Skip to content

chore(deps): update all dependencies#186

Merged
csatib02 merged 4 commits intomainfrom
renovate/all
Jan 5, 2026
Merged

chore(deps): update all dependencies#186
csatib02 merged 4 commits intomainfrom
renovate/all

Conversation

@renovate
Copy link
Contributor

@renovate renovate bot commented Nov 25, 2025

This PR contains the following updates:

Package Type Update Change Pending Age Confidence
cert-manager/cert-manager patch 1.19.11.19.2 age confidence
docker/metadata-action action minor v5.9.0v5.10.0 age confidence
docker/setup-buildx-action action minor v3.11.1v3.12.0 age confidence
gcr.io/distroless/static final digest e8a40442b7c93f
github.com/onsi/ginkgo/v2 require patch v2.27.2v2.27.3 age confidence
github.com/onsi/gomega require patch v1.38.2v1.38.3 age confidence
github.com/open-telemetry/opentelemetry-operator require minor v0.140.0v0.141.0 age confidence
go.opentelemetry.io/collector/component require minor v1.46.0v1.48.0 age confidence
go.opentelemetry.io/collector/config/configauth require minor v1.46.0v1.48.0 age confidence
go.opentelemetry.io/collector/config/configcompression require minor v1.46.0v1.48.0 age confidence
go.opentelemetry.io/collector/config/configopaque require minor v1.46.0v1.48.0 age confidence
go.opentelemetry.io/collector/config/configtelemetry require minor v0.140.0v0.142.0 age confidence
go.opentelemetry.io/collector/otelcol require minor v0.140.0v0.142.0 age confidence
go.opentelemetry.io/collector/pipeline require minor v1.46.0v1.48.0 age confidence
go.opentelemetry.io/collector/service require minor v0.140.0v0.142.0 age confidence
golang stage patch 1.25.2-alpine3.221.25.5-alpine3.22 age confidence
golangci/golangci-lint minor 2.6.22.7.2 age confidence
k8s.io/api require patch v0.34.2v0.34.3 v0.35.0 age confidence
k8s.io/apimachinery require patch v0.34.2v0.34.3 v0.35.0 age confidence
k8s.io/client-go require patch v0.34.2v0.34.3 v0.35.0 age confidence
kubernetes-sigs/controller-tools minor 0.19.00.20.0 age confidence
opentelemetry-operator (source) minor 0.99.20.102.0 age confidence

Release Notes

cert-manager/cert-manager (cert-manager/cert-manager)

v1.19.2

Compare Source

cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.

We updated Go to fix some vulnerabilities in the standard library.

📖 Read the full 1.19 release notes on the cert-manager.io website before upgrading.

Changes since v1.19.1

Bug or Regression
  • Address false positive vulnerabilities CVE-2025-47914 and CVE-2025-58181 which were reported by Trivy. (#​8283, @​SgtCoDFish)
  • Update Go to v1.25.5 to fix CVE-2025-61727 and CVE-2025-61729 (#​8294, @​wallrj-cyberark)
  • Update global.nodeSelector to helm chart to perform a merge and allow for a single nodeSelector to be set across all services. (#​8233, @​cert-manager-bot)
Other (Cleanup or Flake)
docker/metadata-action (docker/metadata-action)

v5.10.0

Compare Source

Full Changelog: docker/metadata-action@v5.9.0...v5.10.0

docker/setup-buildx-action (docker/setup-buildx-action)

v3.12.0

Compare Source

Full Changelog: docker/setup-buildx-action@v3.11.1...v3.12.0

onsi/ginkgo (github.com/onsi/ginkgo/v2)

v2.27.3

Compare Source

2.27.3

Fixes

report exit result in case of failure [1c9f356]
fix data race [ece19c8]

onsi/gomega (github.com/onsi/gomega)

v1.38.3

Compare Source

1.38.3

Fixes

make string formatitng more consistent for users who use format.Object directly

open-telemetry/opentelemetry-operator (github.com/open-telemetry/opentelemetry-operator)

v0.141.0

Compare Source

0.141.0

💡 Enhancements 💡
  • collector: Ensure the collector container is always listed first in the podspec (#​4548)
    This is so tools like kubectx logs will always default to the collector container instead of any additional containers that are configured.
  • target allocator: make evaluation_interval configurable for Prometheus CR watcher (#​4520)
  • operator: Support for Kubernetes 1.34 version. (#​4415)
Components
open-telemetry/opentelemetry-collector (go.opentelemetry.io/collector/component)

v1.48.0

💡 Enhancements 💡
  • exporter/debug: Add logging of dropped attributes, events, and links counts in detailed verbosity (#​14202)

  • extension/memory_limiter: The memorylimiter extension can be used as an HTTP/GRPC middleware. (#​14081)

  • pkg/config/configgrpc: Statically validate gRPC endpoint (#​10451)
    This validation was already done in the OTLP exporter. It will now be applied to any gRPC client.

  • pkg/service: Add support to disabling adding resource attributes as zap fields in internal logging (#​13869)
    Note that this does not affect logs exported through OTLP.

v1.47.0

🛑 Breaking changes 🛑
  • pkg/config/confighttp: Use configoptional.Optional for confighttp.ClientConfig.Cookies field (#​14021)
💡 Enhancements 💡
  • pkg/config/confighttp: Setting compression_algorithms to an empty list now disables automatic decompression, ignoring Content-Encoding (#​14131)
  • pkg/service: Update semantic conventions from internal telemetry to v1.37.0 (#​14232)
  • pkg/xscraper: Implement xscraper for Profiles. (#​13915)
🧰 Bug fixes 🧰
  • pkg/config/configoptional: Ensure that configoptional.None values resulting from unmarshaling are equivalent to configoptional.Optional zero value. (#​14218)
golangci/golangci-lint (golangci/golangci-lint)

v2.7.2

Compare Source

Released on 2025-12-07

  1. Linter bug fixes

v2.7.1

Compare Source

Released on 2025-12-04

  1. Linter bug fixes
    • modernize: disable stringscut analyzer

v2.7.0

Compare Source

Released on 2025-12-03

  1. Bug fixes
    • fix: clone args used by custom command
  2. Linters new features or changes
    • no-sprintf-host-port: from 0.2.0 to 0.3.1 (ignore string literals without a colon)
    • unqueryvet: from 1.2.1 to 1.3.0 (handles const and var declarations)
    • revive: from 1.12.0 to 1.13.0 (new option: enable-default-rules, new rules: forbidden-call-in-wg-go, unnecessary-if, inefficient-map-lookup)
    • modernize: from 0.38.0 to 0.39.0 (new analyzers: plusbuild, stringscut)
  3. Linters bug fixes
    • perfsprint: from 0.10.0 to 0.10.1
    • wrapcheck: from 2.11.0 to 2.12.0
    • godoc-lint: from 0.10.1 to 0.10.2
  4. Misc.
    • Add some flags to the custom command
  5. Documentation
    • docs: split changelog v1 and v2
kubernetes/api (k8s.io/api)

v0.34.3

Compare Source

kubernetes/apimachinery (k8s.io/apimachinery)

v0.34.3

Compare Source

kubernetes/client-go (k8s.io/client-go)

v0.34.3

Compare Source

kubernetes-sigs/controller-tools (kubernetes-sigs/controller-tools)

v0.20.0

Compare Source

What's Changed

Misc

envtest

Dependency bumps

New Contributors

Full Changelog: kubernetes-sigs/controller-tools@v0.19.0...v0.20.0

open-telemetry/opentelemetry-helm-charts (opentelemetry-operator)

v0.102.0

Compare Source

OpenTelemetry Operator Helm chart for Kubernetes

What's Changed

Full Changelog: open-telemetry/opentelemetry-helm-charts@opentelemetry-operator-0.101.0...opentelemetry-operator-0.102.0

v0.101.0

Compare Source

OpenTelemetry Operator Helm chart for Kubernetes

What's Changed

New Contributors

Full Changelog: open-telemetry/opentelemetry-helm-charts@opentelemetry-ebpf-instrumentation-0.2.2...opentelemetry-operator-0.101.0

v0.100.0

Compare Source

OpenTelemetry Operator Helm chart for Kubernetes

What's Changed

Full Changelog: open-telemetry/opentelemetry-helm-charts@opentelemetry-demo-0.39.0...opentelemetry-operator-0.100.0


Configuration

📅 Schedule: Branch creation - Between 12:00 AM and 03:59 AM ( * 0-3 * * * ) in timezone Etc/UTC, Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate bot added the dependencies Pull requests that update a dependency file label Nov 25, 2025
@renovate renovate bot changed the title chore(deps): update golang docker tag to v1.25.4 chore(deps): update all dependencies Nov 27, 2025
@renovate renovate bot force-pushed the renovate/all branch 2 times, most recently from a8c5b53 to c91f5a0 Compare December 1, 2025 16:02
@renovate
Copy link
Contributor Author

renovate bot commented Dec 1, 2025

ℹ Artifact update notice

File name: go.mod

In order to perform the update(s) described in the table above, Renovate ran the go get command, which resulted in the following additional change(s):

  • 38 additional dependencies were updated

Details:

Package Change
go.opentelemetry.io/auto/sdk v1.1.0 -> v1.2.1
go.opentelemetry.io/collector/component/componentstatus v0.140.0 -> v0.141.0
go.opentelemetry.io/collector/component/componenttest v0.140.0 -> v0.141.0
go.opentelemetry.io/collector/confmap v1.46.0 -> v1.47.0
go.opentelemetry.io/collector/confmap/xconfmap v0.140.0 -> v0.141.0
go.opentelemetry.io/collector/connector v0.140.0 -> v0.141.0
go.opentelemetry.io/collector/connector/connectortest v0.140.0 -> v0.141.0
go.opentelemetry.io/collector/connector/xconnector v0.140.0 -> v0.141.0
go.opentelemetry.io/collector/consumer v1.46.0 -> v1.47.0
go.opentelemetry.io/collector/consumer/consumererror v0.140.0 -> v0.141.0
go.opentelemetry.io/collector/consumer/consumertest v0.140.0 -> v0.141.0
go.opentelemetry.io/collector/consumer/xconsumer v0.140.0 -> v0.141.0
go.opentelemetry.io/collector/exporter v1.46.0 -> v1.47.0
go.opentelemetry.io/collector/exporter/exportertest v0.140.0 -> v0.141.0
go.opentelemetry.io/collector/exporter/xexporter v0.140.0 -> v0.141.0
go.opentelemetry.io/collector/extension v1.46.0 -> v1.47.0
go.opentelemetry.io/collector/extension/extensionauth v1.46.0 -> v1.47.0
go.opentelemetry.io/collector/extension/extensioncapabilities v0.140.0 -> v0.141.0
go.opentelemetry.io/collector/extension/extensiontest v0.140.0 -> v0.141.0
go.opentelemetry.io/collector/featuregate v1.46.0 -> v1.47.0
go.opentelemetry.io/collector/internal/fanoutconsumer v0.140.0 -> v0.141.0
go.opentelemetry.io/collector/internal/telemetry v0.140.0 -> v0.141.0
go.opentelemetry.io/collector/pdata v1.46.0 -> v1.47.0
go.opentelemetry.io/collector/pdata/pprofile v0.140.0 -> v0.141.0
go.opentelemetry.io/collector/pdata/testdata v0.140.0 -> v0.141.0
go.opentelemetry.io/collector/pdata/xpdata v0.140.0 -> v0.141.0
go.opentelemetry.io/collector/pipeline/xpipeline v0.140.0 -> v0.141.0
go.opentelemetry.io/collector/processor v1.46.0 -> v1.47.0
go.opentelemetry.io/collector/processor/processortest v0.140.0 -> v0.141.0
go.opentelemetry.io/collector/processor/xprocessor v0.140.0 -> v0.141.0
go.opentelemetry.io/collector/receiver v1.46.0 -> v1.47.0
go.opentelemetry.io/collector/receiver/receivertest v0.140.0 -> v0.141.0
go.opentelemetry.io/collector/receiver/xreceiver v0.140.0 -> v0.141.0
go.opentelemetry.io/collector/service/hostcapabilities v0.140.0 -> v0.141.0
golang.org/x/oauth2 v0.31.0 -> v0.32.0
google.golang.org/genproto/googleapis/api v0.0.0-20250825161204-c5933d9347a5 -> v0.0.0-20251022142026-3a174f9686a8
google.golang.org/genproto/googleapis/rpc v0.0.0-20250825161204-c5933d9347a5 -> v0.0.0-20251022142026-3a174f9686a8
google.golang.org/grpc v1.76.0 -> v1.77.0

@renovate renovate bot force-pushed the renovate/all branch 6 times, most recently from 416afb4 to a7cbcf2 Compare December 9, 2025 18:53
@renovate renovate bot force-pushed the renovate/all branch 2 times, most recently from 73cfa1d to 50f349e Compare December 10, 2025 05:55
@renovate
Copy link
Contributor Author

renovate bot commented Dec 10, 2025

ℹ️ Artifact update notice

File name: go.mod

In order to perform the update(s) described in the table above, Renovate ran the go get command, which resulted in the following additional change(s):

  • 57 additional dependencies were updated

Details:

Package Change
github.com/ebitengine/purego v0.9.0 -> v0.9.1
github.com/hashicorp/go-version v1.7.0 -> v1.8.0
github.com/shirou/gopsutil/v4 v4.25.10 -> v4.25.11
github.com/spf13/cobra v1.10.1 -> v1.10.2
github.com/tklauser/go-sysconf v0.3.15 -> v0.3.16
github.com/tklauser/numcpus v0.10.0 -> v0.11.0
go.opentelemetry.io/auto/sdk v1.1.0 -> v1.2.1
go.opentelemetry.io/collector/component/componentstatus v0.140.0 -> v0.142.0
go.opentelemetry.io/collector/component/componenttest v0.140.0 -> v0.142.0
go.opentelemetry.io/collector/confmap v1.46.0 -> v1.48.0
go.opentelemetry.io/collector/confmap/xconfmap v0.140.0 -> v0.142.0
go.opentelemetry.io/collector/connector v0.140.0 -> v0.142.0
go.opentelemetry.io/collector/connector/connectortest v0.140.0 -> v0.142.0
go.opentelemetry.io/collector/connector/xconnector v0.140.0 -> v0.142.0
go.opentelemetry.io/collector/consumer v1.46.0 -> v1.48.0
go.opentelemetry.io/collector/consumer/consumererror v0.140.0 -> v0.142.0
go.opentelemetry.io/collector/consumer/consumertest v0.140.0 -> v0.142.0
go.opentelemetry.io/collector/consumer/xconsumer v0.140.0 -> v0.142.0
go.opentelemetry.io/collector/exporter v1.46.0 -> v1.48.0
go.opentelemetry.io/collector/exporter/exportertest v0.140.0 -> v0.142.0
go.opentelemetry.io/collector/exporter/xexporter v0.140.0 -> v0.142.0
go.opentelemetry.io/collector/extension v1.46.0 -> v1.48.0
go.opentelemetry.io/collector/extension/extensionauth v1.46.0 -> v1.48.0
go.opentelemetry.io/collector/extension/extensioncapabilities v0.140.0 -> v0.142.0
go.opentelemetry.io/collector/extension/extensiontest v0.140.0 -> v0.142.0
go.opentelemetry.io/collector/featuregate v1.46.0 -> v1.48.0
go.opentelemetry.io/collector/internal/fanoutconsumer v0.140.0 -> v0.142.0
go.opentelemetry.io/collector/internal/telemetry v0.140.0 -> v0.142.0
go.opentelemetry.io/collector/pdata v1.46.0 -> v1.48.0
go.opentelemetry.io/collector/pdata/pprofile v0.140.0 -> v0.142.0
go.opentelemetry.io/collector/pdata/testdata v0.140.0 -> v0.142.0
go.opentelemetry.io/collector/pdata/xpdata v0.140.0 -> v0.142.0
go.opentelemetry.io/collector/pipeline/xpipeline v0.140.0 -> v0.142.0
go.opentelemetry.io/collector/processor v1.46.0 -> v1.48.0
go.opentelemetry.io/collector/processor/processortest v0.140.0 -> v0.142.0
go.opentelemetry.io/collector/processor/xprocessor v0.140.0 -> v0.142.0
go.opentelemetry.io/collector/receiver v1.46.0 -> v1.48.0
go.opentelemetry.io/collector/receiver/receivertest v0.140.0 -> v0.142.0
go.opentelemetry.io/collector/receiver/xreceiver v0.140.0 -> v0.142.0
go.opentelemetry.io/collector/service/hostcapabilities v0.140.0 -> v0.142.0
go.opentelemetry.io/otel v1.38.0 -> v1.39.0
go.opentelemetry.io/otel/log v0.14.0 -> v0.15.0
go.opentelemetry.io/otel/metric v1.38.0 -> v1.39.0
go.opentelemetry.io/otel/sdk v1.38.0 -> v1.39.0
go.opentelemetry.io/otel/sdk/metric v1.38.0 -> v1.39.0
go.opentelemetry.io/otel/trace v1.38.0 -> v1.39.0
golang.org/x/mod v0.29.0 -> v0.30.0
golang.org/x/net v0.47.0 -> v0.48.0
golang.org/x/oauth2 v0.31.0 -> v0.32.0
golang.org/x/sync v0.18.0 -> v0.19.0
golang.org/x/sys v0.38.0 -> v0.39.0
golang.org/x/term v0.37.0 -> v0.38.0
golang.org/x/text v0.31.0 -> v0.32.0
golang.org/x/tools v0.38.0 -> v0.39.0
google.golang.org/genproto/googleapis/api v0.0.0-20250825161204-c5933d9347a5 -> v0.0.0-20251022142026-3a174f9686a8
google.golang.org/genproto/googleapis/rpc v0.0.0-20250825161204-c5933d9347a5 -> v0.0.0-20251022142026-3a174f9686a8
google.golang.org/grpc v1.76.0 -> v1.77.0

@renovate renovate bot force-pushed the renovate/all branch 11 times, most recently from 828aa13 to a27ad70 Compare December 18, 2025 15:03
@renovate
Copy link
Contributor Author

renovate bot commented Jan 5, 2026

Edited/Blocked Notification

Renovate will not automatically rebase this PR, because it does not recognize the last commit author and assumes somebody else may have edited the PR.

You can manually request rebase by checking the rebase/retry box above.

⚠️ Warning: custom changes will be lost.

Signed-off-by: Bence Csati <bence.csati@axoflow.com>
Signed-off-by: Bence Csati <bence.csati@axoflow.com>
Signed-off-by: Bence Csati <bence.csati@axoflow.com>
@csatib02 csatib02 merged commit e9f71f3 into main Jan 5, 2026
11 checks passed
@csatib02 csatib02 deleted the renovate/all branch January 5, 2026 12:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant