Skip to content

Releases: confidential-containers/guest-components

v0.11.0

31 Jan 18:00
Compare
Choose a tag to compare

The v0.11.0 release of guest-components is used in Confidential Containers v0.12.0. CoCo v0.12.0 did not bump image-rs and is using the version from the previous guest-components release.

What's Changed

  • release: Publish vendored code by @fidencio in #722
  • Update README.md by @vuquangthinh in #724
  • AA: Update CcaAttester to use TSM Report ABI by @mathias-arm in #595
  • AA: kbs: Improve handling of invalid RCAR JSON by @jodh-intel in #723
  • Fix configuration file default value and make error information more detailed by @Xynnn007 in #726
  • chore(deps): Bump oci-client from 0.12.0 to 0.12.1 by @dependabot in #721
  • chore(deps): Bump serde_json from 1.0.122 to 1.0.128 by @dependabot in #720
  • attestation-agent: default to ttrpc in Makefile by @mkulke in #728
  • cdh:golang: fix typo in README by @ChengyuZhu6 in #730
  • attestation-agent: add flag 'enable_eventlog' to aa example config by @ChengyuZhu6 in #729
  • chore(deps): Bump tdx-attest-rs from DCAP_1.21 to DCAP_1.22 by @dependabot in #733
  • chore(deps): Bump serde from 1.0.209 to 1.0.210 by @dependabot in #732
  • chore: update prost/tonic/tonic-build deps by @Xynnn007 in #719
  • CI: Publish binaries with ORAS by @mkulke in #731
  • docs: Fix misspelling in IMAGE ENCRYPTION document by @GabyCT in #738
  • gha: Do not use oras-project/setup-oras for s390x by @BbolroC in #739
  • ci: skip oras setup for s390x builds by @mkulke in #740
  • gha: Fix condition for skipping ORAS installation on s390x by @BbolroC in #741
  • ci: fix multi-arch oci publish for AA by @mkulke in #742
  • chore(deps): Bump flate2 from 1.0.31 to 1.0.34 by @dependabot in #735
  • chore(deps): Bump tempfile from 3.12.0 to 3.13.0 by @dependabot in #736
  • chore(deps): Bump thiserror from 1.0.63 to 1.0.64 by @dependabot in #743
  • chore(deps): Bump const_format from 0.2.32 to 0.2.33 by @dependabot in #744
  • chore(deps): Bump tokio from 1.39.3 to 1.40.0 by @dependabot in #746
  • chore(deps): Bump tokio-util from 0.7.11 to 0.7.12 by @dependabot in #745
  • chore(deps): Bump futures-util from 0.3.30 to 0.3.31 by @dependabot in #748
  • chore(deps): Bump async-compression from 0.4.12 to 0.4.14 by @dependabot in #747
  • chore(deps): Bump lycheeverse/lychee-action from 1 to 2 by @dependabot in #750
  • chore(deps): Bump filetime from 0.2.23 to 0.2.25 by @dependabot in #751
  • chore(deps): Bump oci-spec from 0.6.8 to 0.7.0 by @dependabot in #752
  • drop deprecated eaa_kbc + move gh actions to Ubuntu 24.04 by @mythi in #734
  • chore(deps): Bump futures from 0.3.30 to 0.3.31 by @dependabot in #754
  • chore(deps): Bump anyhow from 1.0.87 to 1.0.89 by @dependabot in #753
  • CDH | Fix ttrpc memory bug and gRPC lock bug by @Xynnn007 in #727
  • Image-rs & CDH | Refactoring and use the same ImageClient by @Xynnn007 in #708
  • chore(deps): Bump reqwest from 0.12.5 to 0.12.8 by @dependabot in #756
  • chore(deps): Bump devicemapper from 0.34.3 to 0.34.4 by @dependabot in #758
  • chore(deps): Bump uuid from 1.10.0 to 1.11.0 by @dependabot in #759
  • chore(deps): Bump shadow-rs from 0.33.0 to 0.35.1 by @dependabot in #762
  • chore(deps): Bump openssl from 0.10.66 to 0.10.68 by @dependabot in #761
  • chore(deps): Bump prost from 0.13.2 to 0.13.3 by @dependabot in #766
  • chore(deps): Bump shadow-rs from 0.35.1 to 0.35.2 by @dependabot in #767
  • CDH | add one-shot CDH by @Xynnn007 in #768
  • attester: rename check_init_data => bind_init_data by @mkulke in #769
  • chore(deps): Bump oci-client from 0.13.0 to 0.14.0 by @dependabot in #770
  • chore(deps): Bump async-trait from 0.1.82 to 0.1.83 by @dependabot in #771
  • docs: Fix misspelling in image auth documentation by @GabyCT in #773
  • chore(deps): Bump thiserror from 1.0.64 to 1.0.65 by @dependabot in #775
  • chore(deps): Bump utoipa from 3.5.0 to 5.1.3 by @dependabot in #774
  • chore(deps): Bump tokio from 1.40.0 to 1.41.0 by @dependabot in #778
  • chore(deps): Bump anyhow from 1.0.89 to 1.0.91 by @dependabot in #777
  • chore(deps): Bump jwt-simple from 0.12.9 to 0.12.10 by @dependabot in #780
  • chore(deps): Bump thiserror from 1.0.65 to 1.0.66 by @dependabot in #779
  • chore(deps): Bump serde from 1.0.210 to 1.0.214 by @dependabot in #781
  • chore(deps): Bump utoipa from 5.1.3 to 5.2.0 by @dependabot in #782
  • chore(deps): Bump thiserror from 1.0.66 to 1.0.68 by @dependabot in #784
  • chore(deps): Bump serde_json from 1.0.128 to 1.0.132 by @dependabot in #783
  • kbs_protocol: update KBS config for test_client tests by @mythi in #788
  • Bump csv-rs for openssl 3 support by @EmmEff in #785
  • CDH/KMS: remove ehsm from defaut features by @Xynnn007 in #792
  • chore(deps): Bump anyhow from 1.0.91 to 1.0.93 by @dependabot in #786
  • chore(deps): Bump reqwest from 0.12.8 to 0.12.9 by @dependabot in #787
  • chore(deps): Bump pin-project-lite from 0.2.14 to 0.2.15 by @dependabot in #790
  • cdh: use b64url encoding in sealed-secrets JWS by @mkulke in #794
  • chore(deps): Bump tokio from 1.41.0 to 1.41.1 by @dependabot in #797
  • chore(deps): Bump tempfile from 3.13.0 to 3.14.0 by @dependabot in #796
  • chore(deps): Bump async-compression from 0.4.14 to 0.4.17 by @dependabot in #795
  • chore(deps): Bump oci-spec from 0.7.0 to 0.7.1 by @dependabot in #798
  • AA: fix CoCoAS Token getter by @Xynnn007 in #801
  • chore(deps): Bump thiserror from 1.0.68 to 2.0.3 by @dependabot in #802
  • chore(deps): Bump serde from 1.0.214 to 1.0.215 by @dependabot in #800
  • chore(deps): Bump serial_test from 3.1.1 to 3.2.0...
Read more

v0.10.0

12 Sep 14:03
Compare
Choose a tag to compare

What's Changed

Read more

v0.9.0

25 Jun 17:46
Compare
Choose a tag to compare

What's Changed

Read more

v0.8.0

01 Nov 17:25
Compare
Choose a tag to compare

What's Changed

  • Add unit test case for unencrypted images by @portersrc in #287
  • ci: refactor workflows by @katexochen in #275
  • chore(deps): Bump actions/checkout from 2 to 3 by @dependabot in #176
  • aa: Rename Occlum attester to SGX attester and add Gramine support to it by @mythi in #167
  • attestation-agent/Attesters: refactor the trait of Attester by @Xynnn007 in #284
  • Unify common deps to the same version in Cargo.toml of the worksppace by @Xynnn007 in #285
  • Update base64 crate in guest-components by @Xynnn007 in #282
  • image-rs: add image block device dm-verity and mount by @ChengyuZhu6 in #270
  • ci: enable image-rs rust lint check for all features by @arronwy in #291
  • aa: sgx-attester: update occlum_dcap to a tagged version by @mythi in #289
  • chore(deps): Update strum requirement from 0.24 to 0.25 by @dependabot in #293
  • image-rs: refine implementation of dm-verity by @jiangliu in #294
  • chore(deps): Update strum_macros requirement from 0.24 to 0.25 by @dependabot in #297
  • image-rs: add sha1 hash algorithm support in dm-verity by @ChengyuZhu6 in #300
  • Provide builder for KBS Protocol Wrapper by @mkulke in #278
  • Confidential-Datahub API definition and Sealed Secrets by @Xynnn007 in #288
  • Added two security enhancements to AA by @jialez0 in #273
  • Made Attester trait's get_evidence() async by @mkulke in #299
  • image pull tests: replace image ref by @Xynnn007 in #301
  • Add panic with error msg when test-async-pull-client fails by @portersrc in #303
  • Update commands to generate test image and remove duplicated test case by @arronwy in #305
  • image-rs: Fix the flaky CI with assert_retry by @arronwy in #306
  • image-rs: change fallback kbs_uri from localhost to http://localhost by @mkulke in #308
  • chore(deps): Update tonic-build requirement from 0.8.0 to 0.9.2 by @dependabot in #302
  • chore(deps): Update env_logger requirement from 0.9.0 to 0.10.0 by @dependabot in #310
  • kbs_protocol: use rusttls when rust-crypto feature is enabled by @mythi in #307
  • chore(deps): Update oci-spec requirement from 0.5.8 to 0.6.2 by @dependabot in #311
  • Refactor kbs client by @Xynnn007 in #304
  • image-rs: enclave-cc updates by @mythi in #312
  • chore(deps): Update async-compression requirement from 0.3.15 to 0.4.1 by @dependabot in #313
  • Kbs protocol fix cargo toml by @Xynnn007 in #315
  • Confidential DataHub Part 2: KMS support and unseal secret with KMS by @Xynnn007 in #309
  • chore(deps): Update shadow-rs requirement from 0.5.25 to 0.23.0 by @dependabot in #316
  • Fix: Initialization of tee type is lacked in get_token API by @jialez0 in #320
  • Confidential DataHub Part 3: Define Vault API & Support GetResource API with KBS-Client & Sev support by @Xynnn007 in #319
  • verity: support parsing options from remote snapshotter by @ChengyuZhu6 in #317
  • Add initial support for a hygon csv attester by @BaoshunFang in #323
  • Confidential DataHub Part 4: CDH binary & Attestation API for AA by @Xynnn007 in #322
  • image: Add a function to get image name from remote by @ChengyuZhu6 in #324
  • cargo: Fix the build dependency for eaa_kbc by @arronwy in #327
  • image-rs: Update loopdev to latest master by @surajssd in #328
  • image-rs: add feature gate for verity by @ChengyuZhu6 in #331
  • Remove git reference for sev by @emanuellima1 in #334
  • Initial implementation rest api server for CoCo by @arronwy in #325
  • versions: Downgrade clap by @stevenhorsman in #337
  • versions: Add tilde to clap dependency by @stevenhorsman in #339
  • Fix enclave-cc dep by @Xynnn007 in #335
  • ci: Use toolchain match the kata to replace the beta by @arronwy in #338
  • aa/attester: Update csv-rs dep to rev bcf3bcc. by @BaoshunFang in #342
  • Verity: Redefine functions to support kata by @ChengyuZhu6 in #343
  • aa/attester: Update csv-rs dep to rev 05fbacd. by @BaoshunFang in #348
  • Add Cargo.lock for consistent builds by @beraldoleal in #344
  • workflows: Bump to rust 1.72 by @stevenhorsman in #356
  • New tee type: CCA (Confidential Compute Architecture) by @chendave in #321
  • Api server rest makefile by @stevenhorsman in #358
  • Read agent config from file by @stevenhorsman in #365
  • Fix cc kbc aa param config file parsing by @stevenhorsman in #368
  • attestation-agent: fix extraction of peerpod kbs host addr extraction in token code by @mkulke in #371
  • api-server-rest: fix aa_addr cli param by @mkulke in #370
  • image-rs: Support simple signing with X-R-S-S by @mattarnoatibm in #372
  • cdh/kms/kbs: raise warning when failed to read file for offline-fs-kbc by @Xynnn007 in #374
  • Fix Aliyun KMS suite by @Xynnn007 in #376
  • cdh/kms: add rustls-tls feature for aliyun by @Xynnn007 in #377
  • Fix CDH & kbs_protocol by @Xynnn007 in #381
  • chore(deps): Bump docker/login-action from 2 to 3 by @dependabot in #362
  • chore(deps): Bump docker/build-push-action from 4 to 5 by @dependabot in #363
  • ci: disable eaa-kbc ci for PR and Merge by @Xynnn007 in #386
  • chore(deps): Bump actions/checkout from 3 to 4 by @dependabot in #351

New Contributors

**Full...

Read more

v0.7.0

20 Jul 20:03
Compare
Choose a tag to compare

Although this is v0.7.0, this is the first release of the merged guest-components repository.

Previous releases in this repository are from when the repository contained only image-rs.
This is one reason that so many people are listed as new contributors in this release.

What's Changed

New Contributors

Full Changelog: v0.6.0...v0.7.0

v0.6.0

05 Jun 16:26
62288ee
Compare
Choose a tag to compare

What's Changed

New Contributors

Full Changelog: v0.5.1...v0.6.0

v0.5.1

14 Apr 13:18
Compare
Choose a tag to compare
deps: Bump ocicrypt-rs to v0.5.1

I've missed one dependency bump while releasing ocicrypt-rs v0.5.0,
which lead to a new v0.5.1 release, which we should use here.

Signed-off-by: Fabiano Fidêncio <[email protected]>

v0.5.0

14 Apr 09:10
f031741
Compare
Choose a tag to compare
Merge pull request #139 from fidencio/topic/adapt-dependencies-to-v0.…

v0.4.0

28 Feb 07:42
Compare
Choose a tag to compare
lint: fix clippy warning for ttrpc proto

Signed-off-by: Xynnn007 <[email protected]>

v0.2.0: Merge pull request #75 from arronwy/bump_ocicrypt-rs

07 Nov 08:06
3aca6fd
Compare
Choose a tag to compare
cargo: Bump ocicrypt-rs to v0.2.0