Skip to content

Conversation

@renovate
Copy link
Contributor

@renovate renovate bot commented Oct 20, 2025

This PR contains the following updates:

Package Change Age Confidence
k8s.io/api v0.33.4 -> v0.34.1 age confidence
k8s.io/apimachinery v0.33.4 -> v0.34.1 age confidence
k8s.io/client-go v0.33.4 -> v0.34.1 age confidence

Release Notes

kubernetes/api (k8s.io/api)

v0.34.1

Compare Source

v0.34.0

Compare Source

v0.33.5

Compare Source

kubernetes/apimachinery (k8s.io/apimachinery)

v0.34.1

Compare Source

v0.34.0

Compare Source

v0.33.5

Compare Source

kubernetes/client-go (k8s.io/client-go)

v0.34.1

Compare Source

v0.34.0

Compare Source

v0.33.5

Compare Source


Configuration

📅 Schedule: Branch creation - Between 12:00 AM and 03:59 AM, only on Monday ( * 0-3 * * 1 ) (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about these updates again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
Copy link
Contributor Author

renovate bot commented Oct 20, 2025

ℹ Artifact update notice

File name: go.mod

In order to perform the update(s) described in the table above, Renovate ran the go get command, which resulted in the following additional change(s):

  • 6 additional dependencies were updated

Details:

Package Change
github.com/fxamacker/cbor/v2 v2.8.0 -> v2.9.0
github.com/google/gnostic-models v0.6.9 -> v0.7.0
go.yaml.in/yaml/v3 v3.0.3 -> v3.0.4
k8s.io/gengo/v2 v2.0.0-20250207200755-1244d31929d7 -> v2.0.0-20250604051438-85fd79dbfd9f
github.com/modern-go/reflect2 v1.0.2 -> v1.0.3-0.20250322232337-35a7c28c31ee
k8s.io/kube-openapi v0.0.0-20250318190949-c8a335a9a2ff -> v0.0.0-20250710124328-f3f2b991d03b

@renovate renovate bot requested review from a team as code owners October 20, 2025 01:41
@renovate renovate bot force-pushed the renovate/kubernetes-go branch from 489033a to 2e2cddd Compare October 21, 2025 08:36
@a-cordier a-cordier force-pushed the renovate/kubernetes-go branch from 2e2cddd to 625266d Compare October 24, 2025 10:06
@renovate renovate bot force-pushed the renovate/kubernetes-go branch from 625266d to 7de2ab5 Compare October 24, 2025 10:08
@a-cordier a-cordier force-pushed the renovate/kubernetes-go branch from 7de2ab5 to baefa31 Compare October 24, 2025 10:16
@renovate renovate bot force-pushed the renovate/kubernetes-go branch from baefa31 to 609bb82 Compare October 24, 2025 10:17
@a-cordier a-cordier force-pushed the renovate/kubernetes-go branch from 609bb82 to f5a2a4e Compare October 24, 2025 10:23
@renovate
Copy link
Contributor Author

renovate bot commented Oct 24, 2025

Edited/Blocked Notification

Renovate will not automatically rebase this PR, because it does not recognize the last commit author and assumes somebody else may have edited the PR.

You can manually request rebase by checking the rebase/retry box above.

⚠️ Warning: custom changes will be lost.

@sonarqubecloud
Copy link

github.com/onsi/ginkgo/v2 v2.23.4
github.com/onsi/gomega v1.37.0
github.com/zeebo/xxh3 v1.0.2
golang.org/x/exp v0.0.0-20251017212417-90e834f514db
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Aqua detected vulnerability in your code

Vulnerability ID: CVE-2025-27144
Check Name: go-jose: Go JOSE's Parsing Vulnerable to Denial of Service
Severity: MEDIUM
Fixed Version: 4.0.5
Reachable Path(s) Found: No
Description: Go JOSE provides an implementation of the Javascript Object Signing and Encryption set of standards in Go, including support for JSON Web Encryption (JWE), JSON Web Signature (JWS), and JSON Web Token (JWT) standards. In versions on the 4.x branch prior to version 4.0.5, when parsing compact JWS or JWE input, Go JOSE could use excessive memory. The code used strings.Split(token, ".") to split JWT tokens, which is vulnerable to excessive memory consumption when processing maliciously crafted tokens with a large number of . characters. An attacker could exploit this by sending numerous malformed tokens, leading to memory exhaustion and a Denial of Service. Version 4.0.5 fixes this issue. As a workaround, applications could pre-validate that payloads passed to Go JOSE do not contain an excessive number of . characters.
[This comment was created by Aqua Pipeline]

Read more at https://avd.aquasec.com/nvd/cve-2025-27144

@a-cordier a-cordier force-pushed the renovate/kubernetes-go branch from 0a4db42 to b0fa8af Compare October 24, 2025 12:46
@renovate renovate bot force-pushed the renovate/kubernetes-go branch from b0fa8af to fffa13f Compare October 24, 2025 12:51
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant