Script 'mail_helper' called by obssrc Hello community, here is the log from the commit of package kyverno for openSUSE:Factory checked in at 2022-09-27 20:13:53 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Comparing /work/SRC/openSUSE:Factory/kyverno (Old) and /work/SRC/openSUSE:Factory/.kyverno.new.2275 (New) ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "kyverno" Tue Sep 27 20:13:53 2022 rev:8 rq:1006338 version:1.7.4 Changes: -------- --- /work/SRC/openSUSE:Factory/kyverno/kyverno.changes 2022-09-08 14:22:51.286558293 +0200 +++ /work/SRC/openSUSE:Factory/.kyverno.new.2275/kyverno.changes 2022-09-27 20:13:55.737826788 +0200 @@ -1,0 +2,9 @@ +Tue Sep 27 06:32:11 UTC 2022 - ka...@b1-systems.de + +- Update to version 1.7.4: + * fix: update github action to use current workflow path (#4705) + * tag v1.7.4 (#4698) + * fix: incorrect namespace in report controller (#4637) (#4688) + * Fix issue for wildcard versions (#4670) (#4674) + +------------------------------------------------------------------- Old: ---- kyverno-1.7.3.tar.gz New: ---- kyverno-1.7.4.tar.gz ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Other differences: ------------------ ++++++ kyverno.spec ++++++ --- /var/tmp/diff_new_pack.5mjWaA/_old 2022-09-27 20:13:56.697828905 +0200 +++ /var/tmp/diff_new_pack.5mjWaA/_new 2022-09-27 20:13:56.701828914 +0200 @@ -19,7 +19,7 @@ %define __arch_install_post export NO_BRP_STRIP_DEBUG=true Name: kyverno -Version: 1.7.3 +Version: 1.7.4 Release: 0 Summary: CLI and kubectl plugin for Kyverno License: Apache-2.0 ++++++ _service ++++++ --- /var/tmp/diff_new_pack.5mjWaA/_old 2022-09-27 20:13:56.729828976 +0200 +++ /var/tmp/diff_new_pack.5mjWaA/_new 2022-09-27 20:13:56.729828976 +0200 @@ -3,7 +3,7 @@ <param name="url">https://github.com/kyverno/kyverno</param> <param name="scm">git</param> <param name="exclude">.git</param> - <param name="revision">v1.7.3</param> + <param name="revision">v1.7.4</param> <param name="versionformat">@PARENT_TAG@</param> <param name="changesgenerate">enable</param> <param name="versionrewrite-pattern">v(.*)</param> @@ -17,7 +17,7 @@ <param name="compression">gz</param> </service> <service name="go_modules" mode="disabled"> - <param name="archive">kyverno-1.7.3.tar.gz</param> + <param name="archive">kyverno-1.7.4.tar.gz</param> </service> </services> ++++++ _servicedata ++++++ --- /var/tmp/diff_new_pack.5mjWaA/_old 2022-09-27 20:13:56.753829029 +0200 +++ /var/tmp/diff_new_pack.5mjWaA/_new 2022-09-27 20:13:56.757829037 +0200 @@ -1,6 +1,6 @@ <servicedata> <service name="tar_scm"> <param name="url">https://github.com/kyverno/kyverno</param> - <param name="changesrevision">f2b63cef77d31697191c63aeef9972ee534974d3</param></service></servicedata> + <param name="changesrevision">d6a72d4412756371b74fa5ef0387b88233a5a19b</param></service></servicedata> (No newline at EOF) ++++++ kyverno-1.7.3.tar.gz -> kyverno-1.7.4.tar.gz ++++++ diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/kyverno-1.7.3/.github/workflows/image.yaml new/kyverno-1.7.4/.github/workflows/image.yaml --- old/kyverno-1.7.3/.github/workflows/image.yaml 2022-08-24 18:02:37.000000000 +0200 +++ new/kyverno-1.7.4/.github/workflows/image.yaml 2022-09-26 17:49:08.000000000 +0200 @@ -12,7 +12,7 @@ jobs: push-init-kyverno: - uses: kyverno/kyverno/.github/workflows/reuse.yaml@main + uses: ./.github/workflows/reuse.yaml with: publish_command: docker-publish-initContainer digest_command: docker-get-initContainer-digest @@ -23,7 +23,7 @@ registry_password: ${{ secrets.CR_PAT }} push-kyverno: - uses: kyverno/kyverno/.github/workflows/reuse.yaml@main + uses: ./.github/workflows/reuse.yaml with: publish_command: docker-publish-kyverno digest_command: docker-get-kyverno-digest @@ -34,7 +34,7 @@ registry_password: ${{ secrets.CR_PAT }} push-kyverno-cli: - uses: kyverno/kyverno/.github/workflows/reuse.yaml@main + uses: ./.github/workflows/reuse.yaml with: publish_command: docker-publish-cli digest_command: docker-get-cli-digest diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/kyverno-1.7.3/.github/workflows/release.yaml new/kyverno-1.7.4/.github/workflows/release.yaml --- old/kyverno-1.7.3/.github/workflows/release.yaml 2022-08-24 18:02:37.000000000 +0200 +++ new/kyverno-1.7.4/.github/workflows/release.yaml 2022-09-26 17:49:08.000000000 +0200 @@ -10,7 +10,7 @@ contents: read packages: write id-token: write - uses: kyverno/kyverno/.github/workflows/reuse.yaml@main + uses: ./.github/workflows/reuse.yaml with: publish_command: docker-publish-initContainer digest_command: docker-get-initContainer-digest @@ -26,7 +26,7 @@ contents: read packages: write id-token: write - uses: kyverno/kyverno/.github/workflows/reuse.yaml@main + uses: ./.github/workflows/reuse.yaml with: publish_command: docker-publish-kyverno digest_command: docker-get-kyverno-digest @@ -42,7 +42,7 @@ contents: read packages: write id-token: write - uses: kyverno/kyverno/.github/workflows/reuse.yaml@main + uses: ./.github/workflows/reuse.yaml with: publish_command: docker-publish-cli digest_command: docker-get-cli-digest @@ -121,4 +121,4 @@ - name: Update new version in krew-index if: steps.check-tag.outputs.match == 'true' - uses: rajatjindal/krew-release-bot@3320c0b546b5d2320613c46762bd3f73e2801bdc # v0.0.38 \ No newline at end of file + uses: rajatjindal/krew-release-bot@3320c0b546b5d2320613c46762bd3f73e2801bdc # v0.0.38 diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/kyverno-1.7.3/charts/kyverno/Chart.yaml new/kyverno-1.7.4/charts/kyverno/Chart.yaml --- old/kyverno-1.7.3/charts/kyverno/Chart.yaml 2022-08-24 18:02:37.000000000 +0200 +++ new/kyverno-1.7.4/charts/kyverno/Chart.yaml 2022-09-26 17:49:08.000000000 +0200 @@ -1,8 +1,8 @@ apiVersion: v2 type: application name: kyverno -version: v2.5.3 -appVersion: v1.7.3 +version: v2.5.4 +appVersion: v1.7.4 icon: https://github.com/kyverno/kyverno/raw/main/img/logo.png description: Kubernetes Native Policy Management keywords: diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/kyverno-1.7.3/charts/kyverno/README.md new/kyverno-1.7.4/charts/kyverno/README.md --- old/kyverno-1.7.3/charts/kyverno/README.md 2022-08-24 18:02:37.000000000 +0200 +++ new/kyverno-1.7.4/charts/kyverno/README.md 2022-09-26 17:49:08.000000000 +0200 @@ -2,7 +2,7 @@ Kubernetes Native Policy Management -   +   ## About diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/kyverno-1.7.3/charts/kyverno/templates/crds.yaml new/kyverno-1.7.4/charts/kyverno/templates/crds.yaml --- old/kyverno-1.7.3/charts/kyverno/templates/crds.yaml 2022-08-24 18:02:37.000000000 +0200 +++ new/kyverno-1.7.4/charts/kyverno/templates/crds.yaml 2022-09-26 17:49:08.000000000 +0200 @@ -12,7 +12,7 @@ app.kubernetes.io/instance: kyverno app.kubernetes.io/name: kyverno app.kubernetes.io/part-of: kyverno - app.kubernetes.io/version: v1.7.3 + app.kubernetes.io/version: v1.7.4 name: clusterpolicies.kyverno.io spec: group: kyverno.io @@ -1625,7 +1625,7 @@ app.kubernetes.io/instance: kyverno app.kubernetes.io/name: kyverno app.kubernetes.io/part-of: kyverno - app.kubernetes.io/version: v1.7.3 + app.kubernetes.io/version: v1.7.4 name: clusterpolicyreports.wgpolicyk8s.io spec: group: wgpolicyk8s.io @@ -1891,7 +1891,7 @@ app.kubernetes.io/instance: kyverno app.kubernetes.io/name: kyverno app.kubernetes.io/part-of: kyverno - app.kubernetes.io/version: v1.7.3 + app.kubernetes.io/version: v1.7.4 name: clusterreportchangerequests.kyverno.io spec: group: kyverno.io @@ -2157,7 +2157,7 @@ app.kubernetes.io/instance: kyverno app.kubernetes.io/name: kyverno app.kubernetes.io/part-of: kyverno - app.kubernetes.io/version: v1.7.3 + app.kubernetes.io/version: v1.7.4 name: generaterequests.kyverno.io spec: group: kyverno.io @@ -2332,7 +2332,7 @@ app.kubernetes.io/instance: kyverno app.kubernetes.io/name: kyverno app.kubernetes.io/part-of: kyverno - app.kubernetes.io/version: v1.7.3 + app.kubernetes.io/version: v1.7.4 name: policies.kyverno.io spec: group: kyverno.io @@ -3945,7 +3945,7 @@ app.kubernetes.io/instance: kyverno app.kubernetes.io/name: kyverno app.kubernetes.io/part-of: kyverno - app.kubernetes.io/version: v1.7.3 + app.kubernetes.io/version: v1.7.4 name: policyreports.wgpolicyk8s.io spec: group: wgpolicyk8s.io @@ -4211,7 +4211,7 @@ app.kubernetes.io/instance: kyverno app.kubernetes.io/name: kyverno app.kubernetes.io/part-of: kyverno - app.kubernetes.io/version: v1.7.3 + app.kubernetes.io/version: v1.7.4 name: reportchangerequests.kyverno.io spec: group: kyverno.io @@ -4477,7 +4477,7 @@ app.kubernetes.io/instance: kyverno app.kubernetes.io/name: kyverno app.kubernetes.io/part-of: kyverno - app.kubernetes.io/version: v1.7.3 + app.kubernetes.io/version: v1.7.4 name: updaterequests.kyverno.io spec: group: kyverno.io diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/kyverno-1.7.3/charts/kyverno-policies/Chart.yaml new/kyverno-1.7.4/charts/kyverno-policies/Chart.yaml --- old/kyverno-1.7.3/charts/kyverno-policies/Chart.yaml 2022-08-24 18:02:37.000000000 +0200 +++ new/kyverno-1.7.4/charts/kyverno-policies/Chart.yaml 2022-09-26 17:49:08.000000000 +0200 @@ -1,8 +1,8 @@ apiVersion: v2 type: application name: kyverno-policies -version: v2.5.3 -appVersion: v1.7.3 +version: v2.5.4 +appVersion: v1.7.4 icon: https://github.com/kyverno/kyverno/raw/main/img/logo.png description: Kubernetes Pod Security Standards implemented as Kyverno policies keywords: diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/kyverno-1.7.3/charts/kyverno-policies/README.md new/kyverno-1.7.4/charts/kyverno-policies/README.md --- old/kyverno-1.7.3/charts/kyverno-policies/README.md 2022-08-24 18:02:37.000000000 +0200 +++ new/kyverno-1.7.4/charts/kyverno-policies/README.md 2022-09-26 17:49:08.000000000 +0200 @@ -2,7 +2,7 @@ Kubernetes Pod Security Standards implemented as Kyverno policies -   +   ## About diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/kyverno-1.7.3/config/install.yaml new/kyverno-1.7.4/config/install.yaml --- old/kyverno-1.7.3/config/install.yaml 2022-08-24 18:02:37.000000000 +0200 +++ new/kyverno-1.7.4/config/install.yaml 2022-09-26 17:49:08.000000000 +0200 @@ -7,7 +7,7 @@ app.kubernetes.io/instance: kyverno app.kubernetes.io/name: kyverno app.kubernetes.io/part-of: kyverno - app.kubernetes.io/version: v1.7.3 + app.kubernetes.io/version: v1.7.4 name: kyverno --- apiVersion: apiextensions.k8s.io/v1 @@ -21,7 +21,7 @@ app.kubernetes.io/instance: kyverno app.kubernetes.io/name: kyverno app.kubernetes.io/part-of: kyverno - app.kubernetes.io/version: v1.7.3 + app.kubernetes.io/version: v1.7.4 name: clusterpolicies.kyverno.io spec: group: kyverno.io @@ -2590,7 +2590,7 @@ app.kubernetes.io/instance: kyverno app.kubernetes.io/name: kyverno app.kubernetes.io/part-of: kyverno - app.kubernetes.io/version: v1.7.3 + app.kubernetes.io/version: v1.7.4 name: clusterpolicyreports.wgpolicyk8s.io spec: group: wgpolicyk8s.io @@ -2952,7 +2952,7 @@ app.kubernetes.io/instance: kyverno app.kubernetes.io/name: kyverno app.kubernetes.io/part-of: kyverno - app.kubernetes.io/version: v1.7.3 + app.kubernetes.io/version: v1.7.4 name: clusterreportchangerequests.kyverno.io spec: group: kyverno.io @@ -3314,7 +3314,7 @@ app.kubernetes.io/instance: kyverno app.kubernetes.io/name: kyverno app.kubernetes.io/part-of: kyverno - app.kubernetes.io/version: v1.7.3 + app.kubernetes.io/version: v1.7.4 name: generaterequests.kyverno.io spec: group: kyverno.io @@ -3504,7 +3504,7 @@ app.kubernetes.io/instance: kyverno app.kubernetes.io/name: kyverno app.kubernetes.io/part-of: kyverno - app.kubernetes.io/version: v1.7.3 + app.kubernetes.io/version: v1.7.4 name: policies.kyverno.io spec: group: kyverno.io @@ -6075,7 +6075,7 @@ app.kubernetes.io/instance: kyverno app.kubernetes.io/name: kyverno app.kubernetes.io/part-of: kyverno - app.kubernetes.io/version: v1.7.3 + app.kubernetes.io/version: v1.7.4 name: policyreports.wgpolicyk8s.io spec: group: wgpolicyk8s.io @@ -6436,7 +6436,7 @@ app.kubernetes.io/instance: kyverno app.kubernetes.io/name: kyverno app.kubernetes.io/part-of: kyverno - app.kubernetes.io/version: v1.7.3 + app.kubernetes.io/version: v1.7.4 name: reportchangerequests.kyverno.io spec: group: kyverno.io @@ -6798,7 +6798,7 @@ app.kubernetes.io/instance: kyverno app.kubernetes.io/name: kyverno app.kubernetes.io/part-of: kyverno - app.kubernetes.io/version: v1.7.3 + app.kubernetes.io/version: v1.7.4 name: updaterequests.kyverno.io spec: group: kyverno.io @@ -7187,7 +7187,7 @@ app.kubernetes.io/instance: kyverno app.kubernetes.io/name: kyverno app.kubernetes.io/part-of: kyverno - app.kubernetes.io/version: v1.7.3 + app.kubernetes.io/version: v1.7.4 name: kyverno-service-account namespace: kyverno --- @@ -7200,7 +7200,7 @@ app.kubernetes.io/instance: kyverno app.kubernetes.io/name: kyverno app.kubernetes.io/part-of: kyverno - app.kubernetes.io/version: v1.7.3 + app.kubernetes.io/version: v1.7.4 name: kyverno:leaderelection namespace: kyverno rules: @@ -7234,7 +7234,7 @@ app.kubernetes.io/instance: kyverno app.kubernetes.io/name: kyverno app.kubernetes.io/part-of: kyverno - app.kubernetes.io/version: v1.7.3 + app.kubernetes.io/version: v1.7.4 rbac.authorization.k8s.io/aggregate-to-admin: "true" name: kyverno:admin-generaterequest rules: @@ -7260,7 +7260,7 @@ app.kubernetes.io/instance: kyverno app.kubernetes.io/name: kyverno app.kubernetes.io/part-of: kyverno - app.kubernetes.io/version: v1.7.3 + app.kubernetes.io/version: v1.7.4 rbac.authorization.k8s.io/aggregate-to-admin: "true" name: kyverno:admin-policies rules: @@ -7287,7 +7287,7 @@ app.kubernetes.io/instance: kyverno app.kubernetes.io/name: kyverno app.kubernetes.io/part-of: kyverno - app.kubernetes.io/version: v1.7.3 + app.kubernetes.io/version: v1.7.4 rbac.authorization.k8s.io/aggregate-to-admin: "true" name: kyverno:admin-policyreport rules: @@ -7314,7 +7314,7 @@ app.kubernetes.io/instance: kyverno app.kubernetes.io/name: kyverno app.kubernetes.io/part-of: kyverno - app.kubernetes.io/version: v1.7.3 + app.kubernetes.io/version: v1.7.4 rbac.authorization.k8s.io/aggregate-to-admin: "true" name: kyverno:admin-reportchangerequest rules: @@ -7341,7 +7341,7 @@ app.kubernetes.io/instance: kyverno app.kubernetes.io/name: kyverno app.kubernetes.io/part-of: kyverno - app.kubernetes.io/version: v1.7.3 + app.kubernetes.io/version: v1.7.4 name: kyverno:events rules: - apiGroups: @@ -7363,7 +7363,7 @@ app.kubernetes.io/instance: kyverno app.kubernetes.io/name: kyverno app.kubernetes.io/part-of: kyverno - app.kubernetes.io/version: v1.7.3 + app.kubernetes.io/version: v1.7.4 name: kyverno:generate rules: - apiGroups: @@ -7410,7 +7410,7 @@ app.kubernetes.io/instance: kyverno app.kubernetes.io/name: kyverno app.kubernetes.io/part-of: kyverno - app.kubernetes.io/version: v1.7.3 + app.kubernetes.io/version: v1.7.4 name: kyverno:policies rules: - apiGroups: @@ -7463,7 +7463,7 @@ app.kubernetes.io/instance: kyverno app.kubernetes.io/name: kyverno app.kubernetes.io/part-of: kyverno - app.kubernetes.io/version: v1.7.3 + app.kubernetes.io/version: v1.7.4 name: kyverno:userinfo rules: - apiGroups: @@ -7486,7 +7486,7 @@ app.kubernetes.io/instance: kyverno app.kubernetes.io/name: kyverno app.kubernetes.io/part-of: kyverno - app.kubernetes.io/version: v1.7.3 + app.kubernetes.io/version: v1.7.4 name: kyverno:view rules: - apiGroups: @@ -7507,7 +7507,7 @@ app.kubernetes.io/instance: kyverno app.kubernetes.io/name: kyverno app.kubernetes.io/part-of: kyverno - app.kubernetes.io/version: v1.7.3 + app.kubernetes.io/version: v1.7.4 name: kyverno:webhook rules: - apiGroups: @@ -7533,7 +7533,7 @@ app.kubernetes.io/instance: kyverno app.kubernetes.io/name: kyverno app.kubernetes.io/part-of: kyverno - app.kubernetes.io/version: v1.7.3 + app.kubernetes.io/version: v1.7.4 name: kyverno:leaderelection namespace: kyverno roleRef: @@ -7554,7 +7554,7 @@ app.kubernetes.io/instance: kyverno app.kubernetes.io/name: kyverno app.kubernetes.io/part-of: kyverno - app.kubernetes.io/version: v1.7.3 + app.kubernetes.io/version: v1.7.4 name: kyverno:events roleRef: apiGroup: rbac.authorization.k8s.io @@ -7574,7 +7574,7 @@ app.kubernetes.io/instance: kyverno app.kubernetes.io/name: kyverno app.kubernetes.io/part-of: kyverno - app.kubernetes.io/version: v1.7.3 + app.kubernetes.io/version: v1.7.4 name: kyverno:generate roleRef: apiGroup: rbac.authorization.k8s.io @@ -7594,7 +7594,7 @@ app.kubernetes.io/instance: kyverno app.kubernetes.io/name: kyverno app.kubernetes.io/part-of: kyverno - app.kubernetes.io/version: v1.7.3 + app.kubernetes.io/version: v1.7.4 name: kyverno:policies roleRef: apiGroup: rbac.authorization.k8s.io @@ -7614,7 +7614,7 @@ app.kubernetes.io/instance: kyverno app.kubernetes.io/name: kyverno app.kubernetes.io/part-of: kyverno - app.kubernetes.io/version: v1.7.3 + app.kubernetes.io/version: v1.7.4 name: kyverno:userinfo roleRef: apiGroup: rbac.authorization.k8s.io @@ -7634,7 +7634,7 @@ app.kubernetes.io/instance: kyverno app.kubernetes.io/name: kyverno app.kubernetes.io/part-of: kyverno - app.kubernetes.io/version: v1.7.3 + app.kubernetes.io/version: v1.7.4 name: kyverno:view roleRef: apiGroup: rbac.authorization.k8s.io @@ -7654,7 +7654,7 @@ app.kubernetes.io/instance: kyverno app.kubernetes.io/name: kyverno app.kubernetes.io/part-of: kyverno - app.kubernetes.io/version: v1.7.3 + app.kubernetes.io/version: v1.7.4 name: kyverno:webhook roleRef: apiGroup: rbac.authorization.k8s.io @@ -7679,7 +7679,7 @@ app.kubernetes.io/instance: kyverno app.kubernetes.io/name: kyverno app.kubernetes.io/part-of: kyverno - app.kubernetes.io/version: v1.7.3 + app.kubernetes.io/version: v1.7.4 name: kyverno namespace: kyverno --- @@ -7695,7 +7695,7 @@ app.kubernetes.io/instance: kyverno app.kubernetes.io/name: kyverno app.kubernetes.io/part-of: kyverno - app.kubernetes.io/version: v1.7.3 + app.kubernetes.io/version: v1.7.4 name: kyverno-metrics namespace: kyverno --- @@ -7708,7 +7708,7 @@ app.kubernetes.io/instance: kyverno app.kubernetes.io/name: kyverno app.kubernetes.io/part-of: kyverno - app.kubernetes.io/version: v1.7.3 + app.kubernetes.io/version: v1.7.4 name: kyverno-svc namespace: kyverno spec: @@ -7729,7 +7729,7 @@ app.kubernetes.io/instance: kyverno app.kubernetes.io/name: kyverno app.kubernetes.io/part-of: kyverno - app.kubernetes.io/version: v1.7.3 + app.kubernetes.io/version: v1.7.4 name: kyverno-svc-metrics namespace: kyverno spec: @@ -7750,7 +7750,7 @@ app.kubernetes.io/instance: kyverno app.kubernetes.io/name: kyverno app.kubernetes.io/part-of: kyverno - app.kubernetes.io/version: v1.7.3 + app.kubernetes.io/version: v1.7.4 name: kyverno namespace: kyverno spec: @@ -7772,7 +7772,7 @@ app.kubernetes.io/instance: kyverno app.kubernetes.io/name: kyverno app.kubernetes.io/part-of: kyverno - app.kubernetes.io/version: v1.7.3 + app.kubernetes.io/version: v1.7.4 spec: affinity: podAntiAffinity: @@ -7807,7 +7807,7 @@ value: kyverno-svc - name: TUF_ROOT value: /.sigstore - image: ghcr.io/kyverno/kyverno:v1.7.3 + image: ghcr.io/kyverno/kyverno:v1.7.4 imagePullPolicy: Always livenessProbe: failureThreshold: 2 @@ -7862,7 +7862,7 @@ valueFrom: fieldRef: fieldPath: metadata.namespace - image: ghcr.io/kyverno/kyvernopre:v1.7.3 + image: ghcr.io/kyverno/kyvernopre:v1.7.4 imagePullPolicy: Always name: kyverno-pre resources: diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/kyverno-1.7.3/config/release/install.yaml new/kyverno-1.7.4/config/release/install.yaml --- old/kyverno-1.7.3/config/release/install.yaml 2022-08-24 18:02:37.000000000 +0200 +++ new/kyverno-1.7.4/config/release/install.yaml 2022-09-26 17:49:08.000000000 +0200 @@ -7,7 +7,7 @@ app.kubernetes.io/instance: kyverno app.kubernetes.io/name: kyverno app.kubernetes.io/part-of: kyverno - app.kubernetes.io/version: v1.7.3 + app.kubernetes.io/version: v1.7.4 name: kyverno --- apiVersion: apiextensions.k8s.io/v1 @@ -21,7 +21,7 @@ app.kubernetes.io/instance: kyverno app.kubernetes.io/name: kyverno app.kubernetes.io/part-of: kyverno - app.kubernetes.io/version: v1.7.3 + app.kubernetes.io/version: v1.7.4 name: clusterpolicies.kyverno.io spec: group: kyverno.io @@ -2590,7 +2590,7 @@ app.kubernetes.io/instance: kyverno app.kubernetes.io/name: kyverno app.kubernetes.io/part-of: kyverno - app.kubernetes.io/version: v1.7.3 + app.kubernetes.io/version: v1.7.4 name: clusterpolicyreports.wgpolicyk8s.io spec: group: wgpolicyk8s.io @@ -2952,7 +2952,7 @@ app.kubernetes.io/instance: kyverno app.kubernetes.io/name: kyverno app.kubernetes.io/part-of: kyverno - app.kubernetes.io/version: v1.7.3 + app.kubernetes.io/version: v1.7.4 name: clusterreportchangerequests.kyverno.io spec: group: kyverno.io @@ -3314,7 +3314,7 @@ app.kubernetes.io/instance: kyverno app.kubernetes.io/name: kyverno app.kubernetes.io/part-of: kyverno - app.kubernetes.io/version: v1.7.3 + app.kubernetes.io/version: v1.7.4 name: generaterequests.kyverno.io spec: group: kyverno.io @@ -3504,7 +3504,7 @@ app.kubernetes.io/instance: kyverno app.kubernetes.io/name: kyverno app.kubernetes.io/part-of: kyverno - app.kubernetes.io/version: v1.7.3 + app.kubernetes.io/version: v1.7.4 name: policies.kyverno.io spec: group: kyverno.io @@ -6075,7 +6075,7 @@ app.kubernetes.io/instance: kyverno app.kubernetes.io/name: kyverno app.kubernetes.io/part-of: kyverno - app.kubernetes.io/version: v1.7.3 + app.kubernetes.io/version: v1.7.4 name: policyreports.wgpolicyk8s.io spec: group: wgpolicyk8s.io @@ -6436,7 +6436,7 @@ app.kubernetes.io/instance: kyverno app.kubernetes.io/name: kyverno app.kubernetes.io/part-of: kyverno - app.kubernetes.io/version: v1.7.3 + app.kubernetes.io/version: v1.7.4 name: reportchangerequests.kyverno.io spec: group: kyverno.io @@ -6798,7 +6798,7 @@ app.kubernetes.io/instance: kyverno app.kubernetes.io/name: kyverno app.kubernetes.io/part-of: kyverno - app.kubernetes.io/version: v1.7.3 + app.kubernetes.io/version: v1.7.4 name: updaterequests.kyverno.io spec: group: kyverno.io @@ -7187,7 +7187,7 @@ app.kubernetes.io/instance: kyverno app.kubernetes.io/name: kyverno app.kubernetes.io/part-of: kyverno - app.kubernetes.io/version: v1.7.3 + app.kubernetes.io/version: v1.7.4 name: kyverno-service-account namespace: kyverno --- @@ -7200,7 +7200,7 @@ app.kubernetes.io/instance: kyverno app.kubernetes.io/name: kyverno app.kubernetes.io/part-of: kyverno - app.kubernetes.io/version: v1.7.3 + app.kubernetes.io/version: v1.7.4 name: kyverno:leaderelection namespace: kyverno rules: @@ -7234,7 +7234,7 @@ app.kubernetes.io/instance: kyverno app.kubernetes.io/name: kyverno app.kubernetes.io/part-of: kyverno - app.kubernetes.io/version: v1.7.3 + app.kubernetes.io/version: v1.7.4 rbac.authorization.k8s.io/aggregate-to-admin: "true" name: kyverno:admin-generaterequest rules: @@ -7260,7 +7260,7 @@ app.kubernetes.io/instance: kyverno app.kubernetes.io/name: kyverno app.kubernetes.io/part-of: kyverno - app.kubernetes.io/version: v1.7.3 + app.kubernetes.io/version: v1.7.4 rbac.authorization.k8s.io/aggregate-to-admin: "true" name: kyverno:admin-policies rules: @@ -7287,7 +7287,7 @@ app.kubernetes.io/instance: kyverno app.kubernetes.io/name: kyverno app.kubernetes.io/part-of: kyverno - app.kubernetes.io/version: v1.7.3 + app.kubernetes.io/version: v1.7.4 rbac.authorization.k8s.io/aggregate-to-admin: "true" name: kyverno:admin-policyreport rules: @@ -7314,7 +7314,7 @@ app.kubernetes.io/instance: kyverno app.kubernetes.io/name: kyverno app.kubernetes.io/part-of: kyverno - app.kubernetes.io/version: v1.7.3 + app.kubernetes.io/version: v1.7.4 rbac.authorization.k8s.io/aggregate-to-admin: "true" name: kyverno:admin-reportchangerequest rules: @@ -7341,7 +7341,7 @@ app.kubernetes.io/instance: kyverno app.kubernetes.io/name: kyverno app.kubernetes.io/part-of: kyverno - app.kubernetes.io/version: v1.7.3 + app.kubernetes.io/version: v1.7.4 name: kyverno:events rules: - apiGroups: @@ -7363,7 +7363,7 @@ app.kubernetes.io/instance: kyverno app.kubernetes.io/name: kyverno app.kubernetes.io/part-of: kyverno - app.kubernetes.io/version: v1.7.3 + app.kubernetes.io/version: v1.7.4 name: kyverno:generate rules: - apiGroups: @@ -7410,7 +7410,7 @@ app.kubernetes.io/instance: kyverno app.kubernetes.io/name: kyverno app.kubernetes.io/part-of: kyverno - app.kubernetes.io/version: v1.7.3 + app.kubernetes.io/version: v1.7.4 name: kyverno:policies rules: - apiGroups: @@ -7463,7 +7463,7 @@ app.kubernetes.io/instance: kyverno app.kubernetes.io/name: kyverno app.kubernetes.io/part-of: kyverno - app.kubernetes.io/version: v1.7.3 + app.kubernetes.io/version: v1.7.4 name: kyverno:userinfo rules: - apiGroups: @@ -7486,7 +7486,7 @@ app.kubernetes.io/instance: kyverno app.kubernetes.io/name: kyverno app.kubernetes.io/part-of: kyverno - app.kubernetes.io/version: v1.7.3 + app.kubernetes.io/version: v1.7.4 name: kyverno:view rules: - apiGroups: @@ -7507,7 +7507,7 @@ app.kubernetes.io/instance: kyverno app.kubernetes.io/name: kyverno app.kubernetes.io/part-of: kyverno - app.kubernetes.io/version: v1.7.3 + app.kubernetes.io/version: v1.7.4 name: kyverno:webhook rules: - apiGroups: @@ -7533,7 +7533,7 @@ app.kubernetes.io/instance: kyverno app.kubernetes.io/name: kyverno app.kubernetes.io/part-of: kyverno - app.kubernetes.io/version: v1.7.3 + app.kubernetes.io/version: v1.7.4 name: kyverno:leaderelection namespace: kyverno roleRef: @@ -7554,7 +7554,7 @@ app.kubernetes.io/instance: kyverno app.kubernetes.io/name: kyverno app.kubernetes.io/part-of: kyverno - app.kubernetes.io/version: v1.7.3 + app.kubernetes.io/version: v1.7.4 name: kyverno:events roleRef: apiGroup: rbac.authorization.k8s.io @@ -7574,7 +7574,7 @@ app.kubernetes.io/instance: kyverno app.kubernetes.io/name: kyverno app.kubernetes.io/part-of: kyverno - app.kubernetes.io/version: v1.7.3 + app.kubernetes.io/version: v1.7.4 name: kyverno:generate roleRef: apiGroup: rbac.authorization.k8s.io @@ -7594,7 +7594,7 @@ app.kubernetes.io/instance: kyverno app.kubernetes.io/name: kyverno app.kubernetes.io/part-of: kyverno - app.kubernetes.io/version: v1.7.3 + app.kubernetes.io/version: v1.7.4 name: kyverno:policies roleRef: apiGroup: rbac.authorization.k8s.io @@ -7614,7 +7614,7 @@ app.kubernetes.io/instance: kyverno app.kubernetes.io/name: kyverno app.kubernetes.io/part-of: kyverno - app.kubernetes.io/version: v1.7.3 + app.kubernetes.io/version: v1.7.4 name: kyverno:userinfo roleRef: apiGroup: rbac.authorization.k8s.io @@ -7634,7 +7634,7 @@ app.kubernetes.io/instance: kyverno app.kubernetes.io/name: kyverno app.kubernetes.io/part-of: kyverno - app.kubernetes.io/version: v1.7.3 + app.kubernetes.io/version: v1.7.4 name: kyverno:view roleRef: apiGroup: rbac.authorization.k8s.io @@ -7654,7 +7654,7 @@ app.kubernetes.io/instance: kyverno app.kubernetes.io/name: kyverno app.kubernetes.io/part-of: kyverno - app.kubernetes.io/version: v1.7.3 + app.kubernetes.io/version: v1.7.4 name: kyverno:webhook roleRef: apiGroup: rbac.authorization.k8s.io @@ -7679,7 +7679,7 @@ app.kubernetes.io/instance: kyverno app.kubernetes.io/name: kyverno app.kubernetes.io/part-of: kyverno - app.kubernetes.io/version: v1.7.3 + app.kubernetes.io/version: v1.7.4 name: kyverno namespace: kyverno --- @@ -7695,7 +7695,7 @@ app.kubernetes.io/instance: kyverno app.kubernetes.io/name: kyverno app.kubernetes.io/part-of: kyverno - app.kubernetes.io/version: v1.7.3 + app.kubernetes.io/version: v1.7.4 name: kyverno-metrics namespace: kyverno --- @@ -7708,7 +7708,7 @@ app.kubernetes.io/instance: kyverno app.kubernetes.io/name: kyverno app.kubernetes.io/part-of: kyverno - app.kubernetes.io/version: v1.7.3 + app.kubernetes.io/version: v1.7.4 name: kyverno-svc namespace: kyverno spec: @@ -7729,7 +7729,7 @@ app.kubernetes.io/instance: kyverno app.kubernetes.io/name: kyverno app.kubernetes.io/part-of: kyverno - app.kubernetes.io/version: v1.7.3 + app.kubernetes.io/version: v1.7.4 name: kyverno-svc-metrics namespace: kyverno spec: @@ -7750,7 +7750,7 @@ app.kubernetes.io/instance: kyverno app.kubernetes.io/name: kyverno app.kubernetes.io/part-of: kyverno - app.kubernetes.io/version: v1.7.3 + app.kubernetes.io/version: v1.7.4 name: kyverno namespace: kyverno spec: @@ -7772,7 +7772,7 @@ app.kubernetes.io/instance: kyverno app.kubernetes.io/name: kyverno app.kubernetes.io/part-of: kyverno - app.kubernetes.io/version: v1.7.3 + app.kubernetes.io/version: v1.7.4 spec: affinity: podAntiAffinity: @@ -7807,7 +7807,7 @@ value: kyverno-svc - name: TUF_ROOT value: /.sigstore - image: ghcr.io/kyverno/kyverno:v1.7.3 + image: ghcr.io/kyverno/kyverno:v1.7.4 imagePullPolicy: Always livenessProbe: failureThreshold: 2 @@ -7862,7 +7862,7 @@ valueFrom: fieldRef: fieldPath: metadata.namespace - image: ghcr.io/kyverno/kyvernopre:v1.7.3 + image: ghcr.io/kyverno/kyvernopre:v1.7.4 imagePullPolicy: Always name: kyverno-pre resources: diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/kyverno-1.7.3/config/release/kustomization.yaml new/kyverno-1.7.4/config/release/kustomization.yaml --- old/kyverno-1.7.3/config/release/kustomization.yaml 2022-08-24 18:02:37.000000000 +0200 +++ new/kyverno-1.7.4/config/release/kustomization.yaml 2022-09-26 17:49:08.000000000 +0200 @@ -9,6 +9,6 @@ images: - name: ghcr.io/kyverno/kyverno - newTag: v1.7.3 + newTag: v1.7.4 - name: ghcr.io/kyverno/kyvernopre - newTag: v1.7.3 + newTag: v1.7.4 diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/kyverno-1.7.3/config/release/labels.yaml new/kyverno-1.7.4/config/release/labels.yaml --- old/kyverno-1.7.3/config/release/labels.yaml 2022-08-24 18:02:37.000000000 +0200 +++ new/kyverno-1.7.4/config/release/labels.yaml 2022-09-26 17:49:08.000000000 +0200 @@ -4,7 +4,7 @@ metadata: name: labelTransformer labels: - app.kubernetes.io/version: v1.7.3 + app.kubernetes.io/version: v1.7.4 fieldSpecs: - path: metadata/labels create: true diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/kyverno-1.7.3/pkg/policyreport/reportcontroller.go new/kyverno-1.7.4/pkg/policyreport/reportcontroller.go --- old/kyverno-1.7.3/pkg/policyreport/reportcontroller.go 2022-08-24 18:02:37.000000000 +0200 +++ new/kyverno-1.7.4/pkg/policyreport/reportcontroller.go 2022-09-26 17:49:08.000000000 +0200 @@ -890,7 +890,7 @@ polr.SetGroupVersionKind(schema.GroupVersionKind{Group: gv.Group, Version: gv.Version, Kind: "PolicyReport"}) - if _, err := g.pclient.Wgpolicyk8sV1alpha2().PolicyReports(new.GetNamespace()).Update(context.TODO(), polr, metav1.UpdateOptions{}); err != nil { + if _, err := g.pclient.Wgpolicyk8sV1alpha2().PolicyReports(polr.Namespace).Update(context.TODO(), polr, metav1.UpdateOptions{}); err != nil { return fmt.Errorf("failed to update clusterPolicyReport %s %v", polr.Name, err) } } diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/kyverno-1.7.3/pkg/utils/kube/kind.go new/kyverno-1.7.4/pkg/utils/kube/kind.go --- old/kyverno-1.7.3/pkg/utils/kube/kind.go 2022-08-24 18:02:37.000000000 +0200 +++ new/kyverno-1.7.4/pkg/utils/kube/kind.go 2022-09-26 17:49:08.000000000 +0200 @@ -29,6 +29,18 @@ return strings.Replace(s, ".", "/", 1) } +// GetGroupFromGVK - get group GVK +func GetGroupFromGVK(str string) (group string) { + parts := strings.Split(str, "/") + count := len(parts) + if count == 3 { + if parts[1] == "*" { + return parts[0] + } + } + return "" +} + func SplitSubresource(s string) (kind string, subresource string) { normalized := strings.Replace(s, ".", "/", 1) parts := strings.Split(normalized, "/") diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/kyverno-1.7.3/pkg/webhookconfig/configmanager.go new/kyverno-1.7.4/pkg/webhookconfig/configmanager.go --- old/kyverno-1.7.3/pkg/webhookconfig/configmanager.go 2022-08-24 18:02:37.000000000 +0200 +++ new/kyverno-1.7.4/pkg/webhookconfig/configmanager.go 2022-09-26 17:49:08.000000000 +0200 @@ -795,7 +795,8 @@ continue } if strings.Contains(gvk, "*") { - gvrList = append(gvrList, schema.GroupVersionResource{Group: gvr.Group, Version: "*", Resource: gvr.Resource}) + group := kubeutils.GetGroupFromGVK(gvk) + gvrList = append(gvrList, schema.GroupVersionResource{Group: group, Version: "*", Resource: gvr.Resource}) } else { m.log.V(4).Info("configuring webhook", "GVK", gvk, "GVR", gvr) gvrList = append(gvrList, gvr) diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/kyverno-1.7.3/test/cli/registry/kyverno-test.yaml new/kyverno-1.7.4/test/cli/registry/kyverno-test.yaml --- old/kyverno-1.7.3/test/cli/registry/kyverno-test.yaml 2022-08-24 18:02:37.000000000 +0200 +++ new/kyverno-1.7.4/test/cli/registry/kyverno-test.yaml 2022-09-26 17:49:08.000000000 +0200 @@ -3,6 +3,7 @@ - image-example.yaml resources: - resources.yaml +variables: values.yaml results: - policy: images rule: only-allow-trusted-images diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/kyverno-1.7.3/test/cli/registry/values.yaml new/kyverno-1.7.4/test/cli/registry/values.yaml --- old/kyverno-1.7.3/test/cli/registry/values.yaml 1970-01-01 01:00:00.000000000 +0100 +++ new/kyverno-1.7.4/test/cli/registry/values.yaml 2022-09-26 17:49:08.000000000 +0200 @@ -0,0 +1,6 @@ +policies: +- name: check-image-base + rules: + - name: check-image-base-rule + foreachValues: + mobysource: ["1"] \ No newline at end of file ++++++ vendor.tar.gz ++++++ /work/SRC/openSUSE:Factory/kyverno/vendor.tar.gz /work/SRC/openSUSE:Factory/.kyverno.new.2275/vendor.tar.gz differ: char 5, line 1