Justin Chadwell 
							
						 
					 
					
						
						
							
						
						1d2ac78443 
					 
					
						
						
							
							inspect: move attestation loading to struct methods  
						
						... 
						
						
						
						This refactor ensures that the attestations are not output in the JSON
output for "{{ json . }}", and additionally allows future refactors to
dynamically load the attestation contents, ensuring faster performance
when attestations are not used in the output.
Signed-off-by: Justin Chadwell <me@jedevc.com > 
						
						
							
						
					 
					
						2023-01-10 12:40:42 +00:00 
						 
				 
			
				
					
						
							
							
								Justin Chadwell 
							
						 
					 
					
						
						
							
						
						8b7aa1a168 
					 
					
						
						
							
							build: create error group per opt  
						
						... 
						
						
						
						Using the syncronization primitive, we can avoid needing to create a
separate wait group.
This allows us to sidestep the issue where the wait group could be
completed, but the build invocation functions had not terminated - if
one of the functions was to terminate with an error, then it was
possible to encounter a race condition, where the result handling code
would begin executing, despite an error.
The refactor to use a separate error group which more elegantly handles
the concept of function returns and errors, ensures that we can't
encounter this issue.
Signed-off-by: Justin Chadwell <me@jedevc.com > 
						
						
							
						
					 
					
						2023-01-10 11:02:27 +00:00 
						 
				 
			
				
					
						
							
							
								Justin Chadwell 
							
						 
					 
					
						
						
							
						
						1180d919f5 
					 
					
						
						
							
							build: reorder error group funcs  
						
						... 
						
						
						
						Signed-off-by: Justin Chadwell <me@jedevc.com > 
						
						
							
						
					 
					
						2023-01-10 10:50:15 +00:00 
						 
				 
			
				
					
						
							
							
								Justin Chadwell 
							
						 
					 
					
						
						
							
						
						347417ee12 
					 
					
						
						
							
							build: use copy for BuildWithResultHandler loop vars  
						
						... 
						
						
						
						Signed-off-by: Justin Chadwell <me@jedevc.com > 
						
						
							
						
					 
					
						2023-01-10 10:50:15 +00:00 
						 
				 
			
				
					
						
							
							
								Justin Chadwell 
							
						 
					 
					
						
						
							
						
						fb27e3f919 
					 
					
						
						
							
							Merge pull request  #1502  from developer-guy/fix/readme  
						
						... 
						
						
						
						fix the directory of the buildx binary 
						
						
							
						
					 
					
						2023-01-10 10:28:04 +00:00 
						 
				 
			
				
					
						
							
							
								Batuhan Apaydın 
							
						 
					 
					
						
						
							
						
						edb16f8aab 
					 
					
						
						
							
							fix the directory of the buildx binary  
						
						... 
						
						
						
						Signed-off-by: Batuhan Apaydın <batuhan.apaydin@trendyol.com > 
						
						
							
						
					 
					
						2023-01-10 11:26:11 +03:00 
						 
				 
			
				
					
						
							
							
								Tõnis Tiigi 
							
						 
					 
					
						
						
							
						
						5c56e947fe 
					 
					
						
						
							
							Merge pull request  #1500  from tonistiigi/update-buildkit-v0.11.0  
						
						... 
						
						
						
						github: update CI to buildkit v0.11 
						
						
							
						
					 
					
						2023-01-09 15:59:25 -08:00 
						 
				 
			
				
					
						
							
							
								Tonis Tiigi 
							
						 
					 
					
						
						
							
						
						571871b084 
					 
					
						
						
							
							github: update CI to buildkit v0.11  
						
						... 
						
						
						
						Signed-off-by: Tonis Tiigi <tonistiigi@gmail.com > 
						
						
							
						
					 
					
						2023-01-09 15:50:56 -08:00 
						 
				 
			
				
					
						
							
							
								Tõnis Tiigi 
							
						 
					 
					
						
						
							
						
						8340c40647 
					 
					
						
						
							
							Merge pull request  #1498  from jedevc/attestation-printing  
						
						... 
						
						
						
						Improved attestation inspect 
						
						
							
						
					 
					
						2023-01-09 11:22:20 -08:00 
						 
				 
			
				
					
						
							
							
								Justin Chadwell 
							
						 
					 
					
						
						
							
						
						9818055b0e 
					 
					
						
						
							
							docs: update with new inspect output  
						
						... 
						
						
						
						Signed-off-by: Justin Chadwell <me@jedevc.com > 
						
						
							
						
					 
					
						2023-01-09 19:07:10 +00:00 
						 
				 
			
				
					
						
							
							
								Justin Chadwell 
							
						 
					 
					
						
						
							
						
						484823c97d 
					 
					
						
						
							
							inspect: change additional spdxs to not have duplicates  
						
						... 
						
						
						
						Signed-off-by: Justin Chadwell <me@jedevc.com > 
						
						
							
						
					 
					
						2023-01-09 19:03:23 +00:00 
						 
				 
			
				
					
						
							
							
								Justin Chadwell 
							
						 
					 
					
						
						
							
						
						3ce17b01dc 
					 
					
						
						
							
							inspect: provide access to multiple spdx documents  
						
						... 
						
						
						
						Signed-off-by: Justin Chadwell <me@jedevc.com > 
						
						
							
						
					 
					
						2023-01-09 18:42:26 +00:00 
						 
				 
			
				
					
						
							
							
								Justin Chadwell 
							
						 
					 
					
						
						
							
						
						e68c566c1c 
					 
					
						
						
							
							inspect: parse sbom and provenance into json structs  
						
						... 
						
						
						
						Signed-off-by: Justin Chadwell <me@jedevc.com > 
						
						
							
						
					 
					
						2023-01-09 18:09:43 +00:00 
						 
				 
			
				
					
						
							
							
								Justin Chadwell 
							
						 
					 
					
						
						
							
						
						19d16aa941 
					 
					
						
						
							
							inspect: break after first matching attestation  
						
						... 
						
						
						
						Signed-off-by: Justin Chadwell <me@jedevc.com > 
						
						
							
						
					 
					
						2023-01-09 18:09:06 +00:00 
						 
				 
			
				
					
						
							
							
								CrazyMax 
							
						 
					 
					
						
						
							
						
						6852713121 
					 
					
						
						
							
							Merge pull request  #1494  from thaJeztah/docs_update_docs_tools  
						
						... 
						
						
						
						go.mod: update cli-docs-tool v0.5.1 
						
						
							
						
					 
					
						2023-01-09 13:14:01 +01:00 
						 
				 
			
				
					
						
							
							
								Sebastiaan van Stijn 
							
						 
					 
					
						
						
							
						
						c97500b117 
					 
					
						
						
							
							go.mod: update cli-docs-tool v0.5.1 and re-generate docs  
						
						... 
						
						
						
						Signed-off-by: Sebastiaan van Stijn <github@gone.nl > 
						
						
							
						
					 
					
						2023-01-09 13:03:01 +01:00 
						 
				 
			
				
					
						
							
							
								CrazyMax 
							
						 
					 
					
						
						
							
						
						85040a9067 
					 
					
						
						
							
							Merge pull request  #1493  from thaJeztah/docs_fix_anchors  
						
						... 
						
						
						
						docs: update anchor links 
						
						
							
						
					 
					
						2023-01-09 12:19:58 +01:00 
						 
				 
			
				
					
						
							
							
								Sebastiaan van Stijn 
							
						 
					 
					
						
						
							
						
						b8285c17e6 
					 
					
						
						
							
							docs: update anchor links  
						
						... 
						
						
						
						Signed-off-by: Sebastiaan van Stijn <github@gone.nl > 
						
						
							
						
					 
					
						2023-01-07 15:12:08 +01:00 
						 
				 
			
				
					
						
							
							
								Tõnis Tiigi 
							
						 
					 
					
						
						
							
						
						332dfb4b92 
					 
					
						
						
							
							Merge pull request  #1444  from crazy-max/inspect-attest  
						
						... 
						
						
						
						imagetools inspect: handle provenance and sboms 
						
						
							
						
					 
					
						2023-01-06 16:29:33 -08:00 
						 
				 
			
				
					
						
							
							
								Tõnis Tiigi 
							
						 
					 
					
						
						
							
						
						cb279bb14b 
					 
					
						
						
							
							Merge pull request  #1491  from jedevc/ociindex-refactor  
						
						... 
						
						
						
						vendor: update buildkit to v0.11.0-rc4 
						
						
							
						
					 
					
						2023-01-06 16:29:18 -08:00 
						 
				 
			
				
					
						
							
							
								Justin Chadwell 
							
						 
					 
					
						
						
							
						
						60c9cf74ce 
					 
					
						
						
							
							vendor: update buildkit to v0.11.0-rc4  
						
						... 
						
						
						
						Signed-off-by: Tonis Tiigi <tonistiigi@gmail.com >
Signed-off-by: Justin Chadwell <me@jedevc.com > 
						
						
							
						
					 
					
						2023-01-06 15:51:17 -08:00 
						 
				 
			
				
					
						
							
							
								Tõnis Tiigi 
							
						 
					 
					
						
						
							
						
						ff6754eb04 
					 
					
						
						
							
							Merge pull request  #1456  from jedevc/oci-layout-reference-parsing  
						
						... 
						
						
						
						build: refactor reference parsing for oci image layouts 
						
						
							
						
					 
					
						2023-01-05 23:50:25 -08:00 
						 
				 
			
				
					
						
							
							
								CrazyMax 
							
						 
					 
					
						
						
							
						
						e6b9aba997 
					 
					
						
						
							
							imagetools inspect: handle provenance and sbom  
						
						... 
						
						
						
						use stub structs for SLSA/SBOM while waiting for
go-imageinspect library to be public.
Signed-off-by: CrazyMax <crazy-max@users.noreply.github.com > 
						
						
							
						
					 
					
						2023-01-05 17:34:30 +01:00 
						 
				 
			
				
					
						
							
							
								CrazyMax 
							
						 
					 
					
						
						
							
						
						0302894bfb 
					 
					
						
						
							
							Merge pull request  #1463  from crazy-max/e2e-k3s  
						
						... 
						
						
						
						e2e: use native k3s installation script 
						
						
							
						
					 
					
						2023-01-05 16:50:45 +01:00 
						 
				 
			
				
					
						
							
							
								CrazyMax 
							
						 
					 
					
						
						
							
						
						e46394c3be 
					 
					
						
						
							
							e2e: use native k3s installation script  
						
						... 
						
						
						
						debianmaster/actions-k3s action gives some warnings in our e2e
workflow. This commit brings https://github.com/debianmaster/actions-k3s/blob/master/index.js 
directly in the workflow through actions/github-script with
some changes to properly wait for nodes to be up.
Signed-off-by: CrazyMax <crazy-max@users.noreply.github.com > 
						
						
							
						
					 
					
						2023-01-05 15:37:19 +01:00 
						 
				 
			
				
					
						
							
							
								Justin Chadwell 
							
						 
					 
					
						
						
							
						
						1885e41789 
					 
					
						
						
							
							docs: update oci layout with tag resolution  
						
						... 
						
						
						
						Signed-off-by: Justin Chadwell <me@jedevc.com > 
						
						
							
						
					 
					
						2023-01-05 13:47:42 +00:00 
						 
				 
			
				
					
						
							
							
								CrazyMax 
							
						 
					 
					
						
						
							
						
						2fb9db994b 
					 
					
						
						
							
							imagetools inspect: missing annotations key  
						
						... 
						
						
						
						Signed-off-by: CrazyMax <crazy-max@users.noreply.github.com > 
						
						
							
						
					 
					
						2023-01-04 15:52:16 +01:00 
						 
				 
			
				
					
						
							
							
								Tõnis Tiigi 
							
						 
					 
					
						
						
							
						
						287aaf1696 
					 
					
						
						
							
							Merge pull request  #1482  from AkihiroSuda/auto-propagate-source-date-epoch  
						
						... 
						
						
						
						Propagate SOURCE_DATE_EPOCH from the client env 
						
						
							
						
					 
					
						2022-12-27 17:32:08 -08:00 
						 
				 
			
				
					
						
							
							
								Akihiro Suda 
							
						 
					 
					
						
						
							
						
						0e6f5a155e 
					 
					
						
						
							
							Propagate SOURCE_DATE_EPOCH from the client env  
						
						... 
						
						
						
						Signed-off-by: Akihiro Suda <akihiro.suda.cz@hco.ntt.co.jp > 
						
						
							
						
					 
					
						2022-12-24 01:32:15 +09:00 
						 
				 
			
				
					
						
							
							
								Tõnis Tiigi 
							
						 
					 
					
						
						
							
						
						88852e2330 
					 
					
						
						
							
							Merge pull request  #1480  from crazy-max/fix-badge  
						
						... 
						
						
						
						disable buildx experimental in pipeline 
						
						
							
						
					 
					
						2022-12-16 10:28:20 -08:00 
						 
				 
			
				
					
						
							
							
								CrazyMax 
							
						 
					 
					
						
						
							
						
						6369c50614 
					 
					
						
						
							
							disable buildx experimental in pipeline  
						
						... 
						
						
						
						Signed-off-by: CrazyMax <crazy-max@users.noreply.github.com > 
						
						
							
						
					 
					
						2022-12-16 18:53:46 +01:00 
						 
				 
			
				
					
						
							
							
								CrazyMax 
							
						 
					 
					
						
						
							
						
						a22d0a35a4 
					 
					
						
						
							
							readme: fix status badge  
						
						... 
						
						
						
						Signed-off-by: CrazyMax <crazy-max@users.noreply.github.com > 
						
						
							
						
					 
					
						2022-12-16 17:52:30 +01:00 
						 
				 
			
				
					
						
							
							
								CrazyMax 
							
						 
					 
					
						
						
							
						
						c93c02df85 
					 
					
						
						
							
							Merge pull request  #1479  from jedevc/fixup-git-err-check-order  
						
						... 
						
						
						
						build: check error from toSolveOpt before adding FrontendAttrs 
						
						
							
						
					 
					
						2022-12-16 16:28:17 +01:00 
						 
				 
			
				
					
						
							
							
								Justin Chadwell 
							
						 
					 
					
						
						
							
						
						e584c6e1a7 
					 
					
						
						
							
							build: check error from toSolveOpt before adding FrontendAttrs  
						
						... 
						
						
						
						Signed-off-by: Justin Chadwell <me@jedevc.com > 
						
						
							
						
					 
					
						2022-12-16 12:19:33 +00:00 
						 
				 
			
				
					
						
							
							
								Tõnis Tiigi 
							
						 
					 
					
						
						
							
						
						64e4c19971 
					 
					
						
						
							
							Merge pull request  #1477  from crazy-max/git-wsl  
						
						... 
						
						
						
						build: lookup the right git binary on WSL 
						
						
							
 
						
					 
					
						2022-12-15 18:00:52 -08:00 
						 
				 
			
				
					
						
							
							
								Tonis Tiigi 
							
						 
					 
					
						
						
							
						
						551b8f6785 
					 
					
						
						
							
							git: do not show warnings if project does not use git  
						
						... 
						
						
						
						Signed-off-by: Tonis Tiigi <tonistiigi@gmail.com > 
						
						
							
						
					 
					
						2022-12-15 17:51:46 -08:00 
						 
				 
			
				
					
						
							
							
								Tõnis Tiigi 
							
						 
					 
					
						
						
							
						
						fbbe1c1b91 
					 
					
						
						
							
							Merge pull request  #1472  from crazy-max/ci-attest  
						
						... 
						
						
						
						ci: opt-in sbom and provenance 
						
						
							
						
					 
					
						2022-12-15 17:38:13 -08:00 
						 
				 
			
				
					
						
							
							
								Tonis Tiigi 
							
						 
					 
					
						
						
							
						
						1a85745bf1 
					 
					
						
						
							
							github: update buildkit image to v0.11-rc3  
						
						... 
						
						
						
						Signed-off-by: Tonis Tiigi <tonistiigi@gmail.com > 
						
						
							
						
					 
					
						2022-12-15 16:54:32 -08:00 
						 
				 
			
				
					
						
							
							
								CrazyMax 
							
						 
					 
					
						
						
							
						
						0d1fea8134 
					 
					
						
						
							
							build: warn if git operation fails  
						
						... 
						
						
						
						Signed-off-by: CrazyMax <crazy-max@users.noreply.github.com > 
						
						
							
						
					 
					
						2022-12-15 23:40:19 +01:00 
						 
				 
			
				
					
						
							
							
								CrazyMax 
							
						 
					 
					
						
						
							
						
						19417e76e7 
					 
					
						
						
							
							build: lookup the right git binary on WSL  
						
						... 
						
						
						
						Signed-off-by: CrazyMax <crazy-max@users.noreply.github.com > 
						
						
							
						
					 
					
						2022-12-15 21:16:37 +01:00 
						 
				 
			
				
					
						
							
							
								Tõnis Tiigi 
							
						 
					 
					
						
						
							
						
						53d88a79ef 
					 
					
						
						
							
							Merge pull request  #1475  from jedevc/attest-warn-duplicate  
						
						... 
						
						
						
						buildflags: error on duplicate attest field 
						
						
							
						
					 
					
						2022-12-15 11:07:47 -08:00 
						 
				 
			
				
					
						
							
							
								Justin Chadwell 
							
						 
					 
					
						
						
							
						
						4c21b7e680 
					 
					
						
						
							
							Merge pull request  #1476  from jedevc/dont-filter-attestation-opts  
						
						... 
						
						
						
						build: forward all build opts everywhere 
						
						
							
						
					 
					
						2022-12-15 19:05:39 +00:00 
						 
				 
			
				
					
						
							
							
								Justin Chadwell 
							
						 
					 
					
						
						
							
						
						a8f689c223 
					 
					
						
						
							
							build: forward all build opts everywhere  
						
						... 
						
						
						
						All build options should be passed everywhere - the frontend and the
backend of buildkit should both be able to see all attestations, as well
as all other opts: e.g. epoch settings, and no-cache.
Signed-off-by: Justin Chadwell <me@jedevc.com > 
						
						
							
						
					 
					
						2022-12-15 18:19:47 +00:00 
						 
				 
			
				
					
						
							
							
								CrazyMax 
							
						 
					 
					
						
						
							
						
						ba8e3f9bc5 
					 
					
						
						
							
							ci: generate provenance and sbom for bin image  
						
						... 
						
						
						
						Signed-off-by: CrazyMax <crazy-max@users.noreply.github.com > 
						
						
							
						
					 
					
						2022-12-15 19:12:26 +01:00 
						 
				 
			
				
					
						
							
							
								CrazyMax 
							
						 
					 
					
						
						
							
						
						477200d1f9 
					 
					
						
						
							
							ci: generate provenance and sbom for release binaries  
						
						... 
						
						
						
						Signed-off-by: CrazyMax <crazy-max@users.noreply.github.com > 
						
						
							
						
					 
					
						2022-12-15 19:12:25 +01:00 
						 
				 
			
				
					
						
							
							
								Tõnis Tiigi 
							
						 
					 
					
						
						
							
						
						662738a7e5 
					 
					
						
						
							
							Merge pull request  #1474  from crazy-max/fix-ci  
						
						... 
						
						
						
						ci: fix warnings 
						
						
							
						
					 
					
						2022-12-15 09:29:25 -08:00 
						 
				 
			
				
					
						
							
							
								Justin Chadwell 
							
						 
					 
					
						
						
							
						
						f992b77535 
					 
					
						
						
							
							buildflags: warn on duplicate attest field  
						
						... 
						
						
						
						Signed-off-by: Justin Chadwell <me@jedevc.com > 
						
						
							
						
					 
					
						2022-12-15 15:39:19 +00:00 
						 
				 
			
				
					
						
							
							
								CrazyMax 
							
						 
					 
					
						
						
							
						
						21b2f135b5 
					 
					
						
						
							
							ci: update to ubuntu 22.04  
						
						... 
						
						
						
						Signed-off-by: CrazyMax <crazy-max@users.noreply.github.com > 
						
						
							
						
					 
					
						2022-12-15 14:34:03 +01:00 
						 
				 
			
				
					
						
							
							
								CrazyMax 
							
						 
					 
					
						
						
							
						
						71e6be5d99 
					 
					
						
						
							
							ci: fix deprecated set-output syntax  
						
						... 
						
						
						
						Signed-off-by: CrazyMax <crazy-max@users.noreply.github.com > 
						
						
							
						
					 
					
						2022-12-15 14:24:02 +01:00 
						 
				 
			
				
					
						
							
							
								CrazyMax 
							
						 
					 
					
						
						
							
						
						df8e7d0a9a 
					 
					
						
						
							
							Merge pull request  #1473  from crazy-max/fix-docs-prerelease  
						
						... 
						
						
						
						ci: do not publish docs on prerelease 
						
						
							
						
					 
					
						2022-12-15 14:22:07 +01:00