
- Bump actions/upload-artifact from 7.0.0 to 7.0.1 by @dependabot[bot] in #2816
- Bump step-security/harden-runner from 2.17.0 to 2.19.0 by @dependabot[bot] in #2815
- Bump the go-k8s-dependencies group with 3 updates by @dependabot[bot] in #2811
- Bump github.com/letsencrypt/boulder from 0.20260406.0 to 0.20260413.0 by @dependabot[bot] in #2812
- Bump github.com/google/go-containerregistry from 0.21.4 to 0.21.5 by @dependabot[bot] in #2813
- Bump chainguard-dev/actions from 1.6.5 to 1.6.15 by @dependabot[bot] in #2814
- Bump github/codeql-action from 4.35.1 to 4.35.2 by @dependabot[bot] in #2817
- Bump github.com/docker/cli from 29.4.0+incompatible to 29.4.1+incompatible in the go-docker-dependencies group by @dependabot[bot] in #2820
- Bump github.com/tektoncd/pipeline from 1.11.0 to 1.11.1 by @dependabot[bot] in #2823
- Bump github.com/tektoncd/chains from 0.26.2 to 0.26.3 by @dependabot[bot] in #2827
- Bump chainguard-dev/actions from 1.6.15 to 1.6.16 by @dependabot[bot] in #2829
- Bump go.uber.org/zap from 1.27.1 to 1.28.0 by @dependabot[bot] in #2830
- Bump github.com/letsencrypt/boulder from 0.20260413.0 to 0.20260420.0 by @dependabot[bot] in #2821
- Bump github.com/tektoncd/pipeline from 1.11.1 to 1.12.0 by @dependabot[bot] in #2836
- Bump google.golang.org/grpc from 1.80.0 to 1.81.0 by @dependabot[bot] in #2837
- Bump chainguard-dev/actions from 1.6.16 to 1.6.19 by @dependabot[bot] in #2839
- Bump github.com/golangci/golangci-lint/v2 from 2.11.4 to 2.12.1 in /tools by @dependabot[bot] in #2834
- Bump step-security/harden-runner from 2.19.0 to 2.19.1 by @dependabot[bot] in #2840
- Strip Go symbol table from release binaries by @alliasgher in #2843
- Bump github/codeql-action from 4.35.2 to 4.35.3 by @dependabot[bot] in #2838
- Bump github.com/golangci/golangci-lint/v2 from 2.12.1 to 2.12.2 in /tools by @dependabot[bot] in #2842
- Bump github.com/in-toto/in-toto-golang from 0.10.0 to 0.11.0 by @dependabot[bot] in #2844
- Bump github.com/docker/cli from 29.4.1+incompatible to 29.4.3+incompatible in the go-docker-dependencies group across 1 directory by @dependabot[bot] in #2833
- Update tekton hub to 1.24.0 by @divyansh42 in #2845
- Bump golang.org/x/crypto from 0.50.0 to 0.51.0 by @dependabot[bot] in #2847
New Contributors
- @adityavshinde made their first contribution in #2768
- @alliasgher made their first contribution in #2843
Full Changelog: v0.44.0...v0.45.0
v0.42.2
v0.42.2 Release 🎉
This patch release addresses the following CVEs: CVE-2026-33186, CVE-2026-33810, CVE-2025-61729 and CVE-2025-61726.
Changelog
- 1e1782f New version v0.42.2
Full Changelog: v0.42.1...v0.42.2
v0.37.6
v0.37.6 Release 🎉
This patch release addresses CVE-2026-25679
Changelog
- 0be7186 New version v0.37.6
Full Changelog: v0.37.5...v0.37.6
v0.37.5
v0.37.5 Release 🎉
This patch release addresses the following CVEs: CVE-2026-34986 and CVE-2026-33186.
Changelog
- 40a7331 New version v0.37.5
Full Changelog: v0.37.4...v0.37.5
v0.44.1
v0.44.1 Release 🎉
This patch release addresses the following CVEs: CVE-2026-34986, CVE-2026-33211, and CVE-2026-33186.
Changelog
- feb2d5a New version v0.44.1
Full Changelog: v0.44.0...v0.44.1
v0.37.4
v0.37.4 Release 🎉
This patch release addresses CVE-2025-61726.
Changelog
- e2c95ec New version v0.37.4
Full Changelog: v0.37.3...v0.37.4