Skip to content

chore(2.74.2-dk): release 2.73.2-dk - #343

Closed
flant-team-sysdev wants to merge 1 commit into
2.74.2-dkfrom
release-please--branches--2.74.2-dk
Closed

flant-team-sysdev wants to merge 1 commit into
2.74.2-dkfrom
release-please--branches--2.74.2-dk

Conversation

@flant-team-sysdev

Copy link
Copy Markdown
Collaborator

🤖 I have created a release beep boop

2.73.2-dk (2026-09-22)

Features

  • add TypeScript chart rendering support (NELM_FEAT_TYPESCRIPT=true) (#7341) (b336225)
  • build-report: support reading .env format build reports (8e1501c)
  • build, stapel, git: add WERF_DISABLE_GIT_COMMIT_ANCESTRY_CHECK to disable git commit ancestry check (bae3300)
  • build: add commit to build report for images and stages (#7566) (38be712)
  • build: add image manifest & ELF signing, and dm-verity annotations (55172eb)
  • build: add network isolation for Docker backend (142ce04)
  • build: add network isolation for Docker backend (6f41567)
  • build: add SBOM support during build with werf sbom get command (acd0cbf)
  • build: document network isolation for build containers (beb904f)
  • build: remove unused empty string argument in full dockerfile test (09b3e43)
  • build: respect insecure registries and mirrors from backend-native config (#7376) (fd5a826)
  • build: scratch stapel docker backend (#7441) (490d6e0)
  • build: skip meta tags publication for read only registry (#7291) (7a80bbf)
  • build: support network directive in werf.yaml (30f8e0e)
  • build: support network directive in werf.yaml (bf8482f)
  • build: use build report in commands require build (#7297) (d705476)
  • ci-env: add --use-docker-auth-config flag to generate Docker config from DOCKER_AUTH_CONFIG env var (c2701f7)
  • cleanup: add --kube-scan-namespaces support for in-cluster scan (#7517) (8941a1e)
  • cleanup: delete rejected stages and linked custom tags during cleanup/purge (#7576) (b1b0980)
  • cleanup: support kube token and kube token path (#7327) (352b8c3)
  • config: add packages directive to stapel image configuration (9e40b37)
  • deploy: --set-root-json flag (#7348) (429ea3b)
  • deploy: werf.io/delete-dependency-<id> annotation (#7337) (05dfc1d)
  • deploy: ability to init ts files with WerfRenderContext type (#7464) (1609845)
  • deploy: add werf.io/resource-policy annotation (#7613) (72ae0f2)
  • deploy: add plan freezing support (#7362) (28c053f)
  • deploy: add resource validation flags (#7343) (223d537)
  • deploy: add structured image values to $.Values.global.werf.images (#7413) (1b93dcc)
  • deploy: adopt chart ts init for werf (#7489) (63542e2)
  • deploy: auto delete dependency detection (#7342) (ddb2087)
  • deploy: deno runtime for typescript (#7365) (c27c4d2)
  • deploy: enhanced local resource validation (#7335) (bf1ef99)
  • deploy: implement resource validation against api spec (#7328) (b927515)
  • deploy: move dockerconfigjson to .global.werf (#7583) (79d90cb)
  • deploy: switch to goccy/go-yaml and improve parse error context (#7398) (3097703)
  • host-cleanup: add support for absolute storage units (c5dbdd0)
  • host-cleanup: make validation error more informative (0f9f460)
  • host-cleanup: move units package to pkg/host_cleaning (6f3d931)
  • host-clenaup: cli docs generated (248fdb6)
  • import: provide WERF_EXPERIMENTAL_IMPORT_BY_SOURCE_IMAGE_TAG env to change calculation import checksums method to reduce FD (#7392) (9abe1b5)
  • sbom: add --tag and --digest flags to get command (#76) (aeb693f)
  • sbom: add declarations merge (e0b79a7)
  • sbom: add dependencies merge (e97470c)
  • sbom: add experimental GOST SBOM support (#48) (3711453)
  • sbom: add external references enrichment (#98) (2fb36a3)
  • sbom: add log warning for SBOM emulation mode (b186e3c)
  • sbom: add packages install stage and os-pm SBOM support (#135) (198c497)
  • sbom: add sbom merge command (e73f614)
  • sbom: adopt OCI artifact-based registry-only storage (574e35b)
  • sbom: catalog go.mod packages via go-mod packages directive (cc0a088)
  • sbom: disable current validation for base/import images SBOM (#78) (eda9fc2)
  • sbom: enforce network isolation for Stapel stages when SBOM enabled (e753409)
  • sbom: generate CPE for pm components (b6298e6)
  • sbom: generate metadata for pm components (5608a29)
  • sbom: implement ispras validating (1f9ccb0)
  • sbom: replace PackageResolveStage with shell-based packages stage (7260401)
  • sbom: resolve version unknown (#58) (5956afc)
  • sbom: sbom fstec mvp (#29) (850518c)
  • sbom: skip SBOM generation for trusted builder images (#103) (f796445)
  • sign: add werf verify command (8f40f5a)
  • stapel: provide WERF_EXPERIMENTAL_STAPEL_ARM env for arm64 support (#7454) (f911913)
  • telemetry: extend build metrics with metadata fields (#7384) (09a324e)

Bug Fixes

  • --set-root-json not working (#7374) (613f2e1)
  • buiild, stapel, import: regenerate import checksums if it`s empty (#7506) (eebb1df)
  • build, buildah, dockerfile, staged: resolve staged Dockerfile RUN --mount from=<stage> to built image (#7594) (b1933b3)
  • build, buildah: apply owner group to dst dir (#7462) (fea6b40)
  • build, buildah: correct expansion of instructions (#7460) (aef6003)
  • build, buildah: fix multiarch build failing with "image not known" for cross-platform images (#7573) (8cd109f)
  • build, docker, dockerfile: don't post cleanup images (#7313) (f7bf030)
  • build, docker, stapel: fix stage image cache for multi-platform builds (#7480) (23f89b3)
  • build, dockerfile, staged: fix staged dockerfile dependencies for COPY --from (#7300) (18e3c64)
  • build, docker: handle no such container error (#7482) (83b3227)
  • build, docker: robust image ID extraction for buildx across different Docker storage drivers (#7345) (db3c046)
  • build, signing: stream signed ELF layer instead of buffering (#143) (1770207)
  • build, stapel, buildah: binary files patch incorrect (#7310) (2eec873)
  • build, stapel, import, buildah: close file descriptors in checksum calculation loop (#7320) (b4f5124)
  • build, stapel, import: importing into symlinked directories no longer silently loses files (#7545) (9d1bb68)
  • build, stapel, import: orphan import-server containers after cancellation (#7527) (5c75bea)
  • build, stapel, import: rsync chown "/sys" Read-only file system on to: / (#7590) (b6dac9c)
  • build, stapel, import: unnecessary image rebuilds when using --secondary-repo with imports (#7526) (915a403)
  • build, stapel: handle platform mismatch in stage base image resolution and avoid panic (#7493) (cdf0e83)
  • build, stapel: introspect failed stage from committed image, not temp UUID (#7607) (a0bc374)
  • build: add broken image error handling for image-spec stage (#7322) (56fb883)
  • buildah: extract resolveContainerBackendType and reuse it in localPurger to skip stapel purge for non-Docker backends (e10de67)
  • buildah: fix panic in "host purge" when running in buildah mode (a3ae3df)
  • buildah: normalize dependency import file targets (69cf22f)
  • build: bound retry loop on unexpected stages storage state and invalidate manifest cache on stage rejection (#7369) (9e3c8a1)
  • build: eliminate redundant registry tag listing in post-build metadata publication (#7559) (27404cb)
  • build: fix git owner and group with buildah backend (#7415) (7af23b6)
  • build: fix stage build time in report (#7404) (74ae247)
  • build: freezing on random image (#7539) (6cf58b7)
  • build: handle broken import metadata images in container registry (#7394) (0413384)
  • build: impl requested changes (9973a27)
  • build: impl requested changes (2811f4e)
  • build: include sbom enable state in stage cache digest (ba9ad93)
  • build: non-local synchronization server requires --repo be set (f078e04)
  • build: panic: image "..." not found (#7318) (145064e)
  • build: push custom tags to final repo during multiplatform builds (a402ac6)
  • build: resolve dependency image refs in FROM stage before computing cache digest (#7492) (b42f0b1)
  • build: sanitize docker credentials from buildkit and docker errors (#7299) (ae50410)
  • build: show "default" in log network field when no explicit network (c54a78d)
  • build: use image tag instead of sha256 for docker run (725a629)
  • build: use path.Join for container-internal paths in stapel (#7258) (c974594)
  • build: use registry-mirrors from docker daemon.json (#7329) (0fdeb86)
  • build: use UUID-based naming for scratch base images to prevent buildah misinterpretation (#7602) (9ce7545)
  • ci-env: ci-env ignores session docker config when WERF_DOCKER_CONFIG is set (#7530) (5161412)
  • ci-env: optimize docker config copying to prevent inodes overflow (#7305) (d5005c1)
  • ci: comment out cr in daily tests (#13) (34708ff)
  • ci: fix publish binary name (0cea40c)
  • ci: pr docs preview (#7485) (d29c18b)
  • ci: skip buildah tests for main (#11) (6c52c77)
  • ci: stabilize integration tests and multi-arch build (#17) (0bb96f2)
  • ci: switch release-please to manifest mode, fix upstream werf baseline contamination (#124) (f00cd16)
  • ci: trigger website production deploy after trdl channel update (#7502) (310298c)
  • cleanup: do not require docker daemon for registry mirrors (7a42d33)
  • cleanup: ensure tag is deleted before manifest removal (#7401) (303506e)
  • cleanup: failing for cross-account ECR repositories (37c636c)
  • cleanup: normalize 404 error message on tag deletion (#7332) (72deb33)
  • cleanup: propagate service labels into mutable stage images (bbdd116)
