CI/CD
Tekton: what changed
In the last 90 days, 10 summarized changes: 10 releases. Stackdiff reads Tekton's own feeds (tekton.dev) and writes two sentences per change with a link to the source; it never republishes release notes. Sources last checked .
Latest changes
Newest first, every type. Releases and fixes sit below anything that can hurt you in the weekly brief; here they are in order.
1.0.2Securitymedium
GHSA-94jr-7pqp-xhcq: Tekton Pipeline: Git Resolver Unsanitized Revision Parameter Enables git Argument Injection Leading to RCE
1.0.2Securitymedium
GHSA-m2cx-gpqf-qf74: Tekton Pipelines: HTTP Resolver Unbounded Response Body Read Enables Denial of Service via Memory Exhaustion
1.0.2Securitymedium
GHSA-rx35-6rhx-7858: Tekton Pipelines: VolumeMount path restriction bypass via missing filepath.Clean in /tekton/ check
1.0.2Securitymedium
GHSA-wjxp-xrpv-xpff: Tekton Pipelines: Git resolver API mode leaks system-configured API token to user-controlled serverURL
1.0.2Securitymedium
GHSA-rmx9-2pp3-xhcr: Tekton Pipelines has VerificationPolicy regex pattern bypass via substring matching
1.0.1Securitymedium
GHSA-j5q5-j9gm-2w5c: Path traversal in Tekton Pipelines git resolver allows reading arbitrary files from the resolver pod
1.0.1Securitymedium
GHSA-cv4x-93xx-wgfj: Tekton Pipelines controller panic via long resolver name in TaskRun/PipelineRun
Where Stackdiff reads Tekton
- GitHub releases · tektoncd/pipeline
- Hacker News
- OSV advisories · github.com/tektoncd/pipeline
Only what the vendor publishes for machines. Excerpts are capped, summaries are our own two sentences, and every line links back.
Get Tekton changes in your Monday brief
Add Tekton and the rest of your stack; breaking changes and CVEs go out the moment they're seen, everything else on Monday.
Get your first brief →