Update all non-major dependencies#325
Conversation
ℹ Artifact update noticeFile name: go.modIn order to perform the update(s) described in the table above, Renovate ran the
Details:
|
2b01dac to
64dee19
Compare
7b87743 to
921e3c1
Compare
86f00a3 to
4400a7f
Compare
fa07001 to
27e33a9
Compare
b06926e to
6a99f80
Compare
6a99f80 to
a2230ed
Compare
c67cd33 to
8de3726
Compare
d342f02 to
f5307b0
Compare
c5ac266 to
50783ee
Compare
50783ee to
0b2ad8e
Compare
e7866b4 to
53fd60c
Compare
8a48b3d to
96f8fd5
Compare
|
Hello, is this going to be merged? Some High vulnerabilities are fixed. Thank you |
|
This are the vulnerabilities that are patched with these upgrades:
|
|
Looks like the testing failed, looking in to why |
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
96f8fd5 to
9c664ca
Compare
|
This testing worked locally, going to retry and see if it was a one off |
|
[APPROVALNOTIFIER] This PR is APPROVED Approval requirements bypassed by manually added approval. This pull-request has been approved by: The full list of commands accepted by this bot can be found here. The pull request process is described here DetailsNeeds approval from an approver in each of these files:Approvers can indicate their approval by writing |
This PR contains the following updates:
v1.16.0->v1.16.3v1.27.0->v1.33.0v1.27.15->v1.29.1v1.17.15->v1.17.54v1.29.5->v1.37.13v1.32.1->v1.38.7v1.25.5->v1.29.13v1.28.9->v1.33.9v1.15.4->v1.16.3v1.4.1->v1.4.2v1.9.0->v1.10.01.22.3->1.23.51.22.3->1.23.51.22->1.23v0.30.1->v0.32.1v0.30.1->v0.32.1v0.30.1->v0.32.1fe8a2dd->24370be0.15.0->0.17.1v0.18.2->v0.20.1Release Notes
cert-manager/cert-manager (cert-manager/cert-manager)
v1.16.3Compare Source
cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.
v1.16.3 is a patch release mainly focused around bumping dependencies to address reported CVEs: CVE-2024-45337 and CVE-2024-45338.
We don't believe that cert-manager is actually vulnerable; this release is instead intended to satisfy vulnerability scanners.
It also includes a bug fix to the new
renewBeforePercentagefield. If you were usingrenewBeforePercentage, see PR #7421 for more information.Changes
Bug
golang.org/x/netandgolang.org/x/cryptoto address CVE-2024-45337 and CVE-2024-45338 (#7485, @erikgb)renewBeforePercentageto comply with its spec (#7441, @cert-manager-bot)Other
v1.16.2Compare Source
cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.
This patch release of cert-manager 1.16 makes several changes to how PEM input is validated, adding maximum sizes appropriate to the type of PEM data which is being parsed.
This is to prevent an unacceptable slow-down in parsing specially crafted PEM data. The issue was found by Google's OSS-Fuzz project.
The issue is low severity; to exploit the PEM issue would require privileged access which would likely allow Denial-of-Service through other methods.
Note also that since most PEM data parsed by cert-manager comes from
ConfigMaporSecretresources which have a max size limit of approximately 1MB, it's difficult to force cert-manager to parse large amounts of PEM data.Further information is available in GHSA-r4pg-vg54-wxx4
In addition, the version of Go used to build cert-manager 1.16 was updated along with the base images.
Changes by Kind
Bug or Regression
Other (Cleanup or Flake)
v1.16.1Compare Source
cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.
The cert-manager 1.16 release includes: new Helm chart features, more Prometheus metrics, memory optimizations, and various improvements and bug fixes for the ACME issuer and Venafi Issuer.
📖 Read the complete 1.16 release notes before upgrading.
📜Changes since
v1.16.0Bug or Regression
@inteon)podDisruptionBudget.minAvailableandpodDisruptionBudget.maxAvailablevalues. (#7345,@inteon)enabledto be set as a value to toggle cert-manager as a dependency. (#7356,@inteon)v1.16.0caused cert-manager's ACME ClusterIssuer to look in the wrong namespace for resources required for the issuance (e.g. credential Secrets). This is now fixed inv1.16.1. (#7342,@inteon)aws/aws-sdk-go-v2 (github.com/aws/aws-sdk-go-v2)
v1.33.0Compare Source
v1.32.8Compare Source
v1.32.7Compare Source
v1.32.6Compare Source
v1.32.5Compare Source
v1.32.4Compare Source
v1.32.3Compare Source
v1.32.2Compare Source
v1.32.1Compare Source
v1.32.0Compare Source
v1.31.0Compare Source
v1.30.5Compare Source
v1.30.4Compare Source
v1.30.3Compare Source
v1.30.2Compare Source
v1.30.1v1.30.0v1.28.0v1.27.2v1.27.1go-logr/logr (github.com/go-logr/logr)
v1.4.2Compare Source
What's Changed
Dependencies:
Full Changelog: go-logr/logr@v1.4.1...v1.4.2
stretchr/testify (github.com/stretchr/testify)
v1.10.0Compare Source
What's Changed
Functional Changes
Fixes
Documantation, Build & CI
New Contributors
Full Changelog: stretchr/testify@v1.9.0...v1.10.0
golang/go (go)
v1.23.5v1.23.4v1.23.3v1.23.2v1.23.1v1.23.0v1.22.11v1.22.10v1.22.9v1.22.8v1.22.7v1.22.6v1.22.5v1.22.4kubernetes/api (k8s.io/api)
v0.32.1Compare Source
v0.32.0Compare Source
v0.31.5Compare Source
v0.31.4Compare Source
v0.31.3Compare Source
v0.31.2Compare Source
v0.31.1Compare Source
v0.31.0Compare Source
v0.30.9Compare Source
v0.30.8Compare Source
v0.30.7Compare Source
v0.30.6Compare Source
v0.30.5Compare Source
v0.30.4Compare Source
v0.30.3Compare Source
v0.30.2Compare Source
kubernetes/apimachinery (k8s.io/apimachinery)
v0.32.1Compare Source
v0.32.0Compare Source
v0.31.5Compare Source
v0.31.4Compare Source
v0.31.3Compare Source
v0.31.2Compare Source
v0.31.1Compare Source
v0.31.0Compare Source
v0.30.9Compare Source
v0.30.8Compare Source
v0.30.7Compare Source
v0.30.6Compare Source
v0.30.5Compare Source
v0.30.4Compare Source
v0.30.3Compare Source
v0.30.2Compare Source
kubernetes/client-go (k8s.io/client-go)
v0.32.1Compare Source
v0.32.0Compare Source
v0.31.5Compare Source
v0.31.4Compare Source
v0.31.3Compare Source
v0.31.2Compare Source
v0.31.1Compare Source
v0.31.0Compare Source
v0.30.9Compare Source
v0.30.8Compare Source
v0.30.7Compare Source
v0.30.6Compare Source
v0.30.5Compare Source
v0.30.4Compare Source
v0.30.3Compare Source
v0.30.2Compare Source
kubernetes-sigs/controller-tools (kubernetes-sigs/controller-tools)
v0.17.1Compare Source
What's Changed
Dependencies
Full Changelog: kubernetes-sigs/controller-tools@v0.17.0...v0.17.1
v0.17.0Compare Source
What's Changed
*types.Aliaswith Go 1.23 by @mtardy in https://github.com/kubernetes-sigs/controller-tools/pull/1061Configuration
📅 Schedule: Branch creation - "after 9am on Wednesday,before 12pm on Wednesday" in timezone America/New_York, Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR was generated by Mend Renovate. View the repository job log.