  • cleanup: skip invalid custom tag metadata with warning log (65ff126)
  • compose: show docker compose config error instead of bare exit code (6cc27d8)
  • deploy: werf.io/resource-policy should only respect skip-delete from live (#7623) (f261028)
  • deploy: add standalone pod tracking (#7316) (418e21a)
  • deploy: adjust service account managed fields (#7319) (751a900)
  • deploy: adopt managed fields after migration from helm to nelm (#7406) (ac46e88)
  • deploy: adopt managed fields after migration from helm to nelm (#7406) (eab87e5)
  • deploy: autodependencies between pods/controllers, rolebindings and serviceaccounts (#7567) (f152352)
  • deploy: force adoption always on (8154022)
  • deploy: goroutine leak in watch error channel consumer for ReleaseInstall, ReleaseUninstall and ReleaseRollback (#7418) (f2d817c)
  • deploy: hangs on very long pod lines (#7580) (daefa02)
  • deploy: no more "no match for resource kind" errors (#7585) (a3d0a5a)
  • deploy: pass option for yaml validator to allow duplicate map key (#7408) (ac46e88)
  • deploy: pass option for yaml validator to allow duplicate map key (#7408) (c9ea743)
  • deploy: print engine.Render() result on debug level (#7396) (7237218)
  • deploy: release had pending status after error instead of failed (#7416) (b523cf2)
  • deploy: restore global.env (5e5defd)
  • deploy: restore WERF_EXPERIMENT_NO_GLOBAL_SERVICE_VALUES env (#7468) (e2e0999)
  • deploy: retry also on conversion webhooks unavailability (#7587) (1623efe)
  • deploy: retry on "webhook unavailable" error (#7533) (8810e23)
  • deploy: retry on webhook unavailable errors (#7505) (1718543)
  • deploy: show actual error if webhook retries fail (#7586) (1dc615e)
  • deploy: tracking absence for release namespace deletion (#7397) (6d885d9)
  • host-cleanup: fix absolute volume usage unit parsing logic (0e3f5d6)
  • host-cleanup: handle race condition in tmp files GC when entries disappear between readdir and stat (18ff151)
  • host-cleanup: support nested cli command (ee5f78a)
  • host-clenaup: apply WERF_SELF_INVOCATION_COMMAND in Detach (faf5bf2)
  • host-clenaup: prevent overflow while subtraction (math) (544c423)
  • import: add check to handle symlinks before md5sum launch (679bc6a)
  • import: add one fs rsync flag (c64e3e7)
  • includes, giterminism: fix includePaths handling (#7321) (b71c543)
  • includes: add empty args check (a6b8766)
  • includes: create local branch refs after fresh clone in CloneAndFetch (#7425) (4c94b0b)
  • includes: respect --loose-giterminism for --allow-includes-update (#7414) (db75a5a)
  • init docker config in InitCommonComponents when docker registry is requested (#7488) (76ca703)
  • kube: correctly resolve client config per context (5f12fed)
  • make kube initialization lazy for commands that don't need eager kube client (#7440) (98028f2)
  • parallel: eliminate race between context timeout and goroutine (ed67c0f)
  • propagate --docker-config to image pulling in bundle copy (#7448) (c02babe)
  • regenerate mock for LegacyContainerOptions to add missing AddNetwork method (1ea6c3a)
  • regenerate mocks and add missing Mutate method to test stub (0cbb7b5)
  • sbom, docker: tar sbom artifact correctly (1cbe5a9)
  • sbom: add cross-project merge support (#37) (62a11b5)
  • sbom: dedup external references (9922129)
  • sbom: enable offline validation of CycloneDX 1.6 external schemas (6438078)
  • sbom: ensure bom-ref uniqueness in cyclonedx@1.6 SBOM merge (#71) (f5e1471)
  • sbom: implement mark and sweep model (72c5418)
  • sbom: init components deduplication (57fe3a5)
  • sbom: migrate inherit value to indirect in gost fields (672075c)
  • sbom: relocate syft image from GitHub to Docker Hub (65682ce)
  • sbom: take *-sbom images into account with cleanup commands (3f53e88)
  • sbom: throw warning instead of error when base/import image sbom is missing (#56) (99fa295)
  • sbom: use cache instead of generate SBOM (dc38dde)
  • sbom: use containerFactoryVersion purl qualifier for pm components (#140) (6258e82)
  • signing: guard repeated bsign passes in v2.74.2 (#340) (364cf91)
  • sign: sign normalized manifest so verify matches pushed config (#141) (89774d8)
  • stages-copy: fix panic (#7382) (08d91de)
  • stop retrying 301 redirects in registry transport (#7457) (f588d4c)

Miscellaneous Chores


This PR was generated with Release Please. See documentation.

@alexey-igrychev

Copy link
Copy Markdown
Collaborator

Closing: release-please cannot infer the repository's Deckhouse hotfix suffix convention for this maintenance branch. v2.74.2-dk.1 was published explicitly.

@alexey-igrychev
alexey-igrychev deleted the release-please--branches--2.74.2-dk branch September 22, 2026 12:07
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants