Skip to content

Conversation

@dependabot
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github May 25, 2025

Bumps the go group with 4 updates: github.com/fluxcd/pkg/runtime, github.com/fluxcd/pkg/ssa, github.com/open-component-model/ocm-controller and sigs.k8s.io/controller-runtime.

Updates github.com/fluxcd/pkg/runtime from 0.59.0 to 0.60.0

Commits
  • 3d6f759 Merge pull request #931 from fluxcd/helm-v3.18.0
  • 6c13e0f Update helm to v3.18.0
  • 0e3c44a Merge pull request #930 from fluxcd/controller-runtime-v0.21.0
  • 10f34ae Update controller-runtime to v0.21.0
  • 69fd2d1 Merge pull request #928 from fluxcd/auth-audience-cache-key
  • 82fd687 [RFC-0010] Add provider audience to cache key and decouple packages
  • 7a72e48 Merge pull request #927 from fluxcd/rfc-0010-feature-gate
  • d1cd390 [RFC-0010] Introduce feature gate for enabling object-level workload identity
  • a556f82 Merge pull request #926 from fluxcd/azure-int-tests
  • d8a62c1 Enable scheduled Azure integration tests
  • Additional commits viewable in compare view

Updates github.com/fluxcd/pkg/ssa from 0.47.0 to 0.48.0

Commits
  • 3ba849f Merge pull request #919 from fluxcd/auth-valid-registry
  • d89e633 [RFC-0010] Validate artifact repository for all auth providers
  • 1985bd8 Merge pull request #918 from fluxcd/gogit-agnostic
  • 5b6454a Package git/gogit should be agnostic of providers
  • 00782ed Merge pull request #917 from fluxcd/test-auth-providers
  • 3976c50 [RFC-0010] Add tests for auth providers
  • 182841a Merge pull request #916 from fluxcd/cache-op-label
  • 1e41450 Introduce operation label for cache event metric
  • aa3cde9 Merge pull request #909 from fluxcd/auth-azure
  • 9e0e8bc [RFC-0010] Add azure auth library
  • Additional commits viewable in compare view

Updates github.com/open-component-model/ocm-controller from 0.26.0 to 0.26.1

Release notes

Sourced from github.com/open-component-model/ocm-controller's releases.

v0.26.1

Release v0.26.1

  • Registry Deployment template now gets image info from values.yaml (#660)
  • chore: refactoring the signing test to make it more robust (#657)
  • fix: update the used repository name (#656)
  • fix: add extra identity to the resource lookup reference (#655)
  • adjust GHA to trigger on PR and not pull_request_target (#653)
  • Enable e2e GHA workflow to be executed manually (#650)

🐛 Bug Fixes

  • update slack GHA (#651)

🧰 Maintenance

  • chore(deps): bump the go group with 5 updates (#661)
  • chore(deps): bump the go group with 2 updates (#654)
  • chore(deps): bump the go group with 7 updates (#648)
  • chore(deps): bump the go group with 5 updates (#646)
  • chore(deps): bump the go group with 4 updates (#643)
  • chore(deps): bump the go_modules group across 1 directory with 4 updates (#641)
  • chore(deps): bump the go group across 1 directory with 7 updates (#637)

⬆️ Dependencies

  • chore(deps): bump the go group with 5 updates (#661)
  • chore(deps): bump the go group with 2 updates (#654)
  • chore(deps): bump the go group with 7 updates (#648)
  • chore(deps): bump the go group with 5 updates (#646)
  • chore(deps): bump the go group with 4 updates (#643)
  • chore(deps): bump the go_modules group across 1 directory with 4 updates (#641)
  • chore(deps): bump the go group across 1 directory with 7 updates (#637)
Commits
  • 64957cd chore: release for v0.26.1
  • 8bf7287 Registry Deployment template now gets image info from values.yaml (#660)
  • 4119ac2 chore(deps): bump the go group with 5 updates (#661)
  • 6a25a2b chore(deps): bump github/codeql-action from 3.28.17 to 3.28.18 in the ci grou...
  • 24e78de chore(deps): bump anchore/sbom-action from 0.19.0 to 0.20.0 in the ci group (...
  • ef8d7d6 chore: refactoring the signing test to make it more robust (#657)
  • c0b9d07 fix: update the used repository name (#656)
  • 2f8784e fix: add extra identity to the resource lookup reference (#655)
  • 494a0e7 chore(deps): bump the go group with 2 updates (#654)
  • 715b305 adjust GHA to trigger on PR and not pull_request_target (#653)
  • Additional commits viewable in compare view

Updates sigs.k8s.io/controller-runtime from 0.20.4 to 0.21.0

Release notes

Sourced from sigs.k8s.io/controller-runtime's releases.

v0.21.0

Highlights

  • Bump to Kubernetes v1.33 libraries
  • Improvements for priority queue (#2374)
  • envtest now has an option to download envtest binaries (can be used to replace setup-envtest depending on use case)
  • Metric improvements: native histograms, all Go runtime metrics are enabled now
  • Various bug fixes
  • New reviewers: @​troy0820, @​JoelSpeed!!

⚠️ Breaking Changes

  • Bump to k8s.io/* v0.33.0 and Go 1.24 (#3104 #3142 #3161 #3204 #3215)
  • config: Stop enabling client-side ratelimiter by default (#3119)
    • Previous behavior can be preserved by setting QPS 20 and Burst 30 on the rest.Config
  • controller: NewUnmanaged/NewTypedUnmanaged: Stop requiring a manager (#3141)
  • reconcile: Deprecate Result.Requeue (#3107)

✨ New Features

  • controller: priority queue:
    • Add debug logging for the state of the priority queue (#3075)
    • Add priority label to queue depth metric (#3156)
    • Leverage IsInInitialList (#3162)
    • Remove redundant WithLowPriorityWhenUnchanged in builder (#3168)
    • Retain the priority after Reconcile (#3167)
    • Set priority automatically in handlers (#3111 #3152 #3160 #3174)
  • envtest: Add Environment.KubeConfig field (#2278)
  • envtest: Add option to download envtest binaries (#3135 #3137)
  • events: Add IsInInitialList to TypedCreateEvent (#3162)
  • log/zap: Enable panic log level (#3186)
  • logging: Adopt WarningHandlerWithContext (#3176)
  • logging: Improve logging by adopting contextual logging (#3149)
  • metrics: Adopt native histograms (#3165)
  • metrics: Expose all Go runtime metrics (#3070)

🐛 Bug Fixes

  • apiutil: restmapper: Respect preferred version (#3151)
  • builder: webhook: Fix custom path for webhook conflicts (#3102)
  • cache: Clone maps to prevent data races when concurrently creating caches using the same options (#3078)
  • cache: Stop accumulating lists in multi-namespace cache implementation (#3195)
  • cache: List out of global cache when present and necessary (#3126)
  • client: Return error if pagination is used with the cached client (#3134)
  • controller: Support WaitForSync in TypedSyncingSource (#3084)
  • controller: priority queue: Fix behavior of rate limit option in priorityqueue.AddWithOpts (#3103)
  • controller: priority queue: Yet another queue_depth metric fix (#3085)
  • controllerutil: CreateOrUpdate: Avoid panic when the MutateFn is nil (#2828)
  • envtest: Fix nil pointer exception in Stop() (#3153)
  • fake client: Fix data races when writing to the scheme (#3143)

... (truncated)

Commits
  • 71f7db5 Merge pull request #3225 from troy0820/troy0820/prepare-for-0.21-release
  • 52d8779 update README with go version
  • ab37f74 Merge pull request #3223 from troy0820/troy0820/return-warnings-on-webhooks
  • 250a88f return warnings on webhooks
  • 85ee7a9 Merge pull request #3217 from kubernetes-sigs/dependabot/github_actions/all-g...
  • 81f1fae 🌱 Bump the all-github-actions group across 1 directory with 3 updates
  • d9a2274 Merge pull request #3187 from dongjiang1989/update-golangci-lint-v2
  • 9c38211 update golangci-lint to v2
  • 9b5f6a7 Merge pull request #3208 from troy0820/troy0820/api-machinery-marshal
  • b3278df use sigs.k8s.io/json to unmarshal in fakeclient
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the go group with 4 updates: [github.com/fluxcd/pkg/runtime](https://github.com/fluxcd/pkg), [github.com/fluxcd/pkg/ssa](https://github.com/fluxcd/pkg), [github.com/open-component-model/ocm-controller](https://github.com/open-component-model/ocm-controller) and [sigs.k8s.io/controller-runtime](https://github.com/kubernetes-sigs/controller-runtime).


Updates `github.com/fluxcd/pkg/runtime` from 0.59.0 to 0.60.0
- [Commits](fluxcd/pkg@runtime/v0.59.0...runtime/v0.60.0)

Updates `github.com/fluxcd/pkg/ssa` from 0.47.0 to 0.48.0
- [Commits](fluxcd/pkg@oci/v0.47.0...oci/v0.48.0)

Updates `github.com/open-component-model/ocm-controller` from 0.26.0 to 0.26.1
- [Release notes](https://github.com/open-component-model/ocm-controller/releases)
- [Changelog](https://github.com/open-component-model/ocm-controller/blob/main/.goreleaser.yaml)
- [Commits](open-component-model/ocm-controller@v0.26.0...v0.26.1)

Updates `sigs.k8s.io/controller-runtime` from 0.20.4 to 0.21.0
- [Release notes](https://github.com/kubernetes-sigs/controller-runtime/releases)
- [Changelog](https://github.com/kubernetes-sigs/controller-runtime/blob/main/RELEASE.md)
- [Commits](kubernetes-sigs/controller-runtime@v0.20.4...v0.21.0)

---
updated-dependencies:
- dependency-name: github.com/fluxcd/pkg/runtime
  dependency-version: 0.60.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go
- dependency-name: github.com/fluxcd/pkg/ssa
  dependency-version: 0.48.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go
- dependency-name: github.com/open-component-model/ocm-controller
  dependency-version: 0.26.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go
- dependency-name: sigs.k8s.io/controller-runtime
  dependency-version: 0.21.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go
...

Signed-off-by: dependabot[bot] <[email protected]>
@dependabot dependabot bot added kind/chore chore, maintenance, etc. kind/dependency dependency update, etc. labels May 25, 2025
@dependabot dependabot bot requested a review from a team as a code owner May 25, 2025 06:15
@dependabot dependabot bot added kind/chore chore, maintenance, etc. kind/dependency dependency update, etc. labels May 25, 2025
@hilmarf hilmarf enabled auto-merge (squash) May 26, 2025 06:59
@hilmarf hilmarf merged commit 6a85257 into main May 26, 2025
4 checks passed
@hilmarf hilmarf deleted the dependabot/go_modules/go-5d301bd4f3 branch May 26, 2025 06:59
@ocmbot ocmbot bot added this to the 2025-Q2 milestone May 26, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

kind/chore chore, maintenance, etc. kind/dependency dependency update, etc.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants