Skip to content
Permalink

Comparing changes

Choose two branches to see what’s changed or to start a new pull request. If you need to, you can also or learn more about diff comparisons.

Open a pull request

Create a new pull request by comparing changes across two branches. If you need to, you can also . Learn more about diff comparisons here.
base repository: zarf-dev/zarf
Failed to load repositories. Confirm that selected base ref is valid, then try again.
Loading
base: v0.32.3
Choose a base ref
...
head repository: zarf-dev/zarf
Failed to load repositories. Confirm that selected head ref is valid, then try again.
Loading
compare: v0.32.4
Choose a head ref
  • 17 commits
  • 50 files changed
  • 10 contributors

Commits on Feb 8, 2024

  1. fix(deps): update github.com/anchore/clio digest to 378d8c0 (#2294)

    [![Mend
    Renovate](https://app.renovatebot.com/images/banner.svg)](https://renovatebot.com)
    
    This PR contains the following updates:
    
    | Package | Type | Update | Change |
    |---|---|---|---|
    | [github.com/anchore/clio](https://togithub.com/anchore/clio) | require
    | digest | `3ef5b3b` -> `378d8c0` |
    
    ---
    
    > [!WARNING]
    > Some dependencies could not be looked up. Check the Dependency
    Dashboard for more information.
    
    ---
    
    ### Configuration
    
    📅 **Schedule**: Branch creation - At any time (no schedule defined),
    Automerge - At any time (no schedule defined).
    
    🚦 **Automerge**: Enabled.
    
    ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
    rebase/retry checkbox.
    
    🔕 **Ignore**: Close this PR and you won't be reminded about this update
    again.
    
    ---
    
    - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
    this box
    
    ---
    
    This PR has been generated by [Mend
    Renovate](https://www.mend.io/free-developer-tools/renovate/). View
    repository job log
    [here](https://developer.mend.io/github/defenseunicorns/zarf).
    
    <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiIzNy4xNzMuMCIsInVwZGF0ZWRJblZlciI6IjM3LjE3My4wIiwidGFyZ2V0QnJhbmNoIjoibWFpbiJ9-->
    
    Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
    renovate[bot] authored Feb 8, 2024
    Configuration menu
    Copy the full SHA
    9402e82 View commit details
    Browse the repository at this point in the history

Commits on Feb 9, 2024

  1. fix(deps): update github.com/anchore/clio digest to 06cf78f (#2297)

    [![Mend
    Renovate](https://app.renovatebot.com/images/banner.svg)](https://renovatebot.com)
    
    This PR contains the following updates:
    
    | Package | Type | Update | Change |
    |---|---|---|---|
    | [github.com/anchore/clio](https://togithub.com/anchore/clio) | require
    | digest | `378d8c0` -> `06cf78f` |
    
    ---
    
    > [!WARNING]
    > Some dependencies could not be looked up. Check the Dependency
    Dashboard for more information.
    
    ---
    
    ### Configuration
    
    📅 **Schedule**: Branch creation - At any time (no schedule defined),
    Automerge - At any time (no schedule defined).
    
    🚦 **Automerge**: Enabled.
    
    ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
    rebase/retry checkbox.
    
    🔕 **Ignore**: Close this PR and you won't be reminded about this update
    again.
    
    ---
    
    - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
    this box
    
    ---
    
    This PR has been generated by [Mend
    Renovate](https://www.mend.io/free-developer-tools/renovate/). View
    repository job log
    [here](https://developer.mend.io/github/defenseunicorns/zarf).
    
    <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiIzNy4xNzMuMCIsInVwZGF0ZWRJblZlciI6IjM3LjE3My4wIiwidGFyZ2V0QnJhbmNoIjoibWFpbiJ9-->
    
    Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
    renovate[bot] authored Feb 9, 2024
    Configuration menu
    Copy the full SHA
    d4d9ed6 View commit details
    Browse the repository at this point in the history

Commits on Feb 10, 2024

  1. fix(deps): update github.com/anchore/clio digest to cb94e40 (#2300)

    [![Mend
    Renovate](https://app.renovatebot.com/images/banner.svg)](https://renovatebot.com)
    
    This PR contains the following updates:
    
    | Package | Type | Update | Change |
    |---|---|---|---|
    | [github.com/anchore/clio](https://togithub.com/anchore/clio) | require
    | digest | `06cf78f` -> `cb94e40` |
    
    ---
    
    > [!WARNING]
    > Some dependencies could not be looked up. Check the Dependency
    Dashboard for more information.
    
    ---
    
    ### Configuration
    
    📅 **Schedule**: Branch creation - At any time (no schedule defined),
    Automerge - At any time (no schedule defined).
    
    🚦 **Automerge**: Enabled.
    
    ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
    rebase/retry checkbox.
    
    🔕 **Ignore**: Close this PR and you won't be reminded about this update
    again.
    
    ---
    
    - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
    this box
    
    ---
    
    This PR has been generated by [Mend
    Renovate](https://www.mend.io/free-developer-tools/renovate/). View
    repository job log
    [here](https://developer.mend.io/github/defenseunicorns/zarf).
    
    <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiIzNy4xNzMuMCIsInVwZGF0ZWRJblZlciI6IjM3LjE3My4wIiwidGFyZ2V0QnJhbmNoIjoibWFpbiJ9-->
    
    Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
    renovate[bot] authored Feb 10, 2024
    Configuration menu
    Copy the full SHA
    576c672 View commit details
    Browse the repository at this point in the history

Commits on Feb 12, 2024

  1. fix: improve cmd failure messaging (#2301)

    …s with no retries
    
    ## Description
    
    Add check to see whether action failure was actually due to timeout or
    not. Currently Zarf reports an error of "timed out after 0 seconds" when
    a `cmd` within an action fails (with no retries) even if no timeout was
    set.
    
    ## Related Issue
    
    Fixes #2299
    
    ## Type of change
    
    - [X] Bug fix (non-breaking change which fixes an issue)
    
    ## Checklist before merging
    
    - [X] Test, docs, adr added or updated as needed
    - [X] [Contributor Guide
    Steps](https://github.com/defenseunicorns/zarf/blob/main/CONTRIBUTING.md#developer-workflow)
    followed
    
    ---------
    
    Co-authored-by: Wayne Starr <Racer159@users.noreply.github.com>
    docandrew and Racer159 authored Feb 12, 2024
    Configuration menu
    Copy the full SHA
    7e91d3b View commit details
    Browse the repository at this point in the history

Commits on Feb 16, 2024

  1. fix(deps): update module helm.sh/helm/v3 to v3.14.1 [security] (#2307)

    [![Mend
    Renovate](https://app.renovatebot.com/images/banner.svg)](https://renovatebot.com)
    
    This PR contains the following updates:
    
    | Package | Change | Age | Adoption | Passing | Confidence |
    |---|---|---|---|---|---|
    | [helm.sh/helm/v3](https://togithub.com/helm/helm) | `v3.14.0` ->
    `v3.14.1` |
    [![age](https://developer.mend.io/api/mc/badges/age/go/helm.sh%2fhelm%2fv3/v3.14.1?slim=true)](https://docs.renovatebot.com/merge-confidence/)
    |
    [![adoption](https://developer.mend.io/api/mc/badges/adoption/go/helm.sh%2fhelm%2fv3/v3.14.1?slim=true)](https://docs.renovatebot.com/merge-confidence/)
    |
    [![passing](https://developer.mend.io/api/mc/badges/compatibility/go/helm.sh%2fhelm%2fv3/v3.14.0/v3.14.1?slim=true)](https://docs.renovatebot.com/merge-confidence/)
    |
    [![confidence](https://developer.mend.io/api/mc/badges/confidence/go/helm.sh%2fhelm%2fv3/v3.14.0/v3.14.1?slim=true)](https://docs.renovatebot.com/merge-confidence/)
    |
    
    ---
    
    > [!WARNING]
    > Some dependencies could not be looked up. Check the Dependency
    Dashboard for more information.
    
    ### GitHub Vulnerability Alerts
    
    ####
    [CVE-2024-25620](https://togithub.com/helm/helm/security/advisories/GHSA-v53g-5gjp-272r)
    
    A Helm contributor discovered a path traversal vulnerability when Helm
    saves a chart including at download time.
    
    ### Impact
    
    When either the Helm client or SDK is used to save a chart whose name
    within the `Chart.yaml` file includes a relative path change, the chart
    would be saved outside its expected directory based on the changes in
    the relative path. The validation and linting did not detect the path
    changes in the name.
    
    ### Patches
    
    This issue has been resolved in Helm v3.14.1.
    
    ### Workarounds
    
    Check all charts used by Helm for path changes in their name as found in
    the `Chart.yaml` file. This includes dependencies.
    
    ### Credits
    
    Disclosed by Dominykas Blyžė at Nearform Ltd.
    
    ---
    
    ### Release Notes
    
    <details>
    <summary>helm/helm (helm.sh/helm/v3)</summary>
    
    ### [`v3.14.1`](https://togithub.com/helm/helm/releases/tag/v3.14.1):
    Helm v3.14.1
    
    [Compare
    Source](https://togithub.com/helm/helm/compare/v3.14.0...v3.14.1)
    
    Helm v3.14.1 is a security (patch) release. Users are strongly
    recommended to update to this release.
    
    A Helm contributor discovered a path traversal vulnerability when Helm
    saves a chart including at download time.
    
    [Dominykas Blyžė](https://togithub.com/dominykas) with [Nearform
    Ltd.](https://www.nearform.com/) discovered the vulnerability.
    
    #### Installation and Upgrading
    
    Download Helm v3.14.1. The common platform binaries are here:
    
    - [MacOS amd64](https://get.helm.sh/helm-v3.14.1-darwin-amd64.tar.gz)
    ([checksum](https://get.helm.sh/helm-v3.14.1-darwin-amd64.tar.gz.sha256sum)
    / 67928236b37c4e780b9fb5e614fb3b9aece90d60f0b1b4cb7406ee292c2dae3b)
    - [MacOS arm64](https://get.helm.sh/helm-v3.14.1-darwin-arm64.tar.gz)
    ([checksum](https://get.helm.sh/helm-v3.14.1-darwin-arm64.tar.gz.sha256sum)
    / 96468f927cc6efb4a2b92fd9419f40ed21d634af2f3e84fb8efa59526c7a003b)
    - [Linux amd64](https://get.helm.sh/helm-v3.14.1-linux-amd64.tar.gz)
    ([checksum](https://get.helm.sh/helm-v3.14.1-linux-amd64.tar.gz.sha256sum)
    / 75496ea824f92305ff7d28af37f4af57536bf5138399c824dff997b9d239dd42)
    - [Linux arm](https://get.helm.sh/helm-v3.14.1-linux-arm.tar.gz)
    ([checksum](https://get.helm.sh/helm-v3.14.1-linux-arm.tar.gz.sha256sum)
    / f50c00c262b74435530e677bcec07637aaeda1ed92ef809b49581a4e6182cbbe)
    - [Linux arm64](https://get.helm.sh/helm-v3.14.1-linux-arm64.tar.gz)
    ([checksum](https://get.helm.sh/helm-v3.14.1-linux-arm64.tar.gz.sha256sum)
    / f865b8ad4228fd0990bbc5b50615eb6cb9eb31c9a9ca7238401ed897bbbe9033)
    - [Linux i386](https://get.helm.sh/helm-v3.14.1-linux-386.tar.gz)
    ([checksum](https://get.helm.sh/helm-v3.14.1-linux-386.tar.gz.sha256sum)
    / 3c94ed0601e0e62c195a7e9b75262b18128c8284662aa0e080bb548dc6d47bcd)
    - [Linux ppc64le](https://get.helm.sh/helm-v3.14.1-linux-ppc64le.tar.gz)
    ([checksum](https://get.helm.sh/helm-v3.14.1-linux-ppc64le.tar.gz.sha256sum)
    / 4d853ab8fe3462287c7272fbadd5f73531ecdd6fa0db37d31630e41ae1ae21de)
    - [Linux s390x](https://get.helm.sh/helm-v3.14.1-linux-s390x.tar.gz)
    ([checksum](https://get.helm.sh/helm-v3.14.1-linux-s390x.tar.gz.sha256sum)
    / 19bf07999c7244bfeb0fd27152919b9faa1148cf43910edbb98efa9150058a98)
    - [Linux riscv64](https://get.helm.sh/helm-v3.14.1-linux-riscv64.tar.gz)
    ([checksum](https://get.helm.sh/helm-v3.14.1-linux-riscv64.tar.gz.sha256sum)
    / 2660bd8eb37aafc071599b788a24bfe244e5d3ffa42da1599da5a5041dafa214)
    - [Windows amd64](https://get.helm.sh/helm-v3.14.1-windows-amd64.zip)
    ([checksum](https://get.helm.sh/helm-v3.14.1-windows-amd64.zip.sha256sum)
    / 8a6c78a23a4e497ad8bd288138588adb3e5b49be8dbe82a3200fe7b297dac184)
    
    This release was signed with ` 672C 657B E06B 4B30 969C 4A57 4614 49C2
    5E36 B98E ` and can be found at
    [@&#8203;mattfarina](https://togithub.com/mattfarina) [keybase
    account](https://keybase.io/mattfarina). Please use the attached
    signatures for verifying this release using `gpg`.
    
    The [Quickstart Guide](https://helm.sh/docs/intro/quickstart/) will get
    you going from there. For **upgrade instructions** or detailed
    installation notes, check the [install
    guide](https://helm.sh/docs/intro/install/). You can also use a [script
    to
    install](https://raw.githubusercontent.com/helm/helm/main/scripts/get-helm-3)
    on any system with `bash`.
    
    #### What's Next
    
    - 3.14.2 will contain only bug fixes and be released on March 13, 2024.
    -   3.15.0 is the next feature release and will be on May 08, 2024.
    
    </details>
    
    ---
    
    ### Configuration
    
    📅 **Schedule**: Branch creation - "" (UTC), Automerge - At any time (no
    schedule defined).
    
    🚦 **Automerge**: Enabled.
    
    ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
    rebase/retry checkbox.
    
    🔕 **Ignore**: Close this PR and you won't be reminded about this update
    again.
    
    ---
    
    - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
    this box
    
    ---
    
    This PR has been generated by [Mend
    Renovate](https://www.mend.io/free-developer-tools/renovate/). View
    repository job log
    [here](https://developer.mend.io/github/defenseunicorns/zarf).
    
    <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiIzNy4xNzMuMCIsInVwZGF0ZWRJblZlciI6IjM3LjE3My4wIiwidGFyZ2V0QnJhbmNoIjoibWFpbiJ9-->
    
    Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
    renovate[bot] authored Feb 16, 2024
    Configuration menu
    Copy the full SHA
    0cc2328 View commit details
    Browse the repository at this point in the history

Commits on Feb 19, 2024

  1. fix: revert storageclass checks for git server and seed registry (#2311)

    ## Description
    
    #2180 introduced a bug and
    this PR removes the cause of the bug.
    
    Actions conditionals are being added to Zarf in
    #2276 to allow these sort of
    checks to account for various use cases in a more clean way.
    
    Also reopened #1824
    
    ## Related Issue
    
    Relates to #2273
    
    ## Type of change
    
    - [x] Bug fix (non-breaking change which fixes an issue)
    - [ ] New feature (non-breaking change which adds functionality)
    - [ ] Other (security config, docs update, etc)
    
    ## Checklist before merging
    
    - [x] Test, docs, adr added or updated as needed
    - [x] [Contributor Guide
    Steps](https://github.com/defenseunicorns/zarf/blob/main/CONTRIBUTING.md#developer-workflow)
    followed
    lucasrod16 authored Feb 19, 2024
    Configuration menu
    Copy the full SHA
    84b673e View commit details
    Browse the repository at this point in the history

Commits on Feb 20, 2024

  1. feat(ci): included dependency review action (#2298)

    ## Description
    
    - Included dependency review action
    https://docs.github.com/en/code-security/supply-chain-security/understanding-your-software-supply-chain/about-dependency-review#dependency-review-enforcement
    
    ## Type of change
    
    - [ ] Bug fix (non-breaking change which fixes an issue)
    - [ ] New feature (non-breaking change which adds functionality)
    - [x] Other (security config, docs update, etc)
    
    ## Checklist before merging
    
    - [ ] Test, docs, adr added or updated as needed
    - [x] [Contributor Guide
    Steps](https://github.com/defenseunicorns/zarf/blob/main/CONTRIBUTING.md#developer-workflow)
    followed
    
    ---------
    
    Signed-off-by: naveensrinivasan <172697+naveensrinivasan@users.noreply.github.com>
    Co-authored-by: Austin Abro <37223396+AustinAbro321@users.noreply.github.com>
    Co-authored-by: Wayne Starr <Racer159@users.noreply.github.com>
    Co-authored-by: razzle <harry@razzle.cloud>
    4 people authored Feb 20, 2024
    Configuration menu
    Copy the full SHA
    883b4ba View commit details
    Browse the repository at this point in the history
  2. chore(deps): update actions/checkout action to v4 (#2317)

    [![Mend
    Renovate](https://app.renovatebot.com/images/banner.svg)](https://renovatebot.com)
    
    This PR contains the following updates:
    
    | Package | Type | Update | Change |
    |---|---|---|---|
    | [actions/checkout](https://togithub.com/actions/checkout) | action |
    major | `v3.6.0` -> `v4.1.1` |
    
    ---
    
    > [!WARNING]
    > Some dependencies could not be looked up. Check the Dependency
    Dashboard for more information.
    
    ---
    
    ### Release Notes
    
    <details>
    <summary>actions/checkout (actions/checkout)</summary>
    
    ###
    [`v4.1.1`](https://togithub.com/actions/checkout/releases/tag/v4.1.1)
    
    [Compare
    Source](https://togithub.com/actions/checkout/compare/v4.1.0...v4.1.1)
    
    ##### What's Changed
    
    - Update CODEOWNERS to Launch team by
    [@&#8203;joshmgross](https://togithub.com/joshmgross) in
    [https://github.com/actions/checkout/pull/1510](https://togithub.com/actions/checkout/pull/1510)
    - Correct link to GitHub Docs by
    [@&#8203;peterbe](https://togithub.com/peterbe) in
    [https://github.com/actions/checkout/pull/1511](https://togithub.com/actions/checkout/pull/1511)
    - Link to release page from what's new section by
    [@&#8203;cory-miller](https://togithub.com/cory-miller) in
    [https://github.com/actions/checkout/pull/1514](https://togithub.com/actions/checkout/pull/1514)
    
    ##### New Contributors
    
    - [@&#8203;joshmgross](https://togithub.com/joshmgross) made their first
    contribution in
    [https://github.com/actions/checkout/pull/1510](https://togithub.com/actions/checkout/pull/1510)
    - [@&#8203;peterbe](https://togithub.com/peterbe) made their first
    contribution in
    [https://github.com/actions/checkout/pull/1511](https://togithub.com/actions/checkout/pull/1511)
    
    **Full Changelog**:
    actions/checkout@v4.1.0...v4.1.1
    
    ###
    [`v4.1.0`](https://togithub.com/actions/checkout/blob/HEAD/CHANGELOG.md#v410)
    
    [Compare
    Source](https://togithub.com/actions/checkout/compare/v4.0.0...v4.1.0)
    
    - [Add support for partial checkout
    filters](https://togithub.com/actions/checkout/pull/1396)
    
    ###
    [`v4.0.0`](https://togithub.com/actions/checkout/blob/HEAD/CHANGELOG.md#v400)
    
    [Compare
    Source](https://togithub.com/actions/checkout/compare/v3.6.0...v4.0.0)
    
    - [Support fetching without the --progress
    option](https://togithub.com/actions/checkout/pull/1067)
    -   [Update to node20](https://togithub.com/actions/checkout/pull/1436)
    
    </details>
    
    ---
    
    ### Configuration
    
    📅 **Schedule**: Branch creation - At any time (no schedule defined),
    Automerge - At any time (no schedule defined).
    
    🚦 **Automerge**: Disabled by config. Please merge this manually once you
    are satisfied.
    
    ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
    rebase/retry checkbox.
    
    🔕 **Ignore**: Close this PR and you won't be reminded about this update
    again.
    
    ---
    
    - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
    this box
    
    ---
    
    This PR has been generated by [Mend
    Renovate](https://www.mend.io/free-developer-tools/renovate/). View
    repository job log
    [here](https://developer.mend.io/github/defenseunicorns/zarf).
    
    <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiIzNy4yMDAuMCIsInVwZGF0ZWRJblZlciI6IjM3LjIwMC4wIiwidGFyZ2V0QnJhbmNoIjoibWFpbiJ9-->
    
    Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
    renovate[bot] authored Feb 20, 2024
    Configuration menu
    Copy the full SHA
    ce3f125 View commit details
    Browse the repository at this point in the history
  3. chore(deps): update actions/dependency-review-action action to v4 (#2318

    )
    
    [![Mend
    Renovate](https://app.renovatebot.com/images/banner.svg)](https://renovatebot.com)
    
    This PR contains the following updates:
    
    | Package | Type | Update | Change |
    |---|---|---|---|
    |
    [actions/dependency-review-action](https://togithub.com/actions/dependency-review-action)
    | action | major | `v2.5.1` -> `v4.1.3` |
    
    ---
    
    > [!WARNING]
    > Some dependencies could not be looked up. Check the Dependency
    Dashboard for more information.
    
    ---
    
    ### Release Notes
    
    <details>
    <summary>actions/dependency-review-action
    (actions/dependency-review-action)</summary>
    
    ###
    [`v4.1.3`](https://togithub.com/actions/dependency-review-action/releases/tag/v4.1.3):
    4.1.3
    
    [Compare
    Source](https://togithub.com/actions/dependency-review-action/compare/v4.1.2...v4.1.3)
    
    Fixes a bug in 4.1.2 that would introduce comments in every pull
    request, regardless of the user's configuration (see
    [https://github.com/actions/dependency-review-action/issues/697](https://togithub.com/actions/dependency-review-action/issues/697)).
    
    **Full Changelog**:
    actions/dependency-review-action@v4.1.2...v4.1.3
    
    ###
    [`v4.1.2`](https://togithub.com/actions/dependency-review-action/releases/tag/v4.1.2):
    4.1.2
    
    [Compare
    Source](https://togithub.com/actions/dependency-review-action/compare/v4.1.1...v4.1.2)
    
    #### What's Changed
    
    - Expose dependency comment content by
    [@&#8203;jsoref](https://togithub.com/jsoref) in
    [https://github.com/actions/dependency-review-action/pull/696](https://togithub.com/actions/dependency-review-action/pull/696)
    
    **Full Changelog**:
    actions/dependency-review-action@v4.1.1...v4.1.2
    
    ###
    [`v4.1.1`](https://togithub.com/actions/dependency-review-action/releases/tag/v4.1.1):
    4.1.1
    
    [Compare
    Source](https://togithub.com/actions/dependency-review-action/compare/v4.1.0...v4.1.1)
    
    #### What's Changed
    
    - Bump `undici` to fix
    [GHSA-wqq4-5wpv-mx2g](https://togithub.com/nodejs/undici/security/advisories/GHSA-wqq4-5wpv-mx2g)
    - Bump [@&#8203;types/node](https://togithub.com/types/node) from
    20.11.17 to 20.11.19 by
    [@&#8203;dependabot](https://togithub.com/dependabot) in
    [https://github.com/actions/dependency-review-action/pull/693](https://togithub.com/actions/dependency-review-action/pull/693)
    
    **Full Changelog**:
    actions/dependency-review-action@v4.1.0...v4.1.1
    
    ###
    [`v4.1.0`](https://togithub.com/actions/dependency-review-action/releases/tag/v4.1.0):
    4.1.0
    
    [Compare
    Source](https://togithub.com/actions/dependency-review-action/compare/v4.0.0...v4.1.0)
    
    #### What's Changed
    
    - Add `warn-only` by [@&#8203;tgrall](https://togithub.com/tgrall) in
    [https://github.com/actions/dependency-review-action/pull/432](https://togithub.com/actions/dependency-review-action/pull/432)
    
    Added a new configuration option (`warn-only`, boolean) that makes the
    action always succeed while still displaying found vulnerabilities in
    the log.
    
    - Create stale.yaml by
    [@&#8203;jonjanego](https://togithub.com/jonjanego) in
    [https://github.com/actions/dependency-review-action/pull/671](https://togithub.com/actions/dependency-review-action/pull/671)
    - Use manual codeql config by
    [@&#8203;juxtin](https://togithub.com/juxtin) in
    [https://github.com/actions/dependency-review-action/pull/678](https://togithub.com/actions/dependency-review-action/pull/678)
    - Multiple dependency updates (see the changelog below for more
    information)
    
    #### New Contributors
    
    - [@&#8203;jonjanego](https://togithub.com/jonjanego) made their first
    contribution in
    [https://github.com/actions/dependency-review-action/pull/671](https://togithub.com/actions/dependency-review-action/pull/671)
    - [@&#8203;tgrall](https://togithub.com/tgrall) made their first
    contribution in
    [https://github.com/actions/dependency-review-action/pull/432](https://togithub.com/actions/dependency-review-action/pull/432)
    
    **Full Changelog**:
    actions/dependency-review-action@v4...v4.1.0
    
    ###
    [`v4.0.0`](https://togithub.com/actions/dependency-review-action/releases/tag/v4.0.0)
    
    [Compare
    Source](https://togithub.com/actions/dependency-review-action/compare/v3.1.5...v4.0.0)
    
    - Update action to Node 20 by
    [@&#8203;takost](https://togithub.com/takost) in
    [https://github.com/actions/dependency-review-action/pull/639](https://togithub.com/actions/dependency-review-action/pull/639)
    -   Dependabot updates, see the full changelog for more details.
    
    #### New Contributors
    
    - [@&#8203;takost](https://togithub.com/takost) made their first
    contribution in
    [https://github.com/actions/dependency-review-action/pull/639](https://togithub.com/actions/dependency-review-action/pull/639)
    
    **Full Changelog**:
    actions/dependency-review-action@v3.1.5...v4.0.0
    
    ###
    [`v3.1.5`](https://togithub.com/actions/dependency-review-action/releases/tag/v3.1.5):
    3.1.5
    
    [Compare
    Source](https://togithub.com/actions/dependency-review-action/compare/v3.1.4...v3.1.5)
    
    #### What's Changed
    
    - Smaller `per_page` when requesting diff by
    [@&#8203;hmaurer](https://togithub.com/hmaurer) in
    [https://github.com/actions/dependency-review-action/pull/649](https://togithub.com/actions/dependency-review-action/pull/649)
    -   Update dependencies:
    - Bump
    [@&#8203;typescript-eslint/parser](https://togithub.com/typescript-eslint/parser)
    from 6.10.0 to 6.13.1 by
    [@&#8203;dependabot](https://togithub.com/dependabot) in
    [https://github.com/actions/dependency-review-action/pull/630](https://togithub.com/actions/dependency-review-action/pull/630)
    - Bump prettier from 3.0.3 to 3.1.0 by
    [@&#8203;dependabot](https://togithub.com/dependabot) in
    [https://github.com/actions/dependency-review-action/pull/629](https://togithub.com/actions/dependency-review-action/pull/629)
    - Bump [@&#8203;types/jest](https://togithub.com/types/jest) from 29.5.8
    to 29.5.11 by [@&#8203;dependabot](https://togithub.com/dependabot) in
    [https://github.com/actions/dependency-review-action/pull/637](https://togithub.com/actions/dependency-review-action/pull/637)
    - Bump nodemon from 3.0.1 to 3.0.2 by
    [@&#8203;dependabot](https://togithub.com/dependabot) in
    [https://github.com/actions/dependency-review-action/pull/636](https://togithub.com/actions/dependency-review-action/pull/636)
    - Replace pip -> pypi in PURL examples by
    [@&#8203;febuiles](https://togithub.com/febuiles) in
    [https://github.com/actions/dependency-review-action/pull/638](https://togithub.com/actions/dependency-review-action/pull/638)
    - Bump
    [@&#8203;typescript-eslint/eslint-plugin](https://togithub.com/typescript-eslint/eslint-plugin)
    from 6.12.0 to 6.15.0 by
    [@&#8203;dependabot](https://togithub.com/dependabot) in
    [https://github.com/actions/dependency-review-action/pull/644](https://togithub.com/actions/dependency-review-action/pull/644)
    - Bump eslint from 8.53.0 to 8.56.0 by
    [@&#8203;dependabot](https://togithub.com/dependabot) in
    [https://github.com/actions/dependency-review-action/pull/640](https://togithub.com/actions/dependency-review-action/pull/640)
    - Bump
    [@&#8203;typescript-eslint/parser](https://togithub.com/typescript-eslint/parser)
    from 6.13.1 to 6.16.0 by
    [@&#8203;dependabot](https://togithub.com/dependabot) in
    [https://github.com/actions/dependency-review-action/pull/645](https://togithub.com/actions/dependency-review-action/pull/645)
    - Bump prettier from 3.1.0 to 3.1.1 by
    [@&#8203;dependabot](https://togithub.com/dependabot) in
    [https://github.com/actions/dependency-review-action/pull/646](https://togithub.com/actions/dependency-review-action/pull/646)
    
    **Full Changelog**:
    actions/dependency-review-action@v3.1.4...v3.1.5
    
    ###
    [`v3.1.4`](https://togithub.com/actions/dependency-review-action/releases/tag/v3.1.4):
    3.1.4
    
    [Compare
    Source](https://togithub.com/actions/dependency-review-action/compare/v3.1.3...v3.1.4)
    
    #### What's Changed
    
    - Fixed a
    [bug](https://togithub.com/actions/dependency-review-action/issues/618)
    with severity filtering when using the `allow_ghsas` option:
    [https://github.com/actions/dependency-review-action/pull/623](https://togithub.com/actions/dependency-review-action/pull/623).
    
    -   Updates dependencies:
    - Bump [@&#8203;types/node](https://togithub.com/types/node) from
    16.18.61 to 16.18.62 by
    [@&#8203;dependabot](https://togithub.com/dependabot) in
    [https://github.com/actions/dependency-review-action/pull/619](https://togithub.com/actions/dependency-review-action/pull/619)
            action/pull/620
    - Bump
    [@&#8203;typescript-eslint/eslint-plugin](https://togithub.com/typescript-eslint/eslint-plugin)
    from 6.11.0 to 6.12.0 by
    [@&#8203;dependabot](https://togithub.com/dependabot) in
    [https://github.com/actions/dependency-review-action/pull/625](https://togithub.com/actions/dependency-review-action/pull/625)
    - Bump typescript from 5.2.2 to 5.3.2 by
    [@&#8203;dependabot](https://togithub.com/dependabot) in
    [https://github.com/actions/dependency-review-action/pull/624](https://togithub.com/actions/dependency-review-action/pull/624)
    
    **Full Changelog**:
    actions/dependency-review-action@v3...v3.1.4
    
    ###
    [`v3.1.3`](https://togithub.com/actions/dependency-review-action/releases/tag/v3.1.3):
    3.1.3
    
    [Compare
    Source](https://togithub.com/actions/dependency-review-action/compare/v3.1.2...v3.1.3)
    
    #### What's Changed
    
    - Fixes purl "version must be percent-encoded" by
    [@&#8203;theztefan](https://togithub.com/theztefan) in
    [https://github.com/actions/dependency-review-action/pull/617](https://togithub.com/actions/dependency-review-action/pull/617)
    
    **Full Changelog**:
    actions/dependency-review-action@v3...v3.1.3
    
    ###
    [`v3.1.2`](https://togithub.com/actions/dependency-review-action/releases/tag/v3.1.2):
    3.1.2
    
    [Compare
    Source](https://togithub.com/actions/dependency-review-action/compare/v3.1.1...v3.1.2)
    
    #### What's Changed
    
    - Fix a regression for setups using self-hosted runners behind HTTP
    proxies:[@&#8203;febuiles](https://togithub.com/febuiles) in
    [https://github.com/actions/dependency-review-action/pull/611](https://togithub.com/actions/dependency-review-action/pull/611)
    
    **Full Changelog**:
    actions/dependency-review-action@v3...v3.1.2
    
    ###
    [`v3.1.1`](https://togithub.com/actions/dependency-review-action/releases/tag/v3.1.1):
    3.1.1
    
    [Compare
    Source](https://togithub.com/actions/dependency-review-action/compare/v3.1.0...v3.1.1)
    
    #### What's Changed
    
    - Update a bunch of dependencies, including major version upgrades for
    `octokit`, `@actions/github` and `typescript`.
    
    **Full Changelog**:
    actions/dependency-review-action@v3.1.0...v3.1.1
    
    ###
    [`v3.1.0`](https://togithub.com/actions/dependency-review-action/releases/tag/v3.1.0):
    3.1.0
    
    [Compare
    Source](https://togithub.com/actions/dependency-review-action/compare/v3.0.8...v3.1.0)
    
    #### What's New
    
    Added support for dependencies submitted through the [dependency
    submission
    API](https://docs.github.com/en/code-security/supply-chain-security/understanding-your-software-supply-chain/about-dependency-review#best-practices-for-using-the-dependency-review-api-and-the-dependency-submission-api-together).
    This includes two new configuration parameters:
    `retry-on-snapshot-warnings` and `retry-on-snapshot-warnings-timeout`.
    
    #### What's Changed
    
    - Fix(docs): Correct action input name by
    [@&#8203;oerd](https://togithub.com/oerd) in
    [https://github.com/actions/dependency-review-action/pull/551](https://togithub.com/actions/dependency-review-action/pull/551)
    
    #### New Contributors
    
    - [@&#8203;oerd](https://togithub.com/oerd) made their first
    contribution in
    [https://github.com/actions/dependency-review-action/pull/551](https://togithub.com/actions/dependency-review-action/pull/551)
    
    **Full Changelog**:
    actions/dependency-review-action@v3...v3.1.0
    
    ###
    [`v3.0.8`](https://togithub.com/actions/dependency-review-action/releases/tag/v3.0.8):
    3.0.8
    
    [Compare
    Source](https://togithub.com/actions/dependency-review-action/compare/v3.0.7...v3.0.8)
    
    #### What's Changed
    
    Added `on-failure` option to `comment-summary-in-pr` setting by
    [@&#8203;sgmurphy](https://togithub.com/sgmurphy) in
    [https://github.com/actions/dependency-review-action/pull/540](https://togithub.com/actions/dependency-review-action/pull/540)
    
    Previous configuration files using `true`/`false` for
    `comment-summary-in-pr` will be mapped automatically to the new values,
    but we encourage you to update to `always`/`on-failure`/`never`.
    
    #### New Contributors
    
    - [@&#8203;sgmurphy](https://togithub.com/sgmurphy) made their first
    contribution in
    [https://github.com/actions/dependency-review-action/pull/540](https://togithub.com/actions/dependency-review-action/pull/540)
    
    **Full Changelog**:
    actions/dependency-review-action@v3...v3.0.8
    
    ###
    [`v3.0.7`](https://togithub.com/actions/dependency-review-action/releases/tag/v3.0.7):
    3.0.7
    
    [Compare
    Source](https://togithub.com/actions/dependency-review-action/compare/v3.0.6...v3.0.7)
    
    #### What's Changed
    
    - Make GHES support / setup more clear by
    [@&#8203;rajbos](https://togithub.com/rajbos) in
    [https://github.com/actions/dependency-review-action/pull/534](https://togithub.com/actions/dependency-review-action/pull/534)
    - Add an option to deny packages or groups of packages by
    [@&#8203;adrienpessu](https://togithub.com/adrienpessu) in
    [https://github.com/actions/dependency-review-action/pull/544](https://togithub.com/actions/dependency-review-action/pull/544)
    
    #### New Contributors
    
    - [@&#8203;rajbos](https://togithub.com/rajbos) made their first
    contribution in
    [https://github.com/actions/dependency-review-action/pull/534](https://togithub.com/actions/dependency-review-action/pull/534)
    - [@&#8203;adrienpessu](https://togithub.com/adrienpessu) made their
    first contribution in
    [https://github.com/actions/dependency-review-action/pull/544](https://togithub.com/actions/dependency-review-action/pull/544)
    
    **Full Changelog**:
    actions/dependency-review-action@v3...v3.0.7
    
    ###
    [`v3.0.6`](https://togithub.com/actions/dependency-review-action/releases/tag/v3.0.6):
    3.0.6
    
    [Compare
    Source](https://togithub.com/actions/dependency-review-action/compare/v3.0.5...v3.0.6)
    
    Fixes a bug introduced in 3.0.5 where we raised PURL errors when
    Dependency Graph returns an empty `package_url`.
    
    ###
    [`v3.0.5`](https://togithub.com/actions/dependency-review-action/releases/tag/v3.0.5):
    3.0.5
    
    [Compare
    Source](https://togithub.com/actions/dependency-review-action/compare/v3.0.4...v3.0.5)
    
    #### What's Changed
    
    Thanks to [@&#8203;theztefan](https://togithub.com/theztefan), we now
    have a new `allow-dependencies-licenses` option that takes a list of
    dependencies that will be excluded from license checks. See the
    [configuration
    options](https://togithub.com/actions/dependency-review-action#configuration-options)
    for more information on how to use it.
    
    - Exclude dependencies from license checks by
    [@&#8203;theztefan](https://togithub.com/theztefan) in
    [https://github.com/actions/dependency-review-action/pull/423](https://togithub.com/actions/dependency-review-action/pull/423)
    - Documentation examples by
    [@&#8203;theztefan](https://togithub.com/theztefan) in
    [https://github.com/actions/dependency-review-action/pull/423](https://togithub.com/actions/dependency-review-action/pull/423)
    - Show snapshot warnings in the summary by
    [@&#8203;juxtin](https://togithub.com/juxtin) in
    [https://github.com/actions/dependency-review-action/pull/439](https://togithub.com/actions/dependency-review-action/pull/439)
    - Fix default values for fail-on-severity by
    [@&#8203;febuiles](https://togithub.com/febuiles) in
    [https://github.com/actions/dependency-review-action/pull/451](https://togithub.com/actions/dependency-review-action/pull/451)
    -   Updated dependencies.
    
    #### New Contributors
    
    - [@&#8203;juxtin](https://togithub.com/juxtin) made their first
    contribution in
    [https://github.com/actions/dependency-review-action/pull/439](https://togithub.com/actions/dependency-review-action/pull/439)
    - [@&#8203;theztefan](https://togithub.com/theztefan) made their first
    contribution in
    [https://github.com/actions/dependency-review-action/pull/423](https://togithub.com/actions/dependency-review-action/pull/423)
    
    **Full Changelog**:
    actions/dependency-review-action@v3...v3.0.5
    
    ###
    [`v3.0.4`](https://togithub.com/actions/dependency-review-action/releases/tag/v3.0.4):
    3.0.4
    
    [Compare
    Source](https://togithub.com/actions/dependency-review-action/compare/v3.0.3...v3.0.4)
    
    #### What's New?
    
    The Action can now publish a comment in the pull request if the
    `comment-summary-in-pr` option is set. More information can be found in
    the
    [README](https://togithub.com/actions/dependency-review-action#configuration-options).
    
    #### New Contributors
    
    - [@&#8203;davelosert](https://togithub.com/davelosert) made their first
    contribution in
    [https://github.com/actions/dependency-review-action/pull/393](https://togithub.com/actions/dependency-review-action/pull/393)
    
    #### Changelog
    
    - Write Summary as comment to the pull request by
    [@&#8203;davelosert](https://togithub.com/davelosert) in
    [https://github.com/actions/dependency-review-action/pull/393](https://togithub.com/actions/dependency-review-action/pull/393)
    - Adjust summary format by
    [@&#8203;davelosert](https://togithub.com/davelosert) in
    [https://github.com/actions/dependency-review-action/pull/416](https://togithub.com/actions/dependency-review-action/pull/416)
    -   Security updates.
    
    **Full Changelog**:
    actions/dependency-review-action@v3...v3.0.4
    
    ###
    [`v3.0.3`](https://togithub.com/actions/dependency-review-action/releases/tag/v3.0.3):
    3.0.3
    
    [Compare
    Source](https://togithub.com/actions/dependency-review-action/compare/v3.0.2...v3.0.3)
    
    #### What's Changed
    
    - Use cache in check-dist.yml by
    [@&#8203;jongwooo](https://togithub.com/jongwooo) in
    [https://github.com/actions/dependency-review-action/pull/359](https://togithub.com/actions/dependency-review-action/pull/359)
    - Fix Dependency Review API response error handling by
    [@&#8203;felickz](https://togithub.com/felickz) in
    [https://github.com/actions/dependency-review-action/pull/370](https://togithub.com/actions/dependency-review-action/pull/370)
    -   Security updates
    
    #### New Contributors
    
    - [@&#8203;jongwooo](https://togithub.com/jongwooo) made their first
    contribution in
    [https://github.com/actions/dependency-review-action/pull/359](https://togithub.com/actions/dependency-review-action/pull/359)
    - [@&#8203;felickz](https://togithub.com/felickz) made their first
    contribution in
    [https://github.com/actions/dependency-review-action/pull/370](https://togithub.com/actions/dependency-review-action/pull/370)
    
    **Full Changelog**:
    actions/dependency-review-action@v3...v3.0.3
    
    ###
    [`v3.0.2`](https://togithub.com/actions/dependency-review-action/releases/tag/v3.0.2):
    3.0.2
    
    [Compare
    Source](https://togithub.com/actions/dependency-review-action/compare/v3.0.1...v3.0.2)
    
    This release fixes spelling errors
    [https://github.com/actions/dependency-review-action/pull/348](https://togithub.com/actions/dependency-review-action/pull/348)
    and upgrades dependencies to fix known vulnerabilities
    
    **Full Changelog**:
    actions/dependency-review-action@v3...v3.0.2
    
    ###
    [`v3.0.1`](https://togithub.com/actions/dependency-review-action/releases/tag/v3.0.1):
    3.0.1
    
    [Compare
    Source](https://togithub.com/actions/dependency-review-action/compare/v3.0.0...v3.0.1)
    
    This release contains the following bugfixes:
    
    - Fixing API URL for GHES:
    [https://github.com/actions/dependency-review-action/pull/331](https://togithub.com/actions/dependency-review-action/pull/331)
    - Improve list handling for external config files:
    [https://github.com/actions/dependency-review-action/pull/330](https://togithub.com/actions/dependency-review-action/pull/330)
    
    **Full Changelog**:
    actions/dependency-review-action@v3...v3.0.1
    
    ###
    [`v3.0.0`](https://togithub.com/actions/dependency-review-action/releases/tag/v3.0.0):
    3.0.0
    
    [Compare
    Source](https://togithub.com/actions/dependency-review-action/compare/v2.5.1...v3.0.0)
    
    #### Breaking Changes
    
    By default the action now expects [SPDX-compliant
    licenses](https://spdx.org/licenses/) everywhere. If you were previously
    using license names in the allow or deny lists make sure they're valid!
    
    #### What's Changed
    
    ##### Support for external configuration files
    
    You can now specify a [configuration file external to your
    repository](https://togithub.com/actions/dependency-review-action/#configuration-file).
    This allows organizations to have a single configuration file for all
    their repos.
    
    ##### Broader license support
    
    We've added support for a much broader set of project licenses by using
    GitHub's [Licenses API](https://docs.github.com/en/rest/licenses).
    
    ##### SPDX Compliance
    
    All of our license-related code now expects [SPDX-compliant licenses or
    expressions](https://spdx.org/licenses/). This allows us to standardize
    on a license naming scheme that already supports `OR`/`AND` expressions.
    
    ##### Disable individual checks
    
    You can now use the boolean options `license-check` and
    `vulnerability-check` to disable either one of the checks. More
    information in [our configuration
    options](https://togithub.com/actions/dependency-review-action/#configuration-options).
    
    #### Thanks
    
    Contributors for this release include:
    
    -   [@&#8203;cnagadya](https://togithub.com/cnagadya)
    -   [@&#8203;courtneycl](https://togithub.com/courtneycl)
    -   [@&#8203;ericcornelissen](https://togithub.com/ericcornelissen)
    -   [@&#8203;elireisman](https://togithub.com/elireisman)
    -   [@&#8203;hmaurer](https://togithub.com/hmaurer)
    
    Thanks everyone!
    **Full Changelog**:
    actions/dependency-review-action@v2...v3.0.0
    
    </details>
    
    ---
    
    ### Configuration
    
    📅 **Schedule**: Branch creation - At any time (no schedule defined),
    Automerge - At any time (no schedule defined).
    
    🚦 **Automerge**: Disabled by config. Please merge this manually once you
    are satisfied.
    
    ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
    rebase/retry checkbox.
    
    🔕 **Ignore**: Close this PR and you won't be reminded about this update
    again.
    
    ---
    
    - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
    this box
    
    ---
    
    This PR has been generated by [Mend
    Renovate](https://www.mend.io/free-developer-tools/renovate/). View
    repository job log
    [here](https://developer.mend.io/github/defenseunicorns/zarf).
    
    <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiIzNy4yMDAuMCIsInVwZGF0ZWRJblZlciI6IjM3LjIwMC4wIiwidGFyZ2V0QnJhbmNoIjoibWFpbiJ9-->
    
    Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
    renovate[bot] authored Feb 20, 2024
    Configuration menu
    Copy the full SHA
    a5ae1aa View commit details
    Browse the repository at this point in the history
  4. fix: multi-part tarballs being mismatched sizes (#2314)

    ## Description
    
    This fixes multipart tarballs being different sizes with
    `--max-package-size`
    
    ## Related Issue
    
    Fixes #2313
    
    ## Type of change
    
    - [X] Bug fix (non-breaking change which fixes an issue)
    - [ ] New feature (non-breaking change which adds functionality)
    - [ ] Other (security config, docs update, etc)
    
    ## Checklist before merging
    
    - [X] Test, docs, adr added or updated as needed
    - [X] [Contributor Guide
    Steps](https://github.com/defenseunicorns/zarf/blob/main/CONTRIBUTING.md#developer-workflow)
    followed
    
    ---------
    
    Co-authored-by: Austin Abro <37223396+AustinAbro321@users.noreply.github.com>
    Co-authored-by: Lucas Rodriguez <lucas.rodriguez9616@gmail.com>
    Co-authored-by: Lucas Rodriguez <lucas.rodriguez@defenseunicorns.com>
    4 people authored Feb 20, 2024
    Configuration menu
    Copy the full SHA
    07541a6 View commit details
    Browse the repository at this point in the history

Commits on Feb 21, 2024

  1. fix: change text detect to check first and last 512 bytes (#2310)

    ## Description
    
    Alters text detection logic to read the first and last 512 bytes.
    
    Tested with 5 files:
    - [NVIDIA
    installer](https://us.download.nvidia.com/XFree86/Linux-x86_64/535.154.05/NVIDIA-Linux-x86_64-535.154.05.run)
        Detected as application type when reading last 512.
    - 3 4k size files of junk text with a ZARF_CONST replacement, in
    straight text, yaml, and json
        All 3 detected as text/plain, ZARF_CONST was replaced.
    - 1 small 100 byte file with a ZARF_CONST replacement.
       Was still detected as text and ZARF_CONST was replaced.
      
    Existing unit tests succeeded.
    
    ## Related Issue
    
    Fixes #2308
    <!-- or -->
    Relates to #
    
    ## Type of change
    
    - [x] Bug fix (non-breaking change which fixes an issue)
    - [ ] New feature (non-breaking change which adds functionality)
    - [ ] Other (security config, docs update, etc)
    
    ## Checklist before merging
    
    - [x] Test, docs, adr added or updated as needed
    - [x] [Contributor Guide
    Steps](https://github.com/defenseunicorns/zarf/blob/main/CONTRIBUTING.md#developer-workflow)
    followed
    
    ---------
    
    Co-authored-by: Wayne Starr <Racer159@users.noreply.github.com>
    WeaponX314 and Racer159 authored Feb 21, 2024
    Configuration menu
    Copy the full SHA
    cf1d1e4 View commit details
    Browse the repository at this point in the history
  2. chore: hotfix fix codeql issues across Zarf (#2322)

    ## Description
    
    This fixes the codeql issues that are currently in the Zarf codebase
    
    ## Related Issue
    
    Fixes #N/A
    
    ## Type of change
    
    - [ ] Bug fix (non-breaking change which fixes an issue)
    - [ ] New feature (non-breaking change which adds functionality)
    - [X] Other (security config, docs update, etc)
    
    ## Checklist before merging
    
    - [X] Test, docs, adr added or updated as needed
    - [X] [Contributor Guide
    Steps](https://github.com/defenseunicorns/zarf/blob/main/CONTRIBUTING.md#developer-workflow)
    followed
    Racer159 authored Feb 21, 2024
    Configuration menu
    Copy the full SHA
    5e1c6df View commit details
    Browse the repository at this point in the history
  3. feat: improve zarf tools registry prune messaging (#2323)

    ## Description
    
    This PR fixes the `zarf tools registry prune` messaging to be more
    verbose.
    
    ## Related Issue
    
    Fixes #N/A
    
    ## Type of change
    
    - [ ] Bug fix (non-breaking change which fixes an issue)
    - [ ] New feature (non-breaking change which adds functionality)
    - [X] Other (security config, docs update, etc)
    
    ## Checklist before merging
    
    - [X] Test, docs, adr added or updated as needed
    - [X] [Contributor Guide
    Steps](https://github.com/defenseunicorns/zarf/blob/main/CONTRIBUTING.md#developer-workflow)
    followed
    Racer159 authored Feb 21, 2024
    Configuration menu
    Copy the full SHA
    714f7c0 View commit details
    Browse the repository at this point in the history

Commits on Feb 23, 2024

  1. fix(deps): update module helm.sh/helm/v3 to v3.14.2 [security] (#2329)

    [![Mend
    Renovate](https://app.renovatebot.com/images/banner.svg)](https://renovatebot.com)
    
    This PR contains the following updates:
    
    | Package | Change | Age | Adoption | Passing | Confidence |
    |---|---|---|---|---|---|
    | [helm.sh/helm/v3](https://togithub.com/helm/helm) | `v3.14.1` ->
    `v3.14.2` |
    [![age](https://developer.mend.io/api/mc/badges/age/go/helm.sh%2fhelm%2fv3/v3.14.2?slim=true)](https://docs.renovatebot.com/merge-confidence/)
    |
    [![adoption](https://developer.mend.io/api/mc/badges/adoption/go/helm.sh%2fhelm%2fv3/v3.14.2?slim=true)](https://docs.renovatebot.com/merge-confidence/)
    |
    [![passing](https://developer.mend.io/api/mc/badges/compatibility/go/helm.sh%2fhelm%2fv3/v3.14.1/v3.14.2?slim=true)](https://docs.renovatebot.com/merge-confidence/)
    |
    [![confidence](https://developer.mend.io/api/mc/badges/confidence/go/helm.sh%2fhelm%2fv3/v3.14.1/v3.14.2?slim=true)](https://docs.renovatebot.com/merge-confidence/)
    |
    
    ---
    
    > [!WARNING]
    > Some dependencies could not be looked up. Check the Dependency
    Dashboard for more information.
    
    ### GitHub Vulnerability Alerts
    
    ####
    [CVE-2024-26147](https://togithub.com/helm/helm/security/advisories/GHSA-r53h-jv2g-vpx6)
    
    A Helm contributor discovered uninitialized variable vulnerability when
    Helm parses index and plugin yaml files missing expected content.
    
    ### Impact
    
    When either an `index.yaml` file or a plugins `plugin.yaml` file were
    missing all metadata a panic would occur in Helm.
    
    In the Helm SDK this is found when using the `LoadIndexFile` or
    `DownloadIndexFile` functions in the `repo` package or the `LoadDir`
    function in the `plugin` package. For the Helm client this impacts
    functions around adding a repository and all Helm functions if a
    malicious plugin is added as Helm inspects all known plugins on each
    invocation.
    
    ### Patches
    
    This issue has been resolved in Helm v3.14.2.
    
    ### Workarounds
    
    If a malicious plugin has been added which is causing all Helm client
    commands to panic, the malicious plugin can be manually removed from the
    filesystem.
    
    If using Helm SDK versions prior to 3.14.2, calls to affected functions
    can use `recover` to catch the panic.
    
    ### For more information
    
    Helm's security policy is spelled out in detail in our
    [SECURITY](https://togithub.com/helm/community/blob/master/SECURITY.md)
    document.
    
    ### Credits
    
    Disclosed by Jakub Ciolek at AlphaSense.
    
    ---
    
    ### Release Notes
    
    <details>
    <summary>helm/helm (helm.sh/helm/v3)</summary>
    
    ### [`v3.14.2`](https://togithub.com/helm/helm/releases/tag/v3.14.2):
    Helm v3.14.2
    
    [Compare
    Source](https://togithub.com/helm/helm/compare/v3.14.1...v3.14.2)
    
    Helm v3.14.2 is a security (patch) release. Users are strongly
    recommended to update to this release.
    
    A Helm contributor discovered uninitialized variable vulnerability when
    Helm parses index and plugin yaml files missing expected content.
    
    Jakub Ciolek with AlphaSense discovered the vulnerability.
    
    #### Installation and Upgrading
    
    Download Helm v3.14.2. The common platform binaries are here:
    
    - [MacOS amd64](https://get.helm.sh/helm-v3.14.2-darwin-amd64.tar.gz)
    ([checksum](https://get.helm.sh/helm-v3.14.2-darwin-amd64.tar.gz.sha256sum)
    / 64c633ae194bde77b7e7b7936a2814a7417817dc8b7bb7d270bd24a7a17b8d12)
    - [MacOS arm64](https://get.helm.sh/helm-v3.14.2-darwin-arm64.tar.gz)
    ([checksum](https://get.helm.sh/helm-v3.14.2-darwin-arm64.tar.gz.sha256sum)
    / ff502fd39b06497fa3d5a51ec2ced02b9fcfdb0e9a948d315fb1b2f13ddc39fb)
    - [Linux amd64](https://get.helm.sh/helm-v3.14.2-linux-amd64.tar.gz)
    ([checksum](https://get.helm.sh/helm-v3.14.2-linux-amd64.tar.gz.sha256sum)
    / 0885a501d586c1e949e9b113bf3fb3290b0bbf74db9444a1d8c2723a143006a5)
    - [Linux arm](https://get.helm.sh/helm-v3.14.2-linux-arm.tar.gz)
    ([checksum](https://get.helm.sh/helm-v3.14.2-linux-arm.tar.gz.sha256sum)
    / b70fb6fa2cdf0a5c782320c9d7e7b155fcaec260169218c98316bb3cf0d431d9)
    - [Linux arm64](https://get.helm.sh/helm-v3.14.2-linux-arm64.tar.gz)
    ([checksum](https://get.helm.sh/helm-v3.14.2-linux-arm64.tar.gz.sha256sum)
    / c65d6a9557bb359abc2c0d26670de850b52327dc3976ad6f9e14c298ea3e1b61)
    - [Linux i386](https://get.helm.sh/helm-v3.14.2-linux-386.tar.gz)
    ([checksum](https://get.helm.sh/helm-v3.14.2-linux-386.tar.gz.sha256sum)
    / 0e08cd56cc952ab4646c57c5ec7cde2412c39373aec3df659a14597dd9874461)
    - [Linux ppc64le](https://get.helm.sh/helm-v3.14.2-linux-ppc64le.tar.gz)
    ([checksum](https://get.helm.sh/helm-v3.14.2-linux-ppc64le.tar.gz.sha256sum)
    / f3bc8582ff151e619cd285d9cdf9fef1c5733ee5522d8bed2ef680ef07f87223)
    - [Linux s390x](https://get.helm.sh/helm-v3.14.2-linux-s390x.tar.gz)
    ([checksum](https://get.helm.sh/helm-v3.14.2-linux-s390x.tar.gz.sha256sum)
    / 7bda34aa26638e5116b31385f3b781172572175bf4c1ae00c87d8b154458ed94)
    - [Linux riscv64](https://get.helm.sh/helm-v3.14.2-linux-riscv64.tar.gz)
    ([checksum](https://get.helm.sh/helm-v3.14.2-linux-riscv64.tar.gz.sha256sum)
    / f6278facd3e2e6af52a5f6d038f2149428d115ba2b4523edbe5889d1170e9203)
    - [Windows amd64](https://get.helm.sh/helm-v3.14.2-windows-amd64.zip)
    ([checksum](https://get.helm.sh/helm-v3.14.2-windows-amd64.zip.sha256sum)
    / aa094e435da74ad574f96924c37ecd0c75f0be707ac604ef97ed6021d6bc0784)
    
    This release was signed with ` 672C 657B E06B 4B30 969C 4A57 4614 49C2
    5E36 B98E ` and can be found at
    [@&#8203;mattfarina](https://togithub.com/mattfarina) [keybase
    account](https://keybase.io/mattfarina). Please use the attached
    signatures for verifying this release using `gpg`.
    
    The [Quickstart Guide](https://helm.sh/docs/intro/quickstart/) will get
    you going from there. For **upgrade instructions** or detailed
    installation notes, check the [install
    guide](https://helm.sh/docs/intro/install/). You can also use a [script
    to
    install](https://raw.githubusercontent.com/helm/helm/main/scripts/get-helm-3)
    on any system with `bash`.
    
    #### What's Next
    
    - 3.14.3 will contain only bug fixes and be released on March 13, 2024.
    -   3.15.0 is the next feature release and will be on May 08, 2024.
    
    </details>
    
    ---
    
    ### Configuration
    
    📅 **Schedule**: Branch creation - "" (UTC), Automerge - At any time (no
    schedule defined).
    
    🚦 **Automerge**: Enabled.
    
    ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
    rebase/retry checkbox.
    
    🔕 **Ignore**: Close this PR and you won't be reminded about this update
    again.
    
    ---
    
    - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
    this box
    
    ---
    
    This PR has been generated by [Mend
    Renovate](https://www.mend.io/free-developer-tools/renovate/). View
    repository job log
    [here](https://developer.mend.io/github/defenseunicorns/zarf).
    
    <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiIzNy4yMDAuMCIsInVwZGF0ZWRJblZlciI6IjM3LjIwMC4wIiwidGFyZ2V0QnJhbmNoIjoibWFpbiJ9-->
    
    Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
    renovate[bot] authored Feb 23, 2024
    Configuration menu
    Copy the full SHA
    5852603 View commit details
    Browse the repository at this point in the history
  2. chore: update Zarf roadmap per 2024 goals (#2305)

    ## Description
    
    This PR updates the Zarf roadmap per our 2024 project goals (delaying GA
    and focusing on OpenSSF donation).
    
    ## Related Issue
    
    Fixes #N/A
    
    ## Type of change
    
    - [ ] Bug fix (non-breaking change which fixes an issue)
    - [ ] New feature (non-breaking change which adds functionality)
    - [X] Other (security config, docs update, etc)
    
    ## Checklist before merging
    
    - [X] Test, docs, adr added or updated as needed
    - [X] [Contributor Guide
    Steps](https://github.com/defenseunicorns/zarf/blob/main/CONTRIBUTING.md#developer-workflow)
    followed
    
    ---------
    
    Co-authored-by: Lucas Rodriguez <lucas.rodriguez@defenseunicorns.com>
    Co-authored-by: Lucas Rodriguez <lucas.rodriguez9616@gmail.com>
    3 people authored Feb 23, 2024
    Configuration menu
    Copy the full SHA
    ed8319c View commit details
    Browse the repository at this point in the history
  3. fix: add http request header timeout to help stalling image push (#2319)

    ## Description
    
    This is a test for fixes to intermittent hanging.
    
    ## Related Issue
    
    Relates to #1444
    
    ## Type of change
    
    - [X] Bug fix (non-breaking change which fixes an issue)
    - [ ] New feature (non-breaking change which adds functionality)
    - [ ] Other (security config, docs update, etc)
    
    ## Checklist before merging
    
    - [X] Test, docs, adr added or updated as needed
    - [X] [Contributor Guide
    Steps](https://github.com/defenseunicorns/zarf/blob/main/CONTRIBUTING.md#developer-workflow)
    followed
    Racer159 authored Feb 23, 2024
    Configuration menu
    Copy the full SHA
    51b78e1 View commit details
    Browse the repository at this point in the history

Commits on Feb 26, 2024

  1. fix: allow host+subpath as the source registry for registry-override (#…

    …2306)
    
    ## Description
    
    Instead of looking for refInfo.Host in the override map loop through the
    keys and values in i.RegistryOverrides, check if the refInfo.Reference
    begins with an override key and, if it does, replace that override text
    with the override value and set it back to actualSrc.
    
    Do not use ImageTransformHostWithoutChecksum since we already have the
    parsed ref and all the info we need to do the replacement.
    
    ## Related Issue
    
    Fixes #2135 
    
    ## Type of change
    
    - [x] Bug fix (non-breaking change which fixes an issue)
    - [ ] New feature (non-breaking change which adds functionality)
    - [ ] Other (security config, docs update, etc)
    
    ## Checklist before merging
    
    - [x] Test, docs, adr added or updated as needed
    - [x] [Contributor Guide
    Steps](https://github.com/defenseunicorns/zarf/blob/main/CONTRIBUTING.md#developer-workflow)
    followed
    
    ---------
    
    Signed-off-by: Vibhav Bobade <vibhav.bobde@gmail.com>
    Co-authored-by: Wayne Starr <Racer159@users.noreply.github.com>
    Co-authored-by: Austin Abro <37223396+AustinAbro321@users.noreply.github.com>
    3 people authored Feb 26, 2024
    Configuration menu
    Copy the full SHA
    f6b83e1 View commit details
    Browse the repository at this point in the history
Loading