deps(go): bump the kubernetes group with 3 updates#442
Conversation
Bumps the kubernetes group with 3 updates: [k8s.io/api](https://github.com/kubernetes/api), [k8s.io/apimachinery](https://github.com/kubernetes/apimachinery) and [k8s.io/client-go](https://github.com/kubernetes/client-go). Updates `k8s.io/api` from 0.34.6 to 0.34.7 - [Commits](kubernetes/api@v0.34.6...v0.34.7) Updates `k8s.io/apimachinery` from 0.34.6 to 0.34.7 - [Commits](kubernetes/apimachinery@v0.34.6...v0.34.7) Updates `k8s.io/client-go` from 0.34.6 to 0.34.7 - [Changelog](https://github.com/kubernetes/client-go/blob/master/CHANGELOG.md) - [Commits](kubernetes/client-go@v0.34.6...v0.34.7) --- updated-dependencies: - dependency-name: k8s.io/api dependency-version: 0.34.7 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: kubernetes - dependency-name: k8s.io/apimachinery dependency-version: 0.34.7 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: kubernetes - dependency-name: k8s.io/client-go dependency-version: 0.34.7 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: kubernetes ... Signed-off-by: dependabot[bot] <support@github.com>
LabelsThe following labels could not be found: Please fix the above issues or remove invalid values from |
|
👋 Thanks for your contribution! This PR is from a fork, so the e2e tests require approval to run (they use cluster resources). For maintainers/admins: Comment For contributors: Please wait for a maintainer or admin to approve running the tests. |
MikeSpreitzer
left a comment
There was a problem hiding this comment.
I searched for relevant vulnerabilities, on my own and with Claude. The latter found that this PR incorporates a FIX for a vulnerability, CVE-2026-35469 — github.com/moby/spdystream (CVSS 8.7 HIGH). We found no vulnerabilities introduced by this PR.
I noticed that there is a later version of https://github.com/kubernetes-sigs/structured-merge-diff that could be used. For another PR.
|
/ok-to-test |
|
🚀 E2E tests triggered by /ok-to-test |
Bumps the kubernetes group with 3 updates: k8s.io/api, k8s.io/apimachinery and k8s.io/client-go.
Updates
k8s.io/apifrom 0.34.6 to 0.34.7Commits
b186ef3Update dependencies to v0.34.7 tagad42a1fMerge pull request #138357 from dims/update-moby-spdystream-v0.5.1-1.34f7287d9Merge pull request #138349 from dashpole/update_prop_3439fcc47Update github.com/moby/spdystream from v0.5.0 to v0.5.1dfcdfcdupdate go.opentelemetry.io/otel to v1.41.0Updates
k8s.io/apimachineryfrom 0.34.6 to 0.34.7Commits
454f531Merge pull request #138357 from dims/update-moby-spdystream-v0.5.1-1.34e44e450Merge pull request #138349 from dashpole/update_prop_34e2c5a26Update github.com/moby/spdystream from v0.5.0 to v0.5.103b02abupdate go.opentelemetry.io/otel to v1.41.0Updates
k8s.io/client-gofrom 0.34.6 to 0.34.7Commits
9ba2b87Update dependencies to v0.34.7 tage4156f3Merge pull request #138357 from dims/update-moby-spdystream-v0.5.1-1.34e7de3f2Merge pull request #138349 from dashpole/update_prop_3432b5239Update github.com/moby/spdystream from v0.5.0 to v0.5.13f8d3efupdate go.opentelemetry.io/otel to v1.41.0Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions